Solved Windows has encountered a critical error and will restart in one minute.

Libertybrick

Posts: 16   +0
Hello. I've recently started getting this error: "Windows has encountered a critical problem and will restart automatically in one minute. Please save your work now".

This error was coming up randomly several hours after I booted my PC up until very recently, where it now appears to only happen when I open Chrome, and if I do so, all programs that are currently running also crash and the error pops up. In the event logs I've found this error appears to be the result of lsass.exe crashing. I've read other posts and researched about this error, and although it's nothing new, there seem to be very many causes of it.

I've also been getting crashes on shutdown followed by a restart, which have stopped happening the last few times I've shut down after I tried a scan with both Malwarebytes and RogueKiller, where a few items were found and deleted. This also appeared to limit the random crashing to only when I open Chrome, but it's still a problem I'd appreciate help with.

Here are the logs:
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02.01.2018
Ran by Brian (administrator) on BRIAN-PC (12-05-2018 05:40:36)
Running from C:\Users\Brian\Downloads
Loaded Profiles: Brian (Available Profiles: Brian)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool:

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1002984 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation)
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Policies\Explorer: []
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\MountPoints2: {96ff7f85-ae8e-11df-911b-806e6f6e6963} - D:\Autorun.exe
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\MountPoints2: {d6546ae7-2d7f-11e0-99a8-806e6f6e6963} - D:\Autorun.exe
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Winlogon: [Shell] C:\Windows\explorer.exe [2972672 2016-08-29] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1772568 2017-02-03] (Autodesk, Inc.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{8D135E9C-0C09-4E97-8D8F-71867BBEF404}: [NameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://msn.com/
SearchScopes: HKLM -> DefaultScope {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_171\bin\ssv.dll [2018-04-22] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-22] (Oracle Corporation)
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

FireFox:
========
FF ProfilePath: C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\iuwnxwqq.default [2018-05-12]
FF Homepage: Mozilla\Firefox\Profiles\iuwnxwqq.default -> hxxp://www.msn.com
FF Extension: (TLS 1.3 gradual roll-out) - C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\iuwnxwqq.default\features\{15e34442-bcce-440e-9bc4-85e05769868f}\tls13-rollout-bug1442042@mozilla.org.xpi [2018-05-04] [Legacy]
FF Plugin: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-22] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> msn.com
CHR Profile: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default [2018-05-12]
CHR Extension: (Slides) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-07]
CHR Extension: (YouTube) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-07]
CHR Extension: (Google Search) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-07]
CHR Extension: (Adobe Acrobat) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-05-04]
CHR Extension: (Sheets) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Google Docs Offline) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-14]
CHR Extension: (Kami - PDF and Document Markup) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljojpiodmlhoehoecppliohmplbgeij [2017-03-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-10]
CHR Extension: (Gmail) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-07]
CHR Extension: (Chrome Media Router) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-03]
CHR Profile: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-04-10]
CHR Profile: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\System Profile [2018-05-10]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fkkcgfbgohboipdhliafmacjnhjbhmim] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AdAppMgrSvc; C:\Program Files\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1374072 2018-03-10] (Autodesk Inc.)
S3 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.) [File not signed]
S3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [File not signed]
S3 FlexNet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe [1233376 2017-05-17] (Flexera Software LLC)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4707104 2018-03-27] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [103696 2016-11-14] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280864 2016-11-14] (Microsoft Corporation)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [2119688 2016-04-03] (Electronic Arts)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 anodlwf; C:\Windows\System32\DRIVERS\anodlwf.sys [12800 2009-03-06] ()
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [252808 2016-08-25] (Microsoft Corporation)
S3 MRVW147; C:\Windows\System32\DRIVERS\MRVW147.sys [529408 2008-08-20] (Marvell Semiconductor, Inc)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] ()
S3 netr28u; C:\Windows\System32\DRIVERS\Dnetr28u.sys [750592 2009-08-05] (Ralink Technology Corp.)
S3 rt70x86; C:\Windows\System32\DRIVERS\netr70.sys [306016 2010-04-27] (Ralink Technology Corp.)
S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [629760 2010-08-10] (Realtek Semiconductor Corporation ) [File not signed]
S4 secdrv; C:\Windows\system32\Drivers\secdrv.sys [12400 2017-08-14] (Macrovision Europe Ltd) [File not signed]
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [40448 2009-08-28] (Apple, Inc.) [File not signed]
S3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [193696 2015-08-27] (Jungo)
S3 xb1usb; C:\Windows\System32\DRIVERS\xb1usb.sys [38152 2016-02-22] (Microsoft Corporation)
S3 xusb21; C:\Windows\System32\DRIVERS\xusb21.sys [60160 2009-08-13] (Microsoft Corporation) [File not signed]
S2 atksgt; system32\DRIVERS\atksgt.sys [X]
S4 lirsgt; system32\DRIVERS\lirsgt.sys [X]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
S3 NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-05-12 05:40 - 2018-05-12 05:41 - 000011864 _____ C:\Users\Brian\Downloads\FRST.txt
2018-05-12 05:39 - 2018-05-12 05:39 - 001753600 _____ (Farbar) C:\Users\Brian\Downloads\FRST.exe
2018-05-12 05:37 - 2018-05-12 05:40 - 000000000 ____D C:\FRST
2018-05-12 05:37 - 2018-05-12 05:37 - 000000000 ____D C:\Users\Brian\Downloads\FRST-OlderVersion
2018-05-11 01:11 - 2018-05-11 01:11 - 000000000 ____D C:\Users\Brian\AppData\Local\RadeonInstaller
2018-05-11 01:11 - 2018-05-11 01:11 - 000000000 ____D C:\Program Files\AMD
2018-05-11 01:11 - 2018-05-11 01:11 - 000000000 ____D C:\AMD
2018-05-08 18:13 - 2018-05-08 18:14 - 000066588 _____ C:\Users\Brian\Downloads\cc_20180508_181253.reg
2018-05-08 17:51 - 2018-04-23 11:02 - 000348832 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-05-08 17:51 - 2018-04-22 17:12 - 004047040 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2018-05-08 17:51 - 2018-04-22 17:12 - 003958464 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-05-08 17:51 - 2018-04-22 17:11 - 000190144 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2018-05-08 17:51 - 2018-04-22 17:11 - 000190144 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-05-08 17:51 - 2018-04-22 17:11 - 000137920 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2018-05-08 17:51 - 2018-04-22 17:11 - 000137920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-05-08 17:51 - 2018-04-22 17:11 - 000067264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-05-08 17:51 - 2018-04-22 16:44 - 001310480 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 001417728 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 001063424 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000582144 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000377856 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:24 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-05-08 17:51 - 2018-04-22 16:23 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-05-08 17:51 - 2018-04-22 16:23 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-05-08 17:51 - 2018-04-22 16:23 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-05-08 17:51 - 2018-04-22 16:23 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-05-08 17:51 - 2018-04-22 16:22 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-05-08 17:51 - 2018-04-22 16:21 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-05-08 17:51 - 2018-04-22 16:21 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-05-08 17:51 - 2018-04-22 16:20 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-05-08 17:51 - 2018-04-22 16:19 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-05-08 17:51 - 2018-04-22 16:19 - 000124928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-05-08 17:51 - 2018-04-22 16:19 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-05-08 17:51 - 2018-04-22 16:18 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-05-08 17:51 - 2018-04-22 16:18 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-05-08 17:51 - 2018-04-22 16:18 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 00:24 - 020286464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-05-08 17:51 - 2018-04-22 00:16 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-05-08 17:51 - 2018-04-22 00:16 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-05-08 17:51 - 2018-04-22 00:04 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-05-08 17:51 - 2018-04-22 00:04 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-05-08 17:51 - 2018-04-22 00:03 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-05-08 17:51 - 2018-04-22 00:03 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-05-08 17:51 - 2018-04-22 00:02 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-05-08 17:51 - 2018-04-22 00:00 - 002295296 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-05-08 17:51 - 2018-04-21 23:57 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-05-08 17:51 - 2018-04-21 23:56 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-05-08 17:51 - 2018-04-21 23:55 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-05-08 17:51 - 2018-04-21 23:54 - 000661504 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-05-08 17:51 - 2018-04-21 23:54 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-05-08 17:51 - 2018-04-21 23:53 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-05-08 17:51 - 2018-04-21 23:53 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-05-08 17:51 - 2018-04-21 23:48 - 000668160 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-05-08 17:51 - 2018-04-21 23:45 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-05-08 17:51 - 2018-04-21 23:40 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-05-08 17:51 - 2018-04-21 23:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-05-08 17:51 - 2018-04-21 23:39 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-05-08 17:51 - 2018-04-21 23:37 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-05-08 17:51 - 2018-04-21 23:37 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-05-08 17:51 - 2018-04-21 23:35 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-05-08 17:51 - 2018-04-21 23:34 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-05-08 17:51 - 2018-04-21 23:31 - 004496896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-05-08 17:51 - 2018-04-21 23:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-05-08 17:51 - 2018-04-21 23:27 - 000696320 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-05-08 17:51 - 2018-04-21 23:27 - 000692224 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-05-08 17:51 - 2018-04-21 23:26 - 013679616 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-05-08 17:51 - 2018-04-21 23:26 - 002059776 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-05-08 17:51 - 2018-04-21 23:26 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-05-08 17:51 - 2018-04-21 23:08 - 002767872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-05-08 17:51 - 2018-04-21 23:04 - 001314304 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-05-08 17:51 - 2018-04-21 23:03 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-05-08 17:51 - 2018-04-18 08:51 - 000523776 _____ (Microsoft Corporation) C:\Windows\system32\hhctrl.ocx
2018-05-08 17:51 - 2018-04-18 08:51 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\hhsetup.dll
2018-05-08 17:51 - 2018-04-18 08:35 - 000015360 _____ (Microsoft Corporation) C:\Windows\hh.exe
2018-05-08 17:51 - 2018-04-11 09:36 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2018-05-08 17:51 - 2018-04-11 09:36 - 000142848 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2018-05-08 17:51 - 2018-04-10 12:44 - 000535616 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-05-08 17:51 - 2018-04-10 09:34 - 000167936 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2018-05-08 17:51 - 2018-04-10 09:33 - 001241600 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2018-05-08 17:51 - 2018-04-10 09:32 - 000487936 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2018-05-08 17:51 - 2018-04-10 09:00 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2018-05-08 17:51 - 2018-04-10 08:56 - 002404352 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-05-08 17:51 - 2018-04-10 08:52 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2018-05-08 17:51 - 2018-04-10 08:50 - 000314368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-05-08 17:51 - 2018-04-10 08:50 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-05-08 17:51 - 2018-04-07 09:42 - 000250560 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2018-05-08 17:51 - 2018-03-18 15:16 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-05-08 17:51 - 2018-03-14 10:16 - 002953216 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2018-05-08 17:51 - 2018-03-14 10:16 - 000174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2018-05-08 17:51 - 2018-03-14 10:10 - 000073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 002092032 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000573440 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000136192 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2018-05-08 17:51 - 2018-03-14 09:57 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2018-05-08 17:51 - 2018-03-14 09:57 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2018-05-04 14:21 - 2018-05-04 14:21 - 248421756 _____ C:\Users\Brian\Downloads\Registry Backup.reg
2018-05-04 13:14 - 2018-05-12 05:20 - 000000000 ____D C:\Users\Brian\AppData\Local\CrashDumps
2018-05-04 11:48 - 2018-05-11 22:08 - 000024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-05-04 11:44 - 2018-05-04 12:54 - 000000000 ____D C:\Program Files\RogueKiller
2018-05-04 11:44 - 2018-05-04 11:47 - 000000000 ____D C:\ProgramData\RogueKiller
2018-05-04 11:44 - 2018-05-04 11:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-05-04 10:58 - 2018-05-04 10:58 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\46781755.sys
2018-05-04 10:57 - 2018-05-04 10:57 - 000166848 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2018-05-03 22:33 - 2018-05-10 19:35 - 000000000 ____D C:\Users\Brian\Downloads\Tools
2018-04-27 03:31 - 2018-04-27 03:31 - 000054974 _____ C:\Users\Brian\Desktop\Addition_27-04-2018 03.31.36.txt
2018-04-27 03:31 - 2018-04-27 03:31 - 000039857 _____ C:\Users\Brian\Desktop\FRST_27-04-2018 03.31.36.txt
2018-04-22 18:57 - 2018-04-22 18:57 - 000000000 ____D C:\Program Files\Common Files\Java
2018-04-22 18:56 - 2018-04-22 18:56 - 000000000 ____D C:\Program Files\Common Files\Oracle
2018-04-18 16:49 - 2018-04-18 16:54 - 000000000 ____D C:\AdwCleaner
2018-04-18 16:14 - 2018-04-18 16:14 - 000023000 _____ C:\Users\Brian\Documents\energy-report.html
2018-04-18 05:38 - 2018-04-18 05:38 - 000000000 ____D C:\Program Files\Common Files\Services
2018-04-16 17:57 - 2018-04-16 17:57 - 000000000 ____D C:\Users\Brian\Documents\Bridges
2018-04-16 17:57 - 2018-04-16 17:57 - 000000000 ____D C:\Users\Brian\.phet
2018-04-14 14:31 - 2018-03-10 10:11 - 000340480 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll
2018-04-14 14:31 - 2018-03-09 11:18 - 000309440 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-04-14 14:31 - 2018-03-09 11:12 - 000111616 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-04-14 14:31 - 2018-03-09 11:12 - 000071680 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-04-14 14:31 - 2018-03-09 11:12 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-04-14 14:31 - 2018-03-09 11:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-04-14 14:31 - 2018-03-09 10:31 - 000034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-04-14 14:31 - 2018-03-06 11:13 - 000148160 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2018-04-14 14:31 - 2018-03-06 11:11 - 000184320 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
2018-04-14 14:31 - 2018-03-06 11:11 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000922944 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000066392 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000022360 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000019800 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000016216 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000015704 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-05-12 05:37 - 2017-01-18 15:43 - 000000000 ____D C:\Users\Brian\AppData\LocalLow\Mozilla
2018-05-12 05:27 - 2011-12-19 01:43 - 000000000 ____D C:\Users\Brian\AppData\Local\ElevatedDiagnostics
2018-05-12 05:24 - 2014-08-28 15:16 - 000000000 ____D C:\Windows\pss
2018-05-12 05:24 - 2009-07-13 21:34 - 000010208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-05-12 05:24 - 2009-07-13 21:34 - 000010208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-05-12 05:22 - 2009-07-13 21:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-05-11 21:04 - 2010-08-23 11:28 - 000773912 _____ C:\Windows\system32\PerfStringBackup.INI
2018-05-11 21:04 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\inf
2018-05-11 14:18 - 2015-02-09 16:20 - 000000000 ____D C:\Program Files\Steam
2018-05-10 20:47 - 2018-01-01 20:36 - 000000000 ____D C:\Users\Brian\Documents\Euro Truck Simulator 2
2018-05-09 17:14 - 2014-11-01 23:22 - 000000000 ____D C:\Users\Brian\AppData\Roaming\TS3Client
2018-05-09 17:11 - 2014-11-01 23:22 - 000000000 ____D C:\Program Files\TeamSpeak 3 Client
2018-05-09 16:07 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\rescache
2018-05-09 03:52 - 2009-07-13 21:33 - 000514600 _____ C:\Windows\system32\FNTCACHE.DAT
2018-05-09 03:45 - 2009-07-13 19:37 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-05-09 03:41 - 2016-06-30 01:39 - 000000000 ____D C:\Windows\system32\MRT
2018-05-09 03:35 - 2017-10-11 04:31 - 138711016 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-05-09 03:34 - 2016-06-30 01:39 - 138711016 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-05-09 03:21 - 2018-03-26 16:34 - 000000000 ____D C:\Users\Brian\Downloads\System Tools
2018-05-08 19:34 - 2010-09-02 00:28 - 000154048 _____ C:\Users\Brian\AppData\Local\GDIPFONTCACHEV1.DAT
2018-05-08 18:32 - 2010-09-02 00:08 - 000000000 ____D C:\Windows\Minidump
2018-05-06 15:25 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\registration
2018-05-04 13:50 - 2015-03-23 20:54 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service
2018-05-04 13:28 - 2017-01-09 23:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-05-04 11:33 - 2015-03-23 19:45 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2018-05-03 23:42 - 2009-07-13 19:37 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-05-03 23:31 - 2018-03-30 18:21 - 000000000 ___RD C:\Users\Brian\Google Drive
2018-05-03 21:40 - 2015-11-07 21:20 - 000002170 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-05-03 21:40 - 2015-11-07 21:20 - 000002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-05-03 18:52 - 2012-04-27 18:05 - 000000000 ____D C:\Users\Brian\AppData\Roaming\.minecraft
2018-05-03 17:05 - 2011-12-10 18:50 - 000007601 _____ C:\Users\Brian\AppData\Local\Resmon.ResmonCfg
2018-05-03 16:45 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\system32\NDF
2018-05-03 16:03 - 2018-03-30 17:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2018-05-03 01:23 - 2014-07-14 00:40 - 000000000 ____D C:\Users\Brian\AppData\Local\NBTExplorer
2018-05-01 23:41 - 2014-05-04 13:26 - 000000000 ____D C:\Users\Brian\AppData\Roaming\CorsixTH
2018-05-01 23:40 - 2014-05-04 13:26 - 000000000 ____D C:\Program Files\CorsixTH
2018-04-29 04:03 - 2015-02-09 16:20 - 000000000 ____D C:\Program Files\Common Files\Steam
2018-04-22 18:58 - 2017-04-02 16:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-04-22 18:58 - 2017-04-02 16:47 - 000000000 ____D C:\Program Files\Java
2018-04-22 18:56 - 2017-04-02 16:48 - 000096712 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2018-04-18 17:54 - 2009-07-13 21:53 - 000032590 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-04-18 16:17 - 2010-08-23 01:43 - 000000000 ____D C:\Users\Brian
2018-04-16 18:36 - 2016-06-22 20:35 - 000000000 ___RD C:\Users\Brian\Desktop\Games
2018-04-16 18:01 - 2017-12-18 21:00 - 000000000 ____D C:\Users\Brian\Documents\Digital Locker Backup
2018-04-16 17:58 - 2016-01-09 02:03 - 000000000 ____D C:\Users\Brian\Documents\Notepads
2018-04-16 15:51 - 2015-02-18 21:56 - 000000000 ____D C:\Users\Brian\AppData\Local\Steam
2018-04-13 00:30 - 2017-04-09 20:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat
2018-04-12 17:05 - 2018-04-10 20:54 - 000002238 _____ C:\Users\Brian\Desktop\Audacity.lnk
2018-04-12 15:17 - 2016-07-01 00:25 - 000000000 ____D C:\Windows\system32\appraiser

==================== Files in the root of some directories =======

2015-07-30 23:39 - 2015-07-30 23:39 - 000039997 _____ () C:\Users\Brian\AppData\Local\Perfmon.PerfmonCfg
2018-03-29 19:24 - 2018-03-29 19:24 - 000000832 _____ () C:\Users\Brian\AppData\Local\recently-used.xbel
2011-12-10 18:50 - 2018-05-03 17:05 - 000007601 _____ () C:\Users\Brian\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2018-05-11 22:06 - 2018-04-22 16:44 - 001310480 _____ (Microsoft Corporation) C:\Users\Brian\AppData\Local\Temp\dllnt_dump.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


safeboot: Network => The system is configured to boot to Safe Mode <==== ATTENTION

