Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-03-2017 01
Ran by songe_000 (administrator) on MOMSPC (11-03-2017 18:46:08)
Running from C:\Users\songe_000\Downloads
Loaded Profiles: songe_000 (Available Profiles: songe_000)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Soluto) C:\Program Files\Soluto\SolutoLauncherService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Touch Tools\TouchToolsLaunchSvc.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.7967.57501.0_x64__8wekyb3d8bbwe\onenoteim.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-18] (Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2017-01-22] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [909744 2017-03-02] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [DoroServer] => C:\Program Files (x86)\DoroPDFWriter\DoroServer.exe [204800 2014-12-19] (CompSoft)
HKLM-x32\...\Run: [abDocsDllLoader] => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe [91488 2016-08-15] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-11-18] (Apple Inc.)
HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [1667072 2012-02-28] (AimerSoft)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [61896 2016-12-29] (Avira Operations GmbH & Co. KG)
HKLM\...\Winlogon: [Userinit] c:\windows\system32\userinit.exe,c:\program files\soluto\soluto.exe /userinit
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
HKU\S-1-5-21-634217685-3676121620-3412417090-1001\...\Run: [Spotify Web Helper] => C:\Users\songe_000\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2016-12-21] (Spotify Ltd)
HKU\S-1-5-21-634217685-3676121620-3412417090-1001\...\Run: [AviraSpeedup] => C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe [7611640 2014-12-11] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-634217685-3676121620-3412417090-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7946144 2017-02-23] (SUPERAntiSpyware)
HKU\S-1-5-21-634217685-3676121620-3412417090-1001\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-634217685-3676121620-3412417090-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-01-22] (Apple Inc.)
HKU\S-1-5-21-634217685-3676121620-3412417090-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2017-01-22] (Apple Inc.)
HKU\S-1-5-21-634217685-3676121620-3412417090-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Ribbons.scr [151040 2016-07-16] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-09-08] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-09-08] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2016-09-08] (Acer Incorporated)
ShellIconOverlayIdentifiers-x32: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll [2016-09-08] (Acer Incorporated)
ShellIconOverlayIdentifiers-x32: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll [2016-09-08] (Acer Incorporated)
ShellIconOverlayIdentifiers-x32: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\Win32\shellext_win.dll [2016-09-08] (Acer Incorporated)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.3.25
Tcpip\..\Interfaces\{35e41c0f-2342-4fb7-ac06-ae79d8dbcf9b}: [NameServer] 156.154.70.22,156.154.71.22
Tcpip\..\Interfaces\{dee13008-c737-4ac5-9444-f2960207d42f}: [NameServer] 156.154.70.22,156.154.71.22
Tcpip\..\Interfaces\{dee13008-c737-4ac5-9444-f2960207d42f}: [DhcpNameServer] 192.168.0.1 205.171.3.25
Internet Explorer:
==================
HKU\S-1-5-21-634217685-3676121620-3412417090-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-01-29] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-01-29] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-01-29] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\songe_000\AppData\Roaming\Mozilla\Firefox\Profiles\2lsg6gue.default [2017-03-08]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\2lsg6gue.default -> Google
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\2lsg6gue.default -> Google
FF Keyword.URL: Mozilla\Firefox\Profiles\2lsg6gue.default -> hxxps://search.yahoo.com/search?fr=mcafee&type=B110US662D20141022&p=
