Jump to content


Photo

This network may require you to login to use the internet.


  • This topic is locked This topic is locked
16 replies to this topic

#1 QT Pro

QT Pro

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 26 July 2017 - 01:05 PM

On the top of every page I open I have an information bar with the message "This network may require you to login to use the internet." on the left and a button saying "Show Login Page" on the right. I am already connected to the internet and always have been so am nervous to click on the "Show Login Page" button in case it is a trick to make me download something nasty. Has anyone else seen this before because it is very new to me?

Also, I never used to have any problem entering addresses like google.com into the address bar but since the last 3 days I am getting weird messages instead of the genuine web page. Any ideas how I may be able to stop this please?
 
The only security software I use are: Comodo Internet Security Premium, HitmanPro, and Hitman Pro Alert.
 
icedragon1.jpg
 

EDIT: Please read the Instructions http://www.spywarein...showtopic=79038 and post logs...  Our helpers need details to review in order to help...


Edited by Budfred, 26 July 2017 - 03:41 PM.


#2 QT Pro

QT Pro

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 27 July 2017 - 05:04 AM

Sorry about that. I figured that as I use Hitman Pro Alert instead of MalwareBytes you would not require the latter to be run and end up asking for an HMP log.
Anyway, here are the details you requested:

1. MalwareBytes Scan

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 7/27/17
Scan Time: 11:06 AM
Log File: MWB scan.txt
Administrator: Yes

-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.160
Update Package Version: 1.0.2447
License: Trial

-System Information-
OS: Windows 10 (Build 14393.1480)
CPU: x64
File System: NTFS
User: QTP-BOLLOX\QT Pro

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 392093
Threats Detected: 11
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 2 min, 30 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 4
PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\AUSLOGICS\Disk Defrag Prof, No Action By User, [1815], [383224],1.0.2447
PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{038F4196-36EF-4E91-92ED-B71DE2CF9D10}, No Action By User, [1815], [383225],1.0.2447
PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{BB395229-47F7-442C-BE43-50C48AB50BB7}, No Action By User, [1815], [383225],1.0.2447
PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F00F0BC9-35A4-4F7C-950D-1F70E7C5D206}, No Action By User, [1815], [383225],1.0.2447

Registry Value: 3
PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{038F4196-36EF-4E91-92ED-B71DE2CF9D10}|PATH, No Action By User, [1815], [383225],1.0.2447
PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{BB395229-47F7-442C-BE43-50C48AB50BB7}|PATH, No Action By User, [1815], [383225],1.0.2447
PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F00F0BC9-35A4-4F7C-950D-1F70E7C5D206}|PATH, No Action By User, [1815], [383225],1.0.2447

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 1
PUP.Optional.AuslogicsDiskDefrag, C:\WINDOWS\SYSTEM32\TASKS\AUSLOGICS\Disk Defrag Prof, No Action By User, [1815], [383212],1.0.2447

File: 3
PUP.Optional.AuslogicsDiskDefrag, C:\Windows\System32\Tasks\Auslogics\Disk Defrag Prof\Task {00000001-23D5-4570-B960-E181CA8266C7} for QT Pro, No Action By User, [1815], [383212],1.0.2447
PUP.Optional.AuslogicsDiskDefrag, C:\Windows\System32\Tasks\Auslogics\Disk Defrag Prof\Task {00000001-5A17-4000-BA58-9CC921694207} for QT Pro, No Action By User, [1815], [383212],1.0.2447
PUP.Optional.AuslogicsDiskDefrag, C:\Windows\System32\Tasks\Auslogics\Disk Defrag Prof\Task {00000001-7CA8-4EE0-8E5B-B37C3CDD981D} for QT Pro, No Action By User, [1815], [383212],1.0.2447

Physical Sector: 0
(No malicious items detected)

(end)

 

2. FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-07-2017
Ran by QT Pro (administrator) on QTP-BOLLOX (27-07-2017 11:48:04)
Running from C:\Users\QT Pro\Downloads\Security
Loaded Profiles: QT Pro (Available Profiles: defaultuser0 & QT Pro)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\Comodo\IceDragon\icedragon.exe" -osint -url "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\igfxCUIService.exe
(SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Windows ® Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\IntelCpHDCPSvc.exe
(Alienware) C:\Program Files\Alienware\Graphics Amplifier\GraphicsAmplifierWindowsService.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Nitro Software, Inc.) C:\Program Files\Nitro\Pro 11\NitroPDFDriverService11x64.exe
() C:\Program Files (x86)\Eaton\UPSCompanion\mc2.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe
(Rivet Networks) C:\Program Files\Killer Networking\Killer Control Center\KillerNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
() C:\Program Files (x86)\Acrylic DNS Proxy\AcrylicService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
() C:\Program Files (x86)\Comodo\IceDragon\icedragon_updater.exe
(Horizon DataSys Inc) C:\Program Files\Shield\ShdServ.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\WsxService.exe
(Tobii AB) C:\Program Files (x86)\Tobii\Service\Tobii.Service.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Tobii AB) C:\Program Files (x86)\Tobii\Tobii EyeX\Tobii.EyeX.Engine.exe
(Tobii AB) C:\Program Files (x86)\Tobii\Tobii EyeX Interaction\Tobii.EyeX.Tray.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Tobii AB) C:\Program Files (x86)\Tobii\Tobii EyeX Interaction\Tobii.EyeX.Interaction.exe
(DeskSoft) C:\Program Files (x86)\WindowManager\WindowManager.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\igfxEM.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\Nexus-Ultimate.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(A-Volute) C:\Program Files\Alienware\AWSoundCenter\UserInterface\AWSoundCenterUILauncher.exe
() C:\Windows\System\3DG4me.exe
() C:\Program Files\Alienware\AWSoundCenter\UserInterface\AWSoundCenterSvc32.exe
() C:\Program Files\Alienware\AWSoundCenter\UserInterface\x64\AWSoundCenterSvc64.exe
() C:\Users\QT Pro\Downloads\Utilities\NoSleepHDv2.0\NoSleepHDv2.0.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareTactXMacroController.exe
(Horizon DataSys Inc) C:\Program Files\Shield\ShdTray.exe
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Inc.) C:\Program Files (x86)\Dell Customer Connect\DCCService.exe
(Dell) C:\Program Files\Alienware\Dell Foundation Services\DFSSvc.exe
() C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe
(Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(Dell Inc.) C:\Program Files (x86)\Alienware Update\DellUpService.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Dell Inc.) C:\Program Files (x86)\Alienware Update\DellUpTray.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Dell) C:\Program Files\Alienware\Alienware Product Registration\PRSvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
(Dell) C:\Users\QT Pro\AppData\Local\Apps\2.0\TRE1YDB8.147\ZKC0ME0E.RL4\dell..tion_831211ca63b981c5_0008.0005_9a48d74816d64e41\DellSystemDetect.exe
(Rivet Networks) C:\Program Files\Killer Networking\Killer Control Center\KillerControlCenter.exe
(Alienware Corp.) C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
() C:\Program Files (x86)\Eaton\UPSCompanion\mc2.exe
(Ergonis Software) C:\Program Files\Ergonis\PopChar\PopChar.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\TscHelp.exe
(Quick And Easy Software) C:\Users\QT Pro\Downloads\Utilities\USB.Disk.Ejector.v1.3.0.3\USB_Disk_Eject.exe
(Kirby Software) C:\Program Files (x86)\Kirby Alarm Pro\kirbyalarmpro.exe
(Firetrust) C:\Program Files (x86)\Firetrust\MailWasher\MailWasherPro.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\nvapiw.exe
(Klim & Co limited ) C:\Program Files\KLIM AIM Gaming Mouse\KLIM AIM Gaming Mouse.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagitEditor.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Dell) C:\Program Files\Alienware\Dell Foundation Services\DFS.Common.Agent.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1705.1301.0_x64__8wekyb3d8bbwe\Calculator.exe
() C:\Program Files\WindowsApps\Microsoft.BingWeather_4.20.1102.0_x64__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(ZabKat) C:\Program Files\zabkat\xplorer2\xplorer2.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [GraphicsAmplifierSW] => [X]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9218568 2017-05-05] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493000 2017-05-05] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1489088 2017-07-11] (COMODO)
HKLM\...\Run: [Command Center Controllers] => C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [13856 2017-03-21] (Alienware)
HKLM\...\Run: [AWSoundCenterUILauncher] => C:\Program Files\Alienware\AWSoundCenter\UserInterface\AWSoundCenterUILauncher.exe [1230008 2017-03-10] (A-Volute)
HKLM\...\Run: [3DG4me] => C:\Windows\System\3DG4me.exe [126976 2015-10-05] ()
HKLM\...\Run: [NoSleepHD] => C:\Users\QT Pro\Downloads\Utilities\NoSleepHDv2.0\NoSleepHDv2.0.exe [110080 2009-04-11] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [320584 2017-03-24] (Intel Corporation)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft)
HKLM\...\Run: [Shield] => C:\Program Files\Shield\shdtray.exe [83904 2017-07-15] (Horizon DataSys Inc)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [AlienwareOn-ScreenDisplay] => C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe [3747256 2016-12-02] (Alienware Corp.)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2016-02-03] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [1944576 2013-03-07] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [Eaton Systray Launcher] => C:\Program Files (x86)\Eaton\UPSCompanion\mc2.exe [2806176 2017-07-12] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-12] (Oracle Corporation)
HKLM-x32\...\RunOnce: [Winstep SpeedLaunch] => C:\Program Files (x86)\Winstep\winstep.exe [808448 2017-01-10] (Winstep Software Technologies)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110376 2017-06-11] (Siber Systems)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [FileHippo.com] => C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe [10566352 2015-09-02] ()
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545056 2017-02-14] (Skype Technologies S.A.)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [OSDownloaderUpdate] => C:\Program Files (x86)\OSDownloader\OSDownloaderUpdate.exe [3921920 2017-03-22] (Opensubtitles.org)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [Nexus] => [X]
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [Nexus-Ultimate] => C:\Program Files (x86)\Winstep\Nexus-Ultimate.exe [15838336 2017-01-27] (Winstep Software Technologies)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [DellSystemDetect] => C:\Users\QT Pro\AppData\Local\Apps\2.0\TRE1YDB8.147\ZKC0ME0E.RL4\dell..tion_831211ca63b981c5_0008.0005_9a48d74816d64e41\DellSystemDetect.exe [313264 2017-06-21] (Dell)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\RunOnce: [Uninstall 17.3.6917.0607\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\QT Pro\AppData\Local\Microsoft\OneDrive\17.3.6917.0607\amd64"
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\RunOnce: [Uninstall 17.3.6917.0607] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\QT Pro\AppData\Local\Microsoft\OneDrive\17.3.6917.0607"
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Winlogon: [Shell] - <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Control Center.lnk [2017-05-24]
ShortcutTarget: Killer Control Center.lnk -> C:\Program Files\Killer Networking\Killer Control Center\KillerControlCenter.exe (Rivet Networks)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PopChar.lnk [2017-06-16]
ShortcutTarget: PopChar.lnk -> C:\Program Files\Ergonis\PopChar\PopChar.exe (Ergonis Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 12.lnk [2017-06-11]
ShortcutTarget: Snagit 12.lnk -> C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe (TechSmith Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\USB_Disk_Eject.lnk [2017-06-12]
ShortcutTarget: USB_Disk_Eject.lnk -> C:\Users\QT Pro\Downloads\Utilities\USB.Disk.Ejector.v1.3.0.3\USB_Disk_Eject.exe (Quick And Easy Software)
Startup: C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kirby Alarm Pro.lnk [2017-06-11]
ShortcutTarget: Kirby Alarm Pro.lnk -> C:\Program Files (x86)\Kirby Alarm Pro\kirbyalarmpro.exe (Kirby Software)
Startup: C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MailWasherPro.lnk [2017-06-11]
ShortcutTarget: MailWasherPro.lnk -> C:\Program Files (x86)\Firetrust\MailWasher\MailWasherPro.exe (Firetrust)
BootExecute:

