Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-11-2017
Ran by Gary (administrator) on GARY-PC (07-11-2017 19:21:08)
Running from C:\Users\Gary\Downloads
Loaded Profiles: Gary (Available Profiles: Gary & DefaultAppPool)
Platform: Windows 10 Home Version 1709 16299.19 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Windows\System32\GFNEXSrv.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Alcatel-Lucent) C:\Program Files\Common Files\Motive\McciCMService.exe
(Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 7510 series\Bin\ScanToPCActivationApp.exe
(Murray Hurps Software Pty Ltd) C:\Program Files (x86)\Ad Muncher\AdMunch.exe
(Murray Hurps Software Pty Ltd) C:\Program Files (x86)\Ad Muncher\AdMunch64.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 7510 series\Bin\HPNetworkCommunicator.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2011-03-30] (TOSHIBA Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13776088 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944648 2015-06-12] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Ad Muncher] => C:\Program Files (x86)\Ad Muncher\AdMunch.exe [560760 2015-03-20] (Murray Hurps Software Pty Ltd)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1298816 2011-07-11] (TOSHIBA Corporation)
HKU\S-1-5-21-3942731526-1549951770-3740554991-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9856176 2017-09-20] (Piriform Ltd)
HKU\S-1-5-21-3942731526-1549951770-3740554991-1000\...\Run: [HP Photosmart 7510 series (NET)] => C:\Program Files\HP\HP Photosmart 7510 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-3942731526-1549951770-3740554991-1000\...\RunOnce: [Uninstall 17.3.7074.1023\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Gary\AppData\Local\Microsoft\OneDrive\17.3.7074.1023\amd64"
HKU\S-1-5-21-3942731526-1549951770-3740554991-1000\...\RunOnce: [Uninstall 17.3.7074.1023] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Gary\AppData\Local\Microsoft\OneDrive\17.3.7074.1023"
Startup: C:\Users\Gary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Photosmart 7510 series (Network).lnk [2017-03-12]
ShortcutTarget: Monitor Ink Alerts - HP Photosmart 7510 series (Network).lnk -> C:\Program Files\HP\HP Photosmart 7510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Gary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PalTalk.lnk [2017-06-28]
ShortcutTarget: PalTalk.lnk -> C:\Program Files (x86)\Paltalk Messenger\paltalk.exe (AVM Software Inc.)
GroupPolicy: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 208.180.42.68 208.180.42.100
Tcpip\..\Interfaces\{d4e9f94b-6c9a-40b9-bc36-0a68afafa088}: [DhcpNameServer] 208.180.42.68 208.180.42.100
Tcpip\..\Interfaces\{d523adc0-9e32-424a-82f5-987648328c62}: [DhcpNameServer] 208.180.42.68 208.180.42.100
Tcpip\..\Interfaces\{e982eb49-3b33-45ab-8556-fb0024d1a300}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKU\S-1-5-21-3942731526-1549951770-3740554991-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://yahoo.com/
SearchScopes: HKLM -> DefaultScope {4D30FB0D-DEA1-4AFD-B4E3-3DF95AEC27E0} URL = hxxp://
www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNF
SearchScopes: HKLM -> {4D30FB0D-DEA1-4AFD-B4E3-3DF95AEC27E0} URL = hxxp://
www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNF
SearchScopes: HKLM-x32 -> DefaultScope {4D30FB0D-DEA1-4AFD-B4E3-3DF95AEC27E0} URL = hxxp://
www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNF
SearchScopes: HKLM-x32 -> {4D30FB0D-DEA1-4AFD-B4E3-3DF95AEC27E0} URL = hxxp://
www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNF
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3942731526-1549951770-3740554991-1000 -> DefaultScope {B4288A11-C9B8-4AC1-86C9-457280A60AC5} URL = hxxp://
www.bing.com/search?FORM=U220DF&PC=U220&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3942731526-1549951770-3740554991-1000 -> DD356F92596C4A92A30B5508B958705E URL = hxxps://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11
SearchScopes: HKU\S-1-5-21-3942731526-1549951770-3740554991-1000 -> {615EE365-E54B-4D13-A817-AB1429DFB34C} URL = hxxps://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-3942731526-1549951770-3740554991-1000 -> {B4288A11-C9B8-4AC1-86C9-457280A60AC5} URL = hxxp://
www.bing.com/search?FORM=U220DF&PC=U220&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3942731526-1549951770-3740554991-1000 -> {BB660FD4-3372-4B84-9C8D-9E266C95477C} URL = hxxps://
www.flickr.com/search/?q={searchTerms}
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files\WOT\WOT.dll => No File
BHO: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll [2012-08-24] (TOSHIBA Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO-x32: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files (x86)\WOT\WOT.dll => No File
BHO-x32: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2012-08-24] (TOSHIBA Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)
Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll No File
Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll No File
Toolbar: HKU\S-1-5-21-3942731526-1549951770-3740554991-1000 -> WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll No File
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxps://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1479323368619
DPF: HKLM-x32 {8AD9C840-044E-11D1-B3E9-00805F499D93}
DPF: HKLM-x32 {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} hxxp://
www.superadblocker.com/activex/sabspx.cab
DPF: HKLM-x32 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
DPF: HKLM-x32 {E0FEE963-BB53-4215-81AD-B28C77384644} hxxps://pattcw.att.motive.com/wizlet/DSLActivation/static/installer/ATTInternetInstaller64.cab
Handler: AutorunsDisabled - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: AutorunsDisabled - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll [2012-03-15] (Belarc, Inc.)
