Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-10-2017
Ran by Owner (administrator) on OWNER-PC (28-10-2017 20:29:57)
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AOL Inc.) C:\Program Files\Common Files\aol\acs\AOLacsd.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Egis Incorporated) C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
(Acer Inc.) C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
(MyWebSearch.com) C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
(MyWebSearch.com) C:\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE
(AOL Inc.) C:\Program Files\Common Files\aol\1241352817\ee\aolsoftware.exe
(SupportSoft, Inc.) C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\MSN Messenger\msnmsgr.exe
(Acer Inc.) C:\Acer\Empowering Technology\eNet\eNet Service.exe
(Second Nature Software, Inc.) C:\SLIDESHW\Snsicon.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Acer\Mobility Center\MobilityService.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(MyWebSearch.com) C:\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE
(Sprint Spectrum, L.L.C) C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
(SupportSoft, Inc.) C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
() C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
(acer) C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
(Realtek Semiconductor Corp.) C:\Users\Owner\AppData\Local\Temp\RtkBtMnt.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_27_0_0_159_ActiveX.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-09-07] (Synaptics, Inc.)
HKLM\...\Run: [eRecoveryService] => [X]
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\...\Run: [MyWebSearch Plugin] => rundll32 C:\PROGRA~1\MyWebSearch\bar\2.bin\M3PLUGIN.DLL,UPF
HKLM\...\Run: [MyWebSearch Email Plugin] => C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE [32838 2009-04-30] (MyWebSearch.com)
HKLM\...\Run: [My Web Search Bar Search Scope Monitor] => C:\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE [24688 2009-04-30] (MyWebSearch.com)
HKLM\...\Run: [HostManager] => C:\Program Files\Common Files\AOL\1241352817\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.)
HKLM\...\Run: [ddoctorv2] => C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe [202560 2008-04-24] (SupportSoft, Inc.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-10-15] (Adobe Systems Incorporated)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKU\S-1-5-21-125872590-1481980480-1854466539-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-125872590-1481980480-1854466539-1003\...\Run: [MsnMsgr] => C:\Program Files\MSN Messenger\MsnMsgr.Exe [6856704 2007-09-04] (Microsoft Corporation)
HKU\S-1-5-21-125872590-1481980480-1854466539-1003\...\Run: [MyWebSearch Email Plugin] => C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE [32838 2009-04-30] (MyWebSearch.com)
HKU\S-1-5-21-125872590-1481980480-1854466539-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\32-bit Second Nature.scr [132608 1998-08-12] (Panasonic)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Forget Me Not.lnk [2008-11-18]
ShortcutTarget: Forget Me Not.lnk -> C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe (TLC Multimedia Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2008-09-10]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2008-07-26]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Snsicon.lnk [2010-07-21]
ShortcutTarget: Snsicon.lnk -> C:\SLIDESHW\Snsicon.exe (Second Nature Software, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-125872590-1481980480-1854466539-1003] => :0
AutoConfigURL: [S-1-5-21-125872590-1481980480-1854466539-1003] => :0
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{D68943E1-646B-43AE-9F15-85D946CCF8F4}: [DhcpNameServer] 68.87.66.234 68.87.64.230
Tcpip\..\Interfaces\{EDEA49A3-65C5-4B60-8A0C-88D530E5D8CC}: [DhcpNameServer] 192.168.254.254
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.comcast.net/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://en.us.acer.yahoo.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com
HKU\S-1-5-21-125872590-1481980480-1854466539-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.aol.com/?ncid=toolbar
URLSearchHook: HKLM - AOL Toolbar Search Class - {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
URLSearchHook: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 - AOL Toolbar Search Class - {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
URLSearchHook: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 - (No Name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)
SearchScopes: HKLM -> DefaultScope {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://web.search.aol.com/redirector/sredir?sredir=843&q={searchTerms}&s_it=aol-ie&s_qt=sb&tb_uuid=20110710223541204&tb_oid=10-07-2011&tb_mrud=16-02-2014
SearchScopes: HKLM -> ComcastSearch URL = hxxp://search.comcast.net/?q={searchTerms}&cat=Web&con=ie7
SearchScopes: HKLM -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://web.search.aol.com/redirector/sredir?sredir=843&q={searchTerms}&s_it=aol-ie&s_qt=sb&tb_uuid=20110710223541204&tb_oid=10-07-2011&tb_mrud=16-02-2014
SearchScopes: HKLM -> {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://www.mywebsearch.com/jsp/cfg_redir2..../mywebsearch/dft_redir.jhtml&st=sb&searchfor={searchTerms}&si=74797
SearchScopes: HKLM -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
SearchScopes: HKU\.DEFAULT -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
SearchScopes: HKU\S-1-5-19 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
SearchScopes: HKU\S-1-5-20 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> DefaultScope {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://web.search.aol.com/redirector/sredir?sredir=843&q={searchTerms}&s_it=aol-ie&s_qt=sb&tb_uuid=20110710223541204&tb_oid=10-07-2011&tb_mrud=16-02-2014
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> ComcastSearch URL = hxxp://search.comcast.net/?q={searchTerms}&cat=Web&con=ie7
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://web.search.aol.com/redirector/sredir?sredir=843&q={searchTerms}&s_it=aol-ie&s_qt=sb&tb_uuid=20110710223541204&tb_oid=10-07-2011&tb_mrud=16-02-2014
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://www.mywebsearch.com/jsp/cfg_redir2..../mywebsearch/dft_redir.jhtml&st=sb&searchfor={searchTerms}&si=74797
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=chr-acer
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> {E519AA1F-E8A8-47ED-92E3-BCFB65055819} URL = hxxp://search.comcast.net/search?cat=Web&con=toolbar&q={searchTerms}
BHO: MyWebSearch Search Assistant BHO -> {00A6FAF1-072E-44cf-8957-5838F569A31D} -> C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL [2009-04-30] (MyWebSearch.com)
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22] (Adobe Systems Incorporated)
BHO: mwsBar BHO -> {07B18EA1-A523-4961-B6BB-170DE4475CCA} -> C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL [2009-04-30] (MyWebSearch.com)
BHO: AOL Toolbar Loader -> {3ef64538-8b54-4573-b48f-4d34b0238ab2} -> C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
BHO: hpBHO Class -> {ABD3B5E1-B268-407B-A150-2641DAB8D898} -> C:\Program Files\Common Files\Homepage Protection\HomepageProtection.dll [2009-08-28] (AOL Products)
Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-01-03] (Egis Incorporated.)