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.5.1
Tcpip\..\Interfaces\{cacb34c7-a8b1-4c54-9cc0-7f7e4ad078a4}: [DhcpNameServer] 192.168.5.1

Internet Explorer:
==================
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://dell17win10.msn.com/?pc=DCTE
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.alienwarearena.com/welcome-us
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2017-07-06] (Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-06-11] (Siber Systems Inc.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_141\bin\ssv.dll [2017-07-19] (Oracle Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-07-16] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_141\bin\jp2ssv.dll [2017-07-19] (Oracle Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2016-07-30] (IvoSoft)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2017-06-20] (Microsoft Corporation)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-06-11] (Siber Systems Inc.)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2017-07-16] (Microsoft Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-06-11] (Siber Systems Inc.)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-06-11] (Siber Systems Inc.)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: a7ddyvk1.default
FF ProfilePath: C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default [2017-07-25]
FF DefaultSearchEngine: Comodo\IceDragon\Profiles\a7ddyvk1.default -> Yahoo! FR
FF Homepage: Comodo\IceDragon\Profiles\a7ddyvk1.default -> hxxps://zerohedge.com
FF Session Restore: Comodo\IceDragon\Profiles\a7ddyvk1.default -> is enabled.
FF Extension: (Add to Search Bar) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\add-to-searchbox@maltekraus.de.xpi [2017-06-10]
FF Extension: (Classic Theme Restorer) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2017-06-10]
FF Extension: (colorPicker) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\colorPicker@colorPicker.xpi [2017-06-10]
FF Extension: (Classic Toolbar Buttons) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2017-06-10]
FF Extension: (YouTubeâ„¢ Enhancer Plus) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\firefoxaddon@youtubeenhancer.com.xpi [2017-06-10]
FF Extension: (Dictionnaire français) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\fr-dicollecte@dictionaries.addons.mozilla.org [2017-06-16]
FF Extension: (HTTPS Everywhere) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\https-everywhere@eff.org.xpi [2017-06-10]
FF Extension: (Italian dictionary) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\it-IT@dictionaries.addons.mozilla.org [2017-06-16]
FF Extension: (Google search link fix) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\jid0-XWJxt5VvCXkKzQK99PhZqAn7Xbg@jetpack.xpi [2017-06-10]
FF Extension: (I don't care about cookies) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\jid1-KKzOGWgsW3Ao4Q@jetpack.xpi [2017-06-10]
FF Extension: (RT News) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\jid1-ReWlW1efOwaQJQ@jetpack.xpi [2017-06-10]
FF Extension: (Dorando keyconfig) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\keyconfig@mozilla.dorando.at.xpi [2017-06-10]
FF Extension: (S3.Google Translator) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\s3google@translator.xpi [2017-06-10]
FF Extension: (Saved Password Editor) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\savedpasswordeditor@daniel.dawson.xpi [2017-06-10]
FF Extension: (Super Start) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\superstart@enjoyfreeware.org [2017-06-10]
FF Extension: (The Addon Bar (restored)) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\the-addon-bar@GeekInTraining-GiT.xpi [2017-06-10]
FF Extension: (Beyond Australis) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\thefoxonlybetter@quicksaver.xpi [2017-06-10]
FF Extension: (Thumbnail Zoom Plus) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\thumbnailZoom@dadler.github.com.xpi [2017-06-10]
FF Extension: (NoSquint Plus) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\zoomlevelplus@zoomlevelplus.net.xpi [2017-06-10]
FF Extension: (FlashGot) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2017-06-30]
FF Extension: (RoboForm Toolbar) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{22119944-ED35-4ab1-910B-E619EA06A115} [2017-06-11]
FF Extension: (ColorZilla) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}.xpi [2017-06-10]
FF Extension: (Download Status Bar) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2017-06-10]
FF Extension: (NoScript) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2017-06-10]
FF Extension: (FT DeepDark) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2017-06-25]
FF Extension: (YouTube High Definition) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2017-06-10]
FF Extension: (Adblock Plus) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-10]
FF Extension: (BetterPrivacy) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2017-06-10]
FF Extension: (COMODO SecureBox) - C:\Program Files (x86)\Comodo\IceDragon\browser\features\@csb [2017-07-25] [not signed]
FF Extension: (DragAndDrop) - C:\Program Files (x86)\Comodo\IceDragon\browser\features\DnD@comodo.com [2017-07-25] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_137.dll [2017-07-11] ()
FF Plugin: @java.com/DTPlugin,version=11.141.2 -> C:\Program Files\Java\jre1.8.0_141\bin\dtplugin\npDeployJava1.dll [2017-07-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.141.2 -> C:\Program Files\Java\jre1.8.0_141\bin\plugin2\npjp2.dll [2017-07-19] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-06-20] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.5.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_137.dll [2017-07-11] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-06-20] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2017-06-20] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll [2013-07-26] (Nitro PDF)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-02-13] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-02-13] (NVIDIA Corporation)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AcrylicServiceController; C:\Program Files (x86)\Acrylic DNS Proxy\AcrylicService.exe [646144 2016-11-03] () [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [338312 2016-09-07] (Windows ® Win 7 DDK provider)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4412104 2017-07-18] (Microsoft Corporation)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [10501104 2017-07-11] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2876096 2017-07-11] (COMODO)
R3 cphs; C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\IntelCpHeciSvc.exe [285696 2017-04-10] (Intel Corporation)
R2 cplspcon; C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\IntelCpHDCPSvc.exe [463360 2017-04-10] (Intel Corporation)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [206712 2017-06-20] (Dell Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3296632 2017-06-20] (Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217464 2017-06-20] (Dell Inc.)
R2 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [132472 2016-09-09] (Dell Inc.)
R2 Dell Foundation Services; C:\Program Files\Alienware\Dell Foundation Services\DFSSvc.exe [97616 2017-01-11] (Dell)
R2 DellUpdate; C:\Program Files (x86)\Alienware Update\DellUpService.exe [230248 2017-05-01] (Dell Inc.)
R2 Eaton UPSCompanion; C:\Program Files (x86)\Eaton\UPSCompanion\mc2.exe [2806176 2017-07-12] ()
R2 esifsvc; C:\Windows\system32\Intel\DPTF\esif_uf.exe [2208888 2016-09-02] (Intel Corporation)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R2 GraphicsAmplifierWindowsService; C:\Program Files\Alienware\Graphics Amplifier\GraphicsAmplifierWindowsService.exe [14392 2016-11-15] (Alienware)
S3 HitmanPro37Crusader; C:\Program Files\HitmanPro\HitmanPro.exe [11584088 2017-07-25] (SurfRight B.V.)
S2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [135488 2017-07-25] (SurfRight B.V.)
R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [4853384 2017-07-22] (SurfRight B.V.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [17992 2017-03-24] (Intel Corporation)
R2 IceDragonUpdater; C:\Program Files (x86)\Comodo\IceDragon\icedragon_updater.exe [4295328 2017-05-24] ()
R2 igfxCUIService2.0.0.0; C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\igfxCUIService.exe [324096 2017-04-10] (Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-07-27] (Intel® Corporation)
S3 ioloEnergyBooster; C:\Program Files\Alienware\Command Center\ioloEnergyBooster.exe [6145872 2012-11-01] (iolo technologies, LLC)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [177440 2016-09-15] (Intel Corporation)
R2 Killer Network Service; C:\Program Files\Killer Networking\Killer Control Center\KillerNetworkService.exe [2010336 2016-11-02] (Rivet Networks)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 NitroDriverReadSpool11; C:\Program Files\Nitro\Pro 11\NitroPDFDriverService11x64.exe [327368 2016-12-08] (Nitro Software, Inc.)
R2 NitroReaderDriverReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [230416 2013-07-26] (Nitro PDF Software)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2017-02-09] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2017-02-09] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2017-02-13] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [427064 2017-02-09] (NVIDIA Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1450824 2017-07-17] (Overwolf LTD)
R2 Product Registration; C:\Program Files\Alienware\Alienware Product Registration\PRSvc.exe [47144 2017-04-06] (Dell)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [333328 2017-05-05] (Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2017-05-24] (Microsoft Corporation)
R2 ShdServ; C:\Program Files\Shield\shdserv.exe [308672 2017-07-15] (Horizon DataSys Inc)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [52696 2017-06-28] (Dell Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [252504 2016-09-20] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10803440 2017-07-18] (TeamViewer GmbH)
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
S3 ThunderboltService; c:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe [2015968 2016-08-15] (Intel Corporation)
R2 Tobii Service; C:\Program Files (x86)\Tobii\Service\Tobii.Service.exe [197696 2017-05-30] (Tobii AB)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation)
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [40936 2017-06-02] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [831992 2017-06-02] (COMODO)
R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [50776 2017-06-02] (COMODO)
R3 DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [32960 2017-04-11] (Dell Inc.)
R3 DellProf; C:\Windows\system32\drivers\DellProf.sys [32568 2017-04-11] (Dell Computer Corporation)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 dptf_acpi; C:\Windows\System32\drivers\dptf_acpi.sys [71232 2016-08-13] (Intel Corporation)
R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [66624 2016-08-13] (Intel Corporation)
R0 EMSC; C:\Windows\System32\drivers\EMSC.SYS [35216 2016-08-19] ()
R3 esif_lf; C:\Windows\system32\DRIVERS\esif_lf.sys [350272 2016-08-13] (Intel Corporation)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77376 2017-06-27] ()
R3 HidEventFilter; C:\Windows\System32\drivers\HidEventFilter.sys [54800 2016-08-16] (Intel Corporation)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [55232 2017-07-26] ()
R1 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [253048 2017-07-22] (SurfRight B.V.)
R3 hmpnet; C:\Windows\system32\drivers\hmpnet.sys [93800 2017-07-22] (SurfRight B.V.)
R3 igfx; C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\igdkmd64.sys [11070440 2017-04-10] (Intel Corporation)
R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [132880 2017-06-07] (COMODO)
R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115448 2013-11-21] (EZB Systems, Inc.)
R3 KillerEth; C:\Windows\System32\drivers\e2xw10x64.sys [162120 2016-09-16] (Qualcomm Atheros, Inc.)
R3 kiox_ff_driver; C:\Windows\system32\DRIVERS\kiox_ff_driver.sys [50312 2016-09-21] (Kionix, Inc.)
R0 kxdiskprot; C:\Windows\System32\DRIVERS\kxdiskprot.sys [38544 2016-06-13] (Kionix, Inc.)
S3 libusb0; C:\Windows\system32\DRIVERS\libusb0.sys [51848 2017-07-12] (hxxp://libusb-win32.sourceforge.net)
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [188352 2017-07-27] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [101784 2017-07-27] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [45472 2017-07-27] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [253856 2017-07-27] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [93600 2017-07-27] (Malwarebytes)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_311b72236e1161dc\nvlddmkm.sys [14320056 2017-02-15] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [29240 2017-02-09] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47672 2017-02-09] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [59448 2017-02-09] (NVIDIA Corporation)
R3 Qcamain10x64; C:\Windows\system32\DRIVERS\Qcamain10x64.sys [2412976 2017-04-15] (Qualcomm Atheros, Inc.)
R2 RfeCoSvc; C:\Windows\system32\DRIVERS\RfeCo10X64.sys [89440 2016-11-02] (Rivet Networks, LLC.)
R0 Shdbus; C:\Windows\System32\DRIVERS\Shdbus.sys [30544 2017-07-15] (Horizon DataSys Inc) [File not signed]
R0 Shield; C:\Windows\System32\DRIVERS\shield.sys [117072 2017-07-15] (Horizon DataSys Inc) [File not signed]
R0 Shieldf; C:\Windows\System32\DRIVERS\Shieldf.sys [35664 2017-07-15] (Horizon DataSys Inc) [File not signed]
R0 Shieldm; C:\Windows\System32\DRIVERS\Shieldm.sys [36176 2017-07-15] (Horizon DataSys Inc) [File not signed]
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [63576 2016-09-20] (Synaptics Incorporated)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 USBADVAU; C:\Windows\system32\drivers\cm11264.sys [1308160 2010-04-23] (C-Media Electronics Inc)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-27 11:47 - 2017-07-27 11:48 - 00000000 ____D C:\FRST
2017-07-27 11:45 - 2017-07-27 11:45 - 00003129 _____ C:\Users\QT Pro\Desktop\MWB log.txt
2017-07-27 11:44 - 2017-07-27 11:44 - 00003130 _____ C:\Users\QT Pro\Desktop\MWB scan.txt
2017-07-27 11:03 - 2017-07-27 11:08 - 00093600 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-07-27 11:03 - 2017-07-27 11:03 - 00253856 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-07-27 11:03 - 2017-07-27 11:03 - 00188352 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-07-27 11:03 - 2017-07-27 11:03 - 00101784 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-07-27 11:03 - 2017-07-27 11:03 - 00045472 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-07-27 11:03 - 2017-07-27 11:03 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-07-27 11:03 - 2017-07-27 11:03 - 00000000 ____D C:\Program Files\Malwarebytes
2017-07-27 11:03 - 2017-06-27 12:06 - 00077376 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-07-27 10:52 - 2017-07-26 10:44 - 00000001 ____R C:\Windows\system32\perfc.dat
2017-07-27 09:36 - 2017-07-27 09:36 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2017-07-27 09:04 - 2017-07-27 09:04 - 00003368 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-788432544-2185739174-1534461968-1001
