Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

istatic.eshopcomp.com requested logs

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

istatic.eshopcomp.com requested logs

Unread postby MnSD » December 13th, 2015, 8:13 pm

Hello Folks I will try this again, and apologize for the fact that I put one log in each post. I will display my first log below and as the Additional one will not fit in the same post, I will add it as an Attachment.

I noticed a couple days ago popups from Malware Bytes paid version that it was blocking something in my Chrome browser that was trying to connect tho this website istatic.eshopcomp.com I googled it and it seems its some malware of some type? I have a Dell Laptop running Windows 10 with auto updates on and I checked and they have all launched and I get some everyweek. I have Malwarebytes and its up to date/ The message from Malwarebytes is Malicious website blocked. ip address 205.185.208.206 Type Outbound Port 61213 also have eset smart security 9 its up to date also and current. plus malwarebytes anti -exploit free version.

here is the FRST log I will add the Additonal log
Addition.txt
as an attachmwent Thanks very much for your help.

FRST Log


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-12-2015 01
Ran by Michael (administrator) on MICHAEL-PC (12-12-2015 14:15:13)
Running from C:\Users\Michael\Downloads
Loaded Profiles: Michael & (Available Profiles: Michael & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(Zemana Ltd.) C:\Program Files (x86)\AntiLogger\AntiLogger.exe
(Google Inc.) C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
(Google Inc.) C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Michael\Downloads\FRST64 (2).exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-12] (Alps Electric Co., Ltd.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [4500640 2011-03-10] (Dell Inc.)
HKLM\...\Run: [DellStage] => C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe [1802472 2011-01-25] ()
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-16] (Apple Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2011-09-16] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452272 2012-08-31] (CANON INC.)
HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2621240 2015-11-18] (Malwarebytes Corporation)
HKLM-x32\...\Run: [AntiLogger] => C:\Program Files (x86)\AntiLogger\AntiLogger.exe [14679464 2014-12-30] (Zemana Ltd.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [61200 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [103696 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\Run: [AppleIEDAV] => C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [1079592 2015-06-26] (Apple Inc.)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [349968 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\Run: [Google Update] => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-12-12] (Google Inc.)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [61200 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [103696 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AppleIEDAV] => C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [1079592 2015-06-26] (Apple Inc.)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [349968 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-10-29] (Microsoft Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 127.0.0.1 localhost
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{65267836-78b0-466d-b4e7-7e1c73620721}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpage.com
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpage.com
SearchScopes: HKLM -> DefaultScope {23392EC5-488B-4C8F-BE7D-B591FEDF7497} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM -> {23392EC5-488B-4C8F-BE7D-B591FEDF7497} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {BB692C45-6F19-43E7-AE01-FB2B2FAA29BE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2606919885-2507221499-1667024737-1000 -> {23392EC5-488B-4C8F-BE7D-B591FEDF7497} URL =
SearchScopes: HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {23392EC5-488B-4C8F-BE7D-B591FEDF7497} URL =
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll [2014-01-24] (CANON INC.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-11-02] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-11-02] (Oracle Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2013-10-08] (Adblock Plus)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-01-24] (CANON INC.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-11-02] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-11-02] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2013-10-08] (Adblock Plus)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll [2014-01-24] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-01-24] (CANON INC.)
Toolbar: HKU\S-1-5-21-2606919885-2507221499-1667024737-1000 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll [2014-01-24] (CANON INC.)
Toolbar: HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll [2014-01-24] (CANON INC.)
DPF: HKLM-x32 {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} hxxp://www.support.dell.com/systemprofi ... ProExe.CAB
DPF: HKLM-x32 {57AF0810-BDA7-47A5-B02D-FDA1073C04B0} hxxps://www.mydlink.com/8D/activeX//TunnelX.ocx
DPF: HKLM-x32 {682C59F5-478C-4421-9070-AD170D143B77} hxxp://www.dell.com/support/troubleshoo ... /pcd86.cab
DPF: HKLM-x32 {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} hxxp://xserv.dell.com/DellDriverScanner/DellSystem.CAB
DPF: HKLM-x32 {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} hxxp://support.dell.com/systemprofiler/ ... emLite.CAB
DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.co ... .5.5.0.cab

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2606919885-2507221499-1667024737-1000 -> hxxp://www.startpage.com/

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-11-02] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-11-02] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @canon.com/MycameraPlugin -> C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll [2008-10-15] (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-11-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-11-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-11-02] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-09] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2606919885-2507221499-1667024737-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-12] (Google Inc.)
FF Plugin HKU\S-1-5-21-2606919885-2507221499-1667024737-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-12] (Google Inc.)
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
StartMenuInternet: FIREFOX.EXE -