Toolbar: HKLM - My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL [2009-04-30] (MyWebSearch.com)
Toolbar: HKLM - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
Toolbar: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> AOL Toolbar - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
Toolbar: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL [2009-04-30] (MyWebSearch.com)
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} hxxp://gfx2.hotmail.com/mail/w3/pr01/resources/VistaMSNPUplden-us.cab
DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} hxxp://ak.imgag.com/imgag/cp/install/Crusher.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4cz3fd5h.default [2017-10-13]
FF user.js: detected! => C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4cz3fd5h.default\user.js [2014-02-16]
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\4cz3fd5h.default -> AOL Search
FF Homepage: Mozilla\Firefox\Profiles\4cz3fd5h.default -> hxxp://www.aol.com
FF Keyword.URL: Mozilla\Firefox\Profiles\4cz3fd5h.default -> hxxp://aolsearch.aol.com/aol/search?invocationType=client_searchbox&query=
FF Extension: (AOL Toolbar) - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4cz3fd5h.default\Extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} [2014-02-16] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-12-06] [not signed]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\aolsearch.xml [2014-02-13]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_27_0_0_159.dll [2017-10-13] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-13] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-13] (Google Inc.)
FF Plugin: @viewpoint.com/VMP -> C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPMyWebS.dll [2009-04-30] (MyWebSearch.com)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default [2017-10-15]
CHR Extension: (No Name) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-16]
CHR Extension: (No Name) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-16]
CHR Extension: (No Name) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-16]
CHR Extension: (No Name) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-16]
CHR Extension: (Google Wallet) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-16]
CHR Extension: (No Name) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-16]
CHR crx: C:\Program Files\Google\Chrome\Application\43.0.2357.132\default_apps\search.crx [2015-07-06]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AdobeFlashPlayerUpdateSvc; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [272384 2017-10-28] (Adobe Systems Incorporated) [File not signed]
R2 AOL ACS; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [46184 2014-02-06] (AOL Inc.)
R2 eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [506416 2008-01-03] (Egis Incorporated)
R2 eLockService; C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [24576 2007-10-01] (Acer Inc.) [File not signed]
R2 eNet Service; C:\Acer\Empowering Technology\eNet\eNet Service.exe [131072 2007-12-20] (Acer Inc.) [File not signed]
R2 eRecoveryService; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [57344 2007-09-10] (Acer Inc.) [File not signed]
R2 eSettingsService; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [24576 2007-12-19] () [File not signed]
S3 getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [33752 2008-12-01] (NOS Microsystems Ltd.)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-13] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-03-13] (Hewlett-Packard Co.) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-11-27] () [File not signed]
S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
R2 MyWebSearchService; C:\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE [28762 2009-04-30] (MyWebSearch.com) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 SPCSUtilityService; C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe [131072 2007-08-29] (Sprint Spectrum, L.L.C) [File not signed]
R2 sprtsvc_ddoctorv2; C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe [202560 2008-04-24] (SupportSoft, Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
R2 WMIService; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [167936 2007-09-20] (acer) [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 NTIDrvr; C:\Windows\System32\DRIVERS\NTIDrvr.sys [6144 2008-02-09] (NewTech Infosystems, Inc.) [File not signed]
S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation)
R3 swmsflt; C:\Windows\System32\drivers\swmsflt.sys [24456 2007-08-10] ()
R3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-29] (America Online, Inc.)