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll No File
FireFox:
========
FF DefaultProfile: 4x13xd3n.default-1490672475513-1506989525317
FF ProfilePath: C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\6jzgq59z.default-1505954497758 [2017-11-05]
FF ProfilePath: C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\4x13xd3n.default-1490672475513-1506989525317 [2017-11-07]
FF Homepage: Mozilla\Firefox\Profiles\4x13xd3n.default-1490672475513-1506989525317 -> hxxps://
www.google.com/
FF Extension: (Safe Browsing Version 4 (temporary add-on)) - C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\4x13xd3n.default-1490672475513-1506989525317\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-10-11]
FF Extension: (__MSG_appName__) - C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\4x13xd3n.default-1490672475513-1506989525317\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}.xpi [2017-10-23]
FF Extension: (Adblock Plus) - C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\4x13xd3n.default-1490672475513-1506989525317\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-11-06]
FF Extension: (Skype Click to Call) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-10-25] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-10-25] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @Motive.com/NpMotive,version=1.0 -> C:\Program Files (x86)\Common Files\Motive\npMotive.dll [2010-04-30] (Alcatel-Lucent)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-30] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-30] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3942731526-1549951770-3740554991-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Gary\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2014-04-25] (Google)
FF Plugin HKU\S-1-5-21-3942731526-1549951770-3740554991-1000: @talk.google.com/O1DPlugin -> C:\Users\Gary\AppData\Roaming\Mozilla\plugins\npo1d.dll [2014-04-25] (Google)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Gary\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2014-04-25] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Gary\AppData\Roaming\mozilla\plugins\npo1d.dll [2014-04-25] (Google)
Chrome:
=======
CHR DefaultProfile: Profile 2
CHR Profile: C:\Users\Gary\AppData\Local\Google\Chrome\User Data\Profile 1 [2016-10-31]
CHR Profile: C:\Users\Gary\AppData\Local\Google\Chrome\User Data\Profile 2 [2017-11-06]
CHR Extension: (Docs) - C:\Users\Gary\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-24]
CHR Extension: (Google Drive) - C:\Users\Gary\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-06]
CHR Extension: (YouTube) - C:\Users\Gary\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-06]
CHR Extension: (Sheets) - C:\Users\Gary\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-24]
CHR Extension: (Google Docs Offline) - C:\Users\Gary\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-31]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Gary\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-05]
CHR Extension: (Gmail) - C:\Users\Gary\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-06]
CHR Extension: (Chrome Media Router) - C:\Users\Gary\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-26]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-04-16] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-21] (Advanced Micro Devices, Inc.) [File not signed]
R2 GFNEXSrv; C:\Windows\System32\GFNEXSrv.exe [162824 2010-09-09] ()
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [323952 2017-09-27] (HP Inc.)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [3894760 2017-06-07] (Paramount Software UK Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes)
R2 McciCMService; C:\Program Files (x86)\Common Files\Motive\McciCMService.exe [319488 2010-04-30] (Alcatel-Lucent) [File not signed]
R2 McciCMService64; C:\Program Files\Common Files\Motive\McciCMService.exe [517632 2010-04-30] (Alcatel-Lucent) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 1999-12-31] (Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-06-12] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdide64; C:\WINDOWS\System32\drivers\amdide64.sys [11944 1999-12-31] (Advanced Micro Devices Inc.)
