Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-01-2017 01 Ran by [removed] (administrator) on AFAFA-HP (29-01-2017 13:06:03) Running from C:\Users\[removed]\Desktop [removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\CISVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\RealTimeProtector.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (CyberLink) C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE (Microsoft Corporation) C:\Windows\System32\snmp.exe (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Suo10_SmartRAM.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-13] (Synaptics Incorporated) HKLM\...\Run: [USB3MON] => c:\program files (x86)\intel\intel(r) usb 3.0 extensible host controller driver\application\iusb3mon.exe [291096 2011-12-05] (Intel Corporation) HKLM\...\Run: [HP Quick Launch] => c:\program files (x86)\hewlett-packard\hp quick launch\hpmsgsvc.exe [581024 2012-09-07] (Hewlett-Packard Development Company, L.P.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-01-04] (IDT, Inc.) HKLM-x32\...\Run: [HP CoolSense] => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1343904 2012-11-05] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-11-15] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\Run: [Advanced SystemCare 10] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2913568 2016-12-16] (IObit) HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\Run: [SmartRAM] => C:\Program Files (x86)\IObit\Advanced SystemCare\Suo10_SmartRAM.exe [562464 2016-09-13] (IObit) HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\MountPoints2: {5c8fb8a0-ea9b-11e3-99d0-6817298df5e9} - F:\ToolLauncher-Bootstrap.exe HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\MountPoints2: {7035b1f1-2517-11e4-b886-6817298df5e9} - H:\menu.exe HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\MountPoints2: {fc371099-49c8-11e3-970a-6817298df5e9} - F:\TL_Bootstrap.exe HKU\S-1-5-21-612254933-2129405712-312933494-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-13] (Microsoft Corporation) HKU\S-1-5-18\...\Run: [EEDSpeedLauncher] => rundll32.exe C:\Windows\system32\eed_ec.dll,SpeedLauncher HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1400232 2016-05-25] (Garmin Ltd. or its subsidiaries) IFEO\TeamViewer_Note.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-01-22] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-01-22] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-01-22] () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-29] (AVAST Software) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.8.0.dll [2017-01-05] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation) BootExecute: RegistryDefragBootTime.exeautocheck autochk * ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: [S-1-5-21-612254933-2129405712-312933494-1000] => 192.168.1.20:80 Tcpip\Parameters: [DhcpNameServer] 172.16.134.201 Tcpip\..\Interfaces\{5D376279-4E36-42C8-8A95-9BEBA72E41BF}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{BFB2FA69-9F21-4F59-82FE-02CE6CDF80D8}: [DhcpNameServer] 172.16.134.201 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-612254933-2129405712-312933494-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/ HKU\S-1-5-21-612254933-2129405712-312933494-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} HKU\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPNOT/1 HKU\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPNOT/1 HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://duckduckgo.com HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://duckduckgo.com SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = SearchScopes: HKLM -> {5768A8C6-7DDB-4F5E-9785-F5BFE40D1081} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {5768A8C6-7DDB-4F5E-9785-F5BFE40D1081} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms} SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-612254933-2129405712-312933494-1000 -> DefaultScope {5DA7A6EE-1504-464F-8962-C3CA2E603B96} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-612254933-2129405712-312933494-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-612254933-2129405712-312933494-1000 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms} SearchScopes: HKU\S-1-5-21-612254933-2129405712-312933494-1000 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = SearchScopes: HKU\S-1-5-21-612254933-2129405712-312933494-1000 -> {5768A8C6-7DDB-4F5E-9785-F5BFE40D1081} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKU\S-1-5-21-612254933-2129405712-312933494-1000 -> {5DA7A6EE-1504-464F-8962-C3CA2E603B96} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-612254933-2129405712-312933494-1000 -> {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo SearchScopes: HKU\S-1-5-21-612254933-2129405712-312933494-1000 -> {93BDCD0A-ECAC-43ED-AAD8-9A1616ED4D60} URL = hxxps://duckduckgo.com/?q={searchTerms} SearchScopes: HKU\S-1-5-21-612254933-2129405712-312933494-1000 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = SearchScopes: HKU\S-1-5-21-612254933-2129405712-312933494-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms} SearchScopes: HKU\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334 -> {5768A8C6-7DDB-4F5E-9785-F5BFE40D1081} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKU\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKU\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKU\S-1-5-82-1036420768-1044797643-1061213386-2937092688-4282445334 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms} SearchScopes: HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox SearchScopes: HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 -> {5768A8C6-7DDB-4F5E-9785-F5BFE40D1081} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms} BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit) BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-01-17] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-11-02] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2017-01-17] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-01-17] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-02] (Oracle Corporation) BHO: PrivDog Extension -> {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} -> C:\Program Files\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll [2013-11-15] (AdTrustMedia) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-11-01] (Microsoft Corporation) BHO-x32: IObit Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2016-08-03] (IObit) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-11-01] (Microsoft Corporation) BHO-x32: PrivDog Extension -> {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} -> C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll [2013-11-15] (AdTrustMedia) BHO-x32: IObit Ads Removal -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll [2016-06-23] (IObit) Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKU\S-1-5-21-612254933-2129405712-312933494-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-06-21] (Microsoft Corporation) Handler: WSWSVCUchrome - No CLSID Value FireFox: ======== FF ProfilePath: C:\Users\AFAFA\AppData\Roaming\Mozilla\Firefox\Profiles\rvx1z8cd.default-1453875521799 [2017-01-29] FF user.js: detected! => C:\Users\AFAFA\AppData\Roaming\Mozilla\Firefox\Profiles\rvx1z8cd.default-1453875521799\user.js [2017-01-07] FF DefaultSearchEngine: Mozilla\Firefox\Profiles\rvx1z8cd.default-1453875521799 -> Yahoo FF SelectedSearchEngine: Mozilla\Firefox\Profiles\rvx1z8cd.default-1453875521799 -> Yahoo FF Homepage: Mozilla\Firefox\Profiles\rvx1z8cd.default-1453875521799 -> hxxps://www.google.com FF Keyword.URL: Mozilla\Firefox\Profiles\rvx1z8cd.default-1453875521799 -> hxxp://us.search.yahoo.com/search?fr=ytff-comodo&p= FF Extension: (IObit Surfing Protection & Ads Removal) - C:\Users\AFAFA\AppData\Roaming\Mozilla\Firefox\Profiles\rvx1z8cd.default-1453875521799\Extensions\[removed] [2016-10-18] FF ProfilePath: C:\Users\AFAFA\AppData\Roaming\Comodo\IceDragon\Profiles\gyh4w20q.default [2017-01-29] FF DefaultSearchEngine: Comodo\IceDragon\Profiles\gyh4w20q.default -> Yahoo FF DefaultSearchEngine.US: Comodo\IceDragon\Profiles\gyh4w20q.default -> DuckDuckGo FF SelectedSearchEngine: Comodo\IceDragon\Profiles\gyh4w20q.default -> Yahoo FF Homepage: Comodo\IceDragon\Profiles\gyh4w20q.default -> hxxps://www.duckduckgo.com/ FF Keyword.URL: Comodo\IceDragon\Profiles\gyh4w20q.default -> hxxp://us.search.yahoo.com/search?fr=ytff-comodo&p= FF NetworkProxy: Comodo\IceDragon\Profiles\gyh4w20q.default -> type", 0 FF Extension: (PrivDog) - C:\Users\AFAFA\AppData\Roaming\Comodo\IceDragon\Profiles\gyh4w20q.default\Extensions\[removed] [2017-01-08] [not signed] FF Extension: (COMODO SecureBox) - C:\Program Files (x86)\Comodo\IceDragon\browser\features\@csb [2017-01-08] [not signed] FF Extension: (DragAndDrop) - C:\Program Files (x86)\Comodo\IceDragon\browser\features\[removed] [2017-01-08] [not signed] FF SearchPlugin: C:\Users\AFAFA\AppData\Roaming\Comodo\IceDragon\Profiles\gyh4w20q.default\searchplugins\google-encrypted.xml [2015-07-09] FF SearchPlugin: C:\Users\AFAFA\AppData\Roaming\Comodo\IceDragon\Profiles\gyh4w20q.default\searchplugins\youtube.xml [2015-07-09] FF HKLM\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-29] FF HKLM\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-08-29] FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-02-07] [not signed] FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\ProgramData\Wondershare\Video Converter Ultimate\[removed] => not found FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-13] () FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-02] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-02] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-02-12] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-13] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1225195.dll [2016-09-20] (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2012-04-14] (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2011-12-01] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2011-12-01] (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-12] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2016-06-10] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @mozilla.zeniko.ch/PDFlite_Browser_Plugin -> C:\Program Files (x86)\PDFlite\npPdfViewer.dll [2013-11-19] (Simon Bünzli) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-02-12] (Adobe Systems) FF Plugin HKU\S-1-5-21-612254933-2129405712-312933494-1000: @citrixonline.com/appdetectorplugin -> C:\Users\AFAFA\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-01-25] (Citrix Online) FF Plugin HKU\S-1-5-21-612254933-2129405712-312933494-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\AFAFA\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2016-09-08] (Zoom Video Communications, Inc.) Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxps://www.google.com/ CHR StartupUrls: Default -> "hxxps://www.google.com/" CHR DefaultSearchURL: Default -> hxxps://www.google.com/search?q={searchTerms} CHR DefaultSearchKeyword: Default -> google.com_ CHR DefaultSuggestURL: Default -> hxxps://www.google.com/complete/search?client=chrome&q={searchTerms} CHR Profile: C:\Users\AFAFA\AppData\Local\Google\Chrome\User Data\Default [2017-01-29] CHR Extension: (Google Drive) - C:\Users\AFAFA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-08] CHR Extension: (YouTube) - C:\Users\AFAFA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-06] CHR Extension: (PrivDog) - C:\Users\AFAFA\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja [2017-01-10] [UpdateUrl: hxxp://privdog.com/updates/865/googlechrome/update.xml] <==== ATTENTION CHR Extension: (Google Search) - C:\Users\AFAFA\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-06] CHR Extension: (Google Docs Offline) - C:\Users\AFAFA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-08] CHR Extension: (FreeConferenceCall.com Extension) - C:\Users\AFAFA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfhjonocnlnodflomblbjnjdpllkeljo [2016-11-07] CHR Extension: (Chrome Web Store Payments) - C:\Users\AFAFA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-20] CHR Extension: (Gmail) - C:\Users\AFAFA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-03] CHR Extension: (Chrome Media Router) - C:\Users\AFAFA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-15] CHR HKU\S-1-5-21-612254933-2129405712-312933494-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\AFAFA\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2017-01-08] CHR HKU\S-1-5-21-612254933-2129405712-312933494-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [cmaiofennmphjldldcpphcechfnnohja] - C:\Program Files (x86)\AdTrustMedia\PrivDog\PrivDog_chrome.crx [2017-01-08] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-06-03] CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdvancedSystemCareService10; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [462624 2016-12-12] (IObit) S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2021592 2016-04-05] (Adobe Systems, Incorporated) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-29] (AVAST Software) S4 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed] R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042032 2016-12-13] (Microsoft Corporation) S4 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-26] (Dropbox, Inc.) S4 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-26] (Dropbox, Inc.) S4 DbxSvc; C:\Windows\system32\DbxSvc.exe [51504 2017-01-05] (Dropbox, Inc.) S4 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2272904 2016-09-29] (Comodo) R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [350720 2012-06-01] (Microsoft Corporation) R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [26680 2016-02-18] (Hewlett-Packard Company) S4 IceDragonUpdater; C:\Program Files (x86)\Comodo\IceDragon\icedragon_updater.exe [4295320 2016-12-20] () R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-20] (Microsoft Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2011-12-16] () S2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [360736 2016-10-28] (IObit) R2 iprip; C:\Windows\System32\iprip.dll [35328 