S3 WSVD; C:\Windows\system32\drivers\WSVD.sys [80744 2006-09-19] (Wasay)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-10-28 20:29 - 2017-10-28 20:30 - 000020016 _____ C:\Users\Owner\Desktop\FRST.txt
2017-10-28 20:29 - 2017-10-28 20:29 - 000000000 ____D C:\Users\Owner\Desktop\FRST-OlderVersion
2017-10-28 20:29 - 2017-10-28 20:29 - 000000000 ____D C:\FRST
2017-10-28 20:28 - 2017-10-28 20:29 - 001799680 _____ (Farbar) C:\Users\Owner\Desktop\frst.exe
2017-10-14 03:33 - 2015-08-13 10:15 - 000304640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-10-14 03:33 - 2015-08-13 10:15 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-10-14 03:32 - 2016-01-29 23:09 - 000429056 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2017-10-14 03:32 - 2016-01-29 23:09 - 000324608 _____ (Microsoft Corporation) C:\Windows\system32\sdohlp.dll
2017-10-14 03:32 - 2016-01-29 23:09 - 000323072 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2017-10-14 03:32 - 2016-01-29 23:09 - 000293376 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2017-10-14 03:32 - 2016-01-29 23:09 - 000217600 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2017-10-14 03:32 - 2016-01-29 23:09 - 000153088 _____ (Microsoft Corporation) C:\Windows\system32\sbeio.dll
2017-10-14 03:32 - 2016-01-29 23:08 - 000180224 _____ (Microsoft Corporation) C:\Windows\system32\msorcl32.dll
2017-10-14 03:32 - 2016-01-29 23:08 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll
2017-10-14 03:32 - 2016-01-29 23:08 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2017-10-14 03:32 - 2016-01-29 23:08 - 000080896 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2017-10-14 03:32 - 2016-01-29 23:08 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2017-10-14 03:32 - 2016-01-29 23:08 - 000057856 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2017-10-14 03:32 - 2016-01-29 23:08 - 000057344 _____ (Microsoft Corporation) C:\Windows\system32\iasads.dll
2017-10-14 03:32 - 2016-01-29 23:08 - 000048128 _____ (Microsoft Corporation) C:\Windows\system32\iasdatastore.dll
2017-10-14 03:32 - 2016-01-29 21:32 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\iashost.exe
2017-10-14 03:31 - 2015-07-21 12:07 - 000140224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ecache.sys
2017-10-14 03:31 - 2015-07-21 12:07 - 000056256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2017-10-14 03:31 - 2015-07-21 12:03 - 000564224 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll
2017-10-14 03:31 - 2015-07-21 12:03 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2017-10-14 03:30 - 2015-09-02 17:26 - 001402368 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2017-10-14 03:30 - 2015-09-02 17:26 - 001253376 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2017-10-14 03:29 - 2016-02-01 13:21 - 001208776 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-10-14 03:29 - 2016-01-29 23:15 - 003609024 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2017-10-14 03:29 - 2016-01-29 23:15 - 003556800 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-10-14 03:29 - 2016-01-29 23:09 - 001316864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-10-14 03:29 - 2016-01-29 23:09 - 000783872 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-10-14 03:29 - 2016-01-29 23:08 - 000894976 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-10-14 03:29 - 2016-01-29 23:07 - 000802304 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-10-14 03:29 - 2016-01-29 23:07 - 000049664 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-10-14 03:29 - 2016-01-29 21:24 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-10-14 03:28 - 2015-07-31 15:27 - 000103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-10-14 03:27 - 2015-06-17 12:50 - 002264576 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2017-10-14 03:27 - 2015-06-17 11:09 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2017-10-14 03:25 - 2015-12-05 13:03 - 002873344 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2017-10-14 03:25 - 2015-12-05 13:03 - 001567744 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 001548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 001377792 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 001326080 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 001314816 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-10-14 03:25 - 2015-12-05 13:03 - 001114624 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000867328 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2017-10-14 03:25 - 2015-12-05 13:03 - 000767488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000759296 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000650240 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000605184 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000497152 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2017-10-14 03:25 - 2015-12-05 13:03 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000212992 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000208896 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
2017-10-14 03:25 - 2015-12-05 13:02 - 000853504 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
2017-10-14 03:25 - 2015-12-05 13:02 - 000613888 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2VDEC.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000606208 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000506880 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000480256 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2017-10-14 03:25 - 2015-12-05 13:02 - 000391680 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ADEC.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000314880 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000254976 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000254976 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000209920 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2017-10-14 03:25 - 2015-12-05 13:02 - 000158208 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2017-10-14 03:25 - 2015-12-05 13:02 - 000080896 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll
2017-10-14 03:25 - 2015-12-05 12:44 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2017-10-14 03:24 - 2015-12-05 13:03 - 000506880 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2017-10-14 03:24 - 2015-12-05 13:02 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
2017-10-14 03:24 - 2015-07-10 15:37 - 002067968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2017-10-14 03:23 - 2016-01-07 11:21 - 002068480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-10-14 03:23 - 2015-11-06 13:05 - 000627712 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2017-10-14 03:23 - 2015-11-06 12:32 - 001029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2017-10-14 03:23 - 2015-11-06 12:32 - 000219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2017-10-14 03:23 - 2015-11-06 12:32 - 000189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2017-10-14 03:23 - 2015-11-06 12:32 - 000160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2017-10-14 03:23 - 2015-11-06 11:27 - 001172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2017-10-14 03:23 - 2015-11-06 11:26 - 000486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2017-10-14 03:23 - 2015-11-06 11:20 - 001073152 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-10-14 03:23 - 2015-11-06 11:20 - 000682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-10-14 03:23 - 2015-11-06 11:19 - 000802304 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-10-14 03:22 - 2015-11-13 12:56 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2017-10-14 03:22 - 2015-11-13 12:56 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2017-10-14 03:22 - 2015-11-13 11:27 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe
2017-10-14 03:22 - 2015-10-13 10:31 - 000273408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-10-14 03:22 - 2015-10-13 10:31 - 000072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-10-14 03:20 - 2015-11-02 13:04 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