FF Extension: (Avira Browser Safety) - C:\Users\songe_000\AppData\Roaming\Mozilla\Firefox\Profiles\2lsg6gue.default\Extensions\abs@avira.com.xpi [2016-12-09]
FF Extension: (WOT) - C:\Users\songe_000\AppData\Roaming\Mozilla\Firefox\Profiles\2lsg6gue.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2015-12-11]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2015-01-04]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-23] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-23] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-09] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-09] (Intel Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-01-29] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-21] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-07-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-634217685-3676121620-3412417090-1001: @citrixonline.com/appdetectorplugin -> C:\Users\songe_000\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-05-11] (Citrix Online)
FF Plugin HKU\S-1-5-21-634217685-3676121620-3412417090-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\songe_000\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-07-03] (Unity Technologies ApS)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default [2017-03-11]
CHR Extension: (Google Slides) - C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-07]
CHR Extension: (Google Docs) - C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-07]
CHR Extension: (Google Drive) - C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-26]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2017-03-09]
CHR Extension: (YouTube) - C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29]
CHR Extension: (Google Search) - C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Google Sheets) - C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-07]
CHR Extension: (Google Docs Offline) - C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
CHR Extension: (Gmail) - C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\songe_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-07]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-02-23] (SUPERAntiSpyware.com)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [1115552 2017-03-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [487424 2017-03-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [487424 2017-03-02] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1519144 2017-03-02] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-11-03] (Apple Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [372272 2016-12-29] (Avira Operations GmbH & Co. KG)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2267352 2016-09-20] (Acer Incorporated)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3704520 2017-03-07] (Microsoft Corporation)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5817256 2016-09-28] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2271928 2016-09-28] (COMODO)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573544 2014-03-21] (Acer Incorporated)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-06-30] (Hewlett-Packard Company)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [370064 2015-11-29] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-09] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [459496 2014-03-17] (Acer Incorporate)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [457960 2014-03-21] (Acer Incorporate)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()
R2 SolutoLauncherService; C:\Program Files\Soluto\SolutoLauncherService.exe [221728 2013-12-18] (Soluto)
S3 SolutoRemoteService; C:\Program Files\Soluto\SolutoRemoteService.exe [1942016 2013-12-18] (GlavSoft LLC.) [File not signed]
R2 TouchToolsLaunchService; C:\Program Files\Acer\Acer Touch Tools\TouchToolsLaunchSvc.exe [250624 2014-01-08] (Acer Incorporated)