2017-07-27 09:04 - 2017-07-27 09:04 - 00002410 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-07-26 19:51 - 2017-07-26 19:51 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
2017-07-26 19:51 - 2017-07-26 19:51 - 00000194 _____ C:\Windows\system32\bootdelete.lst
2017-07-26 10:45 - 2017-07-26 10:44 - 00000001 ____R C:\Windows\perfc.dat
2017-07-25 19:30 - 2017-07-25 19:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2017-07-25 18:38 - 2017-07-25 18:38 - 00001044 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2017-07-25 16:26 - 2017-07-25 16:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet
2017-07-25 16:24 - 2017-07-27 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security
2017-07-25 16:15 - 2017-07-25 16:15 - 00001168 _____ C:\Windows\system32\.crusader
2017-07-25 15:53 - 2017-07-26 19:43 - 00055232 _____ C:\Windows\system32\Drivers\hitmanpro37.sys
2017-07-25 15:41 - 2017-07-25 15:42 - 00000000 ____D C:\Program Files\HitmanPro
2017-07-22 18:19 - 2017-07-22 18:19 - 00918664 _____ (SurfRight B.V.) C:\Windows\system32\hmpalert.dll
2017-07-22 18:19 - 2017-07-22 18:19 - 00843400 _____ (SurfRight B.V.) C:\Windows\SysWOW64\hmpalert.dll
2017-07-22 18:19 - 2017-07-22 18:19 - 00253048 _____ (SurfRight B.V.) C:\Windows\system32\Drivers\hmpalert.sys
2017-07-22 18:19 - 2017-07-22 18:19 - 00093800 _____ (SurfRight B.V.) C:\Windows\system32\Drivers\hmpnet.sys
2017-07-22 18:19 - 2017-07-22 18:19 - 00000000 ____D C:\Program Files (x86)\HitmanPro.Alert
2017-07-19 19:02 - 2017-02-27 07:12 - 108640066 _____ C:\Users\QT Pro\Downloads\Les Réseaux pour les Nuls.pdf
2017-07-19 17:00 - 2017-07-19 17:00 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2017-07-19 13:19 - 2017-07-19 13:19 - 00001175 _____ C:\Users\QT Pro\Documents\Winstep.lnk
2017-07-19 12:11 - 2017-07-19 12:11 - 00110144 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2017-07-15 21:04 - 2017-07-15 21:04 - 00000000 ____D C:\Program Files\EZ CD Audio Converter
2017-07-15 08:26 - 2017-07-15 08:26 - 00117072 ____N (Horizon DataSys Inc) C:\Windows\system32\Drivers\shield.sys
2017-07-15 08:26 - 2017-07-15 08:26 - 00036176 ____N (Horizon DataSys Inc) C:\Windows\system32\Drivers\shieldm.sys
2017-07-15 08:26 - 2017-07-15 08:26 - 00035664 ____N (Horizon DataSys Inc) C:\Windows\system32\Drivers\shieldf.sys
2017-07-15 08:26 - 2017-07-15 08:26 - 00031680 ____N (Horizon DataSys Inc) C:\Windows\system32\shdsync.exe
2017-07-15 08:26 - 2017-07-15 08:26 - 00030544 ____N (Horizon DataSys Inc) C:\Windows\system32\Drivers\shdbus.sys
2017-07-14 11:12 - 2017-07-14 11:13 - 00000000 ____D C:\Program Files (x86)\Resource Hacker
2017-07-13 11:11 - 2017-07-26 21:02 - 00000000 ____D C:\Users\QT Pro\AppData\Local\ClassicShell
2017-07-13 11:10 - 2017-07-13 11:10 - 00000000 ____D C:\Users\QT Pro\AppData\Roaming\ClassicShell
2017-07-13 11:10 - 2017-07-13 11:10 - 00000000 ____D C:\ProgramData\ClassicShell
2017-07-13 11:06 - 2017-07-13 11:07 - 00000000 ____D C:\Program Files\Classic Shell
2017-07-13 09:32 - 2017-07-11 13:44 - 00942280 _____ (COMODO) C:\Windows\system32\guard64.dll
2017-07-13 09:32 - 2017-07-11 13:44 - 00732944 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll
2017-07-13 09:32 - 2017-06-07 22:47 - 00132880 _____ (COMODO) C:\Windows\system32\Drivers\inspect.sys
2017-07-13 09:32 - 2017-06-02 04:48 - 00831992 _____ (COMODO) C:\Windows\system32\Drivers\cmdguard.sys
2017-07-13 09:32 - 2017-06-02 04:48 - 00050776 _____ (COMODO) C:\Windows\system32\Drivers\cmdhlp.sys
2017-07-13 09:32 - 2017-06-02 04:48 - 00040936 _____ (COMODO) C:\Windows\system32\Drivers\cmderd.sys
2017-07-12 20:22 - 2017-07-12 20:22 - 00002081 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Powerpoint.lnk
2017-07-12 20:22 - 2017-07-12 20:22 - 00002062 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Word.lnk
2017-07-12 20:22 - 2017-07-12 20:22 - 00002038 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Publisher.lnk
2017-07-12 20:22 - 2017-07-12 20:22 - 00002038 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EXCEL.lnk
2017-07-12 19:43 - 2017-07-19 20:43 - 00000000 ____D C:\Users\QT Pro\Downloads\Android
2017-07-12 12:23 - 2017-07-12 12:23 - 00000000 ____D C:\Users\QT Pro\AppData\Roaming\Eaton
2017-07-12 12:22 - 2017-07-12 12:22 - 00051848 _____ (hxxp://libusb-win32.sourceforge.net) C:\Windows\system32\Drivers\libusb0.sys
2017-07-12 12:22 - 2017-07-12 12:22 - 00001454 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Eaton Notifier.lnk
2017-07-12 12:22 - 2017-07-12 12:22 - 00000000 ____D C:\Program Files (x86)\Eaton
2017-07-12 10:39 - 2017-07-27 09:01 - 00004158 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C0FF1E0A-0626-43AE-8AFF-970EDAFB9EB4}
2017-07-12 07:30 - 2017-06-30 16:46 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-07-12 07:30 - 2017-06-30 16:46 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-07-12 07:28 - 2017-07-07 09:49 - 00340824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-07-12 07:28 - 2017-07-07 09:46 - 00781152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2017-07-12 07:28 - 2017-07-07 09:45 - 02263832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-07-12 07:28 - 2017-07-07 09:29 - 05686272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2017-07-12 07:28 - 2017-07-07 09:13 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupShim.dll
2017-07-12 07:28 - 2017-07-07 09:10 - 00755200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-07-12 07:28 - 2017-07-07 09:09 - 00506368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-07-12 07:28 - 2017-07-07 09:06 - 07626752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-07-12 07:28 - 2017-07-07 08:54 - 02997248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2017-07-12 07:28 - 2017-07-07 08:53 - 02483200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-07-12 07:28 - 2017-07-07 08:52 - 01599488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-07-12 07:28 - 2017-06-21 09:42 - 00601712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-07-12 07:28 - 2017-06-21 09:39 - 02048496 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2017-07-12 07:28 - 2017-06-21 09:29 - 05722320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2017-07-12 07:28 - 2017-06-21 09:28 - 01504056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-07-12 07:28 - 2017-06-21 09:27 - 01431232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2017-07-12 07:28 - 2017-06-21 09:27 - 00975744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2017-07-12 07:28 - 2017-06-21 09:27 - 00861024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2017-07-12 07:28 - 2017-06-21 09:27 - 00116576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostCommon.dll
2017-07-12 07:28 - 2017-06-21 09:25 - 02168288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2017-07-12 07:28 - 2017-06-21 09:24 - 00846560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2017-07-12 07:28 - 2017-06-21 09:22 - 00361104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
2017-07-12 07:28 - 2017-06-21 09:21 - 06665440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-07-12 07:28 - 2017-06-21 09:21 - 04023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2017-07-12 07:28 - 2017-06-21 09:21 - 01845512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2017-07-12 07:28 - 2017-06-21 09:21 - 01277856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2017-07-12 07:28 - 2017-06-21 09:20 - 01360464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2017-07-12 07:28 - 2017-06-21 09:20 - 00981888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2017-07-12 07:28 - 2017-06-21 09:20 - 00962768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-07-12 07:28 - 2017-06-21 09:19 - 04312248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-07-12 07:28 - 2017-06-21 09:04 - 01631232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-07-12 07:28 - 2017-06-21 09:04 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcconf.dll
2017-07-12 07:28 - 2017-06-21 09:01 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Radios.dll
2017-07-12 07:28 - 2017-06-21 09:00 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDeviceRegistration.dll
2017-07-12 07:28 - 2017-06-21 08:59 - 00285184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-07-12 07:28 - 2017-06-21 08:59 - 00255488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unimdm.tsp
2017-07-12 07:28 - 2017-06-21 08:59 - 00177664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Diagnostics.dll
2017-07-12 07:28 - 2017-06-21 08:59 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.HostName.dll
2017-07-12 07:28 - 2017-06-21 08:59 - 00097792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.SystemManagement.dll
2017-07-12 07:28 - 2017-06-21 08:58 - 00136192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinRtTracing.dll
2017-07-12 07:28 - 2017-06-21 08:58 - 00129024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SerialCommunication.dll
2017-07-12 07:28 - 2017-06-21 08:58 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll
2017-07-12 07:28 - 2017-06-21 08:58 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-07-12 07:28 - 2017-06-21 08:58 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.UserDeviceAssociation.dll
2017-07-12 07:28 - 2017-06-21 08:57 - 00142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFi.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 00392192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Input.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 00315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncSettings.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 00184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2017-07-12 07:28 - 2017-06-21 08:56 - 00113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Lights.dll
2017-07-12 07:28 - 2017-06-21 08:55 - 00557568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll
2017-07-12 07:28 - 2017-06-21 08:55 - 00117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthBroker.dll
2017-07-12 07:28 - 2017-06-21 08:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Core.dll
2017-07-12 07:28 - 2017-06-21 08:54 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Import.dll
2017-07-12 07:28 - 2017-06-21 08:54 - 00483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.AllJoyn.dll
2017-07-12 07:28 - 2017-06-21 08:54 - 00298496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2017-07-12 07:28 - 2017-06-21 08:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe
2017-07-12 07:28 - 2017-06-21 08:53 - 00431616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 00390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 00386048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFiDirect.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 00332288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 00325120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 00284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 00271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 00218624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WwaApi.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 00202752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 00185856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 00175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll
2017-07-12 07:28 - 2017-06-21 08:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Picker.dll
2017-07-12 07:28 - 2017-06-21 08:51 - 00747520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Ocr.dll
2017-07-12 07:28 - 2017-06-21 08:51 - 00314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Usb.dll
2017-07-12 07:28 - 2017-06-21 08:51 - 00284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.dll
2017-07-12 07:28 - 2017-06-21 08:50 - 00857600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EmailApis.dll
2017-07-12 07:28 - 2017-06-21 08:50 - 00238080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AboveLockAppHost.dll
2017-07-12 07:28 - 2017-06-21 08:49 - 00288256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CryptoWinRT.dll
2017-07-12 07:28 - 2017-06-21 08:48 - 02333184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2017-07-12 07:28 - 2017-06-21 08:47 - 13873664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2017-07-12 07:28 - 2017-06-21 08:46 - 04615168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2017-07-12 07:28 - 2017-06-21 08:46 - 01077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Editing.dll
2017-07-12 07:28 - 2017-06-21 08:46 - 00355328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTMediaFrame.dll
2017-07-12 07:28 - 2017-06-21 08:45 - 00313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2017-07-12 07:28 - 2017-06-21 08:44 - 00795648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MiracastReceiver.dll
2017-07-12 07:28 - 2017-06-21 08:44 - 00343040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToDevice.dll
2017-07-12 07:28 - 2017-06-21 08:43 - 01534464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.3D.dll
2017-07-12 07:28 - 2017-06-21 08:43 - 00713216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2017-07-12 07:28 - 2017-06-21 08:43 - 00653312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AccountsControl.dll
2017-07-12 07:28 - 2017-06-21 08:43 - 00468992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.InkControls.dll
2017-07-12 07:28 - 2017-06-21 08:42 - 03307008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2017-07-12 07:28 - 2017-06-21 08:42 - 00525312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2017-07-12 07:28 - 2017-06-21 08:41 - 01255936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 02641920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 00901120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 00895488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 00675840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 00220672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToReceiver.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 00090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2017-07-12 07:28 - 2017-06-21 08:39 - 00134144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ErrorDetails.dll
2017-07-12 07:28 - 2017-06-21 08:38 - 03733504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-07-12 07:28 - 2017-06-21 08:38 - 01221120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
2017-07-12 07:28 - 2017-06-21 08:38 - 00709120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2017-07-12 07:28 - 2017-06-21 08:37 - 07468544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2017-07-12 07:28 - 2017-06-21 08:37 - 06109696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2017-07-12 07:28 - 2017-06-21 08:37 - 00400384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2017-07-12 07:28 - 2017-06-21 08:37 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Geolocation.dll
2017-07-12 07:28 - 2017-06-21 08:37 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Devices.dll
2017-07-12 07:28 - 2017-06-21 08:36 - 02648576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2017-07-12 07:28 - 2017-06-21 08:36 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-07-12 07:28 - 2017-06-21 08:36 - 01247232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globali