2017-10-14 03:13 - 2015-07-18 12:03 - 000068608 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2017-10-14 03:12 - 2015-09-02 17:26 - 000034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-10-14 03:12 - 2015-09-02 15:54 - 000297472 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000901264 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000066400 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000022368 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000015200 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011104 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011104 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-10-14 03:11 - 2015-08-05 11:59 - 000602112 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2017-10-14 03:11 - 2015-07-28 20:46 - 011588096 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-10-14 03:10 - 2015-11-05 03:26 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-10-14 03:10 - 2015-05-31 04:11 - 000225792 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2017-10-14 03:06 - 2015-12-05 13:02 - 000298496 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-10-14 03:05 - 2016-01-07 11:18 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2017-10-14 03:05 - 2015-11-10 13:03 - 001208832 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2017-10-14 03:05 - 2015-11-10 13:03 - 000488448 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2017-10-14 03:05 - 2015-10-10 12:02 - 000526272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2017-10-14 03:05 - 2015-07-09 10:25 - 000151040 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2017-10-14 03:05 - 2015-07-09 10:25 - 000151040 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2017-10-14 03:05 - 2015-07-01 11:57 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2017-10-14 03:02 - 2016-01-09 13:06 - 000501760 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-10-14 03:02 - 2015-11-05 03:34 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2017-10-14 03:01 - 2015-09-26 12:05 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-10-14 03:01 - 2015-09-26 12:04 - 000206336 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-10-14 03:01 - 2015-09-26 09:21 - 000274432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-10-14 03:01 - 2015-09-22 09:11 - 000440768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-10-14 03:01 - 2015-06-27 12:02 - 000218112 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-10-14 03:01 - 2015-06-27 10:21 - 000217088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-10-14 03:01 - 2015-06-27 10:21 - 000081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-10-14 03:01 - 2015-01-08 20:17 - 000107008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-10-13 13:48 - 2016-01-25 00:59 - 001815552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-10-13 13:48 - 2016-01-25 00:57 - 012391424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-10-13 13:48 - 2016-01-25 00:55 - 000367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-10-13 13:48 - 2016-01-25 00:54 - 009753600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-10-13 13:48 - 2016-01-25 00:54 - 001140224 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-10-13 13:48 - 2016-01-25 00:53 - 001129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 001804800 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 001427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-10-13 13:48 - 2016-01-25 00:52 - 000718848 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 000607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 000424960 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 000231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 000142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-10-13 13:48 - 2016-01-25 00:52 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 002382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-10-13 13:48 - 2016-01-25 00:51 - 000353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 000176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 000011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2017-10-13 13:48 - 2016-01-25 00:51 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2017-10-13 10:41 - 2017-10-13 10:42 - 072822184 _____ (Oath Inc.) C:\Users\Owner\Downloads\Install_AOL_Desktop.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-10-28 20:28 - 2006-11-02 07:18 - 000000000 ____D C:\Windows\inf
2017-10-28 20:28 - 2006-11-02 06:33 - 000826598 _____ C:\Windows\system32\PerfStringBackup.INI
2017-10-28 20:21 - 2006-11-02 07:18 - 000000000 ____D C:\Windows\rescache
2017-10-28 20:14 - 2012-10-11 13:34 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-10-28 20:14 - 2011-06-26 14:52 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-10-28 20:14 - 2008-02-09 01:38 - 000000000 ____D C:\Windows\system32\Macromed
2017-10-28 19:39 - 2006-11-02 08:47 - 000003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2017-10-28 19:39 - 2006-11-02 08:47 - 000003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2017-10-28 19:38 - 2006-11-02 09:01 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-10-15 13:30 - 2006-11-02 09:01 - 000032566 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-10-15 13:14 - 2009-04-27 19:54 - 000000000 ____D C:\Users\Owner\AppData\Local\Deployment
2017-10-15 12:31 - 2006-11-02 08:47 - 000403120 _____ C:\Windows\system32\FNTCACHE.DAT
2017-10-15 12:29 - 2008-02-09 01:37 - 000000000 ____D C:\Windows\system32\RTCOM
2017-10-15 12:29 - 2006-11-02 08:37 - 000000000 ____D C:\Windows\system32\XPSViewer
2017-10-15 12:29 - 2006-11-02 08:37 - 000000000 ____D C:\Program Files\Windows Journal
2017-10-15 12:29 - 2006-11-02 08:37 - 000000000 ____D C:\Program Files\Windows Collaboration
2017-10-14 03:20 - 2013-08-15 03:10 - 000000000 ____D C:\Windows\system32\MRT
2017-10-14 03:14 - 2006-11-02 06:24 - 144254680 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2017-10-13 19:27 - 2013-12-16 16:45 - 000001949 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-10-13 19:27 - 2013-12-16 16:45 - 000001937 _____ C:\Users\Public\Desktop\Google Chrome.lnk
==================== Files in the root of some directories =======
2008-07-13 21:54 - 2013-03-16 10:04 - 000013312 _____ () C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2008-09-10 20:08 - 2008-09-10 21:49 - 000001127 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
2014-02-12 22:56 - 2014-02-12 22:56 - 000115816 _____ (AOL Inc.) C:\Users\Owner\AppData\Local\Temp\AcsInstall.dll
2010-07-21 22:10 - 2010-07-21 22:10 - 002605008 _____ (Adobe Systems, Inc.) C:\Users\Owner\AppData\Local\Temp\FlashPlayerUpdate.exe
2011-07-10 18:36 - 2011-07-10 18:36 - 000382648 _____ (AOL Products) C:\Users\Owner\AppData\Local\Temp\homepage-protection190C.exe
2013-06-30 03:40 - 2013-06-30 03:40 - 000208896 _____ (Realtek Semiconductor Corp.) C:\Users\Owner\AppData\Local\Temp\RtkBtMnt.exe
2003-10-23 14:27 - 2003-10-23 14:27 - 000022528 _____ (Microsoft Corporation) C:\Users\Owner\AppData\Local\Temp\SHFOLDER.DLL
2010-07-21 22:16 - 2010-07-21 22:16 - 000002560 _____ () C:\Users\Owner\AppData\Local\Temp\~GL_105D.EXE
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-10-28 20:18
==================== End of FRST.txt ============================
Ran by Owner (administrator) on OWNER-PC (28-10-2017 20:29:57)
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AOL Inc.) C:\Program Files\Common Files\aol\acs\AOLacsd.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Egis Incorporated) C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
(Acer Inc.) C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
(MyWebSearch.com) C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
(MyWebSearch.com) C:\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE
(AOL Inc.) C:\Program Files\Common Files\aol\1241352817\ee\aolsoftware.exe
(SupportSoft, Inc.) C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\MSN Messenger\msnmsgr.exe
(Acer Inc.) C:\Acer\Empowering Technology\eNet\eNet Service.exe
(Second Nature Software, Inc.) C:\SLIDESHW\Snsicon.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Acer\Mobility Center\MobilityService.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(MyWebSearch.com) C:\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE
(Sprint Spectrum, L.L.C) C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
(SupportSoft, Inc.) C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Acer Inc.) C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
() C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
(acer) C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
(Realtek Semiconductor Corp.) C:\Users\Owner\AppData\Local\Temp\RtkBtMnt.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_27_0_0_159_ActiveX.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-09-07] (Synaptics, Inc.)
