Lots of slowness and lots of toolbars installed.
Frst 1:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10-02-2017
Ran by Randy (administrator) on HP-RRR (10-02-2017 21:47:09)
Running from C:\Users\Randy\Desktop\Virus
Loaded Profiles: Randy (Available Profiles: Randy & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(SpeedyPC Software) C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupService.exe
(Digital Care Solutions) C:\Program Files\BDServices\BitDefenderCOM.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimService\SlimServiceFactory.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimService\SlimService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(SlimWare Utilities, Inc.) C:\Program Files (x86)\DriverUpdate\DriverUpdate.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP OfficeJet 3830 series\Bin\ScanToPCActivationApp.exe
(The Chromium Authors) C:\Users\Randy\AppData\Local\Chromium\Application\chrome.exe
(The Chromium Authors) C:\Users\Randy\AppData\Local\Chromium\Application\chrome.exe
(Slimware Utilities Holdings, Inc.) C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\1454013173\ee\aolsoftware.exe
() C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
(The Chromium Authors) C:\Users\Randy\AppData\Local\Chromium\Application\chrome.exe
(The Chromium Authors) C:\Users\Randy\AppData\Local\Chromium\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
() C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
() C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
() C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
() C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
(The Chromium Authors) C:\Users\Randy\AppData\Local\Chromium\Application\chrome.exe
(Adobe Systems Incorporated) C:\Config.Msi\cfaec5f2.rbf
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\Install\{27B1DC9B-40FD-4489-AE63-D0E163D5D7FC}\56.0.2924.87_chrome_installer.exe
(Google Inc.) C:\Windows\Temp\CR_58E4E.tmp\setup.exe
(Google Inc.) C:\Windows\Temp\CR_58E4E.tmp\setup.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP OfficeJet 3830 series\Bin\HPNetworkCommunicatorCom.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-01-04] (IDT, Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800416 2012-01-19] (Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3954352 2016-04-27] (Synaptics Incorporated)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [576568 2011-11-29] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1342008 2011-08-26] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [HostManager] => C:\Program Files (x86)\Common Files\AOL\1454013173\ee\AOLSoftware.exe [41800 2010-03-07] (AOL Inc.)
HKLM-x32\...\Run: [NowUSeeIt Player] => C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe [913920 2016-01-04] () <===== ATTENTION
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1160408 2016-12-17] (Adobe Systems Incorporated)
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\...\Run: [HP OfficeJet 3830 series (NET)] => C:\Program Files\HP\HP OfficeJet 3830 series\Bin\ScanToPCActivationApp.exe [3651080 2015-03-09] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\...\Run: [NowUSeeIt Player] => C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe [913920 2016-01-04] () <===== ATTENTION
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\...\Run: [Chromium] => c:\users\randy\appdata\local\chromium\application\chrome.exe [1043456 2016-01-26] (The Chromium Authors)
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\...\Run: [SlimCleaner Plus] => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe [26201280 2016-07-25] (Slimware Utilities Holdings, Inc.)
ShellIconOverlayIdentifiers: [ CustomFolderNotSynced] -> {4008A679-BE48-456D-A32E-97DE3F48E10D} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ CustomFolderSynced] -> {4DD1429E-055B-4585-9E4D-614252FD7FC1} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ FileNotSynced] -> {267973DC-2B3C-41CE-93F1-D2C5CCC06663} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ FileSynced] -> {DBD42211-56CD-4C08-A3E4-48ED07AD7759} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ FolderExcluded] -> {43BAE28F-4AC6-4C1F-9A86-E0D8533370BC} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ FolderNotSynced] -> {3E2576B1-5B08-47DE-8803-95C6ECA734EE} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ FolderSynced] -> {2858A960-566F-45CF-951E-4B3099E70E6F} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ CustomFolderNotSynced] -> {4008A679-BE48-456D-A32E-97DE3F48E10D} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ CustomFolderSynced] -> {4DD1429E-055B-4585-9E4D-614252FD7FC1} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ FileNotSynced] -> {267973DC-2B3C-41CE-93F1-D2C5CCC06663} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ FileSynced] -> {DBD42211-56CD-4C08-A3E4-48ED07AD7759} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ FolderExcluded] -> {43BAE28F-4AC6-4C1F-9A86-E0D8533370BC} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ FolderNotSynced] -> {3E2576B1-5B08-47DE-8803-95C6ECA734EE} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ FolderSynced] -> {2858A960-566F-45CF-951E-4B3099E70E6F} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Event Reminder.lnk [2015-12-11]