Attached Files



#3 QT Pro

QT Pro

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 27 July 2017 - 05:42 AM

I would like to add that when shutting down Windows I get a message saying "This app is preventing shutdown". No program name is given and the icon shown is Windows standard icon for an unidentified application. This app never shuts down and I have no programs open so the only way to shut down is to hit the "Force shutdown" button.

Obviously this is not normal so I'm thinking it may be malware or ransomware related.


Edited by QT Pro, 27 July 2017 - 05:43 AM.


#4 QT Pro

QT Pro

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 27 July 2017 - 11:35 AM

I also ran a HitmanPro scan because even though I had already scanned and rescanned with MalwareBytes, I was still being warned by HitmanPro that my PC was infected. Here is the scan log:

Intruder

PID          10576
Application  C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
Description  Microsoft Edge 11

Detour Report
#  Address             Owner                    Disassembly
-- ------------------  ------------------------ ------------------------
URLDownloadToFileW
 1 0x00007FFE61D37980  urlmon.dll               JMP 0x7ffe3b010bd8
 2 0x00007FFE3B010BD8  (unknown)                

EncryptMessage *
 1 0x00007FFE71E05880  SspiCli.dll              JMP 0x7ffe32790b98
 2 0x00007FFE32790B98  (anonymous)              

FilterConnectCommunicationPort
 1 0x00007FFE71FF20A0  fltlib.dll               JMP 0x7ffe32790298
 2 0x00007FFE32790298  (anonymous)              

FilterSendMessage
 1 0x00007FFE71FF22D0  fltlib.dll               JMP 0x7ffe327902f8
 2 0x00007FFE327902F8  (anonymous)              

CreateDCA
 1 0x00007FFE74E538A0  GDI32.dll                JMP 0x7ffe32790418
 2 0x00007FFE32790418  (anonymous)              

CreateDCW
 1 0x00007FFE74E54190  GDI32.dll                JMP 0x7ffe32790478
 2 0x00007FFE32790478  (anonymous)              

DeleteDC
 1 0x00007FFE74E52080  GDI32.dll                JMP 0x7ffe327905f8
 2 0x00007FFE327905F8  (anonymous)              

GdiAlphaBlend
 1 0x00007FFE74E55450  GDI32.dll                JMP 0x7ffe32790598
 2 0x00007FFE32790598  (anonymous)              

GdiTransparentBlt
 1 0x00007FFE74E554E0  GDI32.dll                JMP 0x7ffe32790538
 2 0x00007FFE32790538  (anonymous)              

GetPixel
 1 0x00007FFE74E54660  GDI32.dll                JMP 0x7ffe327904d8
 2 0x00007FFE327904D8  (anonymous)              

EndTask
 1 0x00007FFE75533370  USER32.dll               JMP 0x7ffe327903b8
 2 0x00007FFE327903B8  (anonymous)              

GetMessageA
 1 0x00007FFE754EE8B0  USER32.dll               JMP 0x7ffe3b010cce
 2 0x00007FFE3B010CCE  (unknown)                

GetMessageW
 1 0x00007FFE754F4840  USER32.dll               JMP 0x7ffe3b010c8e
 2 0x00007FFE3B010C8E  (unknown)                

IsDialogMessage
 1 0x00007FFE755361F0  USER32.dll               JMP 0x7ffe32790958
 2 0x00007FFE32790958  (anonymous)              

IsDialogMessageW
 1 0x00007FFE754E41F0  USER32.dll               JMP 0x7ffe327909b8
 2 0x00007FFE327909B8  (anonymous)              

PeekMessageA
 1 0x00007FFE754EE300  USER32.dll               JMP 0x7ffe3b010c4e
 2 0x00007FFE3B010C4E  (unknown)                

PeekMessageW
 1 0x00007FFE754EE430  USER32.dll               JMP 0x7ffe3b010c0e
 2 0x00007FFE3B010C0E  (unknown)                

SetWindowsHookExA
 1 0x00007FFE754D2730  USER32.dll               JMP 0x7ffe32790a18
 2 0x00007FFE32790A18  (anonymous)              

SetWindowsHookExW
 1 0x00007FFE754F7490  USER32.dll               JMP 0x7ffe32790a78
 2 0x00007FFE32790A78  (anonymous)              

SetWinEventHook
 1 0x00007FFE754F7D70  USER32.dll               JMP 0x7ffe32790ad8
 2 0x00007FFE32790AD8  (anonymous)              

TranslateMessage
 1 0x00007FFE754E5330  USER32.dll               JMP 0x7ffe327908f8
 2 0x00007FFE327908F8  (anonymous)              


Thumbprint
d6095eb13ea95426826bd617e82e395041dc94ecfb5ce4cb514816fc2d7c3b53

 

 

QT PRO - you have requested help both here and at Comodo Forums.
That can become an issue with providing help when you are following instructions from two different sources.
You need to decide which site you will continue to request help at, and request that the topic at the other site be closed before proceeding.
Please let us know how you intend to proceed. Thank you.

https://forums.comod...0.html#lastPost


Edited by Rocket Grannie, 27 July 2017 - 06:12 PM.


#5 QT Pro

QT Pro

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 28 July 2017 - 03:55 AM

Sorry about that but despite numerous views nobody had ever replied there which forced me to look elsewhere.
I tried deleting the thread but got a message saying I cannot delete my own posts so I left a message asking to have the topic closed.
From what I have seen on this forum you guys appear to be far more qualified and committed to the task so I would prefer you to help me on this please.



#6 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,162 posts

Posted 28 July 2017 - 08:19 AM

Hello, Welcome to SpywareInfoForum.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

ATTENTION: System Restore is disabled
Turn System Restore On for Drives in Windows 10
http://www.tenforums...ndows-10-a.html
===

Remove this program in bold via the Control Panel > Programs > Programs and Features.
Auslogics Disk Defrag Professional (HKLM-x32\...\{ADE1535C-C836-4F2E-BDA1-1C7C304743E3}_is1) (Version: 4.8.1.0 - Auslogics Labs Pty Ltd)

Run Malwarebytes and remove all the items listed.
===

Press the Windows key + r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to a new file.
 
Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

HKLM\...\Run: [GraphicsAmplifierSW] => [X]
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [Nexus] => [X]
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Winlogon: [Shell] - <==== ATTENTION
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]
ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File
ContextMenuHandlers05: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.

---

If the problem persists reset your router.

How to Reset a Router Back to the Factory Default Settings
http://www.ehow.com/...t-settings.html

Then, please reconfigure it back to your preferred setting.. Below is the list of default username and password, should you don't know it ;)

http://www.routerpasswords.com/
http://www.phenoelit...rg/dpl/dpl.html
===

Reset for Linksys, Netgear, D-Link and Belkin Routers
http://www.techsuppo...belkin-routers/

====
According to this topic you may also have to make sure that your router is secured.
https://productforum...ate|spell:false

How to tell if my Wireless is secure.
http://www.ehow.com/...ss-secure_.html

===

Please let me know what problem persists with this computer.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#7 QT Pro

QT Pro

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 28 July 2017 - 12:00 PM

Hello nasdaq,

I cannot enable System Restore because my PC is protected by Rollback Rx Professional. This means that the script you asked me to run can't be executed either as it will fail to make a restore point. I can however manually create one using Rollback Rx if you wish?

