Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-08-2017 Ran by Sonia & Jasper (administrator) on JAPSON (20-08-2017 22:14:43) Running from C:\Users\Sonia & Jasper\Downloads Loaded Profiles: Sonia & Jasper (Available Profiles: UpdatusUser & Sonia & Jasper) Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Safe Mode (with Networking) Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe (McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe (McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcupdate.exe (Farbar) C:\Users\Sonia & Jasper\Downloads\FRST64(1).exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [792224 2011-12-13] (Atheros Commnucations) HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [657568 2011-12-13] (Atheros Commnucations) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12446824 2012-01-31] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2011-11-15] (Realtek Semiconductor) HKLM\...\Run: [SynLenovoGestureMgr] => C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [408872 2011-11-10] (Synaptics) HKLM\...\Run: [OnekeyStudio] => C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [789856 2012-05-30] (Lenovo) HKLM\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-14] (CyberLink Corp.) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8079408 2012-05-30] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6200368 2012-05-30] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-05-30] (Lenovo) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3023600 2013-02-25] (Synaptics Incorporated) HKLM\...\Run: [Zune Launcher] => C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-03] (Adobe Systems Incorporated) HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvLaunch.exe [213832 2017-07-30] (AVAST Software) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-27] (Intel Corporation) HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331_STI.EXE [548864 2011-11-24] (Vimicro) HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [MuteSync] => C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe [343040 2012-02-04] (Lenovo) HKLM-x32\...\Run: [Intelligent Touchpad] => C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe [291272 2011-12-08] () HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-27] (CyberLink Corp.) HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-05-30] (Lenovo) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [1532992 2013-03-13] (McAfee, Inc.) HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-14] (CyberLink Corp.) HKLM-x32\...\Run: [CAPOSD] => C:\Program Files (x86)\Lenovo\Lenovo CAPOSD\CAPOSD.exe [1876992 2012-02-09] (LENOVO) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.) HKLM-x32\...\Run: [CitrixReceiver] => "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk" HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.) HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2087264 2014-09-11] (Wondershare) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [318128 2016-11-16] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3487032 2017-08-10] (Dropbox, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\Run: [Spotify Web Helper] => C:\Users\Sonia & Jasper\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1552496 2016-09-04] (Spotify Ltd) HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\Run: [Facebook Update] => C:\Users\Sonia & Jasper\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-07-30] (Facebook Inc.) HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\Run: [CAHeadless] => C:\Program Files (x86)\Adobe\Elements 12 Organizer\CAHeadless\ElementsAutoAnalyzer.exe [1400224 2013-09-03] (Adobe Systems Incorporated) HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\Run: [GoogleChromeAutoLaunch_06C7D88654D525E131BB7B504356242C] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1301848 2017-08-02] (Google Inc.) HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4029.0217" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1165.0612\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1165.0612\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1165.0612] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1165.0612" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.4724.0224] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.4724.0224" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.4726.0226\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.4726.0226\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.4726.0226] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.4726.0226" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5907.0716] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5907.0716" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5930.0814] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5930.0814" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5951.0827] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.5951.0827" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6201.1019] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6201.1019" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6281.1202] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6281.1202" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6301.0127] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6301.0127" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6302.0225] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6302.0225" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6386.0412] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6386.0412" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\RunOnce: [Uninstall C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6390.0509] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Sonia & Jasper\AppData\Local\Microsoft\OneDrive\17.3.6390.0509" HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\...\MountPoints2: {b5a9c0c3-ab15-11e2-9ce0-446d57b759b2} - G:\HTC_Sync_Manager_PC.exe AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2013-03-07] ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{6BD33DA2-4815-44F4-B36F-4E5ABE498CFB}: [DhcpNameServer] 62.179.104.196 213.46.228.196 Tcpip\..\Interfaces\{E11ED79B-04A4-4ADB-B7B2-4C2EF3F7D745}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKU\S-1-5-21-1535155601-2421706697-1459365258-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1535155601-2421706697-1459365258-1001 -> DefaultScope {86647C4B-04EE-4AFE-BC4B-C4B1DB1BAEDC} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US714D20140522&p={searchTerms} SearchScopes: HKU\S-1-5-21-1535155601-2421706697-1459365258-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1535155601-2421706697-1459365258-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN_enNL531 SearchScopes: HKU\S-1-5-21-1535155601-2421706697-1459365258-1001 -> {86647C4B-04EE-4AFE-BC4B-C4B1DB1BAEDC} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US714D20140522&p={searchTerms} BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-07-11] (Microsoft Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll [2017-07-13] (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2017-03-14] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-07-11] (Microsoft Corporation) BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-12-13] (Atheros Commnucations) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2017-07-13] (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2017-03-14] (Microsoft Corporation) Toolbar: HKU\S-1-5-21-1535155601-2421706697-1459365258-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-20] (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-06-01] (Skype Technologies) Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2013-03-13] (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2013-03-13] (McAfee, Inc.) Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.) FireFox: ======== FF ProfilePath: C:\Users\Sonia & Jasper\AppData\Roaming\Mozilla\Firefox\Profiles\ux8d25yj.default [2017-08-20] FF DefaultSearchEngine: Mozilla\Firefox\Profiles\ux8d25yj.default -> Secure Search FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\ux8d25yj.default -> Secure Search FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\ux8d25yj.default -> Secure Search FF SelectedSearchEngine: Mozilla\Firefox\Profiles\ux8d25yj.default -> Secure Search FF Keyword.URL: Mozilla\Firefox\Profiles\ux8d25yj.default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C111US714D20140522&p= FF Extension: (British English Dictionary (Updated)) - C:\Users\Sonia & Jasper\AppData\Roaming\Mozilla\Firefox\Profiles\ux8d25yj.default\Extensions\en-gb@flyingtophat.co.uk [2015-11-16] [not signed] FF Extension: (Avast SafePrice) - C:\Users\Sonia & Jasper\AppData\Roaming\Mozilla\Firefox\Profiles\ux8d25yj.default\Extensions\sp@avast.com.xpi [2017-06-11] FF Extension: (Avast Online Security) - C:\Users\Sonia & Jasper\AppData\Roaming\Mozilla\Firefox\Profiles\ux8d25yj.default\Extensions\wrc@avast.com.xpi [2017-06-11] FF SearchPlugin: C:\Users\Sonia & Jasper\AppData\Roaming\Mozilla\Firefox\Profiles\ux8d25yj.default\searchplugins\McSiteAdvisor.xml [2015-09-02] FF Extension: (Skype) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-05-25] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2015-05-27] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_151.dll [2017-08-10] () FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2013-03-13] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-10] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll [2014-03-11] (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-02-20] () FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2013-10-01] (Citrix Systems, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2013-03-13] () FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-11-29] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1535155601-2421706697-1459365258-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Sonia & Jasper\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited) FF Plugin HKU\S-1-5-21-1535155601-2421706697-1459365258-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Sonia & Jasper\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-04-02] (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\cgpcfg.dll [2008-08-16] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll [2008-08-16] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll [2008-08-16] () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll [2008-08-16] () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxmui.dll [2008-08-16] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icafile.dll [2008-08-16] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icalogon.dll [2008-08-16] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\msvcm80.dll [2008-05-21] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\msvcp80.dll [2008-05-21] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\msvcr80.dll [2008-05-21] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll [2008-08-16] () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2017-03-28] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\sslsdk_b.dll [2008-06-05] (Citrix Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll [2008-08-16] (Citrix Systems, Inc.) Chrome: ======= CHR DefaultProfile: Default CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US714D20140522&p={searchTerms} CHR DefaultSearchKeyword: Default -> mcafee CHR Profile: C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default [2017-08-13] CHR Extension: (Google Docs) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04] CHR Extension: (Google Drive) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23] CHR Extension: (YouTube) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-28] CHR Extension: (Google Cast) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-09-16] CHR Extension: (Videostream for Google Chromecastâ„¢) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2017-05-16] CHR Extension: (Google Search) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Avast SafePrice) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-08-08] CHR Extension: (Google Docs Offline) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17] CHR Extension: (Avast Online Security) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-06-10] CHR Extension: (Invite All Friends on Facebook) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmhkeajgflmokoaaoadgkhhmibjbpj [2017-08-10] CHR Extension: (Chrome Web Store Payments) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-16] CHR Extension: (Gmail) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28] CHR Extension: (Chrome Media Router) - C:\Users\Sonia & Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-08] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 AdobeActiveFileMonitor12.0; C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe [181152 2013-09-03] (Adobe Systems Incorporated) S3 aswbIDSAgent; C:\Program Files\Alwil Software\Avast5\x64\aswidsagenta.exe [7430992 2017-07-30] (AVAST Software s.r.o.) S2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [106144 2011-12-13] (Atheros Commnucations) [File not signed] S2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [263312 2017-07-30] (AVAST Software) S2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042544 2017-03-14] (Microsoft Corporation) S3 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-01-20] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-01-20] (Dropbox, Inc.) S3 DbxSvc; C:\Windows\system32\DbxSvc.exe [49992 2017-08-10] (Dropbox, Inc.) S2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-11-18] (Nero AG) S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-08] () S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-08] (Intel Corporation) S3 McAWFwk; c:\Program Files\mcafee\msc\McAWFwk.exe [225216 2011-01-28] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [384048 2013-02-26] (McAfee, Inc.) S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) S2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [241456 2013-02-19] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218760 2013-02-19] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-02-19] (McAfee, Inc.) S2 NSDSvc; C:\Windows\System32\NSDSvc.exe [120160 2011-12-24] (Lenovo) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2122248 2017-02-22] (Electronic Arts) S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2184208 2017-02-22] (Electronic Arts) S3 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed] S3 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.3.2.219\WsAppService.exe [440832 2016-12-07] (Wondershare) [File not signed] S3 WsDrvInst; C:\Program Files (x86)\Wondershare\Dr.Fone for Android (CPC)\Library\DriverInstaller\DriverInstall.exe [124560 2016-12-13] (Wondershare) S2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2011-12-13] (Atheros) [File not signed] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [320008 2017-07-30] (AVAST Software s.r.o.) S0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [198976 2017-07-30] (AVAST Software s.r.o.) S0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [343288 2017-07-30] (AVAST Software s.r.o.) S0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [57728 2017-07-30] (AVAST Software s.r.o.) S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [82936 2017-01-09] (AVAST Software) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [46984 2017-07-13] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41800 2017-07-13] (AVAST Software) S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [146704 2017-08-13] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [110352 2017-07-13] (AVAST Software) S0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [84392 2017-07-13] (AVAST Software) S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1015880 2017-08-13] (AVAST Software) S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [585608 2017-07-13] (AVAST Software) S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [198768 2017-07-13] (AVAST Software) S0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [361336 2017-07-13] (AVAST Software) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-02-19] (McAfee, Inc.) S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-20] (DT Soft Ltd) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.) S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [121800 2010-03-08] (QUALCOMM Incorporated) S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179280 2013-02-19] (McAfee, Inc.) S3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [309840 2013-02-19] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [515968 2013-02-19] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [771536 2013-02-19] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106552 2013-02-19] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [340216 2013-02-19] (McAfee, Inc.) R0 NSD; C:\Windows\System32\drivers\nsd.sys [24160 2011-12-24] (Lenovo Corporation") S1 Nsdfltr; C:\Windows\System32\drivers\Nsdfltr.sys [59488 2011-12-22] (Lenovo Corporation) R0 PxHlpa64; C:\Windows\System32\drivers\PxHlpa64.sys [56336 2013-07-19] (Corel Corporation) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.) S3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [952832 2011-12-06] (Vimicro Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-08-20 22:13 - 2017-08-20 22:13 - 002395648 _____ (Farbar) C:\Users\Sonia & Jasper\Downloads\FRST64(1).exe 2017-08-20 22:02 - 2017-08-20 22:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2017-08-13 10:07 - 2017-08-13 10:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-08-10 19:03 - 2017-08-10 19:03 - 000049992 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2017-08-10 19:03 - 2017-08-10 19:03 - 000045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2017-08-10 19:03 - 2017-08-10 19:03 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2017-08-10 19:03 - 2017-08-10 19:03 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2017-08-05 11:49 - 2017-08-05 11:49 - 001782988 _____ C:\Users\Sonia & Jasper\Downloads\FadedLaceMitts (2).pdf 2017-08-04 11:38 - 2017-08-04 11:38 - 001782988 _____ C:\Users\Sonia & Jasper\Downloads\FadedLaceMitts (1).pdf 2017-08-03 23:00 - 2017-08-03 23:00 - 000151195 _____ C:\Users\Sonia & Jasper\Downloads\voucher_22416888.pdf 2017-08-03 19:06 - 2017-08-03 19:06 - 000203928 _____ C:\Users\Sonia & Jasper\Downloads\VideostreamNetworkRepair.exe 2017-07-30 09:32 - 2017-07-30 09:31 - 000400464 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2017-07-25 13:06 - 2017-07-25 13:06 - 000000000 ___HD C:\OneDriveTemp 2017-07-25 13:05 - 2017-07-25 13:05 - 000003194 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1535155601-2421706697-1459365258-1001 2017-07-24 20:39 - 2017-07-24 20:39 - 000278261 _____ C:\Users\Sonia & Jasper\Downloads\Passe_partout_version_3.pdf 2017-07-22 23:01 - 2017-07-22 23:01 - 000041914 _____ C:\Users\Sonia & Jasper\Documents\Reservation La Ballena ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-08-20 22:16 - 2017-07-08 07:06 - 000041622 _____ C:\Users\Sonia & Jasper\Downloads\FRST.txt 2017-08-20 22:14 - 2017-07-08 07:05 - 000000000 ____D C:\FRST 2017-08-20 22:13 - 2014-07-09 14:38 - 017036800 ___SH C:\Users\Sonia & Jasper\Downloads\Thumbs.db 2017-08-20 22:02 - 2012-05-30 02:31 - 000001799 _____ C:\Users\Public\Desktop\McAfee AntiVirus Plus.lnk 2017-08-20 21:58 - 2017-07-08 06:56 - 000421268 _____ C:\Windows\ntbtlog.txt 2017-08-20 21:56 - 2016-11-22 20:37 - 000000000 ____D C:\Users\Sonia & Jasper\AppData\LocalLow\Mozilla 2017-08-20 21:56 - 2012-05-30 02:33 - 000295941 _____ C:\Windows\system32\fastboot.set 2017-08-13 15:37 - 2017-01-20 01:29 - 000000924 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2017-08-13 14:24 - 2009-07-14 06:45 - 000032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-08-13 14:24 - 2009-07-14 06:45 - 000032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-08-13 14:14 - 2015-08-12 11:04 - 000000000 ___RD C:\Users\Sonia & Jasper\OneDrive 2017-08-13 14:10 - 2013-04-22 13:47 - 000000000 ____D C:\Users\Sonia & Jasper\AppData\Local\HTC MediaHub 2017-08-13 14:09 - 2012-05-30 02:29 - 000000000 ____D C:\ProgramData\VeriFace 2017-08-13 14:08 - 2017-01-20 01:29 - 000000920 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2017-08-13 14:08 - 2013-07-30 22:54 - 000000964 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1535155601-2421706697-1459365258-1001UA.job 2017-08-13 14:08 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-08-13 10:22 - 2014-10-04 09:52 - 001015880 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2017-08-13 10:22 - 2014-03-22 20:35 - 000146704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys 2017-08-13 10:10 - 2014-06-30 13:11 - 000000000 ____D C:\Users\Sonia & Jasper\AppData\Local\Adobe 2017-08-13 10:07 - 2017-01-20 01:29 - 000000000 ____D C:\Program Files (x86)\Dropbox 2017-08-13 09:50 - 2013-03-25 11:37 - 000000000 ____D C:\Users\Sonia & Jasper\AppData\Local\CrashDumps 2017-08-10 09:56 - 2013-08-05 23:25 - 000000000 ____D C:\Windows\system32\MRT 2017-08-10 09:49 - 2012-05-30 01:54 - 000000000 ____D C:\Users\UpdatusUser 2017-08-10 09:36 - 2013-03-06 23:47 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-08-10 09:35 - 2013-03-06 23:47 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-08-10 09:35 - 2013-03-06 23:47 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-08-10 09:34 - 2013-03-06 23:47 - 000000000 ____D C:\Windows\system32\Macromed 2017-08-10 09:33 - 2012-05-30 02:22 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2017-08-10 09:13 - 2016-02-11 15:13 - 000000000 ____D C:\Users\Sonia & Jasper\Documents\Bluetooth Folder 2017-08-10 08:17 - 2013-08-04 10:08 - 140394280 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-08-10 07:53 - 2013-07-30 22:54 - 000000942 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1535155601-2421706697-1459365258-1001Core.job 2017-08-08 18:03 - 2017-03-19 11:04 - 000004174 _____ C:\Windows\System32\Tasks\Avast Emergency Update 2017-08-08 09:44 - 2012-05-30 02:32 - 000002194 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-08-08 09:44 - 2012-05-30 02:31 - 000002206 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-08-06 11:31 - 2014-12-26 17:22 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-08-04 22:41 - 2013-03-20 22:44 - 000000000 ____D C:\Users\Sonia & Jasper\AppData\Roaming\vlc 2017-08-03 19:08 - 2013-03-08 23:37 - 000000000 ____D C:\ProgramData\Skype 2017-08-03 19:03 - 2013-11-29 10:31 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-08-03 19:01 - 2013-11-29 10:27 - 000000000 ____D C:\Program Files\Microsoft Office 15 2017-07-30 09:31 - 2017-07-13 09:54 - 000343288 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys 2017-07-30 09:31 - 2017-07-13 09:54 - 000320008 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys 2017-07-30 09:31 - 2017-07-13 09:54 - 000198976 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys 2017-07-30 09:31 - 2017-07-13 09:54 - 000057728 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys 2017-07-30 09:31 - 2014-03-22 20:35 - 000146664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys.150139996785403 2017-07-25 13:05 - 2014-02-20 08:14 - 000002197 _____ C:\Users\Sonia & Jasper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk ==================== Files in the root of some directories ======= 2013-03-24 16:30 - 2016-02-22 14:37 - 000000321 _____ () C:\Users\Sonia & Jasper\AppData\Roaming\burnaware.ini 2017-07-13 09:22 - 2017-07-13 09:22 - 000000000 ____H () C:\Users\Sonia & Jasper\AppData\Local\BIT258E.tmp 2014-03-17 15:36 - 2014-03-17 16:25 - 000006144 _____ () C:\Users\Sonia & Jasper\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-07-13 09:21 - 2017-07-13 09:21 - 000000000 _____ () C:\Users\Sonia & Jasper\AppData\Local\{32CE500F-8897-41B1-B8BB-BC60DF6AC0A4} 2017-07-17 08:56 - 2017-07-17 08:56 - 000000000 _____ () C:\Users\Sonia & Jasper\AppData\Local\{50CE23CA-5E41-43FE-9C0B-C7A11A1A23F8} 2016-05-07 21:58 - 2016-05-07 21:58 - 000000000 _____ () C:\Users\Sonia & Jasper\AppData\Local\{7865AA16-89BB-47AB-9503-94BD43ADB615} Some files in TEMP: ==================== 2014-08-06 17:47 - 2014-08-06 17:47 - 000157696 _____ () C:\Users\Sonia & Jasper\AppData\Local\Temp\ERUNT.exe 2015-04-29 12:32 - 2016-03-10 09:28 - 047362176 _____ (Skype Technologies S.A.) C:\Users\Sonia & Jasper\AppData\Local\Temp\SkypeSetup.exe 2015-08-14 14:29 - 2015-07-29 22:08 - 000681097 _____ (SQLite Development Team) C:\Users\Sonia & Jasper\AppData\Local\Temp\sqlite3.dll 2017-03-15 21:28 - 2017-03-15 21:28 - 014456872 _____ (Microsoft Corporation) C:\Users\Sonia & Jasper\AppData\Local\Temp\vc_redist.x86.exe 2016-02-07 14:36 - 2016-02-07 14:36 - 028849904 _____ () C:\Users\Sonia & Jasper\AppData\Local\Temp\vlc-2.2.1-win32.exe 2016-09-16 17:16 - 2016-09-16 17:16 - 030533688 _____ () C:\Users\Sonia & Jasper\AppData\Local\Temp\vlc-2.2.4-win32.exe 2017-08-04 16:11 - 2017-08-04 16:11 - 030950664 _____ () C:\Users\Sonia & Jasper\AppData\Local\Temp\vlc-2.2.6-win32.exe 2015-08-12 01:40 - 2015-08-12 02:56 - 000000000 _____ () C:\Users\Sonia & Jasper\AppData\Local\Temp\{82E7C71E-75F3-4D84-AB84-DB87EC9FE8C3}-44.0.2403.155_44.0.2403.130_chrome_updater.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-08-03 20:45 ==================== End of FRST.txt ============================