Chrome:
=======
CHR HomePage: Default -> hxxp://www.bing.com/?mkt=en-US&pc=__PARAM__
CHR Profile: C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-05]
CHR Extension: (Google Drive) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Google Search) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (iCloud Bookmarks) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2015-10-06]
CHR Extension: (Google Docs Offline) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-17]
CHR Extension: (AdBlock) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-12-04]
CHR Extension: (Hide My AdBlocker) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihcngphjjankfngmgdkihhngndcdflc [2015-12-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-25]
CHR Extension: (Gmail) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [cdldbgojabdbiapkfeldpfmbecmcaoec] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [cdldbgojabdbiapkfeldpfmbecmcaoec] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2015-11-30] (Microsoft Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2505472 2015-10-09] (ESET)
S4 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [24888 2015-07-26] (Hewlett-Packard Company)
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [739640 2015-11-18] (Malwarebytes Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S4 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2012-09-04] (Nalpeiron Ltd.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [303360 2015-06-24] (Realtek Semiconductor)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-29] (Microsoft Corporation)
S2 ZAMSvc; "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /service [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AntiLog32; C:\WINDOWS\system32\drivers\AntiLog64.sys [49752 2015-12-04] (Zemana Ltd.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-10-15] (Motorola Solutions, Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [264040 2015-07-30] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [200192 2015-07-30] (ESET)
R0 edevmon; C:\Windows\SysWOW64\DRIVERS\edevmon.sys [239296 2013-09-17] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [14976 2015-07-30] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [186784 2015-07-30] (ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [142976 2015-10-07] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [206312 2015-07-30] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [52872 2015-07-30] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [69840 2015-07-30] (ESET)
S3 ESETCleanersDriver; C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys [170280 2015-12-11] (ESET)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-12-11] ()
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [63064 2015-11-18] ()
R3 keycrypt; C:\Windows\System32\DRIVERS\KeyCrypt64.sys [76520 2014-12-30] (Zemana Ltd.)
R1 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [109272 2015-06-18] (Malwarebytes Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2015-12-12] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-29] (Realtek )
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [30848 2015-12-12] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-29] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-29] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-29] (Microsoft Corporation)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [199536 2015-12-10] (Zemana Ltd.)
S3 efavdrv; \??\C:\WINDOWS\system32\drivers\efavdrv.sys [X]
U3 idsvc; no ImagePath
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-12 14:13 - 2015-12-12 14:14 - 02369536 _____ (Farbar) C:\Users\Michael\Downloads\FRST64 (2).exe
2015-12-12 09:31 - 2015-12-12 09:31 - 00002503 _____ C:\Users\Michael\Desktop\Google Chrome.lnk
2015-12-12 09:31 - 2015-12-12 09:31 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-12 09:30 - 2015-12-12 13:35 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2606919885-2507221499-1667024737-1000UA.job
2015-12-12 09:30 - 2015-12-12 09:35 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2606919885-2507221499-1667024737-1000Core.job
2015-12-12 09:30 - 2015-12-12 09:30 - 00004060 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2606919885-2507221499-1667024737-1000UA
2015-12-12 09:30 - 2015-12-12 09:30 - 00003684 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2606919885-2507221499-1667024737-1000Core
2015-12-12 09:24 - 2014-02-16 16:24 - 10820032 _____ (SurfRight B.V.) C:\Users\Michael\Downloads\HitmanPro_x64 - Copy.exe
2015-12-12 09:14 - 2015-12-12 09:29 - 00000000 ____D C:\Users\Michael\AppData\Local\Deployment
2015-12-12 06:17 - 2015-12-12 09:24 - 01309184 _____ C:\Users\Michael\Downloads\zoek (2).exe
2015-12-12 06:17 - 2015-12-12 06:18 - 01309184 _____ C:\Users\Michael\Downloads\zoek (1).exe
2015-12-12 06:17 - 2015-12-12 06:17 - 00000000 ____D C:\zoek_backup
2015-12-12 06:10 - 2015-12-12 06:10 - 00085576 _____ C:\Users\Michael\Downloads\Extras.Txt
2015-12-12 06:09 - 2015-12-12 06:09 - 00328268 _____ C:\Users\Michael\Downloads\OTL.Txt
2015-12-12 05:53 - 2015-12-12 05:53 - 00602112 _____ (OldTimer Tools) C:\Users\Michael\Downloads\OTL.exe
2015-12-12 05:50 - 2015-12-12 05:50 - 02031992 _____ (Microsoft Corporation) C:\Users\Michael\Downloads\MGADiag.exe
2015-12-12 05:50 - 2015-12-12 05:50 - 00000000 ____D C:\ProgramData\Office Genuine Advantage
2015-12-12 05:48 - 2015-12-12 05:48 - 00468480 _____ () C:\Users\Michael\Downloads\CKScanner.exe
2015-12-12 05:34 - 2015-12-12 06:45 - 00000000 ____D C:\ProgramData\MyTurboPC.com
2015-12-12 05:34 - 2015-12-12 05:34 - 00000000 ____D C:\Users\Michael\AppData\Roaming\MyTurboPC.com
2015-12-12 05:33 - 2015-12-12 05:34 - 06431232 _____ (MyTurboPC.com) C:\Users\Michael\Downloads\Myturbopc_DAD29E51-CC90-437D-86AD-B89FD0F6FF5A_.exe
2015-12-12 05:33 - 2015-12-12 05:34 - 06431232 _____ (MyTurboPC.com) C:\Users\Michael\Downloads\Myturbopc_4AB3FF50-645F-4103-8F46-1E85701C5CFA_.exe
2015-12-12 05:18 - 2015-12-12 05:19 - 05640685 _____ (Swearware) C:\Users\Michael\Downloads\ComboFix.exe
2015-12-12 05:18 - 2015-12-12 05:18 - 02369536 _____ (Farbar) C:\Users\Michael\Downloads\FRST64 (1).exe
2015-12-12 05:10 - 2015-12-12 05:10 - 01739080 _____ (SurfRight B.V.) C:\Users\Michael\Downloads\hmpalert_x64.exe
2015-12-12 05:05 - 2015-12-12 05:42 - 00000000 ____D C:\Users\Michael\AppData\Local\CrashDumps
2015-12-12 04:06 - 2015-12-12 04:06 - 04676456 _____ (Kaspersky Lab ZAO) C:\Users\Michael\Downloads\tdsskiller.exe
2015-12-12 03:49 - 2015-12-12 05:22 - 00000000 ____D C:\Users\Michael\Downloads\Clif
2015-12-12 00:55 - 2015-12-12 00:55 - 02991832 _____ (ESET) C:\Users\Michael\Downloads\ERARemover_x64 (1).exe
2015-12-12 00:50 - 2015-12-12 00:50 - 00000723 _____ C:\Users\Michael\Desktop\istatic,eshop.txt
2015-12-11 23:39 - 2015-12-11 23:39 - 00000000 _____ C:\autoexec.bat
2015-12-11 23:38 - 2015-12-11 23:38 - 00022704 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2015-12-11 23:32 - 2015-12-11 23:32 - 00065232 _____ (Malwarebytes) C:\Users\Michael\Downloads\regassassin-setup-1.03 (1).exe
2015-12-11 23:32 - 2015-12-11 23:32 - 00000000 ____D C:\Users\Michael\Desktop\mbar
2015-12-11 23:19 - 2015-12-11 23:19 - 00290304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\subinacl.exe
2015-12-11 23:19 - 2015-12-11 23:19 - 00000000 ____D C:\Program Files (x86)\Adware Removal Tool by TSA
2015-12-11 23:18 - 2015-12-11 23:23 - 00700584 _____ C:\Users\Michael\Downloads\Adware_Removal_Tool_by_TSA.exe
2015-12-11 19:09 - 2015-12-11 19:11 - 00048638 _____ C:\Users\Michael\Downloads\Addition.txt
2015-12-11 19:04 - 2015-12-12 14:15 - 00024927 _____ C:\Users\Michael\Downloads\FRST.txt
2015-12-11 19:00 - 2015-12-12 14:15 - 00000000 ____D C:\FRST
2015-12-11 18:59 - 2015-12-11 18:59 - 02369024 _____ (Farbar) C:\Users\Michael\Downloads\FRST64.exe
2015-12-11 18:10 - 2015-12-11 18:50 - 00000000 ____D C:\AdwCleaner
2015-12-09 21:45 - 2015-12-11 23:13 - 00000557 _____ C:\Users\Michael\Desktop\JRT.txt
2015-12-09 21:40 - 2015-12-09 21:40 - 01599336 _____ (Malwarebytes) C:\Users\Michael\Downloads\JRT.exe
2015-12-08 21:45 - 2015-12-08 21:45 - 00394960 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-08 13:06 - 2015-11-30 23:12 - 02152800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-12-08 13:06 - 2015-11-24 04:07 - 01817160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-12-08 13:06 - 2015-11-24 03:07 - 03671896 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-12-08 13:06 - 2015-11-24 03:06 - 01540768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-12-08 13:06 - 2015-11-24 02:26 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2015-12-08 13:06 - 2015-11-24 02:03 - 02918808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-12-08 13:06 - 2015-11-24 02:01 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2015-12-08 13:06 - 2015-11-24 01:54 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
2015-12-08 13:06 - 2015-11-24 01:53 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-12-08 13:06 - 2015-11-24 01:45 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshrm.dll
2015-12-08 13:06 - 2015-11-24 01:37 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
2015-12-08 13:06 - 2015-11-24 01:26 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2015-12-08 13:06 - 2015-11-24 01:19 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2015-12-08 13:06 - 2015-11-24 01:12 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
2015-12-08 13:06 - 2015-11-24 00:58 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-12-08 13:06 - 2015-11-24 00:55 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-12-08 13:06 - 2015-11-24 00:54 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2015-12-08 13:06 - 2015-11-24 00:52 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2015-12-08 13:06 - 2015-11-24 00:49 - 01648640 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2015-12-08 13:06 - 2015-11-24 00:27 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-12-08 13:06 - 2015-11-24 00:14 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
2015-12-08 13:06 - 2015-11-24 00:03 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-12-08 13:06 - 2015-11-23 23:59 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2015-12-08 13:06 - 2015-11-23 23:57 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2015-12-08 13:06 - 2015-11-23 23:35 - 22393856 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-12-08 13:06 - 2015-11-23 23:29 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-12-08 13:06 - 2015-11-23 23:25 - 24601600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-12-08 13:06 - 2015-11-23 23:23 - 13381120 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-12-08 13:06 - 2015-11-23 23:11 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-12-08 13:06 - 2015-11-23 23:09 - 19338240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-12-08 13:06 - 2015-11-23 23:08 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-12-08 13:06 - 2015-11-23 23:04 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-12-07 04:00 - 2015-12-12 04:03 - 00030848 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-12-07 04:00 - 2015-12-07 04:46 - 00000000 ____D C:\ProgramData\RogueKiller
2015-12-07 03:59 - 2015-12-07 04:00 - 20829256 _____ C:\Users\Michael\Downloads\RogueKiller.exe
2015-12-06 20:03 - 2015-12-06 20:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2015-12-06 20:01 - 2015-12-06 20:01 - 00001824 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-12-06 20:01 - 2015-12-06 20:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-12-06 20:00 - 2015-12-06 20:01 - 00000000 ____D C:\Program Files\iTunes
2015-12-06 20:00 - 2015-12-06 20:00 - 00000000 ____D C:\Program Files\iPod
2015-12-06 20:00 - 2015-12-06 20:00 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-12-06 19:57 - 2015-12-06 19:57 - 00000000 ____D C:\Program Files\Bonjour
2015-12-06 19:57 - 2015-12-06 19:57 - 00000000 ____D C:\Program Files (x86)\Bonjour
2015-12-06 19:54 - 2015-12-06 19:54 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2015-12-06 19:54 - 2015-12-06 19:54 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2015-12-06 16:19 - 2015-12-06 16:19 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-12-05 01:20 - 2015-12-05 01:20 - 00002864 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2015-12-05 01:20 - 2015-12-05 01:20 - 00000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-12-05 01:20 - 2015-12-05 01:20 - 00000000 ____D C:\Program Files\CCleaner
2015-12-04 02:53 - 2015-12-04 02:53 - 00049752 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\AntiLog64.sys
2015-12-04 02:53 - 2015-12-04 02:53 - 00000984 _____ C:\Users\Public\Desktop\AntiLogger.lnk
2015-12-04 02:53 - 2015-12-04 02:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiLogger
2015-12-04 02:53 - 2015-12-04 02:53 - 00000000 ____D C:\Program Files (x86)\AntiLogger
2015-12-04 02:53 - 2014-12-30 13:31 - 07039960 _____ (Zemana Ltd.) C:\WINDOWS\SysWOW64\ZALSDKCore.dll
2015-12-04 02:53 - 2014-12-30 13:31 - 00076520 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\KeyCrypt64.sys
2015-12-04 01:47 - 2015-12-12 07:15 - 00016307 _____ C:\WINDOWS\ZAM.krnl.trace
2015-12-04 01:47 - 2015-12-12 07:15 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2015-12-04 01:47 - 2015-12-12 07:06 - 00000695 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2015-12-04 01:47 - 2015-12-10 18:45 - 00199536 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2015-12-04 01:46 - 2015-12-04 02:53 - 00000000 ____D C:\Users\Michael\AppData\Local\Zemana
2015-12-03 03:02 - 2015-12-03 03:02 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2015-12-03 01:51 - 2015-12-03 02:43 - 00000000 ____D C:\Users\Michael\AppData\Roaming\FreeFixer
2015-12-03 01:51 - 2015-12-03 02:03 - 00000000 ____D C:\Users\Michael\AppData\Local\FreeFixer
2015-12-03 01:49 - 2015-12-03 01:49 - 02687418 _____ (Kephyr) C:\Users\Michael\Downloads\freefixersetup.exe
2015-12-03 01:26 - 2015-12-12 07:17 - 00000000 ____D C:\Program Files\FreeFixer
2015-12-03 01:25 - 2015-12-03 01:25 - 02687418 _____ (Kephyr) C:\Users\Michael\Desktop\freefixersetup.exe
2015-12-02 23:07 - 2015-11-22 02:47 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-12-02 23:07 - 2015-11-22 02:47 - 02653816 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-02 23:07 - 2015-11-22 02:41 - 01859448 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-12-02 23:07 - 2015-11-22 02:41 - 01284960 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-12-02 23:07 - 2015-11-22 02:41 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-12-02 23:07 - 2015-11-22 02:35 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-12-02 23:07 - 2015-11-22 02:34 - 00975200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-12-02 23:07 - 2015-11-22 02:34 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
2015-12-02 23:07 - 2015-11-22 02:33 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2015-12-02 23:07 - 2015-11-22 02:33 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2015-12-02 23:07 - 2015-11-22 02:33 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
2015-12-02 23:07 - 2015-11-22 02:30 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-12-02 23:07 - 2015-11-22 02:30 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-12-02 23:07 - 2015-11-22 02:26 - 00431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-12-02 23:07 - 2015-11-22 02:25 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
2015-12-02 23:07 - 2015-11-22 02:24 - 02772584 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2015-12-02 23:07 - 2015-11-22 02:20 - 00795840 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-12-02 23:07 - 2015-11-22 02:19 - 00440160 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2015-12-02 23:07 - 2015-11-22 02:14 - 02185840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2015-12-02 23:07 - 2015-11-22 01:55 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
2015-12-02 23:07 - 2015-11-22 01:54 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2015-12-02 23:07 - 2015-11-22 01:54 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
2015-12-02 23:07 - 2015-11-22 01:52 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-12-02 23:07 - 2015-11-22 01:50 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
2015-12-02 23:07 - 2015-11-22 01:49 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2015-12-02 23:07 - 2015-11-22 01:45 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-12-02 23:07 - 2015-11-22 01:45 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-12-02 23:07 - 2015-11-22 01:43 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-12-02 23:07 - 2015-11-22 01:42 - 13017600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-12-02 23:07 - 2015-11-22 01:42 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-12-02 23:07 - 2015-11-22 01:42 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll
2015-12-02 23:07 - 2015-11-22 01:41 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2015-12-02 23:07 - 2015-11-22 01:41 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-12-02 23:07 - 2015-11-22 01:39 - 02126848 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-12-02 23:07 - 2015-11-22 01:39 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-12-02 23:07 - 2015-11-22 01:39 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-12-02 23:07 - 2015-11-22 01:39 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-12-02 23:07 - 2015-11-22 01:38 - 01223168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-12-02 23:07 - 2015-11-22 01:38 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-12-02 23:07 - 2015-11-22 01:38 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-12-02 23:07 - 2015-11-22 01:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2015-12-02 23:07 - 2015-11-22 01:38 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
2015-12-02 23:07 - 2015-11-22 01:37 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2015-12-02 23:07 - 2015-11-22 01:37 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-12-02 23:07 - 2015-11-22 01:37 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-12-02 23:07 - 2015-11-22 01:36 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2015-12-02 23:07 - 2015-11-22 01:34 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2015-12-02 23:07 - 2015-11-22 01:34 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2015-12-02 23:07 - 2015-11-22 01:33 - 02587136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-12-02 23:07 - 2015-11-22 01:32 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2015-12-02 23:07 - 2015-11-22 01:32 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-12-02 23:07 - 2015-11-22 01:31 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-12-02 23:07 - 2015-11-22 01:31 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-12-02 23:07 - 2015-11-22 01:30 - 02598400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-12-02 23:07 - 2015-11-22 01:28 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-12-02 23:07 - 2015-11-22 01:28 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-12-02 23:07 - 2015-11-22 01:28 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-12-02 23:07 - 2015-11-22 01:28 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-12-02 23:07 - 2015-11-22 01:28 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-12-02 23:07 - 2015-11-22 01:27 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-12-02 23:07 - 2015-11-22 01:27 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-12-02 23:07 - 2015-11-22 01:27 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2015-12-02 23:07 - 2015-11-22 01:27 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2015-12-02 23:07 - 2015-11-22 01:26 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-12-02 23:07 - 2015-11-22 01:26 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-12-02 23:07 - 2015-11-22 01:26 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2015-12-02 23:07 - 2015-11-22 01:26 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-12-02 23:07 - 2015-11-22 01:25 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-12-02 23:07 - 2015-11-22 01:24 - 02647552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-12-02 23:07 - 2015-11-22 01:24 - 01995264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-12-02 23:07 - 2015-11-22 01:24 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-12-02 23:07 - 2015-11-22 01:20 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2015-12-02 23:07 - 2015-11-22 01:19 - 02064384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-12-02 23:07 - 2015-11-22 01:18 - 01505280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-12-02 23:07 - 2015-11-22 01:18 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-12-02 23:07 - 2015-11-22 01:18 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2015-12-02 23:07 - 2015-11-22 01:17 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-12-02 23:07 - 2015-11-22 01:17 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-12-02 23:07 - 2015-11-22 01:16 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2015-12-02 23:07 - 2015-11-22 01:11 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-12-02 23:06 - 2015-11-22 02:00 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2015-12-02 23:06 - 2015-11-22 02:00 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2015-12-02 23:06 - 2015-11-22 01:57 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2015-12-02 23:06 - 2015-11-22 01:57 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
2015-12-02 23:06 - 2015-11-22 01:57 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2015-12-02 23:06 - 2015-11-22 01:57 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2015-12-02 23:06 - 2015-11-22 01:56 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2015-12-02 23:06 - 2015-11-22 01:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2015-12-02 23:06 - 2015-11-22 01:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
2015-12-02 23:06 - 2015-11-22 01:56 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
2015-12-02 23:06 - 2015-11-22 01:55 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2015-12-02 23:06 - 2015-11-22 01:54 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-12-02 23:06 - 2015-11-22 01:54 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2015-12-02 23:06 - 2015-11-22 01:54 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
2015-12-02 23:06 - 2015-11-22 01:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-12-02 23:06 - 2015-11-22 01:54 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2015-12-02 23:06 - 2015-11-22 01:54 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2015-12-02 23:06 - 2015-11-22 01:54 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2015-12-02 23:06 - 2015-11-22 01:52 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2015-12-02 23:06 - 2015-11-22 01:52 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2015-12-02 23:06 - 2015-11-22 01:52 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2015-12-02 23:06 - 2015-11-22 01:52 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2015-12-02 23:06 - 2015-11-22 01:51 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-12-02 23:06 - 2015-11-22 01:51 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2015-12-02 23:06 - 2015-11-22 01:51 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2015-12-02 23:06 - 2015-11-22 01:51 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2015-12-02 23:06 - 2015-11-22 01:51 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2015-12-02 23:06 - 2015-11-22 01:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2015-12-02 23:06 - 2015-11-22 01:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2015-12-02 23:06 - 2015-11-22 01:49 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
2015-12-02 23:06 - 2015-11-22 01:48 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
2015-12-02 23:06 - 2015-11-22 01:47 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2015-12-02 23:06 - 2015-11-22 01:46 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2015-12-02 23:06 - 2015-11-22 01:46 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-12-02 23:06 - 2015-11-22 01:45 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-12-02 23:06 - 2015-11-22 01:45 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
2015-12-02 23:06 - 2015-11-22 01:45 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
2015-12-02 23:06 - 2015-11-22 01:45 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-12-02 23:06 - 2015-11-22 01:45 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
2015-12-02 23:06 - 2015-11-22 01:45 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
2015-12-02 23:06 - 2015-11-22 01:45 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
2015-12-02 23:06 - 2015-11-22 01:44 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2015-12-02 23:06 - 2015-11-22 01:44 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-12-02 23:06 - 2015-11-22 01:44 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2015-12-02 23:06 - 2015-11-22 01:43 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-12-02 23:06 - 2015-11-22 01:43 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-12-02 23:06 - 2015-11-22 01:43 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-12-02 23:06 - 2015-11-22 01:43 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
2015-12-02 23:06 - 2015-11-22 01:42 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-12-02 23:06 - 2015-11-22 01:42 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-12-02 23:06 - 2015-11-22 01:42 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2015-12-02 23:06 - 2015-11-22 01:42 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
2015-12-02 23:06 - 2015-11-22 01:41 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-12-02 23:06 - 2015-11-22 01:40 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-12-02 23:06 - 2015-11-22 01:40 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-12-02 23:06 - 2015-11-22 01:40 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-12-02 23:06 - 2015-11-22 01:40 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2015-12-02 23:06 - 2015-11-22 01:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2015-12-02 23:06 - 2015-11-22 01:39 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2015-12-02 23:06 - 2015-11-22 01:39 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2015-12-02 23:06 - 2015-11-22 01:39 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-12-02 23:06 - 2015-11-22 01:39 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2015-12-02 23:06 - 2015-11-22 01:39 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2015-12-02 23:06 - 2015-11-22 01:39 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2015-12-02 23:06 - 2015-11-22 01:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2015-12-02 23:06 - 2015-11-22 01:34 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2015-12-02 23:06 - 2015-11-22 01:34 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2015-12-02 23:06 - 2015-11-22 01:34 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2015-12-02 23:06 - 2015-11-22 01:34 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2015-12-02 23:06 - 2015-11-22 01:33 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
2015-12-02 23:06 - 2015-11-22 01:32 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-12-02 23:06 - 2015-11-22 01:31 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-12-02 23:06 - 2015-11-22 01:29 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-12-02 23:06 - 2015-11-22 01:28 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2015-12-02 23:06 - 2015-11-22 01:28 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-12-02 23:06 - 2015-11-22 01:28 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2015-12-02 23:06 - 2015-11-22 01:28 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2015-12-02 23:06 - 2015-11-22 01:27 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-12-02 23:06 - 2015-11-22 01:27 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-12-02 23:06 - 2015-11-22 01:25 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-12-02 23:06 - 2015-11-22 01:25 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2015-12-02 23:06 - 2015-11-22 01:24 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2015-12-02 23:06 - 2015-11-22 01:24 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2015-12-02 23:06 - 2015-11-22 01:23 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-12-02 04:58 - 2015-12-02 04:58 - 00167034 _____ C:\Users\Michael\Downloads\fileassassin-setup-1.06.exe
2015-12-02 04:58 - 2015-12-02 04:58 - 00065232 _____ (Malwarebytes) C:\Users\Michael\Downloads\regassassin-setup-1.03.exe
2015-12-02 04:55 - 2015-12-02 04:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
2015-12-02 04:54 - 2015-12-12 04:25 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2015-12-02 04:54 - 2015-12-02 04:54 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Exploit
2015-12-02 04:53 - 2015-12-02 04:54 - 01846024 _____ (Malwarebytes ) C:\Users\Michael\Downloads\mbae-setup-1.08.1.1045.exe
2015-12-02 04:33 - 2015-12-02 04:33 - 00000562 _____ C:\Users\Michael\Documents\untitled_AutoSave.gcs
2015-12-01 12:21 - 2015-12-01 12:21 - 00000000 ____D C:\CCSupport
2015-12-01 12:13 - 2015-11-02 14:02 - 00016800 _____ C:\Users\Michael\AppData\Local\Z@!-28174c76-6d78-455c-a963-8c03f6f030b2.tmp
2015-12-01 11:38 - 2015-12-01 11:38 - 00000022 _____ C:\Users\Michael\Downloads\ESETPoweliksCleaner.exe_20151201.113800.3004.zip
2015-12-01 11:37 - 2015-12-01 11:37 - 00224968 _____ (ESET) C:\Users\Michael\Downloads\ESETPoweliksCleaner.exe
2015-12-01 11:28 - 2015-12-01 11:29 - 02837704 _____ (ESET) C:\Users\Michael\Downloads\eset_smart_security_live_installer.exe
2015-12-01 11:12 - 2015-12-11 18:04 - 00170280 _____ (ESET) C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys
2015-11-30 20:45 - 2015-11-30 20:45 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-11-30 11:14 - 2015-11-30 11:14 - 00000000 ____D C:\Program Files\Windows Identity Foundation
2015-11-29 20:24 - 2015-11-29 20:24 - 00000000 ____D C:\Users\Michael\AppData\Local\ActiveSync
2015-11-29 20:22 - 2015-11-29 20:22 - 00000020 ___SH C:\Users\Michael\ntuser.ini
2015-11-29 20:21 - 2015-11-29 20:21 - 00000000 _SHDL C:\Users\Default\My Documents
2015-11-29 20:21 - 2015-11-29 20:21 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2015-11-29 20:21 - 2015-11-29 20:21 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2015-11-29 20:21 - 2015-11-29 20:21 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2015-11-29 20:21 - 2015-11-29 20:21 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2015-11-29 20:21 - 2015-11-29 20:21 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2015-11-29 20:21 - 2015-11-29 20:21 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2015-11-29 20:14 - 2015-12-12 07:01 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-29 20:02 - 2015-11-29 20:02 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default\Desktop\Play Games
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default\AppData\Local\LogMeIn Rescue Calling Card
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default User\Desktop\Play Games
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2015-11-29 20:02 - 2015-11-29 20:02 - 00000000 ____D C:\Users\Default User\AppData\Local\LogMeIn Rescue Calling Card
2015-11-29 19:53 - 2015-11-29 19:53 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2015-11-29 19:52 - 2015-11-29 20:04 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2015-11-29 19:50 - 2015-12-07 05:02 - 00000000 ____D C:\Users\Michael
2015-11-29 19:50 - 2015-12-03 03:02 - 00000000 ____D C:\Users\DefaultAppPool
2015-11-29 19:50 - 2015-11-29 19:50 - 00000000 _SHDL C:\Users\Michael\My Documents
2015-11-29 19:50 - 2015-11-29 19:50 - 00000000 _SHDL C:\Users\Michael\Documents\My Videos
2015-11-29 19:50 - 2015-11-29 19:50 - 00000000 _SHDL C:\Users\Michael\Documents\My Pictures
2015-11-29 19:50 - 2015-11-29 19:50 - 00000000 _SHDL C:\Users\Michael\Documents\My Music
2015-11-29 19:50 - 2015-11-29 19:50 - 00000000 _SHDL C:\Users\DefaultAppPool\My Documents
2015-11-29 19:50 - 2015-11-29 19:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Videos
2015-11-29 19:50 - 2015-11-29 19:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Pictures
2015-11-29 19:50 - 2015-11-29 19:50 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Music
2015-11-29 19:49 - 2015-12-12 14:13 - 01013760 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-29 19:49 - 2015-11-29 19:49 - 00965390 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2015-11-29 19:46 - 2015-11-29 19:46 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_iBtFltCoex_01009.Wdf
2015-11-29 19:46 - 2015-11-29 19:46 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2015-11-29 19:46 - 2015-11-29 19:46 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
2015-11-29 19:46 - 2015-11-29 19:46 - 00000000 ____D C:\Program Files\Realtek
2015-11-29 19:45 - 2015-11-29 19:45 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Apfiltr_01009.Wdf
2015-11-29 19:45 - 2015-11-29 19:45 - 00000000 ____D C:\Program Files\DellTPad
2015-11-29 19:44 - 2015-10-29 23:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-11-29 19:40 - 2015-12-05 01:24 - 00000000 ___DC C:\WINDOWS\Panther