Also, I don't have a router. I'm on a NordNet satellite connection.

 

 

Update:
I ran HitmanPro last night and it found a small amount of tracking cookies as well as 2 items of malware. When I continued to clean them the program just froze.
I then reactivated Windows Defender and updated its definitions. I did a full scan which took all night. This morning it displayed a longish list of nasties, mostly on an external drive, and I clicked on the button to continue with removal (quarantine, and clean also). The same thing happened. Defender just crashed. The option to scan offline is greyed out, probably because Comodo is still installed even though I exited the program.

At this stage I'm beginning to think the only solution is to reinstall Windows and start over however, my son says the ransomware will have seriously damaged my 3 SSD's and that they will probably need to be replaced because if I reinstall Windows the new installation will be infected instantly.

 

I await your advice nasdaq because my son is better with computers than I am but in no way does he have your skills.


Edited by QT Pro, 29 July 2017 - 02:36 AM.


#8 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,162 posts

Posted 29 July 2017 - 07:11 AM

My searches for this string This network may require you to login to use the internet. reveals that possibly you should change this setting in Firefox.

Quoted from this ling.
https://translate.go...d=1&prev=search
 

Type about : Config in the address bar, and search:

Network.captive-portal-service.enabled

Change its value from ' true ' to ' false '.



The command is case sensitive I would use

about:config

===

If the problem perists can you use Rolllback to restore your system to a date prior to beginning of this error?

p.s.

I'm beginning to think the only solution is to reinstall Windows and start over however, my son says the ransomware will have seriously damaged my 3 SSD's


Were you asked to pay a ransom to restore your files?
If not then this is not caused by malware.

===

Did you execute my fix other than restoring your Restore points?
If not please do it now.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#9 QT Pro

QT Pro

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 29 July 2017 - 12:37 PM

The original issue with the network connection bar in Firefox/IceDragon has been solved by rolling back to the original baseline installation. It is still impossible to clean any malware with HitmanPro, MalwareBytes, and Windows Defender. I scanned the whole PC with Comodo Internet Security and it found nothing whereas the other 3 all found various malware so I uninstalled it and restarted the PC. Please note that no other security program is currently installed other than Defender now. I then reran a scan with Defender but still it will not clean. It just crashes after a few seconds.

I also attempted to launch an offline scan because that option is no longer greyed out but clicking on the button gives an error and asks me to try again later. Again I rebooted and retried the offline scan option. It still refuses. I'm convinced that some extremely potent malware/ransomware is protecting itself and is likely buried deep in the MBR.

In answer to your question about the ransomware, yes, I was asked to pay a ransom and that was why I tried rolling back to the previous day's snapshot with Rollback Rx. That succeeded in returning my files without paying anything but the PC is clearly still damaged.

Is there any way I can get Defender to run an offline scan via Safe Mode or would that be pointless?

I have not run your fix yet because Farbar is no longer on the PC given that I restored it to baseline installation. Do you want me to reinstall and run the FRST test again?



#10 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,162 posts

Posted 30 July 2017 - 07:03 AM

Hi,

Now that a restore has been done please run the Farbar tool and post fresh FRST.txt and Addition.txt logs.
The box to create an Addition.txt file should be marked in order to get a new log.

---
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#11 QT Pro

QT Pro

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 31 July 2017 - 01:49 AM

If there is a problem with the FRST results it will be due to the attached error that came up after launching the program.

 

FRST

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-07-2017
Ran by QT Pro (administrator) on QTP-BOLLOX (31-07-2017 08:38:29)
Running from C:\Users\QT Pro\Downloads\Security
Loaded Profiles: QT Pro (Available Profiles: defaultuser0 & QT Pro)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\Comodo\IceDragon\icedragon.exe" -osint -url "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Windows ® Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Alienware) C:\Program Files\Alienware\Graphics Amplifier\GraphicsAmplifierWindowsService.exe
(Horizon DataSys Inc) C:\Program Files\Shield\ShdServ.exe
() C:\Program Files (x86)\Acrylic DNS Proxy\AcrylicService.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\IntelCpHDCPSvc.exe
() C:\Program Files (x86)\Eaton\UPSCompanion\mc2.exe
(Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Nitro Software, Inc.) C:\Program Files\Nitro\Pro 11\NitroPDFDriverService11x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Rivet Networks) C:\Program Files\Killer Networking\Killer Control Center\KillerNetworkService.exe
() C:\Program Files (x86)\Comodo\IceDragon\icedragon_updater.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Tobii AB) C:\Program Files (x86)\Tobii\Service\Tobii.Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\IntelCpHeciSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Tobii AB) C:\Program Files (x86)\Tobii\Tobii EyeX\Tobii.EyeX.Engine.exe
(Tobii AB) C:\Program Files (x86)\Tobii\Tobii EyeX Interaction\Tobii.EyeX.Tray.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(DeskSoft) C:\Program Files (x86)\WindowManager\WindowManager.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\igfxEM.exe
(Tobii AB) C:\Program Files (x86)\Tobii\Tobii EyeX Interaction\Tobii.EyeX.Interaction.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(A-Volute) C:\Program Files\Alienware\AWSoundCenter\UserInterface\AWSoundCenterUILauncher.exe
() C:\Windows\System\3DG4me.exe
() C:\Program Files\Alienware\AWSoundCenter\UserInterface\AWSoundCenterSvc32.exe
() C:\Program Files\Alienware\AWSoundCenter\UserInterface\x64\AWSoundCenterSvc64.exe
() C:\Users\QT Pro\Downloads\Utilities\NoSleepHDv2.0\NoSleepHDv2.0.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareTactXMacroController.exe
(Horizon DataSys Inc) C:\Program Files\Shield\ShdTray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\Nexus.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
() C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
(Dell) C:\Users\QT Pro\AppData\Local\Apps\2.0\TRE1YDB8.147\ZKC0ME0E.RL4\dell..tion_831211ca63b981c5_0008.0005_9a48d74816d64e41\DellSystemDetect.exe
(Rivet Networks) C:\Program Files\Killer Networking\Killer Control Center\KillerControlCenter.exe
(Alienware Corp.) C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(Ergonis Software) C:\Program Files\Ergonis\PopChar\PopChar.exe
() C:\Program Files (x86)\Eaton\UPSCompanion\mc2.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe
(Klim & Co limited ) C:\Program Files\KLIM AIM Gaming Mouse\KLIM AIM Gaming Mouse.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\TscHelp.exe
(Quick And Easy Software) C:\Users\QT Pro\Downloads\Utilities\USB.Disk.Ejector.v1.3.0.3\USB_Disk_Eject.exe
(Kirby Software) C:\Program Files (x86)\Kirby Alarm Pro\kirbyalarmpro.exe
(Firetrust) C:\Program Files (x86)\Firetrust\MailWasher\MailWasherPro.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagitEditor.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Inc.) C:\Program Files (x86)\Dell Customer Connect\DCCService.exe
(Dell) C:\Program Files\Alienware\Dell Foundation Services\DFSSvc.exe
(Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(Dell Inc.) C:\Program Files (x86)\Alienware Update\DellUpService.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Dell Inc.) C:\Program Files (x86)\Alienware Update\DellUpTray.exe
(Dell) C:\Program Files\Alienware\Alienware Product Registration\PRSvc.exe
(Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\nvapiw.exe
(ZabKat) C:\Program Files\zabkat\xplorer2\xplorer2.exe
(Dell) C:\Program Files\Alienware\Dell Foundation Services\DFS.Common.Agent.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1705.1301.0_x64__8wekyb3d8bbwe\Calculator.exe
() C:\Program Files\WindowsApps\Microsoft.BingWeather_4.20.1102.0_x64__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [GraphicsAmplifierSW] => [X]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9218568 2017-05-05] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493000 2017-05-05] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Command Center Controllers] => C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [13856 2017-03-21] (Alienware)
HKLM\...\Run: [AWSoundCenterUILauncher] => C:\Program Files\Alienware\AWSoundCenter\UserInterface\AWSoundCenterUILauncher.exe [1230008 2017-03-10] (A-Volute)
HKLM\...\Run: [3DG4me] => C:\Windows\System\3DG4me.exe [126976 2015-10-05] ()
HKLM\...\Run: [NoSleepHD] => C:\Users\QT Pro\Downloads\Utilities\NoSleepHDv2.0\NoSleepHDv2.0.exe [110080 2009-04-11] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [320584 2017-03-24] (Intel Corporation)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft)
HKLM\...\Run: [Shield] => C:\Program Files\Shield\shdtray.exe [83904 2017-07-15] (Horizon DataSys Inc)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-28] (Microsoft Corporation)
HKLM-x32\...\Run: [AlienwareOn-ScreenDisplay] => C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe [3747256 2016-12-02] (Alienware Corp.)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2016-02-03] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [1944576 2013-03-07] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [Eaton Systray Launcher] => C:\Program Files (x86)\Eaton\UPSCompanion\mc2.exe [2806176 2017-07-12] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-21] (Oracle Corporation)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110376 2017-06-11] (Siber Systems)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [Nexus] => C:\Program Files (x86)\Winstep\Nexus.exe [13910656 2017-01-27] (Winstep Software Technologies)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [FileHippo.com] => C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe [10566352 2015-09-02] ()
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545056 2017-02-14] (Skype Technologies S.A.)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [OSDownloaderUpdate] => C:\Program Files (x86)\OSDownloader\OSDownloaderUpdate.exe [3921920 2017-03-22] (Opensubtitles.org)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Run: [DellSystemDetect] => C:\Users\QT Pro\AppData\Local\Apps\2.0\TRE1YDB8.147\ZKC0ME0E.RL4\dell..tion_831211ca63b981c5_0008.0005_9a48d74816d64e41\DellSystemDetect.exe [313264 2017-06-21] (Dell)
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Winlogon: [Shell] - <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Control Center.lnk [2017-05-24]
ShortcutTarget: Killer Control Center.lnk -> C:\Program Files\Killer Networking\Killer Control Center\KillerControlCenter.exe (Rivet Networks)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PopChar.lnk [2017-06-16]
ShortcutTarget: PopChar.lnk -> C:\Program Files\Ergonis\PopChar\PopChar.exe (Ergonis Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 12.lnk [2017-06-11]
ShortcutTarget: Snagit 12.lnk -> C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe (TechSmith Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\USB_Disk_Eject.lnk [2017-06-12]
ShortcutTarget: USB_Disk_Eject.lnk -> C:\Users\QT Pro\Downloads\Utilities\USB.Disk.Ejector.v1.3.0.3\USB_Disk_Eject.exe (Quick And Easy Software)
Startup: C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kirby Alarm Pro.lnk [2017-06-11]
ShortcutTarget: Kirby Alarm Pro.lnk -> C:\Program Files (x86)\Kirby Alarm Pro\kirbyalarmpro.exe (Kirby Software)
Startup: C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MailWasherPro.lnk [2017-06-11]
ShortcutTarget: MailWasherPro.lnk -> C:\Program Files (x86)\Firetrust\MailWasher\MailWasherPro.exe (Firetrust)
BootExecute:

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.5.1
Tcpip\..\Interfaces\{cacb34c7-a8b1-4c54-9cc0-7f7e4ad078a4}: [DhcpNameServer] 192.168.5.1