S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [31992 2015-06-03] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S2 APXACC; C:\WINDOWS\system32\DRIVERS\appexDrv.sys [229056 2015-04-03] (AppEx Networks Corporation)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-07-21] (Advanced Micro Devices)
S3 dc3d; C:\WINDOWS\System32\drivers\dc3d.sys [47616 2011-05-18] (Microsoft Corporation) [File not signed]
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [18528 2014-11-18] () [File not signed]
S3 epmntdrv; C:\WINDOWS\SysWOW64\epmntdrv.sys [15968 2014-11-18] () [File not signed]
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77440 2017-10-09] ()
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10848 2014-11-18] () [File not signed]
S3 EuGdiDrv; C:\WINDOWS\SysWOW64\EuGdiDrv.sys [10208 2014-11-18] () [File not signed]
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [192952 2017-10-09] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [110016 2017-11-07] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [45504 2017-11-07] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [252232 2017-11-07] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [94144 2017-11-07] (Malwarebytes)
R1 MpKsl01c1f143; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{42D8B9A9-2C35-4086-8935-DD4C7B788372}\MpKsl01c1f143.sys [58120 2017-11-07] (Microsoft Corporation)
S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2010-04-30] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2010-04-30] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 1999-12-31] (Realtek )
R3 rtwlane_13; C:\WINDOWS\System32\drivers\rtwlane_13.sys [3717120 2017-09-29] (Realtek Semiconductor Corporation )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver.sys [22800 2012-02-24] (Synaptics Incorporated)
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [45728 2015-10-02] (Toshiba Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-11-07 10:01 - 2017-11-07 10:01 - 000000000 ___HD C:\OneDriveTemp
2017-11-07 00:10 - 2017-11-07 00:10 - 000001237 _____ C:\Users\Gary\Desktop\MBAM4.txt
2017-11-06 22:23 - 2017-11-07 00:48 - 000028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2017-11-06 22:22 - 2017-11-07 00:47 - 000000910 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-11-06 22:22 - 2017-11-07 00:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-11-06 22:22 - 2017-11-07 00:47 - 000000000 ____D C:\Program Files\RogueKiller
2017-11-06 22:22 - 2017-11-06 23:35 - 000000000 ____D C:\ProgramData\RogueKiller
2017-11-06 22:19 - 2017-11-06 22:19 - 036135784 _____ (Adlice Software ) C:\Users\Gary\Downloads\RogueKiller_setup_ref3.exe
2017-11-05 22:05 - 2017-11-06 23:50 - 000000000 ____D C:\AdwCleaner
2017-11-05 22:04 - 2017-11-05 22:05 - 008261584 _____ (Malwarebytes) C:\Users\Gary\Downloads\adwcleaner_7.0.4.0.exe
2017-11-05 19:51 - 2017-11-05 19:52 - 000067552 _____ C:\Users\Gary\Downloads\Addition.txt
2017-11-05 19:49 - 2017-11-07 19:21 - 000021559 _____ C:\Users\Gary\Downloads\FRST.txt
2017-11-05 19:48 - 2017-11-07 19:21 - 000000000 ____D C:\FRST
2017-11-05 19:48 - 2017-11-05 19:48 - 000001036 _____ C:\Users\Gary\Desktop\FRST64 - Shortcut.lnk
2017-11-05 19:47 - 2017-11-05 19:49 - 002403328 _____ (Farbar) C:\Users\Gary\Downloads\FRST64.exe
2017-11-05 19:06 - 2017-11-05 19:06 - 000000671 _____ C:\Users\Gary\Desktop\MBAM2.txt
2017-11-05 19:06 - 2017-11-05 19:06 - 000000667 _____ C:\Users\Gary\Desktop\MBAM 3.txt
2017-11-05 15:56 - 2017-11-05 15:56 - 000000659 _____ C:\Users\Gary\Desktop\MBAM.txt
2017-10-31 08:07 - 2017-10-31 08:07 - 000000000 ____D C:\WINDOWS\Panther
2017-10-29 16:32 - 2017-10-29 18:51 - 000003564 _____ C:\Users\Gary\ipconfig.txt
2017-10-29 16:29 - 2017-10-29 18:13 - 000003564 _____ C:\WINDOWS\system32\ipconfig.txt
2017-10-29 16:27 - 2017-10-29 21:25 - 000003564 _____ C:\Users\Gary\myTcp.txt
2017-10-29 09:30 - 2017-10-29 17:54 - 000003564 _____ C:\WINDOWS\system32\myTcp.txt
2017-10-26 23:06 - 2017-10-26 23:06 - 018617536 _____ (Microsoft Corporation) C:\Users\Gary\Downloads\MediaCreationTool(1).exe
2017-10-26 18:28 - 2017-10-26 18:28 - 000000000 ____D C:\Users\Gary\Documents\FeedbackHub
2017-10-23 19:17 - 2017-10-23 19:16 - 000503513 _____ C:\Users\Gary\Desktop\Macrium.zip