2015-11-29 19:36 - 2015-11-29 19:36 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-29 19:36 - 2015-11-29 19:36 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2015-11-29 19:36 - 2015-11-29 19:36 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2015-11-29 19:36 - 2015-11-29 19:36 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-29 19:36 - 2015-11-29 19:36 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2015-11-29 19:36 - 2015-11-29 19:36 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2015-11-29 19:36 - 2015-11-29 19:36 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2015-11-29 19:36 - 2015-11-29 19:36 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2015-11-29 19:34 - 2015-11-29 19:34 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-11-29 19:31 - 2015-11-29 20:04 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-11-29 19:31 - 2015-11-29 19:31 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2015-11-29 19:31 - 2015-11-29 19:31 - 00000000 ____D C:\WINDOWS\system32\msmq
2015-11-29 19:31 - 2015-11-29 19:31 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2015-11-29 19:31 - 2015-11-29 19:31 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-11-29 19:31 - 2015-11-29 19:31 - 00000000 ____D C:\Program Files\MSBuild
2015-11-29 19:31 - 2015-11-29 19:31 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-11-29 19:31 - 2015-11-29 19:31 - 00000000 ____D C:\inetpub
2015-11-29 19:30 - 2015-10-23 17:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2015-11-29 19:30 - 2015-10-23 17:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-11-29 19:30 - 2015-10-23 17:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2015-11-29 19:30 - 2015-10-23 17:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-11-29 19:30 - 2015-10-23 17:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-11-29 19:30 - 2015-10-23 17:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-11-20 22:15 - 2015-11-20 22:15 - 00000000 ___HD C:\ProgramData\CanonIJMIG
2015-11-20 22:14 - 2015-11-20 22:14 - 00535997 _____ C:\Users\Michael\Documents\IMG_20151120_0001.pdf
2015-11-20 22:13 - 2015-11-20 22:14 - 00000000 ___HD C:\ProgramData\CanonIJScan
2015-11-20 22:12 - 2015-11-20 22:14 - 00000000 ____D C:\Users\Michael\Documents\Canon Scans
2015-11-20 21:22 - 2015-11-20 21:22 - 00002088 _____ C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
2015-11-20 21:22 - 2015-11-20 21:22 - 00000000 ____D C:\ProgramData\Canon IJ Network Tool
2015-11-20 21:22 - 2012-09-21 09:33 - 00321024 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNC_BLL.dll
2015-11-20 21:22 - 2012-05-25 09:21 - 00103936 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNC_BLU.dll
2015-11-20 21:22 - 2012-05-15 15:58 - 00098048 _____ C:\WINDOWS\SysWOW64\CNC176BD.TBL
2015-11-20 21:22 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNHMCA.dll
2015-11-20 21:19 - 2015-11-20 21:20 - 00000000 ___HD C:\Program Files\CanonBJ
2015-11-14 21:36 - 2015-11-14 21:36 - 00114616 _____ C:\Users\Michael\Downloads\Report.txt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-12 14:13 - 2015-10-29 23:21 - 00000000 ____D C:\WINDOWS\INF
2015-12-12 14:01 - 2012-09-28 13:47 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-12-12 12:57 - 2014-04-16 12:36 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-12-12 12:29 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-12 12:29 - 2015-09-25 18:46 - 00000000 ___RD C:\Users\Michael\iCloudDrive
2015-12-12 09:30 - 2011-07-20 16:40 - 00000000 ____D C:\Users\Michael\AppData\Local\Google
2015-12-12 09:19 - 2015-08-01 20:54 - 00000000 ___RD C:\Users\Michael\OneDrive
2015-12-12 07:25 - 2011-05-24 22:09 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-12-12 07:20 - 2012-03-15 16:15 - 00000000 ____D C:\Program Files (x86)\Google
2015-12-12 07:01 - 2015-10-29 22:28 - 00000000 ____D C:\Windows
2015-12-12 06:47 - 2015-10-29 22:28 - 00131072 ___SH C:\WINDOWS\system32\config\BBI
2015-12-12 05:25 - 2014-02-28 21:32 - 00000000 ____D C:\Users\Michael\Downloads\DIR-868L_FIRMWARE_1.02
2015-12-12 04:58 - 2014-02-16 15:44 - 02991832 _____ (ESET) C:\Users\Michael\Desktop\ERARemover_x64.exe
2015-12-12 04:07 - 2015-07-12 19:49 - 00000000 ____D C:\Users\Michael\Downloads\StarStaX-0.70_win64
2015-12-12 03:29 - 2014-02-16 16:04 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Michael\Desktop\tdsskiller.exe
2015-12-12 03:27 - 2011-08-07 13:42 - 00000346 _____ C:\Users\Michael\Downloads\deliverStreamingView.asx
2015-12-12 03:25 - 2013-02-23 14:58 - 38490752 _____ C:\Users\Michael\Downloads\HDREfexPro2-pl-ver2.003all.exe
2015-12-10 16:04 - 2015-08-01 20:54 - 00002417 _____ C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-12-09 21:36 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-12-08 21:44 - 2012-05-24 02:02 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-12-08 21:44 - 2012-05-24 02:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-12-08 17:59 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-12-08 16:32 - 2011-07-17 10:01 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-12-08 16:31 - 2015-10-29 23:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-12-08 16:30 - 2012-05-24 02:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-12-08 16:26 - 2013-08-14 02:02 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-12-08 14:29 - 2011-07-17 09:03 - 140158008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-12-07 18:31 - 2014-02-16 20:23 - 00000000 ____D C:\Users\Michael\AppData\LocalLow\Adblock Plus for IE
2015-12-07 05:06 - 2014-10-02 22:11 - 00000000 ____D C:\Users\Michael\AppData\Local\C4D54CA6-B71B-4320-A374-DFAE9C7576C7.aplzod
2015-12-06 20:03 - 2015-09-25 18:46 - 00000000 ____D C:\Users\Michael\AppData\Local\Apple Inc
2015-12-06 20:00 - 2011-10-12 13:10 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-12-06 19:54 - 2011-10-12 13:10 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-12-05 20:43 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\rescache
2015-12-04 14:16 - 2011-05-24 21:51 - 00000000 ____D C:\Program Files\Intel
2015-12-04 14:16 - 2011-05-24 21:49 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-12-03 00:56 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-11-30 16:33 - 2015-10-29 23:26 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-11-30 16:33 - 2015-10-29 23:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-30 03:58 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\appcompat
2015-11-29 20:48 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2015-11-29 20:25 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-11-29 20:25 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-11-29 20:24 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-11-29 20:23 - 2015-08-01 20:46 - 00000000 __RHD C:\Users\Public\AccountPictures
2015-11-29 20:19 - 2015-08-01 19:16 - 00023788 _____ C:\WINDOWS\diagerr.xml
2015-11-29 20:19 - 2015-08-01 19:16 - 00022863 _____ C:\WINDOWS\diagwrn.xml
2015-11-29 20:16 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2015-11-29 20:16 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\Registration
2015-11-29 20:14 - 2015-08-01 20:36 - 00022840 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-11-29 20:14 - 2015-05-15 13:08 - 00002954 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-11-29 20:14 - 2014-02-16 13:12 - 00002306 _____ C:\WINDOWS\System32\Tasks\{6AAF70DB-0961-4FC3-8741-1627DA144DE3}
2015-11-29 20:14 - 2013-12-15 20:35 - 00003434 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1cefa18391140ae
2015-11-29 20:14 - 2012-09-28 13:47 - 00003110 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-11-29 20:14 - 2012-05-16 01:39 - 00002288 _____ C:\WINDOWS\System32\Tasks\{7305280B-A687-41FE-A4EC-7EDFBFDD3CA5}
2015-11-29 20:14 - 2012-05-13 09:20 - 00002332 _____ C:\WINDOWS\System32\Tasks\{3C99C252-58B8-4DE2-9321-6D9AAC20A7E6}
2015-11-29 20:14 - 2011-12-30 02:26 - 00002276 _____ C:\WINDOWS\System32\Tasks\{27154054-D7E0-49F5-B371-6EA65B5695F8}
2015-11-29 20:14 - 2011-12-30 01:10 - 00002280 _____ C:\WINDOWS\System32\Tasks\{70C29E42-1668-4327-AA43-2CBA9A566A99}
2015-11-29 20:14 - 2011-12-29 23:36 - 00002264 _____ C:\WINDOWS\System32\Tasks\{1FF31F46-DA19-4A59-A137-D6772CB3994D}
2015-11-29 20:14 - 2011-12-29 23:28 - 00002292 _____ C:\WINDOWS\System32\Tasks\{D226B8F4-89D3-4B57-9618-067857F42FED}
2015-11-29 20:14 - 2011-12-29 23:19 - 00002264 _____ C:\WINDOWS\System32\Tasks\{7E19D03F-9451-4EED-91FA-F27916D2FB3E}
2015-11-29 20:14 - 2011-12-29 23:15 - 00002264 _____ C:\WINDOWS\System32\Tasks\{74C4BFA2-7D9F-45EF-84DA-5A289494583B}
2015-11-29 20:14 - 2011-07-17 08:32 - 00002160 _____ C:\WINDOWS\System32\Tasks\SidebarExecute
2015-11-29 20:13 - 2015-10-29 23:24 - 00000000 __RSD C:\WINDOWS\Media
2015-11-29 20:13 - 2015-10-29 23:24 - 00000000 __RHD C:\Users\Public\Libraries
2015-11-29 20:13 - 2015-10-29 23:24 - 00000000 ___HD C:\Program Files\WindowsApps
2015-11-29 20:05 - 2015-10-30 01:07 - 00000000 ____D C:\WINDOWS\ShellNew
2015-11-29 20:05 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2015-11-29 20:05 - 2014-05-21 17:01 - 00000000 ____D C:\WINDOWS\system32\STRING
2015-11-29 20:04 - 2015-10-29 23:24 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2015-11-29 20:04 - 2015-10-29 22:28 - 00008192 ___SH C:\WINDOWS\system32\config\ELAM
2015-11-29 20:04 - 2015-09-17 09:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-11-29 20:04 - 2015-02-21 14:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-11-29 20:04 - 2014-04-16 12:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-29 20:04 - 2014-02-15 18:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TurboTax 2013
2015-11-29 20:04 - 2014-02-14 23:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoSync
2015-11-29 20:04 - 2013-12-24 11:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photomatix Pro 5.0
2015-11-29 20:04 - 2013-11-02 02:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-11-29 20:04 - 2013-04-10 18:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TurboTax 2012
2015-11-29 20:04 - 2012-05-16 17:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photomatix Pro 4.2
2015-11-29 20:04 - 2012-02-27 13:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TurboTax 2011
2015-11-29 20:04 - 2011-07-17 10:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2015-11-29 20:04 - 2011-07-17 10:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-11-29 20:04 - 2011-05-31 16:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Modem Diagnostic Tool
2015-11-29 20:04 - 2011-05-31 16:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Netwaiting
2015-11-29 20:04 - 2011-05-24 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio Creator Starter
2015-11-29 20:04 - 2011-05-24 22:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell DataSafe Online
2015-11-29 20:04 - 2011-05-24 22:17 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2015-11-29 20:04 - 2011-05-24 22:17 - 00000000 ____D C:\WINDOWS\en
2015-11-29 20:04 - 2011-05-24 22:11 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Stage
2015-11-29 20:04 - 2011-05-24 22:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Webcam
2015-11-29 20:04 - 2011-05-24 22:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell DataSafe
2015-11-29 20:02 - 2015-07-10 01:05 - 00000000 ____D C:\Users\Default.migrated
2015-11-29 19:56 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2015-11-29 19:56 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2015-11-29 19:56 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\spool
2015-11-29 19:56 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\IME
2015-11-29 19:56 - 2012-05-16 01:27 - 00000000 ___HD C:\WINDOWS\system32\WLANProfiles
2015-11-29 19:56 - 2011-12-30 02:59 - 00000000 ____D C:\WINDOWS\SysWOW64\Dell
2015-11-29 19:56 - 2011-12-29 23:18 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2015-11-29 19:56 - 2011-07-18 11:33 - 00000000 ____D C:\WINDOWS\system32\SPReview
2015-11-29 19:56 - 2011-07-18 11:32 - 00000000 ____D C:\WINDOWS\system32\EventProviders
2015-11-29 19:54 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-11-29 19:54 - 2015-10-29 23:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-11-29 19:54 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\schemas
2015-11-29 19:54 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-11-29 19:54 - 2015-10-29 23:24 - 00000000 ____D C:\ProgramData\USOPrivate
2015-11-29 19:54 - 2015-04-17 13:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-11-29 19:54 - 2011-12-29 23:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics
2015-11-29 19:54 - 2009-07-13 23:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-11-29 19:53 - 2015-11-04 15:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2015-11-29 19:53 - 2015-10-29 23:24 - 00000000 __SHD C:\Program Files\Windows Sidebar
2015-11-29 19:53 - 2015-10-29 23:24 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2015-11-29 19:53 - 2015-10-29 23:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-11-29 19:53 - 2015-07-24 19:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DJI Product
2015-11-29 19:53 - 2014-02-13 21:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GoPro
2015-11-29 19:53 - 2011-10-22 13:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2015-11-29 19:53 - 2011-05-24 22:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2015-11-29 19:53 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Microsoft Games
2015-11-29 19:52 - 2012-05-16 02:21 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intel Corporation
2015-11-29 19:51 - 2015-08-01 20:46 - 00000000 ____D C:\Users\Michael\AppData\Local\Packages
2015-11-29 19:49 - 2015-10-29 22:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-11-29 19:42 - 2015-10-30 01:13 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2015-11-29 19:40 - 2015-10-29 23:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-11-29 19:37 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-29 19:37 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\Provisioning
2015-11-29 19:37 - 2015-10-29 22:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-11-29 19:37 - 2015-10-29 22:28 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-11-29 19:31 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-11-29 19:31 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-11-29 19:30 - 2015-10-29 23:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2015-11-29 19:30 - 2015-10-29 23:19 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2015-11-29 19:30 - 2015-10-29 23:19 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2015-11-29 19:30 - 2015-10-29 23:19 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2015-11-29 19:30 - 2015-10-29 23:19 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2015-11-29 19:30 - 2015-10-29 23:19 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2015-11-29 19:30 - 2015-10-29 23:19 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2015-11-29 19:30 - 2015-10-29 23:19 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2015-11-29 19:30 - 2015-10-29 23:19 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2015-11-29 19:30 - 2015-10-29 23:19 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2015-11-29 19:30 - 2015-10-29 23:19 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2015-11-29 19:30 - 2015-10-29 23:19 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2015-11-29 19:30 - 2015-10-29 23:19 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2015-11-29 19:30 - 2015-10-29 23:19 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2015-11-29 19:30 - 2015-10-29 23:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2015-11-29 19:30 - 2015-10-29 23:19 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2015-11-29 19:30 - 2015-10-29 23:18 - 01417728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2015-11-29 19:30 - 2015-10-29 23:18 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2015-11-29 19:30 - 2015-10-29 23:18 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2015-11-29 19:30 - 2015-10-29 23:18 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2015-11-29 19:30 - 2015-10-29 23:18 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2015-11-29 19:30 - 2015-10-29 23:18 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2015-11-29 19:30 - 2015-10-29 23:18 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2015-11-29 19:30 - 2015-10-29 23:18 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2015-11-29 19:30 - 2015-10-29 23:18 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2015-11-29 19:30 - 2015-10-29 23:18 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2015-11-20 22:14 - 2011-10-22 13:58 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Canon
2015-11-20 21:22 - 2011-10-22 13:06 - 00000000 ____D C:\Program Files (x86)\Canon
2015-11-16 16:18 - 2011-12-30 17:30 - 00007597 _____ C:\Users\Michael\AppData\Local\resmon.resmoncfg