Internet Explorer:
==================
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://dell17win10.msn.com/?pc=DCTE
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.alienwarearena.com/welcome-us
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2017-07-06] (Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-06-11] (Siber Systems Inc.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-07-31] (Oracle Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-07-29] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-31] (Oracle Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2016-07-30] (IvoSoft)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2017-06-20] (Microsoft Corporation)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-06-11] (Siber Systems Inc.)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2017-07-29] (Microsoft Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-06-11] (Siber Systems Inc.)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-06-11] (Siber Systems Inc.)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-07-06] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: a7ddyvk1.default
FF ProfilePath: C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default [2017-07-29]
FF DefaultSearchEngine: Comodo\IceDragon\Profiles\a7ddyvk1.default -> Yahoo! FR
FF Homepage: Comodo\IceDragon\Profiles\a7ddyvk1.default -> hxxps://zerohedge.com
FF Session Restore: Comodo\IceDragon\Profiles\a7ddyvk1.default -> is enabled.
FF Extension: (Add to Search Bar) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\add-to-searchbox@maltekraus.de.xpi [2017-06-10]
FF Extension: (Classic Theme Restorer) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2017-06-10]
FF Extension: (colorPicker) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\colorPicker@colorPicker.xpi [2017-06-10]
FF Extension: (Classic Toolbar Buttons) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2017-06-10]
FF Extension: (YouTubeâ„¢ Enhancer Plus) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\firefoxaddon@youtubeenhancer.com.xpi [2017-06-10]
FF Extension: (Dictionnaire français) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\fr-dicollecte@dictionaries.addons.mozilla.org [2017-06-16]
FF Extension: (HTTPS Everywhere) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\https-everywhere@eff.org.xpi [2017-06-10]
FF Extension: (Italian dictionary) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\it-IT@dictionaries.addons.mozilla.org [2017-06-16]
FF Extension: (Google search link fix) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\jid0-XWJxt5VvCXkKzQK99PhZqAn7Xbg@jetpack.xpi [2017-06-10]
FF Extension: (I don't care about cookies) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\jid1-KKzOGWgsW3Ao4Q@jetpack.xpi [2017-06-10]
FF Extension: (RT News) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\jid1-ReWlW1efOwaQJQ@jetpack.xpi [2017-06-10]
FF Extension: (Dorando keyconfig) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\keyconfig@mozilla.dorando.at.xpi [2017-06-10]
FF Extension: (S3.Google Translator) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\s3google@translator.xpi [2017-06-10]
FF Extension: (Saved Password Editor) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\savedpasswordeditor@daniel.dawson.xpi [2017-06-10]
FF Extension: (Super Start) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\superstart@enjoyfreeware.org [2017-06-10]
FF Extension: (The Addon Bar (restored)) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\the-addon-bar@GeekInTraining-GiT.xpi [2017-06-10]
FF Extension: (Beyond Australis) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\thefoxonlybetter@quicksaver.xpi [2017-06-10]
FF Extension: (Thumbnail Zoom Plus) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\thumbnailZoom@dadler.github.com.xpi [2017-06-10]
FF Extension: (NoSquint Plus) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\zoomlevelplus@zoomlevelplus.net.xpi [2017-06-10]
FF Extension: (FlashGot) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2017-06-30]
FF Extension: (RoboForm Toolbar) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{22119944-ED35-4ab1-910B-E619EA06A115} [2017-06-11]
FF Extension: (ColorZilla) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}.xpi [2017-06-10]
FF Extension: (Download Status Bar) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2017-06-10]
FF Extension: (NoScript) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2017-06-10]
FF Extension: (FT DeepDark) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2017-06-25]
FF Extension: (YouTube High Definition) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2017-06-10]
FF Extension: (Adblock Plus) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-10]
FF Extension: (BetterPrivacy) - C:\Users\QT Pro\AppData\Roaming\Comodo\IceDragon\Profiles\a7ddyvk1.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2017-06-10]
FF Extension: (COMODO SecureBox) - C:\Program Files (x86)\Comodo\IceDragon\browser\features\@csb [2017-06-10] [not signed]
FF Extension: (DragAndDrop) - C:\Program Files (x86)\Comodo\IceDragon\browser\features\DnD@comodo.com [2017-06-10] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_137.dll [2017-07-11] ()
FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-31] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-31] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-06-20] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.5.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_137.dll [2017-07-11] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-06-20] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2017-06-20] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll [2013-07-26] (Nitro PDF)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-02-13] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-02-13] (NVIDIA Corporation)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AcrylicServiceController; C:\Program Files (x86)\Acrylic DNS Proxy\AcrylicService.exe [646144 2016-11-03] () [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [338312 2016-09-07] (Windows ® Win 7 DDK provider)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4412104 2017-07-18] (Microsoft Corporation)
R3 cphs; C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\IntelCpHeciSvc.exe [285696 2017-04-10] (Intel Corporation)
R2 cplspcon; C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\IntelCpHDCPSvc.exe [463360 2017-04-10] (Intel Corporation)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [206712 2017-06-20] (Dell Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3296632 2017-06-20] (Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217464 2017-06-20] (Dell Inc.)
R2 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [132472 2016-09-09] (Dell Inc.)
R2 Dell Foundation Services; C:\Program Files\Alienware\Dell Foundation Services\DFSSvc.exe [97616 2017-01-11] (Dell)
R2 DellUpdate; C:\Program Files (x86)\Alienware Update\DellUpService.exe [230248 2017-05-01] (Dell Inc.)
R2 Eaton UPSCompanion; C:\Program Files (x86)\Eaton\UPSCompanion\mc2.exe [2806176 2017-07-12] ()
R2 esifsvc; C:\Windows\system32\Intel\DPTF\esif_uf.exe [2208888 2016-09-02] (Intel Corporation)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R2 GraphicsAmplifierWindowsService; C:\Program Files\Alienware\Graphics Amplifier\GraphicsAmplifierWindowsService.exe [14392 2016-11-15] (Alienware)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [17992 2017-03-24] (Intel Corporation)
R2 IceDragonUpdater; C:\Program Files (x86)\Comodo\IceDragon\icedragon_updater.exe [4295328 2017-05-24] ()
R2 igfxCUIService2.0.0.0; C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\igfxCUIService.exe [324096 2017-04-10] (Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-07-27] (Intel® Corporation)
S3 ioloEnergyBooster; C:\Program Files\Alienware\Command Center\ioloEnergyBooster.exe [6145872 2012-11-01] (iolo technologies, LLC)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [177440 2016-09-15] (Intel Corporation)
R2 Killer Network Service; C:\Program Files\Killer Networking\Killer Control Center\KillerNetworkService.exe [2010336 2016-11-02] (Rivet Networks)
R2 NitroDriverReadSpool11; C:\Program Files\Nitro\Pro 11\NitroPDFDriverService11x64.exe [327368 2016-12-08] (Nitro Software, Inc.)
R2 NitroReaderDriverReadSpool3; C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe [230416 2013-07-26] (Nitro PDF Software)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2017-02-09] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [464440 2017-02-09] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2017-02-13] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [427064 2017-02-09] (NVIDIA Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1450824 2017-07-25] (Overwolf LTD)
R2 Product Registration; C:\Program Files\Alienware\Alienware Product Registration\PRSvc.exe [47144 2017-04-06] (Dell)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [333328 2017-05-05] (Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2017-05-24] (Microsoft Corporation)
R2 ShdServ; C:\Program Files\Shield\shdserv.exe [308672 2017-07-15] (Horizon DataSys Inc)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [52696 2017-06-28] (Dell Inc.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [252504 2016-09-20] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10803440 2017-07-26] (TeamViewer GmbH)
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
S3 ThunderboltService; c:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe [2015968 2016-08-15] (Intel Corporation)
R2 Tobii Service; C:\Program Files (x86)\Tobii\Service\Tobii.Service.exe [197696 2017-05-30] (Tobii AB)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [32960 2017-04-11] (Dell Inc.)
R3 DellProf; C:\Windows\system32\drivers\DellProf.sys [32568 2017-04-11] (Dell Computer Corporation)
R3 dptf_acpi; C:\Windows\System32\drivers\dptf_acpi.sys [71232 2016-08-13] (Intel Corporation)
R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [66624 2016-08-13] (Intel Corporation)
R0 EMSC; C:\Windows\System32\drivers\EMSC.SYS [35216 2016-08-19] ()
R3 esif_lf; C:\Windows\system32\DRIVERS\esif_lf.sys [350272 2016-08-13] (Intel Corporation)
R3 HidEventFilter; C:\Windows\System32\drivers\HidEventFilter.sys [54800 2016-08-16] (Intel Corporation)
R3 igfx; C:\Windows\System32\DriverStore\FileRepository\ki121509.inf_amd64_cf0568c384a72b13\igdkmd64.sys [11070440 2017-04-10] (Intel Corporation)
R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115448 2013-11-21] (EZB Systems, Inc.)
R3 KillerEth; C:\Windows\System32\drivers\e2xw10x64.sys [162120 2016-09-16] (Qualcomm Atheros, Inc.)
R3 kiox_ff_driver; C:\Windows\system32\DRIVERS\kiox_ff_driver.sys [50312 2016-09-21] (Kionix, Inc.)
R0 kxdiskprot; C:\Windows\System32\DRIVERS\kxdiskprot.sys [38544 2016-06-13] (Kionix, Inc.)
S3 libusb0; C:\Windows\system32\DRIVERS\libusb0.sys [51848 2017-07-12] (hxxp://libusb-win32.sourceforge.net)
R1 MpKsl1b247235; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C77E18F5-3BF7-43B6-ABA8-EB7EEAF0DEFD}\MpKsl1b247235.sys [44928 2017-07-30] (Microsoft Corporation)
R1 MpKslb780015a; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{51B758DE-DB42-43A4-92A2-C7B505F26579}\MpKslb780015a.sys [44928 2017-07-31] (Microsoft Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_311b72236e1161dc\nvlddmkm.sys [14320056 2017-02-15] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [29240 2017-02-09] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47672 2017-02-09] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [59448 2017-02-09] (NVIDIA Corporation)
R3 Qcamain10x64; C:\Windows\system32\DRIVERS\Qcamain10x64.sys [2412976 2017-04-15] (Qualcomm Atheros, Inc.)
R2 RfeCoSvc; C:\Windows\system32\DRIVERS\RfeCo10X64.sys [89440 2016-11-02] (Rivet Networks, LLC.)
R0 Shdbus; C:\Windows\System32\DRIVERS\Shdbus.sys [30544 2017-07-15] (Horizon DataSys Inc) [File not signed]
R0 Shield; C:\Windows\System32\DRIVERS\shield.sys [117072 2017-07-15] (Horizon DataSys Inc) [File not signed]
R0 Shieldf; C:\Windows\System32\DRIVERS\Shieldf.sys [35664 2017-07-15] (Horizon DataSys Inc) [File not signed]
R0 Shieldm; C:\Windows\System32\DRIVERS\Shieldm.sys [36176 2017-07-15] (Horizon DataSys Inc) [File not signed]
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [63576 2016-09-20] (Synaptics Incorporated)
R3 USBADVAU; C:\Windows\system32\drivers\cm11264.sys [1308160 2010-04-23] (C-Media Electronics Inc)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-31 08:35 - 2017-07-31 08:38 - 000000000 ____D C:\FRST
2017-07-31 07:30 - 2017-07-31 07:30 - 000003224 _____ C:\Windows\System32\Tasks\klcp_update
2017-07-31 07:29 - 2005-01-22 01:53 - 000055296 _____ C:\Windows\system32\huffyuv.dll
2017-07-31 07:28 - 2017-07-31 07:28 - 000001108 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
2017-07-31 07:26 - 2017-07-31 07:26 - 000001116 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2017-07-31 07:25 - 2017-07-31 07:24 - 000110144 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2017-07-30 08:55 - 2017-07-30 08:55 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2017-07-29 16:50 - 2017-07-29 16:50 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2017-07-29 15:44 - 2017-07-03 11:57 - 000565416 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2017-07-29 15:43 - 2017-07-29 15:43 - 000000000 _____ C:\Windows\System32\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}
2017-07-29 15:29 - 2017-07-29 15:29 - 000003368 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-788432544-2185739174-1534461968-1001
2017-07-29 15:29 - 2017-07-29 15:29 - 000002410 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-07-15 08:26 - 2017-07-15 08:26 - 000117072 ____N (Horizon DataSys Inc) C:\Windows\system32\Drivers\shield.sys
2017-07-15 08:26 - 2017-07-15 08:26 - 000036176 ____N (Horizon DataSys Inc) C:\Windows\system32\Drivers\shieldm.sys
2017-07-15 08:26 - 2017-07-15 08:26 - 000035664 ____N (Horizon DataSys Inc) C:\Windows\system32\Drivers\shieldf.sys
2017-07-15 08:26 - 2017-07-15 08:26 - 000031680 ____N (Horizon DataSys Inc) C:\Windows\system32\shdsync.exe
2017-07-15 08:26 - 2017-07-15 08:26 - 000030544 ____N (Horizon DataSys Inc) C:\Windows\system32\Drivers\shdbus.sys
2017-07-15 08:26 - 2017-07-15 08:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RollBack Rx Professional
2017-07-14 11:12 - 2017-07-14 11:13 - 000000000 ____D C:\Program Files (x86)\Resource Hacker
2017-07-13 11:11 - 2017-07-30 21:07 - 000000000 ____D C:\Users\QT Pro\AppData\Local\ClassicShell
2017-07-13 11:10 - 2017-07-13 11:10 - 000000000 ____D C:\Users\QT Pro\AppData\Roaming\ClassicShell
2017-07-13 11:10 - 2017-07-13 11:10 - 000000000 ____D C:\ProgramData\ClassicShell
2017-07-13 11:06 - 2017-07-13 11:07 - 000000000 ____D C:\Program Files\Classic Shell
2017-07-13 11:06 - 2017-07-13 11:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2017-07-12 20:22 - 2017-07-12 20:22 - 000002081 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Powerpoint.lnk
2017-07-12 20:22 - 2017-07-12 20:22 - 000002062 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Word.lnk
2017-07-12 20:22 - 2017-07-12 20:22 - 000002038 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Publisher.lnk
2017-07-12 20:22 - 2017-07-12 20:22 - 000002038 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EXCEL.lnk
2017-07-12 19:43 - 2017-07-12 19:44 - 000000000 ____D C:\Users\QT Pro\Downloads\Android
2017-07-12 12:23 - 2017-07-12 12:23 - 000000000 ____D C:\Users\QT Pro\AppData\Roaming\Eaton
2017-07-12 12:22 - 2017-07-12 12:22 - 000051848 _____ (hxxp://libusb-win32.sourceforge.net) C:\Windows\system32\Drivers\libusb0.sys
2017-07-12 12:22 - 2017-07-12 12:22 - 000001454 _____ C:\Users\QT Pro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Eaton Notifier.lnk
2017-07-12 12:22 - 2017-07-12 12:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eaton
2017-07-12 12:22 - 2017-07-12 12:22 - 000000000 ____D C:\Program Files (x86)\Eaton
2017-07-12 10:39 - 2017-07-31 07:29 - 000004158 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C0FF1E0A-0626-43AE-8AFF-970EDAFB9EB4}
2017-07-12 07:30 - 2017-06-30 16:46 - 000835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-07-12 07:30 - 2017-06-30 16:46 - 000177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-07-12 07:28 - 2017-07-07 09:49 - 000340824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-07-12 07:28 - 2017-07-07 09:46 - 000781152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2017-07-12 07:28 - 2017-07-07 09:45 - 002263832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-07-12 07:28 - 2017-07-07 09:29 - 005686272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2017-07-12 07:28 - 2017-07-07 09:13 - 000364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupShim.dll
2017-07-12 07:28 - 2017-07-07 09:10 - 000755200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-07-12 07:28 - 2017-07-07 09:09 - 000506368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-07-12 07:28 - 2017-07-07 09:06 - 007626752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-07-12 07:28 - 2017-07-07 08:54 - 002997248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2017-07-12 07:28 - 2017-07-07 08:53 - 002483200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-07-12 07:28 - 2017-07-07 08:52 - 001599488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-07-12 07:28 - 2017-06-21 09:42 - 000601712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-07-12 07:28 - 2017-06-21 09:39 - 002048496 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2017-07-12 07:28 - 2017-06-21 09:29 - 005722320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2017-07-12 07:28 - 2017-06-21 09:28 - 001504056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-07-12 07:28 - 2017-06-21 09:27 - 001431232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2017-07-12 07:28 - 2017-06-21 09:27 - 000975744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2017-07-12 07:28 - 2017-06-21 09:27 - 000861024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2017-07-12 07:28 - 2017-06-21 09:27 - 000116576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostCommon.dll
2017-07-12 07:28 - 2017-06-21 09:25 - 002168288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2017-07-12 07:28 - 2017-06-21 09:24 - 000846560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2017-07-12 07:28 - 2017-06-21 09:22 - 000361104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
2017-07-12 07:28 - 2017-06-21 09:21 - 006665440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-07-12 07:28 - 2017-06-21 09:21 - 004023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2017-07-12 07:28 - 2017-06-21 09:21 - 001845512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2017-07-12 07:28 - 2017-06-21 09:21 - 001277856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2017-07-12 07:28 - 2017-06-21 09:20 - 001360464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2017-07-12 07:28 - 2017-06-21 09:20 - 000981888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2017-07-12 07:28 - 2017-06-21 09:20 - 000962768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-07-12 07:28 - 2017-06-21 09:19 - 004312248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-07-12 07:28 - 2017-06-21 09:04 - 001631232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-07-12 07:28 - 2017-06-21 09:04 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcconf.dll
2017-07-12 07:28 - 2017-06-21 09:01 - 000141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Radios.dll
2017-07-12 07:28 - 2017-06-21 09:00 - 000156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDeviceRegistration.dll
2017-07-12 07:28 - 2017-06-21 08:59 - 000285184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-07-12 07:28 - 2017-06-21 08:59 - 000255488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unimdm.tsp
2017-07-12 07:28 - 2017-06-21 08:59 - 000177664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Diagnostics.dll
2017-07-12 07:28 - 2017-06-21 08:59 - 000123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.HostName.dll
2017-07-12 07:28 - 2017-06-21 08:59 - 000097792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.SystemManagement.dll
2017-07-12 07:28 - 2017-06-21 08:58 - 000136192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinRtTracing.dll
2017-07-12 07:28 - 2017-06-21 08:58 - 000129024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SerialCommunication.dll
2017-07-12 07:28 - 2017-06-21 08:58 - 000094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll
2017-07-12 07:28 - 2017-06-21 08:58 - 000087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-07-12 07:28 - 2017-06-21 08:58 - 000059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.UserDeviceAssociation.dll
2017-07-12 07:28 - 2017-06-21 08:57 - 000142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFi.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 000392192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Input.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 000374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 000315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 000237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncSettings.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 000231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 000184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2017-07-12 07:28 - 2017-06-21 08:56 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2017-07-12 07:28 - 2017-06-21 08:56 - 000113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Lights.dll
2017-07-12 07:28 - 2017-06-21 08:55 - 000557568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll
2017-07-12 07:28 - 2017-06-21 08:55 - 000117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthBroker.dll
2017-07-12 07:28 - 2017-06-21 08:55 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Core.dll
2017-07-12 07:28 - 2017-06-21 08:54 - 000609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Import.dll
2017-07-12 07:28 - 2017-06-21 08:54 - 000483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.AllJoyn.dll
2017-07-12 07:28 - 2017-06-21 08:54 - 000298496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2017-07-12 07:28 - 2017-06-21 08:54 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe
2017-07-12 07:28 - 2017-06-21 08:53 - 000431616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 000390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 000386048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFiDirect.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 000332288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 000325120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 000284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 000218624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WwaApi.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 000202752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 000185856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll
2017-07-12 07:28 - 2017-06-21 08:53 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll
2017-07-12 07:28 - 2017-06-21 08:52 - 000262144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Picker.dll
2017-07-12 07:28 - 2017-06-21 08:51 - 000747520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Ocr.dll
2017-07-12 07:28 - 2017-06-21 08:51 - 000314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Usb.dll
2017-07-12 07:28 - 2017-06-21 08:51 - 000284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.dll
2017-07-12 07:28 - 2017-06-21 08:50 - 000857600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EmailApis.dll
2017-07-12 07:28 - 2017-06-21 08:50 - 000238080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AboveLockAppHost.dll
2017-07-12 07:28 - 2017-06-21 08:49 - 000288256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CryptoWinRT.dll
2017-07-12 07:28 - 2017-06-21 08:48 - 002333184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2017-07-12 07:28 - 2017-06-21 08:47 - 013873664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2017-07-12 07:28 - 2017-06-21 08:46 - 004615168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2017-07-12 07:28 - 2017-06-21 08:46 - 001077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Editing.dll
2017-07-12 07:28 - 2017-06-21 08:46 - 000355328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTMediaFrame.dll
2017-07-12 07:28 - 2017-06-21 08:45 - 000313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2017-07-12 07:28 - 2017-06-21 08:44 - 000795648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MiracastReceiver.dll
2017-07-12 07:28 - 2017-06-21 08:44 - 000343040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToDevice.dll
2017-07-12 07:28 - 2017-06-21 08:43 - 001534464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.3D.dll
2017-07-12 07:28 - 2017-06-21 08:43 - 000713216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2017-07-12 07:28 - 2017-06-21 08:43 - 000653312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AccountsControl.dll
2017-07-12 07:28 - 2017-06-21 08:43 - 000468992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.InkControls.dll
2017-07-12 07:28 - 2017-06-21 08:42 - 003307008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2017-07-12 07:28 - 2017-06-21 08:42 - 000525312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2017-07-12 07:28 - 2017-06-21 08:41 - 001255936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 002641920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 000901120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 000895488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 000675840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 000220672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToReceiver.dll
2017-07-12 07:28 - 2017-06-21 08:40 - 000090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2017-07-12 07:28 - 2017-06-21 08:39 - 000134144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ErrorDetails.dll
2017-07-12 07:28 - 2017-06-21 08:38 - 003733504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-07-12 07:28 - 2017-06-21 08:38 - 001221120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
2017-07-12 07:28 - 2017-06-21 08:38 - 000709120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2017-07-12 07:28 - 2017-06-21 08:37 - 007468544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2017-07-12 07:28 - 2017-06-21 08:37 - 006109696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2017-07-12 07:28 - 2017-06-21 08:37 - 000400384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2017-07-12 07:28 - 2017-06-21 08:37 - 000357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Geolocation.dll
2017-07-12 07:28 - 2017-06-21 08:37 - 000103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Devices.dll
2017-07-12 07:28 - 2017-06-21 08:36 - 002648576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2017-07-12 07:28 - 2017-06-21 08:36 - 001988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-07-12 07:28 - 2017-06-21 08:36 - 001247232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2017-07-12 07:28 - 2017-06-21 08:35 - 002682880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netshell.dll
2017-07-12 07:28 - 2017-06-21 08:35 - 001656320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Perception.dll
2017-07-12 07:28 - 2017-06-21 08:35 - 001232384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Maps.dll
2017-07-12 07:28 - 2017-06-21 08:35 - 001170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Speech.dll
2017-07-12 07:28 - 2017-06-21 08:35 - 000598528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.dll
2017-07-12 07:28 - 2017-06-21 08:35 - 000589312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
2017-07-12 07:28 - 2017-06-21 08:35 - 000348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Midi.dll
2017-07-12 07:28 - 2017-06-21 08:34 - 001886720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2017-07-12 07:28 - 2017-06-21 08:34 - 000654336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
2017-07-12 07:28 - 2017-06-21 08:34 - 000621056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2017-07-12 07:28 - 2017-06-21 08:34 - 000566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll
2017-07-12 07:28 - 2017-06-21 08:34 - 000542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll
2017-07-12 07:28 - 2017-06-21 08:33 - 001170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Phone.dll
2017-07-12 07:28 - 2017-06-21 08:33 - 001013248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Http.dll
2017-07-12 07:28 - 2017-06-21 08:33 - 000751104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2017-07-12 07:28 - 2017-06-21 08:31 - 003106304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2017-07-12 07:28 - 2017-06-21 08:10 - 000483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2017-07-12 07:28 - 2017-03-04 08:56 - 000263472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll
2017-07-12 07:28 - 2017-03-04 08:21 - 001243136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.FaceAnalysis.dll
2017-07-12 07:28 - 2017-03-04 08:21 - 000670208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll
2017-07-12 07:28 - 2017-03-04 08:20 - 000562176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SmartCards.dll
2017-07-12 07:28 - 2017-03-04 08:20 - 000426496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Wallet.dll
2017-07-12 07:28 - 2017-03-04 08:19 - 000498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mbsmsapi.dll
2017-07-12 07:28 - 2017-03-04 08:18 - 000525824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintDialogs.dll
2017-07-12 07:28 - 2017-03-04 08:02 - 002138112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2017-07-12 07:28 - 2016-10-05 11:15 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dialclient.dll
2017-07-12 07:28 - 2016-09-15 18:58 - 000092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-07-12 07:28 - 2016-09-15 18:47 - 000134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Energy.dll
2017-07-12 07:27 - 2017-07-07 09:44 - 000108896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2017-07-12 07:27 - 2017-07-07 09:42 - 007781720 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-07-12 07:27 - 2017-07-07 09:40 - 020967840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-07-12 07:27 - 2017-07-07 09:40 - 000376672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2017-07-12 07:27 - 2017-07-07 09:37 - 000468320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-07-12 07:27 - 2017-07-07 09:37 - 000118112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-07-12 07:27 - 2017-07-07 09:32 - 000404824 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-07-12 07:27 - 2017-07-07 09:29 - 002759712 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-07-12 07:27 - 2017-07-07 09:29 - 000857440 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2017-07-12 07:27 - 2017-07-07 09:28 - 000223584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-07-12 07:27 - 2017-07-07 09:24 - 022220856 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-07-12 07:27 - 2017-07-07 09:23 - 001600624 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2017-07-12 07:27 - 2017-07-07 09:23 - 000241504 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
2017-07-12 07:27 - 2017-07-07 09:20 - 000059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\l2gpstore.dll
2017-07-12 07:27 - 2017-07-07 09:19 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-07-12 07:27 - 2017-07-07 09:19 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapprovp.dll
2017-07-12 07:27 - 2017-07-07 09:18 - 002532192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-07-12 07:27 - 2017-07-07 09:18 - 001100120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2017-07-12 07:27 - 2017-07-07 09:18 - 000450560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2017-07-12 07:27 - 2017-07-07 09:18 - 000210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\onex.dll
2017-07-12 07:27 - 2017-07-07 09:18 - 000057400 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-07-12 07:27 - 2017-07-07 09:17 - 000118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\raschap.dll
2017-07-12 07:27 - 2017-07-07 09:14 - 000270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-07-12 07:27 - 2017-07-07 09:14 - 000126464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2017-07-12 07:27 - 2017-07-07 09:13 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-07-12 07:27 - 2017-07-07 09:11 - 000340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-07-12 07:27 - 2017-07-07 09:09 - 000637952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2017-07-12 07:27 - 2017-07-07 09:06 - 018364928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2017-07-12 07:27 - 2017-07-07 09:05 - 019414528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-07-12 07:27 - 2017-07-07 09:03 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe
2017-07-12 07:27 - 2017-07-07 09:02 - 001313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2017-07-12 07:27 - 2017-07-07 09:00 - 012187136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-07-12 07:27 - 2017-07-07 09:00 - 000476160 _____ (Microsoft® Windows® Operating System) C:\Windows\SysWOW64\wvc.dll
2017-07-12 07:27 - 2017-07-07 08:58 - 007217152 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2017-07-12 07:27 - 2017-07-07 08:57 - 000691712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-07-12 07:27 - 2017-07-07 08:56 - 006035456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2017-07-12 07:27 - 2017-07-07 08:55 - 004423680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-07-12 07:27 - 2017-07-07 08:55 - 003664896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-07-12 07:27 - 2017-07-07 08:55 - 001571840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2017-07-12 07:27 - 2017-07-07 08:54 - 002027008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-07-12 07:27 - 2017-07-07 08:52 - 004561408 _____ (Microsoft) C:\Windows\SysWOW64\dbgeng.dll
2017-07-12 07:27 - 2017-07-07 08:52 - 001413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2017-07-12 07:27 - 2017-07-07 08:51 - 022569984 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2017-07-12 07:27 - 2017-07-07 08:49 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys
2017-07-12 07:27 - 2017-07-07 08:48 - 000071680 _____ (Microsoft Corporation) C:\Windows\system32\l2gpstore.dll
2017-07-12 07:27 - 2017-07-07 08:48 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\eapprovp.dll
2017-07-12 07:27 - 2017-07-07 08:47 - 000201728 _____ (Microsoft Corporation) C:\Windows\system32\ScDeviceEnum.dll
2017-07-12 07:27 - 2017-07-07 08:47 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthpan.sys
2017-07-12 07:27 - 2017-07-07 08:46 - 000231424 _

Attached Thumbnails

  • FRST_error.jpg


#12 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,162 posts

Posted 31 July 2017 - 06:25 AM

Hi,

Press the Windows key + r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.
 
start

EmptyTemp:
CloseProcesses:

HKLM\...\Run: [GraphicsAmplifierSW] => [X]
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Winlogon: [Shell] - <==== ATTENTION
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

If Defender fails to run then it may just be that it cannot create a Restore point and RollBack is protecting the change.
The same is probably thru of the Farbar error.

Keep me posted.
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#13 QT Pro

QT Pro

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 31 July 2017 - 01:25 PM

Fix result of Farbar Recovery Scan Tool (x64) Version: 31-07-2017
Ran by QT Pro (31-07-2017 19:48:44) Run:1
Running from C:\Users\QT Pro\Downloads\Security
Loaded Profiles: QT Pro (Available Profiles: defaultuser0 & QT Pro)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start

EmptyTemp:
CloseProcesses:

HKLM\...\Run: [GraphicsAmplifierSW] => [X]
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\...\Winlogon: [Shell] - <==== ATTENTION
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File

End
*****************

Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\GraphicsAmplifierSW => value removed successfully
HKU\S-1-5-21-788432544-2185739174-1534461968-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => key removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => key not found.

=========== EmptyTemp: ==========

BITS transfer queue => 284947 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 233549545 B
Java, Flash, Steam htmlcache => 2218 B
Windows/system/drivers => 356180176 B
Edge => 27930079 B
Chrome => 0 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 298771 B
systemprofile32 => 0 B
LocalService => 96800 B
NetworkService => 69886 B
defaultuser0 => 128 B
QT Pro => 260185602 B

RecycleBin => 200109589 B
EmptyTemp: => 1 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 19:49:06 ====

 

 

After running your Fixlist Windows Defender is disabled and will not turn on again. It says the program is controlled by Group Policy and that I should contact my administrator but I am the administrator. Any idea how I can get it running again please nasdaq?

 

Update
I edited the registry key so that Defender was no longer disabled and it runs again, but only partially. Most options are greyed-out with a message saying that my PC is being protected by another AV program. This is false. There is no other security program installed on the machine. I have looked at the Group Policy Editor in detail and can find no option to allow for an offline scan which, at this time, I feel is very much warranted.


Edited by QT Pro, 01 August 2017 - 03:44 AM.


#14 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,162 posts

Posted 01 August 2017 - 06:31 AM


Windows defender is disabled by Comodo.

Look at this log.

Result of Security Analysis by Rocket Grannie (x86) Updated: 25th July, 2017
Running from:C:\Users\QT Pro\Desktop (11:53:12 - 07/27/2017)
***---------------------------------------------------------***
Microsoft Windows 10 Pro X64
UAC is Enabled
Internet Explorer 11
Default Browser: C:\Program Files (x86)\Comodo\IceDragon\icedragon.exe
***------------Antivirus - Antispyware - Firewall-----------***
Windows Defender (Disabled - up to Date)
COMODO Antivirus (Enabled - up to Date)
Malwarebytes (Disabled - up to Date)
COMODO Advanced Protection (Enabled - up to Date)
Malwarebytes (Disabled - up to Date)
Windows Defender (Disabled - up to Date)
COMODO Firewall (Enabled)
***-------Security Programs - Browsers - Miscellaneous------***
Adobe Flash Player 26 NPAPI (26.0.0.137)
HitmanPro (3.7.20.286)
Java (8.0.1410.15)
Malwarebytes (3.1.2.1733)
Microsoft Silverlight (5.1.50907.0)

===

You should disable Windows Defender.

===

If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingc...best-practices/


https://www.bleeping...er-safe-online/
Simple and easy ways to keep your computer safe and secure on the Internet.
===
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#15 QT Pro

QT Pro

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 01 August 2017 - 12:06 PM

That's an old log (July 27th). Comodo is not even installed. Neither are MalwareBytes nor HitmanPro. I uninstalled Comodo because it could find nothing after a full scan whereas Defender, HMP, and MWB all did. I think the reason Defender is not working correctly is because remnants of Comodo are still on the system somewhere or malware is messing with it.



#16 nasdaq

nasdaq

    Forum Deity

  • Global Moderator
  • PipPipPipPipPip
  • 49,162 posts

Posted 01 August 2017 - 12:14 PM

Download and run Comodo Removal toos.

https://www.techsupp...o-removal-tool/

Restart the computer normally.

How is it now?>
nasdaq

Favorite tools: [ SpywareBlaster ] [ Spybot ] [ AdAware ] [ HijackThis ]
[ Housecall online virus scan ] [ Bitdefender online virus scan ]
[ AVG antivirus ] [ Sunbelt Personal Firewall ] [ ZoneAlarm firewall ]

My help is free, but if we have helped you in anyway,please considerDonating ,
see this topic for details.
We need members like you.

========
Shouldn't water be worth more than diamonds?
Adam Smith Glasgow, 1760

#17 QT Pro

QT Pro

    Member

  • Full Member
  • Pip
  • 13 posts

Posted 06 August 2017 - 06:30 AM

Sorry, I was never alerted to your reply.
I ended up reinstalling Windows. Hopefully the problems will be solved now.
Thank you for all your assistance in any event.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of

Support SpywareInfo Forum - click the button
PayPal - The safer, easier way to pay online!