From the start again.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-02-2017 02
Ran by Randy (administrator) on HP-RRR (15-02-2017 20:02:24)
Running from C:\Users\Randy\Desktop\Virus
Loaded Profiles: Randy (Available Profiles: Randy & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-01-04] (IDT, Inc.)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800416 2012-01-19] (Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3954352 2016-04-27] (Synaptics Incorporated)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [576568 2011-11-29] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1342008 2011-08-26] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\...\Run: [HP OfficeJet 3830 series (NET)] => C:\Program Files\HP\HP OfficeJet 3830 series\Bin\ScanToPCActivationApp.exe [3651080 2015-03-09] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\...\Run: [Chromium] => c:\users\randy\appdata\local\chromium\application\chrome.exe [1043456 2016-01-26] (The Chromium Authors)
ShellIconOverlayIdentifiers: [ CustomFolderNotSynced] -> {4008A679-BE48-456D-A32E-97DE3F48E10D} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll -> No File
ShellIconOverlayIdentifiers: [ CustomFolderSynced] -> {4DD1429E-055B-4585-9E4D-614252FD7FC1} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll -> No File
ShellIconOverlayIdentifiers: [ FileNotSynced] -> {267973DC-2B3C-41CE-93F1-D2C5CCC06663} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll -> No File
ShellIconOverlayIdentifiers: [ FileSynced] -> {DBD42211-56CD-4C08-A3E4-48ED07AD7759} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll -> No File
ShellIconOverlayIdentifiers: [ FolderExcluded] -> {43BAE28F-4AC6-4C1F-9A86-E0D8533370BC} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll -> No File
ShellIconOverlayIdentifiers: [ FolderNotSynced] -> {3E2576B1-5B08-47DE-8803-95C6ECA734EE} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll -> No File
ShellIconOverlayIdentifiers: [ FolderSynced] -> {2858A960-566F-45CF-951E-4B3099E70E6F} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ CustomFolderNotSynced] -> {4008A679-BE48-456D-A32E-97DE3F48E10D} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll -> No File
ShellIconOverlayIdentifiers-x32: [ CustomFolderSynced] -> {4DD1429E-055B-4585-9E4D-614252FD7FC1} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll -> No File
ShellIconOverlayIdentifiers-x32: [ FileNotSynced] -> {267973DC-2B3C-41CE-93F1-D2C5CCC06663} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll -> No File
ShellIconOverlayIdentifiers-x32: [ FileSynced] -> {DBD42211-56CD-4C08-A3E4-48ED07AD7759} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll -> No File
ShellIconOverlayIdentifiers-x32: [ FolderExcluded] -> {43BAE28F-4AC6-4C1F-9A86-E0D8533370BC} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll -> No File
ShellIconOverlayIdentifiers-x32: [ FolderNotSynced] -> {3E2576B1-5B08-47DE-8803-95C6ECA734EE} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll -> No File
ShellIconOverlayIdentifiers-x32: [ FolderSynced] -> {2858A960-566F-45CF-951E-4B3099E70E6F} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll -> No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Event Reminder.lnk [2015-12-11]
ShortcutTarget: Event Reminder.lnk -> C:\Program Files (x86)\Broderbund\PrintMaster\pmremind.exe (Broderbund Properties LLC)
Startup: C:\Users\Randy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2016-02-02] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 127.0.0.1 localhost
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8
Tcpip\Parameters: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{31ea90e4-35d4-4540-a94c-eab28ac7c7e0}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{31ea90e4-35d4-4540-a94c-eab28ac7c7e0}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{34167375-BE40-466A-AF7E-71F5E33959CD}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{3973625b-d550-4482-8626-055c851fa7f8}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{3973625b-d550-4482-8626-055c851fa7f8}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{3D493812-5A6C-4569-8948-931983678700}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{3e5366e2-e619-4c7e-a254-4148181480bb}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{3e5366e2-e619-4c7e-a254-4148181480bb}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{5d4a1c6d-c9d7-11e5-93ba-806e6f6e6963}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{6F79DAF9-0BD7-4158-9C0C-745284478CE4}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{797fc918-2a02-4a5f-9f81-cc4932956ea0}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{797fc918-2a02-4a5f-9f81-cc4932956ea0}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{825E0274-4ABB-4A35-83B7-62488622A3B1}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{82f2cad0-7a7c-4d6d-95d4-2003995ef9f1}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{95c3e60d-7d80-41db-be01-e26265544b30}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{a1c95c13-acd4-4e93-88c9-2912fbc94e6c}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{a1c95c13-acd4-4e93-88c9-2912fbc94e6c}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{c1fd1c83-dc19-4fbd-a13f-ebdcb53d58b0}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{c1fd1c83-dc19-4fbd-a13f-ebdcb53d58b0}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{ed4e3568-60c7-4154-bc8c-83374c0e6f1c}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{ed4e3568-60c7-4154-bc8c-83374c0e6f1c}: [DhcpNameServer] 8.8.8.8
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131312655671564010&GUID=F34706C8-BC86-441C-8A8D-ECA6761F344B
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131312655672036951&GUID=F34706C8-BC86-441C-8A8D-ECA6761F344B
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131312655672053665&GUID=F34706C8-BC86-441C-8A8D-ECA6761F344B