HKLM\...\Run: [eRecoveryService] => [X]
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\...\Run: [MyWebSearch Plugin] => rundll32 C:\PROGRA~1\MyWebSearch\bar\2.bin\M3PLUGIN.DLL,UPF
HKLM\...\Run: [MyWebSearch Email Plugin] => C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE [32838 2009-04-30] (MyWebSearch.com)
HKLM\...\Run: [My Web Search Bar Search Scope Monitor] => C:\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE [24688 2009-04-30] (MyWebSearch.com)
HKLM\...\Run: [HostManager] => C:\Program Files\Common Files\AOL\1241352817\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.)
HKLM\...\Run: [ddoctorv2] => C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe [202560 2008-04-24] (SupportSoft, Inc.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-10-15] (Adobe Systems Incorporated)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4853760 2008-01-07] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKU\S-1-5-21-125872590-1481980480-1854466539-1003\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-125872590-1481980480-1854466539-1003\...\Run: [MsnMsgr] => C:\Program Files\MSN Messenger\MsnMsgr.Exe [6856704 2007-09-04] (Microsoft Corporation)
HKU\S-1-5-21-125872590-1481980480-1854466539-1003\...\Run: [MyWebSearch Email Plugin] => C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE [32838 2009-04-30] (MyWebSearch.com)
HKU\S-1-5-21-125872590-1481980480-1854466539-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\32-bit Second Nature.scr [132608 1998-08-12] (Panasonic)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Forget Me Not.lnk [2008-11-18]
ShortcutTarget: Forget Me Not.lnk -> C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe (TLC Multimedia Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2008-09-10]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2008-07-26]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Snsicon.lnk [2010-07-21]
ShortcutTarget: Snsicon.lnk -> C:\SLIDESHW\Snsicon.exe (Second Nature Software, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-125872590-1481980480-1854466539-1003] => :0
AutoConfigURL: [S-1-5-21-125872590-1481980480-1854466539-1003] => :0
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{D68943E1-646B-43AE-9F15-85D946CCF8F4}: [DhcpNameServer] 68.87.66.234 68.87.64.230
Tcpip\..\Interfaces\{EDEA49A3-65C5-4B60-8A0C-88D530E5D8CC}: [DhcpNameServer] 192.168.254.254
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.comcast.net/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://en.us.acer.yahoo.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://global.acer.com
HKU\S-1-5-21-125872590-1481980480-1854466539-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.aol.com/?ncid=toolbar
URLSearchHook: HKLM - AOL Toolbar Search Class - {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
URLSearchHook: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 - AOL Toolbar Search Class - {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
URLSearchHook: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 - (No Name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)
SearchScopes: HKLM -> DefaultScope {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://web.search.aol.com/redirector/sredir?sredir=843&q={searchTerms}&s_it=aol-ie&s_qt=sb&tb_uuid=20110710223541204&tb_oid=10-07-2011&tb_mrud=16-02-2014
SearchScopes: HKLM -> ComcastSearch URL = hxxp://search.comcast.net/?q={searchTerms}&cat=Web&con=ie7
SearchScopes: HKLM -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://web.search.aol.com/redirector/sredir?sredir=843&q={searchTerms}&s_it=aol-ie&s_qt=sb&tb_uuid=20110710223541204&tb_oid=10-07-2011&tb_mrud=16-02-2014
SearchScopes: HKLM -> {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://www.mywebsearch.com/jsp/cfg_redir2..../mywebsearch/dft_redir.jhtml&st=sb&searchfor={searchTerms}&si=74797
SearchScopes: HKLM -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
SearchScopes: HKU\.DEFAULT -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
SearchScopes: HKU\S-1-5-19 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
SearchScopes: HKU\S-1-5-20 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> DefaultScope {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://web.search.aol.com/redirector/sredir?sredir=843&q={searchTerms}&s_it=aol-ie&s_qt=sb&tb_uuid=20110710223541204&tb_oid=10-07-2011&tb_mrud=16-02-2014
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> ComcastSearch URL = hxxp://search.comcast.net/?q={searchTerms}&cat=Web&con=ie7
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://web.search.aol.com/redirector/sredir?sredir=843&q={searchTerms}&s_it=aol-ie&s_qt=sb&tb_uuid=20110710223541204&tb_oid=10-07-2011&tb_mrud=16-02-2014
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://www.mywebsearch.com/jsp/cfg_redir2..../mywebsearch/dft_redir.jhtml&st=sb&searchfor={searchTerms}&si=74797
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=chr-acer
SearchScopes: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> {E519AA1F-E8A8-47ED-92E3-BCFB65055819} URL = hxxp://search.comcast.net/search?cat=Web&con=toolbar&q={searchTerms}
BHO: MyWebSearch Search Assistant BHO -> {00A6FAF1-072E-44cf-8957-5838F569A31D} -> C:\Program Files\MyWebSearch\bar\2.bin\MWSSRCAS.DLL [2009-04-30] (MyWebSearch.com)
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22] (Adobe Systems Incorporated)
BHO: mwsBar BHO -> {07B18EA1-A523-4961-B6BB-170DE4475CCA} -> C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL [2009-04-30] (MyWebSearch.com)
BHO: AOL Toolbar Loader -> {3ef64538-8b54-4573-b48f-4d34b0238ab2} -> C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
BHO: hpBHO Class -> {ABD3B5E1-B268-407B-A150-2641DAB8D898} -> C:\Program Files\Common Files\Homepage Protection\HomepageProtection.dll [2009-08-28] (AOL Products)
Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-01-03] (Egis Incorporated.)
