learninmypc
Posts: 9,789 +739
I've already cleaned some of it up, just need you to make sure its clean, thanks in advance 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-11-2017 02
Ran by Dell Vostro 1000 (administrator) on DELLVOSTRO1000 (06-11-2017 14:03:27)
Running from C:\Users\Dell Vostro 1000\Desktop
Loaded Profiles: Dell Vostro 1000 (Available Profiles: Dell Vostro 1000)
Platform: Microsoft Windows 7 Professional (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2009-12-22] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [948672 2009-12-11] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [253344 2017-11-05] (AVAST Software)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\...\Run: [Google Update] => C:\Users\Dell Vostro 1000\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-05-20] (Google Inc.)
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [7814656 2017-10-18] (Piriform Ltd)
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\...\MountPoints2: {21c6ee82-c26c-11e7-b911-0021707cadb6} - F:\LaunchU3.exe -a
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\...\MountPoints2: {8a8c2786-5fe6-11e2-bc1d-0021707cadb6} - F:\LaunchU3.exe -a
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2017-11-06] (Microsoft Corporation)
Startup: C:\Users\Dell Vostro 1000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013-08-19]
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
GroupPolicy: Restriction - Chrome <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{BBF3435B-C76A-42D1-852D-9A863CF9543F}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.com/?fr=fp-msgr
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yahoo.com/?fr=fp-msgr
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.iplay.com/?o=shp
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-2096075369-1562336306-3977701488-1000 -> DefaultScope {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://start.iplay.com/searchresults.aspx?o=chrome&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2096075369-1562336306-3977701488-1000 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://start.iplay.com/searchresults.aspx?o=chrome&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2096075369-1562336306-3977701488-1000 -> {84AF6053-CBF5-4E3D-B2DD-C09F693A207D} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr=chr-msgr
SearchScopes: HKU\S-1-5-21-2096075369-1562336306-3977701488-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={CB85FC95-1FC2-42A5-8B0F-3EEC10E93E9E}&mid=677ec3b8565747d09fa7d16836984445-0609466699721699054b6aae37a8f7d5486a672c&lang=en&ds=AVG&pr=fr&d=2013-01-16 18:37:52&v=15.5.0.2&pid=avg&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2096075369-1562336306-3977701488-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=mkg028
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21] (Adobe Systems Incorporated)
BHO: Iplay Gamesbar -> {7ffa5f54-1c4f-46de-8576-c271a0dd482f} -> C:\Program Files\iplay_en\encyclopediabritannicagamesbarX.dll => No File
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
Toolbar: HKLM - Iplay Gamesbar - {7ffa5f54-1c4f-46de-8576-c271a0dd482f} - C:\Program Files\iplay_en\encyclopediabritannicagamesbarX.dll No File
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll [2012-06-01] (Belarc, Inc.)
FireFox:
========
FF ProfilePath: C:\Users\Dell Vostro 1000\AppData\Roaming\Mozilla\Firefox\Profiles\ew85w4lr.default-1443471164890 [2017-11-06]
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\ew85w4lr.default-1443471164890 -> Google
FF NetworkProxy: Mozilla\Firefox\Profiles\ew85w4lr.default-1443471164890 -> type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-11-05] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1229199.dll [2017-03-30] (Adobe Systems, Inc.)
FF Plugin: @Oberon-media.com/ONCAdapter -> C:\Program Files\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll [2012-05-31] (Oberon-Media )
FF Plugin: @videolan.org/vlc,version=2.0.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin HKU\S-1-5-21-2096075369-1562336306-3977701488-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Dell Vostro 1000\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-20] (Google Inc.)
FF Plugin HKU\S-1-5-21-2096075369-1562336306-3977701488-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Dell Vostro 1000\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-20] (Google Inc.)
