Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016 Ran by [removed] (administrator) on ASUS-LAPTOP (31-08-2016 23:13:49) Running from C:\Users\[removed]\Desktop [removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (SafeNet Inc.) C:\Windows\System32\hasplms.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (AMD) C:\Windows\System32\atieclxx.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (syncables, LLC) C:\Program Files (x86)\syncables\syncables desktop\syncables.exe (SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe (Dropbox, Inc.) C:\Users\Miller\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Apple Inc.) C:\Program Files (x86)\QuickTime\QTTask.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUS) C:\Windows\AsScrPro.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ASUS WebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-15] () HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2010-04-27] () HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.) HKLM\...\Run: [Setwallpaper] => c:\programdata\SetWallpaper.cmd HKLM\...\Run: [IntelliPoint] => C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2399632 2011-04-13] (Microsoft Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-07-26] (Apple Inc.) HKLM-x32\...\Run: [RemoteControl9] => C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2010-06-24] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [Nuance PDF Reader-reminder] => "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini" HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-12] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] () HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-07-05] (Apple Inc.) HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1282120 2013-05-02] (CANON INC.) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [453736 2013-02-19] (CANON INC.) HKU\S-1-5-21-2651000027-1574550463-3293312737-1000\...\Run: [Syncables] => C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-07-19] (syncables, LLC) HKU\S-1-5-21-2651000027-1574550463-3293312737-1000\...\Run: [Dropbox Update] => C:\Users\Miller\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-02] (Dropbox, Inc.) HKU\S-1-5-21-2651000027-1574550463-3293312737-1000\...\MountPoints2: F - F:\LaunchU3.exe -a ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miller\AppData\Roaming\Dropbox\bin\DropboxExt64.42.dll [2016-08-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miller\AppData\Roaming\Dropbox\bin\DropboxExt64.42.dll [2016-08-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miller\AppData\Roaming\Dropbox\bin\DropboxExt64.42.dll [2016-08-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miller\AppData\Roaming\Dropbox\bin\DropboxExt64.42.dll [2016-08-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miller\AppData\Roaming\Dropbox\bin\DropboxExt64.42.dll [2016-08-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miller\AppData\Roaming\Dropbox\bin\DropboxExt64.42.dll [2016-08-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miller\AppData\Roaming\Dropbox\bin\DropboxExt64.42.dll [2016-08-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miller\AppData\Roaming\Dropbox\bin\DropboxExt64.42.dll [2016-08-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ADSMOverlayIcon] -> {A825576B-0042-4F0F-8FB0-93CE0F054E69} => C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt64.dll [2007-06-15] () ShellIconOverlayIdentifiers: [ADSMOverlayIcon1] -> {A8D448F4-0431-45AC-9F5E-E1B434AB2249} => C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll [2007-06-01] () ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll [2009-11-26] (eCareme Technologies, Inc.) ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll [2009-11-26] (eCareme Technologies, Inc.) ShellIconOverlayIdentifiers-x32: [ADSMOverlayIcon] -> {A825576B-0042-4F0F-8FB0-93CE0F054E69} => C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll [2007-06-15] () ShellIconOverlayIdentifiers-x32: [ADSMOverlayIcon1] -> {A8D448F4-0431-45AC-9F5E-E1B434AB2249} => C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll [2007-06-01] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2011-01-24] ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SRS Premium Sound.lnk [2011-01-24] ShortcutTarget: SRS Premium Sound.lnk -> C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe (Acresso Software Inc.) Startup: C:\Users\Miller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-08-24] ShortcutTarget: Dropbox.lnk -> C:\Users\Miller\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Miller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk [2012-03-20] ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 Tcpip\..\Interfaces\{1C6B5823-4801-4E8F-8E5C-FC66084675FE}: [DhcpNameServer] 10.0.0.1 ManualProxies: Internet Explorer: ================== SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKU\S-1-5-21-2651000027-1574550463-3293312737-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-01-24] (Google Inc.) BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll [2011-01-24] (Google Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-01-24] (Google Inc.