2017-10-22 21:56 - 2017-10-22 21:56 - 006541184 _____ (Microsoft Corporation) C:\Users\Gary\Downloads\Windows10Upgrade9252.exe
2017-10-17 23:00 - 2017-10-17 23:00 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2017-10-17 22:59 - 2017-10-17 22:59 - 000000000 ___HD C:\Users\Gary\MicrosoftEdgeBackups
2017-10-17 22:57 - 2017-10-17 22:57 - 000000000 ____D C:\Users\Gary\AppData\Local\PackageStaging
2017-10-17 22:55 - 2017-10-17 22:55 - 000000020 ___SH C:\Users\Gary\ntuser.ini
2017-10-17 22:50 - 2017-10-17 22:51 - 000011433 _____ C:\WINDOWS\diagwrn.xml
2017-10-17 22:50 - 2017-10-17 22:51 - 000011433 _____ C:\WINDOWS\diagerr.xml
2017-10-17 22:48 - 2017-11-07 15:45 - 000004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{EBCAAE08-B5B5-420E-8AC2-0C02C1866AB3}
2017-10-17 22:48 - 2017-11-07 10:01 - 000003360 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3942731526-1549951770-3740554991-1000
2017-10-17 22:48 - 2017-11-07 02:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-10-17 22:48 - 2017-10-25 07:23 - 000004386 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-10-17 22:48 - 2017-10-17 22:48 - 000003610 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3942731526-1549951770-3740554991-1000UA
2017-10-17 22:48 - 2017-10-17 22:48 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-10-17 22:48 - 2017-10-17 22:48 - 000003344 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-10-17 22:48 - 2017-10-17 22:48 - 000003338 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3942731526-1549951770-3740554991-1000Core
2017-10-17 22:48 - 2017-10-17 22:48 - 000003120 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-10-17 22:48 - 2017-10-17 22:48 - 000002668 _____ C:\WINDOWS\System32\Tasks\HPCustParticipation HP Photosmart 7510 series
2017-10-17 22:48 - 2017-10-17 22:48 - 000002590 _____ C:\WINDOWS\System32\Tasks\hpUrlLauncher.exe_{B3FA9662-64A8-451C-906B-878A3124103B}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002412 _____ C:\WINDOWS\System32\Tasks\{CA8DD57D-1216-49C1-BAA8-BC03908E6419}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002364 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
2017-10-17 22:48 - 2017-10-17 22:48 - 000002338 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2017-10-17 22:48 - 2017-10-17 22:48 - 000002336 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2017-10-17 22:48 - 2017-10-17 22:48 - 000002322 _____ C:\WINDOWS\System32\Tasks\Microsoft Security Essentials
2017-10-17 22:48 - 2017-10-17 22:48 - 000002316 _____ C:\WINDOWS\System32\Tasks\{E27305A3-3D67-455A-8EE4-B2BA875BFEA8}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002302 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe
2017-10-17 22:48 - 2017-10-17 22:48 - 000002298 _____ C:\WINDOWS\System32\Tasks\{A2D0D853-65BE-4435-9C98-7F6A6713DC9B}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002270 _____ C:\WINDOWS\System32\Tasks\{B8C8DC05-D942-4CCA-9500-6C7D74AEEDC0}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002268 _____ C:\WINDOWS\System32\Tasks\{674AE313-2F92-49E2-8E62-817F62D2DAC3}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002244 _____ C:\WINDOWS\System32\Tasks\HPCustPartic.exe_{D81A7C3A-72D9-49DD-887E-EB791438ADDC}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002224 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_rundll32_exe
2017-10-17 22:48 - 2017-10-17 22:48 - 000002220 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-10-17 22:48 - 2017-10-17 22:48 - 000002176 _____ C:\WINDOWS\System32\Tasks\SidebarExecute
2017-10-17 22:48 - 2017-10-17 22:48 - 000002174 _____ C:\WINDOWS\System32\Tasks\{4F97251C-13CB-441A-8F32-4B3B52E010A4}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002132 _____ C:\WINDOWS\System32\Tasks\{4D8AFD95-72DE-4EB0-B9AB-D864CF243669}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002124 _____ C:\WINDOWS\System32\Tasks\{DB4AB491-93EF-4ECB-8886-400360145FDD}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002124 _____ C:\WINDOWS\System32\Tasks\{7AB3CB3B-92FA-42F7-B9EB-AC59CDFE9AD0}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002124 _____ C:\WINDOWS\System32\Tasks\{22A8C708-0AEE-48AD-9762-07C92BBEDF46}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002112 _____ C:\WINDOWS\System32\Tasks\{28732AC3-6D3D-4C63-BB16-B0985D3FA390}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002104 _____ C:\WINDOWS\System32\Tasks\{A3A9F015-55A3-41CB-9987-CC71BF0278F2}