FF Plugin HKU\S-1-5-21-2096075369-1562336306-3977701488-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Dell Vostro 1000\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-01-26] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll [2010-01-15] (mozilla.org)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox-branding.js [2010-01-15]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox-l10n.js [2010-01-15]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox.js [2010-01-15]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\reporter.js [2010-01-15]
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR Profile: C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default [2017-11-06]
CHR Extension: (Slides) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-11-05]
CHR Extension: (Docs) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-05]
CHR Extension: (Google Drive) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-20]
CHR Extension: (Adguard AdBlocker) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2017-11-05]
CHR Extension: (YouTube) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Google Search) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Sheets) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-05]
CHR Extension: (Google Docs Offline) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23]
CHR Extension: (Gmail) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-05]
StartMenuInternet: Google Chrome.TYRE6KKZI4WAYA4S2SQAD7ADIA - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [143776 2017-01-30] (SUPERAntiSpyware.com)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5828816 2017-11-05] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416 2017-11-05] (AVAST Software)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4430792 2017-08-07] (Malwarebytes)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdriverx.sys [255624 2017-11-05] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidshx.sys [157416 2017-11-05] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswblogx.sys [276736 2017-11-05] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbunivx.sys [50384 2017-11-05] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [42856 2017-11-05] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [124952 2017-11-05] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [99560 2017-11-05] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [70864 2017-11-05] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [783648 2017-11-05] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [499560 2017-11-05] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [149824 2017-11-05] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [297840 2017-11-05] (AVAST Software)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [221112 2017-11-06] (Malwarebytes)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-06 14:03 - 2017-11-06 14:03 - 000012967 _____ C:\Users\Dell Vostro 1000\Desktop\FRST.txt
2017-11-06 10:38 - 2017-11-06 10:38 - 000000000 ____D C:\Windows\system32\SPReview
2017-11-06 10:37 - 2017-11-06 10:37 - 000000000 ____D C:\Windows\system32\EventProviders
2017-11-06 10:32 - 2017-11-06 14:03 - 000000000 ____D C:\FRST
2017-11-06 10:32 - 2017-11-06 10:32 - 001799680 _____ (Farbar) C:\Users\Dell Vostro 1000\Desktop\FRST.exe
2017-11-06 09:24 - 2017-11-06 09:24 - 002082630 _____ (J.C. Kessels ) C:\Users\Dell Vostro 1000\Desktop\MyDefrag-v431.exe
2017-11-05 18:26 - 2010-01-08 22:52 - 000132608 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2017-11-05 18:26 - 2009-12-28 22:55 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2017-11-05 18:20 - 2017-11-05 18:20 - 000000969 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-11-05 18:20 - 2017-11-05 18:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-11-05 18:20 - 2017-11-05 18:20 - 000000000 ____D C:\Program Files\CCleaner
2017-11-05 18:17 - 2017-11-05 18:17 - 000040924 __RSH C:\ProgramData\ntuser.pol
2017-11-05 18:16 - 2017-11-05 18:18 - 000000000 ____D C:\Program Files\SpywareBlaster