==================== Files in the root of some directories =======

2015-11-22 03:03 - 2015-12-12 06:42 - 0000115 _____ () C:\Users\Michael\AppData\Roaming\LogFile.txt
2015-08-04 21:20 - 2015-08-04 21:20 - 0003584 _____ () C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-16 01:39 - 2012-05-16 01:39 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.023914.txt
2012-05-16 01:39 - 2012-05-16 01:39 - 0002427 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.023947.txt
2012-05-16 01:40 - 2012-05-16 01:40 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024046.txt
2012-05-16 01:41 - 2012-05-16 01:41 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024138.txt
2012-05-16 01:42 - 2012-05-16 01:42 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024204.txt
2012-05-16 01:42 - 2012-05-16 01:42 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024249.txt
2012-05-16 01:43 - 2012-05-16 01:43 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024358.txt
2012-05-16 01:47 - 2012-05-16 01:47 - 0002402 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024715.txt
2012-05-16 01:49 - 2012-05-16 01:49 - 0002427 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024958.txt
2012-05-16 01:50 - 2012-05-16 01:50 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.025055.txt
2012-05-16 01:51 - 2012-05-16 01:51 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.025137.txt
2012-05-16 02:06 - 2012-05-16 02:06 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.030649.txt
2011-07-18 14:12 - 2011-07-18 14:12 - 0028042 _____ () C:\Users\Michael\AppData\Local\IWDAudHelper.20110718.151210.txt
2012-05-16 02:19 - 2012-05-16 02:19 - 0002242 _____ () C:\Users\Michael\AppData\Local\IWDAudHelper.20120516.031925.txt
2011-07-17 08:59 - 2011-07-17 08:59 - 0001567 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110717.095904.txt
2011-07-18 10:07 - 2011-07-18 10:07 - 0001567 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.110712.txt
2011-07-18 12:27 - 2011-07-18 12:27 - 0001567 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.132721.txt
2011-07-18 14:10 - 2011-07-18 14:10 - 0001603 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151056.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0000621 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151105.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0000661 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151129.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0001579 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151131.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0001263 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151144.txt
2011-07-18 14:12 - 2011-07-18 14:12 - 0001227 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151201.txt
2011-07-18 14:12 - 2011-07-18 14:12 - 0001245 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151247.txt
2011-07-18 15:31 - 2011-07-18 15:31 - 0001526 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.163122.txt
2012-05-16 01:19 - 2012-05-16 01:19 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.021939.txt
2012-05-16 01:47 - 2012-05-16 01:47 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.024749.txt
2012-05-16 01:49 - 2012-05-16 01:49 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.024909.txt
2012-05-16 01:52 - 2012-05-16 01:52 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.025219.txt
2012-05-16 02:06 - 2012-05-16 02:06 - 0001547 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.030607.txt
2012-05-16 02:07 - 2012-05-16 02:07 - 0001524 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.030754.txt
2011-12-30 17:30 - 2015-11-16 16:18 - 0007597 _____ () C:\Users\Michael\AppData\Local\resmon.resmoncfg
2012-05-16 02:17 - 2012-05-16 02:18 - 0005386 _____ () C:\Users\Michael\AppData\Local\WiDiSetupLog.20120516.031747.txt
2012-05-16 02:18 - 2012-05-16 02:20 - 0026650 _____ () C:\Users\Michael\AppData\Local\WiDiSetupLog.20120516.031838.txt
2015-12-01 12:13 - 2015-11-02 14:02 - 0016800 _____ () C:\Users\Michael\AppData\Local\Z@!-28174c76-6d78-455c-a963-8c03f6f030b2.tmp
2015-09-17 09:30 - 2015-09-17 09:30 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-02-27 13:04 - 2014-02-15 19:35 - 0000935 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

Some files in TEMP:
====================
C:\Users\Michael\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Michael\AppData\Local\Temp\HitmanPro.exe
C:\Users\Michael\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-12-12 04:34

==================== End of FRST.txt ============================
You do not have the required permissions to view the files attached to this post.
MnSD
Active Member
 
Posts: 9
Joined: December 12th, 2015, 5:17 pm
Location: California
Advertisement
Register to Remove

Re: istatic.eshopcomp.com requested logs

Unread postby Gary R » December 17th, 2015, 2:38 am

Sorry you've been kept waiting so long, sometimes when we're busy topics get overlooked.

Looking over your logs now, back soon.
User avatar
Gary R
Administrator
Administrator
 
Posts: 21869
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: istatic.eshopcomp.com requested logs

Unread postby Gary R » December 17th, 2015, 2:51 am

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the "Infected? Virus, malware, adware, ransomware, oh my!" forum and wait for help.


Unless informed of in advance, failure to post replies within 3 days will result in this thread being closed.


Hi MnSD

I'm Gary R,

Before we start: Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start.

As an added safety precaution, before we start removing anything, I'd like you to make a backup of your Registry, which we can restore to if necessary.

Please click on THIS link, and follow the instructions for installing TCRB and creating a backup of your Registry.

Please observe these rules while we work:
  • Do not edit your logs in any way whatsoever.
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to install any new software (other than those I ask you to) until we've got your computer clean.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process. If your defensive programmes warn you about any of those tools, be assured that they are not infected, and are safe to use.
If you can do these things, everything should go smoothly.
  • As you're using Windows 10, it may be necessary to right click all tools we use and select ----> Run as Administrator

It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.


First ...

Please go to Control Panel > Programs > Uninstall a program and Uninstall the following:

Java 7 Update 45
Java(TM) 6 Update 24


Old versions of Java can be, and usually are exploited.

Next ...

I need you to run a couple of additional scans for me, to give me a more complete picture of what we need to remove.

1. Please download AdwCleaner and save it to your desktop.

  • Double click AdwCleaner.exe to run it.
  • Click Scan.
  • A logfile will automatically open after the scan has finished.
  • Close the adwCleaner window, click ok to the prompt.
  • Please post the contents of that logfile with your next reply.
  • You can also find the logfile at C:\AdwCleaner[R1].txt.

AT THIS POINT, DO NOT ATTEMPT TO CLEAN ANYTHING THAT MAY BE FOUND

2.

  • Double click Frst64.exe to launch it.
  • FRST will start to run.
    • When the tool opens click Yes to the disclaimer.
    • Copy/Paste or Type the following line into the Search: box.
    Fun4IM;Bandoo;Searchnu;Searchqu;iLivid;whitesmoke;datamngr;kelkoopartners;trolltech;babylon;conduit;trovi;clientconnect

    • Press the Search Registry button.
    • When finished searching a log will open on your Desktop ... Search.txt
    • Please post it in your next reply.

Summary of the logs I need from you in your next post:
  • ADWCleaner log
  • Search.txt


Please post each log separately to prevent it being cut off by the forum post size limiter. Check each after you've posted it to make sure it's all present, if any log is cut off you'll have to post it in sections.
User avatar
Gary R
Administrator
Administrator
 
Posts: 21869
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: istatic.eshopcomp.com requested logs

Unread postby MnSD » December 17th, 2015, 4:15 am

Hello Gary,

many thanks for your help and expertise. I have backed up files including the registry per your request. Using TCRD. I removed the two versions of Java you recommended and left Java 7 update 45 ( 64 bit version). You did not say remove that one.

I have run both scanners as the Admin per your request and here are the scans.
One thing I had found was that one of the browser extensions I had added to Google Chrome was listed as a source of Adware/Malware....while removing it did lessen the occurrence of the malicious website highjack in Chrome it still happens.