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Google Dictionary Compression sdch -> {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -> C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2011-01-24] (Google Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2011-01-24] (Google Inc.) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-01-24] (Google Inc.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.) Toolbar: HKU\S-1-5-21-2651000027-1574550463-3293312737-1000 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.) DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455} Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File FireFox: ======== FF ProfilePath: C:\Users\Miller\AppData\Roaming\Mozilla\Firefox\Profiles\2davnkav.default FF DefaultSearchEngine.US: Google FF Homepage: hxxp://www.wpr.org/ hxxp://www.jsonline.com/sports/outdoors/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-15] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-15] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] () FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: ZEON/PDF,version=2.0 -> C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll [2010-01-23] (Zeon Corporation) FF Plugin HKU\S-1-5-21-2651000027-1574550463-3293312737-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Miller\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-12-17] (Citrix Online) FF Extension: (Garmin Communicator) - C:\Users\Miller\AppData\Roaming\Mozilla\Firefox\Profiles\2davnkav.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2016-04-27] FF Extension: (Download Statusbar) - C:\Users\Miller\AppData\Roaming\Mozilla\Firefox\Profiles\2davnkav.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2016-04-27] FF Extension: (Download Status Bar) - C:\Users\Miller\AppData\Roaming\Mozilla\Firefox\Profiles\2davnkav.default\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2016-08-19] FF Extension: (Video DownloadHelper) - C:\Users\Miller\AppData\Roaming\Mozilla\Firefox\Profiles\2davnkav.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-08-03] FF HKLM-x32\...\Thunderbird\Extensions: [[removed]] - C:\Program Files (x86)\AVG\AVG2012\Thunderbird => not found Chrome: ======= CHR Profile: C:\Users\Miller\AppData\Local\Google\Chrome\User Data\Default ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 ADSMService; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.) [File not signed] R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.) R2 hasplms; C:\Windows\system32\hasplms.exe [4180576 2010-09-27] (SafeNet Inc.) R2 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144 2009-09-30] (Intel Corporation) [File not signed] R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] () [File not signed] R2 UNS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation) [File not signed] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [46960 2016-08-30] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-19] () S3 sscdserd; C:\Windows\System32\DRIVERS\sscdserd.sys [141384 2012-06-27] (MCCI Corporation) U5 Tpm; C:\Windows\System32\Drivers\Tpm.sys [211296 2016-07-27] () [File not signed] R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-08-06] () S3 motccgp; system32\DRIVERS\motccgp.sys [X] S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [X] S3 motmodem; system32\DRIVERS\motmodem.sys [X] S3 motport; system32\DRIVERS\motport.sys [X] U3 tmlwf; no ImagePath U3 tmwfp; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-08-31 23:13 - 2016-08-31 23:14 - 00021512 _____ C:\Users\Miller\Desktop\FRST.txt 2016-08-31 23:13 - 2016-08-31 23:13 - 00000000 ____D C:\FRST 2016-08-31 23:12 - 2016-08-31 23:12 - 02397696 _____ (Farbar) C:\Users\Miller\Desktop\FRST64.exe 2016-08-30 22:40 - 2016-08-30 22:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2016-08-30 09:53 - 2016-08-30 09:53 - 00012408 _____ C:\Users\Miller\Desktop\JRT.txt 2016-08-30 09:23 - 2016-08-31 16:29 - 00000000 ____D C:\AdwCleaner 2016-08-30 08:58 - 2016-08-30 08:58 - 00046960 _____ C:\Windows\system32\Drivers\hitmanpro37.sys 2016-08-30 08:55 - 2016-08-30 08:55 - 00011758 _____ C:\Windows\system32\.crusader 2016-08-30 08:33 - 2016-08-30 08:56 - 00000000 ____D C:\ProgramData\HitmanPro 2016-08-30 08:33 - 2016-08-30 08:34 - 11438608 _____ (SurfRight B.V.) C:\Users\Miller\Desktop\HitmanPro_x64.exe 2016-08-29 22:21 - 2016-08-29 22:21 - 00000000 ____D C:\Users\Miller\AppData\Local\ESET 2016-08-29 22:17 - 2016-08-29 22:20 - 06761600 _____ (ESET spol. s r.o.) C:\Users\Miller\Desktop\esetonlinescanner_enu.exe 2016-08-29 22:13 - 2016-08-29 22:13 - 02744744 _____ (Symantec Corporation) C:\Users\Miller\Desktop\FixTool64.exe 2016-08-29 21:53 - 2016-08-29 21:53 - 01610560 _____ (Malwarebytes) C:\Users\Miller\Desktop\JunkwareRemovalTool.exe 