Toolbar: HKLM - My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL [2009-04-30] (MyWebSearch.com)
Toolbar: HKLM - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
Toolbar: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> AOL Toolbar - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
Toolbar: HKU\S-1-5-21-125872590-1481980480-1854466539-1003 -> My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL [2009-04-30] (MyWebSearch.com)
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} hxxp://gfx2.hotmail.com/mail/w3/pr01/resources/VistaMSNPUplden-us.cab
DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} hxxp://ak.imgag.com/imgag/cp/install/Crusher.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4cz3fd5h.default [2017-10-13]
FF user.js: detected! => C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4cz3fd5h.default\user.js [2014-02-16]
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\4cz3fd5h.default -> AOL Search
FF Homepage: Mozilla\Firefox\Profiles\4cz3fd5h.default -> hxxp://www.aol.com
FF Keyword.URL: Mozilla\Firefox\Profiles\4cz3fd5h.default -> hxxp://aolsearch.aol.com/aol/search?invocationType=client_searchbox&query=
FF Extension: (AOL Toolbar) - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\4cz3fd5h.default\Extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} [2014-02-16] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-12-06] [not signed]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\aolsearch.xml [2014-02-13]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_27_0_0_159.dll [2017-10-13] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-13] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-13] (Google Inc.)
FF Plugin: @viewpoint.com/VMP -> C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPMyWebS.dll [2009-04-30] (MyWebSearch.com)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default [2017-10-15]
CHR Extension: (No Name) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-16]
CHR Extension: (No Name) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-16]
CHR Extension: (No Name) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-16]
CHR Extension: (No Name) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-16]
CHR Extension: (Google Wallet) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-16]
CHR Extension: (No Name) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-16]
CHR crx: C:\Program Files\Google\Chrome\Application\43.0.2357.132\default_apps\search.crx [2015-07-06]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AdobeFlashPlayerUpdateSvc; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [272384 2017-10-28] (Adobe Systems Incorporated) [File not signed]
R2 AOL ACS; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [46184 2014-02-06] (AOL Inc.)
R2 eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [506416 2008-01-03] (Egis Incorporated)
R2 eLockService; C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [24576 2007-10-01] (Acer Inc.) [File not signed]
R2 eNet Service; C:\Acer\Empowering Technology\eNet\eNet Service.exe [131072 2007-12-20] (Acer Inc.) [File not signed]
R2 eRecoveryService; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [57344 2007-09-10] (Acer Inc.) [File not signed]
R2 eSettingsService; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [24576 2007-12-19] () [File not signed]
S3 getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [33752 2008-12-01] (NOS Microsystems Ltd.)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-13] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-03-13] (Hewlett-Packard Co.) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-11-27] () [File not signed]
S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
R2 MyWebSearchService; C:\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE [28762 2009-04-30] (MyWebSearch.com) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 SPCSUtilityService; C:\Program Files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe [131072 2007-08-29] (Sprint Spectrum, L.L.C) [File not signed]
R2 sprtsvc_ddoctorv2; C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe [202560 2008-04-24] (SupportSoft, Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
R2 WMIService; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [167936 2007-09-20] (acer) [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 NTIDrvr; C:\Windows\System32\DRIVERS\NTIDrvr.sys [6144 2008-02-09] (NewTech Infosystems, Inc.) [File not signed]
S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation)
R3 swmsflt; C:\Windows\System32\drivers\swmsflt.sys [24456 2007-08-10] ()
R3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-29] (America Online, Inc.)