Adw Log:
# AdwCleaner v5.025 - Logfile created 16/12/2015 at 23:51:54
# Updated 13/12/2015 by Xplode
# Database : 2015-12-13.2 [Server]
# Operating system : Windows 10 Home (x64)
# Username : Michael - MICHAEL-PC
# Running from : C:\Users\Michael\Desktop\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

Folder Found : C:\ProgramData\myturbopc.com
Folder Found : C:\Users\Michael\AppData\Roaming\myturbopc.com

***** [ Files ] *****


***** [ DLL ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\MyTurboPC.com
Key Found : HKLM\SOFTWARE\MyTurboPC.com

***** [ Web browsers ] *****


########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [757 bytes] ##########

FRST Registry Scan:
Farbar Recovery Scan Tool (x64) Version:17-12-2015
Ran by Michael (2015-12-17 00:04:47)
Running from C:\Users\Michael\Desktop
Boot Mode: Normal

================== Search Registry: "Fun4IM;Bandoo;Searchnu;Searchqu;iLivid;whitesmoke;datamngr;kelkoopartners;trolltech;babylon;conduit;trovi;clientconnect" ===========


===================== Search result for "Searchqu" ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1B217815-E578-4C96-8A2D-1B30392F0F91}]
""="ISearchQueryHelperPriv"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{69563521-C154-4B45-B884-035872E3F96A}]
""="ISearchQueryCondition"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
""="ISearchQueryHelper"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CAC6C3B8-3C64-4DFD-AD9F-479E4D4065A4}]
""="__x_Windows_CApplicationModel_CSearch_CISearchQueryLinguisticDetailsFactory"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{1B217815-E578-4C96-8A2D-1B30392F0F91}]
""="ISearchQueryHelperPriv"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{69563521-C154-4B45-B884-035872E3F96A}]
""="ISearchQueryCondition"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
""="ISearchQueryHelper"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{CAC6C3B8-3C64-4DFD-AD9F-479E4D4065A4}]
""="__x_Windows_CApplicationModel_CSearch_CISearchQueryLinguisticDetailsFactory"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Search.SearchQueryLinguisticDetails]

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\WindowsRuntime\ActivatableClassId\Windows.ApplicationModel.Search.SearchQueryLinguisticDetails]

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\WindowsRuntime\CLSID\{d6519d77-1cdf-30a5-812e-d88fb4798a29}]
"ActivatableClassId"="Windows.ApplicationModel.Search.SearchQueryLinguisticDetails"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{46A1205B-69C9-4745-B72F-A8A4FC8F24AE}]
""="__x_Windows_CApplicationModel_CSearch_CISearchQueryLinguisticDetails"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{AB310581-AC80-11D1-8DF3-00C04FB6EF63}]
""="ISearchQueryHelper"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{CAC6C3B8-3C64-4DFD-AD9F-479E4D4065A4}]
""="__x_Windows_CApplicationModel_CSearch_CISearchQueryLinguisticDetailsFactory"


===================== Search result for "trolltech" ==========

[HKEY_USERS\S-1-5-21-2606919885-2507221499-1667024737-1000\SOFTWARE\Trolltech]

[HKEY_USERS\S-1-5-21-2606919885-2507221499-1667024737-1000\SOFTWARE\Trolltech\OrganizationDefaults\Qt Factory Cache 4.8\com.trolltech.Qt.QTextCodecFactoryInterface:]

===================== Search result for "babylon" ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
"DllName"="BabylonToolbar.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
"DllName"="BabylonToolbarTlbr.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
"DllName"="BabylonToolbar.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
"DllName"="BabylonToolbarTlbr.dll"


===================== Search result for "conduit" ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966]
"E1810453A043A7E44B90136643272B7F"="C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iSyncConduit.dll"


===================== Search result for "clientconnect" ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8DD5142F-7E23-4c44-9DD7-98B9C7032535}]
""="INapEnforcementClientConnectionPrivate"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BD244906-70DD-4690-BEEA-648653393500}]
""="INapEnforcementClientConnection2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FB3A3505-DDB1-468A-B307-F328A57419D8}]
""="INapEnforcementClientConnection"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8DD5142F-7E23-4c44-9DD7-98B9C7032535}]
""="INapEnforcementClientConnectionPrivate"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{BD244906-70DD-4690-BEEA-648653393500}]
""="INapEnforcementClientConnection2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{FB3A3505-DDB1-468A-B307-F328A57419D8}]
""="INapEnforcementClientConnection"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{8DD5142F-7E23-4c44-9DD7-98B9C7032535}]
""="INapEnforcementClientConnectionPrivate"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{BD244906-70DD-4690-BEEA-648653393500}]
""="INapEnforcementClientConnection2"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{FB3A3505-DDB1-468A-B307-F328A57419D8}]
""="INapEnforcementClientConnection"

====== End of Search ======
MnSD
Active Member
 
Posts: 9
Joined: December 12th, 2015, 5:17 pm
Location: California

Re: istatic.eshopcomp.com requested logs

Unread postby Gary R » December 17th, 2015, 5:27 am

It is clear from the logs you've supplied so far that you have previously been receiving help with this problem at another forum.

Can you please supply me with a link to your previous help topic, as it may give me clues as to the source of your problem. The previous attempts to clean your machine have removed many of the clues that would have helped me identify what the cause might be.
User avatar
Gary R
Administrator
Administrator
 
Posts: 21869
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: istatic.eshopcomp.com requested logs

Unread postby MnSD » December 17th, 2015, 6:10 am

Hello Gary,

I really have had no other help from anyone on the with all the people that need help.solution for this issue, I would not use anyone's time in two places as I can see from your forum how valuable peoples time is.
I have and tried things I have seen at places like Major Geeks and I looked at the Malwarebytes site as it is the program that catches the Highjack attempt. When I searched for information on the istatic.eshopcomp.com malware in google thats how I started my search that eventually led to you guys.. Since the malware always seemed to come from Chrome. I decided to just look at the 5 or 6 add ons/extensions I had in Chrome, and read the reviews when I got to" Hide my Adblocker extenion{ I was shocked at the reviews....as they all talked about malware etc.....) Sp O removed it....it helped some but the message from Malwarebytes still pops up in Chrome from time to time that this malware is trying to contact an outside website.rr

I am truly sorry if I have made it difficult to find the issue....but again I did not even know help like this exisated until I began my extensive search for the solution to my issue.... I was trying figure it out as I thought that was my only solution short of wiping the hard drive. I didhjave an issue with when I upgraded from windows 7 to windows 10 and Microsoft ran some scans a few months ago.

Again sorry if I have caused any issues.

Mike
MnSD
Active Member
 
Posts: 9
Joined: December 12th, 2015, 5:17 pm
Location: California

Re: istatic.eshopcomp.com requested logs

Unread postby Gary R » December 17th, 2015, 7:27 am

OK, no problem, looks like we're just going to have to deal with everything "non-standard" that we find then, and see if somewhere along the way we find what is causing the problem.

So, to begin with ....

  • Click Start
  • Open a Search, and type notepad.exe in the search box.
  • Click on the Notepad icon that Windows finds.
  • A blank Notepad page should open.
    • Copy/Paste the contents of the code box below into Notepad (don't include Code: Select all).
Code: Select all
[-HKEY_USERS\S-1-5-21-2606919885-2507221499-1667024737-1000\SOFTWARE\Trolltech]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpage.com
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpage.com
SearchScopes: HKU\S-1-5-21-2606919885-2507221499-1667024737-1000 -> {23392EC5-488B-4C8F-BE7D-B591FEDF7497} URL =
SearchScopes: HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {23392EC5-488B-4C8F-BE7D-B591FEDF7497} URL =
Edge HomeButtonPage: HKU\S-1-5-21-2606919885-2507221499-1667024737-1000 -> hxxp://www.startpage.com/
CHR HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [cdldbgojabdbiapkfeldpfmbecmcaoec] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [cdldbgojabdbiapkfeldpfmbecmcaoec] - hxxps://clients2.google.com/service/update2/crx
2012-05-16 01:39 - 2012-05-16 01:39 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.023914.txt
2012-05-16 01:39 - 2012-05-16 01:39 - 0002427 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.023947.txt
2012-05-16 01:40 - 2012-05-16 01:40 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024046.txt
2012-05-16 01:41 - 2012-05-16 01:41 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024138.txt
2012-05-16 01:42 - 2012-05-16 01:42 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024204.txt
2012-05-16 01:42 - 2012-05-16 01:42 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024249.txt
2012-05-16 01:43 - 2012-05-16 01:43 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024358.txt
2012-05-16 01:47 - 2012-05-16 01:47 - 0002402 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024715.txt
2012-05-16 01:49 - 2012-05-16 01:49 - 0002427 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024958.txt
2012-05-16 01:50 - 2012-05-16 01:50 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.025055.txt
2012-05-16 01:51 - 2012-05-16 01:51 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.025137.txt
2012-05-16 02:06 - 2012-05-16 02:06 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.030649.txt
2011-07-17 08:59 - 2011-07-17 08:59 - 0001567 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110717.095904.txt
2011-07-18 10:07 - 2011-07-18 10:07 - 0001567 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.110712.txt
2011-07-18 12:27 - 2011-07-18 12:27 - 0001567 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.132721.txt
2011-07-18 14:10 - 2011-07-18 14:10 - 0001603 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151056.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0000621 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151105.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0000661 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151129.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0001579 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151131.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0001263 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151144.txt
2011-07-18 14:12 - 2011-07-18 14:12 - 0001227 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151201.txt
2011-07-18 14:12 - 2011-07-18 14:12 - 0001245 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151247.txt
2011-07-18 15:31 - 2011-07-18 15:31 - 0001526 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.163122.txt
2012-05-16 01:19 - 2012-05-16 01:19 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.021939.txt
2012-05-16 01:47 - 2012-05-16 01:47 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.024749.txt
2012-05-16 01:49 - 2012-05-16 01:49 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.024909.txt
2012-05-16 01:52 - 2012-05-16 01:52 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.025219.txt
2012-05-16 02:06 - 2012-05-16 02:06 - 0001547 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.030607.txt
2012-05-16 02:07 - 2012-05-16 02:07 - 0001524 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.030754.txt
2015-12-01 12:13 - 2015-11-02 14:02 - 0016800 _____ () C:\Users\Michael\AppData\Local\Z@!-28174c76-6d78-455c-a963-8c03f6f030b2.tmp
Task: {14DD014D-34D1-4D29-96A3-990A69004688} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {3D3AAA67-A857-4D92-A662-EF636053687F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {5C64554A-E019-4FF7-AC5D-2CC65045E1EC} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {65DE1CA9-E0ED-4313-9D2F-597D979F0BB3} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {69383C0A-80BB-409D-A861-157FB6727C27} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {6C62DE57-025C-4012-96FD-F75F9CC0C418} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {83C74002-0AD8-49AB-ADCD-01E21A2D23EC} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {954C7289-5918-4475-8867-398CE00680CE} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {BA56EB86-33A9-4E1E-B2AF-E30F930752B7} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {CF52CCB7-A2B0-46E4-A78D-9D58762DD06C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {CFED57C4-E0CE-43AD-919D-C713D38B69A8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
AlternateDataStreams: C:\Program Files\Adblock Plus for IE:Win32App_1
AlternateDataStreams: C:\Program Files\Bonjour:Win32App_1
AlternateDataStreams: C:\Program Files\CCleaner:Win32App_1
AlternateDataStreams: C:\Program Files\DellTPad:Win32App_1
AlternateDataStreams: C:\Program Files\HitmanPro:Win32App_1
AlternateDataStreams: C:\Program Files\iTunes:Win32App_1
AlternateDataStreams: C:\Program Files\Microsoft Silverlight:Win32App_1
AlternateDataStreams: C:\Program Files\Modem Diagnostic Tool:Win32App_1
AlternateDataStreams: C:\Program Files\PhotomatixPro4:Win32App_1
AlternateDataStreams: C:\Program Files\PhotomatixPro5:Win32App_1
AlternateDataStreams: C:\Program Files\Roxio:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\AntiLogger:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Apple Software Update:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Bonjour:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Dell DataSafe Local Backup:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Digital Line Detect:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\eBay:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\HP:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Malwarebytes Anti-Exploit:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Malwarebytes Anti-Malware:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Microsoft Office:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Microsoft SQL Server Compact Edition:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Microsoft Visual Studio 8:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\MSBuild:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Netwaiting:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\PhotoSync:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\QuickTime:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Roxio:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\SystemRequirementsLab:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Windows Live:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Zemana AntiMalware:Win32App_1
AlternateDataStreams: C:\Program Files\Common Files\microsoft shared:Win32App_1
AlternateDataStreams: C:\ProgramData\HP:Win32App_1
AlternateDataStreams: C:\ProgramData\HP Photo Creations:Win32App_1
AlternateDataStreams: C:\ProgramData\PhotoShow Shared Assets:Win32App_1
AlternateDataStreams: C:\ProgramData\Temp:054203E4
AlternateDataStreams: C:\ProgramData\Temp:5C321E34
AlternateDataStreams: C:\Users\Michael\AppData\LocalLow\Adblock Plus for IE:Win32App_1
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Public\Documents\.DS_Store:AFP_AfpInfo
EmptyTemp:
Hosts:
cmd: ipconfig/flushdns