ShortcutTarget: Event Reminder.lnk -> C:\Program Files (x86)\Broderbund\PrintMaster\pmremind.exe (Broderbund Properties LLC)
Startup: C:\Users\Randy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2016-02-02] ()
Startup: C:\Users\Randy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JZIP.lnk [2015-12-11]
ShortcutTarget: JZIP.lnk -> C:\Windows\System32\schtasks.exe (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 127.0.0.1 localhost
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\Parameters: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{21464931-263a-4a60-930e-a79b690b399f}: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{21464931-263a-4a60-930e-a79b690b399f}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{31ea90e4-35d4-4540-a94c-eab28ac7c7e0}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{3973625b-d550-4482-8626-055c851fa7f8}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3e5366e2-e619-4c7e-a254-4148181480bb}: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{3e5366e2-e619-4c7e-a254-4148181480bb}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{797fc918-2a02-4a5f-9f81-cc4932956ea0}: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{797fc918-2a02-4a5f-9f81-cc4932956ea0}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{825E0274-4ABB-4A35-83B7-62488622A3B1}: [NameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{a1c95c13-acd4-4e93-88c9-2912fbc94e6c}: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{a1c95c13-acd4-4e93-88c9-2912fbc94e6c}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{c1fd1c83-dc19-4fbd-a13f-ebdcb53d58b0}: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{c1fd1c83-dc19-4fbd-a13f-ebdcb53d58b0}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{ed4e3568-60c7-4154-bc8c-83374c0e6f1c}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131312655671564010&GUID=F34706C8-BC86-441C-8A8D-ECA6761F344B
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131312655672036951&GUID=F34706C8-BC86-441C-8A8D-ECA6761F344B
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131312655672053665&GUID=F34706C8-BC86-441C-8A8D-ECA6761F344B
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {77F8667C-BC7F-4CCB-B5BD-96659BD2F0DE} URL = hxxp://search.aol.com/aol/search?q={searchTerms}&s_it=clireset-ie
SearchScopes: HKLM-x32 -> {9a216821-0ec5-49a3-85ac-fb72ae79a1e8} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^Y6^xdm003^YYA^us&si=CP6fnartpMoCFc5bfgodIZsNCA&ptb=5EEB6E1C-093A-40CF-A501-0BE772DDE2B1&ind=2016011213&n=7829e3cd&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> {1B687A8D-64D5-4CAD-B865-D4512F4B23DD} URL = hxxp://search.aol.com/aol/search?q={searchTerms}&s_it=clireset-ie
SearchScopes: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> {9a216821-0ec5-49a3-85ac-fb72ae79a1e8} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^Y6^xdm003^YYA^us&si=CP6fnartpMoCFc5bfgodIZsNCA&ptb=5EEB6E1C-093A-40CF-A501-0BE772DDE2B1&ind=2016011213&n=7829e3cd&psa=&st=sb&searchfor={searchTerms}
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-01-19] (Atheros Commnucations)
Toolbar: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
FireFox:
========
FF ProfilePath: C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default [2016-08-08]
FF user.js: detected! => C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\user.js [2016-01-28]
FF Homepage: Mozilla\Firefox\Profiles\w1n6vmjf.default -> hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_instlmtrx_16_07¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0EyDyEtAtBtA0D0C0E0Azz0E0AyEtN0D0Tzu0StCyDtDyCtN1L2XzutAtFtCzztFtCtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDyEzz0DyDzy0B0FtGyD0E0CyDtGzytA0BtCtGtAtC0E0AtG0CyB0D0AtC0ByByCzytCyEyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEtAyC0F0ByByD0EtG0BtAtDzytGyE0F0DyCtGzyyD0C0EtGzzzz0EtCyByDyByCyBtByE0D2QtN0A0LzutB%26cr%3D1936506275%26a%3Dwncy_instlmtrx_16_07%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\w1n6vmjf.default -> Search Provided by Yahoo
FF Keyword.URL: Mozilla\Firefox\Profiles\w1n6vmjf.default -> hxxp://aolsearch.aol.com/aol/search?invocationType=client_searchbox&query=
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\w1n6vmjf.default -> Search Provided by Yahoo
FF NewTab: Mozilla\Firefox\Profiles\w1n6vmjf.default -> about:newtab
FF Extension: (videoresumerjetpack) - C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\Extensions\videoresumer@jetpack [2015-12-11] [not signed]
FF Extension: (Yahoo! Toolbar) - C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2016-01-04] [not signed]
FF Extension: (AOL Toolbar) - C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\Extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} [2016-01-28] [not signed]
FF SearchPlugin: C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\searchplugins\aolsearch.xml [2015-12-15]
FF SearchPlugin: C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\searchplugins\Search Provided by Yahoo.xml [2016-02-15]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\aolsearch.xml [2015-12-15]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2011-11-07] (Adobe Systems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-10] (Google Inc.)