LastRegBack: 2018-05-08 19:22

==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02.01.2018
Ran by Brian (12-05-2018 05:42:38)
Running from C:\Users\Brian\Downloads
Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2010-08-23 08:42:40)
Boot Mode: Safe Mode (with Networking)
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2999710313-2874845586-1671460366-500 - Administrator - Disabled)
Brian (S-1-5-21-2999710313-2874845586-1671460366-1000 - Administrator - Enabled) => C:\Users\Brian
Guest (S-1-5-21-2999710313-2874845586-1671460366-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2999710313-2874845586-1671460366-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

2.4GHz Wireless N Client Installation Program (HKLM\...\{ECB9E368-1F6B-4253-B6CD-4833FB87225E}) (Version: 2.01.0012 - )
A360 Desktop (HKLM\...\{B65CD59E-A771-4354-AA4B-C3E01B496BCD}) (Version: 8.2.3.1800 - Autodesk)
ACA & MEP 2018 Object Enabler (HKLM\...\{28B89EEF-1004-0000-5002-CF3F3A09B77D}) (Version: 8.0.40.0 - Autodesk) Hidden
ACAD Private (HKLM\...\{28B89EEF-1001-0000-3002-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
Adobe Acrobat Reader DC (HKLM\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Audacity 2.1.0 (HKLM\...\Audacity_is1) (Version: 2.1.0 - Audacity Team)
AutoCAD 2014 - English (HKLM\...\{5783F2D7-D001-0000-0002-0060B0CE6BBA}) (Version: 19.1.108.0 - Autodesk) Hidden
AutoCAD 2014 - English (HKLM\...\{5783F2D7-D001-0409-2002-0060B0CE6BBA}) (Version: 19.1.18.0 - Autodesk) Hidden
AutoCAD 2014 Language Pack - English (HKLM\...\{5783F2D7-D001-0409-1002-0060B0CE6BBA}) (Version: 19.1.18.0 - Autodesk) Hidden
AutoCAD 2018 - English (HKLM\...\{28B89EEF-1001-0409-2002-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
AutoCAD 2018 (HKLM\...\{28B89EEF-1001-0000-0002-CF3F3A09B77D}) (Version: 22.0.72.0 - Autodesk) Hidden
AutoCAD 2018 Language Pack - English (HKLM\...\{28B89EEF-1001-0409-1002-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2018 (HKLM\...\{177AD7F6-9C77-4E50-BA53-B7259C5F282D}) (Version: 16.11.1.0 - Autodesk)
Autodesk App Manager (HKLM\...\{C070121A-C8C5-4D52-9A7D-D240631BD433}) (Version: 1.1.0 - Autodesk)
Autodesk App Manager 2016-2018 (HKLM\...\{20EC0CA2-346E-4660-9903-51B278DF15F6}) (Version: 2.4.0 - Autodesk)
Autodesk AutoCAD 2014 - English (HKLM\...\AutoCAD 2014 - English) (Version: 19.1.18.0 - Autodesk)
Autodesk AutoCAD 2014 - English SP1 (HKLM\...\AutoCAD 2014 - English SP1) (Version: 1 - Autodesk)
Autodesk AutoCAD 2018 - English (HKLM\...\AutoCAD 2018 - English) (Version: 22.0.49.0 - Autodesk)
Autodesk AutoCAD 2018.0.2 (HKLM\...\{b501e2dd-1001-0000-0002-2d66c6a9c722}) (Version: 22.0.72.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.8 (HKLM\...\{214D3370-746E-4886-8EAA-5769EB87D044}) (Version: 1.2.8.0 - Autodesk)
Autodesk Content Service (HKLM\...\{62F029AB-85F2-0000-866A-9FC0DD99DDBC}) (Version: 3.1.3.0 - Autodesk) Hidden
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.1.3.0 - Autodesk)
Autodesk Content Service Language Pack (HKLM\...\{62F029AB-85F2-0001-866A-9FC0DD99DDBC}) (Version: 3.1.3.0 - Autodesk) Hidden
Autodesk Desktop App (HKLM\...\Autodesk Desktop App) (Version: 7.0.9.191 - Autodesk)
Autodesk DWG TrueView 2015 - English (HKLM\...\DWG TrueView 2015 - English) (Version: 20.0.51.0 - Autodesk)
Autodesk Featured Apps (HKLM\...\{F732FEDA-7713-4428-934B-EF83B8DD65D0}) (Version: 1.1.0 - Autodesk)
Autodesk Featured Apps 2016-2018 (HKLM\...\{384C4B74-B749-4AB6-9367-4D51A6AA9CB8}) (Version: 2.4.0 - Autodesk)
Autodesk License Service (x86) - 5.1.5 (HKLM\...\{36AC22AD-5E3A-436E-ABF0-911257790BC6}) (Version: 5.1.5.0 - Autodesk)
Autodesk Material Library 2014 (HKLM\...\{644F9B19-A462-499C-BF4D-300ABC2A28B1}) (Version: 4.0.19.0 - Autodesk)
Autodesk Material Library 2018 (HKLM\...\{7847611E-92E9-4917-B395-71C91D523104}) (Version: 16.11.1.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2014 (HKLM\...\{51BF3210-B825-4092-8E0D-66D689916E02}) (Version: 4.0.19.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2018 (HKLM\...\{FCDED119-A969-4E48-8A32-D21AD6B03253}) (Version: 16.11.1.0 - Autodesk)
Autodesk ReCap (HKLM\...\{31ABA3F2-0000-1033-0002-111D43815377}) (Version: 1.0.43.13 - Autodesk) Hidden
Autodesk ReCap (HKLM\...\Autodesk ReCap) (Version: 1.0.43.13 - Autodesk)
Autodesk ReCap Language Pack-English (HKLM\...\{31ABA3F2-0010-1033-0002-111D43815377}) (Version: 1.0.43.13 - Autodesk) Hidden
Backup and Sync from Google (HKLM\...\{316376FE-CAC0-44AE-BD59-EBDBDEF1592F}) (Version: 3.41.9267.0638 - Google, Inc.)
Bridge Designer 2016 (2nd Edition) (remove only) (HKLM\...\Bridge Designer 2016 (2nd Edition)) (Version: - )
Brother MFL-Pro Suite MFC-J280W (HKLM\...\{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}) (Version: 1.0.19.0 - Brother Industries, Ltd.)
Cities XL (HKLM\...\Cities XL) (Version: 1.0.0 - Monte Cristo Games)
CorsixTH 0.61 (HKLM\...\CorsixTH) (Version: 0.61 - CorsixTH Team)
DWG TrueView 2015 - English (HKLM\...\{5783F2D7-E028-0409-0000-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
Emergency 3 (HKLM\...\{F9787326-0394-4467-A2EE-817C34F6C751}) (Version: 1.03.001 - )
FARO LS 1.1.501.0 (HKLM\...\{8F196892-666A-4A40-8587-6AE38F78A5C2}) (Version: 5.1.0.30630 - FARO Scanner Production)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Git version 2.13.3 (HKLM\...\Git_is1) (Version: 2.13.3 - The Git Development Community)
Google Chrome (HKLM\...\Google Chrome) (Version: 66.0.3359.139 - Google Inc.)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
HP ENVY 5660 series Basic Device Software (HKLM\...\{A6FB5EF8-1518-41F4-9408-81E2D5C36A67}) (Version: 34.2.117.50647 - Hewlett-Packard Co.)
HP ENVY 5660 series Help (HKLM\...\{607F50D9-40BD-4F17-A584-152F563293B4}) (Version: 34.0.0 - Hewlett Packard)
HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Hydrogen (Advanced drum machine for GNU/Linux) (HKLM\...\ON) (Version: 0.9.7-beta2 - Hydrogen Developers)
Java 8 Update 171 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
Lightworks (HKLM\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 14.0.0.0 - EditShare)
LMMS 1.1.3 (HKLM\...\LMMS) (Version: 1.1.3 - LMMS Developers)
Logger Pro 3.12 A20160921-0947_853e1db (HKLM\...\{55C9FFC1-E9A2-4E49-72B1-3831B5AD4AB8}) (Version: 5.182.945 - Vernier Software & Technology)
Malwarebytes version 3.4.5.2467 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.5.2467 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.11.25325 (HKLM\...\{404c9c27-8377-4fd1-b607-7ca635db4e49}) (Version: 14.11.25325.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 59.0.3 (x86 en-US) (HKLM\...\Mozilla Firefox 59.0.3 (x86 en-US)) (Version: 59.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 59.0.3.6691 - Mozilla)
MS Access 97 SP2 (HKLM\...\MS Access 97 SP2) (Version: - )
MSXML 4.0 SP2 Parser and SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
NETGEAR WN311T Wireless PCI Adapter (HKLM\...\{F7321BC6-51AD-4299-9CE9-462DBC141C93}) (Version: - )
Network Addon Mod (HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Network Addon Mod) (Version: 35 - The NAM Team)
Notepad++ (HKLM\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
OpenRCT2 Launcher version 0.0.7 (HKLM\...\{D71D87CE-20E7-4DB6-A0D8-E6DE57051B35}_is1) (Version: 0.0.7 - OpenRCT2)
OpenTTD 1.8.0 (HKLM\...\OpenTTD) (Version: 1.8.0 - OpenTTD)
Origin (HKLM\...\Origin) (Version: 9.1.10.2728 - Electronic Arts, Inc.)
paint.net (HKLM\...\{E8FA8815-3817-4128-A814-E2EAC456ADEF}) (Version: 4.0.21 - dotPDN LLC)
Photo Story 3 for Windows (HKLM\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.11 - Microsoft Corporation)
Product Improvement Study for HP ENVY 5660 series (HKLM\...\{18B597E2-8F59-4969-B932-91DB7EB0C27D}) (Version: 34.2.117.50647 - Hewlett-Packard Co.)
RCT3 Soaked (HKLM\...\{EA926717-CE5A-4CB4-AB21-9E6E9565A458}) (Version: 1.00.000 - )
RNX-N250PC2 Driver (HKLM\...\{871F397C-447E-43B2-B01A-3E656F3D61B6}) (Version: 1.00.0000 - )
RogueKiller version 12.12.16.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.12.16.0 - Adlice Software)
Roller Coaster Tycoon 2 (HKLM\...\Roller Coaster Tycoon 2) (Version: - )
RollerCoaster Tycoon 2 (HKLM\...\{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}) (Version: - )
RollerCoaster Tycoon 2: Time Twister (HKLM\...\{BA1E1AFD-D1F2-4C52-88C3-186FC5E61604}) (Version: 1.00.000 - )
RollerCoaster Tycoon 2: Wacky Worlds (HKLM\...\{B1AD83A0-DC92-41E3-B111-E9472349768C}) (Version: - )
RollerCoaster Tycoon Deluxe (HKLM\...\{924EAD66-F854-4605-8493-696DD59A113B}) (Version: 1.00.000 - )
RollerCoaster Tycoon® 3 (HKLM\...\{907B4640-266B-4A21-92FB-CD1A86CD0F63}) (Version: 1.00.000 - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
SimCity 2000 Special Edition (HKLM\...\SimCity 2000 Special Edition_is1) (Version: - GOG.com)
SimCity 3000 (HKLM\...\SimCity 3000) (Version: - )
SimCity 4 Deluxe (HKLM\...\{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}) (Version: - )
SimCity™ (HKLM\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 1.0.0.0 - Electronic Arts)
SimSafari (HKLM\...\SimSafariUninstall) (Version: - )
SketchUp Import for AutoCAD 2014 (HKLM\...\{644E9589-F73A-49A4-AC61-A953B9DE5669}) (Version: 1.1.0 - Autodesk)
SmartMusic (HKLM\...\{42B1BDFC-9AF7-42C4-BC3C-EAED79D4DBEB}) (Version: 1.1.2204 - MakeMusic, Inc.)
Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
swMSM (HKLM\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Theme Hospital (HKLM\...\Theme Hospital_is1) (Version: - GOG.com)
Traffic Simulator Configuration Tool (HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Traffic Simulator Configuration Tool) (Version: - )
Tycoon City - New York (HKLM\...\{A5101403-2C42-40E0-8D9E-5E49E7C3B89E}) (Version: 1.00.000 - )
VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
WinRAR 4.20 (32-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Zoo Tycoon: Complete Collection (HKLM\...\Zoo Tycoon 1.0) (Version: - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2015 - English\dwgviewr.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2015 - English\en-US\dwgviewrficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{6A221957-2D85-42A7-8E19-BE33950D1DEB}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{6d05bf60-3eaf-4a97-87c5-10cce505435b}\localserver32 -> C:\Users\Brian\AppData\Local\Temp\{9c0ba3c1-2b67-45eb-bf69-bed9658d28d2}\IDriver.NonElevated.exe => No File
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{7DE1BE5C-CEBA-4F1D-ACBC-9CE11EE9A2A1}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{9AAF0EB6-42D8-46C1-A2EF-679511B37A0D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2018\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{B6EB585B-B467-4E46-A9C7-48D7D6FD26CB}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2018\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{BD0DEB94-63DB-4392-9420-6EEE05094B1F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2014\en-US\acadficn.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2018-04-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2018-04-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2018-04-12] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2017-02-02] (Autodesk, Inc.)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2017-02-02] (Autodesk)
ContextMenuHandlers1: [ANotepad++] -> {00F3C2EC-A6EE-11DE-A03A-EF8F55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2014-05-12] ()
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu32.dll [2018-04-12] (Google)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu32.dll [2018-04-12] (Google)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {11F243B2-2411-4E64-8EFD-30BFE038CC7E} - System32\Tasks\{3E78A3A7-EFBB-48DD-B3AF-19FD801C1792} => C:\Program Files\Google\Chrome\Application\chrome.exe
Task: {37DE0088-61A2-4AA6-90BC-A7FD0BCEA41C} - System32\Tasks\HPCustPartic.exe_{762481A1-212E-47A4-9AC2-1E733D0C91D4} => C:\Program Files\HP\HP ENVY 5660 series\Bin\HPCustPartic.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {4A77D819-3F29-4582-A4C6-DA9A9413749F} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {80CBADC1-3A90-4393-9F3C-372EEBE38E32} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {91EA052A-7798-4876-8384-50B209A35B80} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {94B7CA64-83EC-4F6A-853C-A8984FC3189E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {A66CB07D-5764-4FF3-AA9A-28E1B76C34D6} - System32\Tasks\HP AR Program Upload - 06ff241776ee4cceb938b15f1421550aaa4d4d390a554ccda27d2eeab85f184d => C:\Program Files\HP\HP ENVY 5660 series\bin\HPRewards.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {ADF623AC-AF47-4DE2-9E3A-91494FE56E36} - System32\Tasks\HPCustParticipation HP ENVY 5660 series => C:\Program Files\HP\HP ENVY 5660 series\Bin\HPCustPartic.exe [2014-08-22] (Hewlett-Packard Development Company, LP)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\Brian\Documents\SimCity 4\Plugins\Network Addon Mod\Traffic Simulator Configuration Tool.lnk -> C:\Program Files\Traffic Simulator Configuration Tool\TSCT.bat ()
Shortcut: C:\Users\Brian\Desktop\Games\Games\SimCity 4\Mods and Tools\Traffic Simulator Configuration Tool.lnk -> C:\Program Files\Traffic Simulator Configuration Tool\TSCT.bat ()
Shortcut: C:\Users\Brian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxis\SimCity 4\Traffic Simulator Configuration Tool.lnk -> C:\Program Files\Traffic Simulator Configuration Tool\TSCT.bat ()

==================== Loaded Modules (Whitelisted) ==============

2013-09-05 01:14 - 2013-09-05 01:14 - 004300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:45 - 2010-10-20 16:45 - 008801120 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2014-05-12 02:49 - 2014-05-12 02:49 - 000260608 _____ () C:\Program Files\Notepad++\NppShell_06.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1"

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:04 - 2009-06-10 14:39 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Brian\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: a2AntiMalware => 2
MSCONFIG\Services: Apple Mobile Device => 3
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: BstHdLogRotatorSvc => 2
MSCONFIG\Services: GfExperienceService => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: NvStreamSvc => 2
MSCONFIG\Services: PDFProFiltSrvPP => 2
MSCONFIG\Services: Stereo Service => 2
MSCONFIG\Services: WinNetSvc2 => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^2.4GHz Wireless N Client Utility.lnk => C:\Windows\pss\2.4GHz Wireless N Client Utility.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Brian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP ENVY 5660 series.lnk => C:\Windows\pss\Monitor Ink Alerts - HP ENVY 5660 series.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AE43EAC771ADEE2FEEB86AD6759833F2448FAA11._service_run => "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=service /prefetch:8
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\Brian\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: Autodesk Desktop App => "C:\Program Files\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
MSCONFIG\startupreg: Autodesk Sync => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: BrMfcWnd => C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
MSCONFIG\startupreg: BrStsMon00 => C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: ControlCenter3 => C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
MSCONFIG\startupreg: ControlCenter4 => C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: IndexSearch => "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: Malwarebytes Anti-Exploit => C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe
MSCONFIG\startupreg: NvBackend => "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
MSCONFIG\startupreg: Nvtmru => "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: Steam => "C:\Program Files\Steam\steam.exe" -silent
MSCONFIG\startupreg: WN311T.exe => C:\Program Files\NETGEAR\WN311T\WN311T.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

29-04-2018 17:06:40 Windows Update
02-05-2018 21:57:37 Windows Update
03-05-2018 23:54:23 Microsoft Hotfix
06-05-2018 15:32:30 Windows Update
09-05-2018 03:30:28 Windows Update
10-05-2018 19:47:51 Revo Uninstaller's restore point - Akamai NetSession Interface
10-05-2018 19:52:15 Revo Uninstaller's restore point - Caesium version 1.7.0
11-05-2018 21:01:37 Windows Update
11-05-2018 21:40:51 Restore Point #1

==================== Faulty Device Manager Devices =============

Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Microsoft Virtual WiFi Miniport Adapter #2
Description: Microsoft Virtual WiFi Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (05/12/2018 05:20:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 66.0.3359.139, time stamp: 0x5ae13fc6
Faulting module name: USER32.dll, version: 6.1.7601.23594, time stamp: 0x58249e2b
Exception code: 0xc0000005
Fault offset: 0x0001636c
Faulting process id: 0x1038
Faulting application start time: 0x01d3e9eb8cb941f0
Faulting application path: C:\Program Files\Google\Chrome\Application\chrome.exe
Faulting module path: C:\Windows\system32\USER32.dll
Report Id: d6336810-55de-11e8-a331-001d60e9db68

Error: (05/12/2018 05:20:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 66.0.3359.139, time stamp: 0x5ae13fc6
Faulting module name: ntdll.dll, version: 6.1.7601.24117, time stamp: 0x5add1df9
Exception code: 0xc0000005
Fault offset: 0x000529df
Faulting process id: 0x1688
Faulting application start time: 0x01d3e9eb8ccc4cf0
Faulting application path: C:\Program Files\Google\Chrome\Application\chrome.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: d632cbd0-55de-11e8-a331-001d60e9db68

Error: (05/12/2018 05:20:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: software_reporter_tool.exe, version: 29.154.200.0, time stamp: 0x5ae90712
Faulting module name: software_reporter_tool.exe, version: 29.154.200.0, time stamp: 0x5ae90712
Exception code: 0xc0000005
Fault offset: 0x00105e3b
Faulting process id: 0x1554
Faulting application start time: 0x01d3e9eb95d5b750
Faulting application path: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\SwReporter\29.154.200\software_reporter_tool.exe
Faulting module path: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\SwReporter\29.154.200\software_reporter_tool.exe
Report Id: d63319f0-55de-11e8-a331-001d60e9db68

Error: (05/12/2018 05:20:20 AM) (Source: Wininit) (EventID: 1015) (User: )
Description: A critical system process, C:\Windows\system32\lsass.exe, failed with status code c0000005. The machine must now be restarted.