2009-07-13] (Microsoft Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation) R2 LPDSVC; C:\Windows\system32\lpdsvc.dll [45568 2009-07-13] (Microsoft Corporation) R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed] S3 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [189440 2010-11-20] (Microsoft Corporation) S2 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272688 2012-06-25] () R3 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [793280 2014-11-04] (Samsung Electronics Co., Ltd.) R2 SNMP; C:\Windows\System32\snmp.exe [49664 2010-11-20] (Microsoft Corporation) R2 SNMP; C:\Windows\SysWOW64\snmp.exe [47616 2010-11-20] (Microsoft Corporation) S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7500048 2016-09-20] (TeamViewer GmbH) S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-13] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S3 WMSVC; C:\Windows\system32\inetsrv\wmsvc.exe [10752 2009-07-13] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3325232 2012-06-25] (Intel® Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [82936 2016-11-09] (AVAST Software) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-29] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-29] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-29] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-08-29] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-29] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-13] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-22] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-08-29] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software) R3 hswpan; C:\Windows\System32\DRIVERS\hswpan.sys [108288 2011-12-07] (Ozmo Inc) R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-12-24] (REALiX(tm)) S3 MDA_NTDRV; C:\Windows\system32\MDA_NTDRV.sys [47104 2016-05-20] () S3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.) R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit) R3 SmbDrv; C:\Windows\system32\drivers\Smb_driver.sys [20016 2011-10-13] (Synaptics Incorporated) S3 btmaux; system32\DRIVERS\btmaux.sys [X] S3 dbx; system32\DRIVERS\dbx.sys [X] S3 RTL8187; system32\DRIVERS\wg111v2.sys [X] ========================== Drivers MD5 ======================= C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Accelerometer.sys 899B7E724BF19F17978B6A37B864A277 C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit C:\Windows\system32\drivers\afd.sys 9A4A1EEE802BF2F878EE8EAB407B21B7 C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49 C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048 C:\Windows\System32\DRIVERS\AMPPAL.sys D46391F209DE0A98A97D1D1765F53438 C:\Windows\System32\DRIVERS\amppal.sys D46391F209DE0A98A97D1D1765F53438 C:\Windows\system32\drivers\appid.sys 5F9389D9A2D5A2A7B03DC92914B43A88 C:\Windows\system32\drivers\arc.sys ==> MD5 is legit C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit C:\Windows\system32\drivers\aswHdsKe.sys 3CE1B3C4122030A4FAE6894A49BBDC0B C:\Windows\system32\drivers\aswHwid.sys 9B480B472D6826E7257C90E2D0EE2954 C:\Windows\system32\drivers\aswKbd.sys 06362BBA1347CBA0996F4B39BB1D8353 C:\Windows\system32\drivers\aswMonFlt.sys 1BB00571CC2C78463ABD7E9C32970758 C:\Windows\system32\drivers\aswRdr2.sys 7010B57D708DA5C9686A5923EE621776 C:\Windows\System32\Drivers\aswRvrt.sys 937885085BFE5BD08EC1BC0245DD203B C:\Windows\system32\drivers\aswSnx.sys 0B6352251C5D84130DF4252D33D266C2 C:\Windows\system32\drivers\aswSP.sys 28213B34725B18387CC1B8C3D73858A1 C:\Windows\system32\drivers\aswStm.sys 9C58B6E9663D0A76D00D83E43C765BDF C:\Windows\System32\Drivers\aswVmm.sys D60D9201739400F0FBDB9E36A3212D91 C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\system32\drivers\atapi.sys ==> MD5 is legit C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bcmwl664.sys 9E84A931DBEE0292E38ED672F6293A99 C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\system32\drivers\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bridge.sys 5C2F352A4E961D72518261257AAE204B C:\Windows\System32\DRIVERS\bridge.sys 5C2F352A4E961D72518261257AAE204B C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\BthEnum.sys CF98190A94F62E405C8CB255018B2315 C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bthpan.sys 02DD601B708DD0667E1331FA8518E9FF C:\Windows\System32\Drivers\BTHport.sys 738D0E9272F59EB7A1449C3EC118E6C4 C:\Windows\System32\Drivers\BTHUSB.sys F188B7394D81010767B6DF3178519A37 C:\Windows\System32\DRIVERS\btmhsf.sys 2B4B508AFAC2A563931AF1FE875A5B16 C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys 404B7DF9CA4D1CB675045AF220FF3285 C:\Windows\System32\DRIVERS\clwvd.sys 9573E8C7C3B3D1625FD941841FD0859C C:\Windows\System32\DRIVERS\CmBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys 3323F76352B0AF14B2CDC4DFBF3E980A C:\Windows\System32\drivers\compbatt.sys ==> MD5 is legit C:\Windows\system32\drivers\CompositeBus.sys ==> MD5 is legit C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\drivers\disk.sys 616387BBD83372220B09DE95F4E67BBC C:\Windows\system32\drivers\drmkaud.sys 26FE888505E5A945B0536AF9A2A27A6F C:\Windows\System32\drivers\dxgkrnl.sys 3A9D7D464BDB3B70D7ECF689ADABBD4D C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0 C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A C:\Windows\system32\drivers\HDAudBus.sys ==> MD5 is legit C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit C:\Windows\System32\drivers\hpdskflt.sys D104FF402FC3DDB686E6DEF00334DB26 C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hswpan.sys AA57785469C8E41643E4A6EBD43B0667 C:\Windows\System32\drivers\HTTP.sys F61634BEC53F73702A10DE69F6DCAF57 C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS E5805896A55D4166C20F216249F40FA3 C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\i8042prt.sys ==> MD5 is legit C:\Windows\System32\drivers\iaStor.sys C224331A54571C8C9162F7714400BBBD C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366 C:\Windows\System32\DRIVERS\iBtFltCoex.sys 9E3D44CE737388F6BBBB6DD4A1C1847C C:\Windows\System32\DRIVERS\igdkmd64.sys 11BA677667432A99CA261A472A2C29B8 C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit C:\Windows\System32\drivers\intelaud.sys CADDF0927DAC63EDAE48F5C35A61D87D C:\Windows\System32\DRIVERS\IntcDAud.sys 6C9FFFECA9FED31347D211C5D1FFBD2D C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit C:\Windows\system32\drivers\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\msiscsi.sys 96BB922A0981BC7432C8CF52B5410FE6 C:\Windows\System32\drivers\iusb3hcs.sys DC0DBA5164F657DE2AE94B9D1FF75DA4 C:\Windows\System32\DRIVERS\iusb3hub.sys BA4F3A70F03584E5B907DA815677727D C:\Windows\System32\DRIVERS\iusb3xhc.sys E6130F70D61867C7EFC13A2F808EDC58 C:\Windows\system32\drivers\iwdbus.sys 716F66336F10885D935B08174DC54242 C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit C:\Windows\System32\Drivers\ksecdd.sys CFBA6BCBBDC7E33813D92FFB3460FA07 C:\Windows\System32\Drivers\ksecpkg.sys CE66825289EE8326CB52C4E9E785ACB0 C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\LHidFilt.Sys AFDFA4A6B0F7B15AA38E494FD4595741 C:\Windows\System32\DRIVERS\LMouFilt.Sys C3E82B320F34C97F32B8026F4C249BEF C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\System32\Drivers\LUsbFilt.Sys C71AD919F64815B8E7C027AB167A1859 C:\Windows\system32\MDA_NTDRV.sys 39DFF42E57C53A58C162F4760A75EA84 C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\HECIx64.sys 772A1DEEDFDBC244183B5C805D1B7D85 C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys 67050452C0118BAF2883928E6FCCFE47 C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\System32\drivers\mqac.sys CD22D2563039DDA6793F7624719363A7 C:\Windows\system32\drivers\mrxdav.sys D7ADC2B83CA0B0381F75A98351F72CEE C:\Windows\System32\DRIVERS\mrxsmb.sys B7FADA5E1E55BB63F90EB9F8F016113B C:\Windows\System32\DRIVERS\mrxsmb10.sys 34AFF1849B3EC042C40C5EEC9D78562A C:\Windows\System32\DRIVERS\mrxsmb20.sys 058CE7A55E140EB0C72FBA6FD2FA72DE C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\system32\drivers\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\Windows\System32\drivers\ndis.sys F7309F42555F8AAB7144A51A1F2585B0 C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys E47D571FEC2C76E867935109AB2A770C C:\Windows\System32\DRIVERS\NETwNs64.sys B51E9AD4F4E4F8DBE0AB882756BC5DAB C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\System32\Drivers\Ntfs.sys 47B2D0B31BDC3EBE6090228E2BA3764D C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nvm62x64.sys A85B4F2EF3A7304A5399EF0526423040 C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit C:\Windows\system32\drivers\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C C:\Windows\System32\drivers\pci.sys ==> MD5 is legit C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ED6E75158D28D33A2E2A020AC5B2B59D C:\Windows\System32\DRIVERS\pneteth.sys A010F13D27C1033A8BE09D5FA9BF348B C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\drivers\processr.sys ==> MD5 is legit C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit C:\Windows\system32\drivers\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34 C:\Windows\System32\Drivers\RDPWD.sys FE571E088C2D83619D2D48D4E961BF41 C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rfcomm.sys 3DD798846E2C28102B922C56E71B7932 C:\Windows\System32\DRIVERS\RtsP2Stor.sys 7F324DFFCA5318EEF040DBE351D038D8 C:\Windows\System32\DRIVERS\Rt64win7.sys 9140DB0911DE035FED0A9A77A2D156EA C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\sdbus.sys 111E0EBC0AD79CB0FA014B907B231CF0 C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\serenum.sys ==> MD5 is legit C:\Windows\system32\drivers\serial.sys ==> MD5 is legit C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit C:\Windows\System32\Drivers\SmartDefragDriver.sys E77CB3736A702D46A6FB15FB4A9894E3 C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\system32\drivers\Smb_driver.sys 8AF2546861B179E2517EB02748B4FAB7 C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\srv.sys F2F4B895296EE3ECCE781CC2A296A5D1 C:\Windows\System32\DRIVERS\srv2.sys FD0008BEDD2723170CCA7D61837DFD52 C:\Windows\System32\DRIVERS\VSTAZL6.SYS 0C4540311E11664B245A263E1154CEF8 C:\Windows\System32\DRIVERS\VSTDPV6.SYS 02071D207A9858FBE3A48CBFD59C4A04 C:\Windows\System32\DRIVERS\VSTCNXT6.SYS 18E40C245DBFAF36FD0134A7EF2DF396 C:\Windows\System32\DRIVERS\srvnet.sys 63B5845D9379262083655D5C6AB8DFC5 C:\Windows\System32\DRIVERS\ssadbus.sys 8F8324ED1DE63FFC7B1A02CD2D963C72 C:\Windows\System32\DRIVERS\ssadmdfl.sys 58221EFCB74167B73667F0024C661CE0 C:\Windows\System32\DRIVERS\ssadmdm.sys 4DA7C71BFAC5AD71255B7E4CAB980163 C:\Windows\System32\DRIVERS\ssadserd.sys D33D1BD3EC0E766211A234F56A12726D C:\Windows\system32\Drivers\SSPORT.sys 0211AB46B73A2623B86C1CFCB30579AB C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\stwrt64.sys 6F69D75F50E8FAF1003AA6CFB18B91EC C:\Windows\System32\DRIVERS\serscan.sys DECACB6921DED1A38642642685D77DAC C:\Windows\system32\drivers\swenum.sys ==> MD5 is legit C:\Windows\system32\drivers\SynTP.sys AC3CC98B1BDB6540021D3FFB105AC2B9 C:\Windows\System32\drivers\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E C:\Windows\System32\DRIVERS\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8 C:\Windows\System32\DRIVERS\tdx.sys AA77EB517D2F07A947294F260E3ACA83 C:\Windows\system32\drivers\termdd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\tssecsrv.sys 19BEDA57F3E0A06B8D5EB6D619BD5624 C:\Windows\System32\drivers\tsusbflt.sys E9981ECE8D894CEF7038FD1D040EB426 C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07 C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umpass.sys ==> MD5 is legit C:\Windows\System32\drivers\usbaudio.sys B0435098C81D04CAFFF80DDB746CD3A2 C:\Windows\System32\DRIVERS\usbccgp.sys DCA68B0943D6FA415F0C56C92158A83A C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31 C:\Windows\System32\DRIVERS\usbehci.sys 18A85013A3E0F7E1755365D287443965 C:\Windows\System32\DRIVERS\usbhub.sys 8D1196CFBB223621F2C67D45710F25BA C:\Windows\system32\drivers\usbohci.sys 765A92D428A8DB88B960DA5A8D6089DC C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbscan.sys 9661DA76B4531B2DA272ECCE25A8AF24 C:\Windows\System32\DRIVERS\usbser.sys B57B4F0BEC4270A281B9F8537EB2FA04 C:\Windows\System32\DRIVERS\USBSTOR.SYS D029DD09E22EB24318A8FC3D8138BA43 C:\Windows\system32\drivers\usbuhci.sys DD253AFC3BC6CBA412342DE60C3647F3 C:\Windows\System32\Drivers\usbvideo.sys 1F775DA4CF1A3A1834207E975A72E9D7 C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\drivers\volsnap.sys DF8126BD41180351A093A3AD2FC8903B C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwifimp.sys ==> MD5 is legit C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\drivers\wd.sys ==> MD5 is legit C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8 C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WSDPrint.sys 8D918B1DB190A4D9B1753A66FA8C96E8 C:\Windows\System32\DRIVERS\WSDScan.sys 4A2A5C50DD1A63577D3ACA94269FBC7F C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659 ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-01-29 13:06 - 2017-01-29 13:06 - 00059094 _____ C:\Users\AFAFA\Desktop\FRST.txt 2017-01-29 13:05 - 2017-01-29 13:06 - 00000000 ____D C:\FRST 2017-01-29 13:03 - 2017-01-29 13:03 - 02420736 _____ (Farbar) C:\Users\AFAFA\Desktop\FRST64.exe 2017-01-29 13:01 - 2017-01-29 13:01 - 00363667 _____ C:\Users\AFAFA\Downloads\infected with the cryptowall _ Free Malware Removal Forum.pdf 2017-01-29 12:34 - 2017-01-29 12:34 - 00255350 _____ C:\Users\AFAFA\Downloads\Adware Removal instructions.pdf 2017-01-29 12:34 - 2017-01-29 12:34 - 00224584 _____ C:\Users\AFAFA\Downloads\Internet Optimizer Adware Registry Key location.pdf 2017-01-29 12:32 - 2017-01-29 12:32 - 00172688 _____ C:\Users\AFAFA\Downloads\FxNetOpt.exe 2017-01-29 00:27 - 2017-01-29 00:27 - 05952100 _____ C:\Users\AFAFA\Downloads\ezcheckprinting-check-write-amp-print-501_ODxCracK.zip.crdownload 2017-01-28 13:25 - 2017-01-28 13:25 - 01605632 _____ C:\Users\AFAFA\Downloads\CheckPrintingSetup.msi 2017-01-28 13:13 - 2017-01-28 13:13 - 00114653 _____ C:\Users\AFAFA\Downloads\Demand Draft Sample.pdf 2017-01-28 13:13 - 2017-01-28 13:13 - 00114653 _____ C:\Users\AFAFA\Downloads\ddco.pdf 2017-01-28 13:10 - 2017-01-28 13:10 - 00118131 _____ C:\Users\AFAFA\Downloads\Automatic_Bank_Draft_Authorization_Form.pdf 2017-01-28 13:06 - 2017-01-28 13:06 - 00054360 _____ C:\Users\AFAFA\Downloads\GALLAUDET.ttf 2017-01-28 10:08 - 2017-01-28 10:08 - 01051278 _____ C:\Users\AFAFA\Downloads\finaljudgmentandcivilorders101414.pdf 2017-01-28 09:55 - 2017-01-28 09:55 - 00164793 _____ C:\Users\AFAFA\Downloads\Kelly C161-1345 ROA 1-3-17.pdf 2017-01-24 16:41 - 2017-01-24 16:41 - 00000000 ____D C:\Windows\SysWOW64\GWX 2017-01-23 22:52 - 2017-01-23 22:52 - 00011613 _____ C:\Users\AFAFA\Downloads\Proof (1).pdf 2017-01-22 23:49 - 2017-01-22 23:49 - 00128841 _____ C:\Users\AFAFA\Downloads\WO201701220000022.pdf 2017-01-22 23:46 - 2017-01-22 23:46 - 00135159 _____ C:\Users\AFAFA\Downloads\20170122000046-7.pdf 2017-01-22 23:46 - 2017-01-22 23:46 - 00129119 _____ C:\Users\AFAFA\Downloads\20170122000046-7_A.pdf 2017-01-22 23:24 - 2017-01-22 23:24 - 00044867 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1_w_add (4).pdf 2017-01-22 19:29 - 2017-01-22 19:29 - 64051848 _____ C:\Users\AFAFA\Downloads\Tim Damron UCC 1 Class Day 1.m4a 2017-01-22 19:29 - 2017-01-22 19:29 - 42894703 _____ C:\Users\AFAFA\Downloads\Tim Damron Call 12-10.m4a 2017-01-22 19:29 - 2017-01-22 19:29 - 25251330 _____ C:\Users\AFAFA\Downloads\Wayne County Kurt Kallenback 11-14.m4a 2017-01-22 19:28 - 2017-01-22 19:29 - 27121659 _____ C:\Users\AFAFA\Downloads\Kw 10-18.m4a 2017-01-22 19:28 - 2017-01-22 19:29 - 09185299 _____ C:\Users\AFAFA\Downloads\Tim Damron 11-17.m4a 2017-01-22 19:08 - 2017-01-22 19:08 - 00082217 _____ C:\Users\AFAFA\Downloads\waiver-intervivos.pdf 2017-01-22 19:02 - 2017-01-22 19:02 - 00331762 _____ C:\Users\AFAFA\Downloads\Constitution-$10-email thread.pdf 2017-01-22 19:02 - 2017-01-22 19:02 - 00205605 _____ C:\Users\AFAFA\Downloads\margie-letter.pdf 2017-01-22 19:02 - 2017-01-22 19:02 - 00167917 _____ C:\Users\AFAFA\Downloads\20160523-prek-kuestions.pdf 2017-01-22 19:02 - 2017-01-22 19:02 - 00143299 _____ C:\Users\AFAFA\Downloads\20160606-post-call-001.pdf 2017-01-22 19:02 - 2017-01-22 19:02 - 00085370 _____ C:\Users\AFAFA\Downloads\governor-letter.pdf 2017-01-22 01:02 - 2017-01-22 01:04 - 00030219 _____ C:\Users\AFAFA\Downloads\Copy of 9-18-15 State-by-State Instructions for Submitting Med Certificate_1.xlsx 2017-01-21 15:38 - 2017-01-21 15:39 - 06999639 _____ C:\Users\AFAFA\Downloads\UCC1_paperwork.zip 2017-01-21 15:35 - 2017-01-21 15:35 - 00054072 _____ C:\Users\AFAFA\Downloads\Ein_#.zip 2017-01-20 23:19 - 2017-01-20 23:19 - 00013961 _____ C:\Users\AFAFA\Downloads\Jake%27s Private Bank EIN CP575Notice_1484069489693.pdf 2017-01-20 20:58 - 2017-01-20 20:58 - 06306737 _____ C:\Users\AFAFA\Downloads\US Supreme Court Cases Driver License.pdf 2017-01-20 20:35 - 2017-01-20 22:22 - 00000000 ___SD C:\Windows\system32\GWX 2017-01-20 20:16 - 2017-01-20 20:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2017-01-20 19:52 - 2017-01-20 19:55 - 00000000 ____D C:\Users\AFAFA\Downloads\TRKT 2017-01-19 17:58 - 2017-01-19 17:58 - 00007465 _____ C:\Users\AFAFA\Downloads\micr-encoding (1).zip 2017-01-19 17:58 - 2017-01-19 17:58 - 00000000 ____D C:\Users\AFAFA\Downloads\micr-encoding (1) 2017-01-19 16:56 - 2017-01-19 16:56 - 00007465 _____ C:\Users\AFAFA\Downloads\micr-encoding.zip 2017-01-18 23:54 - 2017-01-18 23:54 - 00298443 _____ C:\Users\AFAFA\Downloads\My Cart Jake - DressLily.pdf 2017-01-17 23:22 - 2017-01-17 23:22 - 07338463 _____ C:\Users\AFAFA\Downloads\1_ (FED) HABEAS CORPUS-ilovepdf-compressed.pdf 2017-01-17 23:08 - 2017-01-17 23:08 - 00198790 _____ C:\Users\AFAFA\Downloads\court_survival_guide.pdf 2017-01-17 23:08 - 2017-01-17 23:08 - 00181844 _____ C:\Users\AFAFA\Downloads\court_tricks_and_traps.pdf 2017-01-17 23:08 - 2017-01-17 23:08 - 00025022 _____ C:\Users\AFAFA\Downloads\rights_violation_checklist_for_unlawful_arrest.pdf 2017-01-17 05:43 - 2017-01-17 05:43 - 00304361 _____ C:\Users\AFAFA\Downloads\ViewFile (4).pdf 2017-01-17 05:42 - 2017-01-17 05:42 - 00297009 _____ C:\Users\AFAFA\Downloads\ViewFile (3).pdf 2017-01-17 05:40 - 2017-01-17 05:40 - 00298122 _____ C:\Users\AFAFA\Downloads\ViewFile (2).pdf 2017-01-16 23:11 - 2017-01-16 23:11 - 00045198 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1_TCF (3).pdf 2017-01-16 23:11 - 2017-01-16 23:11 - 00035958 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1_TCF (4).pdf 2017-01-16 21:47 - 2017-01-16 21:47 - 00128846 _____ C:\Users\AFAFA\Downloads\WO201701160000245.pdf 2017-01-16 21:45 - 2017-01-16 21:45 - 00134254 _____ C:\Users\AFAFA\Downloads\20170116000311-7.pdf 2017-01-16 21:44 - 2017-01-16 21:44 - 00129103 _____ C:\Users\AFAFA\Downloads\20170116000311-7_A.pdf 2017-01-16 21:18 - 2017-01-16 21:18 - 00045198 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1_TCF (2).pdf 2017-01-16 21:01 - 2017-01-28 19:55 - 00000892 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2017-01-16 21:01 - 2017-01-16 21:01 - 00243552 _____ C:\Users\AFAFA\Downloads\Firefox Setup Stub 50.1.0.exe 2017-01-16 21:01 - 2017-01-16 21:01 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-01-16 21:00 - 2017-01-16 21:01 - 20630616 _____ (Adobe Systems Incorporated) C:\Users\AFAFA\Downloads\install_flash_player_ppapi.exe 2017-01-16 20:20 - 2017-01-16 20:20 - 00008285 _____ C:\Users\AFAFA\Downloads\MyPDF (2).PDF 2017-01-16 20:17 - 2017-01-16 20:17 - 00008283 _____ C:\Users\AFAFA\Downloads\MyPDF (1).PDF 2017-01-16 20:08 - 2017-01-16 20:08 - 00008301 _____ C:\Users\AFAFA\Downloads\MyPDF.PDF 2017-01-16 19:28 - 2017-01-16 19:28 - 03183117 _____ C:\Users\AFAFA\Downloads\UCCOnlineAccountSetup.pdf 2017-01-16 19:20 - 2017-01-16 19:21 - 00119542 _____ C:\Users\AFAFA\Downloads\filingDetail.pdf 2017-01-16 19:10 - 2017-01-16 19:10 - 00035906 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1_TCF (1).pdf 2017-01-16 19:03 - 2017-01-16 19:03 - 00173497 _____ C:\Users\AFAFA\Downloads\808_10777_AdminCode.pdf 2017-01-16 18:58 - 2017-01-16 18:58 - 00045146 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1_TCF.pdf 2017-01-16 18:31 - 2017-01-16 18:31 - 00006928 _____ C:\Users\AFAFA\Downloads\mcl-780-9 (1).pdf 2017-01-16 18:28 - 2017-01-16 18:28 - 00006928 _____ C:\Users\AFAFA\Downloads\mcl-780-9.pdf 2017-01-16 15:36 - 2017-01-16 15:36 - 00013961 _____ C:\Users\AFAFA\Downloads\Jake's Private Bank EIN CP575Notice_1484069489693(2).pdf 2017-01-16 15:35 - 2017-01-16 15:35 - 00013961 _____ C:\Users\AFAFA\Downloads\Jake's Private Bank EIN CP575Notice_1484069489693(1).pdf 2017-01-16 15:34 - 2017-01-16 15:34 - 00013961 _____ C:\Users\AFAFA\Downloads\Jake's Private Bank EIN CP575Notice_1484069489693.pdf 2017-01-15 21:45 - 2017-01-15 21:50 - 00045062 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1_w_add (3).pdf 2017-01-15 21:00 - 2017-01-15 21:00 - 00145202 _____ C:\Users\AFAFA\Downloads\i56.pdf 2017-01-15 21:00 - 2017-01-15 21:00 - 00094690 _____ C:\Users\AFAFA\Downloads\f56f.pdf 2017-01-15 14:40 - 2017-01-15 14:40 - 00101713 _____ C:\Users\AFAFA\Downloads\OIDRemedy - Report 1099, Explanation of the 1099OID and the 1040V by Freedom School.pdf 2017-01-15 14:38 - 2017-01-15 14:38 - 08683588 _____ C:\Users\AFAFA\Downloads\OID Manual 120808 (from John Kirk)Revised.pdf 2017-01-15 14:21 - 2017-01-15 14:22 - 10980608 _____ C:\Users\AFAFA\Downloads\Secret_Banker's_Manual.pdf 2017-01-15 14:21 - 2017-01-15 14:21 - 13507735 _____ C:\Users\AFAFA\Downloads\bankers-secret-manual.pdf 2017-01-15 14:19 - 2017-01-15 14:19 - 10950122 _____ C:\Users\AFAFA\Downloads\Top-Secret-Bankers-Manual-by-Thomas-Schauf-Copyright-2002.pdf 2017-01-15 14:17 - 2017-01-15 14:17 - 00582442 _____ C:\Users\AFAFA\Downloads\tomschauf-topsecretbankersmanual2003_ocr_v-1.pdf 2017-01-15 12:48 - 2017-01-15 14:33 - 00000000 ____D C:\My Web Sites 2017-01-15 12:47 - 2017-01-15 12:47 - 00000796 _____ C:\Users\AFAFA\Desktop\HTTrack Website Copier.lnk 2017-01-15 12:47 - 2017-01-15 12:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinHTTrack(Website Copier) 2017-01-15 12:47 - 2017-01-15 12:47 - 00000000 ____D C:\Program Files\WinHTTrack 2017-01-15 10:01 - 2017-01-15 10:03 - 49880336 _____ (Garmin Ltd or its subsidiaries) C:\Users\AFAFA\Downloads\GarminExpressInstaller (3).exe 2017-01-14 21:58 - 2017-01-14 21:59 - 49880336 _____ (Garmin Ltd or its subsidiaries) C:\Users\AFAFA\Downloads\GarminExpressInstaller (2).exe 2017-01-14 21:41 - 2017-01-14 21:42 - 08576559 _____ C:\Users\AFAFA\Downloads\GPO-STYLEMANUAL-2008.pdf 2017-01-14 19:41 - 2017-01-14 19:41 - 01834758 _____ C:\Users\AFAFA\Downloads\MAC Website copier httrack-3.48.22.tar 2017-01-14 19:40 - 2017-01-14 19:40 - 04498888 _____ (HTTrack ) C:\Users\AFAFA\Downloads\Website copier httrack_x64-3.48.22.exe 2017-01-14 01:00 - 2017-01-14 01:00 - 00054097 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1_w_add (2).pdf 2017-01-14 00:38 - 2017-01-14 00:38 - 00022928 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1_w_add (1).pdf 2017-01-14 00:23 - 2017-01-14 00:23 - 00022676 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1 My Royal Land.pdf 2017-01-13 23:47 - 2017-01-13 23:47 - 00055918 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1 DL & VEH.pdf 2017-01-13 22:58 - 2017-01-13 22:58 - 00021601 _____ C:\Users\AFAFA\Downloads\Kellys_Editable_Non_UCC1_w_add.pdf 2017-01-13 19:08 - 2017-01-13 19:08 - 00013917 _____ C:\Users\AFAFA\Desktop\15 USC Non-UCC1 filing example.txt 2017-01-13 17:00 - 2017-01-13 17:00 - 00000581 _____ C:\Users\AFAFA\Downloads\20-Dec-2016_to_11-Jan-2017.csv 2017-01-13 17:00 - 2017-01-13 17:00 - 00000581 _____ C:\Users\AFAFA\Downloads\20-Dec-2016_to_11-Jan-2017 (1).csv 2017-01-12 20:25 - 2017-01-12 20:25 - 00087479 _____ C:\Users\AFAFA\Downloads\GL Accounts and Mapping.xlsx 2017-01-12 20:21 - 2017-01-12 20:21 - 00979812 _____ C:\Users\AFAFA\Downloads\DepartmentalSAProgramManual.pdf 2017-01-12 20:15 - 2017-01-12 20:15 - 05101517 _____ C:\Users\AFAFA\Downloads\Salary Book_WL.pdf 2017-01-12 20:10 - 2017-01-12 20:10 - 00017934 _____ C:\Users\AFAFA\Downloads\WL-Pay-Scales-2016-2017.xlsx 2017-01-12 19:26 - 2017-01-12 19:26 - 00322271 _____ C:\Users\AFAFA\Downloads\for_the_defense_-_kingsley_authored_-_august_2010.pdf 2017-01-12 19:26 - 2017-01-12 19:26 - 00207740 _____ C:\Users\AFAFA\Downloads\03. Bachrach.pdf 2017-01-11 23:26 - 2017-01-11 23:27 - 00003222 _____ C:\Windows\System32\Tasks\{1FDE7613-8D57-4223-B70C-1477649384DB} 2017-01-11 23:21 - 2017-01-11 23:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-01-11 21:38 - 2017-01-11 21:38 - 00350850 _____ C:\Users\AFAFA\Downloads\ViewFile (1).pdf 2017-01-10 21:24 - 2017-01-10 21:25 - 19855436 _____ C:\Users\AFAFA\Downloads\Claim of Birthright Process.compressed(1).pdf 2017-01-10 20:05 - 2017-01-11 23:27 - 00003222 _____ C:\Windows\System32\Tasks\{54C2B55B-7BBF-42BE-8B8F-1537BA58E15F} 2017-01-10 19:31 - 2017-01-10 19:31 - 85668188 _____ C:\Users\AFAFA\Downloads\DD214 2017.pdf 2017-01-10 17:43 - 2017-01-10 17:43 - 00115716 _____ C:\Users\AFAFA\Downloads\J & K Notary App to Dept of State.pdf 2017-01-10 17:42 - 2017-01-10 17:42 - 00998292 _____ C:\Users\AFAFA\Downloads\LabelDownloadServlet.pdf 2017-01-10 17:42 - 2017-01-10 17:42 - 00998292 _____ C:\Users\AFAFA\Downloads\LabelDownloadServlet (1).pdf 2017-01-10 17:42 - 2017-01-10 17:42 - 00998273 _____ C:\Users\AFAFA\Downloads\Label-395034650.pdf 2017-01-10 17:06 - 2017-01-10 17:06 - 06046331 _____ C:\Users\AFAFA\Downloads\Jake N Kelly Notary Apps.pdf 2017-01-09 22:04 - 2017-01-09 22:04 - 00692024 _____ C:\Users\AFAFA\Downloads\Common and Commercial Law and Liens.pdf 2017-01-09 19:01 - 2017-01-09 19:01 - 03827897 _____ C:\Users\AFAFA\Downloads\UCC1 response.pdf 2017-01-09 19:01 - 2017-01-09 19:01 - 01291605 _____ C:\Users\AFAFA\Downloads\warrant hazel park040.pdf 2017-01-09 19:00 - 2017-01-09 19:00 - 00042469 _____ C:\Users\AFAFA\Downloads\Trinity golden eggs.odt 2017-01-09 18:59 - 2017-01-09 18:59 - 01311539 _____ C:\Users\AFAFA\Downloads\speeding hazel park039.pdf 2017-01-09 18:58 - 2017-01-09 18:58 - 01066812 _____ C:\Users\AFAFA\Downloads\public defender bull shit044.pdf 2017-01-09 18:58 - 2017-01-09 18:58 - 00686403 _____ C:\Users\AFAFA\Downloads\right of master033.pdf 2017-01-09 18:57 - 2017-01-09 18:57 - 03817374 _____ C:\Users\AFAFA\Downloads\Original tickets045.pdf 2017-01-09 18:57 - 2017-01-09 18:57 - 01315264 _____ C:\Users\AFAFA\Downloads\no prf insurance hazel park041.pdf 2017-01-09 18:57 - 2017-01-09 18:57 - 01313249 _____ C:\Users\AFAFA\Downloads\no prf regis hazel park042.pdf 2017-01-09 18:57 - 2017-01-09 18:57 - 01121088 _____ C:\Users\AFAFA\Downloads\Non UCC filed 043.pdf 2017-01-09 18:56 - 2017-01-09 18:56 - 00986414 _____ C:\Users\AFAFA\Downloads\NO FEMALE can be arrested on civil049.pdf 2017-01-09 18:56 - 2017-01-09 18:56 - 00864812 _____ C:\Users\AFAFA\Downloads\impound receipt047.pdf 2017-01-09 18:54 - 2017-01-09 18:54 - 00501396 _____ C:\Users\AFAFA\Downloads\good luck finding ur car046.pdf 2017-01-09 18:53 - 2017-01-09 18:53 - 01104850 _____ C:\Users\AFAFA\Downloads\bond orders048.pdf 2017-01-09 18:52 - 2017-01-09 18:52 - 00231526 _____ C:\Users\AFAFA\Downloads\8874.jpeg 2017-01-09 18:52 - 2017-01-09 18:52 - 00213489 _____ C:\Users\AFAFA\Downloads\8875.jpeg 2017-01-09 18:52 - 2017-01-09 18:52 - 00145590 _____ C:\Users\AFAFA\Downloads\8871.jpeg 2017-01-09 18:52 - 2017-01-09 18:52 - 00145590 _____ C:\Users\AFAFA\Downloads\8871(1).jpeg 2017-01-09 18:52 - 2017-01-09 18:52 - 00135394 _____ C:\Users\AFAFA\Downloads\8872.jpeg 2017-01-09 18:51 - 2017-01-09 18:51 - 00160388 _____ C:\Users\AFAFA\Downloads\8870.jpeg 2017-01-09 18:51 - 2017-01-09 18:51 - 00118911 _____ C:\Users\AFAFA\Downloads\8749~2.jpeg 2017-01-09 18:49 - 2017-01-09 18:49 - 00231292 _____ C:\Users\AFAFA\Downloads\download-1483720501055.pdf 2017-01-09 18:49 - 2017-01-09 18:49 - 00231292 _____ C:\Users\AFAFA\Downloads\download-1483720501055(1).pdf 2017-01-09 18:45 - 2017-01-09 18:45 - 00000000 ____D C:\Users\AFAFA\AppData\Local\Chromium 2017-01-08 23:04 - 2017-01-08 23:04 - 00133686 _____ C:\Users\AFAFA\Downloads\i926.pdf 2017-01-08 20:14 - 2017-01-08 20:14 - 00065864 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8B86.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00034698 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8B57.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00033056 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8B70.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00025310 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8D2A.