2016-08-29 21:51 - 2016-08-29 21:51 - 03826240 _____ C:\Users\Miller\Desktop\AdwCleaner.exe 2016-08-29 21:13 - 2016-08-29 21:48 - 09097104 _____ C:\Users\Miller\Desktop\WiNlOgOn.exe log file - terminated.txt 2016-08-29 21:13 - 2016-08-29 21:13 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Miller\Desktop\WiNlOgOn.exe - terminated.exe 2016-08-29 20:35 - 2016-08-29 21:10 - 09097104 _____ C:\Users\Miller\Desktop\iExplore.exe log file - terminated.txt 2016-08-29 20:06 - 2016-08-29 20:32 - 09097104 _____ C:\Users\Miller\Desktop\uSeRiNiT.exe log file terminated.txt 2016-08-29 20:05 - 2016-08-29 20:05 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Miller\Desktop\uSeRiNiT.exe - terminated.exe 2016-08-29 19:28 - 2016-08-29 20:03 - 09097104 _____ C:\Users\Miller\Desktop\eXplorer.exe log file - terminated.txt 2016-08-29 19:27 - 2016-08-29 19:27 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Miller\Desktop\eXplorer.exe - terminated.exe 2016-08-29 18:10 - 2016-08-29 19:25 - 09097104 _____ C:\Users\Miller\Desktop\Rkill.scr log file - terminated.txt 2016-08-29 18:09 - 2016-08-29 18:09 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Miller\Desktop\rkill.scr - terminated.scr 2016-08-29 17:43 - 2016-08-29 18:07 - 09097104 _____ C:\Users\Miller\Desktop\Rkill.exe log file - terminated.txt 2016-08-29 17:42 - 2016-08-29 17:42 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Miller\Desktop\rkill.exe -terminated.exe 2016-08-29 17:08 - 2016-08-29 17:38 - 09097194 _____ C:\Users\Miller\Desktop\Rkill log file - terminated.txt 2016-08-29 17:05 - 2016-08-29 17:05 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Miller\Desktop\iExplore.exe - terminated.exe 2016-08-29 16:57 - 2016-08-29 16:57 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Miller\Desktop\rkill -terminated.com 2016-08-27 23:50 - 2016-08-27 23:50 - 01246226 _____ C:\Users\Miller\Documents\sleep aid procedure.pdf 2016-08-24 15:37 - 2016-08-24 15:37 - 00000000 ____D C:\Users\Miller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-08-23 09:40 - 2016-08-23 09:40 - 457944693 _____ C:\Windows\MEMORY.DMP 2016-08-23 09:40 - 2016-08-23 09:40 - 00275960 _____ C:\Windows\Minidump\082316-36738-01.dmp 2016-08-19 08:57 - 2016-08-30 10:01 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-08-19 08:56 - 2016-08-19 08:56 - 00001108 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2016-08-19 08:56 - 2016-08-19 08:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-08-19 08:56 - 2016-08-19 08:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2016-08-19 08:56 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-08-19 08:56 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-08-19 08:56 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-08-19 08:55 - 2016-08-19 08:55 - 22851472 _____ (Malwarebytes ) C:\Users\Miller\Downloads\mbam-setup-2.2.1.1043.exe 2016-08-17 08:13 - 2016-07-08 10:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2016-08-17 08:13 - 2016-07-08 10:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2016-08-15 13:46 - 2016-07-08 10:37 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-08-15 13:46 - 2016-07-08 10:37 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-08-15 13:46 - 2016-07-08 10:32 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-08-15 13:46 - 2016-07-08 10:32 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-08-15 13:46 - 2016-07-08 10:32 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2016-08-15 13:46 - 2016-07-08 10:32 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-08-15 13:46 - 2016-07-08 10:16 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2016-08-15 13:46 - 2016-07-08 10:16 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-08-15 13:45 - 2016-07-08 10:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-08-15 13:45 - 2016-07-08 10:17 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-08-15 13:45 - 2016-07-08 10:17 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-08-15 13:45 - 2016-07-08 10:16 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-08-15 13:45 - 2016-07-08 10:16 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-08-15 13:45 - 2016-07-08 10:16 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-08-15 13:45 - 2016-07-08 10:16 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-08-15 13:45 - 2016-07-08 10:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-08-15 13:45 - 2016-07-08 10:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-08-15 13:45 - 2016-07-08 10:16 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2016-08-15 13:45 - 2016-07-08 10:16 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-08-15 13:45 - 2016-07-08 10:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-08-15 13:45 - 2016-07-08 10:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-08-15 13:45 - 2016-07-08 10:16 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-08-15 13:45 - 2016-07-08 10:03 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-08-15 13:45 - 2016-07-08 09:57 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-08-15 13:45 - 2016-07-08 09:56 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-08-15 13:45 - 2016-07-08 09:56 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-08-15 13:45 - 2016-07-08 09:55 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-08-15 13:45 - 2016-07-08 09:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-08-15 13:45 - 2016-07-08 09:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-08-15 13:44 - 2016-07-08 10:01 - 03218944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-08-03 00:19 - 2016-08-03 00:19 - 00001755 _____ C:\Users\Public\Desktop\iTunes.lnk 2016-08-03 00:19 - 2016-08-03 00:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2016-08-03 00:18 - 2016-08-03 00:19 - 00000000 ____D C:\Program Files\iTunes 2016-08-03 00:18 - 2016-08-03 00:18 - 00000000 ____D C:\Program Files\iPod 2016-08-03 00:18 - 2016-08-03 00:18 - 00000000 ____D C:\Program Files (x86)\iTunes ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-08-31 23:13 - 2009-07-13 23:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-08-31 23:13 - 2009-07-13 23:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-08-31 22:35 - 2015-06-02 07:49 - 00000922 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2651000027-1574550463-3293312737-1000UA.job 2016-08-31 22:27 - 2013-04-09 22:17 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-08-31 20:28 - 2009-07-14 00:13 - 00782510 _____ C:\Windows\system32\PerfStringBackup.INI 2016-08-31 20:28 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf 2016-08-31 17:35 - 2015-06-02 07:49 - 00000870 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2651000027-1574550463-3293312737-1000Core.job 2016-08-31 16:27 - 2013-04-09 22:17 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-08-31 14:58 - 2016-01-27 14:42 - 00000000 ____D C:\Users\Miller\Documents\Brad Trailer 2016-08-31 11:19 - 2015-01-07 19:27 - 00000000 ___RD C:\Users\Miller\Dropbox 2016-08-31 11:19 - 2013-06-09 08:15 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job 2016-08-31 11:19 - 2013-06-03 18:03 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2016-08-31 11:19 - 2011-01-24 13:18 - 00000000 ____D C:\Program Files\P4G 2016-08-31 08:35 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-08-31 06:32 - 2012-04-25 02:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-08-30 17:19 - 2011-07-18 00:13 - 00000000 ____D C:\Users\Miller\AppData\Roaming\vlc 2016-08-30 13:27 - 2011-07-26 23:57 - 00000000 ____D C:\Users\Miller\dwhelper 2016-08-30 09:28 - 2016-06-28 10:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-08-29 23:55 - 2015-03-18 23:52 - 00000000 ____D C:\Users\Miller\AppData\Local\CrashDumps 2016-08-28 19:51 - 2014-10-16 21:04 - 00000000 ____D C:\Users\Miller\AppData\Local\Adobe 2016-08-24 15:37 - 2015-01-07 19:22 - 00000000 ____D C:\Users\Miller\AppData\Roaming\Dropbox 2016-08-23 09:40 - 2013-08-14 22:55 - 00000000 ____D C:\Windows\Minidump 2016-08-16 09:59 - 2009-07-13 23:45 - 00354408 _____ C:\Windows\system32\FNTCACHE.DAT 2016-08-15 20:31 - 2013-08-14 23:00 - 00000000 ____D C:\Windows\system32\MRT 2016-08-15 20:26 - 2011-07-21 21:33 - 147640136 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-08-05 21:21 - 2009-07-14 00:08 - 00032638 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2016-08-03 00:18 - 2011-08-23 23:20 - 00000000 ____D C:\Program Files\Common Files\Apple ==================== Files in the root of some directories ======= 2013-06-26 22:55 - 2014-06-25 00:15 - 0003728 _____ () C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml 2011-01-24 12:58 - 2010-07-06 19:10 - 0131472 _____ () C:\ProgramData\FullRemove.exe 2011-01-24 12:45 - 2011-01-24 12:45 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2011-01-24 12:47 - 2011-01-24 12:47 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2011-01-24 12:44 - 2011-01-24 12:45 - 0000106 _____ () C:\ProgramData\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}.log 2011-01-24 12:46 - 2011-01-24 12:46 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log 2011-01-24 12:41 - 2011-01-24 12:44 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log 2011-01-24 12:46 - 2011-01-24 12:46 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log 2011-01-24 12:39 - 2011-01-24 12:41 - 0000115 _____ () C:\ProgramData\{E3739848-5329-48E3-8D28-5BBD6E8BE384}.log Some files in TEMP: ==================== C:\Users\Miller\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpispcxb.dll C:\Users\Miller\AppData\Local\Temp\libeay32.dll C:\Users\Miller\AppData\Local\Temp\msvcr120.dll C:\Users\Miller\AppData\Local\Temp\sqlite3.dll C:\Users\Miller\AppData\Local\Temp\vlc-2.2.1-win32.exe C:\Users\Miller\AppData\Local\Temp\vlc-2.2.4-win32.exe ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-07-27 08:34 ==================== End of FRST.txt ============================