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [222952 2014-01-24] (acer)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [161824 2017-03-02] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [163976 2017-03-02] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [44488 2017-03-02] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [88488 2017-03-02] (Avira Operations GmbH & Co. KG)
R1 cmderd; C:\WINDOWS\System32\DRIVERS\cmderd.sys [40960 2016-09-08] (COMODO)
R1 cmdGuard; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [862648 2016-09-08] (COMODO)
R1 cmdHlp; C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [54336 2016-09-08] (COMODO)
R3 cpuz136; C:\WINDOWS\TEMP\cpuz136\cpuz136_x64.sys [23856 2016-09-20] (CPUID)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-10-12] (Samsung Electronics Co., Ltd.)
R1 inspect; C:\WINDOWS\system32\DRIVERS\inspect.sys [147304 2016-09-08] (COMODO)
R3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-09] (Intel Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-07-22] (Realtek )
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [761600 2015-06-24] (Realsil Semiconductor Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 SynRMIHID; C:\WINDOWS\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-19] (Synaptics Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation)
R3 WsAudio_Device(1); C:\WINDOWS\system32\drivers\VirtualAudio1.sys [31080 2016-05-16] (Wondershare)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-11 18:44 - 2017-03-11 18:44 - 00000000 ____D C:\Users\songe_000\Downloads\FRST-OlderVersion
2017-03-10 01:29 - 2017-03-10 01:29 - 00000892 _____ C:\Users\songe_000\Desktop\JRT.txt
2017-03-10 01:10 - 2017-03-10 01:11 - 01663736 _____ (Malwarebytes) C:\Users\songe_000\Downloads\JRT.exe
2017-03-10 00:45 - 2017-03-10 00:45 - 04031440 _____ C:\Users\songe_000\Downloads\AdwCleaner.exe
2017-03-10 00:36 - 2017-03-10 00:36 - 00000233 _____ C:\mbam.txt
2017-03-09 20:15 - 2017-03-09 22:15 - 00000000 ____D C:\Program Files\RogueKiller
2017-03-09 20:15 - 2017-03-09 20:15 - 00000903 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-03-09 20:15 - 2017-03-09 20:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-03-09 20:09 - 2017-03-09 20:14 - 34885984 _____ (Adlice Software ) C:\Users\songe_000\Downloads\setup.exe
2017-03-09 13:06 - 2017-03-11 18:48 - 00021641 _____ C:\Users\songe_000\Downloads\FRST.txt
2017-03-09 13:04 - 2017-03-11 18:44 - 02424320 _____ (Farbar) C:\Users\songe_000\Downloads\FRST64.exe
2017-03-08 15:14 - 2017-03-09 03:39 - 00000000 ____D C:\Users\songe_000\AppData\Roaming\tor
2017-03-08 15:14 - 2017-03-08 15:14 - 02967040 _____ C:\Users\songe_000\AppData\Roaming\tor.exe
2017-03-08 15:14 - 2017-03-08 15:14 - 01990144 _____ (The OpenSSL Project, hxxp://
www.openssl.org/) C:\Users\songe_000\AppData\Roaming\libeay32.dll
2017-03-08 15:14 - 2017-03-08 15:14 - 00719217 _____ C:\Users\songe_000\AppData\Roaming\libevent-2-0-5.dll
2017-03-08 15:14 - 2017-03-08 15:14 - 00523262 _____ C:\Users\songe_000\AppData\Roaming\libgcc_s_sjlj-1.dll
2017-03-08 15:14 - 2017-03-08 15:14 - 00400384 _____ (The OpenSSL Project, hxxp://
www.openssl.org/) C:\Users\songe_000\AppData\Roaming\ssleay32.dll
2017-03-08 15:14 - 2017-03-08 15:14 - 00107520 _____ C:\Users\songe_000\AppData\Roaming\zlib1.dll
2017-03-08 15:14 - 2017-03-08 15:14 - 00092599 _____ C:\Users\songe_000\AppData\Roaming\libssp-0.dll
2017-03-08 15:13 - 2017-03-08 22:48 - 00000000 ____D C:\Users\songe_000\AppData\Roaming\Zeort
2017-03-08 15:13 - 2017-03-08 15:13 - 00000000 ____D C:\Users\songe_000\AppData\Roaming\Ozam
2017-03-08 15:13 - 2017-03-08 15:13 - 00000000 ____D C:\Users\songe_000\AppData\Roaming\Olpu
2017-03-08 15:13 - 2017-03-08 15:13 - 00000000 ____D C:\Users\songe_000\AppData\Roaming\Irocd
2017-03-07 14:13 - 2017-03-07 14:13 - 00065134 _____ C:\Users\songe_000\Documents\RebekahBlum.pdf
2017-03-06 22:07 - 2017-03-07 13:33 - 00065331 _____ C:\Users\songe_000\Documents\KadnWhaley.pdf
2017-02-28 22:38 - 2017-02-28 22:38 - 00064236 _____ C:\Users\songe_000\Documents\SydneyWeese.pdf
2017-02-28 11:23 - 2017-02-28 11:23 - 00454522 _____ C:\Users\songe_000\Downloads\esca.pdf
2017-02-23 20:46 - 2017-02-23 20:46 - 00024314 _____ C:\Users\songe_000\Downloads\COD18_1958399_08032016.pdf