2017-11-05 18:16 - 2017-11-05 18:16 - 000001041 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2017-11-05 18:16 - 2017-11-05 18:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2017-11-05 18:16 - 2012-05-02 12:17 - 001070152 _____ (Microsoft Corporation) C:\Windows\system32\MSCOMCTL.OCX
2017-11-05 18:16 - 2009-03-24 13:52 - 000129872 _____ (Microsoft Corporation) C:\Windows\system32\MSSTDFMT.DLL
2017-11-05 18:11 - 2017-11-05 18:11 - 004291320 _____ (BrightFort LLC ) C:\Users\Dell Vostro 1000\Downloads\spywareblastersetup55.exe
2017-11-05 18:09 - 2017-11-05 18:10 - 010427120 _____ (Piriform Ltd) C:\Users\Dell Vostro 1000\Downloads\ccsetup536.exe
2017-11-05 15:19 - 2017-11-05 15:19 - 000001028 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-11-05 15:03 - 2017-11-05 15:03 - 000000000 ____D C:\Users\Dell Vostro 1000\AppData\Roaming\AVAST Software
2017-11-05 15:03 - 2017-11-05 15:03 - 000000000 ____D C:\Users\Dell Vostro 1000\AppData\Local\CEF
2017-11-05 15:02 - 2017-11-05 15:02 - 000783648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000499560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000297840 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000149824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000124952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000099560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000070864 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000042856 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000002079 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2017-11-05 15:02 - 2017-11-05 15:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2017-11-05 15:02 - 2017-11-05 15:01 - 000921280 _____ (Microsoft Corporation) C:\Windows\ucrtbase.dll
2017-11-05 15:02 - 2017-11-05 15:01 - 000304816 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-11-05 15:02 - 2017-11-05 15:01 - 000276736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswblogx.sys
2017-11-05 15:02 - 2017-11-05 15:01 - 000255624 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdriverx.sys
2017-11-05 15:02 - 2017-11-05 15:01 - 000157416 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidshx.sys
2017-11-05 15:02 - 2017-11-05 15:01 - 000050384 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbunivx.sys
2017-11-05 15:00 - 2017-11-05 15:00 - 000000000 ____D C:\Program Files\AVAST Software
2017-11-05 14:58 - 2017-11-05 15:59 - 000000000 ____D C:\ProgramData\AVAST Software
2017-11-05 14:39 - 2017-11-05 14:39 - 000000000 _____ C:\Windows\ativpsrm.bin
2017-11-05 14:32 - 2017-11-05 14:36 - 000000000 ____D C:\Windows\system32\MRT
2017-11-05 14:32 - 2017-11-05 14:32 - 124059592 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2017-11-05 14:31 - 2017-11-05 14:32 - 124059592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-11-05 14:31 - 2016-06-25 07:43 - 000301056 _____ (Microsoft Corporation) C:\Windows\system32\EOSNotify.exe
2017-11-05 14:31 - 2011-04-08 21:56 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2017-11-05 14:31 - 2010-12-17 21:29 - 000541184 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-11-05 14:31 - 2009-12-08 00:05 - 000310784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-11-05 14:30 - 2015-03-18 18:57 - 003963320 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2017-11-05 14:30 - 2015-03-18 18:57 - 003908024 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-11-05 14:30 - 2014-09-14 16:42 - 002377216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-11-05 14:30 - 2013-03-18 20:54 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-11-05 14:30 - 2013-03-18 18:50 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-11-05 14:30 - 2009-12-08 00:05 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-11-05 14:27 - 2012-06-02 15:19 - 000171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-11-05 14:27 - 2012-06-02 15:12 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-11-05 14:27 - 2012-06-02 14:19 - 001933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-11-05 14:27 - 2012-06-02 14:19 - 000577048 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-11-05 14:27 - 2012-06-02 14:19 - 000053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-11-05 14:27 - 2012-06-02 14:19 - 