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00025310 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8B45.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00019259 _____ C:\Users\AFAFA\AppData\LocalLow\wbk89B3.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00019241 _____ C:\Users\AFAFA\AppData\LocalLow\wbk89C5.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00016445 _____ C:\Users\AFAFA\AppData\LocalLow\wbk89FA.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00010371 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8BB4.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00002639 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8B5A.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00001873 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8B9E.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00001651 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8B98.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00001575 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8B6D.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00001568 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8B83.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00001405 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8B9B.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00000765 _____ C:\Users\AFAFA\AppData\LocalLow\wbk89F7.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00000520 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8BD9.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00000451 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8BB1.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00000205 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8C88.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00000205 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8BC6.tmp 2017-01-08 20:14 - 2017-01-08 20:14 - 00000088 _____ C:\Users\AFAFA\AppData\LocalLow\wbk8CE8.tmp 2017-01-08 18:49 - 2017-01-08 22:03 - 00000000 ____D C:\Users\AFAFA\Downloads\New way to pay bills 2017-01-08 17:33 - 2017-01-08 17:34 - 09045034 _____ C:\Users\AFAFA\Downloads\MiWAM Clmt Toolkit.pdf 2017-01-08 17:33 - 2017-01-08 17:33 - 00304361 _____ C:\Users\AFAFA\Downloads\ViewFile(7).pdf 2017-01-08 17:31 - 2017-01-08 17:31 - 00350850 _____ C:\Users\AFAFA\Downloads\ViewFile(6).pdf 2017-01-08 17:08 - 2017-01-08 17:08 - 00306282 _____ C:\Users\AFAFA\Downloads\ViewFile(4).pdf 2017-01-08 17:08 - 2017-01-08 17:08 - 00306268 _____ C:\Users\AFAFA\Downloads\ViewFile(3).pdf 2017-01-08 17:08 - 2017-01-08 17:08 - 00297009 _____ C:\Users\AFAFA\Downloads\ViewFile(5).pdf 2017-01-08 17:06 - 2017-01-08 17:06 - 00304361 _____ C:\Users\AFAFA\Downloads\ViewFile(2).pdf 2017-01-08 17:06 - 2017-01-08 17:06 - 00304361 _____ C:\Users\AFAFA\Downloads\ViewFile(1).pdf 2017-01-08 14:31 - 2017-01-08 14:31 - 00467679 _____ C:\Users\AFAFA\Downloads\InstructionFile(1) 2017-01-08 13:49 - 2017-01-29 01:05 - 00000000 ____D C:\Users\AFAFA\AppData\LocalLow\Mozilla 2017-01-08 13:49 - 2017-01-08 13:49 - 00000000 ____D C:\Users\AFAFA\AppData\Roaming\IceDragon 2017-01-08 13:38 - 2017-01-08 13:38 - 00000000 ____D C:\Program Files\AdTrustMedia 2017-01-08 13:38 - 2017-01-08 13:38 - 00000000 ____D C:\Program Files (x86)\AdTrustMedia 2017-01-08 13:37 - 2017-01-08 13:37 - 00000000 ____D C:\ProgramData\Adtrustmedia 2017-01-08 13:36 - 2017-01-08 13:36 - 00001116 _____ C:\Users\Public\Desktop\Comodo Dragon.lnk 2017-01-08 13:36 - 2017-01-08 13:36 - 00001116 _____ C:\ProgramData\Desktop\Comodo Dragon.lnk 2017-01-08 13:36 - 2017-01-08 13:36 - 00000000 ____D C:\ProgramData\Comodo Downloader 2017-01-08 13:27 - 2017-01-08 13:29 - 00001062 _____ C:\Users\Public\Desktop\Comodo IceDragon.lnk 2017-01-08 13:27 - 2017-01-08 13:29 - 00001062 _____ C:\ProgramData\Desktop\Comodo IceDragon.lnk 2017-01-08 13:26 - 2017-01-08 13:31 - 230532272 _____ (COMODO) C:\Users\AFAFA\Downloads\cispremium_installer_5746_14.exe 2017-01-08 13:24 - 2017-01-08 13:25 - 53489464 _____ (COMODO) C:\Users\AFAFA\Downloads\icedragonsetup.exe 2017-01-08 12:34 - 2017-01-08 12:34 - 00467679 _____ C:\Users\AFAFA\Downloads\InstructionFile 2017-01-08 12:18 - 2017-01-08 12:18 - 00022104 _____ C:\Users\AFAFA\Downloads\MDOC_Web_Directory_381270_7.pdf 2017-01-08 10:17 - 2017-01-08 10:17 - 00005423 _____ C:\Users\AFAFA\AppData\Local\recently-used.xbel 2017-01-08 09:01 - 2017-01-08 09:01 - 00000000 __SHD C:\found.001 2017-01-07 21:08 - 2017-01-07 21:08 - 00154130 _____ C:\Users\AFAFA\Downloads\IRS Form LTC i1099ltc.pdf 2017-01-07 21:08 - 2017-01-07 21:08 - 00115841 _____ C:\Users\AFAFA\Downloads\f1099ltc.pdf 2017-01-07 21:07 - 2017-01-07 21:07 - 00145888 _____ C:\Users\AFAFA\Downloads\i1099ltc.pdf 2017-01-07 11:18 - 2017-01-07 11:18 - 02761351 _____ C:\Users\AFAFA\Downloads\Federal Reserve Banking Documents.zip 2017-01-07 11:18 - 2017-01-07 11:18 - 00100807 _____ C:\Users\AFAFA\Downloads\Fiduciary F56 over your SS Mortmain Account example.pdf 2017-01-07 10:41 - 2017-01-16 21:03 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2017-01-07 10:41 - 2017-01-16 21:03 - 00001147 _____ C:\ProgramData\Desktop\Mozilla Firefox.lnk 2017-01-07 02:12 - 2017-01-07 02:12 - 00000000 ____D C:\Users\AFAFA\Documents\OneNote Notebooks 2017-01-05 19:04 - 2017-01-05 19:04 - 00051504 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2017-01-05 18:48 - 2017-01-05 18:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2017-01-05 18:48 - 2017-01-05 18:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2017-01-05 18:48 - 2017-01-05 18:48 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2017-01-02 13:38 - 2017-01-20 00:04 - 00000000 ____D C:\Users\AFAFA\Downloads\Devine Downloads 2017-01-02 10:49 - 2017-01-02 10:36 - 1685627898 _____ C:\calls.zip.crdownload 2017-01-02 10:46 - 2017-01-07 15:13 - 00000000 ____D C:\Patrick Devine 2017-01-02 10:36 - 2017-01-02 10:52 - 1685692968 _____ C:\Users\AFAFA\Downloads\calls.zip 2017-01-02 10:36 - 2017-01-02 10:39 - 301033967 _____ C:\Users\AFAFA\Downloads\Patrick Devine files.zip 2017-01-01 20:40 - 2017-01-01 20:52 - 00000141 _____ C:\Users\AFAFA\Documents\Patrick Devine Docs location.txt 2016-12-31 10:40 - 2016-12-31 10:40 - 02427178 _____ C:\Users\AFAFA\Downloads\Michigan Auto_Insurance_Guide_448003_7.pdf 2016-12-31 10:27 - 2016-12-31 10:27 - 02426238 _____ C:\Users\AFAFA\Downloads\Auto_Insurance_Guide_448003_7.pdf 2016-12-31 09:29 - 2016-12-31 09:29 - 00096641 _____ C:\Users\AFAFA\Downloads\Michigan Non Profit Plate App.unlocked.pdf 2016-12-31 09:06 - 2016-12-31 09:06 - 00093412 _____ C:\Users\AFAFA\Downloads\bdvr97_75305_7.pdf 2016-12-31 08:56 - 2016-12-31 08:56 - 00242984 _____ C:\Users\AFAFA\Downloads\SOS445_Special_Organization_448735_7.pdf 2016-12-30 23:32 - 2016-12-30 23:32 - 00223938 _____ C:\Users\AFAFA\Downloads\Dealer_Manual_Chapter_7_186063_7.pdf 2016-12-30 21:46 - 2016-12-30 21:46 - 00189769 _____ C:\Users\AFAFA\Downloads\f1099msc.pdf 2016-12-30 21:35 - 2016-12-30 21:35 - 00155332 _____ C:\Users\AFAFA\Downloads\f1096.pdf 2016-12-30 21:03 - 2016-12-30 21:06 - 00509554 _____ C:\Users\AFAFA\Downloads\panasonic KGTX-7641 Corless Phone Quick Manual.pdf 2016-12-30 21:00 - 2016-12-30 21:00 - 00523170 _____ C:\Users\AFAFA\Downloads\kxtg7622.pdf ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-01-29 13:05 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf 2017-01-29 12:19 - 2009-07-13 23:45 - 00031472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-01-29 12:19 - 2009-07-13 23:45 - 00031472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-01-29 12:18 - 2015-04-07 21:38 - 00000000 ____D C:\Users\DefaultAppPool 2017-01-29 12:18 - 2015-04-03 09:27 - 00000000 ____D C:\Users\Classic .NET AppPool 2017-01-29 12:10 - 2009-07-14 00:13 - 00918774 _____ C:\Windows\system32\PerfStringBackup.INI 2017-01-29 12:06 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\inetsrv 2017-01-29 12:04 - 2015-02-22 16:42 - 00000000 ____D C:\ProgramData\ProductData 2017-01-29 12:02 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-01-29 12:02 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\registration 2017-01-29 12:01 - 2015-04-08 17:31 - 127184896 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak 2017-01-29 12:01 - 2015-04-08 17:31 - 127184896 _____ C:\Windows\system32\config\SOFTWARE.iodefrag 2017-01-29 12:01 - 2015-04-08 17:31 - 01093632 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak 2017-01-29 12:01 - 2015-04-08 17:31 - 01093632 _____ C:\Windows\system32\config\DEFAULT.iodefrag 2017-01-29 12:01 - 2015-04-08 17:31 - 00098304 _____ C:\Windows\system32\config\SAM.iodefrag.bak 2017-01-29 12:01 - 2015-04-08 17:31 - 00098304 _____ C:\Windows\system32\config\SAM.iodefrag 2017-01-29 12:01 - 2015-04-08 17:31 - 00024576 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak 2017-01-29 12:01 - 2015-04-08 17:31 - 00024576 _____ C:\Windows\system32\config\SECURITY.iodefrag 2017-01-29 12:00 - 2015-05-21 06:51 - 44986368 _____ C:\Windows\system32\config\components.iodefrag.bak 2017-01-29 12:00 - 2009-07-13 23:45 - 00000000 ____D C:\Windows\ServiceProfiles 2017-01-29 11:49 - 2013-12-04 16:10 - 00000000 ____D C:\Program Files\Enigma Software Group 2017-01-29 00:31 - 2015-08-28 17:35 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-01-28 22:00 - 2013-10-29 10:48 - 00003926 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{64827B23-3178-46BC-93AF-4A4EF7726CB0} 2017-01-28 19:55 - 2012-02-23 22:25 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-01-28 09:00 - 2015-03-11 20:31 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2017-01-25 17:46 - 2014-11-17 19:40 - 00000000 ____D C:\Windows\Minidump 2017-01-25 17:46 - 2014-01-02 17:01 - 00000000 ____D C:\Users\AFAFA\AppData\Local\CrashDumps 2017-01-22 23:08 - 2015-08-26 17:53 - 00000000 ____D C:\Users\AFAFA\Documents\Jakes Docs from F 2017-01-22 19:04 - 2016-09-15 21:38 - 00000000 ____D C:\Users\AFAFA\Downloads\krk 2017-01-22 01:01 - 2013-11-19 15:14 - 00000000 ____D C:\Users\AFAFA\AppData\Roaming\Skype 2017-01-20 22:14 - 2009-07-13 23:45 - 00467392 _____ C:\Windows\system32\FNTCACHE.DAT 2017-01-20 20:55 - 2015-07-17 18:25 - 00000000 ____D C:\ProgramData\boost_interprocess 2017-01-19 18:17 - 2013-11-01 18:07 - 00129512 _____ C:\Users\AFAFA\AppData\Local\GDIPFONTCACHEV1.DAT 2017-01-18 09:34 - 2012-02-23 22:25 - 00000000 ____D C:\Windows\system32\Macromed 2017-01-17 19:57 - 2016-06-10 06:12 - 00000000 ____D C:\Program Files\Microsoft Office 15 2017-01-17 19:11 - 2014-05-01 16:43 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-01-17 19:10 - 2015-07-11 08:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-01-16 21:04 - 2015-02-22 16:43 - 00000000 ____D C:\Users\AFAFA\AppData\LocalLow\IObit 2017-01-16 21:03 - 2016-03-02 09:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-01-16 21:03 - 2015-07-11 08:46 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2017-01-16 21:01 - 2014-05-01 16:43 - 00003770 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-01-16 21:01 - 2012-02-23 22:25 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-01-16 21:01 - 2012-02-23 22:25 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-01-16 18:15 - 2014-09-16 20:01 - 00000000 ____D C:\Users\AFAFA\AppData\Local\Adobe 2017-01-14 22:28 - 2016-03-03 22:41 - 00000000 ____D C:\ProgramData\Package Cache 2017-01-12 18:56 - 2016-07-26 19:31 - 00000906 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2017-01-12 18:56 - 2016-07-26 19:31 - 00000902 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2017-01-11 23:27 - 2016-07-26 19:31 - 00003914 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA 2017-01-11 23:27 - 2016-07-26 19:31 - 00003662 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore 2017-01-11 23:27 - 2016-06-12 16:42 - 00003278 _____ C:\Windows\System32\Tasks\{0ED743AF-110F-438F-857A-07D0CDEE5031} 2017-01-11 23:27 - 2016-02-07 21:57 - 00003124 _____ C:\Windows\System32\Tasks\{F15BC9CB-A46D-4729-A974-4D40197F6127} 2017-01-11 23:27 - 2015-08-29 14:58 - 00003152 _____ C:\Windows\System32\Tasks\{0F098EA3-0A19-4DF2-979C-8646A72FF716} 2017-01-11 23:27 - 2013-11-16 14:36 - 00004286 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2017-01-11 23:27 - 2013-11-16 14:36 - 00004050 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2017-01-11 23:21 - 2016-07-26 19:31 - 00000000 ____D C:\Program Files (x86)\Dropbox 2017-01-09 18:45 - 2013-11-05 19:19 - 00000000 ____D C:\Program Files (x86)\Comodo 2017-01-08 15:11 - 2016-05-21 18:02 - 00000000 ___RD C:\Users\AFAFA\Documents\OneDrive 2017-01-08 14:19 - 2013-11-15 13:01 - 00000000 ____D C:\Windows\pss 2017-01-08 13:39 - 2013-11-05 19:19 - 00000000 ____D C:\ProgramData\COMODO 2017-01-08 13:36 - 2013-11-05 19:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo 2017-01-08 13:35 - 2013-11-05 19:19 - 00000000 ____D C:\Program Files\COMODO 2017-01-08 10:25 - 2016-03-20 11:38 - 00000000 ____D C:\Users\AFAFA\.gimp-2.8 2017-01-08 10:17 - 2016-03-20 11:50 - 00000000 ____D C:\Users\AFAFA\AppData\Local\gtk-2.0 2017-01-08 09:07 - 2016-06-06 19:12 - 00000000 ___RD C:\Users\AFAFA\Google Drive 2017-01-07 16:47 - 2016-03-24 21:46 - 00000000 ____D C:\Users\AFAFA\Downloads\Court Support 2017-01-03 19:56 - 2012-02-23 22:37 - 00000000 ____D C:\ProgramData\Adobe 2017-01-03 17:14 - 2016-07-26 21:55 - 00000000 ___RD C:\Users\AFAFA\Dropbox 2017-01-02 15:15 - 2016-12-15 21:01 - 00000828 _____ C:\Users\Public\Desktop\Greenshot.lnk 2017-01-02 15:15 - 2016-12-15 21:01 - 00000828 _____ C:\ProgramData\Desktop\Greenshot.lnk 2017-01-02 08:38 - 2014-06-16 04:55 - 00000000 ____D C:\Users\AFAFA\Documents\Jurisdictionary 2017-01-02 08:32 - 2013-10-29 10:41 - 00000000 ____D C:\Users\AFAFA 2017-01-01 01:00 - 2014-01-22 09:57 - 00000000 ____D C:\Users\AFAFA\AppData\Local\ElevatedDiagnostics ==================== Files in the root of some directories ======= 2003-02-23 04:54 - 2003-02-23 04:54 - 0000107 _____ () C:\Program Files (x86)\zMarker.txt 2016-07-30 10:54 - 2016-07-30 10:54 - 0004096 ____H () C:\Users\AFAFA\AppData\Local\keyfile3.drm 2017-01-08 10:17 - 2017-01-08 10:17 - 0005423 _____ () C:\Users\AFAFA\AppData\Local\recently-used.xbel 2015-07-09 04:52 - 2015-07-09 04:52 - 0007609 _____ () C:\Users\AFAFA\AppData\Local\Resmon.ResmonCfg ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-01-23 17:52 ==================== End of FRST.txt ============================