2017-02-19 20:07 - 2017-02-19 20:07 - 11442275 _____ C:\Users\songe_000\Downloads\broken-way-printables-simple.pdf
2017-02-19 20:05 - 2017-02-19 20:06 - 17060235 _____ C:\Users\songe_000\Downloads\broken-way-printables-decorative-version.pdf
2017-02-13 18:43 - 2017-02-13 18:43 - 00026443 _____ C:\Users\songe_000\Downloads\STEPS TO BECOME A CONSULTANT-4.pdf
2017-02-13 17:44 - 2017-02-13 17:44 - 00231591 _____ C:\Users\songe_000\Downloads\How-Long-to-Pay-Back-My-Initial-Investment.pdf
2017-02-13 17:42 - 2017-02-13 17:42 - 00026977 _____ C:\Users\songe_000\Downloads\LulaRoe_FAQ.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-11 18:46 - 2015-06-22 23:59 - 00000000 ____D C:\FRST
2017-03-10 21:56 - 2016-07-16 04:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-10 21:56 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-10 21:49 - 2016-09-20 14:17 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-10 01:02 - 2016-09-20 14:20 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-03-10 01:02 - 2014-10-22 20:58 - 00000000 __SHD C:\Users\songe_000\IntelGraphicsProfiles
2017-03-10 01:01 - 2016-09-20 17:54 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-10 01:00 - 2016-07-15 23:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-03-10 00:58 - 2015-02-22 13:23 - 00000000 ____D C:\AdwCleaner
2017-03-10 00:34 - 2015-02-02 21:21 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-03-10 00:23 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-03-09 22:52 - 2016-05-11 15:55 - 00000696 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-634217685-3676121620-3412417090-1001.job
2017-03-09 22:52 - 2016-05-11 15:55 - 00000600 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-634217685-3676121620-3412417090-1001.job
2017-03-09 22:17 - 2015-02-03 21:24 - 00000000 ____D C:\ProgramData\RogueKiller
2017-03-09 22:02 - 2016-07-16 04:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-09 20:18 - 2015-02-03 21:24 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2017-03-09 19:47 - 2014-07-31 03:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon 1Button App
2017-03-09 13:21 - 2015-06-23 00:05 - 00181876 _____ C:\Users\songe_000\Downloads\Addition.txt
2017-03-09 09:30 - 2016-07-16 04:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-03-09 09:25 - 2014-07-31 03:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-03-09 09:05 - 2015-02-03 22:27 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-03-09 03:40 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-03-08 22:37 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\Branding
2017-03-08 22:37 - 2014-07-31 03:20 - 00000000 ____D C:\Program Files (x86)\Amazon
2017-03-08 15:10 - 2014-10-22 20:58 - 00000000 ____D C:\Users\songe_000\AppData\Local\Packages
2017-03-02 16:27 - 2016-07-26 10:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2017-03-02 16:25 - 2014-10-25 16:52 - 00163976 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2017-03-02 16:25 - 2014-10-25 16:52 - 00161824 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2017-03-02 16:25 - 2014-10-25 16:52 - 00088488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2017-03-02 16:25 - 2014-10-25 16:52 - 00044488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2017-03-02 16:24 - 2016-10-11 20:44 - 00048584 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys
2017-02-23 19:18 - 2014-10-25 15:29 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-23 17:02 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-02-23 17:02 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-23 17:01 - 2017-01-10 20:16 - 20359768 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2017-02-23 14:39 - 2016-07-16 04:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-02-23 14:39 - 2016-07-16 04:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-02-23 14:39 - 2016-07-16 04:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-23 14:38 - 2014-10-25 18:59 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-23 14:35 - 2014-10-25 18:59 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-23 14:02 - 2015-06-09 17:43 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-23 13:43 - 2014-11-09 13:57 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2017-02-19 17:43 - 2016-09-20 14:25 - 00000000 ____D C:\Users\songe_000