000045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-11-05 14:27 - 2012-06-02 14:19 - 000035864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-11-05 14:27 - 2012-06-02 14:12 - 002422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-11-05 14:27 - 2012-06-02 14:12 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-11-05 14:22 - 2017-11-05 16:53 - 000024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-11-05 14:22 - 2017-11-05 16:53 - 000001005 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-11-05 14:22 - 2017-11-05 16:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-11-05 14:22 - 2017-11-05 16:53 - 000000000 ____D C:\Program Files\RogueKiller
2017-11-05 14:22 - 2017-11-05 14:37 - 000000000 ____D C:\ProgramData\RogueKiller
2017-11-05 14:20 - 2017-11-06 13:49 - 000221112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2017-11-05 14:17 - 2017-11-05 14:19 - 000000000 ____D C:\AdwCleaner
2017-11-05 14:15 - 2017-11-05 14:15 - 000448512 _____ (OldTimer Tools) C:\Users\Dell Vostro 1000\Desktop\TFC.exe
2017-11-05 14:13 - 2017-11-05 14:13 - 008261584 _____ (Malwarebytes) C:\Users\Dell Vostro 1000\Desktop\AdwCleaner.exe
2017-11-05 13:52 - 2017-11-05 13:52 - 000166848 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-11-05 13:52 - 2017-11-05 13:52 - 000065824 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-11-05 13:52 - 2017-11-05 13:52 - 000040352 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-11-05 13:51 - 2017-11-05 14:19 - 000059904 _____ C:\Windows\system32\Drivers\mbae.sys
2017-11-05 13:51 - 2017-11-05 13:51 - 000002024 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-11-05 13:51 - 2017-11-05 13:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-11-05 13:51 - 2017-11-05 13:51 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-11-05 13:51 - 2017-11-05 13:51 - 000000000 ____D C:\Program Files\Malwarebytes
2017-11-05 13:21 - 2017-11-05 13:21 - 000000000 ____D C:\Users\Dell Vostro 1000\AppData\Roaming\SUPERAntiSpyware.com
2017-11-05 13:20 - 2017-11-05 13:21 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2017-11-05 13:20 - 2017-11-05 13:20 - 000001965 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2017-11-05 13:20 - 2017-11-05 13:20 - 000000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2017-11-05 13:20 - 2017-11-05 13:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-06 13:55 - 2009-07-13 20:34 - 000020512 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-11-06 13:55 - 2009-07-13 20:34 - 000020512 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-11-06 13:48 - 2009-07-13 20:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-11-06 10:30 - 2013-01-16 06:16 - 000713888 _____ C:\Windows\system32\PerfStringBackup.INI
2017-11-06 10:30 - 2009-07-13 18:37 - 000000000 ____D C:\Windows\inf
2017-11-05 18:22 - 2013-01-16 06:01 - 000000000 ____D C:\Windows\Panther
2017-11-05 18:18 - 2015-12-18 05:27 - 000000000 ____D C:\ProgramData\TEMP
2017-11-05 18:16 - 2009-07-13 18:37 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2017-11-05 16:43 - 2015-01-18 21:03 - 000000000 ____D C:\ProgramData\Yahoo!
2017-11-05 16:43 - 2015-01-18 21:00 - 000000000 ____D C:\Program Files\Yahoo!
2017-11-05 15:19 - 2014-08-21 07:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-11-05 15:18 - 2015-01-18 21:04 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-11-05 15:18 - 2013-01-16 18:24 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-11-05 15:18 - 2013-01-16 18:24 - 000000000 ____D C:\Windows\system32\Macromed
2017-11-05 15:18 - 2013-01-16 18:24 - 000000000 ____D C:\Program Files\Mozilla Firefox
2017-11-05 15:11 - 2013-01-16 18:25 - 000000000 ____D C:\Program Files\Common Files\Adobe AIR
2017-11-05 15:10 - 2013-01-16 18:24 - 000000000 ____D C:\Windows\system32\Adobe
2017-11-05 14:50 - 2009-07-13 18:37 - 000000000 ____D C:\Windows\system32\NDF
2017-11-05 14:39 - 2009-07-13 20:33 - 000292176 _____ C:\Windows\system32\FNTCACHE.DAT
2017-11-05 14:19 - 2015-01-18 21:04 - 000000000 ____D C:\Users\Dell Vostro 1000\AppData\Roaming\Yahoo!
2017-11-05 14:19 - 2015-01-18 21:04 - 000000000 ____D C:\Users\Dell Vostro 1000\AppData\LocalLow\Yahoo!