2017-10-17 22:48 - 2017-10-17 22:48 - 000002104 _____ C:\WINDOWS\System32\Tasks\{6916640E-4285-4EF9-BB23-B3A4CD4A369E}
2017-10-17 22:48 - 2017-10-17 22:48 - 000000000 ____D C:\WINDOWS\System32\Tasks\WPD
2017-10-17 22:48 - 2017-10-17 22:48 - 000000000 ____D C:\WINDOWS\System32\Tasks\S-1-5-21-3942731526-1549951770-3740554991-1000
2017-10-17 22:48 - 2017-10-17 22:48 - 000000000 ____D C:\WINDOWS\System32\Tasks\Hewlett-Packard
2017-10-17 22:48 - 2017-10-17 22:48 - 000000000 ____D C:\WINDOWS\System32\Tasks\Event Viewer Tasks
2017-10-17 22:30 - 2017-10-17 22:30 - 000000000 ____D C:\ProgramData\USOShared
2017-10-17 22:29 - 2017-10-17 22:29 - 000001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-10-17 22:26 - 2017-10-17 23:15 - 000000000 ____D C:\Users\Gary\AppData\Local\Packages
2017-10-17 22:24 - 2017-10-29 18:36 - 000000000 ____D C:\Users\Gary
2017-10-17 22:24 - 2017-10-17 22:40 - 000000000 ____D C:\Users\DefaultAppPool
2017-10-17 22:24 - 2017-10-17 22:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2017-10-17 22:24 - 2017-10-17 22:23 - 000000000 ____D C:\Users\Gary\AppData\Roaming\ATI
2017-10-17 22:24 - 2017-10-17 22:23 - 000000000 ____D C:\Users\Gary\AppData\Local\ATI
2017-10-17 22:24 - 2017-10-17 22:23 - 000000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\ATI
2017-10-17 22:24 - 2017-10-17 22:23 - 000000000 ____D C:\Users\DefaultAppPool\AppData\Local\ATI
2017-10-17 22:23 - 2017-11-07 02:39 - 001076744 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-10-17 22:23 - 2017-10-17 22:23 - 000000000 ____D C:\Users\Default\AppData\Roaming\ATI
2017-10-17 22:23 - 2017-10-17 22:23 - 000000000 ____D C:\Users\Default\AppData\Local\ATI
2017-10-17 22:23 - 2017-10-17 22:23 - 000000000 ____D C:\Users\Default User\AppData\Roaming\ATI
2017-10-17 22:23 - 2017-10-17 22:23 - 000000000 ____D C:\Users\Default User\AppData\Local\ATI
2017-10-17 22:22 - 2017-09-29 07:41 - 002241024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-10-17 22:18 - 2017-11-07 19:18 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-10-17 22:18 - 2017-10-17 22:36 - 000235816 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-10-17 21:37 - 2017-11-07 17:43 - 000094144 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-10-17 21:37 - 2017-11-07 02:35 - 000252232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2017-10-17 21:37 - 2017-11-07 02:35 - 000110016 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-10-17 21:37 - 2017-11-07 02:35 - 000045504 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-10-17 21:37 - 2017-10-09 03:03 - 000192952 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2017-10-17 21:37 - 2017-10-09 03:02 - 000077440 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-10-17 21:36 - 2017-10-18 01:07 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2017-10-17 21:36 - 2017-10-17 21:36 - 000000000 ____D C:\Program Files\Common Files\SpeechEngines
2017-10-17 21:32 - 2017-10-17 21:36 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2017-10-17 21:26 - 2017-10-17 21:26 - 025246208 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-10-17 21:26 - 2017-10-17 21:26 - 023664128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-10-17 21:26 - 2017-10-17 21:26 - 021752832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2017-10-17 21:26 - 2017-10-17 21:26 - 019343360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-10-17 21:26 - 2017-10-17 21:26 - 018913792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-10-17 21:26 - 2017-10-17 21:26 - 017080832 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2017-10-17 21:26 - 2017-10-17 21:26 - 008097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-10-17 21:26 - 2017-10-17 21:26 - 006032896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-10-17 21:26 - 2017-10-17 21:26 - 004744192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-10-17 21:26 - 2017-10-17 21:26 - 003681280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-10-17 21:26 - 2017-10-17 21:26 - 002474080 _____ C:\WINDOWS\SysWOW64\Windows.Mirage.dll