FF Plugin-x32: @viewpoint.com/VMP -> C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2783097096-289569773-1546617986-1001: bluejeans.com/bjninstallplugin -> C:\Users\Randy\AppData\Roaming\Blue Jeans\bjnplugin\2.115.57.5\npbjninstallplugin_2.115.57.5.dll [2015-10-15] (Blue Jeans)
FF Plugin HKU\S-1-5-21-2783097096-289569773-1546617986-1001: bluejeans.com/bjnplugin -> C:\Users\Randy\AppData\Roaming\Blue Jeans\bjnplugin\2.115.57.5\npbjnplugin_2.115.57.5.dll [2015-10-15] (Blue Jeans)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\prefs.js [2015-12-11] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\cfg [2015-12-11] <==== ATTENTION
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=86311316¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC1YN8j239I6Mjyd7vNuRVuF4vDPXvI545K5Lk0yZuaPTEZETNhOb%2FBJMlU3cWrtE3B5LPuATRj4TiQDTLE5W%2F6T1gG3gr%2B63Fuf4DJw3bmxC%2BZWeGECWX8xosk8oaYOJhVzfdn7C0MU8tFOhlX0D867I7w%2FY3BPKDl2YWznSMNnMNhdfhuhn%2BhoVJITdlVyN5g%3D
CHR StartupUrls: Default -> "hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=86311316¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC1YN8j239I6Mjyd7vNuRVuFhCJrEQv%2Fc%2BX2qZcHHjPPs%2Bq5PxEnDevcjOXYLyIHaBnM0IoJ8MqMcKnm8tCbPzRbgJMRuO8J430v3e4Ts%2F%2BpSpNuZ2wz8ISRKpXfOt2Mn1ECKZer7C78v27A4TWru%2BOJphUGzd3uNG%2Bbj9taw10baItFUSSmTPZfB91iIJ4NZHs%3D","hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_instlmtrx_16_07¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0EyDyEtAtBtA0D0C0E0Azz0E0AyEtN0D0Tzu0StCyDtDyCtN1L2XzutAtFtCzztFtCtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDyEzz0DyDzy0B0FtGyD0E0CyDtGzytA0BtCtGtAtC0E0AtG0CyB0D0AtC0ByByCzytCyEyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEtAyC0F0ByByD0EtG0BtAtDzytGyE0F0DyCtGzyyD0C0EtGzzzz0EtCyByDyByCyBtByE0D2QtN0A0LzutB%26cr%3D1936506275%26a%3Dwncy_instlmtrx_16_07%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome"
CHR DefaultSearchURL: Default -> hxxps://us.search.yahoo.com/yhs/search?hspart=omr&hsimp=yhs-001&type=86311316¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC1YN8j239I6Mjyd7vNuRVuF%2BSx9IQO%2Btq1ES3xDVIbRnGPfSeuBJV3RjakyiaTUMyic9cEOZz%2BIMAEXlTGw29QZ8O%2BMT2WbP3ntbUpNhkYAiDSvZVBLYjw6TmKit75VvKwgkCE5sGqaHpFG3bnw81er2LsvJrXoUWjpc3z21x5IKcuu7XPn1%2FeTgH5tz0ptHRU%3D&p={searchTerms}
CHR DefaultSearchKeyword: Default -> search.yahoo.com
CHR DefaultNewTabURL: Default -> hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=86311316¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC1YN8j239I6Mjyd7vNuRVuF9CWpdq8%2BWMi2ZHXIPXjQavHclM9j1Ab9UVxxrvumLdV%2BHCMXZufzoRPgqvEu%2BSX%2BVjLy6NdvJS4GO4EhWobrp%2BCPE5Ncg5ey6jMngZaMQCh%2BAmhFzEwpL1%2F33kJ7fiGTyGwEETEUxfbQHs30Lj1Pcjs8sJdvhGspUs%2FhtFiexxQ%3D
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms}
CHR Profile: C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default [2016-08-08]
CHR Extension: (Google Docs) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-30]
CHR Extension: (Google Drive) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-30]
CHR Extension: (YouTube) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-30]
CHR Extension: (Google Search) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-30]
CHR Extension: (Google Docs Offline) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-08-06]
CHR Extension: (Home Tab) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\kofkpgiaknijknhajbhnghkodiccblkg [2016-08-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-06]
CHR Extension: (Gmail) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-30]
CHR Extension: (Chrome Media Router) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-08]
CHR HKLM\...\Chrome\Extension: [kofkpgiaknijknhajbhnghkodiccblkg] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2783097096-289569773-1546617986-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kofkpgiaknijknhajbhnghkodiccblkg] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [kofkpgiaknijknhajbhnghkodiccblkg] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-02-10] (Advanced Micro Devices, Inc.) [File not signed]
R2 BackupService; C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupService.exe [247808 2016-05-06] (SpeedyPC Software) [File not signed]
R2 BitDefenderCOM; C:\Program Files\BDServices\BitDefenderCom.exe [1012736 2016-06-24] (Digital Care Solutions) [File not signed]
R3 scan; C:\Program Files\BDServices\scan.dll [602456 2016-06-14] (Bitdefender)
R2 SlimService; C:\Program Files\SlimService\SlimServiceFactory.exe [252096 2016-07-25] (SlimWare Utilities, Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [253960 2016-04-27] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-29] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-06-30] (Microsoft Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2012-01-19] (Atheros) [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices)
S3 lehidmini; C:\WINDOWS\system32\drivers\leath_hid.sys [36128 2012-01-19] (Atheros) [File not signed]
R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [136408 2015-12-11] (Malwarebytes Corporation)
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2015-10-29] (Realtek )
R2 sbmntr; C:\Program Files (x86)\YTDownloader\sbmntr.sys [58528 2015-10-22] (YTDownloader)
S3 ssmirrdr; C:\WINDOWS\system32\DRIVERS\ssmirrdr.sys [10112 2015-06-29] (support.com, Inc)
S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [13920 2017-02-10] ()
R3 Trufos; C:\WINDOWS\System32\DRIVERS\Trufos.sys [452040 2016-06-14] (BitDefender S.R.L.)
