Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Adware removal help please

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Adware removal help please

Unread postby serialbusdriver » May 10th, 2017, 11:57 pm

I have adware on my computer. I ran Malwarebytes, but it has failed to satisfactorily resolve the problem. Malwarebytes keeps wanting me to reboot in order to complete the quarantine process. Did that, but no joy. I have to go to work now, will look in later to see if anyone has replied. Thanks serialbusdriver.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-05-2017
Ran by Darryl (administrator) on DARYL-PC (11-05-2017 13:46:58)
Running from C:\Users\Darryl\Downloads
Loaded Profiles: Darryl (Available Profiles: Darryl)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
(VoiceFive, Inc.) C:\Program Files (x86)\PremierOpinion\pmservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.SmartMonitor.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Device Integrator\wldi.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Device Integrator\DI_HIDServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe
HKLM\...\Run: [Persistence] => C:\Windows\system32\igfxpers.exe
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [WindowsLiveDeviceIntegrator] => C:\Program Files (x86)\Windows Live\Device Integrator\wldi.exe [245544 2010-09-24] (Microsoft Corporation)
HKLM-x32\...\Run: [tvncontrol] => "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\...\MountPoints2: {7381b751-215b-11e6-b813-806e6f6e6963} - D:\Bin\Instv2.exe
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{32168274-7FAD-488F-8B52-F84235607655}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{59C24924-C494-4126-83E7-06B8FA81FDC0}: [DhcpNameServer] 192.168.0.33 192.168.0.35 192.168.0.48
Tcpip\..\Interfaces\{768B4AA3-8550-4F25-81F5-A41CB87974CB}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{8EECCB24-0617-42D6-A07D-C116CD0FAD50}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{91CFFC6B-4C5F-4937-AF63-A585CFF7D819}: [NameServer] 192.168.1.1
Tcpip\..\Interfaces\{A93B07B1-50F2-41C7-B151-66390C5FD36B}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{CE3B93E3-F59D-4AB3-BEDB-A05D2999B530}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://k2b-bulk.ebay.com.au/ws/eBayISAP ... e=LCActive
HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://ninemsn.com.au/?ocid=iehp
HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.quicksales.com.au/secure/Use ... statusid=2
hxxps://www.facebook.com/groups/dublin. ... ctivity#!/
hxxp://www.biblegateway.com/
hxxp://www.news.com.au/breaking-news
hxxps://outlook.office365.com/owa/?exsv ... path=/mail
SearchScopes: HKU\.DEFAULT -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> {10B4E706-0FB5-43BE-88B2-C3CC5CCFECC8} URL = hxxp://search.surfcanyon.com/search?f=sb&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q={searchTerms}&src=IE-SearchBox
BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-04-26] (Intel Security)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2011-01-26] (SEIKO EPSON CORPORATION)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-05] (Google Inc.)
BHO-x32: IE7Pro BHO -> {00011268-E188-40DF-A514-835FCD78B1BF} -> C:\Program Files (x86)\IEPro\iepro.dll [2010-06-02] (IE7Pro.com)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-04-26] (Intel Security)
BHO-x32: Fast Search -> {5AB7104A-B71F-49AD-9154-F7F8806AE848} -> C:\Program Files (x86)\Surf Canyon\surfcanyon.dll [2012-06-26] (Surf Canyon Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-08-22] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-05] (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-08-22] (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2011-01-26] (SEIKO EPSON CORPORATION)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-05] (Google Inc.)
Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-04-26] (Intel Security)
Toolbar: HKLM-x32 - Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\IEPro\IEProRecorder.dll [2010-06-02] ()
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-05] (Google Inc.)
Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-04-26] (Intel Security)
Toolbar: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
Toolbar: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-05] (Google Inc.)
Toolbar: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> No Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - No File
DPF: HKLM {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net ... plugin.cab
DPF: HKLM {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.5.0/ ... s-i586.cab
DPF: HKLM-x32 {0742B9EF-8C83-41CA-BFBA-830A59E23533} hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: HKLM-x32 {38AB0814-B09B-4378-9940-14A19638C3C2} hxxp://merchant.auctivacommerce.com/js/ ... ader57.cab
DPF: HKLM-x32 {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} hxxp://www.oztion.com.au/WebResource.ax ... 2182260000
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {EE1FA3D5-2E0E-4D14-B9B4-7C81DEB58A46} hxxp://www.auctiva.com/Aurigma/8.0.49/Uploader8.cab
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll [2010-05-05] (Belarc, Inc.)