Error: (05/12/2018 05:20:19 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 59.0.3.6691, time stamp: 0x5ae39f1a
Faulting module name: user32.dll, version: 6.1.7601.23594, time stamp: 0x58249e2b
Exception code: 0xc0000005
Fault offset: 0x0001636c
Faulting process id: 0xe30
Faulting application start time: 0x01d3e9ea72356f80
Faulting application path: C:\Program Files\Mozilla Firefox\firefox.exe
Faulting module path: C:\Windows\system32\user32.dll
Report Id: d58d8b20-55de-11e8-a331-001d60e9db68

Error: (05/12/2018 05:20:19 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: lsass.exe, version: 6.1.7601.24117, time stamp: 0x5add1847
Faulting module name: ntdll.dll, version: 6.1.7601.24117, time stamp: 0x5add1df9
Exception code: 0xc0000005
Fault offset: 0x000315f8
Faulting process id: 0x1f8
Faulting application start time: 0x01d3e9ea317032a0
Faulting application path: C:\Windows\system32\lsass.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: d58ca0c0-55de-11e8-a331-001d60e9db68

Error: (05/11/2018 11:42:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: software_reporter_tool.exe, version: 29.154.200.0, time stamp: 0x5ae90712
Faulting module name: ntdll.dll, version: 6.1.7601.24117, time stamp: 0x5add1df9
Exception code: 0x80000003
Fault offset: 0x000c3b65
Faulting process id: 0xf10
Faulting application start time: 0x01d3e9bc4f3dbd30
Faulting application path: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\SwReporter\29.154.200\software_reporter_tool.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 943a5a10-55af-11e8-81d3-001d60e9db68

Error: (05/11/2018 11:41:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 66.0.3359.139, time stamp: 0x5ae13fc6
Faulting module name: KERNELBASE.dll, version: 6.1.7601.24117, time stamp: 0x5add1e31
Exception code: 0xc0000409
Fault offset: 0x00020706
Faulting process id: 0xa3c
Faulting application start time: 0x01d3e9bc482758d0
Faulting application path: C:\Program Files\Google\Chrome\Application\chrome.exe
Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report Id: 8e46ea10-55af-11e8-81d3-001d60e9db68

Error: (05/11/2018 11:41:53 PM) (Source: Wininit) (EventID: 1015) (User: )
Description: A critical system process, C:\Windows\system32\lsass.exe, failed with status code 255. The machine must now be restarted.

Error: (05/11/2018 11:41:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: lsass.exe, version: 6.1.7601.24117, time stamp: 0x5add1847
Faulting module name: ntdll.dll, version: 6.1.7601.24117, time stamp: 0x5add1df9
Exception code: 0x40010006
Fault offset: 0x00084df0
Faulting process id: 0x1f8
Faulting application start time: 0x01d3e9ada9033ca0
Faulting application path: C:\Windows\system32\lsass.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 8d3b0fc0-55af-11e8-81d3-001d60e9db68


System errors:
=============
Error: (05/12/2018 05:39:28 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (05/12/2018 05:39:28 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (05/12/2018 05:39:28 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (05/12/2018 05:28:19 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (05/12/2018 05:28:19 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (05/12/2018 05:28:17 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (05/12/2018 05:28:05 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (05/12/2018 05:28:05 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (05/12/2018 05:28:05 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (05/12/2018 05:27:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The PnP-X IP Bus Enumerator service depends on the Function Discovery Provider Host service which failed to start because of the following error:
The dependency service or group failed to start.


CodeIntegrity:
===================================
Date: 2016-07-25 16:22:14.208
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-25 01:23:19.251
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-25 01:10:09.306
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 21:23:12.036
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 15:21:33.606
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 15:02:29.721
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 13:17:26.948
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 05:33:00.907
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 04:11:50.829
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 01:40:43.572
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4000+
Percentage of memory in use: 32%
Total physical RAM: 3071.3 MB
Available physical RAM: 2058.34 MB
Total Virtual: 7675.66 MB
Available Virtual: 6722.09 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:372.61 GB) (Free:74.76 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (RCT3_WILD) (CDROM) (Total:0.64 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 372.6 GB) (Disk ID: 00000001)
Partition 1: (Active) - (Size=372.6 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================
 
Welcome aboard

Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

====================================================

From your log:

safeboot: Network => The system is configured to boot to Safe Mode <==== ATTENTION
Why is your computer configured to start in safe mode?
 
Hi Broni. Sorry for the delay.
I forgot to mention I was starting in safe mode to see if that would stop the error, but it was still crashing. I guess I didn't change it back during the scan. Do you want the logs in normal mode?
 
Here you go:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13.05.2018
Ran by Brian (administrator) on BRIAN-PC (12-05-2018 21:24:40)
Running from C:\Users\Brian\Desktop
Loaded Profiles: Brian (Available Profiles: Brian)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1002984 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation)
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Policies\Explorer: []
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\MountPoints2: {96ff7f85-ae8e-11df-911b-806e6f6e6963} - D:\Autorun.exe
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Winlogon: [Shell] C:\Windows\explorer.exe [2972672 2016-08-29] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1772568 2017-02-03] (Autodesk, Inc.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{8D135E9C-0C09-4E97-8D8F-71867BBEF404}: [NameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://msn.com/
SearchScopes: HKLM -> DefaultScope {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_171\bin\ssv.dll [2018-04-22] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-22] (Oracle Corporation)
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

FireFox:
========
FF ProfilePath: C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\iuwnxwqq.default [2018-05-12]
FF Homepage: Mozilla\Firefox\Profiles\iuwnxwqq.default -> hxxp://www.msn.com
FF Plugin: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-22] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> msn.com
CHR Profile: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default [2018-05-12]
CHR Extension: (Slides) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-07]
CHR Extension: (YouTube) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-07]
CHR Extension: (Google Search) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-07]
CHR Extension: (Adobe Acrobat) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-05-04]
CHR Extension: (Sheets) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Google Docs Offline) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-14]
CHR Extension: (Kami - PDF and Document Markup) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljojpiodmlhoehoecppliohmplbgeij [2017-03-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-10]
CHR Extension: (Gmail) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-07]
CHR Extension: (Chrome Media Router) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-03]
CHR Profile: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-04-10]
CHR Profile: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\System Profile [2018-05-10]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fkkcgfbgohboipdhliafmacjnhjbhmim] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AdAppMgrSvc; C:\Program Files\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1374072 2018-03-10] (Autodesk Inc.)
S3 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.) [File not signed]
S3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [File not signed]
S3 FlexNet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe [1233376 2017-05-17] (Flexera Software LLC)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4707104 2018-03-27] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [103696 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280864 2016-11-14] (Microsoft Corporation)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [2119688 2016-04-03] (Electronic Arts)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 anodlwf; C:\Windows\System32\DRIVERS\anodlwf.sys [12800 2009-03-06] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [252808 2016-08-25] (Microsoft Corporation)
S3 MRVW147; C:\Windows\System32\DRIVERS\MRVW147.sys [529408 2008-08-20] (Marvell Semiconductor, Inc)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] ()
S3 netr28u; C:\Windows\System32\DRIVERS\Dnetr28u.sys [750592 2009-08-05] (Ralink Technology Corp.)
S3 rt70x86; C:\Windows\System32\DRIVERS\netr70.sys [306016 2010-04-27] (Ralink Technology Corp.)
S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [629760 2010-08-10] (Realtek Semiconductor Corporation ) [File not signed]
S4 secdrv; C:\Windows\system32\Drivers\secdrv.sys [12400 2017-08-14] (Macrovision Europe Ltd) [File not signed]
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [40448 2009-08-28] (Apple, Inc.) [File not signed]
R3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [193696 2015-08-27] (Jungo)
S3 xb1usb; C:\Windows\System32\DRIVERS\xb1usb.sys [38152 2016-02-22] (Microsoft Corporation)
S3 xusb21; C:\Windows\System32\DRIVERS\xusb21.sys [60160 2009-08-13] (Microsoft Corporation) [File not signed]
S2 atksgt; system32\DRIVERS\atksgt.sys [X]
S4 lirsgt; system32\DRIVERS\lirsgt.sys [X]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
S3 NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-05-12 21:24 - 2018-05-12 21:26 - 000011896 _____ C:\Users\Brian\Desktop\FRST.txt
2018-05-12 21:24 - 2018-05-12 21:24 - 000000000 ____D C:\Users\Brian\Desktop\FRST-OlderVersion
2018-05-12 21:21 - 2018-05-12 21:24 - 001765376 _____ (Farbar) C:\Users\Brian\Desktop\FRST.exe
2018-05-12 05:42 - 2018-05-12 05:48 - 000040734 _____ C:\Users\Brian\Downloads\Addition.txt
2018-05-12 05:40 - 2018-05-12 05:48 - 000041809 _____ C:\Users\Brian\Downloads\FRST.txt
2018-05-12 05:39 - 2018-05-12 05:39 - 001753600 _____ (Farbar) C:\Users\Brian\Downloads\FRST.exe
2018-05-12 05:37 - 2018-05-12 21:24 - 000000000 ____D C:\FRST
2018-05-12 05:37 - 2018-05-12 05:37 - 000000000 ____D C:\Users\Brian\Downloads\FRST-OlderVersion
2018-05-11 01:11 - 2018-05-11 01:11 - 000000000 ____D C:\Users\Brian\AppData\Local\RadeonInstaller
2018-05-11 01:11 - 2018-05-11 01:11 - 000000000 ____D C:\Program Files\AMD
2018-05-11 01:11 - 2018-05-11 01:11 - 000000000 ____D C:\AMD
2018-05-08 18:13 - 2018-05-08 18:14 - 000066588 _____ C:\Users\Brian\Downloads\cc_20180508_181253.reg
2018-05-08 17:51 - 2018-04-23 11:02 - 000348832 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-05-08 17:51 - 2018-04-22 17:12 - 004047040 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2018-05-08 17:51 - 2018-04-22 17:12 - 003958464 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-05-08 17:51 - 2018-04-22 17:11 - 000190144 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2018-05-08 17:51 - 2018-04-22 17:11 - 000190144 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-05-08 17:51 - 2018-04-22 17:11 - 000137920 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2018-05-08 17:51 - 2018-04-22 17:11 - 000137920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-05-08 17:51 - 2018-04-22 17:11 - 000067264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-05-08 17:51 - 2018-04-22 16:44 - 001310480 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 001417728 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 001063424 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000582144 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000377856 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:24 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-05-08 17:51 - 2018-04-22 16:23 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-05-08 17:51 - 2018-04-22 16:23 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-05-08 17:51 - 2018-04-22 16:23 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-05-08 17:51 - 2018-04-22 16:23 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-05-08 17:51 - 2018-04-22 16:22 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-05-08 17:51 - 2018-04-22 16:21 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-05-08 17:51 - 2018-04-22 16:21 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-05-08 17:51 - 2018-04-22 16:20 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-05-08 17:51 - 2018-04-22 16:19 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-05-08 17:51 - 2018-04-22 16:19 - 000124928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-05-08 17:51 - 2018-04-22 16:19 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-05-08 17:51 - 2018-04-22 16:18 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-05-08 17:51 - 2018-04-22 16:18 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-05-08 17:51 - 2018-04-22 16:18 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 00:24 - 020286464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-05-08 17:51 - 2018-04-22 00:16 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-05-08 17:51 - 2018-04-22 00:16 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-05-08 17:51 - 2018-04-22 00:04 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-05-08 17:51 - 2018-04-22 00:04 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-05-08 17:51 - 2018-04-22 00:03 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-05-08 17:51 - 2018-04-22 00:03 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-05-08 17:51 - 2018-04-22 00:02 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-05-08 17:51 - 2018-04-22 00:00 - 002295296 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-05-08 17:51 - 2018-04-21 23:57 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-05-08 17:51 - 2018-04-21 23:56 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-05-08 17:51 - 2018-04-21 23:55 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-05-08 17:51 - 2018-04-21 23:54 - 000661504 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-05-08 17:51 - 2018-04-21 23:54 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-05-08 17:51 - 2018-04-21 23:53 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-05-08 17:51 - 2018-04-21 23:53 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-05-08 17:51 - 2018-04-21 23:48 - 000668160 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-05-08 17:51 - 2018-04-21 23:45 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-05-08 17:51 - 2018-04-21 23:40 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-05-08 17:51 - 2018-04-21 23:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-05-08 17:51 - 2018-04-21 23:39 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-05-08 17:51 - 2018-04-21 23:37 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-05-08 17:51 - 2018-04-21 23:37 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-05-08 17:51 - 2018-04-21 23:35 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-05-08 17:51 - 2018-04-21 23:34 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-05-08 17:51 - 2018-04-21 23:31 - 004496896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-05-08 17:51 - 2018-04-21 23:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-05-08 17:51 - 2018-04-21 23:27 - 000696320 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-05-08 17:51 - 2018-04-21 23:27 - 000692224 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-05-08 17:51 - 2018-04-21 23:26 - 013679616 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-05-08 17:51 - 2018-04-21 23:26 - 002059776 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-05-08 17:51 - 2018-04-21 23:26 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-05-08 17:51 - 2018-04-21 23:08 - 002767872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-05-08 17:51 - 2018-04-21 23:04 - 001314304 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-05-08 17:51 - 2018-04-21 23:03 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-05-08 17:51 - 2018-04-18 08:51 - 000523776 _____ (Microsoft Corporation) C:\Windows\system32\hhctrl.ocx
2018-05-08 17:51 - 2018-04-18 08:51 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\hhsetup.dll
2018-05-08 17:51 - 2018-04-18 08:35 - 000015360 _____ (Microsoft Corporation) C:\Windows\hh.exe
2018-05-08 17:51 - 2018-04-11 09:36 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2018-05-08 17:51 - 2018-04-11 09:36 - 000142848 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2018-05-08 17:51 - 2018-04-10 12:44 - 000535616 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-05-08 17:51 - 2018-04-10 09:34 - 000167936 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2018-05-08 17:51 - 2018-04-10 09:33 - 001241600 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2018-05-08 17:51 - 2018-04-10 09:32 - 000487936 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2018-05-08 17:51 - 2018-04-10 09:00 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2018-05-08 17:51 - 2018-04-10 08:56 - 002404352 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-05-08 17:51 - 2018-04-10 08:52 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2018-05-08 17:51 - 2018-04-10 08:50 - 000314368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-05-08 17:51 - 2018-04-10 08:50 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-05-08 17:51 - 2018-04-07 09:42 - 000250560 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2018-05-08 17:51 - 2018-03-18 15:16 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-05-08 17:51 - 2018-03-14 10:16 - 002953216 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2018-05-08 17:51 - 2018-03-14 10:16 - 000174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2018-05-08 17:51 - 2018-03-14 10:10 - 000073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 002092032 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000573440 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000136192 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2018-05-08 17:51 - 2018-03-14 09:57 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2018-05-08 17:51 - 2018-03-14 09:57 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2018-05-04 14:21 - 2018-05-04 14:21 - 248421756 _____ C:\Users\Brian\Downloads\Registry Backup.reg
2018-05-04 13:14 - 2018-05-12 05:20 - 000000000 ____D C:\Users\Brian\AppData\Local\CrashDumps
2018-05-04 11:48 - 2018-05-11 22:08 - 000024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-05-04 11:44 - 2018-05-04 12:54 - 000000000 ____D C:\Program Files\RogueKiller
2018-05-04 11:44 - 2018-05-04 11:47 - 000000000 ____D C:\ProgramData\RogueKiller
2018-05-04 11:44 - 2018-05-04 11:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-05-04 10:58 - 2018-05-04 10:58 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\46781755.sys
2018-05-04 10:57 - 2018-05-04 10:57 - 000166848 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2018-05-03 22:33 - 2018-05-10 19:35 - 000000000 ____D C:\Users\Brian\Downloads\Tools
2018-04-27 03:31 - 2018-04-27 03:31 - 000054974 _____ C:\Users\Brian\Downloads\Addition_27-04-2018 03.31.36.txt
2018-04-27 03:31 - 2018-04-27 03:31 - 000039857 _____ C:\Users\Brian\Downloads\FRST_27-04-2018 03.31.36.txt
2018-04-22 18:57 - 2018-04-22 18:57 - 000000000 ____D C:\Program Files\Common Files\Java
2018-04-22 18:56 - 2018-04-22 18:56 - 000000000 ____D C:\Program Files\Common Files\Oracle
2018-04-18 16:49 - 2018-04-18 16:54 - 000000000 ____D C:\AdwCleaner
2018-04-18 16:14 - 2018-04-18 16:14 - 000023000 _____ C:\Users\Brian\Documents\energy-report.html
2018-04-18 05:38 - 2018-04-18 05:38 - 000000000 ____D C:\Program Files\Common Files\Services
2018-04-16 17:57 - 2018-04-16 17:57 - 000000000 ____D C:\Users\Brian\Documents\Bridges
2018-04-16 17:57 - 2018-04-16 17:57 - 000000000 ____D C:\Users\Brian\.phet
2018-04-14 14:31 - 2018-03-10 10:11 - 000340480 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll
2018-04-14 14:31 - 2018-03-09 11:18 - 000309440 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-04-14 14:31 - 2018-03-09 11:12 - 000111616 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-04-14 14:31 - 2018-03-09 11:12 - 000071680 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-04-14 14:31 - 2018-03-09 11:12 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-04-14 14:31 - 2018-03-09 11:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-04-14 14:31 - 2018-03-09 10:31 - 000034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-04-14 14:31 - 2018-03-06 11:13 - 000148160 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2018-04-14 14:31 - 2018-03-06 11:11 - 000184320 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
2018-04-14 14:31 - 2018-03-06 11:11 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000922944 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000066392 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000022360 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000019800 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000016216 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000015704 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-05-12 21:22 - 2017-01-18 15:43 - 000000000 ____D C:\Users\Brian\AppData\LocalLow\Mozilla
2018-05-12 21:21 - 2015-02-09 16:20 - 000000000 ____D C:\Program Files\Steam
2018-05-12 19:22 - 2009-07-13 21:34 - 000010208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-05-12 19:22 - 2009-07-13 21:34 - 000010208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-05-12 19:14 - 2009-07-13 21:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-05-12 05:27 - 2011-12-19 01:43 - 000000000 ____D C:\Users\Brian\AppData\Local\ElevatedDiagnostics
2018-05-12 05:24 - 2014-08-28 15:16 - 000000000 ____D C:\Windows\pss
2018-05-11 21:04 - 2010-08-23 11:28 - 000773912 _____ C:\Windows\system32\PerfStringBackup.INI
2018-05-11 21:04 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\inf
2018-05-10 20:47 - 2018-01-01 20:36 - 000000000 ____D C:\Users\Brian\Documents\Euro Truck Simulator 2
2018-05-09 17:14 - 2014-11-01 23:22 - 000000000 ____D C:\Users\Brian\AppData\Roaming\TS3Client
2018-05-09 17:11 - 2014-11-01 23:22 - 000000000 ____D C:\Program Files\TeamSpeak 3 Client
2018-05-09 16:07 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\rescache
2018-05-09 03:52 - 2009-07-13 21:33 - 000514600 _____ C:\Windows\system32\FNTCACHE.DAT
2018-05-09 03:45 - 2009-07-13 19:37 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-05-09 03:41 - 2016-06-30 01:39 - 000000000 ____D C:\Windows\system32\MRT
2018-05-09 03:35 - 2017-10-11 04:31 - 138711016 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-05-09 03:34 - 2016-06-30 01:39 - 138711016 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-05-09 03:21 - 2018-03-26 16:34 - 000000000 ____D C:\Users\Brian\Downloads\System Tools
2018-05-08 19:34 - 2010-09-02 00:28 - 000154048 _____ C:\Users\Brian\AppData\Local\GDIPFONTCACHEV1.DAT
2018-05-08 18:32 - 2010-09-02 00:08 - 000000000 ____D C:\Windows\Minidump
2018-05-06 15:25 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\registration
2018-05-04 13:50 - 2015-03-23 20:54 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service
2018-05-04 13:28 - 2017-01-09 23:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-05-04 11:33 - 2015-03-23 19:45 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2018-05-03 23:42 - 2009-07-13 19:37 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-05-03 23:31 - 2018-03-30 18:21 - 000000000 ___RD C:\Users\Brian\Google Drive
2018-05-03 21:40 - 2015-11-07 21:20 - 000002170 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-05-03 21:40 - 2015-11-07 21:20 - 000002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-05-03 18:52 - 2012-04-27 18:05 - 000000000 ____D C:\Users\Brian\AppData\Roaming\.minecraft
2018-05-03 17:05 - 2011-12-10 18:50 - 000007601 _____ C:\Users\Brian\AppData\Local\Resmon.ResmonCfg
2018-05-03 16:45 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\system32\NDF
2018-05-03 16:03 - 2018-03-30 17:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2018-05-03 01:23 - 2014-07-14 00:40 - 000000000 ____D C:\Users\Brian\AppData\Local\NBTExplorer
2018-05-01 23:41 - 2014-05-04 13:26 - 000000000 ____D C:\Users\Brian\AppData\Roaming\CorsixTH
2018-05-01 23:40 - 2014-05-04 13:26 - 000000000 ____D C:\Program Files\CorsixTH
2018-04-29 04:03 - 2015-02-09 16:20 - 000000000 ____D C:\Program Files\Common Files\Steam
2018-04-22 18:58 - 2017-04-02 16:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-04-22 18:58 - 2017-04-02 16:47 - 000000000 ____D C:\Program Files\Java
2018-04-22 18:56 - 2017-04-02 16:48 - 000096712 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2018-04-18 17:54 - 2009-07-13 21:53 - 000032590 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-04-18 16:17 - 2010-08-23 01:43 - 000000000 ____D C:\Users\Brian
2018-04-16 18:36 - 2016-06-22 20:35 - 000000000 ___RD C:\Users\Brian\Desktop\Games
2018-04-16 18:01 - 2017-12-18 21:00 - 000000000 ____D C:\Users\Brian\Documents\Digital Locker Backup
2018-04-16 17:58 - 2016-01-09 02:03 - 000000000 ____D C:\Users\Brian\Documents\Notepads
2018-04-16 15:51 - 2015-02-18 21:56 - 000000000 ____D C:\Users\Brian\AppData\Local\Steam
2018-04-13 00:30 - 2017-04-09 20:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat
2018-04-12 17:05 - 2018-04-10 20:54 - 000002238 _____ C:\Users\Brian\Desktop\Audacity.lnk
2018-04-12 15:17 - 2016-07-01 00:25 - 000000000 ____D C:\Windows\system32\appraiser