    • Save it to the same folder/directory that FRST.exe is in, naming it as fixlist.txt

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

  • Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
    • Press the Fix button once and wait.
    • FRST will process fixlist.txt
    • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
    • Please post me the log

Let me know how your computer is behaving now as well please.
User avatar
Gary R
Administrator
Administrator
 
Posts: 21869
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: istatic.eshopcomp.com requested logs

Unread postby MnSD » December 17th, 2015, 10:00 pm

Hello Gary,

per your request here is the fix.log

Fix result of Farbar Recovery Scan Tool (x64) Version:17-12-2015
Ran by Michael (2015-12-17 17:46:29) Run:1
Running from C:\Users\Michael\Desktop
Loaded Profiles: Michael (Available Profiles: Michael & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
[-HKEY_USERS\S-1-5-21-2606919885-2507221499-1667024737-1000\SOFTWARE\Trolltech]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpage.com
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpage.com
SearchScopes: HKU\S-1-5-21-2606919885-2507221499-1667024737-1000 -> {23392EC5-488B-4C8F-BE7D-B591FEDF7497} URL =
SearchScopes: HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {23392EC5-488B-4C8F-BE7D-B591FEDF7497} URL =
Edge HomeButtonPage: HKU\S-1-5-21-2606919885-2507221499-1667024737-1000 -> hxxp://www.startpage.com/
CHR HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [cdldbgojabdbiapkfeldpfmbecmcaoec] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [cdldbgojabdbiapkfeldpfmbecmcaoec] - hxxps://clients2.google.com/service/update2/crx
2012-05-16 01:39 - 2012-05-16 01:39 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.023914.txt
2012-05-16 01:39 - 2012-05-16 01:39 - 0002427 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.023947.txt
2012-05-16 01:40 - 2012-05-16 01:40 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024046.txt
2012-05-16 01:41 - 2012-05-16 01:41 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024138.txt
2012-05-16 01:42 - 2012-05-16 01:42 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024204.txt
2012-05-16 01:42 - 2012-05-16 01:42 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024249.txt
2012-05-16 01:43 - 2012-05-16 01:43 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024358.txt
2012-05-16 01:47 - 2012-05-16 01:47 - 0002402 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024715.txt
2012-05-16 01:49 - 2012-05-16 01:49 - 0002427 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.024958.txt
2012-05-16 01:50 - 2012-05-16 01:50 - 0002404 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.025055.txt
2012-05-16 01:51 - 2012-05-16 01:51 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.025137.txt
2012-05-16 02:06 - 2012-05-16 02:06 - 0002425 _____ () C:\Users\Michael\AppData\Local\FastClean.20120516.030649.txt
2011-07-17 08:59 - 2011-07-17 08:59 - 0001567 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110717.095904.txt
2011-07-18 10:07 - 2011-07-18 10:07 - 0001567 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.110712.txt
2011-07-18 12:27 - 2011-07-18 12:27 - 0001567 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.132721.txt
2011-07-18 14:10 - 2011-07-18 14:10 - 0001603 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151056.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0000621 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151105.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0000661 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151129.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0001579 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151131.txt
2011-07-18 14:11 - 2011-07-18 14:11 - 0001263 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151144.txt
2011-07-18 14:12 - 2011-07-18 14:12 - 0001227 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151201.txt
2011-07-18 14:12 - 2011-07-18 14:12 - 0001245 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.151247.txt
2011-07-18 15:31 - 2011-07-18 15:31 - 0001526 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20110718.163122.txt
2012-05-16 01:19 - 2012-05-16 01:19 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.021939.txt
2012-05-16 01:47 - 2012-05-16 01:47 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.024749.txt
2012-05-16 01:49 - 2012-05-16 01:49 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.024909.txt
2012-05-16 01:52 - 2012-05-16 01:52 - 0001549 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.025219.txt
2012-05-16 02:06 - 2012-05-16 02:06 - 0001547 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.030607.txt
2012-05-16 02:07 - 2012-05-16 02:07 - 0001524 _____ () C:\Users\Michael\AppData\Local\PDLSetup.20120516.030754.txt
2015-12-01 12:13 - 2015-11-02 14:02 - 0016800 _____ () C:\Users\Michael\AppData\Local\Z@!-28174c76-6d78-455c-a963-8c03f6f030b2.tmp
Task: {14DD014D-34D1-4D29-96A3-990A69004688} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {3D3AAA67-A857-4D92-A662-EF636053687F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {5C64554A-E019-4FF7-AC5D-2CC65045E1EC} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {65DE1CA9-E0ED-4313-9D2F-597D979F0BB3} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {69383C0A-80BB-409D-A861-157FB6727C27} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {6C62DE57-025C-4012-96FD-F75F9CC0C418} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {83C74002-0AD8-49AB-ADCD-01E21A2D23EC} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {954C7289-5918-4475-8867-398CE00680CE} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {BA56EB86-33A9-4E1E-B2AF-E30F930752B7} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {CF52CCB7-A2B0-46E4-A78D-9D58762DD06C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {CFED57C4-E0CE-43AD-919D-C713D38B69A8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
AlternateDataStreams: C:\Program Files\Adblock Plus for IE:Win32App_1
AlternateDataStreams: C:\Program Files\Bonjour:Win32App_1
AlternateDataStreams: C:\Program Files\CCleaner:Win32App_1
AlternateDataStreams: C:\Program Files\DellTPad:Win32App_1
AlternateDataStreams: C:\Program Files\HitmanPro:Win32App_1
AlternateDataStreams: C:\Program Files\iTunes:Win32App_1
AlternateDataStreams: C:\Program Files\Microsoft Silverlight:Win32App_1
AlternateDataStreams: C:\Program Files\Modem Diagnostic Tool:Win32App_1
AlternateDataStreams: C:\Program Files\PhotomatixPro4:Win32App_1
AlternateDataStreams: C:\Program Files\PhotomatixPro5:Win32App_1
AlternateDataStreams: C:\Program Files\Roxio:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\AntiLogger:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Apple Software Update:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Bonjour:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Dell DataSafe Local Backup:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Digital Line Detect:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\eBay:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\HP:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Malwarebytes Anti-Exploit:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Malwarebytes Anti-Malware:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Microsoft Office:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Microsoft SQL Server Compact Edition:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Microsoft Visual Studio 8:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\MSBuild:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Netwaiting:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\PhotoSync:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\QuickTime:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Roxio:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\SystemRequirementsLab:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Windows Live:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Zemana AntiMalware:Win32App_1
AlternateDataStreams: C:\Program Files\Common Files\microsoft shared:Win32App_1
AlternateDataStreams: C:\ProgramData\HP:Win32App_1
AlternateDataStreams: C:\ProgramData\HP Photo Creations:Win32App_1
AlternateDataStreams: C:\ProgramData\PhotoShow Shared Assets:Win32App_1
AlternateDataStreams: C:\ProgramData\Temp:054203E4
AlternateDataStreams: C:\ProgramData\Temp:5C321E34
AlternateDataStreams: C:\Users\Michael\AppData\LocalLow\Adblock Plus for IE:Win32App_1
AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo
AlternateDataStreams: C:\Users\Public\Documents\.DS_Store:AFP_AfpInfo
EmptyTemp:
Hosts:
cmd: ipconfig/flushdns
*****************