FireFox:
========
FF ProfilePath: C:\Users\Darryl\AppData\Roaming\TomTom\HOME\Profiles\1jil5pi8.default [2016-06-17]
FF Extension: (Emulator) - C:\Users\Darryl\AppData\Roaming\TomTom\HOME\Profiles\1jil5pi8.default\Extensions\Navcore.9.510.1234792@tomtom.com [2016-06-17] [not signed]
FF Extension: (Map status indicator) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [2016-06-17] [not signed]
FF ProfilePath: C:\Users\Darryl\AppData\Roaming\Mozilla\Firefox\Profiles\aaxirjbo.default [2017-04-20]
FF NewTab: Mozilla\Firefox\Profiles\aaxirjbo.default -> http://www.google.com
FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\aaxirjbo.default -> Bing
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\aaxirjbo.default -> Bing
FF Homepage: Mozilla\Firefox\Profiles\aaxirjbo.default -> hxxp://k2b-bulk.ebay.com.au/ws/eBayISAP ... e=LCActive
hxxp://www.quicksales.com.au/secure/use ... statusid=2
hxxps://www.facebook.com/
FF Keyword.URL: Mozilla\Firefox\Profiles\aaxirjbo.default -> hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q=
FF Extension: (Bing Search) - C:\Users\Darryl\AppData\Roaming\Mozilla\Firefox\Profiles\aaxirjbo.default\Extensions\bingsearch.full@microsoft.com [2015-07-04] [not signed]
FF Extension: (Avira Password Manager) - C:\Users\Darryl\AppData\Roaming\Mozilla\Firefox\Profiles\aaxirjbo.default\Extensions\passwordmanager@avira.com [2017-04-20]
FF Extension: (Avira SafeSearch Plus) - C:\Users\Darryl\AppData\Roaming\Mozilla\Firefox\Profiles\aaxirjbo.default\Extensions\safesearchplus2@avira.com [2017-04-20]
FF ProfilePath: C:\Users\Darryl\AppData\Roaming\Flock\Browser\Profiles\r9aq44ne.default [2014-06-20]
FF SelectedSearchEngine: Flock\Browser\Profiles\r9aq44ne.default -> Yahoo
FF Homepage: Flock\Browser\Profiles\r9aq44ne.default -> hxxp://www.flock.com/photobucket/start/
FF Extension: (Skype Click to Call) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found
FF HKLM-x32\...\Firefox\Extensions: [{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}] - C:\Program Files (x86)\PremierOpinion\firefox
FF Extension: (PremierOpinion) - C:\Program Files (x86)\PremierOpinion\firefox [2017-05-10] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-10] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-10] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-08-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-08-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-08-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2012-06-22] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.4.53 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-06-22] (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-29] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2012-03-22] (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxps://signin.ebay.com.au/ws/eBayISAPI.dll?SignIn&UsingSSL=1&pUserId=&co_partnerId=2&siteid=15&ru=http%3A%2F%2Fk2b-bulk.ebay.com.au%2Fws%2FeBayISAPI.dll%3FListingConsole%26%26guest%3D1%26currentPage%3DLCActive%26guest%3D1&pageType=5468","hxxps://www.auctiva.com/signin.aspx","hxxps://www.facebook.com/","hxxp://www.symbols-n-emoticons.com/p/facebook-emoticons-list.html","hxxps://www.biblegateway.com/","hxxps://signon.telstra.com.au/login?goto=http%3A%2F%2Femail.telstra.com%3A443%2Fwebmail%2Fbin%2Fauth","hxxps://login.microsoftonline.com/common/oauth2/authorize?client_id=4345a7b9-9a63-4910-a426-35363201d503&response_mode=form_post&response_type=code+id_token&scope=openid+profile&state=OpenIdConnect.AuthenticationProperties%3dfKBDx9fO04YsbD2NrT1ePa7RGdH3EtgoWE7YfheIEyO3zzyOU7oeARaPBk-bZrdFY42I_2CxHkL5f4iB0Q8sdLaNz03nr-v35IjeoXcxermTg48J-2D-ZBRzF9O3br5Zu3Trtp6nseriLx50XrqEojSs6gVJom2aZeStiEO3vYAVH695dDHqqaCZSBi6VVTtwTYV6S5YOfUI7o8gHAHFzXcQAE4QodQw371p6qR7p6ybKBSWZUOg32yFWPiGIZ9Iv6ZKfDp06-pn3Smlq5CTh4nOAtK9CdgkYPgsZBDbRcY&nonce=636283272081392523.Yzk1MTFmNzgtNDUzOS00NjI0LWJkYTktMGNiZGJjYWJlMzk1MTcyNDkxZWEtMDBiNi00MTgzLTgwZTktOTZjNzA3MzEyOWFm&redirect_uri=https%3a%2f%2fwww.office.com%2flanding&ui_locales=en-AU&mkt=en-AU&client-request-id=56d6fe0f-cd40-4096-87c0-4b11aedfc291&msafed=0"
CHR NewTab: Default -> Not-active:"chrome-extension://hookklgbmgffgeefbnhhnbmcobhcgced/newtab/newtab.html"
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM ... PARAM__&q={searchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSuggestURL: Default -> hxxps://search.avira.net/suggestions?q={searchTerms}&li=ff&hl=en
CHR Profile: C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default [2017-05-11]
CHR Extension: (Avira Safe Shopping) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2017-04-20]
CHR Extension: (The Dusty Arcade Ad) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph [2017-05-09]
CHR Extension: (History Button) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\fofpnhmbgmmeaialapfddhbhfongoinh [2014-01-22]
CHR Extension: (Weather Forecast Alerts) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\hookklgbmgffgeefbnhhnbmcobhcgced [2017-03-11]
CHR Extension: (Avira SafeSearch Plus) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp [2017-04-20]
CHR Extension: (eBay for Chrome) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\khhckppjhonfmcpegdjdibmngahahhck [2016-11-23]
CHR Extension: (PremierOpinion) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle [2017-05-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-11]
CHR Extension: (Chrome Media Router) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-05]
CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkndcbhcgphcfkkddanakjiepeknbgle] - C:\Program Files (x86)\PremierOpinion\pmcm.crx [2017-05-10]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2014-07-23] ()
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2014-07-23] () [File not signed]
R2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [662592 2014-08-03] (SEIKO EPSON CORPORATION)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [341984 2016-12-06] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [207648 2015-08-07] (Intel Corporation)
S3 KtmRm; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 KtmRm; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 PremierOpinion; C:\Program Files (x86)\PremierOpinion\pmservice.exe [204736 2017-03-14] (VoiceFive, Inc.) [File not signed] <==== ATTENTION
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-24] (StarWind Software) [File not signed]
R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [996736 2017-04-18] (McAfee, Inc.)
R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16160 2017-04-18] (McAfee, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [20520 2010-03-01] ()
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-09] ()
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [471496 2015-05-19] (Intel Corporation)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-03-22] ()
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31144 2015-07-29] (Intel Corporation)
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-05-11] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-05-11] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-05-11] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251832 2017-05-11] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82720 2017-05-11] (Malwarebytes)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [178976 2015-07-28] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [503352 2010-12-29] () [File not signed]