S1 vwcgkjth; C:\WINDOWS\system32\drivers\vwcgkjth.sys [55168 2017-02-10] (Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44568 2015-10-29] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [293216 2015-10-29] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-29] (Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation)
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-10 21:46 - 2017-02-10 21:46 - 00055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwcgkjth.sys
2017-02-10 21:46 - 2017-02-10 21:46 - 00001291 _____ C:\Users\Randy\Desktop\Google Chrome.lnk
2017-02-10 21:27 - 2017-02-10 21:47 - 00000000 ____D C:\Users\Randy\Desktop\Virus
2017-02-10 21:27 - 2017-02-10 21:27 - 00000000 ____D C:\Users\Randy\Desktop\New folder
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-10 21:50 - 2016-08-08 22:41 - 00000512 _____ C:\WINDOWS\Tasks\SpeedyBackup reigistration schedule.job
2017-02-10 21:47 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-02-10 21:47 - 2014-09-12 16:11 - 00000000 ____D C:\FRST
2017-02-10 21:46 - 2016-02-15 14:41 - 00000000 ____D C:\Users\Randy\AppData\Local\{3A700C2C-1ED8-6094-7340-457C5728B9E4}
2017-02-10 21:46 - 2015-10-29 23:24 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-10 21:45 - 2016-02-02 10:45 - 00000000 ____D C:\Users\Randy\AppData\Local\Packages
2017-02-10 21:42 - 2016-05-14 18:42 - 00000284 _____ C:\WINDOWS\Tasks\{4E20A085-1B30-164D-0726-6688F373B3A8}.job
2017-02-10 21:41 - 2016-02-15 14:41 - 00000284 _____ C:\WINDOWS\Tasks\UpdateTask.job
2017-02-10 21:36 - 2013-01-03 20:56 - 00003416 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-02-10 21:36 - 2013-01-03 20:56 - 00003292 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-02-10 21:33 - 2015-10-29 23:21 - 00000000 ____D C:\WINDOWS\INF
2017-02-10 21:31 - 2012-03-01 11:01 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-10 21:24 - 2013-02-24 22:05 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-02-10 21:23 - 2016-02-02 10:17 - 01010686 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-10 21:21 - 2016-08-08 22:41 - 00000496 _____ C:\WINDOWS\Tasks\SpeedyBackup Startup.job
2017-02-10 21:19 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-02-10 21:18 - 2016-08-08 20:54 - 00000474 _____ C:\WINDOWS\Tasks\RegCure Pro Startup.job
2017-02-10 21:17 - 2016-08-06 19:12 - 00000432 _____ C:\WINDOWS\Tasks\DriverUpdate Startup.job
2017-02-10 21:16 - 2016-08-08 22:41 - 00000530 _____ C:\WINDOWS\Tasks\SpeedyPC Update Version3 Startup Task.job
2017-02-10 21:16 - 2016-08-08 22:41 - 00000522 _____ C:\WINDOWS\Tasks\SpeedyBackup reigistration schedule startup.job
2017-02-10 21:16 - 2016-01-15 09:52 - 00013920 _____ C:\WINDOWS\system32\Drivers\SWDUMon.sys
==================== Files in the root of some directories =======
2016-08-08 20:54 - 2017-02-10 21:18 - 0000115 _____ () C:\Users\Randy\AppData\Roaming\LogFile.txt
2016-06-19 06:26 - 2016-06-19 06:26 - 2049556 _____ () C:\Users\Randy\AppData\Roaming\sb0.dat
2016-06-10 06:41 - 2016-06-10 06:41 - 2049556 _____ () C:\Users\Randy\AppData\Roaming\sb203.dat
2016-02-17 11:41 - 2016-08-05 17:41 - 0000228 _____ () C:\Users\Randy\AppData\Roaming\WB.CFG
2015-11-15 15:05 - 2015-11-15 15:05 - 0002560 _____ () C:\Users\Randy\AppData\Local\uninstall.exe
2015-01-27 15:51 - 2015-01-27 15:51 - 0000057 _____ () C:\ProgramData\Ament.ini
Files to move or delete:
====================
C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
C:\Windows\Tasks\{4E20A085-1B30-164D-0726-6688F373B3A8}.job
Some files in TEMP:
====================
2016-08-08 22:40 - 2016-08-08 22:41 - 8464000 _____ (SpeedyPC Software Inc.) C:\Users\Randy\AppData\Local\Temp\OMD5938.tmp.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-08-08 21:12
==================== End of FRST.txt ============================
Frst 1:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10-02-2017
Ran by Randy (administrator) on HP-RRR (10-02-2017 21:47:09)
Running from C:\Users\Randy\Desktop\Virus
Loaded Profiles: Randy (Available Profiles: Randy & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(SpeedyPC Software) C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupService.exe
(Digital Care Solutions) C:\Program Files\BDServices\BitDefenderCOM.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimService\SlimServiceFactory.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimService\SlimService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(SlimWare Utilities, Inc.) C:\Program Files (x86)\DriverUpdate\DriverUpdate.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP OfficeJet 3830 series\Bin\ScanToPCActivationApp.exe
(The Chromium Authors) C:\Users\Randy\AppData\Local\Chromium\Application\chrome.exe
(The Chromium Authors) C:\Users\Randy\AppData\Local\Chromium\Application\chrome.exe
(Slimware Utilities Holdings, Inc.) C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\1454013173\ee\aolsoftware.exe
() C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
(The Chromium Authors) C:\Users\Randy\AppData\Local\Chromium\Application\chrome.exe
(The Chromium Authors) C:\Users\Randy\AppData\Local\Chromium\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
() C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
() C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
() C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
() C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
(The Chromium Authors) C:\Users\Randy\AppData\Local\Chromium\Application\chrome.exe
(Adobe Systems Incorporated) C:\Config.Msi\cfaec5f2.rbf
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\Install\{27B1DC9B-40FD-4489-AE63-D0E163D5D7FC}\56.0.2924.87_chrome_installer.exe
(Google Inc.) C:\Windows\Temp\CR_58E4E.tmp\setup.exe
(Google Inc.) C:\Windows\Temp\CR_58E4E.tmp\setup.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP OfficeJet 3830 series\Bin\HPNetworkCommunicatorCom.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-01-04] (IDT, Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800416 2012-01-19] (Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3954352 2016-04-27] (Synaptics Incorporated)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [576568 2011-11-29] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1342008 2011-08-26] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [HostManager] => C:\Program Files (x86)\Common Files\AOL\1454013173\ee\AOLSoftware.exe [41800 2010-03-07] (AOL Inc.)
HKLM-x32\...\Run: [NowUSeeIt Player] => C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe [913920 2016-01-04] () <===== ATTENTION
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1160408 2016-12-17] (Adobe Systems Incorporated)
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\...\Run: [HP OfficeJet 3830 series (NET)] => C:\Program Files\HP\HP OfficeJet 3830 series\Bin\ScanToPCActivationApp.exe [3651080 2015-03-09] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\...\Run: [NowUSeeIt Player] => C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe [913920 2016-01-04] () <===== ATTENTION
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\...\Run: [Chromium] => c:\users\randy\appdata\local\chromium\application\chrome.exe [1043456 2016-01-26] (The Chromium Authors)
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\...\Run: [SlimCleaner Plus] => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe [26201280 2016-07-25] (Slimware Utilities Holdings, Inc.)
ShellIconOverlayIdentifiers: [ CustomFolderNotSynced] -> {4008A679-BE48-456D-A32E-97DE3F48E10D} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ CustomFolderSynced] -> {4DD1429E-055B-4585-9E4D-614252FD7FC1} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ FileNotSynced] -> {267973DC-2B3C-41CE-93F1-D2C5CCC06663} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ FileSynced] -> {DBD42211-56CD-4C08-A3E4-48ED07AD7759} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ FolderExcluded] -> {43BAE28F-4AC6-4C1F-9A86-E0D8533370BC} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ FolderNotSynced] -> {3E2576B1-5B08-47DE-8803-95C6ECA734EE} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers: [ FolderSynced] -> {2858A960-566F-45CF-951E-4B3099E70E6F} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_64.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ CustomFolderNotSynced] -> {4008A679-BE48-456D-A32E-97DE3F48E10D} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ CustomFolderSynced] -> {4DD1429E-055B-4585-9E4D-614252FD7FC1} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ FileNotSynced] -> {267973DC-2B3C-41CE-93F1-D2C5CCC06663} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ FileSynced] -> {DBD42211-56CD-4C08-A3E4-48ED07AD7759} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ FolderExcluded] -> {43BAE28F-4AC6-4C1F-9A86-E0D8533370BC} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ FolderNotSynced] -> {3E2576B1-5B08-47DE-8803-95C6ECA734EE} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
ShellIconOverlayIdentifiers-x32: [ FolderSynced] -> {2858A960-566F-45CF-951E-4B3099E70E6F} => C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupOverlay_32.dll [2016-05-06] (SpeedyPC Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Event Reminder.lnk [2015-12-11]
ShortcutTarget: Event Reminder.lnk -> C:\Program Files (x86)\Broderbund\PrintMaster\pmremind.exe (Broderbund Properties LLC)
Startup: C:\Users\Randy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2016-02-02] ()
Startup: C:\Users\Randy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JZIP.lnk [2015-12-11]
ShortcutTarget: JZIP.lnk -> C:\Windows\System32\schtasks.exe (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 127.0.0.1 localhost