2017-11-05 13:15 - 2015-01-03 17:54 - 000002393 _____ C:\Users\Dell Vostro 1000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
Some files in TEMP:
====================
2017-11-05 16:53 - 2009-07-13 17:17 - 001286144 _____ (Microsoft Corporation) C:\Users\Dell Vostro 1000\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-09-21 15:11
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-11-2017 02
Ran by Dell Vostro 1000 (administrator) on DELLVOSTRO1000 (06-11-2017 14:03:27)
Running from C:\Users\Dell Vostro 1000\Desktop
Loaded Profiles: Dell Vostro 1000 (Available Profiles: Dell Vostro 1000)
Platform: Microsoft Windows 7 Professional (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2009-12-22] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [948672 2009-12-11] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [253344 2017-11-05] (AVAST Software)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\...\Run: [Google Update] => C:\Users\Dell Vostro 1000\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-05-20] (Google Inc.)
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [7814656 2017-10-18] (Piriform Ltd)
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\...\MountPoints2: {21c6ee82-c26c-11e7-b911-0021707cadb6} - F:\LaunchU3.exe -a
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\...\MountPoints2: {8a8c2786-5fe6-11e2-bc1d-0021707cadb6} - F:\LaunchU3.exe -a
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2017-11-06] (Microsoft Corporation)
Startup: C:\Users\Dell Vostro 1000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013-08-19]
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
GroupPolicy: Restriction - Chrome <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{BBF3435B-C76A-42D1-852D-9A863CF9543F}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.com/?fr=fp-msgr
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yahoo.com/?fr=fp-msgr
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.iplay.com/?o=shp
HKU\S-1-5-21-2096075369-1562336306-3977701488-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-2096075369-1562336306-3977701488-1000 -> DefaultScope {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://start.iplay.com/searchresults.aspx?o=chrome&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2096075369-1562336306-3977701488-1000 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://start.iplay.com/searchresults.aspx?o=chrome&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2096075369-1562336306-3977701488-1000 -> {84AF6053-CBF5-4E3D-B2DD-C09F693A207D} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr=chr-msgr
SearchScopes: HKU\S-1-5-21-2096075369-1562336306-3977701488-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={CB85FC95-1FC2-42A5-8B0F-3EEC10E93E9E}&mid=677ec3b8565747d09fa7d16836984445-0609466699721699054b6aae37a8f7d5486a672c&lang=en&ds=AVG&pr=fr&d=2013-01-16 18:37:52&v=15.5.0.2&pid=avg&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2096075369-1562336306-3977701488-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=mkg028
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21] (Adobe Systems Incorporated)
BHO: Iplay Gamesbar -> {7ffa5f54-1c4f-46de-8576-c271a0dd482f} -> C:\Program Files\iplay_en\encyclopediabritannicagamesbarX.dll => No File
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
Toolbar: HKLM - Iplay Gamesbar - {7ffa5f54-1c4f-46de-8576-c271a0dd482f} - C:\Program Files\iplay_en\encyclopediabritannicagamesbarX.dll No File
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll [2012-06-01] (Belarc, Inc.)
FireFox:
========
FF ProfilePath: C:\Users\Dell Vostro 1000\AppData\Roaming\Mozilla\Firefox\Profiles\ew85w4lr.default-1443471164890 [2017-11-06]
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\ew85w4lr.default-1443471164890 -> Google
FF NetworkProxy: Mozilla\Firefox\Profiles\ew85w4lr.default-1443471164890 -> type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-11-05] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1229199.dll [2017-03-30] (Adobe Systems, Inc.)
FF Plugin: @Oberon-media.com/ONCAdapter -> C:\Program Files\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll [2012-05-31] (Oberon-Media )
FF Plugin: @videolan.org/vlc,version=2.0.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin HKU\S-1-5-21-2096075369-1562336306-3977701488-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Dell Vostro 1000\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-20] (Google Inc.)
FF Plugin HKU\S-1-5-21-2096075369-1562336306-3977701488-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Dell Vostro 1000\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-20] (Google Inc.)
FF Plugin HKU\S-1-5-21-2096075369-1562336306-3977701488-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Dell Vostro 1000\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-01-26] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npnul32.dll [2010-01-15] (mozilla.org)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox-branding.js [2010-01-15]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox-l10n.js [2010-01-15]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\firefox.js [2010-01-15]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\reporter.js [2010-01-15]
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR Profile: C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default [2017-11-06]
CHR Extension: (Slides) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-11-05]
CHR Extension: (Docs) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-05]
CHR Extension: (Google Drive) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-20]
CHR Extension: (Adguard AdBlocker) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2017-11-05]
CHR Extension: (YouTube) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Google Search) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Sheets) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-05]
CHR Extension: (Google Docs Offline) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23]
CHR Extension: (Gmail) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-05]
StartMenuInternet: Google Chrome.TYRE6KKZI4WAYA4S2SQAD7ADIA - C:\Users\Dell Vostro 1000\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [143776 2017-01-30] (SUPERAntiSpyware.com)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5828816 2017-11-05] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416 2017-11-05] (AVAST Software)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4430792 2017-08-07] (Malwarebytes)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdriverx.sys [255624 2017-11-05] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidshx.sys [157416 2017-11-05] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswblogx.sys [276736 2017-11-05] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbunivx.sys [50384 2017-11-05] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [42856 2017-11-05] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [124952 2017-11-05] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [99560 2017-11-05] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [70864 2017-11-05] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [783648 2017-11-05] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [499560 2017-11-05] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [149824 2017-11-05] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [297840 2017-11-05] (AVAST Software)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [221112 2017-11-06] (Malwarebytes)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-06 14:03 - 2017-11-06 14:03 - 000012967 _____ C:\Users\Dell Vostro 1000\Desktop\FRST.txt
2017-11-06 10:38 - 2017-11-06 10:38 - 000000000 ____D C:\Windows\system32\SPReview
2017-11-06 10:37 - 2017-11-06 10:37 - 000000000 ____D C:\Windows\system32\EventProviders
2017-11-06 10:32 - 2017-11-06 14:03 - 000000000 ____D C:\FRST
2017-11-06 10:32 - 2017-11-06 10:32 - 001799680 _____ (Farbar) C:\Users\Dell Vostro 1000\Desktop\FRST.exe
2017-11-06 09:24 - 2017-11-06 09:24 - 002082630 _____ (J.C. Kessels ) C:\Users\Dell Vostro 1000\Desktop\MyDefrag-v431.exe
2017-11-05 18:26 - 2010-01-08 22:52 - 000132608 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2017-11-05 18:26 - 2009-12-28 22:55 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2017-11-05 18:20 - 2017-11-05 18:20 - 000000969 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-11-05 18:20 - 2017-11-05 18:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-11-05 18:20 - 2017-11-05 18:20 - 000000000 ____D C:\Program Files\CCleaner
2017-11-05 18:17 - 2017-11-05 18:17 - 000040924 __RSH C:\ProgramData\ntuser.pol
2017-11-05 18:16 - 2017-11-05 18:18 - 000000000 ____D C:\Program Files\SpywareBlaster
2017-11-05 18:16 - 2017-11-05 18:16 - 000001041 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2017-11-05 18:16 - 2017-11-05 18:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2017-11-05 18:16 - 2012-05-02 12:17 - 001070152 _____ (Microsoft Corporation) C:\Windows\system32\MSCOMCTL.OCX
2017-11-05 18:16 - 2009-03-24 13:52 - 000129872 _____ (Microsoft Corporation) C:\Windows\system32\MSSTDFMT.DLL
2017-11-05 18:11 - 2017-11-05 18:11 - 004291320 _____ (BrightFort LLC ) C:\Users\Dell Vostro 1000\Downloads\spywareblastersetup55.exe
2017-11-05 18:09 - 2017-11-05 18:10 - 010427120 _____ (Piriform Ltd) C:\Users\Dell Vostro 1000\Downloads\ccsetup536.exe
2017-11-05 15:19 - 2017-11-05 15:19 - 000001028 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-11-05 15:03 - 2017-11-05 15:03 - 000000000 ____D C:\Users\Dell Vostro 1000\AppData\Roaming\AVAST Software
2017-11-05 15:03 - 2017-11-05 15:03 - 000000000 ____D C:\Users\Dell Vostro 1000\AppData\Local\CEF
2017-11-05 15:02 - 2017-11-05 15:02 - 000783648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000499560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000297840 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000149824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000124952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000099560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000070864 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000042856 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-11-05 15:02 - 2017-11-05 15:02 - 000002079 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2017-11-05 15:02 - 2017-11-05 15:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2017-11-05 15:02 - 2017-11-05 15:01 - 000921280 _____ (Microsoft Corporation) C:\Windows\ucrtbase.dll
2017-11-05 15:02 - 2017-11-05 15:01 - 000304816 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-11-05 15:02 - 2017-11-05 15:01 - 000276736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswblogx.sys
2017-11-05 15:02 - 2017-11-05 15:01 - 000255624 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdriverx.sys
2017-11-05 15:02 - 2017-11-05 15:01 - 000157416 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidshx.sys
2017-11-05 15:02 - 2017-11-05 15:01 - 000050384 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbunivx.sys
2017-11-05 15:00 - 2017-11-05 15:00 - 000000000 ____D C:\Program Files\AVAST Software
2017-11-05 14:58 - 2017-11-05 15:59 - 000000000 ____D C:\ProgramData\AVAST Software
2017-11-05 14:39 - 2017-11-05 14:39 - 000000000 _____ C:\Windows\ativpsrm.bin
2017-11-05 14:32 - 2017-11-05 14:36 - 000000000 ____D C:\Windows\system32\MRT
2017-11-05 14:32 - 2017-11-05 14:32 - 124059592 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2017-11-05 14:31 - 2017-11-05 14:32 - 124059592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-11-05 14:31 - 2016-06-25 07:43 - 000301056 _____ (Microsoft Corporation) C:\Windows\system32\EOSNotify.exe
2017-11-05 14:31 - 2011-04-08 21:56 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2017-11-05 14:31 - 2010-12-17 21:29 - 000541184 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-11-05 14:31 - 2009-12-08 00:05 - 000310784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-11-05 14:30 - 2015-03-18 18:57 - 003963320 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2017-11-05 14:30 - 2015-03-18 18:57 - 003908024 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-11-05 14:30 - 2014-09-14 16:42 - 002377216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-11-05 14:30 - 2013-03-18 20:54 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-11-05 14:30 - 2013-03-18 18:50 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-11-05 14:30 - 2009-12-08 00:05 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-11-05 14:27 - 2012-06-02 15:19 - 000171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-11-05 14:27 - 2012-06-02 15:12 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-11-05 14:27 - 2012-06-02 14:19 - 001933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-11-05 14:27 - 2012-06-02 14:19 - 000577048 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-11-05 14:27 - 2012-06-02 14:19 - 000053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-11-05 14:27 - 2012-06-02 14:19 - 000045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-11-05 14:27 - 2012-06-02 14:19 - 000035864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-11-05 14:27 - 2012-06-02 14:12 - 002422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-11-05 14:27 - 2012-06-02 14:12 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-11-05 14:22 - 2017-11-05 16:53 - 000024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-11-05 14:22 - 2017-11-05 16:53 - 000001005 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-11-05 14:22 - 2017-11-05 16:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-11-05 14:22 - 2017-11-05 16:53 - 000000000 ____D C:\Program Files\RogueKiller
2017-11-05 14:22 - 2017-11-05 14:37 - 000000000 ____D C:\ProgramData\RogueKiller
2017-11-05 14:20 - 2017-11-06 13:49 - 000221112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2017-11-05 14:17 - 2017-11-05 14:19 - 000000000 ____D C:\AdwCleaner
2017-11-05 14:15 - 2017-11-05 14:15 - 000448512 _____ (OldTimer Tools) C:\Users\Dell Vostro 1000\Desktop\TFC.exe
2017-11-05 14:13 - 2017-11-05 14:13 - 008261584 _____ (Malwarebytes) C:\Users\Dell Vostro 1000\Desktop\AdwCleaner.exe
2017-11-05 13:52 - 2017-11-05 13:52 - 000166848 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-11-05 13:52 - 2017-11-05 13:52 - 000065824 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-11-05 13:52 - 2017-11-05 13:52 - 000040352 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-11-05 13:51 - 2017-11-05 14:19 - 000059904 _____ C:\Windows\system32\Drivers\mbae.sys
2017-11-05 13:51 - 2017-11-05 13:51 - 000002024 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-11-05 13:51 - 2017-11-05 13:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-11-05 13:51 - 2017-11-05 13:51 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-11-05 13:51 - 2017-11-05 13:51 - 000000000 ____D C:\Program Files\Malwarebytes
2017-11-05 13:21 - 2017-11-05 13:21 - 000000000 ____D C:\Users\Dell Vostro 1000\AppData\Roaming\SUPERAntiSpyware.com
2017-11-05 13:20 - 2017-11-05 13:21 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2017-11-05 13:20 - 2017-11-05 13:20 - 000001965 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2017-11-05 13:20 - 2017-11-05 13:20 - 000000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2017-11-05 13:20 - 2017-11-05 13:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-06 13:55 - 2009-07-13 20:34 - 000020512 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-11-06 13:55 - 2009-07-13 20:34 - 000020512 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-11-06 13:48 - 2009-07-13 20:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-11-06 10:30 - 2013-01-16 06:16 - 000713888 _____ C:\Windows\system32\PerfStringBackup.INI
2017-11-06 10:30 - 2009-07-13 18:37 - 000000000 ____D C:\Windows\inf
2017-11-05 18:22 - 2013-01-16 06:01 - 000000000 ____D C:\Windows\Panther
2017-11-05 18:18 - 2015-12-18 05:27 - 000000000 ____D C:\ProgramData\TEMP
2017-11-05 18:16 - 2009-07-13 18:37 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2017-11-05 16:43 - 2015-01-18 21:03 - 000000000 ____D C:\ProgramData\Yahoo!
2017-11-05 16:43 - 2015-01-18 21:00 - 000000000 ____D C:\Program Files\Yahoo!
2017-11-05 15:19 - 2014-08-21 07:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-11-05 15:18 - 2015-01-18 21:04 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-11-05 15:18 - 2013-01-16 18:24 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-11-05 15:18 - 2013-01-16 18:24 - 000000000 ____D C:\Windows\system32\Macromed
2017-11-05 15:18 - 2013-01-16 18:24 - 000000000 ____D C:\Program Files\Mozilla Firefox
2017-11-05 15:11 - 2013-01-16 18:25 - 000000000 ____D C:\Program Files\Common Files\Adobe AIR
2017-11-05 15:10 - 2013-01-16 18:24 - 000000000 ____D C:\Windows\system32\Adobe
2017-11-05 14:50 - 2009-07-13 18:37 - 000000000 ____D C:\Windows\system32\NDF
2017-11-05 14:39 - 2009-07-13 20:33 - 000292176 _____ C:\Windows\system32\FNTCACHE.DAT
2017-11-05 14:19 - 2015-01-18 21:04 - 000000000 ____D C:\Users\Dell Vostro 1000\AppData\Roaming\Yahoo!
2017-11-05 14:19 - 2015-01-18 21:04 - 000000000 ____D C:\Users\Dell Vostro 1000\AppData\LocalLow\Yahoo!
2017-11-05 13:15 - 2015-01-03 17:54 - 000002393 _____ C:\Users\Dell Vostro 1000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
Some files in TEMP:
====================
2017-11-05 16:53 - 2009-07-13 17:17 - 001286144 _____ (Microsoft Corporation) C:\Users\Dell Vostro 1000\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-09-21 15:11
==================== End of FRST.txt ============================