S3 WSVD; C:\Windows\system32\drivers\WSVD.sys [80744 2006-09-19] (Wasay)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-10-28 20:29 - 2017-10-28 20:30 - 000020016 _____ C:\Users\Owner\Desktop\FRST.txt
2017-10-28 20:29 - 2017-10-28 20:29 - 000000000 ____D C:\Users\Owner\Desktop\FRST-OlderVersion
2017-10-28 20:29 - 2017-10-28 20:29 - 000000000 ____D C:\FRST
2017-10-28 20:28 - 2017-10-28 20:29 - 001799680 _____ (Farbar) C:\Users\Owner\Desktop\frst.exe
2017-10-14 03:33 - 2015-08-13 10:15 - 000304640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-10-14 03:33 - 2015-08-13 10:15 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-10-14 03:32 - 2016-01-29 23:09 - 000429056 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2017-10-14 03:32 - 2016-01-29 23:09 - 000324608 _____ (Microsoft Corporation) C:\Windows\system32\sdohlp.dll
2017-10-14 03:32 - 2016-01-29 23:09 - 000323072 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2017-10-14 03:32 - 2016-01-29 23:09 - 000293376 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2017-10-14 03:32 - 2016-01-29 23:09 - 000217600 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2017-10-14 03:32 - 2016-01-29 23:09 - 000153088 _____ (Microsoft Corporation) C:\Windows\system32\sbeio.dll
2017-10-14 03:32 - 2016-01-29 23:08 - 000180224 _____ (Microsoft Corporation) C:\Windows\system32\msorcl32.dll
2017-10-14 03:32 - 2016-01-29 23:08 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll
2017-10-14 03:32 - 2016-01-29 23:08 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2017-10-14 03:32 - 2016-01-29 23:08 - 000080896 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2017-10-14 03:32 - 2016-01-29 23:08 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2017-10-14 03:32 - 2016-01-29 23:08 - 000057856 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2017-10-14 03:32 - 2016-01-29 23:08 - 000057344 _____ (Microsoft Corporation) C:\Windows\system32\iasads.dll
2017-10-14 03:32 - 2016-01-29 23:08 - 000048128 _____ (Microsoft Corporation) C:\Windows\system32\iasdatastore.dll
2017-10-14 03:32 - 2016-01-29 21:32 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\iashost.exe
2017-10-14 03:31 - 2015-07-21 12:07 - 000140224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ecache.sys
2017-10-14 03:31 - 2015-07-21 12:07 - 000056256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2017-10-14 03:31 - 2015-07-21 12:03 - 000564224 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll
2017-10-14 03:31 - 2015-07-21 12:03 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2017-10-14 03:30 - 2015-09-02 17:26 - 001402368 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2017-10-14 03:30 - 2015-09-02 17:26 - 001253376 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2017-10-14 03:29 - 2016-02-01 13:21 - 001208776 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-10-14 03:29 - 2016-01-29 23:15 - 003609024 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2017-10-14 03:29 - 2016-01-29 23:15 - 003556800 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-10-14 03:29 - 2016-01-29 23:09 - 001316864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-10-14 03:29 - 2016-01-29 23:09 - 000783872 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-10-14 03:29 - 2016-01-29 23:08 - 000894976 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-10-14 03:29 - 2016-01-29 23:07 - 000802304 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-10-14 03:29 - 2016-01-29 23:07 - 000049664 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-10-14 03:29 - 2016-01-29 21:24 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-10-14 03:28 - 2015-07-31 15:27 - 000103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-10-14 03:27 - 2015-06-17 12:50 - 002264576 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2017-10-14 03:27 - 2015-06-17 11:09 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2017-10-14 03:25 - 2015-12-05 13:03 - 002873344 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2017-10-14 03:25 - 2015-12-05 13:03 - 001567744 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 001548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 001377792 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 001326080 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 001314816 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-10-14 03:25 - 2015-12-05 13:03 - 001114624 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000867328 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2017-10-14 03:25 - 2015-12-05 13:03 - 000767488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000759296 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000650240 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000605184 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000497152 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2017-10-14 03:25 - 2015-12-05 13:03 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000212992 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
2017-10-14 03:25 - 2015-12-05 13:03 - 000208896 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
2017-10-14 03:25 - 2015-12-05 13:02 - 000853504 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
2017-10-14 03:25 - 2015-12-05 13:02 - 000613888 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2VDEC.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000606208 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000506880 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000480256 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2017-10-14 03:25 - 2015-12-05 13:02 - 000391680 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ADEC.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000314880 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000254976 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000254976 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000209920 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2017-10-14 03:25 - 2015-12-05 13:02 - 000158208 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2017-10-14 03:25 - 2015-12-05 13:02 - 000080896 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
2017-10-14 03:25 - 2015-12-05 13:02 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll
2017-10-14 03:25 - 2015-12-05 12:44 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2017-10-14 03:24 - 2015-12-05 13:03 - 000506880 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2017-10-14 03:24 - 2015-12-05 13:02 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
2017-10-14 03:24 - 2015-07-10 15:37 - 002067968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2017-10-14 03:23 - 2016-01-07 11:21 - 002068480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-10-14 03:23 - 2015-11-06 13:05 - 000627712 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2017-10-14 03:23 - 2015-11-06 12:32 - 001029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2017-10-14 03:23 - 2015-11-06 12:32 - 000219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2017-10-14 03:23 - 2015-11-06 12:32 - 000189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2017-10-14 03:23 - 2015-11-06 12:32 - 000160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2017-10-14 03:23 - 2015-11-06 11:27 - 001172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2017-10-14 03:23 - 2015-11-06 11:26 - 000486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2017-10-14 03:23 - 2015-11-06 11:20 - 001073152 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-10-14 03:23 - 2015-11-06 11:20 - 000682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-10-14 03:23 - 2015-11-06 11:19 - 000802304 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-10-14 03:22 - 2015-11-13 12:56 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2017-10-14 03:22 - 2015-11-13 12:56 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2017-10-14 03:22 - 2015-11-13 11:27 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe
2017-10-14 03:22 - 2015-10-13 10:31 - 000273408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-10-14 03:22 - 2015-10-13 10:31 - 000072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-10-14 03:20 - 2015-11-02 13:04 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
2017-10-14 03:13 - 2015-07-18 12:03 - 000068608 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2017-10-14 03:12 - 2015-09-02 17:26 - 000034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-10-14 03:12 - 2015-09-02 15:54 - 000297472 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000901264 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000066400 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000022368 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000015200 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011104 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-14 03:12 - 2015-07-18 09:14 - 000011104 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-10-14 03:11 - 2015-08-05 11:59 - 000602112 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2017-10-14 03:11 - 2015-07-28 20:46 - 011588096 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-10-14 03:10 - 2015-11-05 03:26 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-10-14 03:10 - 2015-05-31 04:11 - 000225792 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2017-10-14 03:06 - 2015-12-05 13:02 - 000298496 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-10-14 03:05 - 2016-01-07 11:18 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2017-10-14 03:05 - 2015-11-10 13:03 - 001208832 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2017-10-14 03:05 - 2015-11-10 13:03 - 000488448 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2017-10-14 03:05 - 2015-10-10 12:02 - 000526272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2017-10-14 03:05 - 2015-07-09 10:25 - 000151040 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2017-10-14 03:05 - 2015-07-09 10:25 - 000151040 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2017-10-14 03:05 - 2015-07-01 11:57 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2017-10-14 03:02 - 2016-01-09 13:06 - 000501760 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-10-14 03:02 - 2015-11-05 03:34 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2017-10-14 03:01 - 2015-09-26 12:05 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-10-14 03:01 - 2015-09-26 12:04 - 000206336 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-10-14 03:01 - 2015-09-26 09:21 - 000274432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-10-14 03:01 - 2015-09-22 09:11 - 000440768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-10-14 03:01 - 2015-06-27 12:02 - 000218112 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-10-14 03:01 - 2015-06-27 10:21 - 000217088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-10-14 03:01 - 2015-06-27 10:21 - 000081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-10-14 03:01 - 2015-01-08 20:17 - 000107008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-10-13 13:48 - 2016-01-25 00:59 - 001815552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-10-13 13:48 - 2016-01-25 00:57 - 012391424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-10-13 13:48 - 2016-01-25 00:55 - 000367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-10-13 13:48 - 2016-01-25 00:54 - 009753600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-10-13 13:48 - 2016-01-25 00:54 - 001140224 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-10-13 13:48 - 2016-01-25 00:53 - 001129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 001804800 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 001427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-10-13 13:48 - 2016-01-25 00:52 - 000718848 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 000607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 000424960 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 000231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2017-10-13 13:48 - 2016-01-25 00:52 - 000142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-10-13 13:48 - 2016-01-25 00:52 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 002382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-10-13 13:48 - 2016-01-25 00:51 - 000353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 000176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2017-10-13 13:48 - 2016-01-25 00:51 - 000011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2017-10-13 13:48 - 2016-01-25 00:51 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2017-10-13 10:41 - 2017-10-13 10:42 - 072822184 _____ (Oath Inc.) C:\Users\Owner\Downloads\Install_AOL_Desktop.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-10-28 20:28 - 2006-11-02 07:18 - 000000000 ____D C:\Windows\inf
2017-10-28 20:28 - 2006-11-02 06:33 - 000826598 _____ C:\Windows\system32\PerfStringBackup.INI
2017-10-28 20:21 - 2006-11-02 07:18 - 000000000 ____D C:\Windows\rescache
2017-10-28 20:14 - 2012-10-11 13:34 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-10-28 20:14 - 2011-06-26 14:52 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-10-28 20:14 - 2008-02-09 01:38 - 000000000 ____D C:\Windows\system32\Macromed
2017-10-28 19:39 - 2006-11-02 08:47 - 000003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2017-10-28 19:39 - 2006-11-02 08:47 - 000003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2017-10-28 19:38 - 2006-11-02 09:01 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-10-15 13:30 - 2006-11-02 09:01 - 000032566 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-10-15 13:14 - 2009-04-27 19:54 - 000000000 ____D C:\Users\Owner\AppData\Local\Deployment
2017-10-15 12:31 - 2006-11-02 08:47 - 000403120 _____ C:\Windows\system32\FNTCACHE.DAT
2017-10-15 12:29 - 2008-02-09 01:37 - 000000000 ____D C:\Windows\system32\RTCOM
2017-10-15 12:29 - 2006-11-02 08:37 - 000000000 ____D C:\Windows\system32\XPSViewer
2017-10-15 12:29 - 2006-11-02 08:37 - 000000000 ____D C:\Program Files\Windows Journal
2017-10-15 12:29 - 2006-11-02 08:37 - 000000000 ____D C:\Program Files\Windows Collaboration
2017-10-14 03:20 - 2013-08-15 03:10 - 000000000 ____D C:\Windows\system32\MRT
2017-10-14 03:14 - 2006-11-02 06:24 - 144254680 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2017-10-13 19:27 - 2013-12-16 16:45 - 000001949 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-10-13 19:27 - 2013-12-16 16:45 - 000001937 _____ C:\Users\Public\Desktop\Google Chrome.lnk
==================== Files in the root of some directories =======
2008-07-13 21:54 - 2013-03-16 10:04 - 000013312 _____ () C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2008-09-10 20:08 - 2008-09-10 21:49 - 000001127 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
2014-02-12 22:56 - 2014-02-12 22:56 - 000115816 _____ (AOL Inc.) C:\Users\Owner\AppData\Local\Temp\AcsInstall.dll
2010-07-21 22:10 - 2010-07-21 22:10 - 002605008 _____ (Adobe Systems, Inc.) C:\Users\Owner\AppData\Local\Temp\FlashPlayerUpdate.exe
2011-07-10 18:36 - 2011-07-10 18:36 - 000382648 _____ (AOL Products) C:\Users\Owner\AppData\Local\Temp\homepage-protection190C.exe
2013-06-30 03:40 - 2013-06-30 03:40 - 000208896 _____ (Realtek Semiconductor Corp.) C:\Users\Owner\AppData\Local\Temp\RtkBtMnt.exe
2003-10-23 14:27 - 2003-10-23 14:27 - 000022528 _____ (Microsoft Corporation) C:\Users\Owner\AppData\Local\Temp\SHFOLDER.DLL
2010-07-21 22:16 - 2010-07-21 22:16 - 000002560 _____ () C:\Users\Owner\AppData\Local\Temp\~GL_105D.EXE
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-10-28 20:18
==================== End of FRST.txt ============================