HKEY_USERS\S-1-5-21-2606919885-2507221499-1667024737-1000\SOFTWARE\Trolltech => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_USERS\S-1-5-21-2606919885-2507221499-1667024737-1000\SOFTWARE\Trolltech => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B} => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC} => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B} => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC} => key removed successfully
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64 => value removed successfully
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64 => value removed successfully
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64 => value not found.
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64 => value not found.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main\\Start Page => Error setting value.
"HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{23392EC5-488B-4C8F-BE7D-B591FEDF7497}" => key removed successfully
HKCR\CLSID\{23392EC5-488B-4C8F-BE7D-B591FEDF7497} => key not found.
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{23392EC5-488B-4C8F-BE7D-B591FEDF7497} => key not found.
HKCR\CLSID\{23392EC5-488B-4C8F-BE7D-B591FEDF7497} => key not found.
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Main\\HomeButtonPage => value removed successfully
"HKU\S-1-5-21-2606919885-2507221499-1667024737-1000\SOFTWARE\Google\Chrome\Extensions\cdldbgojabdbiapkfeldpfmbecmcaoec" => key removed successfully
HKU\S-1-5-21-2606919885-2507221499-1667024737-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\cdldbgojabdbiapkfeldpfmbecmcaoec => key not found.
C:\Users\Michael\AppData\Local\FastClean.20120516.023914.txt => moved successfully
C:\Users\Michael\AppData\Local\FastClean.20120516.023947.txt => moved successfully
C:\Users\Michael\AppData\Local\FastClean.20120516.024046.txt => moved successfully
C:\Users\Michael\AppData\Local\FastClean.20120516.024138.txt => moved successfully
C:\Users\Michael\AppData\Local\FastClean.20120516.024204.txt => moved successfully
C:\Users\Michael\AppData\Local\FastClean.20120516.024249.txt => moved successfully
C:\Users\Michael\AppData\Local\FastClean.20120516.024358.txt => moved successfully
C:\Users\Michael\AppData\Local\FastClean.20120516.024715.txt => moved successfully
C:\Users\Michael\AppData\Local\FastClean.20120516.024958.txt => moved successfully
C:\Users\Michael\AppData\Local\FastClean.20120516.025055.txt => moved successfully
C:\Users\Michael\AppData\Local\FastClean.20120516.025137.txt => moved successfully
C:\Users\Michael\AppData\Local\FastClean.20120516.030649.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20110717.095904.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20110718.110712.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20110718.132721.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20110718.151056.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20110718.151105.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20110718.151129.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20110718.151131.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20110718.151144.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20110718.151201.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20110718.151247.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20110718.163122.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20120516.021939.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20120516.024749.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20120516.024909.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20120516.025219.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20120516.030607.txt => moved successfully
C:\Users\Michael\AppData\Local\PDLSetup.20120516.030754.txt => moved successfully
C:\Users\Michael\AppData\Local\Z@!-28174c76-6d78-455c-a963-8c03f6f030b2.tmp => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{14DD014D-34D1-4D29-96A3-990A69004688}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{14DD014D-34D1-4D29-96A3-990A69004688}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3D3AAA67-A857-4D92-A662-EF636053687F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D3AAA67-A857-4D92-A662-EF636053687F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5C64554A-E019-4FF7-AC5D-2CC65045E1EC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C64554A-E019-4FF7-AC5D-2CC65045E1EC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{65DE1CA9-E0ED-4313-9D2F-597D979F0BB3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65DE1CA9-E0ED-4313-9D2F-597D979F0BB3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{69383C0A-80BB-409D-A861-157FB6727C27}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{69383C0A-80BB-409D-A861-157FB6727C27}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C62DE57-025C-4012-96FD-F75F9CC0C418}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C62DE57-025C-4012-96FD-F75F9CC0C418}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{83C74002-0AD8-49AB-ADCD-01E21A2D23EC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83C74002-0AD8-49AB-ADCD-01E21A2D23EC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{954C7289-5918-4475-8867-398CE00680CE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{954C7289-5918-4475-8867-398CE00680CE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BA56EB86-33A9-4E1E-B2AF-E30F930752B7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA56EB86-33A9-4E1E-B2AF-E30F930752B7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CF52CCB7-A2B0-46E4-A78D-9D58762DD06C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CF52CCB7-A2B0-46E4-A78D-9D58762DD06C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CFED57C4-E0CE-43AD-919D-C713D38B69A8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CFED57C4-E0CE-43AD-919D-C713D38B69A8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
C:\Program Files\Adblock Plus for IE => ":Win32App_1" ADS removed successfully.
C:\Program Files\Bonjour => ":Win32App_1" ADS removed successfully.
C:\Program Files\CCleaner => ":Win32App_1" ADS removed successfully.
C:\Program Files\DellTPad => ":Win32App_1" ADS removed successfully.
"C:\Program Files\HitmanPro" => ":Win32App_1" ADS not found.
"C:\Program Files\iTunes" => ":Win32App_1" ADS not found.
C:\Program Files\Microsoft Silverlight => ":Win32App_1" ADS removed successfully.
C:\Program Files\Modem Diagnostic Tool => ":Win32App_1" ADS removed successfully.
C:\Program Files\PhotomatixPro4 => ":Win32App_1" ADS removed successfully.
C:\Program Files\PhotomatixPro5 => ":Win32App_1" ADS removed successfully.
C:\Program Files\Roxio => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\AntiLogger => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Apple Software Update => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Bonjour => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Dell DataSafe Local Backup => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Digital Line Detect => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\eBay => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\HP => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Malwarebytes Anti-Exploit => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Malwarebytes Anti-Malware => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Microsoft Office => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Microsoft SQL Server Compact Edition => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Microsoft Visual Studio 8 => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\MSBuild => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Netwaiting => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\PhotoSync => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\QuickTime => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Roxio => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\SystemRequirementsLab => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Windows Live => ":Win32App_1" ADS removed successfully.
"C:\Program Files (x86)\Zemana AntiMalware" => ":Win32App_1" ADS not found.
C:\Program Files\Common Files\microsoft shared => ":Win32App_1" ADS removed successfully.
C:\ProgramData\HP => ":Win32App_1" ADS removed successfully.
C:\ProgramData\HP Photo Creations => ":Win32App_1" ADS removed successfully.
C:\ProgramData\PhotoShow Shared Assets => ":Win32App_1" ADS removed successfully.
C:\ProgramData\Temp => ":054203E4" ADS removed successfully.
C:\ProgramData\Temp => ":5C321E34" ADS removed successfully.
C:\Users\Michael\AppData\LocalLow\Adblock Plus for IE => ":Win32App_1" ADS removed successfully.
C:\Users\Public\.DS_Store => ":AFP_AfpInfo" ADS removed successfully.
C:\Users\Public\Documents\.DS_Store => ":AFP_AfpInfo" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= ipconfig/flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

EmptyTemp: => 687.2 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 17:47:13 ====
MnSD
Active Member
 
Posts: 9
Joined: December 12th, 2015, 5:17 pm
Location: California

Re: istatic.eshopcomp.com requested logs

Unread postby Gary R » December 18th, 2015, 2:31 am

How is your computer behaving now ????
User avatar
Gary R
Administrator
Administrator
 
Posts: 21869
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: istatic.eshopcomp.com requested logs

Unread postby MnSD » December 18th, 2015, 5:22 am

Hello Gary.

it seems to be working great! no Malwarebytes malicious software warnings at all.....I would say also the whole system seems a little faster and more responsive. I have used both Chrome and the IE browser, and they both seem to preform as they should.
I was reading through the log at the end and all the files you exposed as incorrect, or needing to be removed or as and ADS Stream....not sure what ADS stream was until I googled it...potentially pretty serious stuff.

Is there anything else Gary we need to check? I am just thankful and amazed by you and your teams assistance.
MnSD
Active Member
 
Posts: 9
Joined: December 12th, 2015, 5:17 pm
Location: California

Re: istatic.eshopcomp.com requested logs

Unread postby Gary R » December 18th, 2015, 10:29 am

Before we finish and I give you details for how to safely remove the programs we've been using to clean your computer, I'd like you to run an additional online scan for me, so that we can ensure that we haven't missed anything.

Normally I use e-set, but I know you have e-set installed on your computer and that presumably is not finding anything, so I'd like to cross check using an alternate scanner.

Please run Microsoft Safety Scanner
  • Click Download Now (this is a large download, approx. 70Mb)
  • If you are asked about 32-bit or 64-bit, click on the type matching your Windows system.
  • If asked to Run or Save, choose Run.
  • OK the User Account Permission or the query "Do you want to run this software".
  • If you get a message saying "running this type of program could harm your computer" or similar, just ignore it and tell it to Run anyway.
  • Click the box to Accept the license agreement.
  • Click Next.
  • Click Next to run the Scan.
  • Click the Quick Scan button. (... also Full Scan option)
  • Click Next
    • (If it finds nothing, it will just Exit. It still creates a report.)
    • If it has found anything, check the box titled "Help Remove potentially unwanted software"
      • Click Next (the Dialog label will become "Cleaning your computer").
      • After this operation completes, click Finish.
      • When removals are complete, it will report through a link, "View detailed results of the scan"
      • Clicking the link will popup a report in Notepad.
      • Please post the contents of the file in your reply.
      • The file is also saved in C:\Windows\debug\msert.log
User avatar
Gary R
Administrator
Administrator
 
Posts: 21869
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: istatic.eshopcomp.com requested logs

Unread postby MnSD » December 18th, 2015, 11:46 am

Hello Gary,

here is the Microsoft scan:

Microsoft Safety Scanner v1.0, (build 1.213.247.0)
Started On Fri Dec 18 07:24:42 2015
->Scan ERROR: resource process://pid:384,ProcessStart:130948808542798291 (code 0x00000005 (5))
->Scan ERROR: resource process://pid:536,ProcessStart:130948808848942059 (code 0x00000005 (5))
->Scan ERROR: resource process://pid:652,ProcessStart:130948808851789887 (code 0x00000005 (5))
->Scan ERROR: resource process://pid:664,ProcessStart:130948808851949779 (code 0x00000005 (5))
->Scan ERROR: resource process://pid:744,ProcessStart:130948808853712146 (code 0x00000005 (5))
->Scan ERROR: resource process://pid:3220,ProcessStart:130949230600767217 (code 0x00000005 (5))
->Scan ERROR: resource process://pid:5772,ProcessStart:130949258755042316 (code 0x00000005 (5))
->Scan ERROR: resource file://C:\hiberfil.sys (code 0x00000020 (32))
->Scan ERROR: resource file://C:\hiberfil.sys (code 0x00000020 (32))
->Scan ERROR: resource file://C:\pagefile.sys (code 0x00000020 (32))
->Scan ERROR: resource file://C:\pagefile.sys (code 0x00000020 (32))
->Scan ERROR: resource file://C:\swapfile.sys (code 0x00000020 (32))
->Scan ERROR: resource file://C:\swapfile.sys (code 0x00000020 (32))

Results Summary:
----------------
No infection found.
Microsoft Safety Scanner Finished On Fri Dec 18 07:44:02 2015


Return code: 0 (0x0)
MnSD
Active Member
 
Posts: 9
Joined: December 12th, 2015, 5:17 pm
Location: California

Re: istatic.eshopcomp.com requested logs

Unread postby Gary R » December 18th, 2015, 12:21 pm

OK, time for a little tidying up then.

  • Please download delfix and save it to your desktop.
  • Right-click on delfix.exe and select " Run as administrator " to run it.
  • Check the following box ...
    • Remove disinfection tools

    ... then click on Run.
  • Once it has finished, a notepad file named DelFix.txt will open. Post the contents of this notepad in your next reply.
  • The log can also be located at the root of the system drive, C:\DelFix.txt.

As far as I can see, your computer looks clear of infection now.

  • If you have any remaining problems please let me know about them.
  • If not it's time to make your computer more secure.

Please read the article below which will give you a few suggestions for how to minimise your chances of getting another infection.
User avatar
Gary R
Administrator
Administrator
 
Posts: 21869
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: istatic.eshopcomp.com requested logs

Unread postby MnSD » December 19th, 2015, 2:36 am

Hello Gary,
The log I will post below but I first want to Thank You and NonSuch for organizing this team for benevolent IT team of professionals/hobbyist/geeks with the notion to help people because its the right thing to do!

What a class act that after you show us all your toys, you neetly put them away and help us tidy up our computer room so to speak!.

here is my log...:
# DelFix v1.011 - Logfile created 18/12/2015 at 22:30:39
# Updated 18/08/2015 by Xplode
# Username : Michael - MICHAEL-PC
# Operating System : Windows 10 Home (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\RegBackup
Deleted : C:\Users\Michael\Desktop\mbar
Deleted : C:\TDSSKiller.2.8.16.0_12.12.2015_19.45.31_log.txt
Deleted : C:\TDSSKiller.3.1.0.8_12.12.2015_19.46.24_log.txt
Deleted : C:\Users\Michael\Desktop\AdwCleaner.exe
Deleted : C:\Users\Michael\Desktop\Fixlog.txt
Deleted : C:\Users\Michael\Desktop\FRST64.exe
Deleted : C:\Users\Michael\Desktop\tdsskiller.exe
Deleted : C:\Users\Michael\Downloads\Addition.txt
Deleted : C:\Users\Michael\Downloads\CKScanner.exe
Deleted : C:\Users\Michael\Downloads\esetsmartinstaller_enu.exe
Deleted : C:\Users\Michael\Downloads\FRST.txt
Deleted : C:\Users\Michael\Downloads\JRT.exe
Deleted : C:\Users\Michael\Downloads\RogueKiller.exe
Deleted : C:\Users\Michael\Downloads\tdsskiller.exe
Deleted : C:\Users\Michael\Downloads\tdsskiller.zip
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner

########## - EOF - ##########
MnSD
Active Member
 
Posts: 9
Joined: December 12th, 2015, 5:17 pm
Location: California

Re: istatic.eshopcomp.com requested logs

Unread postby Gary R » December 19th, 2015, 12:28 pm

You're welcome. :)

Glad we could help you with your problem.

Looks like everything we used has been removed OK, so you're clear to go.

Keep safe,

Gary

As your problems appear to have been resolved, this topic is now closed.
User avatar
Gary R
Administrator
Administrator
 
Posts: 21869
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire
Advertisement
Register to Remove


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 55 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware