FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-07-2017
Ran by Sharon-Toshiba (administrator) on DESKTOP-RL5BCH2 (10-07-2017 22:12:41)
Running from C:\Users\Sharon-Toshiba\Downloads
Loaded Profiles: Sharon-Toshiba (Available Profiles: defaultuser0 & Sharon-Toshiba)
Platform: Windows 10 Home Version 1703 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\dataup\dataup.exe
() C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe
(Toshiba Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
() C:\Windows\System32\tprdpw64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoResident.exe
(Google, Inc) C:\Users\Sharon-Toshiba\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Users\Sharon-Toshiba\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDExtHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files (x86)\EMET 5.5\EMET_Service.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDAppHost.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDRuntimeHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDSurrogateHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Program Files (x86)\EMET 5.5\EMET_Agent.exe
(CyberLink) C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Users\Sharon-Toshiba\AppData\Local\fxhvmda\cshzvz\ct.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe
() C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [601944 2015-08-14] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [180016 2015-06-08] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\Toshiba\System Setting\TCrdMain_Win8.exe [559920 2015-10-09] (TOSHIBA Corporation)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2369240 2015-10-20] (Microsoft Corp.)
HKLM-x32\...\Run: [TSUScheduler] => C:\Program Files (x86)\TOSHIBA\Sync Utility\TosSyncScheduler.exe [923520 2011-08-18] (TOSHIBA Corporation)
HKLM-x32\...\Run: [cpx] => "C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\cpx\cpx.exe" -starup <==== ATTENTION
HKLM-x32\...\Run: [svcvmx] => C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe [884224 2017-04-21] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [Dashlane] => C:\Users\Sharon-Toshiba\AppData\Roaming\Dashlane\Dashlane.exe [505296 2017-06-29] (Dashlane, Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [DashlanePlugin] => C:\Users\Sharon-Toshiba\AppData\Roaming\Dashlane\DashlanePlugin.exe [552400 2017-06-29] (Dashlane, Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7963552 2017-06-12] (SUPERAntiSpyware)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [Google Update] => C:\Users\Sharon-Toshiba\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-28] (Google Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [Google Photos Backup] => C:\Users\Sharon-Toshiba\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe [3790936 2016-04-08] (Google, Inc)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23819304 2017-03-21] (Google)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [160824 2017-05-24] (BlueStack Systems, Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [MusicManager] => C:\Users\Sharon-Toshiba\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7643136 2016-02-01] (Google Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545048 2017-03-14] (Skype Technologies S.A.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [Spotify Web Helper] => C:\Users\Sharon-Toshiba\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1446000 2017-04-16] (Spotify Ltd)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4022328 2017-05-25] (Tonec Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [InterStat] => C:\Users\Sharon-Toshiba\AppData\Roaming\InterStat\interstat.exe <==== ATTENTION
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [GoogleChromeAutoLaunch_5E9B00E50FBF7F4CE97A3FE9A19AA703] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1197912 2017-06-22] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2017-07-10]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Sharon-Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Slack.lnk [2017-03-17]
ShortcutTarget: Slack.lnk -> C:\Users\Sharon-Toshiba\AppData\Local\slack\slack.exe (Slack Technologies)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 4.2.2.1
Tcpip\..\Interfaces\{314a7f20-9c10-454a-9f70-ba6bc0b00dfe}: [DhcpNameServer] 4.2.2.1
Tcpip\..\Interfaces\{4b3b1d40-78f9-45a8-a2d5-40e1d7cf8a39}: [DhcpNameServer] 8.8.8.8
Internet Explorer:
==================
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-12-10] (Internet Download Manager, Tonec Inc.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-07-04] (Oracle Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-07-04] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2016-12-10] (Internet Download Manager, Tonec Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-07-04] (Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-07-04] (Oracle Corporation)
Toolbar: HKLM-x32 - Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Sharon-Toshiba\AppData\Roaming\Dashlane\ie\KWIEBar.dll [2017-06-29] (Dashlane, Inc.)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)
Edge:
======
Edge Extension: (Office Online) -> 2016_MicrosoftOfficeOnline_8wekyb3d8bbwe => C:\Program Files\WindowsApps\Microsoft.OfficeOnline_1.5.1.0_neutral__8wekyb3d8bbwe [2017-05-15]
Edge Extension: (AdBlock) -> EdgeExtension_BetaFishAdBlock_c1wakc4j0nefm => C:\Program Files\WindowsApps\BetaFish.AdBlock_2.1.6.0_neutral__c1wakc4j0nefm [2017-05-26]
Edge Extension: (Pin It Button) -> EdgeExtension_PinterestPinItButton_xnkra2w3aecd0 => C:\Program Files\WindowsApps\Pinterest.PinItButton_1.39.5.0_neutral__xnkra2w3aecd0 [2017-04-15]
Edge Extension: (Save to Pocket) -> EdgeExtension_PocketSavetoPocket_v63j13wrfzj3t => C:\Program Files\WindowsApps\Pocket.SavetoPocket_2.0.38.0_neutral__v63j13wrfzj3t [2017-04-06]
Edge Extension: (LastPass: Free Password Manager) -> hdokiejnpimakedhajhdlcegeplioahd_LastPassLastPassFreePasswordManager_qq0fmhteeht3j => C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.1.45.0_neutral__qq0fmhteeht3j [2017-06-23]
Edge Extension: (Translator For Microsoft Edge) -> MicrosoftTranslate_MicrosoftTranslatorforMicrosoftEdge_8wekyb3d8bbwe => C:\Program Files\WindowsApps\Microsoft.TranslatorforMicrosoftEdge_0.91.16.0_neutral__8wekyb3d8bbwe [2017-04-15]
FireFox:
========
FF DefaultProfile: 2y9roifj.default
FF DefaultProfile: [email protected]
FF ProfilePath: C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\2y9roifj.default [2017-06-30]
FF Session Restore: Mozilla\Firefox\Profiles\2y9roifj.default -> is enabled.
FF Extension: (Emoji Keyboard) - C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\2y9roifj.default\Extensions\@emojikeyboard.xpi [2017-06-22]
FF Extension: (Enhancer for YouTube™) - C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\2y9roifj.default\Extensions\[email protected] [2017-03-25]
FF Extension: (Dashlane) - C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\2y9roifj.default\Extensions\[email protected] [2017-06-22]
FF Extension: (uBlock Origin) - C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\2y9roifj.default\Extensions\[email protected] [2017-06-22]
FF HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi
FF Extension: (No Name) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2017-05-16]
FF HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\Sharon-Toshiba\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Sharon-Toshiba\AppData\Roaming\IDM\idmmzcc5 [2017-06-07] [not signed]
FF HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-01-26]
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-07-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-07-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1229199.dll [2017-03-31] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-07-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-07-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 10\npnitromozilla.dll [2016-03-03] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: logmeonce.com/LogmeOnce -> C:\Program Files (x86)\LogmeOnce\nplogmeonce.dll [No File]
FF Plugin HKU\S-1-5-21-1391234854-2931249872-507013314-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1391234854-2931249872-507013314-1001: @talk.google.com/O1DPlugin -> C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1391234854-2931249872-507013314-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Sharon-Toshiba\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1391234854-2931249872-507013314-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Sharon-Toshiba\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon-Toshiba\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon-Toshiba\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.trovi.com/?gd=&ctid=CT3333527&octid=EB_ORIGINAL_CTID&ISID=IFD16E428-4DBC-4DF1-9DBE-1A0EC18048F4&SearchSource=55&CUI=&UM=8&UP=SP8D5DC7D9-9954-4ED7-87CD-9BCDE28EEBEC&D=060115&SSPV="
CHR DefaultSearchURL: Default -> chrome-extension://chphlpgkkbolifaimnlloiipkdnihall/onetab.html
CHR DefaultSearchKeyword: Default -> lp
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default [2017-07-10]
CHR Extension: (Google Translate) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2017-07-01]
CHR Extension: (Scribd Downloader Free) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aijgbekkajnbfllinekkbcibhnmgkcne [2017-03-10]
CHR Extension: (Google Drive) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-08]
CHR Extension: (MEGA) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2017-06-30]
CHR Extension: (YouTube) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-08]
CHR Extension: (Adblock Plus) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-03-21]
CHR Extension: (OneTab) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall [2017-03-08]
CHR Extension: (OneNote Online) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciniambnphakdoflgeamacamhfllbkmo [2017-03-08]
CHR Extension: (Spotify - Music for every moment) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2017-03-08]
CHR Extension: (Download Manager) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\daoidaoebhfcgccdpgjjcbdginkofmfe [2017-03-08]
CHR Extension: (MiniPlay) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfddfiedihbijfeacjamchlliogmjjnd [2017-03-09]
CHR Extension: (Session Buddy) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\edacconmaakjimmfgnblocblbcdcpbko [2017-07-05]
CHR Extension: (Google Calendar) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-03-08]
CHR Extension: (Wikiwand: Wikipedia Modernized) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\emffkefkbkpkgpdeeooapgaicgmcbolj [2017-03-08]
CHR Extension: (Google Play Music) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2017-07-10]
CHR Extension: (Dashlane Secure Password Manager) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2017-07-06]
CHR Extension: (Bookmark Manager) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2017-03-08]
CHR Extension: (TweetDeck by Twitter) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2017-03-08]
CHR Extension: (Google Photos) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcglmfcclpfgljeaiahehebeoaiicbko [2017-03-08]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2017-06-30]
CHR Extension: (ImageSpark - Ultimate Image Downloader) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hooaoionkjogngfhjjniefmenehnopag [2017-03-16]
CHR Extension: (Kindle Cloud Reader) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2017-03-08]
CHR Extension: (Google Play Music) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg [2017-03-08]
CHR Extension: (Zillow) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\iifccoboedmhjapdlpgkigibgnkmdjoh [2017-03-08]
CHR Extension: (Unpaywall) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplffkdpngmdjhlpjmppncnlhomiipha [2017-06-20]
CHR Extension: (Grammarly for Chrome) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2017-07-10]
CHR Extension: (Google Hangouts) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2017-05-26]
CHR Extension: (SoundCloud Downloader Free) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\libedajeiljdoodmokbppgapcfbignci [2017-03-08]
CHR Extension: (Google Maps) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2017-03-08]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2017-03-08]
CHR Extension: (Pocket) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2017-03-08]
CHR Extension: (OneDrive) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2017-03-08]
CHR Extension: (IDM Integration Module) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2017-06-30]
CHR Extension: (Save to Pocket) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2017-06-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
CHR Extension: (Hover Zoom) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl [2017-04-14]
CHR Extension: (Gmail) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-08]
CHR Extension: (Chrome Media Router) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-30]
CHR Extension: (Clearbit Connect - Supercharge Gmail™) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmnhcgfcafcnkbengdcanjablaabjplo [2017-03-08]
CHR Extension: (Enhancer for YouTube™) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ponfpcnoihfmfllpaingbgckeeldkhle [2017-07-10]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-05-25]
CHR HKU\S-1-5-21-1391234854-2931249872-507013314-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-05-25]
Opera:
=======
OPR Extension: (Google Translate) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2017-04-10]
OPR Extension: (Scribd Downloader Free) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\aijgbekkajnbfllinekkbcibhnmgkcne [2017-04-08]
OPR Extension: (Scribd Downloader Free) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\fbfifpkeojjlabelpjdgonmigjofgoim [2017-05-15]
OPR Extension: (Google Scholar Adder) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\fmjdgeladpkegliclimggpbbkamkhomb [2017-04-07]
OPR Extension: (Pocket (formerly Read It Later)) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\hedlhkdmdlcjhiblbmfggdiaeekblnoi [2017-04-07]
OPR Extension: (LastPass: Free Password Manager) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\hnjalnkldgigidggphhmacmimbdlafdo [2017-07-01]
OPR Extension: (Toolbox for Google Play Store™) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\ijoigpeoogooiilehgffdnidbminnfmc [2017-04-07]
OPR Extension: (Unpaywall) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\iplffkdpngmdjhlpjmppncnlhomiipha [2017-06-01]
OPR Extension: (Grammarly for Chrome) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2017-07-01]
OPR Extension: (GooglePlus Full-Size) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbgdfdhfmcibgdohjihdkeeedgdhlmke [2017-04-07]
OPR Extension: (Download Chrome Extension) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\kipjbhgniklcnglfaldilecjomjaddfi [2017-04-07]
OPR Extension: (Youtube Downloader) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\mdpelnicjpejiahnbkdohfjglhmaohcb [2017-06-07]
OPR Extension: (Google Dictionary (by Google)) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2017-04-07]
OPR Extension: (Huntr: Job Search Tracker ) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\mihdfbecejheednfigjpdacgeilhlmnf [2017-07-01]
OPR Extension: (IDM Integration Module) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2017-06-23]
OPR Extension: (Scribd Downloader Free) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\ofhehnfmgbgnkjaojifkmebjjgffjaeh [2017-06-23]
StartMenuInternet: (HKLM) OperaStable - C:\Program Files\Opera\Launcher.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
"drmkpro64" => service could not be unlocked. <==== ATTENTION
S2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-30] (SUPERAntiSpyware.com)
S2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173784 2015-10-20] (Microsoft Corp.)
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [387128 2017-05-24] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [369720 2017-05-24] (BlueStack Systems, Inc.)
S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Plus-Service.exe [406584 2017-05-24] (BlueStack Systems, Inc.)
R2 Dataup; C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\dataup\dataup.exe [77824 2017-01-05] () [File not signed] <==== ATTENTION
R3 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [19960 2015-05-27] ()
R2 EMET_Service; C:\Program Files (x86)\EMET 5.5\EMET_Service.exe [33960 2016-01-29] (Microsoft Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373752 2016-12-02] (Intel Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 NitroDriverReadSpool10; C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe [327320 2016-03-03] (Nitro PDF Software)
R2 NitroUpdateService; C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe [417944 2016-03-03] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [614664 2015-09-22] (CyberLink)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1570520 2016-02-02] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [837848 2016-02-02] (Secunia)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-05-04] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation)
R2 windowsmanagementservice; C:\Users\Sharon-Toshiba\AppData\Local\fxhvmda\cshzvz\ct.exe [689664 2017-05-30] () [File not signed] <==== ATTENTION
R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [152672 2017-05-24] (BlueStack Systems)
S3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [270904 2017-05-22] (Bluestack System Inc. )
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77376 2017-05-31] ()
R1 HssDRV6; C:\WINDOWS\system32\DRIVERS\hssdrv6.sys [44648 2015-09-18] (AnchorFree Inc.)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [230656 2016-12-12] (Intel Corporation)
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [186304 2017-03-22] (Malwarebytes)
S3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-03-22] (Malwarebytes)
S3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-03-22] (Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2017-07-10] (Malwarebytes)
S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [92088 2017-03-23] (Malwarebytes)
R1 MpKslaf4bbe7b; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D57D94D4-4E56-4DC1-9C00-E85D52ED7149}\MpKslaf4bbe7b.sys [44928 2017-07-10] (Microsoft Corporation)
R3 NETwNb64; C:\WINDOWS\System32\drivers\Netwbw02.sys [3485696 2017-03-18] (Intel Corporation)
R3 PSI; C:\WINDOWS\System32\DRIVERS\psi_mf_amd64.sys [18456 2016-02-02] (Secunia)
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [72792 2017-05-04] (Synaptics Incorporated)
R3 taphss6; C:\WINDOWS\System32\drivers\taphss6.sys [42088 2015-09-18] (Anchorfree Inc.)
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [52816 2016-08-03] (Toshiba Client Solutions Co., Ltd.)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [File not signed]
R3 VBAudioVMVAIOMME; C:\WINDOWS\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [41192 2017-03-17] (Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-10 22:12 - 2017-07-10 22:14 - 00035461 _____ C:\Users\Sharon-Toshiba\Downloads\FRST.txt
2017-07-10 22:11 - 2017-07-10 22:12 - 00000000 ____D C:\FRST
2017-07-10 20:26 - 2017-07-10 20:26 - 02437120 _____ (Farbar) C:\Users\Sharon-Toshiba\Downloads\FRST64.exe
2017-07-10 20:14 - 2017-07-10 20:16 - 02338496 _____ C:\Users\Sharon-Toshiba\Downloads\Hitlers Black Victims - Clarence Lusane.pdf
2017-07-10 17:35 - 2017-07-10 17:45 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-07-10 17:33 - 2017-07-10 17:46 - 00000000 ____D C:\WINDOWS\pss
2017-07-10 17:32 - 2017-07-10 17:32 - 00000000 ___HD C:\OneDriveTemp
2017-07-10 17:23 - 2017-07-10 17:24 - 04922400 _____ (AO Kaspersky Lab) C:\Users\Sharon-Toshiba\Desktop\tdsskiller.exe
2017-07-10 15:42 - 2017-07-10 15:42 - 00000000 _____ C:\WINDOWS\SysWOW64\last.dump
2017-07-10 15:40 - 2017-07-10 15:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enhanced Mitigation Experience Toolkit
2017-07-10 15:40 - 2017-07-10 15:40 - 00000000 ____D C:\Program Files (x86)\EMET 5.5
2017-07-10 15:39 - 2017-07-10 15:39 - 00001067 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-07-10 15:16 - 2017-07-10 15:16 - 00001142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
2017-07-10 15:16 - 2017-07-10 15:16 - 00000000 ____D C:\Program Files (x86)\Secunia
2017-07-05 00:02 - 2017-07-05 00:02 - 01192400 _____ C:\WINDOWS\is-MAP9U.exe
2017-07-05 00:02 - 2017-07-05 00:02 - 00022709 _____ C:\WINDOWS\is-MAP9U.msg
2017-07-05 00:02 - 2017-07-05 00:02 - 00000334 _____ C:\WINDOWS\is-MAP9U.lst
2017-07-04 23:56 - 2017-07-04 23:56 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2017-07-04 22:15 - 2017-07-10 17:27 - 00000000 ____D C:\Program Files\AVAST Software
2017-07-04 22:13 - 2017-07-04 22:13 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf
2017-07-04 22:11 - 2017-07-04 22:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2017-07-04 22:11 - 2017-07-04 22:11 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2017-07-04 22:07 - 2017-07-04 22:07 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2017-07-04 22:06 - 2017-07-04 22:06 - 00000000 ____D C:\Program Files\Java
2017-07-04 21:56 - 2017-07-04 21:56 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2017-07-04 21:55 - 2017-07-04 21:55 - 00000000 ____D C:\Program Files (x86)\Java
2017-07-04 20:00 - 2017-07-10 15:38 - 00000000 ____D C:\ProgramData\AVAST Software
2017-07-01 03:49 - 2017-07-01 03:50 - 00546716 _____ C:\WINDOWS\Minidump\070117-33906-01.dmp
2017-07-01 03:49 - 2017-07-01 03:49 - 960298518 _____ C:\WINDOWS\MEMORY.DMP
2017-07-01 03:49 - 2017-07-01 03:49 - 00000000 ____D C:\WINDOWS\Minidump
2017-07-01 03:32 - 2017-07-01 03:32 - 00000000 ____D C:\WINDOWS\SysWOW64\Adobe
2017-07-01 03:26 - 2017-07-01 03:26 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Sun
2017-07-01 03:25 - 2017-07-04 22:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-07-01 03:21 - 2017-07-01 03:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-07-01 03:16 - 2017-07-01 03:16 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-07-01 03:16 - 2017-07-01 03:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-07-01 03:15 - 2017-07-01 03:15 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2017-07-01 03:15 - 2017-07-01 03:15 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2017-07-01 03:15 - 2017-07-01 03:15 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-07-01 03:14 - 2017-07-01 03:14 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-07-01 03:11 - 2017-07-10 17:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-07-01 03:11 - 2017-07-04 21:31 - 00001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-07-01 03:11 - 2017-07-04 21:31 - 00001216 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-07-01 03:09 - 2017-07-04 20:08 - 00003966 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1498892944
2017-07-01 03:09 - 2017-07-04 20:08 - 00000981 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2017-07-01 00:18 - 2017-07-01 00:18 - 00128728 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\48230029.sys
2017-06-30 22:50 - 2017-06-30 22:50 - 00000085 _____ C:\WINDOWS\wininit.ini
2017-06-30 22:22 - 2017-06-30 22:22 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2017-06-30 22:21 - 2017-07-01 00:02 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-06-30 22:21 - 2017-06-30 22:50 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-06-30 22:17 - 2017-07-10 17:27 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-06-30 22:14 - 2017-07-10 15:02 - 00000000 ____D C:\Users\Sharon-Toshiba\Desktop\mbar
2017-06-30 21:58 - 2017-06-30 22:08 - 00000000 ____D C:\AdwCleaner
2017-06-30 20:19 - 2017-07-04 22:11 - 00001849 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2017-06-30 17:35 - 2017-06-30 17:35 - 00000000 ____D C:\SUPERDelete
2017-06-30 17:25 - 2017-07-04 19:59 - 00000662 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2017-06-30 17:12 - 2017-06-30 20:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\llssoft
2017-06-30 17:02 - 2017-06-30 18:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist
2017-06-30 17:02 - 2017-06-30 17:02 - 00003796 _____ C:\WINDOWS\System32\Tasks\AdapterUpdater
2017-06-30 17:02 - 2017-06-30 17:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\devnull
2017-06-30 17:02 - 2017-06-30 17:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\ggxfkhl
2017-06-30 17:02 - 2017-06-30 17:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\fxhvmda
2017-06-30 17:02 - 2017-06-30 17:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\AdvinstAnalytics
2017-06-30 17:01 - 2017-06-30 17:01 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\c
2017-06-30 17:00 - 2017-06-30 17:00 - 00000000 ____D C:\Program Files (x86)\GenlTybros
2017-06-30 16:54 - 2017-06-30 17:01 - 00000000 ____D C:\Program Files (x86)\AnonymizerGadget
2017-06-30 16:54 - 2017-06-30 16:55 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\AGData
2017-06-30 16:35 - 2017-06-30 16:35 - 00035352 _____ (Connectify) C:\WINDOWS\system32\Drivers\cnnctfy3.sys
2017-06-30 16:23 - 2017-06-30 16:59 - 00002317 ____R C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Оpеrа Вrоwsеr.lnk
2017-06-30 15:14 - 2017-06-30 15:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cygwin
2017-06-30 15:12 - 2017-06-30 15:12 - 00000000 ____D C:\Users\Sharon-Toshiba\Documents\http%3a%2f%2fmirrors.koehn.com%2fcygwin%2fcygwin-ftp%2f
2017-06-30 15:08 - 2017-06-30 15:08 - 00000000 ____D C:\Users\Sharon-Toshiba\Documents\http%3a%2f%2fcygwin.mirrors.hoobly.com%2f
2017-06-30 15:07 - 2017-06-30 15:09 - 00000000 ____D C:\Users\Sharon-Toshiba\Documents\http%3a%2f%2fcygwin.mirror.constant.com%2f
2017-06-30 15:05 - 2017-06-30 15:14 - 00000000 ____D C:\cygwin64
2017-06-30 14:54 - 2017-06-30 14:54 - 01010720 ___RS (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCHRT20.OCX
2017-06-30 14:54 - 2017-06-30 14:54 - 00224016 ___RS (Microsoft Corporation) C:\WINDOWS\SysWOW64\TABCTL32.OCX
2017-06-30 14:54 - 2017-06-30 14:54 - 00140488 ___RS (Microsoft Corporation) C:\WINDOWS\SysWOW64\COMDLG32.OCX
2017-06-30 14:53 - 2017-06-30 14:53 - 01070232 ___RS (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCOMCTL.OCX
2017-06-27 02:47 - 2017-06-27 02:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2017-06-27 01:23 - 2017-06-27 01:27 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2017-06-27 01:23 - 2017-05-24 02:58 - 00000000 ____D C:\ProgramData\BlueStacks
2017-06-23 21:07 - 2017-06-23 21:09 - 12678001 _____ C:\Users\Sharon-Toshiba\Downloads\drive-download-20170624T010752Z-001.zip
2017-06-23 20:02 - 2017-06-23 20:09 - 00733184 _____ C:\Users\Sharon-Toshiba\Downloads\Dario Fernandez-Morera-The Myth of the Andalusian Paradise_ Muslims, Christians, and Jews under Islamic Rule in Medieval Spain-Intercollegiate Studies Institute (2016).epub
2017-06-23 20:00 - 2017-06-23 20:00 - 00193318 _____ C:\Users\Sharon-Toshiba\Downloads\fernandez-morera.pdf
2017-06-18 09:49 - 2017-06-18 09:49 - 02785959 _____ C:\Users\Sharon-Toshiba\Downloads\[Massey,_Gerald]_The_natural_genesis_or,_Second_p(b-ok.org) (1).pdf
2017-06-13 23:36 - 2017-06-13 23:36 - 00000000 ____D C:\WINDOWS\PCHEALTH
2017-06-13 23:34 - 2017-06-03 06:15 - 01596600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-06-13 23:34 - 2017-06-03 06:15 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-06-13 23:34 - 2017-06-03 06:15 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-06-13 23:34 - 2017-06-03 06:14 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-06-13 23:34 - 2017-06-03 06:14 - 01024928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-06-13 23:34 - 2017-06-03 06:10 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-06-13 23:34 - 2017-06-03 06:09 - 08318880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-06-13 23:34 - 2017-06-03 06:09 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-06-13 23:34 - 2017-06-03 06:08 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-06-13 23:34 - 2017-06-03 06:07 - 00923048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-06-13 23:34 - 2017-06-03 06:07 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-06-13 23:34 - 2017-06-03 06:02 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-06-13 23:34 - 2017-06-03 06:01 - 05477096 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-06-13 23:34 - 2017-06-03 06:00 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-06-13 23:34 - 2017-06-03 06:00 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll
2017-06-13 23:34 - 2017-06-03 06:00 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2017-06-13 23:34 - 2017-06-03 05:59 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-06-13 23:34 - 2017-06-03 05:59 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-06-13 23:34 - 2017-06-03 05:59 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-06-13 23:34 - 2017-06-03 05:59 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2017-06-13 23:34 - 2017-06-03 05:58 - 21352696 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-06-13 23:34 - 2017-06-03 05:58 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-06-13 23:34 - 2017-06-03 05:58 - 00660384 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2017-06-13 23:34 - 2017-06-03 05:58 - 00254176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2017-06-13 23:34 - 2017-06-03 05:57 - 00371616 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-06-13 23:34 - 2017-06-03 05:55 - 02681760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-06-13 23:34 - 2017-06-03 05:36 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-06-13 23:34 - 2017-06-03 05:35 - 02259768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-06-13 23:34 - 2017-06-03 05:28 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-06-13 23:34 - 2017-06-03 05:26 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll
2017-06-13 23:34 - 2017-06-03 05:23 - 20373920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-06-13 23:34 - 2017-06-03 05:23 - 06760024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-06-13 23:34 - 2017-06-03 05:23 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2017-06-13 23:34 - 2017-06-03 05:20 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-06-13 23:34 - 2017-06-03 05:14 - 03673088 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-06-13 23:34 - 2017-06-03 05:14 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2017-06-13 23:34 - 2017-06-03 05:14 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll
2017-06-13 23:34 - 2017-06-03 05:14 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2017-06-13 23:34 - 2017-06-03 05:14 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-06-13 23:34 - 2017-06-03 05:12 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-06-13 23:34 - 2017-06-03 05:11 - 02958848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-06-13 23:34 - 2017-06-03 05:11 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-06-13 23:34 - 2017-06-03 05:11 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-06-13 23:34 - 2017-06-03 05:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-06-13 23:34 - 2017-06-03 05:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-06-13 23:34 - 2017-06-03 05:11 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-06-13 23:34 - 2017-06-03 05:10 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-06-13 23:34 - 2017-06-03 05:10 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-06-13 23:34 - 2017-06-03 05:10 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe
2017-06-13 23:34 - 2017-06-03 05:09 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-06-13 23:34 - 2017-06-03 05:09 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll
2017-06-13 23:34 - 2017-06-03 05:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-06-13 23:34 - 2017-06-03 05:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-06-13 23:34 - 2017-06-03 05:07 - 23682048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-06-13 23:34 - 2017-06-03 05:07 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2017-06-13 23:34 - 2017-06-03 05:07 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-06-13 23:34 - 2017-06-03 05:07 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2017-06-13 23:34 - 2017-06-03 05:07 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-06-13 23:34 - 2017-06-03 05:06 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-06-13 23:34 - 2017-06-03 05:05 - 20506624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-06-13 23:34 - 2017-06-03 05:05 - 07336448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-06-13 23:34 - 2017-06-03 05:05 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-06-13 23:34 - 2017-06-03 05:05 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-06-13 23:34 - 2017-06-03 05:05 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll
2017-06-13 23:34 - 2017-06-03 05:04 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-06-13 23:34 - 2017-06-03 05:04 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-06-13 23:34 - 2017-06-03 05:04 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-06-13 23:34 - 2017-06-03 05:03 - 19336192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-06-13 23:34 - 2017-06-03 05:03 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-06-13 23:34 - 2017-06-03 05:03 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-06-13 23:34 - 2017-06-03 05:02 - 08245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-06-13 23:34 - 2017-06-03 05:01 - 06726656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-06-13 23:34 - 2017-06-03 05:01 - 02804736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-06-13 23:34 - 2017-06-03 05:00 - 03379200 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-06-13 23:34 - 2017-06-03 05:00 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-06-13 23:34 - 2017-06-03 05:00 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 02672128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 02625024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-06-13 23:34 - 2017-06-03 04:59 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 01142784 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-06-13 23:34 - 2017-06-03 04:59 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 02650112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-06-13 23:34 - 2017-06-03 04:57 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 02829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 01675264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-06-13 23:34 - 2017-06-03 04:56 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-06-13 23:34 - 2017-06-03 04:55 - 03656192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-06-13 23:34 - 2017-06-03 04:55 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-06-13 23:34 - 2017-06-03 04:55 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-06-13 23:34 - 2017-06-03 04:54 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-06-13 23:34 - 2017-06-03 04:54 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-06-13 23:34 - 2017-06-03 04:53 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-06-13 23:34 - 2017-06-03 04:51 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe
2017-06-12 13:35 - 2017-06-12 13:39 - 25795785 _____ C:\Users\Sharon-Toshiba\Downloads\Sleight of Mouth by Robert Dilts.pdf
2017-06-10 20:11 - 2017-06-10 20:11 - 00007607 _____ C:\Users\Sharon-Toshiba\AppData\Local\Resmon.ResmonCfg
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-10 22:12 - 2017-03-09 13:43 - 00000000 ___RD C:\Users\Sharon-Toshiba\Google Drive
2017-07-10 22:10 - 2017-04-15 07:48 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-07-10 20:42 - 2017-04-15 08:16 - 00004184 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6A62C9AA-5090-47B0-AAB7-506E12B279C8}
2017-07-10 17:53 - 2017-03-08 14:32 - 00000000 ____D C:\Program Files\Opera
2017-07-10 17:50 - 2017-03-08 13:13 - 00000000 ___RD C:\Users\Sharon-Toshiba\OneDrive
2017-07-10 17:49 - 2017-04-15 07:52 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-07-10 17:49 - 2017-03-08 20:39 - 00000000 __SHD C:\Users\Sharon-Toshiba\IntelGraphicsProfiles
2017-07-10 17:47 - 2017-04-15 08:16 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-07-10 17:46 - 2017-03-18 07:40 - 02097152 _____ C:\WINDOWS\system32\config\BBI
2017-07-10 17:33 - 2017-03-09 10:48 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\DMCache
2017-07-10 17:26 - 2017-04-15 07:54 - 00000000 ____D C:\Users\Sharon-Toshiba
2017-07-10 17:25 - 2017-03-10 23:39 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\MusicBee
2017-07-10 15:05 - 2017-03-09 09:49 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-07-10 14:43 - 2017-03-08 22:28 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\CrashDumps
2017-07-09 01:08 - 2017-03-18 17:03 - 00000000 ___HD C:\Program Files\WindowsApps
2017-07-09 01:08 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-07-05 02:27 - 2017-03-10 23:29 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Mp3tag
2017-07-05 00:02 - 2017-03-09 09:49 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-07-05 00:02 - 2017-03-09 09:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-07-04 21:31 - 2017-03-08 14:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-07-04 21:19 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-07-04 20:57 - 2017-03-21 15:32 - 00000000 ____D C:\Users\Sharon-Toshiba\Downloads\Music Inbox
2017-07-04 11:33 - 2017-03-08 22:00 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Dashlane
2017-07-04 11:32 - 2017-03-08 22:26 - 00001983 _____ C:\Users\Sharon-Toshiba\Desktop\Dashlane.lnk
2017-07-04 11:32 - 2017-03-08 22:00 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dashlane
2017-07-04 02:37 - 2017-03-16 20:49 - 00000000 ____D C:\Users\Sharon-Toshiba\Downloads\Telegram Desktop
2017-07-04 02:34 - 2017-03-10 14:21 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Telegram Desktop
2017-07-02 23:58 - 2017-04-15 08:15 - 01142712 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-07-02 23:52 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-07-01 03:15 - 2017-03-10 18:28 - 00000000 ____D C:\ProgramData\Adobe
2017-07-01 03:15 - 2017-03-10 18:03 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\Adobe
2017-07-01 03:15 - 2017-03-08 13:11 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Adobe
2017-07-01 03:14 - 2017-03-08 13:37 - 00000000 ____D C:\Program Files (x86)\Google
2017-06-30 23:44 - 2017-03-09 13:15 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Skype
2017-06-30 23:06 - 2017-03-18 17:01 - 00000000 ____D C:\WINDOWS\INF
2017-06-30 22:25 - 2017-03-19 16:00 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Apple Computer
2017-06-30 22:25 - 2017-03-19 13:24 - 00000000 ____D C:\Program Files\Common Files\Apple
2017-06-30 22:17 - 2017-03-09 09:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-30 22:01 - 2017-04-23 17:38 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\Facebook
2017-06-30 22:01 - 2017-03-08 13:11 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\Packages
2017-06-30 22:00 - 2017-03-19 13:21 - 00000000 ____D C:\ProgramData\Apple
2017-06-30 17:32 - 2017-03-09 13:26 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\FluxSoftware
2017-06-30 17:02 - 2017-03-09 10:03 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\tixati
2017-06-30 16:59 - 2017-03-08 22:09 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2017-06-30 16:59 - 2017-03-08 14:19 - 00002450 ____R C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk
2017-06-30 01:17 - 2017-03-09 14:23 - 00000000 ____D C:\ProgramData\Package Cache
2017-06-27 12:06 - 2017-03-09 09:49 - 00077376 _____ C:\WINDOWS\SMSS-PFRO540b.tmp
2017-06-27 02:47 - 2017-03-10 11:46 - 00001048 ____N C:\Users\Public\Desktop\Mp3tag.lnk
2017-06-27 02:47 - 2017-03-10 11:46 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2017-06-27 01:35 - 2017-03-09 18:39 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2017-06-27 01:27 - 2017-03-18 17:03 - 00000000 __RHD C:\Users\Public\Libraries
2017-06-27 01:27 - 2017-03-09 18:38 - 00001644 ____N C:\Users\Public\Desktop\BlueStacks.lnk
2017-06-27 01:27 - 2017-03-09 18:38 - 00001644 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk
2017-06-27 01:26 - 2017-03-09 17:59 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\Bluestacks
2017-06-23 23:48 - 2017-03-09 14:48 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Kodi
2017-06-23 15:50 - 2017-05-22 22:36 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\Apple Inc
2017-06-22 12:40 - 2017-03-08 14:23 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\LocalLow\Mozilla
2017-06-20 22:35 - 2017-05-22 22:35 - 00003522 _____ C:\WINDOWS\System32\Tasks\Apple Diagnostics
2017-06-20 13:13 - 2017-04-15 08:16 - 00003308 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-06-20 13:13 - 2017-03-08 13:13 - 00002390 ____N C:\Users\Sharon-Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-06-19 17:15 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\rescache
2017-06-18 09:12 - 2016-11-20 14:51 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-06-18 09:09 - 2017-04-15 07:48 - 00381168 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-06-14 03:10 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-06-14 03:10 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-06-13 23:46 - 2017-03-08 14:21 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-06-13 23:42 - 2017-03-18 16:51 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-06-13 23:42 - 2017-03-08 14:21 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-06-13 23:36 - 2016-07-16 07:47 - 00000167 _____ C:\WINDOWS\win.ini
==================== Files in the root of some directories =======
2017-03-17 21:56 - 2017-04-14 18:15 - 0004502 _____ () C:\Users\Sharon-Toshiba\AppData\Roaming\VoiceMeeterDefault.xml
2017-05-17 11:32 - 2017-05-17 11:32 - 0125952 _____ () C:\Users\Sharon-Toshiba\AppData\Local\report
2017-06-10 20:11 - 2017-06-10 20:11 - 0007607 _____ () C:\Users\Sharon-Toshiba\AppData\Local\Resmon.ResmonCfg
2017-03-09 19:29 - 2017-03-09 19:29 - 0000552 _____ () C:\Users\Sharon-Toshiba\AppData\Local\TroubleshooterConfig.json
2017-03-08 14:24 - 2017-03-08 14:24 - 0000003 _____ () C:\Users\Sharon-Toshiba\AppData\Local\updater.log
2017-03-08 14:24 - 2017-05-07 02:50 - 0000425 _____ () C:\Users\Sharon-Toshiba\AppData\Local\UserProducts.xml
Some files in TEMP:
====================
2017-06-28 11:05 - 2017-06-28 11:05 - 3181912 _____ (Lead IT) C:\Users\Sharon-Toshiba\AppData\Local\Temp\djzjVb3W-prog.exe
2014-03-02 16:39 - 2014-06-29 17:48 - 0384141 _____ () C:\Users\Sharon-Toshiba\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-07-04 23:16
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-07-2017
Ran by Sharon-Toshiba (administrator) on DESKTOP-RL5BCH2 (10-07-2017 22:12:41)
Running from C:\Users\Sharon-Toshiba\Downloads
Loaded Profiles: Sharon-Toshiba (Available Profiles: defaultuser0 & Sharon-Toshiba)
Platform: Windows 10 Home Version 1703 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\dataup\dataup.exe
() C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe
(Toshiba Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
() C:\Windows\System32\tprdpw64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoResident.exe
(Google, Inc) C:\Users\Sharon-Toshiba\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Users\Sharon-Toshiba\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDExtHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files (x86)\EMET 5.5\EMET_Service.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDAppHost.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDRuntimeHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDSurrogateHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Program Files (x86)\EMET 5.5\EMET_Agent.exe
(CyberLink) C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Users\Sharon-Toshiba\AppData\Local\fxhvmda\cshzvz\ct.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe
() C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
() C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [601944 2015-08-14] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [180016 2015-06-08] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\Toshiba\System Setting\TCrdMain_Win8.exe [559920 2015-10-09] (TOSHIBA Corporation)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2369240 2015-10-20] (Microsoft Corp.)
HKLM-x32\...\Run: [TSUScheduler] => C:\Program Files (x86)\TOSHIBA\Sync Utility\TosSyncScheduler.exe [923520 2011-08-18] (TOSHIBA Corporation)
HKLM-x32\...\Run: [cpx] => "C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\cpx\cpx.exe" -starup <==== ATTENTION
HKLM-x32\...\Run: [svcvmx] => C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe [884224 2017-04-21] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [Dashlane] => C:\Users\Sharon-Toshiba\AppData\Roaming\Dashlane\Dashlane.exe [505296 2017-06-29] (Dashlane, Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [DashlanePlugin] => C:\Users\Sharon-Toshiba\AppData\Roaming\Dashlane\DashlanePlugin.exe [552400 2017-06-29] (Dashlane, Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7963552 2017-06-12] (SUPERAntiSpyware)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [Google Update] => C:\Users\Sharon-Toshiba\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-28] (Google Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [Google Photos Backup] => C:\Users\Sharon-Toshiba\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe [3790936 2016-04-08] (Google, Inc)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23819304 2017-03-21] (Google)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [160824 2017-05-24] (BlueStack Systems, Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [MusicManager] => C:\Users\Sharon-Toshiba\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7643136 2016-02-01] (Google Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545048 2017-03-14] (Skype Technologies S.A.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [Spotify Web Helper] => C:\Users\Sharon-Toshiba\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1446000 2017-04-16] (Spotify Ltd)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4022328 2017-05-25] (Tonec Inc.)
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [InterStat] => C:\Users\Sharon-Toshiba\AppData\Roaming\InterStat\interstat.exe <==== ATTENTION
HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Run: [GoogleChromeAutoLaunch_5E9B00E50FBF7F4CE97A3FE9A19AA703] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1197912 2017-06-22] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2017-07-10]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Sharon-Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Slack.lnk [2017-03-17]
ShortcutTarget: Slack.lnk -> C:\Users\Sharon-Toshiba\AppData\Local\slack\slack.exe (Slack Technologies)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 4.2.2.1
Tcpip\..\Interfaces\{314a7f20-9c10-454a-9f70-ba6bc0b00dfe}: [DhcpNameServer] 4.2.2.1
Tcpip\..\Interfaces\{4b3b1d40-78f9-45a8-a2d5-40e1d7cf8a39}: [DhcpNameServer] 8.8.8.8
Internet Explorer:
==================
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-12-10] (Internet Download Manager, Tonec Inc.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-07-04] (Oracle Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-07-04] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2016-12-10] (Internet Download Manager, Tonec Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-07-04] (Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-07-04] (Oracle Corporation)
Toolbar: HKLM-x32 - Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Sharon-Toshiba\AppData\Roaming\Dashlane\ie\KWIEBar.dll [2017-06-29] (Dashlane, Inc.)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)
Edge:
======
Edge Extension: (Office Online) -> 2016_MicrosoftOfficeOnline_8wekyb3d8bbwe => C:\Program Files\WindowsApps\Microsoft.OfficeOnline_1.5.1.0_neutral__8wekyb3d8bbwe [2017-05-15]
Edge Extension: (AdBlock) -> EdgeExtension_BetaFishAdBlock_c1wakc4j0nefm => C:\Program Files\WindowsApps\BetaFish.AdBlock_2.1.6.0_neutral__c1wakc4j0nefm [2017-05-26]
Edge Extension: (Pin It Button) -> EdgeExtension_PinterestPinItButton_xnkra2w3aecd0 => C:\Program Files\WindowsApps\Pinterest.PinItButton_1.39.5.0_neutral__xnkra2w3aecd0 [2017-04-15]
Edge Extension: (Save to Pocket) -> EdgeExtension_PocketSavetoPocket_v63j13wrfzj3t => C:\Program Files\WindowsApps\Pocket.SavetoPocket_2.0.38.0_neutral__v63j13wrfzj3t [2017-04-06]
Edge Extension: (LastPass: Free Password Manager) -> hdokiejnpimakedhajhdlcegeplioahd_LastPassLastPassFreePasswordManager_qq0fmhteeht3j => C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.1.45.0_neutral__qq0fmhteeht3j [2017-06-23]
Edge Extension: (Translator For Microsoft Edge) -> MicrosoftTranslate_MicrosoftTranslatorforMicrosoftEdge_8wekyb3d8bbwe => C:\Program Files\WindowsApps\Microsoft.TranslatorforMicrosoftEdge_0.91.16.0_neutral__8wekyb3d8bbwe [2017-04-15]
FireFox:
========
FF DefaultProfile: 2y9roifj.default
FF DefaultProfile: [email protected]
FF ProfilePath: C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\2y9roifj.default [2017-06-30]
FF Session Restore: Mozilla\Firefox\Profiles\2y9roifj.default -> is enabled.
FF Extension: (Emoji Keyboard) - C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\2y9roifj.default\Extensions\@emojikeyboard.xpi [2017-06-22]
FF Extension: (Enhancer for YouTube™) - C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\2y9roifj.default\Extensions\[email protected] [2017-03-25]
FF Extension: (Dashlane) - C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\2y9roifj.default\Extensions\[email protected] [2017-06-22]
FF Extension: (uBlock Origin) - C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\2y9roifj.default\Extensions\[email protected] [2017-06-22]
FF HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi
FF Extension: (No Name) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2017-05-16]
FF HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\Sharon-Toshiba\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Sharon-Toshiba\AppData\Roaming\IDM\idmmzcc5 [2017-06-07] [not signed]
FF HKU\S-1-5-21-1391234854-2931249872-507013314-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-01-26]
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-07-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-07-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1229199.dll [2017-03-31] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-07-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-07-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 10\npnitromozilla.dll [2016-03-03] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: logmeonce.com/LogmeOnce -> C:\Program Files (x86)\LogmeOnce\nplogmeonce.dll [No File]
FF Plugin HKU\S-1-5-21-1391234854-2931249872-507013314-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1391234854-2931249872-507013314-1001: @talk.google.com/O1DPlugin -> C:\Users\Sharon-Toshiba\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1391234854-2931249872-507013314-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Sharon-Toshiba\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1391234854-2931249872-507013314-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Sharon-Toshiba\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon-Toshiba\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon-Toshiba\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.trovi.com/?gd=&ctid=CT3333527&octid=EB_ORIGINAL_CTID&ISID=IFD16E428-4DBC-4DF1-9DBE-1A0EC18048F4&SearchSource=55&CUI=&UM=8&UP=SP8D5DC7D9-9954-4ED7-87CD-9BCDE28EEBEC&D=060115&SSPV="
CHR DefaultSearchURL: Default -> chrome-extension://chphlpgkkbolifaimnlloiipkdnihall/onetab.html
CHR DefaultSearchKeyword: Default -> lp
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default [2017-07-10]
CHR Extension: (Google Translate) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2017-07-01]
CHR Extension: (Scribd Downloader Free) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aijgbekkajnbfllinekkbcibhnmgkcne [2017-03-10]
CHR Extension: (Google Drive) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-08]
CHR Extension: (MEGA) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2017-06-30]
CHR Extension: (YouTube) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-08]
CHR Extension: (Adblock Plus) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-03-21]
CHR Extension: (OneTab) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall [2017-03-08]
CHR Extension: (OneNote Online) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciniambnphakdoflgeamacamhfllbkmo [2017-03-08]
CHR Extension: (Spotify - Music for every moment) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2017-03-08]
CHR Extension: (Download Manager) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\daoidaoebhfcgccdpgjjcbdginkofmfe [2017-03-08]
CHR Extension: (MiniPlay) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfddfiedihbijfeacjamchlliogmjjnd [2017-03-09]
CHR Extension: (Session Buddy) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\edacconmaakjimmfgnblocblbcdcpbko [2017-07-05]
CHR Extension: (Google Calendar) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-03-08]
CHR Extension: (Wikiwand: Wikipedia Modernized) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\emffkefkbkpkgpdeeooapgaicgmcbolj [2017-03-08]
CHR Extension: (Google Play Music) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2017-07-10]
CHR Extension: (Dashlane Secure Password Manager) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2017-07-06]
CHR Extension: (Bookmark Manager) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2017-03-08]
CHR Extension: (TweetDeck by Twitter) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2017-03-08]
CHR Extension: (Google Photos) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcglmfcclpfgljeaiahehebeoaiicbko [2017-03-08]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2017-06-30]
CHR Extension: (ImageSpark - Ultimate Image Downloader) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hooaoionkjogngfhjjniefmenehnopag [2017-03-16]
CHR Extension: (Kindle Cloud Reader) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2017-03-08]
CHR Extension: (Google Play Music) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg [2017-03-08]
CHR Extension: (Zillow) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\iifccoboedmhjapdlpgkigibgnkmdjoh [2017-03-08]
CHR Extension: (Unpaywall) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplffkdpngmdjhlpjmppncnlhomiipha [2017-06-20]
CHR Extension: (Grammarly for Chrome) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2017-07-10]
CHR Extension: (Google Hangouts) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2017-05-26]
CHR Extension: (SoundCloud Downloader Free) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\libedajeiljdoodmokbppgapcfbignci [2017-03-08]
CHR Extension: (Google Maps) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2017-03-08]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2017-03-08]
CHR Extension: (Pocket) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2017-03-08]
CHR Extension: (OneDrive) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2017-03-08]
CHR Extension: (IDM Integration Module) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2017-06-30]
CHR Extension: (Save to Pocket) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2017-06-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
CHR Extension: (Hover Zoom) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl [2017-04-14]
CHR Extension: (Gmail) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-08]
CHR Extension: (Chrome Media Router) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-30]
CHR Extension: (Clearbit Connect - Supercharge Gmail™) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmnhcgfcafcnkbengdcanjablaabjplo [2017-03-08]
CHR Extension: (Enhancer for YouTube™) - C:\Users\Sharon-Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ponfpcnoihfmfllpaingbgckeeldkhle [2017-07-10]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-05-25]
CHR HKU\S-1-5-21-1391234854-2931249872-507013314-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-05-25]
Opera:
=======
OPR Extension: (Google Translate) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2017-04-10]
OPR Extension: (Scribd Downloader Free) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\aijgbekkajnbfllinekkbcibhnmgkcne [2017-04-08]
OPR Extension: (Scribd Downloader Free) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\fbfifpkeojjlabelpjdgonmigjofgoim [2017-05-15]
OPR Extension: (Google Scholar Adder) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\fmjdgeladpkegliclimggpbbkamkhomb [2017-04-07]
OPR Extension: (Pocket (formerly Read It Later)) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\hedlhkdmdlcjhiblbmfggdiaeekblnoi [2017-04-07]
OPR Extension: (LastPass: Free Password Manager) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\hnjalnkldgigidggphhmacmimbdlafdo [2017-07-01]
OPR Extension: (Toolbox for Google Play Store™) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\ijoigpeoogooiilehgffdnidbminnfmc [2017-04-07]
OPR Extension: (Unpaywall) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\iplffkdpngmdjhlpjmppncnlhomiipha [2017-06-01]
OPR Extension: (Grammarly for Chrome) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2017-07-01]
OPR Extension: (GooglePlus Full-Size) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbgdfdhfmcibgdohjihdkeeedgdhlmke [2017-04-07]
OPR Extension: (Download Chrome Extension) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\kipjbhgniklcnglfaldilecjomjaddfi [2017-04-07]
OPR Extension: (Youtube Downloader) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\mdpelnicjpejiahnbkdohfjglhmaohcb [2017-06-07]
OPR Extension: (Google Dictionary (by Google)) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2017-04-07]
OPR Extension: (Huntr: Job Search Tracker ) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\mihdfbecejheednfigjpdacgeilhlmnf [2017-07-01]
OPR Extension: (IDM Integration Module) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2017-06-23]
OPR Extension: (Scribd Downloader Free) - C:\Users\Sharon-Toshiba\AppData\Roaming\Opera Software\Opera Stable\Extensions\ofhehnfmgbgnkjaojifkmebjjgffjaeh [2017-06-23]
StartMenuInternet: (HKLM) OperaStable - C:\Program Files\Opera\Launcher.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
"drmkpro64" => service could not be unlocked. <==== ATTENTION
S2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-30] (SUPERAntiSpyware.com)
S2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173784 2015-10-20] (Microsoft Corp.)
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [387128 2017-05-24] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [369720 2017-05-24] (BlueStack Systems, Inc.)
S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Plus-Service.exe [406584 2017-05-24] (BlueStack Systems, Inc.)
R2 Dataup; C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist\dataup\dataup.exe [77824 2017-01-05] () [File not signed] <==== ATTENTION
R3 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [19960 2015-05-27] ()
R2 EMET_Service; C:\Program Files (x86)\EMET 5.5\EMET_Service.exe [33960 2016-01-29] (Microsoft Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373752 2016-12-02] (Intel Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 NitroDriverReadSpool10; C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe [327320 2016-03-03] (Nitro PDF Software)
R2 NitroUpdateService; C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe [417944 2016-03-03] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [614664 2015-09-22] (CyberLink)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1570520 2016-02-02] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [837848 2016-02-02] (Secunia)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [278616 2017-05-04] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation)
R2 windowsmanagementservice; C:\Users\Sharon-Toshiba\AppData\Local\fxhvmda\cshzvz\ct.exe [689664 2017-05-30] () [File not signed] <==== ATTENTION
R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [152672 2017-05-24] (BlueStack Systems)
S3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [270904 2017-05-22] (Bluestack System Inc. )
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77376 2017-05-31] ()
R1 HssDRV6; C:\WINDOWS\system32\DRIVERS\hssdrv6.sys [44648 2015-09-18] (AnchorFree Inc.)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [230656 2016-12-12] (Intel Corporation)
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [186304 2017-03-22] (Malwarebytes)
S3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-03-22] (Malwarebytes)
S3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-03-22] (Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2017-07-10] (Malwarebytes)
S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [92088 2017-03-23] (Malwarebytes)
R1 MpKslaf4bbe7b; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D57D94D4-4E56-4DC1-9C00-E85D52ED7149}\MpKslaf4bbe7b.sys [44928 2017-07-10] (Microsoft Corporation)
R3 NETwNb64; C:\WINDOWS\System32\drivers\Netwbw02.sys [3485696 2017-03-18] (Intel Corporation)
R3 PSI; C:\WINDOWS\System32\DRIVERS\psi_mf_amd64.sys [18456 2016-02-02] (Secunia)
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [72792 2017-05-04] (Synaptics Incorporated)
R3 taphss6; C:\WINDOWS\System32\drivers\taphss6.sys [42088 2015-09-18] (Anchorfree Inc.)
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [52816 2016-08-03] (Toshiba Client Solutions Co., Ltd.)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Apple, Inc.) [File not signed]
R3 VBAudioVMVAIOMME; C:\WINDOWS\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [41192 2017-03-17] (Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-10 22:12 - 2017-07-10 22:14 - 00035461 _____ C:\Users\Sharon-Toshiba\Downloads\FRST.txt
2017-07-10 22:11 - 2017-07-10 22:12 - 00000000 ____D C:\FRST
2017-07-10 20:26 - 2017-07-10 20:26 - 02437120 _____ (Farbar) C:\Users\Sharon-Toshiba\Downloads\FRST64.exe
2017-07-10 20:14 - 2017-07-10 20:16 - 02338496 _____ C:\Users\Sharon-Toshiba\Downloads\Hitlers Black Victims - Clarence Lusane.pdf
2017-07-10 17:35 - 2017-07-10 17:45 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-07-10 17:33 - 2017-07-10 17:46 - 00000000 ____D C:\WINDOWS\pss
2017-07-10 17:32 - 2017-07-10 17:32 - 00000000 ___HD C:\OneDriveTemp
2017-07-10 17:23 - 2017-07-10 17:24 - 04922400 _____ (AO Kaspersky Lab) C:\Users\Sharon-Toshiba\Desktop\tdsskiller.exe
2017-07-10 15:42 - 2017-07-10 15:42 - 00000000 _____ C:\WINDOWS\SysWOW64\last.dump
2017-07-10 15:40 - 2017-07-10 15:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enhanced Mitigation Experience Toolkit
2017-07-10 15:40 - 2017-07-10 15:40 - 00000000 ____D C:\Program Files (x86)\EMET 5.5
2017-07-10 15:39 - 2017-07-10 15:39 - 00001067 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-07-10 15:16 - 2017-07-10 15:16 - 00001142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
2017-07-10 15:16 - 2017-07-10 15:16 - 00000000 ____D C:\Program Files (x86)\Secunia
2017-07-05 00:02 - 2017-07-05 00:02 - 01192400 _____ C:\WINDOWS\is-MAP9U.exe
2017-07-05 00:02 - 2017-07-05 00:02 - 00022709 _____ C:\WINDOWS\is-MAP9U.msg
2017-07-05 00:02 - 2017-07-05 00:02 - 00000334 _____ C:\WINDOWS\is-MAP9U.lst
2017-07-04 23:56 - 2017-07-04 23:56 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2017-07-04 22:15 - 2017-07-10 17:27 - 00000000 ____D C:\Program Files\AVAST Software
2017-07-04 22:13 - 2017-07-04 22:13 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf
2017-07-04 22:11 - 2017-07-04 22:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2017-07-04 22:11 - 2017-07-04 22:11 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2017-07-04 22:07 - 2017-07-04 22:07 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2017-07-04 22:06 - 2017-07-04 22:06 - 00000000 ____D C:\Program Files\Java
2017-07-04 21:56 - 2017-07-04 21:56 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2017-07-04 21:55 - 2017-07-04 21:55 - 00000000 ____D C:\Program Files (x86)\Java
2017-07-04 20:00 - 2017-07-10 15:38 - 00000000 ____D C:\ProgramData\AVAST Software
2017-07-01 03:49 - 2017-07-01 03:50 - 00546716 _____ C:\WINDOWS\Minidump\070117-33906-01.dmp
2017-07-01 03:49 - 2017-07-01 03:49 - 960298518 _____ C:\WINDOWS\MEMORY.DMP
2017-07-01 03:49 - 2017-07-01 03:49 - 00000000 ____D C:\WINDOWS\Minidump
2017-07-01 03:32 - 2017-07-01 03:32 - 00000000 ____D C:\WINDOWS\SysWOW64\Adobe
2017-07-01 03:26 - 2017-07-01 03:26 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Sun
2017-07-01 03:25 - 2017-07-04 22:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-07-01 03:21 - 2017-07-01 03:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-07-01 03:16 - 2017-07-01 03:16 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-07-01 03:16 - 2017-07-01 03:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-07-01 03:15 - 2017-07-01 03:15 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2017-07-01 03:15 - 2017-07-01 03:15 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2017-07-01 03:15 - 2017-07-01 03:15 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-07-01 03:14 - 2017-07-01 03:14 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-07-01 03:11 - 2017-07-10 17:27 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-07-01 03:11 - 2017-07-04 21:31 - 00001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-07-01 03:11 - 2017-07-04 21:31 - 00001216 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-07-01 03:09 - 2017-07-04 20:08 - 00003966 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1498892944
2017-07-01 03:09 - 2017-07-04 20:08 - 00000981 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2017-07-01 00:18 - 2017-07-01 00:18 - 00128728 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\48230029.sys
2017-06-30 22:50 - 2017-06-30 22:50 - 00000085 _____ C:\WINDOWS\wininit.ini
2017-06-30 22:22 - 2017-06-30 22:22 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2017-06-30 22:21 - 2017-07-01 00:02 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-06-30 22:21 - 2017-06-30 22:50 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-06-30 22:17 - 2017-07-10 17:27 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-06-30 22:14 - 2017-07-10 15:02 - 00000000 ____D C:\Users\Sharon-Toshiba\Desktop\mbar
2017-06-30 21:58 - 2017-06-30 22:08 - 00000000 ____D C:\AdwCleaner
2017-06-30 20:19 - 2017-07-04 22:11 - 00001849 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2017-06-30 17:35 - 2017-06-30 17:35 - 00000000 ____D C:\SUPERDelete
2017-06-30 17:25 - 2017-07-04 19:59 - 00000662 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2017-06-30 17:12 - 2017-06-30 20:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\llssoft
2017-06-30 17:02 - 2017-06-30 18:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\ntuserlitelist
2017-06-30 17:02 - 2017-06-30 17:02 - 00003796 _____ C:\WINDOWS\System32\Tasks\AdapterUpdater
2017-06-30 17:02 - 2017-06-30 17:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\devnull
2017-06-30 17:02 - 2017-06-30 17:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\ggxfkhl
2017-06-30 17:02 - 2017-06-30 17:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\fxhvmda
2017-06-30 17:02 - 2017-06-30 17:02 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\AdvinstAnalytics
2017-06-30 17:01 - 2017-06-30 17:01 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\c
2017-06-30 17:00 - 2017-06-30 17:00 - 00000000 ____D C:\Program Files (x86)\GenlTybros
2017-06-30 16:54 - 2017-06-30 17:01 - 00000000 ____D C:\Program Files (x86)\AnonymizerGadget
2017-06-30 16:54 - 2017-06-30 16:55 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\AGData
2017-06-30 16:35 - 2017-06-30 16:35 - 00035352 _____ (Connectify) C:\WINDOWS\system32\Drivers\cnnctfy3.sys
2017-06-30 16:23 - 2017-06-30 16:59 - 00002317 ____R C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Оpеrа Вrоwsеr.lnk
2017-06-30 15:14 - 2017-06-30 15:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cygwin
2017-06-30 15:12 - 2017-06-30 15:12 - 00000000 ____D C:\Users\Sharon-Toshiba\Documents\http%3a%2f%2fmirrors.koehn.com%2fcygwin%2fcygwin-ftp%2f
2017-06-30 15:08 - 2017-06-30 15:08 - 00000000 ____D C:\Users\Sharon-Toshiba\Documents\http%3a%2f%2fcygwin.mirrors.hoobly.com%2f
2017-06-30 15:07 - 2017-06-30 15:09 - 00000000 ____D C:\Users\Sharon-Toshiba\Documents\http%3a%2f%2fcygwin.mirror.constant.com%2f
2017-06-30 15:05 - 2017-06-30 15:14 - 00000000 ____D C:\cygwin64
2017-06-30 14:54 - 2017-06-30 14:54 - 01010720 ___RS (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCHRT20.OCX
2017-06-30 14:54 - 2017-06-30 14:54 - 00224016 ___RS (Microsoft Corporation) C:\WINDOWS\SysWOW64\TABCTL32.OCX
2017-06-30 14:54 - 2017-06-30 14:54 - 00140488 ___RS (Microsoft Corporation) C:\WINDOWS\SysWOW64\COMDLG32.OCX
2017-06-30 14:53 - 2017-06-30 14:53 - 01070232 ___RS (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCOMCTL.OCX
2017-06-27 02:47 - 2017-06-27 02:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2017-06-27 01:23 - 2017-06-27 01:27 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2017-06-27 01:23 - 2017-05-24 02:58 - 00000000 ____D C:\ProgramData\BlueStacks
2017-06-23 21:07 - 2017-06-23 21:09 - 12678001 _____ C:\Users\Sharon-Toshiba\Downloads\drive-download-20170624T010752Z-001.zip
2017-06-23 20:02 - 2017-06-23 20:09 - 00733184 _____ C:\Users\Sharon-Toshiba\Downloads\Dario Fernandez-Morera-The Myth of the Andalusian Paradise_ Muslims, Christians, and Jews under Islamic Rule in Medieval Spain-Intercollegiate Studies Institute (2016).epub
2017-06-23 20:00 - 2017-06-23 20:00 - 00193318 _____ C:\Users\Sharon-Toshiba\Downloads\fernandez-morera.pdf
2017-06-18 09:49 - 2017-06-18 09:49 - 02785959 _____ C:\Users\Sharon-Toshiba\Downloads\[Massey,_Gerald]_The_natural_genesis_or,_Second_p(b-ok.org) (1).pdf
2017-06-13 23:36 - 2017-06-13 23:36 - 00000000 ____D C:\WINDOWS\PCHEALTH
2017-06-13 23:34 - 2017-06-03 06:15 - 01596600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-06-13 23:34 - 2017-06-03 06:15 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-06-13 23:34 - 2017-06-03 06:15 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-06-13 23:34 - 2017-06-03 06:14 - 01147296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-06-13 23:34 - 2017-06-03 06:14 - 01024928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-06-13 23:34 - 2017-06-03 06:10 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-06-13 23:34 - 2017-06-03 06:09 - 08318880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-06-13 23:34 - 2017-06-03 06:09 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-06-13 23:34 - 2017-06-03 06:08 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-06-13 23:34 - 2017-06-03 06:07 - 00923048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-06-13 23:34 - 2017-06-03 06:07 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-06-13 23:34 - 2017-06-03 06:02 - 02444192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-06-13 23:34 - 2017-06-03 06:01 - 05477096 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-06-13 23:34 - 2017-06-03 06:00 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-06-13 23:34 - 2017-06-03 06:00 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll
2017-06-13 23:34 - 2017-06-03 06:00 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2017-06-13 23:34 - 2017-06-03 05:59 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-06-13 23:34 - 2017-06-03 05:59 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-06-13 23:34 - 2017-06-03 05:59 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-06-13 23:34 - 2017-06-03 05:59 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2017-06-13 23:34 - 2017-06-03 05:58 - 21352696 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-06-13 23:34 - 2017-06-03 05:58 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-06-13 23:34 - 2017-06-03 05:58 - 00660384 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2017-06-13 23:34 - 2017-06-03 05:58 - 00254176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2017-06-13 23:34 - 2017-06-03 05:57 - 00371616 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-06-13 23:34 - 2017-06-03 05:55 - 02681760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-06-13 23:34 - 2017-06-03 05:36 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-06-13 23:34 - 2017-06-03 05:35 - 02259768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-06-13 23:34 - 2017-06-03 05:28 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-06-13 23:34 - 2017-06-03 05:26 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll
2017-06-13 23:34 - 2017-06-03 05:23 - 20373920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-06-13 23:34 - 2017-06-03 05:23 - 06760024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-06-13 23:34 - 2017-06-03 05:23 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2017-06-13 23:34 - 2017-06-03 05:20 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-06-13 23:34 - 2017-06-03 05:14 - 03673088 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-06-13 23:34 - 2017-06-03 05:14 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2017-06-13 23:34 - 2017-06-03 05:14 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll
2017-06-13 23:34 - 2017-06-03 05:14 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2017-06-13 23:34 - 2017-06-03 05:14 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-06-13 23:34 - 2017-06-03 05:12 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-06-13 23:34 - 2017-06-03 05:11 - 02958848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-06-13 23:34 - 2017-06-03 05:11 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-06-13 23:34 - 2017-06-03 05:11 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-06-13 23:34 - 2017-06-03 05:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-06-13 23:34 - 2017-06-03 05:11 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-06-13 23:34 - 2017-06-03 05:11 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-06-13 23:34 - 2017-06-03 05:10 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-06-13 23:34 - 2017-06-03 05:10 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-06-13 23:34 - 2017-06-03 05:10 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe
2017-06-13 23:34 - 2017-06-03 05:09 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-06-13 23:34 - 2017-06-03 05:09 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll
2017-06-13 23:34 - 2017-06-03 05:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-06-13 23:34 - 2017-06-03 05:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-06-13 23:34 - 2017-06-03 05:07 - 23682048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-06-13 23:34 - 2017-06-03 05:07 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2017-06-13 23:34 - 2017-06-03 05:07 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-06-13 23:34 - 2017-06-03 05:07 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2017-06-13 23:34 - 2017-06-03 05:07 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-06-13 23:34 - 2017-06-03 05:06 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-06-13 23:34 - 2017-06-03 05:05 - 20506624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-06-13 23:34 - 2017-06-03 05:05 - 07336448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-06-13 23:34 - 2017-06-03 05:05 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-06-13 23:34 - 2017-06-03 05:05 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-06-13 23:34 - 2017-06-03 05:05 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll
2017-06-13 23:34 - 2017-06-03 05:04 - 12787200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-06-13 23:34 - 2017-06-03 05:04 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-06-13 23:34 - 2017-06-03 05:04 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-06-13 23:34 - 2017-06-03 05:03 - 19336192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-06-13 23:34 - 2017-06-03 05:03 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-06-13 23:34 - 2017-06-03 05:03 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-06-13 23:34 - 2017-06-03 05:02 - 08245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-06-13 23:34 - 2017-06-03 05:01 - 06726656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-06-13 23:34 - 2017-06-03 05:01 - 02804736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-06-13 23:34 - 2017-06-03 05:00 - 03379200 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-06-13 23:34 - 2017-06-03 05:00 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-06-13 23:34 - 2017-06-03 05:00 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 04730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 02672128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 02625024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 02056192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-06-13 23:34 - 2017-06-03 04:59 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 01142784 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-06-13 23:34 - 2017-06-03 04:59 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-06-13 23:34 - 2017-06-03 04:59 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 02650112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2017-06-13 23:34 - 2017-06-03 04:58 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-06-13 23:34 - 2017-06-03 04:57 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 02829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 01675264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-06-13 23:34 - 2017-06-03 04:57 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-06-13 23:34 - 2017-06-03 04:56 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-06-13 23:34 - 2017-06-03 04:55 - 03656192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-06-13 23:34 - 2017-06-03 04:55 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-06-13 23:34 - 2017-06-03 04:55 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-06-13 23:34 - 2017-06-03 04:54 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-06-13 23:34 - 2017-06-03 04:54 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-06-13 23:34 - 2017-06-03 04:53 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-06-13 23:34 - 2017-06-03 04:51 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe
2017-06-12 13:35 - 2017-06-12 13:39 - 25795785 _____ C:\Users\Sharon-Toshiba\Downloads\Sleight of Mouth by Robert Dilts.pdf
2017-06-10 20:11 - 2017-06-10 20:11 - 00007607 _____ C:\Users\Sharon-Toshiba\AppData\Local\Resmon.ResmonCfg
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-10 22:12 - 2017-03-09 13:43 - 00000000 ___RD C:\Users\Sharon-Toshiba\Google Drive
2017-07-10 22:10 - 2017-04-15 07:48 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-07-10 20:42 - 2017-04-15 08:16 - 00004184 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6A62C9AA-5090-47B0-AAB7-506E12B279C8}
2017-07-10 17:53 - 2017-03-08 14:32 - 00000000 ____D C:\Program Files\Opera
2017-07-10 17:50 - 2017-03-08 13:13 - 00000000 ___RD C:\Users\Sharon-Toshiba\OneDrive
2017-07-10 17:49 - 2017-04-15 07:52 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-07-10 17:49 - 2017-03-08 20:39 - 00000000 __SHD C:\Users\Sharon-Toshiba\IntelGraphicsProfiles
2017-07-10 17:47 - 2017-04-15 08:16 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-07-10 17:46 - 2017-03-18 07:40 - 02097152 _____ C:\WINDOWS\system32\config\BBI
2017-07-10 17:33 - 2017-03-09 10:48 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\DMCache
2017-07-10 17:26 - 2017-04-15 07:54 - 00000000 ____D C:\Users\Sharon-Toshiba
2017-07-10 17:25 - 2017-03-10 23:39 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\MusicBee
2017-07-10 15:05 - 2017-03-09 09:49 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-07-10 14:43 - 2017-03-08 22:28 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\CrashDumps
2017-07-09 01:08 - 2017-03-18 17:03 - 00000000 ___HD C:\Program Files\WindowsApps
2017-07-09 01:08 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-07-05 02:27 - 2017-03-10 23:29 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Mp3tag
2017-07-05 00:02 - 2017-03-09 09:49 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-07-05 00:02 - 2017-03-09 09:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-07-04 21:31 - 2017-03-08 14:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-07-04 21:19 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-07-04 20:57 - 2017-03-21 15:32 - 00000000 ____D C:\Users\Sharon-Toshiba\Downloads\Music Inbox
2017-07-04 11:33 - 2017-03-08 22:00 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Dashlane
2017-07-04 11:32 - 2017-03-08 22:26 - 00001983 _____ C:\Users\Sharon-Toshiba\Desktop\Dashlane.lnk
2017-07-04 11:32 - 2017-03-08 22:00 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dashlane
2017-07-04 02:37 - 2017-03-16 20:49 - 00000000 ____D C:\Users\Sharon-Toshiba\Downloads\Telegram Desktop
2017-07-04 02:34 - 2017-03-10 14:21 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Telegram Desktop
2017-07-02 23:58 - 2017-04-15 08:15 - 01142712 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-07-02 23:52 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-07-01 03:15 - 2017-03-10 18:28 - 00000000 ____D C:\ProgramData\Adobe
2017-07-01 03:15 - 2017-03-10 18:03 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\Adobe
2017-07-01 03:15 - 2017-03-08 13:11 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Adobe
2017-07-01 03:14 - 2017-03-08 13:37 - 00000000 ____D C:\Program Files (x86)\Google
2017-06-30 23:44 - 2017-03-09 13:15 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Skype
2017-06-30 23:06 - 2017-03-18 17:01 - 00000000 ____D C:\WINDOWS\INF
2017-06-30 22:25 - 2017-03-19 16:00 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Apple Computer
2017-06-30 22:25 - 2017-03-19 13:24 - 00000000 ____D C:\Program Files\Common Files\Apple
2017-06-30 22:17 - 2017-03-09 09:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-30 22:01 - 2017-04-23 17:38 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\Facebook
2017-06-30 22:01 - 2017-03-08 13:11 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\Packages
2017-06-30 22:00 - 2017-03-19 13:21 - 00000000 ____D C:\ProgramData\Apple
2017-06-30 17:32 - 2017-03-09 13:26 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\FluxSoftware
2017-06-30 17:02 - 2017-03-09 10:03 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\tixati
2017-06-30 16:59 - 2017-03-08 22:09 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2017-06-30 16:59 - 2017-03-08 14:19 - 00002450 ____R C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk
2017-06-30 01:17 - 2017-03-09 14:23 - 00000000 ____D C:\ProgramData\Package Cache
2017-06-27 12:06 - 2017-03-09 09:49 - 00077376 _____ C:\WINDOWS\SMSS-PFRO540b.tmp
2017-06-27 02:47 - 2017-03-10 11:46 - 00001048 ____N C:\Users\Public\Desktop\Mp3tag.lnk
2017-06-27 02:47 - 2017-03-10 11:46 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2017-06-27 01:35 - 2017-03-09 18:39 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2017-06-27 01:27 - 2017-03-18 17:03 - 00000000 __RHD C:\Users\Public\Libraries
2017-06-27 01:27 - 2017-03-09 18:38 - 00001644 ____N C:\Users\Public\Desktop\BlueStacks.lnk
2017-06-27 01:27 - 2017-03-09 18:38 - 00001644 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk
2017-06-27 01:26 - 2017-03-09 17:59 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\Bluestacks
2017-06-23 23:48 - 2017-03-09 14:48 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Roaming\Kodi
2017-06-23 15:50 - 2017-05-22 22:36 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\Local\Apple Inc
2017-06-22 12:40 - 2017-03-08 14:23 - 00000000 ____D C:\Users\Sharon-Toshiba\AppData\LocalLow\Mozilla
2017-06-20 22:35 - 2017-05-22 22:35 - 00003522 _____ C:\WINDOWS\System32\Tasks\Apple Diagnostics
2017-06-20 13:13 - 2017-04-15 08:16 - 00003308 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-06-20 13:13 - 2017-03-08 13:13 - 00002390 ____N C:\Users\Sharon-Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-06-19 17:15 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\rescache
2017-06-18 09:12 - 2016-11-20 14:51 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-06-18 09:09 - 2017-04-15 07:48 - 00381168 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-06-14 03:10 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-06-14 03:10 - 2017-03-18 17:03 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-06-13 23:46 - 2017-03-08 14:21 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-06-13 23:42 - 2017-03-18 16:51 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-06-13 23:42 - 2017-03-08 14:21 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-06-13 23:36 - 2016-07-16 07:47 - 00000167 _____ C:\WINDOWS\win.ini
==================== Files in the root of some directories =======
2017-03-17 21:56 - 2017-04-14 18:15 - 0004502 _____ () C:\Users\Sharon-Toshiba\AppData\Roaming\VoiceMeeterDefault.xml
2017-05-17 11:32 - 2017-05-17 11:32 - 0125952 _____ () C:\Users\Sharon-Toshiba\AppData\Local\report
2017-06-10 20:11 - 2017-06-10 20:11 - 0007607 _____ () C:\Users\Sharon-Toshiba\AppData\Local\Resmon.ResmonCfg
2017-03-09 19:29 - 2017-03-09 19:29 - 0000552 _____ () C:\Users\Sharon-Toshiba\AppData\Local\TroubleshooterConfig.json
2017-03-08 14:24 - 2017-03-08 14:24 - 0000003 _____ () C:\Users\Sharon-Toshiba\AppData\Local\updater.log
2017-03-08 14:24 - 2017-05-07 02:50 - 0000425 _____ () C:\Users\Sharon-Toshiba\AppData\Local\UserProducts.xml
Some files in TEMP:
====================
2017-06-28 11:05 - 2017-06-28 11:05 - 3181912 _____ (Lead IT) C:\Users\Sharon-Toshiba\AppData\Local\Temp\djzjVb3W-prog.exe
2014-03-02 16:39 - 2014-06-29 17:48 - 0384141 _____ () C:\Users\Sharon-Toshiba\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-07-04 23:16
==================== End of FRST.txt ============================