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-01-19] (Atheros Commnucations)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
FireFox:
========
FF ProfilePath: C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default [2017-02-11]
FF NewTab: Mozilla\Firefox\Profiles\w1n6vmjf.default -> about:newtab
FF Extension: (No Name) - C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\extensions\videoresumer@jetpack [not found]
FF Extension: (No Name) - C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [not found]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\aolsearch.xml [2015-12-15]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2011-11-07] (Adobe Systems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2783097096-289569773-1546617986-1001: bluejeans.com/bjninstallplugin -> C:\Users\Randy\AppData\Roaming\Blue Jeans\bjnplugin\2.115.57.5\npbjninstallplugin_2.115.57.5.dll [2015-10-15] (Blue Jeans)
FF Plugin HKU\S-1-5-21-2783097096-289569773-1546617986-1001: bluejeans.com/bjnplugin -> C:\Users\Randy\AppData\Roaming\Blue Jeans\bjnplugin\2.115.57.5\npbjnplugin_2.115.57.5.dll [2015-10-15] (Blue Jeans)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-02-10] (Advanced Micro Devices, Inc.) [File not signed]
R3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [253960 2016-04-27] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-10-25] (Microsoft Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2012-01-19] (Atheros) [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices)
S3 lehidmini; C:\WINDOWS\system32\drivers\leath_hid.sys [36128 2012-01-19] (Atheros) [File not signed]
S3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-02-15] (Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [251848 2017-02-15] (Malwarebytes)
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2015-10-29] (Realtek )
S3 ssmirrdr; C:\WINDOWS\system32\DRIVERS\ssmirrdr.sys [10112 2015-06-29] (support.com, Inc)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44568 2015-10-29] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [293216 2015-10-29] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-29] (Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation)
S3 wanatw; \SystemRoot\System32\drivers\wanatw64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-15 20:02 - 2017-02-15 20:02 - 00000000 ____D C:\FRST
2017-02-15 18:01 - 2017-02-15 18:04 - 00000000 ____D C:\AdwCleaner
2017-02-14 21:26 - 2017-02-14 21:26 - 00003638 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2017-02-14 21:25 - 2017-02-14 21:26 - 00001335 _____ C:\DelFix.txt
2017-02-13 20:41 - 2017-02-13 20:41 - 00000000 ____D C:\ProgramData\Sophos
2017-02-13 20:40 - 2017-02-13 20:40 - 00002775 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2017-02-13 20:40 - 2017-02-13 20:40 - 00002775 _____ C:\ProgramData\Desktop\Sophos Virus Removal Tool.lnk
2017-02-13 20:40 - 2017-02-13 20:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2017-02-13 20:40 - 2017-02-13 20:40 - 00000000 ____D C:\Program Files (x86)\Sophos
2017-02-13 18:54 - 2017-02-13 18:54 - 00000002 _____ C:\WINDOWS\msoffice.ini
2017-02-12 19:56 - 2017-02-13 11:28 - 00176584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-02-12 19:55 - 2017-02-15 18:18 - 00251848 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-02-12 19:55 - 2017-02-15 18:18 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-02-12 19:55 - 2017-02-12 19:57 - 00091584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-02-12 19:55 - 2017-02-12 19:55 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-02-12 19:55 - 2017-02-12 19:55 - 00001912 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2017-02-12 19:55 - 2017-02-12 19:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-02-12 19:55 - 2017-02-12 19:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-02-12 19:55 - 2017-02-12 19:55 - 00000000 ____D C:\Program Files\Malwarebytes
2017-02-12 19:55 - 2017-01-20 07:47 - 00077416 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-02-12 16:58 - 2017-02-12 22:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2017-02-12 15:09 - 2017-02-12 15:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-02-12 15:09 - 2017-02-12 15:09 - 00000000 ____D C:\Program Files\RogueKiller
2017-02-11 18:00 - 2016-12-20 23:18 - 01372312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2017-02-11 18:00 - 2016-11-22 01:24 - 02938408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-02-11 18:00 - 2016-11-22 01:17 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2017-02-11 18:00 - 2016-11-22 01:16 - 00064072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
2017-02-11 18:00 - 2016-11-22 00:49 - 02195640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2017-02-11 18:00 - 2016-11-22 00:48 - 01522672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-02-11 18:00 - 2016-11-22 00:47 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-02-11 18:00 - 2016-11-22 00:12 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-02-11 18:00 - 2016-11-21 23:54 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2017-02-11 18:00 - 2016-11-21 23:41 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2017-02-11 18:00 - 2016-11-21 23:38 - 00541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2017-02-11 18:00 - 2016-11-21 22:59 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2017-02-11 18:00 - 2016-11-21 22:55 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-02-11 18:00 - 2016-11-02 05:32 - 00316256 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-02-11 18:00 - 2016-11-02 05:31 - 00546968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-02-11 18:00 - 2016-10-25 01:34 - 00454496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys
2017-02-11 18:00 - 2016-10-25 00:32 - 01862000 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-02-11 18:00 - 2016-10-25 00:32 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2017-02-11 18:00 - 2016-10-25 00:32 - 00845568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2017-02-11 18:00 - 2016-10-25 00:32 - 00034088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2017-02-11 18:00 - 2016-10-25 00:28 - 01083648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2017-02-11 18:00 - 2016-10-25 00:05 - 00712032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-02-11 18:00 - 2016-10-24 23:45 - 00032096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys
2017-02-11 18:00 - 2016-10-24 23:39 - 00306840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2017-02-11 18:00 - 2016-10-24 23:37 - 02180128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-02-11 18:00 - 2016-10-24 23:37 - 01349632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-02-11 18:00 - 2016-10-24 23:37 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-02-11 18:00 - 2016-10-24 23:37 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2017-02-11 18:00 - 2016-10-24 23:37 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-02-11 18:00 - 2016-10-24 23:37 - 00709176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2017-02-11 18:00 - 2016-10-24 23:31 - 01824272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-02-11 18:00 - 2016-10-24 23:31 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-02-11 18:00 - 2016-10-24 23:30 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-02-11 18:00 - 2016-10-24 23:29 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-02-11 18:00 - 2016-10-24 23:27 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-02-11 18:00 - 2016-10-24 23:27 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-02-11 18:00 - 2016-10-24 23:27 - 00256704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2017-02-11 18:00 - 2016-10-24 23:26 - 05240952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-02-11 18:00 - 2016-10-24 23:26 - 04074160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-02-11 18:00 - 2016-10-24 23:26 - 01355344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2017-02-11 18:00 - 2016-10-24 23:26 - 00836752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-02-11 18:00 - 2016-10-24 23:26 - 00569752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2017-02-11 18:00 - 2016-10-24 23:22 - 00268040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2017-02-11 18:00 - 2016-10-24 23:19 - 00295776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-02-11 18:00 - 2016-10-24 23:18 - 01536088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-02-11 18:00 - 2016-10-24 22:56 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2017-02-11 18:00 - 2016-10-24 22:54 - 00273760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\input.dll
2017-02-11 18:00 - 2016-10-24 22:53 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-02-11 18:00 - 2016-10-24 22:27 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-02-11 18:00 - 2016-10-24 22:26 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-02-11 18:00 - 2016-10-24 22:21 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2017-02-11 18:00 - 2016-10-24 22:08 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2017-02-11 18:00 - 2016-10-24 22:06 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2017-02-11 18:00 - 2016-10-24 22:00 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2017-02-11 18:00 - 2016-10-24 21:59 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oemlicense.dll
2017-02-11 18:00 - 2016-10-24 21:54 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2017-02-11 18:00 - 2016-10-24 21:50 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\azroleui.dll
2017-02-11 18:00 - 2016-10-24 21:50 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-02-11 18:00 - 2016-10-24 21:50 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-02-11 18:00 - 2016-10-24 21:49 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-02-11 18:00 - 2016-10-24 21:49 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3ui.dll
2017-02-11 18:00 - 2016-10-24 21:48 - 00217600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2017-02-11 18:00 - 2016-10-24 21:48 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-02-11 18:00 - 2016-10-24 21:45 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2017-02-11 18:00 - 2016-10-24 21:45 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneOm.dll
2017-02-11 18:00 - 2016-10-24 21:44 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAnimation.dll
2017-02-11 18:00 - 2016-10-24 21:43 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\filemgmt.dll
2017-02-11 18:00 - 2016-10-24 21:42 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-02-11 18:00 - 2016-10-24 21:41 - 00499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2017-02-11 18:00 - 2016-10-24 21:39 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2017-02-11 18:00 - 2016-10-24 21:39 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certreq.exe
2017-02-11 18:00 - 2016-10-24 21:39 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-02-11 18:00 - 2016-10-24 21:37 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2017-02-11 18:00 - 2016-10-24 21:37 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll
2017-02-11 18:00 - 2016-10-24 21:37 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2017-02-11 18:00 - 2016-10-24 21:36 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2017-02-11 18:00 - 2016-10-24 21:36 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2017-02-11 18:00 - 2016-10-24 21:36 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2017-02-11 18:00 - 2016-10-24 21:36 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll
2017-02-11 18:00 - 2016-10-24 21:36 - 00413696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64