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13920 2017-05-10] ()
S3 zgwhsdiag; C:\Windows\System32\DRIVERS\zgwhsdiag.sys [150656 2009-02-19] (ZTE Incorporated)
S3 zgwhsmdm; C:\Windows\System32\DRIVERS\zgwhsmdm.sys [150656 2009-02-19] (ZTE Incorporated)
U3 a4be0mt1; C:\Windows\System32\Drivers\a4be0mt1.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
S3 DIRECTIO; \??\UNC\buildlab\Buildtools\BurnInTest_64\DirectIo.sys [X]
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
S3 massfilter_hs; \??\C:\Windows\system32\drivers\massfilter_hs.sys [X]
S3 zghsdiag; system32\DRIVERS\zghsdiag.sys [X]
S3 zghsmdm; system32\DRIVERS\zghsmdm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-11 12:33 - 2017-05-11 12:34 - 00047111 _____ C:\Users\Darryl\Downloads\Addition.txt
2017-05-11 12:32 - 2017-05-11 13:46 - 00027596 _____ C:\Users\Darryl\Downloads\FRST.txt
2017-05-11 12:31 - 2017-05-11 13:46 - 00000000 ____D C:\FRST
2017-05-11 12:30 - 2017-05-11 12:31 - 02429440 _____ (Farbar) C:\Users\Darryl\Downloads\FRST64.exe
2017-05-11 12:30 - 2017-05-11 12:30 - 01769984 _____ (Farbar) C:\Users\Darryl\Downloads\FRST.exe
2017-05-11 00:29 - 2017-05-11 09:24 - 00082720 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-05-11 00:29 - 2017-05-11 09:07 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-05-11 00:29 - 2017-05-11 09:07 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-05-11 00:29 - 2017-05-11 00:29 - 00186304 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-05-11 00:28 - 2017-05-11 09:07 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-05-11 00:28 - 2017-05-11 00:28 - 00001827 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-05-11 00:28 - 2017-05-11 00:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-05-11 00:28 - 2017-05-11 00:28 - 00000000 ____D C:\Program Files\Malwarebytes
2017-05-11 00:28 - 2017-03-22 11:02 - 00077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-05-11 00:26 - 2017-05-11 00:27 - 60107896 _____ (Malwarebytes ) C:\Users\Darryl\Downloads\mb3-setup-consumer-3.0.6.1469-10103.exe
2017-05-10 20:57 - 2017-05-10 20:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion
2017-05-10 08:54 - 2017-04-28 11:14 - 05547240 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-05-10 08:54 - 2017-04-28 11:14 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-05-10 08:54 - 2017-04-28 11:14 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-05-10 08:54 - 2017-04-28 11:14 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-05-10 08:54 - 2017-04-28 11:14 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-05-10 08:54 - 2017-04-28 11:11 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:36 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-05-10 08:54 - 2017-04-28 10:36 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-05-10 08:54 - 2017-04-28 10:34 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:19 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-05-10 08:54 - 2017-04-28 10:19 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-05-10 08:54 - 2017-04-28 10:19 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-05-10 08:54 - 2017-04-28 10:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-05-10 08:54 - 2017-04-28 10:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-05-10 08:54 - 2017-04-28 10:14 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-05-10 08:54 - 2017-04-28 10:12 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-05-10 08:54 - 2017-04-28 10:11 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-05-10 08:54 - 2017-04-28 10:11 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-05-10 08:54 - 2017-04-28 10:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-05-10 08:54 - 2017-04-28 10:10 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-05-10 08:54 - 2017-04-28 10:10 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-05-10 08:54 - 2017-04-28 10:08 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-05-10 08:54 - 2017-04-28 10:08 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-05-10 08:54 - 2017-04-28 10:08 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-05-10 08:54 - 2017-04-28 10:08 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-05-10 08:54 - 2017-04-28 10:07 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-05-10 08:54 - 2017-04-28 10:07 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:07 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:07 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-05-10 08:54 - 2017-04-27 00:59 - 03220992 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-05-10 08:54 - 2017-04-22 01:34 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-05-10 08:54 - 2017-04-22 01:15 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-05-10 08:54 - 2017-04-18 01:37 - 02065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-05-10 08:54 - 2017-04-18 01:37 - 00876544 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2017-05-10 08:54 - 2017-04-18 01:37 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-05-10 08:54 - 2017-04-18 01:37 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2017-05-10 08:54 - 2017-04-18 01:37 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2017-05-10 08:54 - 2017-04-18 01:12 - 01417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-05-10 08:54 - 2017-04-18 01:12 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-05-10 08:54 - 2017-04-18 01:12 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2017-05-10 08:54 - 2017-04-18 00:54 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2017-05-10 08:54 - 2017-04-13 01:32 - 01483776 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2017-05-10 08:54 - 2017-04-13 01:32 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2017-05-10 08:54 - 2017-04-13 01:32 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2017-05-10 08:54 - 2017-04-13 01:32 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2017-05-10 08:54 - 2017-04-13 01:26 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2017-05-10 08:54 - 2017-04-13 01:25 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2017-05-10 08:54 - 2017-04-13 01:25 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2017-05-10 08:54 - 2017-04-13 01:25 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2017-05-10 08:54 - 2017-04-08 01:34 - 00986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-05-10 08:54 - 2017-04-08 01:34 - 00265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-05-10 08:54 - 2017-04-08 01:30 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-05-10 08:54 - 2017-04-08 01:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-05-10 08:54 - 2017-04-08 01:22 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-05-10 08:54 - 2017-04-06 00:55 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-05-10 08:54 - 2017-04-06 00:55 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-05-10 08:54 - 2017-04-06 00:55 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-05-10 08:54 - 2017-04-05 01:34 - 01895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-05-10 08:54 - 2017-04-05 01:34 - 00377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-05-10 08:54 - 2017-04-05 01:34 - 00287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-05-10 08:54 - 2017-04-05 00:53 - 00496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-05-10 08:54 - 2017-04-05 00:53 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-05-10 08:54 - 2017-03-11 02:32 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2017-05-10 08:54 - 2017-03-11 02:32 - 00300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2017-05-10 08:54 - 2017-03-11 02:20 - 01508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2017-05-10 08:54 - 2017-03-11 02:20 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2017-05-10 08:54 - 2017-03-11 01:57 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe
2017-05-10 08:54 - 2017-03-11 01:55 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2017-05-10 08:54 - 2017-03-11 01:55 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys
2017-05-10 08:54 - 2017-03-10 02:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-05-10 08:54 - 2017-03-10 02:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-05-10 08:37 - 2017-05-10 16:55 - 00000000 ____D C:\Users\Darryl\Downloads\opera autoupdate
2017-05-10 08:33 - 2017-05-10 08:33 - 00000000 ____D C:\ProgramData\dbg
2017-05-10 08:31 - 2017-05-10 21:46 - 00000000 ____D C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc
2017-05-10 08:31 - 2017-05-10 16:50 - 00013920 _____ C:\Windows\system32\Drivers\SWDUMon.sys
2017-05-09 23:51 - 2017-05-09 23:51 - 00001645 _____ C:\Users\Darryl\Desktop\Carinity.jpg - Shortcut.lnk
2017-05-09 18:02 - 2017-05-11 09:13 - 00000000 ____D C:\Program Files (x86)\PremierOpinion
2017-05-09 18:02 - 2017-05-09 18:02 - 00004286 _____ C:\Windows\System32\Tasks\Opera scheduled suite Autoupdate 1494316921
2017-05-09 18:02 - 2017-05-09 18:02 - 00004066 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1494316920
2017-05-09 18:02 - 2017-05-09 18:02 - 00000000 ____D C:\Users\Darryl\AppData\Roaming\Opera Software
2017-05-09 18:02 - 2017-05-09 18:02 - 00000000 ____D C:\Users\Darryl\AppData\Local\Opera Software
2017-05-09 18:01 - 2017-05-09 18:02 - 00000000 ____D C:\ProgramData\COMODO
2017-05-09 18:01 - 2017-05-09 18:01 - 00000000 ____D C:\Program Files\COMODO
2017-05-09 17:58 - 2017-05-09 17:58 - 00777411 _____ C:\Users\Darryl\Downloads\_FiveNightsAtFreddys_download.zip
2017-05-09 17:57 - 2017-05-09 17:57 - 01242128 _____ (Bekubicamo ) C:\Users\Darryl\Downloads\FiveNightsAtFreddys_download.exe
2017-05-08 19:29 - 2017-05-08 19:53 - 00001681 _____ C:\Users\Darryl\Desktop\it's a trap.jpeg - Shortcut.lnk
2017-05-08 19:28 - 2017-05-08 19:28 - 00040506 _____ C:\Users\Darryl\Documents\it's a trap.jpeg
2017-05-08 19:27 - 2017-05-08 19:27 - 00064771 _____ C:\Users\Darryl\Documents\e1509117d4b42527547953f2c7c4c966_admiral-ackbar-its-a-trap-meme-admiral-ackbar-its-a-trap-meme_853-480.jpeg
2017-05-08 16:12 - 2017-05-11 00:07 - 00000000 ____D C:\Users\Darryl\AppData\Local\tkdata
2017-05-08 16:11 - 2017-05-10 08:36 - 00001165 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\True Key.lnk
2017-05-08 16:11 - 2017-05-10 08:36 - 00001151 _____ C:\Users\Public\Desktop\True Key.lnk
2017-05-08 16:11 - 2017-05-08 16:11 - 00000000 ____D C:\ProgramData\TrueKey
2017-05-08 16:11 - 2017-05-08 16:11 - 00000000 ____D C:\Program Files\Intel Security
2017-05-08 16:09 - 2017-05-10 16:25 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-05-08 16:09 - 2017-05-08 16:09 - 00003344 _____ C:\Windows\System32\Tasks\McAfee Remediation (Prepare)
2017-05-08 16:09 - 2017-05-08 16:09 - 00000000 ____D C:\Program Files\Common Files\McAfee
2017-05-08 15:55 - 2017-05-10 20:02 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-05-08 15:55 - 2017-05-10 16:24 - 00000000 ____D C:\Program Files\TrueKey
2017-05-08 12:11 - 2017-05-08 12:11 - 00022357 _____ C:\Users\Darryl\Downloads\Receipt-3538012.pdf
2017-05-08 11:39 - 2017-05-08 11:39 - 00000000 ____D C:\Users\Darryl\AppData\Local\{F773F2D2-30C3-4008-8D2E-04B91644EC51}
2017-05-07 16:07 - 2017-05-08 19:55 - 00001794 _____ C:\Users\Darryl\Desktop\tasmaniabluecrossdemijohn.jpg - Shortcut.lnk
2017-05-06 19:00 - 2017-05-08 19:55 - 00001704 _____ C:\Users\Darryl\Desktop\anniversarydate.jpg - Shortcut.lnk
2017-05-05 09:51 - 2017-05-05 09:51 - 00011430 _____ C:\Users\Darryl\Downloads\CallsYetToBeBilled_Service_0412712186 (5).csv
2017-05-03 10:56 - 2017-05-03 10:56 - 00209810 _____ C:\Users\Darryl\Downloads\Hodgkinson Goldfields Geo Map 2.pdf
2017-05-03 10:55 - 2017-05-03 10:55 - 00153835 _____ C:\Users\Darryl\Downloads\Hodgkinson Goldfield Geo Map 1.pdf
2017-04-27 11:00 - 2017-05-05 10:58 - 00001650 _____ C:\Users\Darryl\Desktop\universal.jpg - Shortcut.lnk
2017-04-25 17:03 - 2017-05-05 10:58 - 00002065 _____ C:\Users\Darryl\Desktop\daryljudy.JPG - Shortcut.lnk
2017-04-22 17:08 - 2017-05-05 10:58 - 00001765 _____ C:\Users\Darryl\Desktop\cyclonetrackmapoverlay.jpeg - Shortcut.lnk
2017-04-22 13:17 - 2017-05-05 10:58 - 00001610 _____ C:\Users\Darryl\Desktop\2zge8.jpg - Shortcut.lnk
2017-04-21 21:07 - 2017-04-21 21:07 - 00000000 ____D C:\Users\Darryl\AppData\Local\{C00089DC-4914-4633-AB99-99B47714DC39}
2017-04-21 08:44 - 2017-04-21 08:44 - 00002062 _____ C:\Users\Darryl\Desktop\Free Antivirus Profile Quick scan.LNK
2017-04-21 08:37 - 2017-04-21 08:37 - 00000000 ____D C:\Users\Darryl\AppData\Local\CEF
2017-04-20 22:33 - 2017-04-20 22:33 - 00000000 ____D C:\Users\Darryl\AppData\Local\AviraSpeedup
2017-04-20 22:32 - 2017-04-20 22:32 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf
2017-04-20 22:16 - 2017-04-21 11:27 - 00000000 ____D C:\Users\Darryl\AppData\Local\Avira
2017-04-20 22:16 - 2017-04-20 22:16 - 00000000 ____D C:\Windows\System32\Tasks\Avira
2017-04-20 22:10 - 2017-04-20 22:10 - 04737440 _____ (Avira Operations GmbH & Co. KG) C:\Users\Darryl\Downloads\avira_en_fass0_58f8a4b11987a__ws.exe
2017-04-16 09:19 - 2017-04-16 09:19 - 00000000 ____D C:\Users\Darryl\AppData\Local\{B611D048-5CF0-4624-9E92-C5915CCB5516}
2017-04-15 23:26 - 2017-04-16 10:10 - 00001704 _____ C:\Users\Darryl\Desktop\Rosalie Frater2.jpg - Shortcut.lnk
2017-04-15 23:00 - 2017-04-15 23:00 - 00153930 _____ C:\Users\Darryl\Downloads\Harriet Cook GURR.pdf
2017-04-15 22:47 - 2017-04-16 10:10 - 00001969 _____ C:\Users\Darryl\Desktop\Rosalie Frater 5th from the right second row.jpg - Shortcut.lnk
2017-04-12 07:08 - 2017-03-23 01:32 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-04-12 07:08 - 2017-03-23 01:32 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-04-12 07:08 - 2017-03-23 01:32 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-04-12 07:08 - 2017-03-23 01:30 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-04-12 07:08 - 2017-03-23 01:24 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-04-12 07:08 - 2017-03-23 01:17 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-04-12 07:08 - 2017-03-23 01:15 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-04-12 07:08 - 2017-03-23 01:15 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-04-12 07:08 - 2017-03-23 01:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-04-12 07:08 - 2017-03-23 01:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-04-12 07:08 - 2017-03-23 01:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-04-12 07:08 - 2017-03-23 01:15 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-04-12 07:08 - 2017-03-23 01:05 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-04-12 07:08 - 2017-03-23 01:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-04-12 07:08 - 2017-03-23 01:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-04-12 07:08 - 2017-03-23 01:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-04-12 07:08 - 2017-03-11 02:35 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-04-12 07:08 - 2017-03-11 02:31 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-04-12 07:08 - 2017-03-11 02:31 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-04-12 07:08 - 2017-03-11 02:31 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-04-12 07:08 - 2017-03-11 02:31 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-04-12 07:08 - 2017-03-11 02:27 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-04-12 07:08 - 2017-03-11 02:20 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-04-12 07:08 - 2017-03-11 02:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-04-12 07:08 - 2017-03-11 02:19 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-04-12 07:08 - 2017-03-11 01:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-04-12 07:08 - 2017-03-08 02:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2017-04-12 07:08 - 2017-03-08 02:17 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-04-12 07:08 - 2017-03-08 00:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-04-12 07:08 - 2017-03-04 11:27 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-04-12 07:08 - 2017-03-04 11:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll
2017-04-12 07:08 - 2017-03-04 11:14 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-04-12 07:08 - 2017-03-04 11:14 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2017-04-12 07:08 - 2017-02-15 02:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-04-12 07:08 - 2017-02-15 02:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-04-12 07:08 - 2017-02-10 02:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2017-04-12 07:08 - 2017-02-10 02:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2017-04-12 07:08 - 2017-02-10 02:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-12 07:08 - 2016-03-24 08:40 - 03181568 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-04-12 07:08 - 2016-03-24 08:40 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-11 09:24 - 2014-05-20 12:12 - 24368414 _____ C:\Windows\ntbtlog.txt
2017-05-11 09:19 - 2009-07-14 14:45 - 00023376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-05-11 09:19 - 2009-07-14 14:45 - 00023376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-05-11 09:16 - 2010-07-23 21:04 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-11 09:08 - 2016-05-26 10:35 - 00000000 __SHD C:\Users\Darryl\IntelGraphicsProfiles
2017-05-11 09:06 - 2009-07-14 15:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-11 00:48 - 2014-05-21 09:57 - 00000000 ____D C:\Users\Darryl\AppData\Local\CrashDumps
2017-05-11 00:28 - 2011-08-30 12:58 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-05-10 22:36 - 2011-01-19 12:26 - 00003930 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F59818A2-D362-475B-81B4-C930E710F76C}
2017-05-10 21:52 - 2010-08-04 08:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2017-05-10 21:52 - 2010-08-04 08:31 - 00000000 ____D C:\ProgramData\WinZip
2017-05-10 21:48 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\inf
2017-05-10 20:02 - 2012-07-25 17:20 - 00803320 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-05-10 20:02 - 2012-07-25 17:20 - 00144888 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-05-10 20:02 - 2012-07-25 17:20 - 00004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-05-10 20:02 - 2010-11-21 14:34 - 00000000 ____D C:\Windows\system32\Macromed
2017-05-10 20:02 - 2010-07-23 15:23 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-05-10 16:32 - 2009-07-14 15:13 - 00783288 _____ C:\Windows\system32\PerfStringBackup.INI
2017-05-10 16:25 - 2009-07-14 14:45 - 00321720 _____ C:\Windows\system32\FNTCACHE.DAT
2017-05-10 16:06 - 2010-09-11 21:02 - 00767154 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-05-10 16:04 - 2013-07-18 03:23 - 00000000 ____D C:\Windows\system32\MRT
2017-05-10 16:02 - 2010-07-23 16:13 - 156335152 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-05-10 08:37 - 2011-06-17 19:56 - 00000000 ____D C:\ProgramData\McAfee
2017-05-10 08:36 - 2010-07-21 15:31 - 00000000 ____D C:\Program Files\Common Files\Intel
2017-05-10 08:33 - 2009-07-14 15:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2017-05-09 17:59 - 2015-03-11 16:02 - 00000000 ____D C:\Users\Darryl\AppData\Local\Downloaded Installers
2017-05-08 16:12 - 2014-06-10 23:28 - 00000000 ____D C:\ProgramData\Intel
2017-05-08 16:10 - 2016-05-24 13:57 - 00000000 ____D C:\ProgramData\Package Cache
2017-05-08 16:09 - 2015-07-04 18:31 - 00000000 ____D C:\Program Files\Common Files\AV
2017-05-08 15:56 - 2010-07-23 16:02 - 00000000 ____D C:\Users\Darryl\AppData\Local\Adobe
2017-05-07 10:13 - 2010-07-23 19:02 - 01398834 _____ C:\aqueduct.txt
2017-05-07 10:13 - 2010-07-23 19:01 - 00000082 _____ C:\Windows\MPLAYER.INI
2017-05-07 10:13 - 2010-07-23 19:00 - 00000000 ____D C:\FTW
2017-05-07 10:13 - 2009-07-14 12:34 - 00000434 _____ C:\Windows\win.ini
2017-05-05 19:39 - 2015-06-27 18:04 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-04-28 16:08 - 2010-07-23 21:01 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-28 16:08 - 2010-07-23 21:01 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-20 22:39 - 2015-10-23 21:39 - 00000000 ____D C:\Users\Darryl\AppData\Local\AvgSetupLog
2017-04-20 22:39 - 2011-01-09 14:36 - 00000000 ____D C:\Users\Darryl\AppData\Roaming\skypePM
2017-04-20 22:39 - 2011-01-09 14:33 - 00000000 ____D C:\Users\Darryl\AppData\Roaming\Skype
2017-04-20 22:39 - 2010-12-12 20:34 - 00000000 ____D C:\Program Files (x86)\TranslatorBar_3.3
2017-04-20 22:39 - 2010-10-01 21:16 - 00000000 ____D C:\Users\Darryl\AppData\LocalLow\Temp
2017-04-20 22:39 - 2010-10-01 21:16 - 00000000 ____D C:\Program Files (x86)\myBabylon_English
2017-04-20 22:39 - 2010-07-23 18:25 - 00000000 ___DC C:\Users\Darryl\AppData\Local\MigWiz
2017-04-20 22:39 - 2010-07-23 18:04 - 00000000 ____D C:\Users\Darryl\AppData\Roaming\TeamViewer
2017-04-20 22:39 - 2010-07-22 08:44 - 00000000 ____D C:\Windows\Panther
2017-04-20 22:16 - 2013-06-08 13:54 - 00073928 _____ C:\Users\Darryl\AppData\Local\GDIPFONTCACHEV1.DAT
2017-04-17 10:04 - 2009-07-14 15:08 - 00032612 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-04-16 10:20 - 2016-12-04 16:39 - 00000000 ____D C:\Users\Darryl\Desktop\DARIA
2017-04-13 10:26 - 2014-11-13 22:45 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-04-12 16:25 - 2012-05-12 21:15 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-04-12 16:25 - 2012-05-12 21:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-04-12 16:07 - 2012-05-12 21:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight

==================== Files in the root of some directories =======

2010-07-23 23:21 - 2010-07-23 23:21 - 0000707 _____ () C:\Program Files (x86)\Canasta From Special K.LNK
2016-02-10 10:57 - 2016-02-10 10:57 - 0003072 _____ () C:\Program Files (x86)\http_canasta-from-special-k.software.informer.com_0.localstorage
2016-02-10 10:57 - 2016-02-10 10:57 - 0000000 _____ () C:\Program Files (x86)\http_canasta-from-special-k.software.informer.com_0.localstorage-journal
2015-02-25 16:42 - 2015-02-25 17:02 - 0000115 _____ () C:\Users\Darryl\AppData\Roaming\LogFile.txt
2016-04-12 23:06 - 2016-04-12 23:06 - 0023040 _____ () C:\Users\Darryl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-02-28 18:07 - 2016-02-28 18:07 - 0003389 _____ () C:\Users\Darryl\AppData\Local\recently-used.xbel
2015-08-03 20:30 - 2015-08-03 20:30 - 0267353 _____ () C:\ProgramData\1438597611.bdinstall.bin
2011-01-09 14:36 - 2011-03-05 07:50 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2012-12-24 16:16 - 2012-12-24 16:16 - 0000120 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-07-14 11:30

==================== End of FRST.txt
serialbusdriver
Active Member
 
Posts: 2
Joined: May 10th, 2017, 11:34 pm
Advertisement
Register to Remove

Re: Adware removal help please

Unread postby serialbusdriver » May 11th, 2017, 3:15 am

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 5/11/17
Scan Time: 11:57 AM
Logfile:
Administrator: Yes

-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.103
Update Package Version: 1.0.1913
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: DARYL-PC\Darryl

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 356763
Time Elapsed: 15 min, 17 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 1
Adware.Graftor, C:\PROGRAM FILES (X86)\PREMIEROPINION\PMSERVICE.EXE, No Action By User, [8451], [299817],1.0.1913

Module: 1
Adware.Graftor, C:\PROGRAM FILES (X86)\PREMIEROPINION\PMSERVICE.EXE, No Action By User, [8451], [299817],1.0.1913

Registry Key: 14
Adware.Graftor, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PremierOpinion, No Action By User, [8451], [299817],1.0.1913
Adware.PremierOpinion, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{eeb86aef-4a5d-4b75-9d74-f16d438fc286}, No Action By User, [4726], [164279],1.0.1913
PUP.Optional.GeekBuddy, HKLM\SOFTWARE\WOW6432NODE\GeekBuddyRSP, No Action By User, [1911], [342277],1.0.1913
PUP.Optional.SpeedyPC, HKLM\SOFTWARE\WOW6432NODE\SpeedyPC Software, No Action By User, [856], [396735],1.0.1913
PUP.Optional.RelevantKnowledge, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\mkndcbhcgphcfkkddanakjiepeknbgle, No Action By User, [1176], [242294],1.0.1913
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\SlimWare Utilities, Inc.\DriverApp, No Action By User, [946], [341522],1.0.1913
PUP.Optional.Plumbytes, HKLM\SOFTWARE\MICROSOFT\TRACING\Plumbytes_RASAPI32, No Action By User, [9045], [396951],1.0.1913
PUP.Optional.Plumbytes, HKLM\SOFTWARE\MICROSOFT\TRACING\Plumbytes_RASMANCS, No Action By User, [9045], [396951],1.0.1913
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\SLIMWARE UTILITIES INC\DriverUpdate, No Action By User, [946], [338931],1.0.1913
PUP.Optional.GeekBuddy, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\GeekBuddyRSP, No Action By User, [1911], [362758],1.0.1913
PUP.Optional.InstallCore, HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\SOFTWARE\csastats, No Action By User, [3], [260986],1.0.1913
PUP.Optional.SpeedyPC, HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\SOFTWARE\SpeedyPC Software, No Action By User, [856], [396736],1.0.1913
PUP.Optional.GeekBuddy, HKLM\SOFTWARE\GeekBuddyRSP, No Action By User, [1911], [342277],1.0.1913
PUP.Optional.ProductSetup, HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\SOFTWARE\PRODUCTSETUP, No Action By User, [14749], [242047],1.0.1913

Registry Value: 5
PUP.Optional.GeekBuddy, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|TVNCONTROL, No Action By User, [1911], [342276],1.0.1913
PUP.Optional.PremierOpinion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{7EB21B9B-C41E-4785-ACC1-67470C42F458}, No Action By User, [12233], [257568],1.0.1913
PUP.Optional.PremierOpinion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{01A04D09-98D9-4E88-805B-D00911C095F6}, No Action By User, [12233], [257568],1.0.1913
PUP.Optional.OpinionSquare, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}, No Action By User, [12205], [241422],1.0.1913
PUP.Optional.ProductSetup, HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\SOFTWARE\PRODUCTSETUP|TB, No Action By User, [14749], [242047],1.0.1913

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 51
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing\window, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\events, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\traits, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\preferences, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\platform, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\page-mod, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\console, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\loader, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\addon, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\event, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\lang, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\dom, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\net, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\toolkit, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\defaults\preferences, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\data, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\lib, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\defaults, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\components, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\PROGRAM FILES (X86)\PremierOpinion, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\USERS\DARRYL\APPDATA\LOCAL\TEMP\PremierOpinion, No Action By User, [12233], [178971],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Images, No Action By User, [946], [341510],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs, No Action By User, [946], [341510],1.0.1913
PUP.Optional.DriverUpdate, C:\USERS\DARRYL\APPDATA\LOCAL\SlimWare Utilities Inc\DriverUpdate, No Action By User, [946], [341510],1.0.1913
Adware.PremierOpinion, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION, No Action By User, [4726], [171825],1.0.1913
PUP.Optional.RelevantKnowledge, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle\1.3.337.4_0, No Action By User, [1176], [179185],1.0.1913
PUP.Optional.RelevantKnowledge, C:\USERS\DARRYL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\MKNDCBHCGPHCFKKDDANAKJIEPEKNBGLE, No Action By User, [1176], [179185],1.0.1913
PUP.Optional.GeekBuddy, C:\Program Files\COMODO\GeekBuddy\imageformats, No Action By User, [1911], [342281],1.0.1913
PUP.Optional.GeekBuddy, C:\PROGRAM FILES\COMODO\GeekBuddy, No Action By User, [1911], [342281],1.0.1913
PUP.Optional.GamerCompete, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph\12.0.0.1_0\_metadata, No Action By User, [215], [396008],1.0.1913
PUP.Optional.GamerCompete, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph\12.0.0.1_0\images, No Action By User, [215], [396008],1.0.1913
PUP.Optional.GamerCompete, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph\12.0.0.1_0\js, No Action By User, [215], [396008],1.0.1913
PUP.Optional.GamerCompete, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph\12.0.0.1_0, No Action By User, [215], [396008],1.0.1913
PUP.Optional.GamerCompete, C:\USERS\DARRYL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\COCBLBIAEMIMHLPGKADMMMPNBDDJIGPH, No Action By User, [215], [396008],1.0.1913