==================== Files in the root of some directories =======

2015-07-30 23:39 - 2015-07-30 23:39 - 000039997 _____ () C:\Users\Brian\AppData\Local\Perfmon.PerfmonCfg
2018-03-29 19:24 - 2018-03-29 19:24 - 000000832 _____ () C:\Users\Brian\AppData\Local\recently-used.xbel
2011-12-10 18:50 - 2018-05-03 17:05 - 000007601 _____ () C:\Users\Brian\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2018-05-11 22:06 - 2018-04-22 16:44 - 001310480 _____ (Microsoft Corporation) C:\Users\Brian\AppData\Local\Temp\dllnt_dump.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-05-08 19:22

==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13.05.2018
Ran by Brian (12-05-2018 21:26:58)
Running from C:\Users\Brian\Desktop
Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2010-08-23 08:42:40)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2999710313-2874845586-1671460366-500 - Administrator - Disabled)
Brian (S-1-5-21-2999710313-2874845586-1671460366-1000 - Administrator - Enabled) => C:\Users\Brian
Guest (S-1-5-21-2999710313-2874845586-1671460366-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2999710313-2874845586-1671460366-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

2.4GHz Wireless N Client Installation Program (HKLM\...\{ECB9E368-1F6B-4253-B6CD-4833FB87225E}) (Version: 2.01.0012 - )
A360 Desktop (HKLM\...\{B65CD59E-A771-4354-AA4B-C3E01B496BCD}) (Version: 8.2.3.1800 - Autodesk)
ACA & MEP 2018 Object Enabler (HKLM\...\{28B89EEF-1004-0000-5002-CF3F3A09B77D}) (Version: 8.0.40.0 - Autodesk) Hidden
ACAD Private (HKLM\...\{28B89EEF-1001-0000-3002-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
Adobe Acrobat Reader DC (HKLM\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Audacity 2.1.0 (HKLM\...\Audacity_is1) (Version: 2.1.0 - Audacity Team)
AutoCAD 2014 - English (HKLM\...\{5783F2D7-D001-0000-0002-0060B0CE6BBA}) (Version: 19.1.108.0 - Autodesk) Hidden
AutoCAD 2014 - English (HKLM\...\{5783F2D7-D001-0409-2002-0060B0CE6BBA}) (Version: 19.1.18.0 - Autodesk) Hidden
AutoCAD 2014 Language Pack - English (HKLM\...\{5783F2D7-D001-0409-1002-0060B0CE6BBA}) (Version: 19.1.18.0 - Autodesk) Hidden
AutoCAD 2018 - English (HKLM\...\{28B89EEF-1001-0409-2002-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
AutoCAD 2018 (HKLM\...\{28B89EEF-1001-0000-0002-CF3F3A09B77D}) (Version: 22.0.72.0 - Autodesk) Hidden
AutoCAD 2018 Language Pack - English (HKLM\...\{28B89EEF-1001-0409-1002-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2018 (HKLM\...\{177AD7F6-9C77-4E50-BA53-B7259C5F282D}) (Version: 16.11.1.0 - Autodesk)
Autodesk App Manager (HKLM\...\{C070121A-C8C5-4D52-9A7D-D240631BD433}) (Version: 1.1.0 - Autodesk)
Autodesk App Manager 2016-2018 (HKLM\...\{20EC0CA2-346E-4660-9903-51B278DF15F6}) (Version: 2.4.0 - Autodesk)
Autodesk AutoCAD 2014 - English (HKLM\...\AutoCAD 2014 - English) (Version: 19.1.18.0 - Autodesk)
Autodesk AutoCAD 2014 - English SP1 (HKLM\...\AutoCAD 2014 - English SP1) (Version: 1 - Autodesk)
Autodesk AutoCAD 2018 - English (HKLM\...\AutoCAD 2018 - English) (Version: 22.0.49.0 - Autodesk)
Autodesk AutoCAD 2018.0.2 (HKLM\...\{b501e2dd-1001-0000-0002-2d66c6a9c722}) (Version: 22.0.72.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.8 (HKLM\...\{214D3370-746E-4886-8EAA-5769EB87D044}) (Version: 1.2.8.0 - Autodesk)
Autodesk Content Service (HKLM\...\{62F029AB-85F2-0000-866A-9FC0DD99DDBC}) (Version: 3.1.3.0 - Autodesk) Hidden
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.1.3.0 - Autodesk)
Autodesk Content Service Language Pack (HKLM\...\{62F029AB-85F2-0001-866A-9FC0DD99DDBC}) (Version: 3.1.3.0 - Autodesk) Hidden
Autodesk Desktop App (HKLM\...\Autodesk Desktop App) (Version: 7.0.9.191 - Autodesk)
Autodesk DWG TrueView 2015 - English (HKLM\...\DWG TrueView 2015 - English) (Version: 20.0.51.0 - Autodesk)
Autodesk Featured Apps (HKLM\...\{F732FEDA-7713-4428-934B-EF83B8DD65D0}) (Version: 1.1.0 - Autodesk)
Autodesk Featured Apps 2016-2018 (HKLM\...\{384C4B74-B749-4AB6-9367-4D51A6AA9CB8}) (Version: 2.4.0 - Autodesk)
Autodesk License Service (x86) - 5.1.5 (HKLM\...\{36AC22AD-5E3A-436E-ABF0-911257790BC6}) (Version: 5.1.5.0 - Autodesk)
Autodesk Material Library 2014 (HKLM\...\{644F9B19-A462-499C-BF4D-300ABC2A28B1}) (Version: 4.0.19.0 - Autodesk)
Autodesk Material Library 2018 (HKLM\...\{7847611E-92E9-4917-B395-71C91D523104}) (Version: 16.11.1.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2014 (HKLM\...\{51BF3210-B825-4092-8E0D-66D689916E02}) (Version: 4.0.19.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2018 (HKLM\...\{FCDED119-A969-4E48-8A32-D21AD6B03253}) (Version: 16.11.1.0 - Autodesk)
Autodesk ReCap (HKLM\...\{31ABA3F2-0000-1033-0002-111D43815377}) (Version: 1.0.43.13 - Autodesk) Hidden
Autodesk ReCap (HKLM\...\Autodesk ReCap) (Version: 1.0.43.13 - Autodesk)
Autodesk ReCap Language Pack-English (HKLM\...\{31ABA3F2-0010-1033-0002-111D43815377}) (Version: 1.0.43.13 - Autodesk) Hidden
Backup and Sync from Google (HKLM\...\{316376FE-CAC0-44AE-BD59-EBDBDEF1592F}) (Version: 3.41.9267.0638 - Google, Inc.)
Bridge Designer 2016 (2nd Edition) (remove only) (HKLM\...\Bridge Designer 2016 (2nd Edition)) (Version: - )
Brother MFL-Pro Suite MFC-J280W (HKLM\...\{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}) (Version: 1.0.19.0 - Brother Industries, Ltd.)
Cities XL (HKLM\...\Cities XL) (Version: 1.0.0 - Monte Cristo Games)
CorsixTH 0.61 (HKLM\...\CorsixTH) (Version: 0.61 - CorsixTH Team)
DWG TrueView 2015 - English (HKLM\...\{5783F2D7-E028-0409-0000-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
Emergency 3 (HKLM\...\{F9787326-0394-4467-A2EE-817C34F6C751}) (Version: 1.03.001 - )
FARO LS 1.1.501.0 (HKLM\...\{8F196892-666A-4A40-8587-6AE38F78A5C2}) (Version: 5.1.0.30630 - FARO Scanner Production)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Git version 2.13.3 (HKLM\...\Git_is1) (Version: 2.13.3 - The Git Development Community)
Google Chrome (HKLM\...\Google Chrome) (Version: 66.0.3359.139 - Google Inc.)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
HP ENVY 5660 series Basic Device Software (HKLM\...\{A6FB5EF8-1518-41F4-9408-81E2D5C36A67}) (Version: 34.2.117.50647 - Hewlett-Packard Co.)
HP ENVY 5660 series Help (HKLM\...\{607F50D9-40BD-4F17-A584-152F563293B4}) (Version: 34.0.0 - Hewlett Packard)
HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Hydrogen (Advanced drum machine for GNU/Linux) (HKLM\...\ON) (Version: 0.9.7-beta2 - Hydrogen Developers)
Java 8 Update 171 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
Lightworks (HKLM\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 14.0.0.0 - EditShare)
LMMS 1.1.3 (HKLM\...\LMMS) (Version: 1.1.3 - LMMS Developers)
Logger Pro 3.12 A20160921-0947_853e1db (HKLM\...\{55C9FFC1-E9A2-4E49-72B1-3831B5AD4AB8}) (Version: 5.182.945 - Vernier Software & Technology)
Malwarebytes version 3.4.5.2467 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.5.2467 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.11.25325 (HKLM\...\{404c9c27-8377-4fd1-b607-7ca635db4e49}) (Version: 14.11.25325.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 59.0.3 (x86 en-US) (HKLM\...\Mozilla Firefox 59.0.3 (x86 en-US)) (Version: 59.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 59.0.3.6691 - Mozilla)
MS Access 97 SP2 (HKLM\...\MS Access 97 SP2) (Version: - )
MSXML 4.0 SP2 Parser and SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
NETGEAR WN311T Wireless PCI Adapter (HKLM\...\{F7321BC6-51AD-4299-9CE9-462DBC141C93}) (Version: - )
Network Addon Mod (HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Network Addon Mod) (Version: 35 - The NAM Team)
Notepad++ (HKLM\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
OpenRCT2 Launcher version 0.0.7 (HKLM\...\{D71D87CE-20E7-4DB6-A0D8-E6DE57051B35}_is1) (Version: 0.0.7 - OpenRCT2)
OpenTTD 1.8.0 (HKLM\...\OpenTTD) (Version: 1.8.0 - OpenTTD)
Origin (HKLM\...\Origin) (Version: 9.1.10.2728 - Electronic Arts, Inc.)
paint.net (HKLM\...\{E8FA8815-3817-4128-A814-E2EAC456ADEF}) (Version: 4.0.21 - dotPDN LLC)
Photo Story 3 for Windows (HKLM\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.11 - Microsoft Corporation)
Product Improvement Study for HP ENVY 5660 series (HKLM\...\{18B597E2-8F59-4969-B932-91DB7EB0C27D}) (Version: 34.2.117.50647 - Hewlett-Packard Co.)
RCT3 Soaked (HKLM\...\{EA926717-CE5A-4CB4-AB21-9E6E9565A458}) (Version: 1.00.000 - )
RNX-N250PC2 Driver (HKLM\...\{871F397C-447E-43B2-B01A-3E656F3D61B6}) (Version: 1.00.0000 - )
RogueKiller version 12.12.16.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.12.16.0 - Adlice Software)
Roller Coaster Tycoon 2 (HKLM\...\Roller Coaster Tycoon 2) (Version: - )
RollerCoaster Tycoon 2 (HKLM\...\{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}) (Version: - )
RollerCoaster Tycoon 2: Time Twister (HKLM\...\{BA1E1AFD-D1F2-4C52-88C3-186FC5E61604}) (Version: 1.00.000 - )
RollerCoaster Tycoon 2: Wacky Worlds (HKLM\...\{B1AD83A0-DC92-41E3-B111-E9472349768C}) (Version: - )
RollerCoaster Tycoon Deluxe (HKLM\...\{924EAD66-F854-4605-8493-696DD59A113B}) (Version: 1.00.000 - )
RollerCoaster Tycoon® 3 (HKLM\...\{907B4640-266B-4A21-92FB-CD1A86CD0F63}) (Version: 1.00.000 - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
SimCity 2000 Special Edition (HKLM\...\SimCity 2000 Special Edition_is1) (Version: - GOG.com)
SimCity 3000 (HKLM\...\SimCity 3000) (Version: - )
SimCity 4 Deluxe (HKLM\...\{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}) (Version: - )
SimCity™ (HKLM\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 1.0.0.0 - Electronic Arts)
SimSafari (HKLM\...\SimSafariUninstall) (Version: - )
SketchUp Import for AutoCAD 2014 (HKLM\...\{644E9589-F73A-49A4-AC61-A953B9DE5669}) (Version: 1.1.0 - Autodesk)
SmartMusic (HKLM\...\{42B1BDFC-9AF7-42C4-BC3C-EAED79D4DBEB}) (Version: 1.1.2204 - MakeMusic, Inc.)
Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
swMSM (HKLM\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Theme Hospital (HKLM\...\Theme Hospital_is1) (Version: - GOG.com)
Traffic Simulator Configuration Tool (HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Traffic Simulator Configuration Tool) (Version: - )
Tycoon City - New York (HKLM\...\{A5101403-2C42-40E0-8D9E-5E49E7C3B89E}) (Version: 1.00.000 - )
VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
WinRAR 4.20 (32-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Zoo Tycoon: Complete Collection (HKLM\...\Zoo Tycoon 1.0) (Version: - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2015 - English\dwgviewr.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2015 - English\en-US\dwgviewrficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{6A221957-2D85-42A7-8E19-BE33950D1DEB}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{6d05bf60-3eaf-4a97-87c5-10cce505435b}\localserver32 -> C:\Users\Brian\AppData\Local\Temp\{9c0ba3c1-2b67-45eb-bf69-bed9658d28d2}\IDriver.NonElevated.exe => No File
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{7DE1BE5C-CEBA-4F1D-ACBC-9CE11EE9A2A1}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{9AAF0EB6-42D8-46C1-A2EF-679511B37A0D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2018\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{B6EB585B-B467-4E46-A9C7-48D7D6FD26CB}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2018\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{BD0DEB94-63DB-4392-9420-6EEE05094B1F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2014\en-US\acadficn.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2018-04-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2018-04-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2018-04-12] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2017-02-02] (Autodesk, Inc.)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2017-02-02] (Autodesk)
ContextMenuHandlers1: [ANotepad++] -> {00F3C2EC-A6EE-11DE-A03A-EF8F55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2014-05-12] ()
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu32.dll [2018-04-12] (Google)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu32.dll [2018-04-12] (Google)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {11F243B2-2411-4E64-8EFD-30BFE038CC7E} - System32\Tasks\{3E78A3A7-EFBB-48DD-B3AF-19FD801C1792} => C:\Program Files\Google\Chrome\Application\chrome.exe
Task: {37DE0088-61A2-4AA6-90BC-A7FD0BCEA41C} - System32\Tasks\HPCustPartic.exe_{762481A1-212E-47A4-9AC2-1E733D0C91D4} => C:\Program Files\HP\HP ENVY 5660 series\Bin\HPCustPartic.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {80CBADC1-3A90-4393-9F3C-372EEBE38E32} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {91EA052A-7798-4876-8384-50B209A35B80} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {94B7CA64-83EC-4F6A-853C-A8984FC3189E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {9B34FC60-D62F-4D64-A93F-222AF7DDBEDB} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {A66CB07D-5764-4FF3-AA9A-28E1B76C34D6} - System32\Tasks\HP AR Program Upload - 06ff241776ee4cceb938b15f1421550aaa4d4d390a554ccda27d2eeab85f184d => C:\Program Files\HP\HP ENVY 5660 series\bin\HPRewards.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {ADF623AC-AF47-4DE2-9E3A-91494FE56E36} - System32\Tasks\HPCustParticipation HP ENVY 5660 series => C:\Program Files\HP\HP ENVY 5660 series\Bin\HPCustPartic.exe [2014-08-22] (Hewlett-Packard Development Company, LP)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\Brian\Documents\SimCity 4\Plugins\Network Addon Mod\Traffic Simulator Configuration Tool.lnk -> C:\Program Files\Traffic Simulator Configuration Tool\TSCT.bat ()
Shortcut: C:\Users\Brian\Desktop\Games\Games\SimCity 4\Mods and Tools\Traffic Simulator Configuration Tool.lnk -> C:\Program Files\Traffic Simulator Configuration Tool\TSCT.bat ()
Shortcut: C:\Users\Brian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxis\SimCity 4\Traffic Simulator Configuration Tool.lnk -> C:\Program Files\Traffic Simulator Configuration Tool\TSCT.bat ()

==================== Loaded Modules (Whitelisted) ==============

2013-09-05 01:14 - 2013-09-05 01:14 - 004300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:45 - 2010-10-20 16:45 - 008801120 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1"

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:04 - 2009-06-10 14:39 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Brian\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: a2AntiMalware => 2
MSCONFIG\Services: Apple Mobile Device => 3
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: BstHdLogRotatorSvc => 2
MSCONFIG\Services: GfExperienceService => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: NvStreamSvc => 2
MSCONFIG\Services: PDFProFiltSrvPP => 2
MSCONFIG\Services: Stereo Service => 2
MSCONFIG\Services: WinNetSvc2 => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^2.4GHz Wireless N Client Utility.lnk => C:\Windows\pss\2.4GHz Wireless N Client Utility.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Brian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP ENVY 5660 series.lnk => C:\Windows\pss\Monitor Ink Alerts - HP ENVY 5660 series.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AE43EAC771ADEE2FEEB86AD6759833F2448FAA11._service_run => "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=service /prefetch:8
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\Brian\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: Autodesk Desktop App => "C:\Program Files\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
MSCONFIG\startupreg: Autodesk Sync => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: BrMfcWnd => C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
MSCONFIG\startupreg: BrStsMon00 => C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: ControlCenter3 => C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
MSCONFIG\startupreg: ControlCenter4 => C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: IndexSearch => "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: Malwarebytes Anti-Exploit => C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe
MSCONFIG\startupreg: NvBackend => "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
MSCONFIG\startupreg: Nvtmru => "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: Steam => "C:\Program Files\Steam\steam.exe" -silent
MSCONFIG\startupreg: WN311T.exe => C:\Program Files\NETGEAR\WN311T\WN311T.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{85E83454-DF00-4F46-AE17-5680C8A78605}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{2145A948-81E9-4B58-85F1-730CFEC49A01}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{018FB3CC-5708-4B35-A0F9-50D6148899F1}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{10669CC4-ED71-4164-B1E2-185722CE0AE5}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe

==================== Restore Points =========================

29-04-2018 17:06:40 Windows Update
02-05-2018 21:57:37 Windows Update
03-05-2018 23:54:23 Microsoft Hotfix
06-05-2018 15:32:30 Windows Update
09-05-2018 03:30:28 Windows Update
10-05-2018 19:47:51 Revo Uninstaller's restore point - Akamai NetSession Interface
10-05-2018 19:52:15 Revo Uninstaller's restore point - Caesium version 1.7.0
11-05-2018 21:01:37 Windows Update
11-05-2018 21:40:51 Restore Point #1

==================== Faulty Device Manager Devices =============

Name: Microsoft Virtual WiFi Miniport Adapter #2
Description: Microsoft Virtual WiFi Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (05/12/2018 05:20:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 66.0.3359.139, time stamp: 0x5ae13fc6
Faulting module name: USER32.dll, version: 6.1.7601.23594, time stamp: 0x58249e2b
Exception code: 0xc0000005
Fault offset: 0x0001636c
Faulting process id: 0x1038
Faulting application start time: 0x01d3e9eb8cb941f0
Faulting application path: C:\Program Files\Google\Chrome\Application\chrome.exe
Faulting module path: C:\Windows\system32\USER32.dll
Report Id: d6336810-55de-11e8-a331-001d60e9db68

Error: (05/12/2018 05:20:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 66.0.3359.139, time stamp: 0x5ae13fc6
Faulting module name: ntdll.dll, version: 6.1.7601.24117, time stamp: 0x5add1df9
Exception code: 0xc0000005
Fault offset: 0x000529df
Faulting process id: 0x1688
Faulting application start time: 0x01d3e9eb8ccc4cf0
Faulting application path: C:\Program Files\Google\Chrome\Application\chrome.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: d632cbd0-55de-11e8-a331-001d60e9db68

Error: (05/12/2018 05:20:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: software_reporter_tool.exe, version: 29.154.200.0, time stamp: 0x5ae90712
Faulting module name: software_reporter_tool.exe, version: 29.154.200.0, time stamp: 0x5ae90712
Exception code: 0xc0000005
Fault offset: 0x00105e3b
Faulting process id: 0x1554
Faulting application start time: 0x01d3e9eb95d5b750
Faulting application path: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\SwReporter\29.154.200\software_reporter_tool.exe
Faulting module path: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\SwReporter\29.154.200\software_reporter_tool.exe
Report Id: d63319f0-55de-11e8-a331-001d60e9db68

Error: (05/12/2018 05:20:20 AM) (Source: Wininit) (EventID: 1015) (User: )
Description: A critical system process, C:\Windows\system32\lsass.exe, failed with status code c0000005. The machine must now be restarted.

Error: (05/12/2018 05:20:19 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 59.0.3.6691, time stamp: 0x5ae39f1a
Faulting module name: user32.dll, version: 6.1.7601.23594, time stamp: 0x58249e2b
Exception code: 0xc0000005
Fault offset: 0x0001636c
Faulting process id: 0xe30
Faulting application start time: 0x01d3e9ea72356f80
Faulting application path: C:\Program Files\Mozilla Firefox\firefox.exe
Faulting module path: C:\Windows\system32\user32.dll
Report Id: d58d8b20-55de-11e8-a331-001d60e9db68

Error: (05/12/2018 05:20:19 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: lsass.exe, version: 6.1.7601.24117, time stamp: 0x5add1847
Faulting module name: ntdll.dll, version: 6.1.7601.24117, time stamp: 0x5add1df9
Exception code: 0xc0000005
Fault offset: 0x000315f8
Faulting process id: 0x1f8
Faulting application start time: 0x01d3e9ea317032a0
Faulting application path: C:\Windows\system32\lsass.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: d58ca0c0-55de-11e8-a331-001d60e9db68

Error: (05/11/2018 11:42:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: software_reporter_tool.exe, version: 29.154.200.0, time stamp: 0x5ae90712
Faulting module name: ntdll.dll, version: 6.1.7601.24117, time stamp: 0x5add1df9
Exception code: 0x80000003
Fault offset: 0x000c3b65
Faulting process id: 0xf10
Faulting application start time: 0x01d3e9bc4f3dbd30
Faulting application path: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\SwReporter\29.154.200\software_reporter_tool.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 943a5a10-55af-11e8-81d3-001d60e9db68

Error: (05/11/2018 11:41:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 66.0.3359.139, time stamp: 0x5ae13fc6
Faulting module name: KERNELBASE.dll, version: 6.1.7601.24117, time stamp: 0x5add1e31
Exception code: 0xc0000409
Fault offset: 0x00020706
Faulting process id: 0xa3c
Faulting application start time: 0x01d3e9bc482758d0
Faulting application path: C:\Program Files\Google\Chrome\Application\chrome.exe
Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report Id: 8e46ea10-55af-11e8-81d3-001d60e9db68


System errors:
=============
Error: (05/12/2018 07:14:25 PM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 1

The details view of this entry contains further information.

Error: (05/12/2018 07:14:25 PM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 1

The details view of this entry contains further information.

Error: (05/12/2018 07:14:25 PM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 10
Processor ID: 1

The details view of this entry contains further information.

Error: (05/12/2018 07:14:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The atksgt service failed to start due to the following error:
The system cannot find the file specified.

Error: (05/12/2018 05:15:32 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} did not register with DCOM within the required timeout.

Error: (05/12/2018 02:37:14 PM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 1

The details view of this entry contains further information.

Error: (05/12/2018 02:37:14 PM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 9
Processor ID: 1

The details view of this entry contains further information.

Error: (05/12/2018 02:37:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The atksgt service failed to start due to the following error:
The system cannot find the file specified.


Windows Defender:
===================================
Date: 2016-11-23 03:53:06.437
Description:
Windows Defender scan has been stopped before completion.
Scan ID:{CDB51533-EEB1-46AB-80C3-76C8F4A6551F}
Scan Type:AntiSpyware
Scan Parameters:Quick Scan

Date: 2016-09-04 02:59:14.724
Description:
Windows Defender scan has been stopped before completion.
Scan ID:{2C6C7A14-A9C1-4418-8B92-07D66C67A9EF}
Scan Type:AntiSpyware
Scan Parameters:Quick Scan

Date: 2016-06-04 03:14:24.942
Description:
Windows Defender scan has been stopped before completion.
Scan ID:{61092E3C-8DAC-40A6-95FE-AEE30C73187F}
Scan Type:AntiSpyware
Scan Parameters:Quick Scan

Date: 2016-02-15 19:13:18.986
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name=SoftwareBundler:Win32/Mizenota&threatid=223449
Name:SoftwareBundler:Win32/Mizenota
ID:223449
Severity:High
Category:Software Bundler
Path Found:containerfile:C:\Users\Brian\Downloads\EuroTruckSimulator2CDKeyGenera Downloader.rar;file:C:\Users\Brian\Downloads\EuroTruckSimulator2CDKeyGenera Downloader.rar->CMT;filelocalcopy:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{663C7ACA-8F97-4219-99EE-B5416090D454}-EuroTruckSimulator2CDKeyGenera Downloader.rar;filelocalcopy:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{F142CAEC-2021-4A61-9756-0CE8402BCA64}-EuroTruckSimulator2CDKeyGenera Downloader.rar;webfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{663C7ACA-8F97-4219-99EE-B5416090D454}-EuroTruckSimulator2CDKeyGenera Downloader.rar|http://mymediadownloadsthirtytwo.co...yb21wdGRvd25sb2FkZXIuY29tJTJGbG9nby5wbmcmcHJl
Detection Type:Concrete
Detection Source:Downloads and attachments
Status:Unknown
Process Name:C:\Program Files\Google\Chrome\Application\chrome.exe

Date: 2016-02-15 19:12:43.723
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name=SoftwareBundler:Win32/Mizenota&threatid=223449
Name:SoftwareBundler:Win32/Mizenota
ID:223449
Severity:High
Category:Software Bundler
Path Found:containerfile:C:\Users\Brian\Downloads\EuroTruckSimulator2CDKeyGenera Downloader.rar;file:C:\Users\Brian\Downloads\EuroTruckSimulator2CDKeyGenera Downloader.rar->CMT;filelocalcopy:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{F142CAEC-2021-4A61-9756-0CE8402BCA64}-EuroTruckSimulator2CDKeyGenera Downloader.rar;webfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{F142CAEC-2021-4A61-9756-0CE8402BCA64}-EuroTruckSimulator2CDKeyGenera Downloader.rar|http://mymediadownloadsthirtytwo.co...JGcHJvbXB0ZG93bmxvYWRlci5jb20lMkYlM0ZjYW5jZWw
Detection Type:Concrete
Detection Source:Downloads and attachments
Status:Unknown
Process Name:C:\Program Files\Google\Chrome\Application\chrome.exe

Date: 2014-02-07 12:27:25.253
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

CodeIntegrity:
===================================

Date: 2016-07-25 16:22:14.208
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-25 01:23:19.251
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-25 01:10:09.306
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 21:23:12.036
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 15:21:33.606
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 15:02:29.721
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 13:17:26.948
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 05:33:00.907
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4000+
Percentage of memory in use: 34%
Total physical RAM: 3071.3 MB
Available physical RAM: 2003.6 MB
Total Virtual: 7675.66 MB
Available Virtual: 6138.11 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:372.61 GB) (Free:74.41 GB) NTFS ==>[drive with boot components (obtained from BCD)]


==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 372.6 GB) (Disk ID: 00000001)
Partition 1: (Active) - (Size=372.6 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================
 
redtarget.gif
Download RogueKiller from one of the following links and save it to your Desktop:

Link 1
Link 2
  • Close all the running programs
  • Double click on downloaded setup.exe file to install the program.
  • Click on Start Scan button.
  • Click on another Start Scan button.
  • Wait until the Status box shows Scan Finished
  • Click on Remove Selected.
  • Wait until the Status box shows Deleting Finished.
  • Click on Report and copy/paste the content of the Notepad into your next reply.
  • RKreport.txt could also be found on your desktop.
  • If more than one log is produced post all logs.
redtarget.gif
Please download Malwarebytes to your desktop.
  • Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program.
  • Then click Finish.
  • Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  • If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
  • The Scan log is available throughout History ->Application logs. Please post it contents in your next reply.
redtarget.gif
Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8/10 users right-click and select Run As Administrator
  • The tool will start to update the database if one is required.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Logfile button.
  • A window will open which lists the logs of your scans.
  • Click on the Scan tab.
  • Double-click the most recent scan which will be at the top of the list....the log will appear.
  • Review the results...see note below
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[CX].txt) will open automatically (where the largest value of X represents the most recent report).
  • To open a Cleaning log, launch AdwareClearer, click on the Logfile button, click on the Cleaning tab and double-click the log at the top of the list.
  • Copy and paste the contents of AdwCleaner[CX].txt in your next reply.
  • A copy of all logfiles are saved to C:\AdwCleaner.
-- Note: The contents of the AdwCleaner log file may be confusing. Unless you see a program name or entry that you recognize and know should not be removed, don't worry about it. If you see an entry you want to keep, return to AdwCleaner before cleaning...all detected items will be listed (and checked) in each tab. Click on and uncheck any items you want to keep.
 
Everything appears to be clean in the scans, but when opening Chrome it still crashes along with any other open programs. I haven't gotten the critical error message yet after it crashes though.

Here are the logs:

RogueKiller V12.12.16.0 [May 4 2018] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : Brian [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller.exe
Mode : Scan -- Date : 05/13/2018 15:52:34 (Duration : 01:16:15)
Switches : -refid

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: HDS72404 0KLSA80 SCSI Disk Device +++++
--- User ---
[MBR] 25d063be37cd871a45faeec77a7ab126
[BSP] 46364c0343a9641c4485752a03dce1fa : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 19 | Size: 381552 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
Error reading LL2 MBR! ([1] Incorrect function. )

+++++ PhysicalDrive1: HP ENVY 5660 series USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )
 
Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 5/13/18
Scan Time: 5:22 PM
Log File: ddc363d1-570c-11e8-873d-001d60e9db68.json
Administrator: Yes

-Software Information-
Version: 3.5.1.2522
Components Version: 1.0.365
Update Package Version: 1.0.5094
License: Free

-System Information-
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Brian-PC\Brian

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 232871
Threats Detected: 0
(No malicious items detected)
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 33 min, 4 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)
 
# -------------------------------
# Malwarebytes AdwCleaner 7.1.1.0
# -------------------------------
# Build: 04-27-2018
# Database: 2018-05-11.1
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 05-13-2018
# Duration: 00:00:01
# OS: Windows 7 Ultimate
# Cleaned: 0
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************


########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C04].txt ##########
 
Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.

  • Double click to run it.
  • Make sure you checkmark Addition.txt box.
  • Press Scan button.
  • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13.05.2018
Ran by Brian (administrator) on BRIAN-PC (13-05-2018 19:00:29)
Running from C:\Users\Brian\Desktop
Loaded Profiles: Brian (Available Profiles: Brian)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1002984 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation)
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Policies\Explorer: []
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\MountPoints2: {96ff7f85-ae8e-11df-911b-806e6f6e6963} - D:\Autorun.exe
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Winlogon: [Shell] C:\Windows\explorer.exe [2972672 2016-08-29] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1772568 2017-02-03] (Autodesk, Inc.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{8D135E9C-0C09-4E97-8D8F-71867BBEF404}: [NameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://msn.com/
SearchScopes: HKLM -> DefaultScope {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_171\bin\ssv.dll [2018-04-22] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-22] (Oracle Corporation)
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

FireFox:
========
FF ProfilePath: C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\iuwnxwqq.default [2018-05-13]
FF Homepage: Mozilla\Firefox\Profiles\iuwnxwqq.default -> hxxp://www.msn.com
FF Plugin: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-22] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> msn.com
CHR Profile: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default [2018-05-13]
CHR Extension: (Slides) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-07]
CHR Extension: (YouTube) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-07]
CHR Extension: (Google Search) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-07]
CHR Extension: (Adobe Acrobat) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-05-04]
CHR Extension: (Sheets) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Google Docs Offline) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-14]
CHR Extension: (Kami - PDF and Document Markup) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljojpiodmlhoehoecppliohmplbgeij [2017-03-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-10]
CHR Extension: (Gmail) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-07]
CHR Extension: (Chrome Media Router) - C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-03]
CHR Profile: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-04-10]
CHR Profile: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\System Profile [2018-05-10]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fkkcgfbgohboipdhliafmacjnhjbhmim] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AdAppMgrSvc; C:\Program Files\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1374072 2018-03-10] (Autodesk Inc.)
S3 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.) [File not signed]
S3 BrYNSvc; C:\Program Files\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [File not signed]
S3 FlexNet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe [1233376 2017-05-17] (Flexera Software LLC)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4753104 2018-05-09] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [103696 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280864 2016-11-14] (Microsoft Corporation)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [2119688 2016-04-03] (Electronic Arts)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 anodlwf; C:\Windows\System32\DRIVERS\anodlwf.sys [12800 2009-03-06] ()
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [220896 2018-05-13] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [252808 2016-08-25] (Microsoft Corporation)
S3 MRVW147; C:\Windows\System32\DRIVERS\MRVW147.sys [529408 2008-08-20] (Marvell Semiconductor, Inc)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] ()
S3 netr28u; C:\Windows\System32\DRIVERS\Dnetr28u.sys [750592 2009-08-05] (Ralink Technology Corp.)
S3 rt70x86; C:\Windows\System32\DRIVERS\netr70.sys [306016 2010-04-27] (Ralink Technology Corp.)
S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [629760 2010-08-10] (Realtek Semiconductor Corporation ) [File not signed]
S4 secdrv; C:\Windows\system32\Drivers\secdrv.sys [12400 2017-08-14] (Macrovision Europe Ltd) [File not signed]
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [40448 2009-08-28] (Apple, Inc.) [File not signed]
R3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [193696 2015-08-27] (Jungo)
S3 xb1usb; C:\Windows\System32\DRIVERS\xb1usb.sys [38152 2016-02-22] (Microsoft Corporation)
S3 xusb21; C:\Windows\System32\DRIVERS\xusb21.sys [60160 2009-08-13] (Microsoft Corporation) [File not signed]
S2 atksgt; system32\DRIVERS\atksgt.sys [X]
S4 lirsgt; system32\DRIVERS\lirsgt.sys [X]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
S3 NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-05-13 17:57 - 2018-05-13 17:57 - 000001300 _____ C:\Users\Brian\Desktop\Malwarebytes Report.txt
2018-05-13 17:20 - 2018-05-13 17:20 - 000220896 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-05-13 17:19 - 2018-05-13 17:19 - 000002024 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-05-13 17:19 - 2018-05-13 17:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-05-13 17:16 - 2018-05-13 17:16 - 000002720 _____ C:\Users\Brian\Desktop\RogueKiller Report.txt
2018-05-13 15:51 - 2018-05-13 15:51 - 007271632 _____ (Malwarebytes) C:\Users\Brian\Downloads\AdwCleaner.exe
2018-05-13 15:49 - 2018-05-13 15:49 - 075127256 _____ (Malwarebytes ) C:\Users\Brian\Downloads\mb3-setup-consumer-3.5.1.2522-1.0.365-1.0.5088.exe
2018-05-13 15:46 - 2018-05-13 15:46 - 036639176 _____ (Adlice Software ) C:\Users\Brian\Downloads\RogueKiller_setup_ref3.exe
2018-05-12 21:26 - 2018-05-12 21:32 - 000042542 _____ C:\Users\Brian\Desktop\Addition.txt
2018-05-12 21:24 - 2018-05-13 19:01 - 000012064 _____ C:\Users\Brian\Desktop\FRST.txt
2018-05-12 21:21 - 2018-05-12 21:24 - 001765376 _____ (Farbar) C:\Users\Brian\Desktop\FRST.exe
2018-05-12 05:37 - 2018-05-13 19:00 - 000000000 ____D C:\FRST
2018-05-11 01:11 - 2018-05-11 01:11 - 000000000 ____D C:\Users\Brian\AppData\Local\RadeonInstaller
2018-05-11 01:11 - 2018-05-11 01:11 - 000000000 ____D C:\Program Files\AMD
2018-05-11 01:11 - 2018-05-11 01:11 - 000000000 ____D C:\AMD
2018-05-08 18:13 - 2018-05-08 18:14 - 000066588 _____ C:\Users\Brian\Downloads\cc_20180508_181253.reg
2018-05-08 17:51 - 2018-04-23 11:02 - 000348832 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-05-08 17:51 - 2018-04-22 17:12 - 004047040 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2018-05-08 17:51 - 2018-04-22 17:12 - 003958464 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-05-08 17:51 - 2018-04-22 17:11 - 000190144 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2018-05-08 17:51 - 2018-04-22 17:11 - 000190144 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-05-08 17:51 - 2018-04-22 17:11 - 000137920 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2018-05-08 17:51 - 2018-04-22 17:11 - 000137920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-05-08 17:51 - 2018-04-22 17:11 - 000067264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-05-08 17:51 - 2018-04-22 16:44 - 001310480 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-05-08 17:51 - 2018-04-22 16:41 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 001417728 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 001063424 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000582144 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000377856 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:24 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-05-08 17:51 - 2018-04-22 16:23 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-05-08 17:51 - 2018-04-22 16:23 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-05-08 17:51 - 2018-04-22 16:23 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-05-08 17:51 - 2018-04-22 16:23 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-05-08 17:51 - 2018-04-22 16:22 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-05-08 17:51 - 2018-04-22 16:21 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-05-08 17:51 - 2018-04-22 16:21 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-05-08 17:51 - 2018-04-22 16:20 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-05-08 17:51 - 2018-04-22 16:19 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-05-08 17:51 - 2018-04-22 16:19 - 000124928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-05-08 17:51 - 2018-04-22 16:19 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-05-08 17:51 - 2018-04-22 16:18 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-05-08 17:51 - 2018-04-22 16:18 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-05-08 17:51 - 2018-04-22 16:18 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 16:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-05-08 17:51 - 2018-04-22 00:24 - 020286464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-05-08 17:51 - 2018-04-22 00:16 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-05-08 17:51 - 2018-04-22 00:16 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-05-08 17:51 - 2018-04-22 00:04 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-05-08 17:51 - 2018-04-22 00:04 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-05-08 17:51 - 2018-04-22 00:03 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-05-08 17:51 - 2018-04-22 00:03 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-05-08 17:51 - 2018-04-22 00:02 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-05-08 17:51 - 2018-04-22 00:00 - 002295296 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-05-08 17:51 - 2018-04-21 23:57 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-05-08 17:51 - 2018-04-21 23:56 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-05-08 17:51 - 2018-04-21 23:55 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-05-08 17:51 - 2018-04-21 23:54 - 000661504 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-05-08 17:51 - 2018-04-21 23:54 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-05-08 17:51 - 2018-04-21 23:53 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-05-08 17:51 - 2018-04-21 23:53 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-05-08 17:51 - 2018-04-21 23:48 - 000668160 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-05-08 17:51 - 2018-04-21 23:45 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-05-08 17:51 - 2018-04-21 23:40 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-05-08 17:51 - 2018-04-21 23:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-05-08 17:51 - 2018-04-21 23:39 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-05-08 17:51 - 2018-04-21 23:37 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-05-08 17:51 - 2018-04-21 23:37 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-05-08 17:51 - 2018-04-21 23:35 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-05-08 17:51 - 2018-04-21 23:34 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-05-08 17:51 - 2018-04-21 23:31 - 004496896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-05-08 17:51 - 2018-04-21 23:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-05-08 17:51 - 2018-04-21 23:27 - 000696320 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-05-08 17:51 - 2018-04-21 23:27 - 000692224 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-05-08 17:51 - 2018-04-21 23:26 - 013679616 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-05-08 17:51 - 2018-04-21 23:26 - 002059776 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-05-08 17:51 - 2018-04-21 23:26 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-05-08 17:51 - 2018-04-21 23:08 - 002767872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-05-08 17:51 - 2018-04-21 23:04 - 001314304 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-05-08 17:51 - 2018-04-21 23:03 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-05-08 17:51 - 2018-04-18 08:51 - 000523776 _____ (Microsoft Corporation) C:\Windows\system32\hhctrl.ocx
2018-05-08 17:51 - 2018-04-18 08:51 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\hhsetup.dll
2018-05-08 17:51 - 2018-04-18 08:35 - 000015360 _____ (Microsoft Corporation) C:\Windows\hh.exe
2018-05-08 17:51 - 2018-04-11 09:36 - 000158720 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2018-05-08 17:51 - 2018-04-11 09:36 - 000142848 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2018-05-08 17:51 - 2018-04-10 12:44 - 000535616 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-05-08 17:51 - 2018-04-10 09:34 - 000167936 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2018-05-08 17:51 - 2018-04-10 09:33 - 001241600 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2018-05-08 17:51 - 2018-04-10 09:32 - 000487936 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2018-05-08 17:51 - 2018-04-10 09:00 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2018-05-08 17:51 - 2018-04-10 08:56 - 002404352 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-05-08 17:51 - 2018-04-10 08:52 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2018-05-08 17:51 - 2018-04-10 08:50 - 000314368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-05-08 17:51 - 2018-04-10 08:50 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-05-08 17:51 - 2018-04-07 09:42 - 000250560 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2018-05-08 17:51 - 2018-03-18 15:16 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-05-08 17:51 - 2018-03-14 10:16 - 002953216 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2018-05-08 17:51 - 2018-03-14 10:16 - 000174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2018-05-08 17:51 - 2018-03-14 10:10 - 000073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 002092032 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000573440 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000136192 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2018-05-08 17:51 - 2018-03-14 09:57 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2018-05-08 17:51 - 2018-03-14 09:57 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2018-05-08 17:51 - 2018-03-14 09:57 - 000011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2018-05-04 14:21 - 2018-05-04 14:21 - 248421756 _____ C:\Users\Brian\Downloads\Registry Backup.reg
2018-05-04 13:14 - 2018-05-13 18:15 - 000000000 ____D C:\Users\Brian\AppData\Local\CrashDumps
2018-05-04 11:48 - 2018-05-13 15:52 - 000024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-05-04 11:44 - 2018-05-13 15:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-05-04 11:44 - 2018-05-13 15:48 - 000000000 ____D C:\Program Files\RogueKiller
2018-05-04 11:44 - 2018-05-04 11:47 - 000000000 ____D C:\ProgramData\RogueKiller
2018-05-04 10:58 - 2018-05-04 10:58 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\46781755.sys
2018-05-03 22:33 - 2018-05-10 19:35 - 000000000 ____D C:\Users\Brian\Downloads\Tools
2018-04-27 03:31 - 2018-04-27 03:31 - 000054974 _____ C:\Users\Brian\Desktop\Addition_27-04-2018 03.31.36.txt
2018-04-27 03:31 - 2018-04-27 03:31 - 000039857 _____ C:\Users\Brian\Desktop\FRST_27-04-2018 03.31.36.txt
2018-04-22 18:57 - 2018-04-22 18:57 - 000000000 ____D C:\Program Files\Common Files\Java
2018-04-22 18:56 - 2018-04-22 18:56 - 000000000 ____D C:\Program Files\Common Files\Oracle
2018-04-18 16:49 - 2018-04-18 16:54 - 000000000 ____D C:\AdwCleaner
2018-04-18 16:14 - 2018-04-18 16:14 - 000023000 _____ C:\Users\Brian\Documents\energy-report.html
2018-04-18 05:38 - 2018-04-18 05:38 - 000000000 ____D C:\Program Files\Common Files\Services
2018-04-16 17:57 - 2018-04-16 17:57 - 000000000 ____D C:\Users\Brian\Documents\Bridges
2018-04-16 17:57 - 2018-04-16 17:57 - 000000000 ____D C:\Users\Brian\.phet
2018-04-14 14:31 - 2018-03-10 10:11 - 000340480 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll
2018-04-14 14:31 - 2018-03-09 11:18 - 000309440 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-04-14 14:31 - 2018-03-09 11:12 - 000111616 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-04-14 14:31 - 2018-03-09 11:12 - 000071680 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-04-14 14:31 - 2018-03-09 11:12 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-04-14 14:31 - 2018-03-09 11:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-04-14 14:31 - 2018-03-09 10:31 - 000034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-04-14 14:31 - 2018-03-06 11:13 - 000148160 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2018-04-14 14:31 - 2018-03-06 11:11 - 000184320 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
2018-04-14 14:31 - 2018-03-06 11:11 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000922944 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000066392 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000022360 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000019800 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000016216 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000015704 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2018-04-14 14:31 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-05-13 18:17 - 2009-07-13 21:34 - 000010208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-05-13 18:17 - 2009-07-13 21:34 - 000010208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-05-13 18:15 - 2017-01-18 15:43 - 000000000 ____D C:\Users\Brian\AppData\LocalLow\Mozilla
2018-05-13 18:08 - 2009-07-13 21:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-05-13 17:19 - 2013-01-10 17:49 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-05-13 15:43 - 2015-02-09 16:20 - 000000000 ____D C:\Program Files\Steam
2018-05-12 05:27 - 2011-12-19 01:43 - 000000000 ____D C:\Users\Brian\AppData\Local\ElevatedDiagnostics
2018-05-12 05:24 - 2014-08-28 15:16 - 000000000 ____D C:\Windows\pss
2018-05-11 21:04 - 2010-08-23 11:28 - 000773912 _____ C:\Windows\system32\PerfStringBackup.INI
2018-05-11 21:04 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\inf
2018-05-10 20:47 - 2018-01-01 20:36 - 000000000 ____D C:\Users\Brian\Documents\Euro Truck Simulator 2
2018-05-09 17:14 - 2014-11-01 23:22 - 000000000 ____D C:\Users\Brian\AppData\Roaming\TS3Client
2018-05-09 17:11 - 2014-11-01 23:22 - 000000000 ____D C:\Program Files\TeamSpeak 3 Client
2018-05-09 16:07 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\rescache
2018-05-09 03:52 - 2009-07-13 21:33 - 000514600 _____ C:\Windows\system32\FNTCACHE.DAT
2018-05-09 03:45 - 2009-07-13 19:37 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-05-09 03:41 - 2016-06-30 01:39 - 000000000 ____D C:\Windows\system32\MRT
2018-05-09 03:35 - 2017-10-11 04:31 - 138711016 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-05-09 03:34 - 2016-06-30 01:39 - 138711016 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-05-09 03:21 - 2018-03-26 16:34 - 000000000 ____D C:\Users\Brian\Downloads\System Tools
2018-05-08 19:34 - 2010-09-02 00:28 - 000154048 _____ C:\Users\Brian\AppData\Local\GDIPFONTCACHEV1.DAT
2018-05-08 18:32 - 2010-09-02 00:08 - 000000000 ____D C:\Windows\Minidump
2018-05-06 15:25 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\registration
2018-05-04 13:50 - 2015-03-23 20:54 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service
2018-05-04 13:28 - 2017-01-09 23:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-05-04 11:33 - 2015-03-23 19:45 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2018-05-03 23:42 - 2009-07-13 19:37 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-05-03 23:31 - 2018-03-30 18:21 - 000000000 ___RD C:\Users\Brian\Google Drive
2018-05-03 21:40 - 2015-11-07 21:20 - 000002170 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-05-03 21:40 - 2015-11-07 21:20 - 000002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-05-03 18:52 - 2012-04-27 18:05 - 000000000 ____D C:\Users\Brian\AppData\Roaming\.minecraft
2018-05-03 17:05 - 2011-12-10 18:50 - 000007601 _____ C:\Users\Brian\AppData\Local\Resmon.ResmonCfg
2018-05-03 16:45 - 2009-07-13 19:37 - 000000000 ____D C:\Windows\system32\NDF
2018-05-03 16:03 - 2018-03-30 17:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2018-05-03 01:23 - 2014-07-14 00:40 - 000000000 ____D C:\Users\Brian\AppData\Local\NBTExplorer
2018-05-01 23:41 - 2014-05-04 13:26 - 000000000 ____D C:\Users\Brian\AppData\Roaming\CorsixTH
2018-05-01 23:40 - 2014-05-04 13:26 - 000000000 ____D C:\Program Files\CorsixTH
2018-04-29 04:03 - 2015-02-09 16:20 - 000000000 ____D C:\Program Files\Common Files\Steam
2018-04-26 05:36 - 2018-03-18 17:16 - 000128736 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae.sys
2018-04-22 18:58 - 2017-04-02 16:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-04-22 18:58 - 2017-04-02 16:47 - 000000000 ____D C:\Program Files\Java
2018-04-22 18:56 - 2017-04-02 16:48 - 000096712 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2018-04-18 17:54 - 2009-07-13 21:53 - 000032590 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-04-18 16:17 - 2010-08-23 01:43 - 000000000 ____D C:\Users\Brian
2018-04-16 18:36 - 2016-06-22 20:35 - 000000000 ___RD C:\Users\Brian\Desktop\Games
2018-04-16 18:01 - 2017-12-18 21:00 - 000000000 ____D C:\Users\Brian\Documents\Digital Locker Backup
2018-04-16 17:58 - 2016-01-09 02:03 - 000000000 ____D C:\Users\Brian\Documents\Notepads
2018-04-16 15:51 - 2015-02-18 21:56 - 000000000 ____D C:\Users\Brian\AppData\Local\Steam
2018-04-13 00:30 - 2017-04-09 20:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat

==================== Files in the root of some directories =======

2015-07-30 23:39 - 2015-07-30 23:39 - 000039997 _____ () C:\Users\Brian\AppData\Local\Perfmon.PerfmonCfg
2018-03-29 19:24 - 2018-03-29 19:24 - 000000832 _____ () C:\Users\Brian\AppData\Local\recently-used.xbel
2011-12-10 18:50 - 2018-05-03 17:05 - 000007601 _____ () C:\Users\Brian\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2018-05-11 22:06 - 2018-04-22 16:44 - 001310480 _____ (Microsoft Corporation) C:\Users\Brian\AppData\Local\Temp\dllnt_dump.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-05-08 19:22

==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13.05.2018
Ran by Brian (13-05-2018 19:02:35)
Running from C:\Users\Brian\Desktop
Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2010-08-23 08:42:40)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2999710313-2874845586-1671460366-500 - Administrator - Disabled)
Brian (S-1-5-21-2999710313-2874845586-1671460366-1000 - Administrator - Enabled) => C:\Users\Brian
Guest (S-1-5-21-2999710313-2874845586-1671460366-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2999710313-2874845586-1671460366-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

2.4GHz Wireless N Client Installation Program (HKLM\...\{ECB9E368-1F6B-4253-B6CD-4833FB87225E}) (Version: 2.01.0012 - )
A360 Desktop (HKLM\...\{B65CD59E-A771-4354-AA4B-C3E01B496BCD}) (Version: 8.2.3.1800 - Autodesk)
ACA & MEP 2018 Object Enabler (HKLM\...\{28B89EEF-1004-0000-5002-CF3F3A09B77D}) (Version: 8.0.40.0 - Autodesk) Hidden
ACAD Private (HKLM\...\{28B89EEF-1001-0000-3002-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
Adobe Acrobat Reader DC (HKLM\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Audacity 2.1.0 (HKLM\...\Audacity_is1) (Version: 2.1.0 - Audacity Team)
AutoCAD 2014 - English (HKLM\...\{5783F2D7-D001-0000-0002-0060B0CE6BBA}) (Version: 19.1.108.0 - Autodesk) Hidden
AutoCAD 2014 - English (HKLM\...\{5783F2D7-D001-0409-2002-0060B0CE6BBA}) (Version: 19.1.18.0 - Autodesk) Hidden
AutoCAD 2014 Language Pack - English (HKLM\...\{5783F2D7-D001-0409-1002-0060B0CE6BBA}) (Version: 19.1.18.0 - Autodesk) Hidden
AutoCAD 2018 - English (HKLM\...\{28B89EEF-1001-0409-2002-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
AutoCAD 2018 (HKLM\...\{28B89EEF-1001-0000-0002-CF3F3A09B77D}) (Version: 22.0.72.0 - Autodesk) Hidden
AutoCAD 2018 Language Pack - English (HKLM\...\{28B89EEF-1001-0409-1002-CF3F3A09B77D}) (Version: 22.0.49.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2018 (HKLM\...\{177AD7F6-9C77-4E50-BA53-B7259C5F282D}) (Version: 16.11.1.0 - Autodesk)
Autodesk App Manager (HKLM\...\{C070121A-C8C5-4D52-9A7D-D240631BD433}) (Version: 1.1.0 - Autodesk)
Autodesk App Manager 2016-2018 (HKLM\...\{20EC0CA2-346E-4660-9903-51B278DF15F6}) (Version: 2.4.0 - Autodesk)
Autodesk AutoCAD 2014 - English (HKLM\...\AutoCAD 2014 - English) (Version: 19.1.18.0 - Autodesk)
Autodesk AutoCAD 2014 - English SP1 (HKLM\...\AutoCAD 2014 - English SP1) (Version: 1 - Autodesk)
Autodesk AutoCAD 2018 - English (HKLM\...\AutoCAD 2018 - English) (Version: 22.0.49.0 - Autodesk)
Autodesk AutoCAD 2018.0.2 (HKLM\...\{b501e2dd-1001-0000-0002-2d66c6a9c722}) (Version: 22.0.72.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.8 (HKLM\...\{214D3370-746E-4886-8EAA-5769EB87D044}) (Version: 1.2.8.0 - Autodesk)
Autodesk Content Service (HKLM\...\{62F029AB-85F2-0000-866A-9FC0DD99DDBC}) (Version: 3.1.3.0 - Autodesk) Hidden
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.1.3.0 - Autodesk)
Autodesk Content Service Language Pack (HKLM\...\{62F029AB-85F2-0001-866A-9FC0DD99DDBC}) (Version: 3.1.3.0 - Autodesk) Hidden
Autodesk Desktop App (HKLM\...\Autodesk Desktop App) (Version: 7.0.9.191 - Autodesk)
Autodesk DWG TrueView 2015 - English (HKLM\...\DWG TrueView 2015 - English) (Version: 20.0.51.0 - Autodesk)
Autodesk Featured Apps (HKLM\...\{F732FEDA-7713-4428-934B-EF83B8DD65D0}) (Version: 1.1.0 - Autodesk)
Autodesk Featured Apps 2016-2018 (HKLM\...\{384C4B74-B749-4AB6-9367-4D51A6AA9CB8}) (Version: 2.4.0 - Autodesk)
Autodesk License Service (x86) - 5.1.5 (HKLM\...\{36AC22AD-5E3A-436E-ABF0-911257790BC6}) (Version: 5.1.5.0 - Autodesk)
Autodesk Material Library 2014 (HKLM\...\{644F9B19-A462-499C-BF4D-300ABC2A28B1}) (Version: 4.0.19.0 - Autodesk)
Autodesk Material Library 2018 (HKLM\...\{7847611E-92E9-4917-B395-71C91D523104}) (Version: 16.11.1.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2014 (HKLM\...\{51BF3210-B825-4092-8E0D-66D689916E02}) (Version: 4.0.19.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2018 (HKLM\...\{FCDED119-A969-4E48-8A32-D21AD6B03253}) (Version: 16.11.1.0 - Autodesk)
Autodesk ReCap (HKLM\...\{31ABA3F2-0000-1033-0002-111D43815377}) (Version: 1.0.43.13 - Autodesk) Hidden
Autodesk ReCap (HKLM\...\Autodesk ReCap) (Version: 1.0.43.13 - Autodesk)
Autodesk ReCap Language Pack-English (HKLM\...\{31ABA3F2-0010-1033-0002-111D43815377}) (Version: 1.0.43.13 - Autodesk) Hidden
Backup and Sync from Google (HKLM\...\{316376FE-CAC0-44AE-BD59-EBDBDEF1592F}) (Version: 3.41.9267.0638 - Google, Inc.)
Bridge Designer 2016 (2nd Edition) (remove only) (HKLM\...\Bridge Designer 2016 (2nd Edition)) (Version: - )
Brother MFL-Pro Suite MFC-J280W (HKLM\...\{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}) (Version: 1.0.19.0 - Brother Industries, Ltd.)
Cities XL (HKLM\...\Cities XL) (Version: 1.0.0 - Monte Cristo Games)
CorsixTH 0.61 (HKLM\...\CorsixTH) (Version: 0.61 - CorsixTH Team)
DWG TrueView 2015 - English (HKLM\...\{5783F2D7-E028-0409-0000-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
Emergency 3 (HKLM\...\{F9787326-0394-4467-A2EE-817C34F6C751}) (Version: 1.03.001 - )
FARO LS 1.1.501.0 (HKLM\...\{8F196892-666A-4A40-8587-6AE38F78A5C2}) (Version: 5.1.0.30630 - FARO Scanner Production)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Git version 2.13.3 (HKLM\...\Git_is1) (Version: 2.13.3 - The Git Development Community)
Google Chrome (HKLM\...\Google Chrome) (Version: 66.0.3359.139 - Google Inc.)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
HP ENVY 5660 series Basic Device Software (HKLM\...\{A6FB5EF8-1518-41F4-9408-81E2D5C36A67}) (Version: 34.2.117.50647 - Hewlett-Packard Co.)
HP ENVY 5660 series Help (HKLM\...\{607F50D9-40BD-4F17-A584-152F563293B4}) (Version: 34.0.0 - Hewlett Packard)
HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Hydrogen (Advanced drum machine for GNU/Linux) (HKLM\...\ON) (Version: 0.9.7-beta2 - Hydrogen Developers)
Java 8 Update 171 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
Lightworks (HKLM\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 14.0.0.0 - EditShare)
LMMS 1.1.3 (HKLM\...\LMMS) (Version: 1.1.3 - LMMS Developers)
Logger Pro 3.12 A20160921-0947_853e1db (HKLM\...\{55C9FFC1-E9A2-4E49-72B1-3831B5AD4AB8}) (Version: 5.182.945 - Vernier Software & Technology)
Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.11.25325 (HKLM\...\{404c9c27-8377-4fd1-b607-7ca635db4e49}) (Version: 14.11.25325.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 59.0.3 (x86 en-US) (HKLM\...\Mozilla Firefox 59.0.3 (x86 en-US)) (Version: 59.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 59.0.3.6691 - Mozilla)
MS Access 97 SP2 (HKLM\...\MS Access 97 SP2) (Version: - )
MSXML 4.0 SP2 Parser and SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
NETGEAR WN311T Wireless PCI Adapter (HKLM\...\{F7321BC6-51AD-4299-9CE9-462DBC141C93}) (Version: - )
Network Addon Mod (HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Network Addon Mod) (Version: 35 - The NAM Team)
Notepad++ (HKLM\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
OpenRCT2 Launcher version 0.0.7 (HKLM\...\{D71D87CE-20E7-4DB6-A0D8-E6DE57051B35}_is1) (Version: 0.0.7 - OpenRCT2)
OpenTTD 1.8.0 (HKLM\...\OpenTTD) (Version: 1.8.0 - OpenTTD)
Origin (HKLM\...\Origin) (Version: 9.1.10.2728 - Electronic Arts, Inc.)
paint.net (HKLM\...\{E8FA8815-3817-4128-A814-E2EAC456ADEF}) (Version: 4.0.21 - dotPDN LLC)
Photo Story 3 for Windows (HKLM\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.11 - Microsoft Corporation)
Product Improvement Study for HP ENVY 5660 series (HKLM\...\{18B597E2-8F59-4969-B932-91DB7EB0C27D}) (Version: 34.2.117.50647 - Hewlett-Packard Co.)
RCT3 Soaked (HKLM\...\{EA926717-CE5A-4CB4-AB21-9E6E9565A458}) (Version: 1.00.000 - )
RNX-N250PC2 Driver (HKLM\...\{871F397C-447E-43B2-B01A-3E656F3D61B6}) (Version: 1.00.0000 - )
RogueKiller version 12.12.16.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.12.16.0 - Adlice Software)
Roller Coaster Tycoon 2 (HKLM\...\Roller Coaster Tycoon 2) (Version: - )
RollerCoaster Tycoon 2 (HKLM\...\{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}) (Version: - )
RollerCoaster Tycoon 2: Time Twister (HKLM\...\{BA1E1AFD-D1F2-4C52-88C3-186FC5E61604}) (Version: 1.00.000 - )
RollerCoaster Tycoon 2: Wacky Worlds (HKLM\...\{B1AD83A0-DC92-41E3-B111-E9472349768C}) (Version: - )
RollerCoaster Tycoon Deluxe (HKLM\...\{924EAD66-F854-4605-8493-696DD59A113B}) (Version: 1.00.000 - )
RollerCoaster Tycoon® 3 (HKLM\...\{907B4640-266B-4A21-92FB-CD1A86CD0F63}) (Version: 1.00.000 - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
SimCity 2000 Special Edition (HKLM\...\SimCity 2000 Special Edition_is1) (Version: - GOG.com)
SimCity 3000 (HKLM\...\SimCity 3000) (Version: - )
SimCity 4 Deluxe (HKLM\...\{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}) (Version: - )
SimCity™ (HKLM\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 1.0.0.0 - Electronic Arts)
SimSafari (HKLM\...\SimSafariUninstall) (Version: - )
SketchUp Import for AutoCAD 2014 (HKLM\...\{644E9589-F73A-49A4-AC61-A953B9DE5669}) (Version: 1.1.0 - Autodesk)
SmartMusic (HKLM\...\{42B1BDFC-9AF7-42C4-BC3C-EAED79D4DBEB}) (Version: 1.1.2204 - MakeMusic, Inc.)
Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
swMSM (HKLM\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Theme Hospital (HKLM\...\Theme Hospital_is1) (Version: - GOG.com)
Traffic Simulator Configuration Tool (HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Traffic Simulator Configuration Tool) (Version: - )
Tycoon City - New York (HKLM\...\{A5101403-2C42-40E0-8D9E-5E49E7C3B89E}) (Version: 1.00.000 - )
VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
WinRAR 4.20 (32-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Zoo Tycoon: Complete Collection (HKLM\...\Zoo Tycoon 1.0) (Version: - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2015 - English\dwgviewr.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2015 - English\en-US\dwgviewrficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{6A221957-2D85-42A7-8E19-BE33950D1DEB}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{6d05bf60-3eaf-4a97-87c5-10cce505435b}\localserver32 -> C:\Users\Brian\AppData\Local\Temp\{9c0ba3c1-2b67-45eb-bf69-bed9658d28d2}\IDriver.NonElevated.exe => No File
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{7DE1BE5C-CEBA-4F1D-ACBC-9CE11EE9A2A1}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{9AAF0EB6-42D8-46C1-A2EF-679511B37A0D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2018\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{B6EB585B-B467-4E46-A9C7-48D7D6FD26CB}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2018\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{BD0DEB94-63DB-4392-9420-6EEE05094B1F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2014\en-US\acadficn.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2018-04-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2018-04-12] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2018-04-12] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2017-02-02] (Autodesk, Inc.)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2017-02-02] (Autodesk)
ContextMenuHandlers1: [ANotepad++] -> {00F3C2EC-A6EE-11DE-A03A-EF8F55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2014-05-12] ()
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu32.dll [2018-04-12] (Google)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu32.dll [2018-04-12] (Google)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {11F243B2-2411-4E64-8EFD-30BFE038CC7E} - System32\Tasks\{3E78A3A7-EFBB-48DD-B3AF-19FD801C1792} => C:\Program Files\Google\Chrome\Application\chrome.exe
Task: {37DE0088-61A2-4AA6-90BC-A7FD0BCEA41C} - System32\Tasks\HPCustPartic.exe_{762481A1-212E-47A4-9AC2-1E733D0C91D4} => C:\Program Files\HP\HP ENVY 5660 series\Bin\HPCustPartic.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {80CBADC1-3A90-4393-9F3C-372EEBE38E32} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {87181B53-7D35-49A2-A0E7-1DB898E16DDA} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {91EA052A-7798-4876-8384-50B209A35B80} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {94B7CA64-83EC-4F6A-853C-A8984FC3189E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {A66CB07D-5764-4FF3-AA9A-28E1B76C34D6} - System32\Tasks\HP AR Program Upload - 06ff241776ee4cceb938b15f1421550aaa4d4d390a554ccda27d2eeab85f184d => C:\Program Files\HP\HP ENVY 5660 series\bin\HPRewards.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {ADF623AC-AF47-4DE2-9E3A-91494FE56E36} - System32\Tasks\HPCustParticipation HP ENVY 5660 series => C:\Program Files\HP\HP ENVY 5660 series\Bin\HPCustPartic.exe [2014-08-22] (Hewlett-Packard Development Company, LP)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\Brian\Documents\SimCity 4\Plugins\Network Addon Mod\Traffic Simulator Configuration Tool.lnk -> C:\Program Files\Traffic Simulator Configuration Tool\TSCT.bat ()
Shortcut: C:\Users\Brian\Desktop\Games\Games\SimCity 4\Mods and Tools\Traffic Simulator Configuration Tool.lnk -> C:\Program Files\Traffic Simulator Configuration Tool\TSCT.bat ()
Shortcut: C:\Users\Brian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxis\SimCity 4\Traffic Simulator Configuration Tool.lnk -> C:\Program Files\Traffic Simulator Configuration Tool\TSCT.bat ()

==================== Loaded Modules (Whitelisted) ==============

2013-09-05 01:14 - 2013-09-05 01:14 - 004300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:45 - 2010-10-20 16:45 - 008801120 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1"

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:04 - 2009-06-10 14:39 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Brian\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: a2AntiMalware => 2
MSCONFIG\Services: Apple Mobile Device => 3
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: BstHdLogRotatorSvc => 2
MSCONFIG\Services: GfExperienceService => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: NvStreamSvc => 2
MSCONFIG\Services: PDFProFiltSrvPP => 2
MSCONFIG\Services: Stereo Service => 2
MSCONFIG\Services: WinNetSvc2 => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^2.4GHz Wireless N Client Utility.lnk => C:\Windows\pss\2.4GHz Wireless N Client Utility.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Brian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP ENVY 5660 series.lnk => C:\Windows\pss\Monitor Ink Alerts - HP ENVY 5660 series.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AE43EAC771ADEE2FEEB86AD6759833F2448FAA11._service_run => "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=service /prefetch:8
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\Brian\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: Autodesk Desktop App => "C:\Program Files\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
MSCONFIG\startupreg: Autodesk Sync => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: BrMfcWnd => C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
MSCONFIG\startupreg: BrStsMon00 => C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: ControlCenter3 => C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
MSCONFIG\startupreg: ControlCenter4 => C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: IndexSearch => "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: Malwarebytes Anti-Exploit => C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe
MSCONFIG\startupreg: NvBackend => "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
MSCONFIG\startupreg: Nvtmru => "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: Steam => "C:\Program Files\Steam\steam.exe" -silent
MSCONFIG\startupreg: WN311T.exe => C:\Program Files\NETGEAR\WN311T\WN311T.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{85E83454-DF00-4F46-AE17-5680C8A78605}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{2145A948-81E9-4B58-85F1-730CFEC49A01}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{018FB3CC-5708-4B35-A0F9-50D6148899F1}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{10669CC4-ED71-4164-B1E2-185722CE0AE5}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe

==================== Restore Points =========================

29-04-2018 17:06:40 Windows Update
02-05-2018 21:57:37 Windows Update
03-05-2018 23:54:23 Microsoft Hotfix
06-05-2018 15:32:30 Windows Update
09-05-2018 03:30:28 Windows Update
10-05-2018 19:47:51 Revo Uninstaller's restore point - Akamai NetSession Interface
10-05-2018 19:52:15 Revo Uninstaller's restore point - Caesium version 1.7.0
11-05-2018 21:01:37 Windows Update
11-05-2018 21:40:51 Restore Point #1

==================== Faulty Device Manager Devices =============

Name: Microsoft Virtual WiFi Miniport Adapter #2
Description: Microsoft Virtual WiFi Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (05/13/2018 06:15:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: software_reporter_tool.exe, version: 29.154.200.0, time stamp: 0x5ae90712
Faulting module name: software_reporter_tool.exe, version: 29.154.200.0, time stamp: 0x5ae90712
Exception code: 0xc0000005
Fault offset: 0x00105e3b
Faulting process id: 0xcc8
Faulting application start time: 0x01d3eb2109473ca0
Faulting application path: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\SwReporter\29.154.200\software_reporter_tool.exe
Faulting module path: C:\Users\Brian\AppData\Local\Google\Chrome\User Data\SwReporter\29.154.200\software_reporter_tool.exe
Report Id: 4b918ac0-5714-11e8-a788-001d60e9db68

Error: (05/13/2018 06:15:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 59.0.3.6691, time stamp: 0x5ae39f1a
Faulting module name: user32.dll, version: 6.1.7601.23594, time stamp: 0x58249e2b
Exception code: 0xc0000005
Fault offset: 0x0001636c
Faulting process id: 0xe2c
Faulting application start time: 0x01d3eb204cd9e6d0
Faulting application path: C:\Program Files\Mozilla Firefox\firefox.exe
Faulting module path: C:\Windows\system32\user32.dll
Report Id: 49139a40-5714-11e8-a788-001d60e9db68

Error: (05/13/2018 06:15:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 66.0.3359.139, time stamp: 0x5ae13fc6
Faulting module name: USER32.dll, version: 6.1.7601.23594, time stamp: 0x58249e2b
Exception code: 0xc0000005
Fault offset: 0x0001636c
Faulting process id: 0x1668
Faulting application start time: 0x01d3eb20f83fadc0
Faulting application path: C:\Program Files\Google\Chrome\Application\chrome.exe
Faulting module path: C:\Windows\system32\USER32.dll
Report Id: 48898a80-5714-11e8-a788-001d60e9db68

Error: (05/13/2018 03:43:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 59.0.3.6691, time stamp: 0x5ae39f1a
Faulting module name: xul.dll, version: 59.0.3.6691, time stamp: 0x5ae3a3cb
Exception code: 0xc0000005
Fault offset: 0x004bfb76
Faulting process id: 0x68c
Faulting application start time: 0x01d3eb0accd50060
Faulting application path: C:\Program Files\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files\Mozilla Firefox\xul.dll
Report Id: 0bafdca0-56ff-11e8-a1de-001d60e9db68

Error: (05/13/2018 03:43:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 59.0.3.6691, time stamp: 0x5ae39f1a
Faulting module name: user32.dll, version: 6.1.7601.23594, time stamp: 0x58249e2b
Exception code: 0xc0000005
Fault offset: 0x0001636c
Faulting process id: 0x66c
Faulting application start time: 0x01d3eb0ad01648b0
Faulting application path: C:\Program Files\Mozilla Firefox\firefox.exe
Faulting module path: C:\Windows\system32\user32.dll
Report Id: 0bae7d10-56ff-11e8-a1de-001d60e9db68

Error: (05/12/2018 10:07:14 PM) (Source: Wininit) (EventID: 1015) (User: )
Description: A critical system process, C:\Windows\system32\lsass.exe, failed with status code c0000005. The machine must now be restarted.

Error: (05/12/2018 05:20:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 66.0.3359.139, time stamp: 0x5ae13fc6
Faulting module name: USER32.dll, version: 6.1.7601.23594, time stamp: 0x58249e2b
Exception code: 0xc0000005
Fault offset: 0x0001636c
Faulting process id: 0x1038
Faulting application start time: 0x01d3e9eb8cb941f0
Faulting application path: C:\Program Files\Google\Chrome\Application\chrome.exe
Faulting module path: C:\Windows\system32\USER32.dll
Report Id: d6336810-55de-11e8-a331-001d60e9db68

Error: (05/12/2018 05:20:21 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 66.0.3359.139, time stamp: 0x5ae13fc6
Faulting module name: ntdll.dll, version: 6.1.7601.24117, time stamp: 0x5add1df9
Exception code: 0xc0000005
Fault offset: 0x000529df
Faulting process id: 0x1688
Faulting application start time: 0x01d3e9eb8ccc4cf0
Faulting application path: C:\Program Files\Google\Chrome\Application\chrome.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: d632cbd0-55de-11e8-a331-001d60e9db68


System errors:
=============
Error: (05/13/2018 06:09:27 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout.

Error: (05/13/2018 06:08:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The atksgt service failed to start due to the following error:
The system cannot find the file specified.

Error: (05/13/2018 06:07:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The AMD External Events Utility service terminated unexpectedly. It has done this 1 time(s).

Error: (05/13/2018 06:07:10 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (05/13/2018 06:07:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s).

Error: (05/13/2018 10:31:36 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 1

The details view of this entry contains further information.

Error: (05/13/2018 10:31:36 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 1

The details view of this entry contains further information.

Error: (05/13/2018 10:31:36 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 10
Processor ID: 1

The details view of this entry contains further information.


Windows Defender:
===================================
Date: 2016-11-23 03:53:06.437
Description:
Windows Defender scan has been stopped before completion.
Scan ID:{CDB51533-EEB1-46AB-80C3-76C8F4A6551F}
Scan Type:AntiSpyware
Scan Parameters:Quick Scan

Date: 2016-09-04 02:59:14.724
Description:
Windows Defender scan has been stopped before completion.
Scan ID:{2C6C7A14-A9C1-4418-8B92-07D66C67A9EF}
Scan Type:AntiSpyware
Scan Parameters:Quick Scan

Date: 2016-06-04 03:14:24.942
Description:
Windows Defender scan has been stopped before completion.
Scan ID:{61092E3C-8DAC-40A6-95FE-AEE30C73187F}
Scan Type:AntiSpyware
Scan Parameters:Quick Scan

Date: 2016-02-15 19:13:18.986
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name=SoftwareBundler:Win32/Mizenota&threatid=223449
Name:SoftwareBundler:Win32/Mizenota
ID:223449
Severity:High
Category:Software Bundler
Path Found:containerfile:C:\Users\Brian\Downloads\EuroTruckSimulator2CDKeyGenera Downloader.rar;file:C:\Users\Brian\Downloads\EuroTruckSimulator2CDKeyGenera Downloader.rar->CMT;filelocalcopy:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{663C7ACA-8F97-4219-99EE-B5416090D454}-EuroTruckSimulator2CDKeyGenera Downloader.rar;filelocalcopy:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{F142CAEC-2021-4A61-9756-0CE8402BCA64}-EuroTruckSimulator2CDKeyGenera Downloader.rar;webfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{663C7ACA-8F97-4219-99EE-B5416090D454}-EuroTruckSimulator2CDKeyGenera Downloader.rar|http://mymediadownloadsthirtytwo.co...yb21wdGRvd25sb2FkZXIuY29tJTJGbG9nby5wbmcmcHJl
Detection Type:Concrete
Detection Source:Downloads and attachments
Status:Unknown
Process Name:C:\Program Files\Google\Chrome\Application\chrome.exe

Date: 2016-02-15 19:12:43.723
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name=SoftwareBundler:Win32/Mizenota&threatid=223449
Name:SoftwareBundler:Win32/Mizenota
ID:223449
Severity:High
Category:Software Bundler
Path Found:containerfile:C:\Users\Brian\Downloads\EuroTruckSimulator2CDKeyGenera Downloader.rar;file:C:\Users\Brian\Downloads\EuroTruckSimulator2CDKeyGenera Downloader.rar->CMT;filelocalcopy:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{F142CAEC-2021-4A61-9756-0CE8402BCA64}-EuroTruckSimulator2CDKeyGenera Downloader.rar;webfile:C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{F142CAEC-2021-4A61-9756-0CE8402BCA64}-EuroTruckSimulator2CDKeyGenera Downloader.rar|http://mymediadownloadsthirtytwo.co...JGcHJvbXB0ZG93bmxvYWRlci5jb20lMkYlM0ZjYW5jZWw
Detection Type:Concrete
Detection Source:Downloads and attachments
Status:Unknown
Process Name:C:\Program Files\Google\Chrome\Application\chrome.exe

Date: 2014-02-07 12:27:25.253
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified.
Signature version:0.0.0.0
Engine version:0.0.0.0

CodeIntegrity:
===================================

Date: 2016-07-25 16:22:14.208
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-25 01:23:19.251
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-25 01:10:09.306
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 21:23:12.036
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 15:21:33.606
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 15:02:29.721
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 13:17:26.948
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-07-24 05:33:00.907
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks32.dll because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4000+
Percentage of memory in use: 51%
Total physical RAM: 3071.3 MB
Available physical RAM: 1503.61 MB
Total Virtual: 7675.66 MB
Available Virtual: 5770.18 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:372.61 GB) (Free:72.79 GB) NTFS ==>[drive with boot components (obtained from BCD)]


==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 372.6 GB) (Disk ID: 00000001)
Partition 1: (Active) - (Size=372.6 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================
 
Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST(FRST64) and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
 

Attachments

  • fixlist.txt
    1.6 KB · Views: 1
Fix result of Farbar Recovery Scan Tool (x86) Version: 13.05.2018
Ran by Brian (14-05-2018 15:58:41) Run:1
Running from C:\Users\Brian\Desktop
Loaded Profiles: Brian (Available Profiles: Brian)
Boot Mode: Normal

==============================================

fixlist content:
*****************
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\MountPoints2: {96ff7f85-ae8e-11df-911b-806e6f6e6963} - D:\Autorun.exe
HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\...\Winlogon: [Shell] C:\Windows\explorer.exe [2972672 2016-08-29] (Microsoft Corporation) <==== ATTENTION
SearchScopes: HKLM -> DefaultScope {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL =
S2 atksgt; system32\DRIVERS\atksgt.sys [X]
S4 lirsgt; system32\DRIVERS\lirsgt.sys [X]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
S3 NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2015-07-30 23:39 - 2015-07-30 23:39 - 000039997 _____ () C:\Users\Brian\AppData\Local\Perfmon.PerfmonCfg
2018-03-29 19:24 - 2018-03-29 19:24 - 000000832 _____ () C:\Users\Brian\AppData\Local\recently-used.xbel
2011-12-10 18:50 - 2018-05-03 17:05 - 000007601 _____ () C:\Users\Brian\AppData\Local\Resmon.ResmonCfg
2018-05-11 22:06 - 2018-04-22 16:44 - 001310480 _____ (Microsoft Corporation) C:\Users\Brian\AppData\Local\Temp\dllnt_dump.dll
CustomCLSID: HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{6d05bf60-3eaf-4a97-87c5-10cce505435b}\localserver32 -> C:\Users\Brian\AppData\Local\Temp\{9c0ba3c1-2b67-45eb-bf69-bed9658d28d2}\IDriver.NonElevated.exe => No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]

*****************

"HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{96ff7f85-ae8e-11df-911b-806e6f6e6963}" => removed successfully.
HKLM\Software\Classes\CLSID\{96ff7f85-ae8e-11df-911b-806e6f6e6963} => not found
"HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell" => removed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\System\CurrentControlSet\Services\atksgt" => removed successfully.
atksgt => service removed successfully.
"HKLM\System\CurrentControlSet\Services\lirsgt" => removed successfully.
lirsgt => service removed successfully.
"HKLM\System\CurrentControlSet\Services\nvlddmkm" => removed successfully.
nvlddmkm => service removed successfully.
"HKLM\System\CurrentControlSet\Services\NvStreamKms" => removed successfully.
NvStreamKms => service removed successfully.
"HKLM\System\CurrentControlSet\Services\nvvad_WaveExtensible" => removed successfully.
nvvad_WaveExtensible => service removed successfully.
"HKLM\System\CurrentControlSet\Services\Synth3dVsc" => removed successfully.
Synth3dVsc => service removed successfully.
"HKLM\System\CurrentControlSet\Services\tsusbhub" => removed successfully.
tsusbhub => service removed successfully.
"HKLM\System\CurrentControlSet\Services\VGPU" => removed successfully.
VGPU => service removed successfully.
C:\Users\Brian\AppData\Local\Perfmon.PerfmonCfg => moved successfully
C:\Users\Brian\AppData\Local\recently-used.xbel => moved successfully
C:\Users\Brian\AppData\Local\Resmon.ResmonCfg => moved successfully
C:\Users\Brian\AppData\Local\Temp\dllnt_dump.dll => moved successfully
"HKU\S-1-5-21-2999710313-2874845586-1671460366-1000_Classes\CLSID\{6d05bf60-3eaf-4a97-87c5-10cce505435b}" => removed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => removed successfully.
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
C:\ProgramData\Reprise => ":wupeogjxldtlfudivq`qsp`27hfm" ADS removed successfully.

==== End of Fixlog 15:58:56 ====
 
Last scans...

redtarget.gif
Download Security Check from here or here and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


redtarget.gif
Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
Make sure the following options are checked:
  • Internet Services
  • Windows Firewall
  • System Restore
  • Security Center
  • Windows Update
  • Windows Defender
  • Other Services

Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.
Please copy and paste the log to your reply.


redtarget.gif
Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.


redtarget.gif
Download Sophos Free Virus Removal Tool and save it to your desktop.
  • Double click the icon and select Run
  • Click Next
  • Select I accept the terms in this license agreement, then click Next twice
  • Click Install
  • Click Finish to launch the program
  • Once the virus database has been updated click Start Scanning
  • If any threats are found click Details, then View log file... (bottom left hand corner)
  • Copy and paste the results in your reply
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup
  • Click Exit to close the program
 
Results of screen317's Security Check version 1.014 --- 12/23/15
Windows 7 Service Pack 1 x86 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 8 Update 171
Java version 32-bit out of Date!
Mozilla Firefox (60.0)
Google Chrome (66.0.3359.139)
Google Chrome (SetupMetrics...)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
 
Farbar Service Scanner Version: 27-01-2016
Ran by Brian (administrator) on 14-05-2018 at 17:18:04
Running from "C:\Users\Brian\Desktop"
Microsoft Windows 7 Ultimate Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Policy:
========================


Action Center:
============


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\system32\nsisvc.dll => File is digitally signed
C:\Windows\system32\Drivers\nsiproxy.sys => File is digitally signed
C:\Windows\system32\dhcpcore.dll => File is digitally signed
C:\Windows\system32\Drivers\afd.sys => File is digitally signed
C:\Windows\system32\Drivers\tdx.sys => File is digitally signed
C:\Windows\system32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\system32\dnsrslvr.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\mpssvc.dll => File is digitally signed
C:\Windows\system32\bfe.dll => File is digitally signed
C:\Windows\system32\Drivers\mpsdrv.sys => File is digitally signed
C:\Windows\system32\SDRSVC.dll => File is digitally signed
C:\Windows\system32\vssvc.exe => File is digitally signed
C:\Windows\system32\wscsvc.dll => File is digitally signed
C:\Windows\system32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\system32\wuaueng.dll => File is digitally signed
C:\Windows\system32\qmgr.dll => File is digitally signed
C:\Windows\system32\es.dll => File is digitally signed
C:\Windows\system32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\system32\ipnathlp.dll => File is digitally signed
C:\Windows\system32\iphlpsvc.dll => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed


**** End of log ****
 
The Sophos scan found one threat, but it's a game that I've bought and played in the past. I'm not sure if this is a false positive or not. Should I still start the cleanup? As of now I've opened Chrome again and it still crashed, crashed all other open programs along with the lsass.exe process, displaying the critical error message and causing a restart. Is it possible that Chrome has been modified or corrupted by some previously removed malware?

Here's the last log:

2018-05-15 02:37:09.044 Sophos Virus Removal Tool version 2.6.1
2018-05-15 02:37:09.044 Copyright (c) 2009-2017 Sophos Limited. All rights reserved.

2018-05-15 02:37:09.044 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2018-05-15 02:37:09.044 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x100 PT=0x1 Win32
2018-05-15 02:37:09.044 Checking for updates...
2018-05-15 02:37:09.372 Update progress: proxy server not available
2018-05-15 02:38:37.929 Downloading updates...
2018-05-15 02:38:37.944 Update progress: [I96736] sdds.svrt_10: adding primary package C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED baseVersion=1
2018-05-15 02:38:37.944 Update progress: [I95020] sdds.svrt_10: looking for packages included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2018-05-15 02:38:37.944 Update progress: [I22529] sdds.svrt_10: looking for supplements included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2018-05-15 02:38:37.944 Update progress: [I49502] sdds.savi0910.xml: found supplement SAVIW32 LATEST path= baseVersion= [included from product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=]
2018-05-15 02:38:37.944 Update progress: [I95020] sdds.savi0910.xml: looking for packages included from product SAVIW32 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I22529] sdds.savi0910.xml: looking for supplements included from product SAVIW32 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I49502] sdds.data0910.xml: found supplement IDE547 LATEST path= baseVersion= [included from product SAVIW32 LATEST path=]
2018-05-15 02:38:37.944 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE547 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE547 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I49502] sdds.data0910.xml: found supplement IDE548 LATEST path= baseVersion= [included from product IDE547 LATEST path=]
2018-05-15 02:38:37.944 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE548 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE548 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I49502] sdds.data0910.xml: found supplement IDE549 LATEST path= baseVersion= [included from product IDE548 LATEST path=]
2018-05-15 02:38:37.944 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE549 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE549 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I49502] sdds.data0910.xml: found supplement IDE550 LATEST path= baseVersion= [included from product IDE549 LATEST path=]
2018-05-15 02:38:37.944 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE550 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE550 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I49502] sdds.data0910.xml: found supplement IDE551 LATEST path= baseVersion= [included from product IDE550 LATEST path=]
2018-05-15 02:38:37.944 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE551 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE551 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I49502] sdds.data0910.xml: found supplement IDE552 LATEST path= baseVersion= [included from product IDE551 LATEST path=]
2018-05-15 02:38:37.944 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE552 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE552 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I49502] sdds.data0910.xml: found supplement IDE553 LATEST path= baseVersion= [included from product IDE552 LATEST path=]
2018-05-15 02:38:37.944 Update progress: [I95020] sdds.data0910.xml: looking for packages included from product IDE553 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I22529] sdds.data0910.xml: looking for supplements included from product IDE553 LATEST path=
2018-05-15 02:38:37.944 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 RECOMMENDED path=
2018-05-15 02:38:41.486 Option all = no
2018-05-15 02:38:41.486 Option recurse = yes
2018-05-15 02:38:41.486 Option archive = no
2018-05-15 02:38:41.486 Option service = yes
2018-05-15 02:38:41.486 Option confirm = yes
2018-05-15 02:38:41.486 Option sxl = yes
2018-05-15 02:38:41.486 Option max-data-age = 35
2018-05-15 02:38:41.486 Option vdl-logging = yes
2018-05-15 02:38:41.564 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2018-05-15 02:38:41.564 Machine ID: 08c9fe29c46a4335a7e7395205a7af8c
2018-05-15 02:38:41.595 Component SVRTcli.exe version 2.6.1
2018-05-15 02:38:41.595 Component control.dll version 2.6.1
2018-05-15 02:38:41.595 Component SVRTservice.exe version 2.6.1
2018-05-15 02:38:41.595 Component engine\osdp.dll version 1.44.1.2286
2018-05-15 02:38:41.595 Component engine\veex.dll version 3.68.6.2286
2018-05-15 02:38:41.595 Component engine\savi.dll version 9.0.7.2286
2018-05-15 02:38:41.595 Component rkdisk.dll version 1.5.31.1
2018-05-15 02:38:41.610 Version info: Product version 2.6.1
2018-05-15 02:38:41.610 Version info: Detection engine 3.68.6
2018-05-15 02:38:41.610 Version info: Detection data 5.46
2018-05-15 02:38:41.610 Version info: Build date 11/28/2017
2018-05-15 02:38:41.610 Version info: Data files added 908
2018-05-15 02:38:41.610 Version info: Last successful update 5/14/2018 5:37:15 PM
2018-05-15 02:39:01.032 Update progress: [I19463] Syncing product SAVIW32 LATEST path=
2018-05-15 02:39:07.194 Update progress: [I19463] Syncing product IDE547 LATEST path=
2018-05-15 02:39:11.874 Update progress: [I19463] Syncing product IDE548 LATEST path=
2018-05-15 02:39:17.428 Update progress: [I19463] Syncing product IDE549 LATEST path=
2018-05-15 02:39:21.000 Update progress: [I19463] Syncing product IDE550 LATEST path=
2018-05-15 02:39:25.244 Update progress: [I19463] Syncing product IDE551 LATEST path=
2018-05-15 02:39:28.691 Update progress: [I19463] Syncing product IDE552 LATEST path=
2018-05-15 02:39:28.691 Update progress: [I19463] Syncing product IDE553 LATEST path=
2018-05-15 02:39:28.925 Installing updates...
2018-05-15 02:39:30.142 Error level 1
2018-05-15 02:39:31.437 Update successful
2018-05-15 02:39:52.606 Option all = no
2018-05-15 02:39:52.606 Option recurse = yes
2018-05-15 02:39:52.606 Option archive = no
2018-05-15 02:39:52.606 Option service = yes
2018-05-15 02:39:52.606 Option confirm = yes
2018-05-15 02:39:52.606 Option sxl = yes
2018-05-15 02:39:52.622 Option max-data-age = 35
2018-05-15 02:39:52.622 Option vdl-logging = yes
2018-05-15 02:39:52.653 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2018-05-15 02:39:52.653 Machine ID: 08c9fe29c46a4335a7e7395205a7af8c
2018-05-15 02:39:52.653 Component SVRTcli.exe version 2.6.1
2018-05-15 02:39:52.653 Component control.dll version 2.6.1
2018-05-15 02:39:52.653 Component SVRTservice.exe version 2.6.1
2018-05-15 02:39:52.653 Component engine\osdp.dll version 1.44.1.2286
2018-05-15 02:39:52.653 Component engine\veex.dll version 3.68.6.2286
2018-05-15 02:39:52.653 Component engine\savi.dll version 9.0.7.2286
2018-05-15 02:39:52.653 Component rkdisk.dll version 1.5.31.1
2018-05-15 02:39:52.653 Version info: Product version 2.6.1
2018-05-15 02:39:52.653 Version info: Detection engine 3.68.6
2018-05-15 02:39:52.653 Version info: Detection data 5.46
2018-05-15 02:39:52.653 Version info: Build date 11/28/2017
2018-05-15 02:39:52.653 Version info: Data files added 908
2018-05-15 02:39:52.653 Version info: Last successful update 5/14/2018 7:39:31 PM

2018-05-15 06:46:46.132 Could not open C:\Boot\BCD
2018-05-15 06:46:48.815 Could not open C:\hiberfil.sys
2018-05-15 06:49:23.942 >>> Virus 'Mal/Generic-S' found in file C:\Program Files\Atari\RollerCoaster Tycoon® 3\RCT3plus.exe
2018-05-15 06:49:23.942 >>> Virus 'Mal/Generic-S' found in file C:\Program Files\Atari\RollerCoaster Tycoon® 3\RCT3plus.exe
2018-05-15 06:49:23.942 >>> Virus 'Mal/Generic-S' found in file C:\Program Files\Atari\RollerCoaster Tycoon® 3\RCT3plus.exe
2018-05-15 06:49:23.942 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1609
2018-05-15 06:49:23.942 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500
2018-05-15 06:49:23.942 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-2999710313-2874845586-1671460366-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500
2018-05-15 07:59:30.778 Could not open C:\System Volume Information\{01823b2b-4f64-11e8-9b77-001d60e9db68}{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-05-15 07:59:30.794 Could not open C:\System Volume Information\{3082758f-54a1-11e8-af59-001d60e9db68}{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-05-15 07:59:30.794 Could not open C:\System Volume Information\{30827593-54a1-11e8-af59-001d60e9db68}{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-05-15 07:59:30.794 Could not open C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-05-15 07:59:30.794 Could not open C:\System Volume Information\{9f26089e-555f-11e8-b2ca-001d60e9db68}{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-05-15 07:59:30.794 Could not open C:\System Volume Information\{a9b6f88d-517b-11e8-bf53-001d60e9db68}{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-05-15 07:59:30.794 Could not open C:\System Volume Information\{c48437f9-559a-11e8-adc6-001d60e9db68}{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-05-15 07:59:30.794 Could not open C:\System Volume Information\{d7d69fa3-531d-11e8-b1c2-001d60e9db68}{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-05-15 07:59:30.794 Could not open C:\System Volume Information\{f6c94919-57d1-11e8-9cc7-001d60e9db68}{3808876b-c176-4e48-b7ae-04046e6cc752}
2018-05-15 09:05:46.438 Could not open C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
2018-05-15 09:05:46.485 Could not open C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
2018-05-15 09:06:06.000 Could not open C:\Windows\System32\config\RegBack\DEFAULT
2018-05-15 09:06:06.032 Could not open C:\Windows\System32\config\RegBack\SAM
2018-05-15 09:06:06.032 Could not open C:\Windows\System32\config\RegBack\SECURITY
2018-05-15 09:06:06.032 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
2018-05-15 09:06:06.032 Could not open C:\Windows\System32\config\RegBack\SYSTEM
2018-05-15 09:33:42.237 Could not open LOGICAL:0003:00000000
2018-05-15 09:33:42.252 Could not open D:\
2018-05-15 09:33:42.252 Could not open LOGICAL:0005:00000000
2018-05-15 09:33:42.252 Could not open F:\
2018-05-15 09:33:42.346 Could not open PHYSICAL:0081:0000:0000:0001
2018-05-15 09:33:42.377 The following items will be cleaned up:
2018-05-15 09:33:42.377 Mal/Generic-S
 
Your computer is clean

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download
51a5ce45263de-delfix.png
DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore
  • Reset system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.

2. Make sure Windows Updates are current.

3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

4. Check if your browser plugins are up to date.
Firefox - https://www.mozilla.org/en-US/plugincheck/
other browsers: https://browsercheck.qualys.com/ (click on "Scan without installing plugin" and then on "Scan now")

5. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

6. Run Temporary File Cleaner (TFC) and AdwCleaner weekly (you need to redownload these tools since they were removed by DelFix).

7. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

8. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

9. Read:
How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

10. Please, let me know, how your computer is doing.
 
I very much appreciate your time and instruction. I decided to just completely uninstall Chrome and that appears to have fixed the crashes and errors, as I can actually open and use it now. It must have been corrupted somehow. Everything appears to be clean and I'm no longer getting the errors in the event logs anymore. Thank you so much for your assistance Broni!
 
Back