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\Parameters: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{21464931-263a-4a60-930e-a79b690b399f}: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{21464931-263a-4a60-930e-a79b690b399f}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{31ea90e4-35d4-4540-a94c-eab28ac7c7e0}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{3973625b-d550-4482-8626-055c851fa7f8}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3e5366e2-e619-4c7e-a254-4148181480bb}: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{3e5366e2-e619-4c7e-a254-4148181480bb}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{797fc918-2a02-4a5f-9f81-cc4932956ea0}: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{797fc918-2a02-4a5f-9f81-cc4932956ea0}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{825E0274-4ABB-4A35-83B7-62488622A3B1}: [NameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{a1c95c13-acd4-4e93-88c9-2912fbc94e6c}: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{a1c95c13-acd4-4e93-88c9-2912fbc94e6c}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{c1fd1c83-dc19-4fbd-a13f-ebdcb53d58b0}: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{c1fd1c83-dc19-4fbd-a13f-ebdcb53d58b0}: [DhcpNameServer] 82.163.143.171
Tcpip\..\Interfaces\{ed4e3568-60c7-4154-bc8c-83374c0e6f1c}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131312655671564010&GUID=F34706C8-BC86-441C-8A8D-ECA6761F344B
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131312655672036951&GUID=F34706C8-BC86-441C-8A8D-ECA6761F344B
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131312655672053665&GUID=F34706C8-BC86-441C-8A8D-ECA6761F344B
HKU\S-1-5-21-2783097096-289569773-1546617986-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {77F8667C-BC7F-4CCB-B5BD-96659BD2F0DE} URL = hxxp://search.aol.com/aol/search?q={searchTerms}&s_it=clireset-ie
SearchScopes: HKLM-x32 -> {9a216821-0ec5-49a3-85ac-fb72ae79a1e8} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^Y6^xdm003^YYA^us&si=CP6fnartpMoCFc5bfgodIZsNCA&ptb=5EEB6E1C-093A-40CF-A501-0BE772DDE2B1&ind=2016011213&n=7829e3cd&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> {1B687A8D-64D5-4CAD-B865-D4512F4B23DD} URL = hxxp://search.aol.com/aol/search?q={searchTerms}&s_it=clireset-ie
SearchScopes: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> {9a216821-0ec5-49a3-85ac-fb72ae79a1e8} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^Y6^xdm003^YYA^us&si=CP6fnartpMoCFc5bfgodIZsNCA&ptb=5EEB6E1C-093A-40CF-A501-0BE772DDE2B1&ind=2016011213&n=7829e3cd&psa=&st=sb&searchfor={searchTerms}
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-01-19] (Atheros Commnucations)
Toolbar: HKU\S-1-5-21-2783097096-289569773-1546617986-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
FireFox:
========
FF ProfilePath: C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default [2016-08-08]
FF user.js: detected! => C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\user.js [2016-01-28]
FF Homepage: Mozilla\Firefox\Profiles\w1n6vmjf.default -> hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_instlmtrx_16_07¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0EyDyEtAtBtA0D0C0E0Azz0E0AyEtN0D0Tzu0StCyDtDyCtN1L2XzutAtFtCzztFtCtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDyEzz0DyDzy0B0FtGyD0E0CyDtGzytA0BtCtGtAtC0E0AtG0CyB0D0AtC0ByByCzytCyEyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEtAyC0F0ByByD0EtG0BtAtDzytGyE0F0DyCtGzyyD0C0EtGzzzz0EtCyByDyByCyBtByE0D2QtN0A0LzutB%26cr%3D1936506275%26a%3Dwncy_instlmtrx_16_07%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\w1n6vmjf.default -> Search Provided by Yahoo
FF Keyword.URL: Mozilla\Firefox\Profiles\w1n6vmjf.default -> hxxp://aolsearch.aol.com/aol/search?invocationType=client_searchbox&query=
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\w1n6vmjf.default -> Search Provided by Yahoo
FF NewTab: Mozilla\Firefox\Profiles\w1n6vmjf.default -> about:newtab
FF Extension: (videoresumerjetpack) - C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\Extensions\videoresumer@jetpack [2015-12-11] [not signed]
FF Extension: (Yahoo! Toolbar) - C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2016-01-04] [not signed]
FF Extension: (AOL Toolbar) - C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\Extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} [2016-01-28] [not signed]
FF SearchPlugin: C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\searchplugins\aolsearch.xml [2015-12-15]
FF SearchPlugin: C:\Users\Randy\AppData\Roaming\Mozilla\Firefox\Profiles\w1n6vmjf.default\searchplugins\Search Provided by Yahoo.xml [2016-02-15]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\aolsearch.xml [2015-12-15]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2011-11-07] (Adobe Systems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-10] (Google Inc.)
FF Plugin-x32: @viewpoint.com/VMP -> C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2783097096-289569773-1546617986-1001: bluejeans.com/bjninstallplugin -> C:\Users\Randy\AppData\Roaming\Blue Jeans\bjnplugin\2.115.57.5\npbjninstallplugin_2.115.57.5.dll [2015-10-15] (Blue Jeans)
FF Plugin HKU\S-1-5-21-2783097096-289569773-1546617986-1001: bluejeans.com/bjnplugin -> C:\Users\Randy\AppData\Roaming\Blue Jeans\bjnplugin\2.115.57.5\npbjnplugin_2.115.57.5.dll [2015-10-15] (Blue Jeans)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\prefs.js [2015-12-11] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\cfg [2015-12-11] <==== ATTENTION
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=86311316¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC1YN8j239I6Mjyd7vNuRVuF4vDPXvI545K5Lk0yZuaPTEZETNhOb%2FBJMlU3cWrtE3B5LPuATRj4TiQDTLE5W%2F6T1gG3gr%2B63Fuf4DJw3bmxC%2BZWeGECWX8xosk8oaYOJhVzfdn7C0MU8tFOhlX0D867I7w%2FY3BPKDl2YWznSMNnMNhdfhuhn%2BhoVJITdlVyN5g%3D
CHR StartupUrls: Default -> "hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=86311316¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC1YN8j239I6Mjyd7vNuRVuFhCJrEQv%2Fc%2BX2qZcHHjPPs%2Bq5PxEnDevcjOXYLyIHaBnM0IoJ8MqMcKnm8tCbPzRbgJMRuO8J430v3e4Ts%2F%2BpSpNuZ2wz8ISRKpXfOt2Mn1ECKZer7C78v27A4TWru%2BOJphUGzd3uNG%2Bbj9taw10baItFUSSmTPZfB91iIJ4NZHs%3D","hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_instlmtrx_16_07¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0EyDyEtAtBtA0D0C0E0Azz0E0AyEtN0D0Tzu0StCyDtDyCtN1L2XzutAtFtCzztFtCtFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyDyEzz0DyDzy0B0FtGyD0E0CyDtGzytA0BtCtGtAtC0E0AtG0CyB0D0AtC0ByByCzytCyEyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEtAyC0F0ByByD0EtG0BtAtDzytGyE0F0DyCtGzyyD0C0EtGzzzz0EtCyByDyByCyBtByE0D2QtN0A0LzutB%26cr%3D1936506275%26a%3Dwncy_instlmtrx_16_07%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome"
CHR DefaultSearchURL: Default -> hxxps://us.search.yahoo.com/yhs/search?hspart=omr&hsimp=yhs-001&type=86311316¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC1YN8j239I6Mjyd7vNuRVuF%2BSx9IQO%2Btq1ES3xDVIbRnGPfSeuBJV3RjakyiaTUMyic9cEOZz%2BIMAEXlTGw29QZ8O%2BMT2WbP3ntbUpNhkYAiDSvZVBLYjw6TmKit75VvKwgkCE5sGqaHpFG3bnw81er2LsvJrXoUWjpc3z21x5IKcuu7XPn1%2FeTgH5tz0ptHRU%3D&p={searchTerms}
CHR DefaultSearchKeyword: Default -> search.yahoo.com
CHR DefaultNewTabURL: Default -> hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp=yhs-001&type=86311316¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC1YN8j239I6Mjyd7vNuRVuF9CWpdq8%2BWMi2ZHXIPXjQavHclM9j1Ab9UVxxrvumLdV%2BHCMXZufzoRPgqvEu%2BSX%2BVjLy6NdvJS4GO4EhWobrp%2BCPE5Ncg5ey6jMngZaMQCh%2BAmhFzEwpL1%2F33kJ7fiGTyGwEETEUxfbQHs30Lj1Pcjs8sJdvhGspUs%2FhtFiexxQ%3D
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms}
CHR Profile: C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default [2016-08-08]
CHR Extension: (Google Docs) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-30]
CHR Extension: (Google Drive) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-30]
CHR Extension: (YouTube) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-30]
CHR Extension: (Google Search) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-30]
CHR Extension: (Google Docs Offline) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-08-06]
CHR Extension: (Home Tab) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\kofkpgiaknijknhajbhnghkodiccblkg [2016-08-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-06]
CHR Extension: (Gmail) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-30]
CHR Extension: (Chrome Media Router) - C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-08]
CHR HKLM\...\Chrome\Extension: [kofkpgiaknijknhajbhnghkodiccblkg] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2783097096-289569773-1546617986-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kofkpgiaknijknhajbhnghkodiccblkg] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [kofkpgiaknijknhajbhnghkodiccblkg] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-02-10] (Advanced Micro Devices, Inc.) [File not signed]
R2 BackupService; C:\Program Files (x86)\SpeedyPC Software\SpeedyBackup\BackupService.exe [247808 2016-05-06] (SpeedyPC Software) [File not signed]
R2 BitDefenderCOM; C:\Program Files\BDServices\BitDefenderCom.exe [1012736 2016-06-24] (Digital Care Solutions) [File not signed]
R3 scan; C:\Program Files\BDServices\scan.dll [602456 2016-06-14] (Bitdefender)
R2 SlimService; C:\Program Files\SlimService\SlimServiceFactory.exe [252096 2016-07-25] (SlimWare Utilities, Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [253960 2016-04-27] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-29] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-06-30] (Microsoft Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2012-01-19] (Atheros) [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices)
S3 lehidmini; C:\WINDOWS\system32\drivers\leath_hid.sys [36128 2012-01-19] (Atheros) [File not signed]
R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [136408 2015-12-11] (Malwarebytes Corporation)
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2015-10-29] (Realtek )
R2 sbmntr; C:\Program Files (x86)\YTDownloader\sbmntr.sys [58528 2015-10-22] (YTDownloader)
S3 ssmirrdr; C:\WINDOWS\system32\DRIVERS\ssmirrdr.sys [10112 2015-06-29] (support.com, Inc)
S3 SWDUMon; C:\WINDOWS\system32\DRIVERS\SWDUMon.sys [13920 2017-02-10] ()
R3 Trufos; C:\WINDOWS\System32\DRIVERS\Trufos.sys [452040 2016-06-14] (BitDefender S.R.L.)
S1 vwcgkjth; C:\WINDOWS\system32\drivers\vwcgkjth.sys [55168 2017-02-10] (Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44568 2015-10-29] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [293216 2015-10-29] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-29] (Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation)
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-10 21:46 - 2017-02-10 21:46 - 00055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwcgkjth.sys
2017-02-10 21:46 - 2017-02-10 21:46 - 00001291 _____ C:\Users\Randy\Desktop\Google Chrome.lnk
2017-02-10 21:27 - 2017-02-10 21:47 - 00000000 ____D C:\Users\Randy\Desktop\Virus
2017-02-10 21:27 - 2017-02-10 21:27 - 00000000 ____D C:\Users\Randy\Desktop\New folder
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-10 21:50 - 2016-08-08 22:41 - 00000512 _____ C:\WINDOWS\Tasks\SpeedyBackup reigistration schedule.job
2017-02-10 21:47 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-02-10 21:47 - 2014-09-12 16:11 - 00000000 ____D C:\FRST
2017-02-10 21:46 - 2016-02-15 14:41 - 00000000 ____D C:\Users\Randy\AppData\Local\{3A700C2C-1ED8-6094-7340-457C5728B9E4}
2017-02-10 21:46 - 2015-10-29 23:24 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-10 21:45 - 2016-02-02 10:45 - 00000000 ____D C:\Users\Randy\AppData\Local\Packages
2017-02-10 21:42 - 2016-05-14 18:42 - 00000284 _____ C:\WINDOWS\Tasks\{4E20A085-1B30-164D-0726-6688F373B3A8}.job
2017-02-10 21:41 - 2016-02-15 14:41 - 00000284 _____ C:\WINDOWS\Tasks\UpdateTask.job
2017-02-10 21:36 - 2013-01-03 20:56 - 00003416 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-02-10 21:36 - 2013-01-03 20:56 - 00003292 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-02-10 21:33 - 2015-10-29 23:21 - 00000000 ____D C:\WINDOWS\INF
2017-02-10 21:31 - 2012-03-01 11:01 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-10 21:24 - 2013-02-24 22:05 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-02-10 21:23 - 2016-02-02 10:17 - 01010686 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-10 21:21 - 2016-08-08 22:41 - 00000496 _____ C:\WINDOWS\Tasks\SpeedyBackup Startup.job
2017-02-10 21:19 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-02-10 21:18 - 2016-08-08 20:54 - 00000474 _____ C:\WINDOWS\Tasks\RegCure Pro Startup.job
2017-02-10 21:17 - 2016-08-06 19:12 - 00000432 _____ C:\WINDOWS\Tasks\DriverUpdate Startup.job
2017-02-10 21:16 - 2016-08-08 22:41 - 00000530 _____ C:\WINDOWS\Tasks\SpeedyPC Update Version3 Startup Task.job
2017-02-10 21:16 - 2016-08-08 22:41 - 00000522 _____ C:\WINDOWS\Tasks\SpeedyBackup reigistration schedule startup.job
2017-02-10 21:16 - 2016-01-15 09:52 - 00013920 _____ C:\WINDOWS\system32\Drivers\SWDUMon.sys
==================== Files in the root of some directories =======
2016-08-08 20:54 - 2017-02-10 21:18 - 0000115 _____ () C:\Users\Randy\AppData\Roaming\LogFile.txt
2016-06-19 06:26 - 2016-06-19 06:26 - 2049556 _____ () C:\Users\Randy\AppData\Roaming\sb0.dat
2016-06-10 06:41 - 2016-06-10 06:41 - 2049556 _____ () C:\Users\Randy\AppData\Roaming\sb203.dat
2016-02-17 11:41 - 2016-08-05 17:41 - 0000228 _____ () C:\Users\Randy\AppData\Roaming\WB.CFG
2015-11-15 15:05 - 2015-11-15 15:05 - 0002560 _____ () C:\Users\Randy\AppData\Local\uninstall.exe
2015-01-27 15:51 - 2015-01-27 15:51 - 0000057 _____ () C:\ProgramData\Ament.ini
Files to move or delete:
====================
C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe
C:\Windows\Tasks\{4E20A085-1B30-164D-0726-6688F373B3A8}.job
Some files in TEMP:
====================
2016-08-08 22:40 - 2016-08-08 22:41 - 8464000 _____ (SpeedyPC Software Inc.) C:\Users\Randy\AppData\Local\Temp\OMD5938.tmp.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-08-08 21:12
==================== End of FRST.txt ============================