2017-02-17 22:23 - 2016-12-06 09:55 - 00003280 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-02-17 22:23 - 2015-11-30 01:22 - 00002415 _____ C:\Users\songe_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-02-17 22:23 - 2014-10-22 21:01 - 00000000 __RDO C:\Users\songe_000\OneDrive
2017-02-14 21:51 - 2017-01-18 23:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-02-14 21:51 - 2014-10-23 14:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-02-13 14:01 - 2016-02-09 15:32 - 00066025 _____ C:\Users\songe_000\Documents\JustinSonger.pdf
==================== Files in the root of some directories =======
2017-03-08 15:14 - 2017-03-08 15:14 - 1990144 _____ (The OpenSSL Project,
http://www.openssl.org/) C:\Users\songe_000\AppData\Roaming\libeay32.dll
2017-03-08 15:14 - 2017-03-08 15:14 - 0719217 _____ () C:\Users\songe_000\AppData\Roaming\libevent-2-0-5.dll
2017-03-08 15:14 - 2017-03-08 15:14 - 0523262 _____ () C:\Users\songe_000\AppData\Roaming\libgcc_s_sjlj-1.dll
2017-03-08 15:14 - 2017-03-08 15:14 - 0092599 _____ () C:\Users\songe_000\AppData\Roaming\libssp-0.dll
2017-03-08 15:14 - 2017-03-08 15:14 - 0400384 _____ (The OpenSSL Project,
http://www.openssl.org/) C:\Users\songe_000\AppData\Roaming\ssleay32.dll
2017-03-08 15:14 - 2017-03-08 15:14 - 2967040 _____ () C:\Users\songe_000\AppData\Roaming\tor.exe
2017-03-08 15:14 - 2017-03-08 15:14 - 0107520 _____ () C:\Users\songe_000\AppData\Roaming\zlib1.dll
2015-07-26 22:24 - 2015-07-26 22:24 - 0003463 _____ () C:\Users\songe_000\AppData\Local\ZedgeLog.txt
2015-02-12 14:54 - 2015-02-12 14:54 - 0000000 _____ () C:\Users\songe_000\AppData\Local\{57E7CF6A-D32F-4B89-AC9B-E9DF5CA836F1}
2016-09-20 14:20 - 2016-09-20 14:20 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-02-09 22:34 - 2015-02-09 22:34 - 0000098 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2016-09-20 19:43 - 2016-09-20 19:43 - 0000028 _____ () C:\ProgramData\pintext.txt
Some files in TEMP:
====================
2016-09-20 19:47 - 2016-09-20 19:47 - 0000000 ____D () C:\Users\songe_000\AppData\Local\Temp\avgnt.exe
2017-03-08 15:20 - 2017-03-08 15:20 - 0103936 _____ () C:\Users\songe_000\AppData\Local\Temp\certutil.exe
2017-03-09 20:16 - 2016-12-12 17:11 - 1886344 _____ (Microsoft Corporation) C:\Users\songe_000\AppData\Local\Temp\dllnt_dump.dll
2017-03-08 15:20 - 2017-03-08 15:21 - 0222208 _____ (Mozilla Foundation) C:\Users\songe_000\AppData\Local\Temp\freebl3.dll
2017-03-08 15:20 - 2017-03-08 15:21 - 0199680 _____ (Mozilla Foundation) C:\Users\songe_000\AppData\Local\Temp\libnspr4.dll
2017-03-08 15:20 - 2017-03-08 15:21 - 0014336 _____ (Mozilla Foundation) C:\Users\songe_000\AppData\Local\Temp\libplc4.dll
2017-03-08 15:20 - 2017-03-08 15:21 - 0012288 _____ (Mozilla Foundation) C:\Users\songe_000\AppData\Local\Temp\libplds4.dll
2017-03-08 15:20 - 2017-03-08 15:21 - 0773968 _____ (Microsoft Corporation) C:\Users\songe_000\AppData\Local\Temp\msvcr100.dll
2017-03-08 15:20 - 2017-03-08 15:20 - 0798720 _____ (Mozilla Foundation) C:\Users\songe_000\AppData\Local\Temp\nss3.dll
2017-03-08 15:20 - 2017-03-08 15:21 - 0108544 _____ (Mozilla Foundation) C:\Users\songe_000\AppData\Local\Temp\nssdbm3.dll
2017-03-08 15:20 - 2017-03-08 15:20 - 0093696 _____ (Mozilla Foundation) C:\Users\songe_000\AppData\Local\Temp\nssutil3.dll
2017-03-08 15:20 - 2017-03-08 15:20 - 0097792 _____ (Mozilla Foundation) C:\Users\songe_000\AppData\Local\Temp\smime3.dll
2017-03-08 15:20 - 2017-03-08 15:21 - 0172544 _____ (Mozilla Foundation) C:\Users\songe_000\AppData\Local\Temp\softokn3.dll
2017-03-08 15:20 - 2017-03-08 15:21 - 0423936 _____ () C:\Users\songe_000\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-01 16:05
==================== End of FRST.txt ============================