File: 144
Adware.Graftor, C:\PROGRAM FILES (X86)\PREMIEROPINION\PMSERVICE.EXE, No Action By User, [8451], [299817],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\components\pmxg.dll, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\defaults\preferences\prefs.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\addon\runner.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\console\plain-text.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\console\traceback.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\content-proxy.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\content-worker.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\loader.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\thumbnail.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\worker.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core\heritage.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core\namespace.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core\promise.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\events\assembler.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\traits\core.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\api-utils.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\cortex.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\errors.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\events.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\light-traits.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\list.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\memory.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\observer-service.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\traits.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\window-utils.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\dom\events.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\event\core.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\event\target.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\byte-streams.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\data.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\file.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\text-streams.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\core.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\html.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\loader.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\locale.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\prefs.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\lang\functional.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\loader\cuddlefish.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\loader\sandbox.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\net\url.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\page-mod\match-pattern.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\platform\xpcom.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\preferences\service.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing\window\utils.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing\utils.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\environment.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\events.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\globals.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\runtime.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\unload.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\xul-app.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\common.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\events.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\helpers.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\namespace.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\observer.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tab-fennec.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tab-firefox.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tab.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tabs-firefox.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tabs.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\utils.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\worker.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\array.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\deprecate.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\list.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\object.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\registry.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\uuid.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window\browser.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window\namespace.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window\utils.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\dom.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\fennec.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\firefox.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\loader.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\observer.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\tabs-fennec.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\tabs-firefox.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\base64.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\page-mod.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\self.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\timers.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\url.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\addon-sdk\lib\toolkit\loader.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\data\content.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\lib\dompilot.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\lib\dputil.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\dpjs\lib\main.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\resources\chrome.manifest, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\bootstrap.js, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\harness-options.json, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\install.rdf, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\locales.json, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\firefox\pmnx.dll, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\asmcf.dat, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\chrome.manifest, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\install.rdf, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\nscf.dat, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmcm.crx, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmcm.txt, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmls.dll, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmls64.dll, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmoci.bin, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmph.dll, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\pmxf.dll, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.PremierOpinion, C:\Program Files (x86)\PremierOpinion\readme.txt, No Action By User, [12233], [178970],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Images\acer.png, No Action By User, [946], [341510],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2017-05-10 08-31-26 0.log, No Action By User, [946], [341510],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\Logs\2017-05-10 16-50-01 0.log, No Action By User, [946], [341510],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\ignores.dat, No Action By User, [946], [341510],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\rupdates.db, No Action By User, [946], [341510],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\settings.db, No Action By User, [946], [341510],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\supdates.db, No Action By User, [946], [341510],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\SWDUMon.cat, No Action By User, [946], [341510],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\SWDUMon.inf, No Action By User, [946], [341510],1.0.1913
PUP.Optional.DriverUpdate, C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc\DriverUpdate\SWDUMon.sys, No Action By User, [946], [341510],1.0.1913
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion\About PremierOpinion.lnk, No Action By User, [4726], [171825],1.0.1913
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion\Member of GRID - Goodware Repository Information Database.lnk, No Action By User, [4726], [171825],1.0.1913
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion\Privacy Policy and User License Agreement.lnk, No Action By User, [4726], [171825],1.0.1913
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion\Support.lnk, No Action By User, [4726], [171825],1.0.1913
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion\Uninstall Instructions.lnk, No Action By User, [4726], [171825],1.0.1913
PUP.Optional.RelevantKnowledge, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle\1.3.337.4_0\background.js, No Action By User, [1176], [179185],1.0.1913
PUP.Optional.RelevantKnowledge, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle\1.3.337.4_0\contentscript.js, No Action By User, [1176], [179185],1.0.1913
PUP.Optional.RelevantKnowledge, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle\1.3.337.4_0\icon128.png, No Action By User, [1176], [179185],1.0.1913
PUP.Optional.RelevantKnowledge, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle\1.3.337.4_0\icon48.png, No Action By User, [1176], [179185],1.0.1913
PUP.Optional.RelevantKnowledge, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle\1.3.337.4_0\manifest.json, No Action By User, [1176], [179185],1.0.1913
PUP.Optional.WinZipRegistryOptimizer, C:\USERS\DARRYL\APPDATA\LOCAL\TEMP\IN45E3D6A1\63F98BA4_STP\WZRO50.EXE, No Action By User, [689], [335595],1.0.1913
PUP.Optional.GeekBuddy, C:\USERS\DARRYL\APPDATA\LOCAL\TEMP\IN45E3D6A1\3FCF86C5_STP\LPS-GB-VT-X64.EXE, No Action By User, [1911], [342282],1.0.1913
PUP.Optional.InstallCore, C:\USERS\DARRYL\DOWNLOADS\FIVENIGHTSATFREDDYS_DOWNLOAD.EXE, No Action By User, [3], [372124],1.0.1913
PUP.Optional.GamerCompete, C:\USERS\DARRYL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\COCBLBIAEMIMHLPGKADMMMPNBDDJIGPH\12.0.0.1_0\MANIFEST.JSON, No Action By User, [215], [396008],1.0.1913
PUP.Optional.GamerCompete, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph\12.0.0.1_0\images\icon19.png, No Action By User, [215], [396008],1.0.1913
PUP.Optional.GamerCompete, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph\12.0.0.1_0\images\icon38.png, No Action By User, [215], [396008],1.0.1913
PUP.Optional.GamerCompete, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph\12.0.0.1_0\js\bg.js, No Action By User, [215], [396008],1.0.1913
PUP.Optional.GamerCompete, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph\12.0.0.1_0\js\contentscript.js, No Action By User, [215], [396008],1.0.1913
PUP.Optional.GamerCompete, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph\12.0.0.1_0\js\contentscript2.js, No Action By User, [215], [396008],1.0.1913
PUP.Optional.GamerCompete, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph\12.0.0.1_0\_metadata\computed_hashes.json, No Action By User, [215], [396008],1.0.1913
PUP.Optional.GamerCompete, C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph\12.0.0.1_0\_metadata\verified_contents.json, No Action By User, [215], [396008],1.0.1913

Physical Sector: 0
(No malicious items detected)


(end)
serialbusdriver
Active Member
 
Posts: 2
Joined: May 10th, 2017, 11:34 pm

Re: Adware removal help please

Unread postby Gary R » May 11th, 2017, 8:38 am

By opening your topic with 2 posts, you have inadvertently removed your topic from the "zero reply" topic that our helpers use when looking to see who needs help. Because of this, you are unlikely to get a reply to your request for help, as helpers will believe that you are already receiving help from another helper.

May I draw your attention to THIS topic, which you should have read, that states what we need you to post, so we can help you.
Specifically, this section will tell you what information we require before we can help you and why we need it.

If you still need help, please start a new thread an include your full FRST logs:
  • FRST.txt.
  • Addition.txt.
  • A description of the problems or symptoms you're experiencing.

This topic will now be closed.
User avatar
Gary R
Administrator
Administrator
 
Posts: 23255
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 71 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware