Professional Documents
Culture Documents
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\FreeLAN\bin\freelan.exe
(Avira Operations Gmbh & Co. KG) C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe Shopping.exe
HKLM-x32\...\Run: [Avira Safe Shopping] => C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe
Shopping.exe [546960 2017-10-30] (Avira Operations Gmbh & Co. KG)
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: G - G:\stp-fm2017.exe
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: {d2c0facc-7de3-11e7-
85e9-4061861f71d2} - H:\Autoplay.exe -auto
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\Software\Microsoft\Internet
Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
FireFox:
========
FF ProfilePath: C:\Users\Win 7\AppData\Roaming\Mozilla\Firefox\Profiles\bN6sIJQi.default [2017-09-
11]
Chrome:
=======
Opera:
=======
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072
2016-05-30] (Disc Soft Ltd)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
2017-11-16 20:58 - 2012-07-20 02:06 - 000068656 _____ C:\Users\Win 7\Desktop\good times rg.ttf
2017-11-09 22:20 - 2017-11-09 22:20 - 000000000 ____D C:\Program Files (x86)\Mouse Server
2017-12-04 17:07 - 2017-10-11 02:22 - 000000000 ___RD C:\Users\Win 7\Creative Cloud Files
2017-11-13 16:37 - 2017-08-10 22:55 - 000000000 ____D C:\Program Files (x86)\Popcorn Time
C:\Windows\system32\dnsapi.dll => File is digitally signedScan result of Farbar Recovery Scan Tool
(FRST) (x64) Version: 30-11-2017
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files\FreeLAN\bin\freelan.exe
(Avira Operations Gmbh & Co. KG) C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe Shopping.exe
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will
not be moved.)
HKLM-x32\...\Run: [Avira Safe Shopping] => C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe
Shopping.exe [546960 2017-10-30] (Avira Operations Gmbh & Co. KG)
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: G - G:\stp-fm2017.exe
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: {d2c0facc-7de3-11e7-
85e9-4061861f71d2} - H:\Autoplay.exe -auto
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\Control Panel\Desktop\\SCRNSAVE.EXE ->
C:\Windows\system32\ssText3d.scr [333824 2010-11-21] (Microsoft Corporation)
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Internet Explorer:
==================
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\Software\Microsoft\Internet
Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
FireFox:
========
Chrome:
=======
Opera:
=======
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072
2016-05-30] (Disc Soft Ltd)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
Error(1) reading file: "C:\Users\Win 7\Downloads\THE PAPER PEGASUS HEXAGON PS BRUSHES "
2017-11-09 22:20 - 2017-11-09 22:20 - 000000000 ____D C:\Program Files (x86)\Mouse Server
2017-12-04 17:07 - 2017-10-11 02:22 - 000000000 ___RD C:\Users\Win 7\Creative Cloud Files
2017-11-13 16:37 - 2017-08-10 22:55 - 000000000 ____D C:\Program Files (x86)\Popcorn Time
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\FreeLAN\bin\freelan.exe
(Avira Operations Gmbh & Co. KG) C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe Shopping.exe
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will
not be moved.)
HKLM-x32\...\Run: [Avira Safe Shopping] => C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe
Shopping.exe [546960 2017-10-30] (Avira Operations Gmbh & Co. KG)
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: G - G:\stp-fm2017.exe
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: {d2c0facc-7de3-11e7-
85e9-4061861f71d2} - H:\Autoplay.exe -auto
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Internet Explorer:
==================
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\Software\Microsoft\Internet
Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
FireFox:
========
=======
Opera:
=======
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop
Common\ElevationManager\AdobeUpdateService.exe [817760 2017-09-20] (Adobe Systems
Incorporated)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072
2016-05-30] (Disc Soft Ltd)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
Error(1) reading file: "C:\Users\Win 7\Downloads\THE PAPER PEGASUS HEXAGON PS BRUSHES "
2017-11-16 20:58 - 2012-07-20 02:06 - 000068656 _____ C:\Users\Win 7\Desktop\good times rg.ttf
2017-11-09 22:20 - 2017-11-09 22:20 - 000000000 ____D C:\Program Files (x86)\Mouse Server
2017-12-04 17:07 - 2017-10-11 02:22 - 000000000 ___RD C:\Users\Win 7\Creative Cloud Files
2017-11-13 16:37 - 2017-08-10 22:55 - 000000000 ____D C:\Program Files (x86)\Popcorn Time
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\FreeLAN\bin\freelan.exe
(Avira Operations Gmbh & Co. KG) C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe Shopping.exe
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will
not be moved.)
HKLM-x32\...\Run: [Avira Safe Shopping] => C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe
Shopping.exe [546960 2017-10-30] (Avira Operations Gmbh & Co. KG)
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: G - G:\stp-fm2017.exe
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: {d2c0facc-7de3-11e7-
85e9-4061861f71d2} - H:\Autoplay.exe -auto
Internet Explorer:
==================
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\Software\Microsoft\Internet
Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
FireFox:
========
FF ProfilePath: C:\Users\Win 7\AppData\Roaming\Mozilla\Firefox\Profiles\bN6sIJQi.default [2017-09-
11]
Chrome:
=======
Opera:
=======
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072
2016-05-30] (Disc Soft Ltd)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
2017-11-16 20:58 - 2012-07-20 02:06 - 000068656 _____ C:\Users\Win 7\Desktop\good times rg.ttf
2017-11-09 22:20 - 2017-11-09 22:20 - 000000000 ____D C:\Program Files (x86)\Mouse Server
2017-12-04 17:07 - 2017-10-11 02:22 - 000000000 ___RD C:\Users\Win 7\Creative Cloud Files
2017-11-13 16:37 - 2017-08-10 22:55 - 000000000 ____D C:\Program Files (x86)\Popcorn Time
C:\Windows\system32\userinit.exe => File is digitally signedScan result of Farbar Recovery Scan Tool
(FRST) (x64) Version: 30-11-2017
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\FreeLAN\bin\freelan.exe
(Avira Operations Gmbh & Co. KG) C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe Shopping.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common
Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will
not be moved.)
HKLM-x32\...\Run: [Avira Safe Shopping] => C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe
Shopping.exe [546960 2017-10-30] (Avira Operations Gmbh & Co. KG)
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: G - G:\stp-fm2017.exe
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: {d2c0facc-7de3-11e7-
85e9-4061861f71d2} - H:\Autoplay.exe -auto
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Internet Explorer:
==================
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\Software\Microsoft\Internet
Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
FireFox:
========
Chrome:
=======
=======
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072
2016-05-30] (Disc Soft Ltd)
R2 FreeLAN Service; C:\Program Files\FreeLAN\bin\freelan.exe [3486720 2015-05-07] () [File not signed]
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
==================== One Month Created files and folders ========
Error(1) reading file: "C:\Users\Win 7\Downloads\THE PAPER PEGASUS HEXAGON PS BRUSHES "
2017-11-16 20:58 - 2012-07-20 02:06 - 000068656 _____ C:\Users\Win 7\Desktop\good times rg.ttf
2017-11-09 22:20 - 2017-11-09 22:20 - 000000000 ____D C:\Program Files (x86)\Mouse Server
2017-12-04 17:07 - 2017-10-11 02:22 - 000000000 ___RD C:\Users\Win 7\Creative Cloud Files
2017-11-13 16:37 - 2017-08-10 22:55 - 000000000 ____D C:\Program Files (x86)\Popcorn Time
C:\Windows\system32\dnsapi.dll => File is digitally signedScan result of Farbar Recovery Scan Tool
(FRST) (x64) Version: 30-11-2017
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\FreeLAN\bin\freelan.exe
(Avira Operations Gmbh & Co. KG) C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe Shopping.exe
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will
not be moved.)
HKLM-x32\...\Run: [Avira Safe Shopping] => C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe
Shopping.exe [546960 2017-10-30] (Avira Operations Gmbh & Co. KG)
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: G - G:\stp-fm2017.exe
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: {d2c0facc-7de3-11e7-
85e9-4061861f71d2} - H:\Autoplay.exe -auto
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Internet Explorer:
==================
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\Software\Microsoft\Internet
Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
FireFox:
========
Chrome:
=======
Opera:
=======
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072
2016-05-30] (Disc Soft Ltd)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
Error(1) reading file: "C:\Users\Win 7\Downloads\THE PAPER PEGASUS HEXAGON PS BRUSHES "
2017-11-16 20:58 - 2012-07-20 02:06 - 000068656 _____ C:\Users\Win 7\Desktop\good times rg.ttf
2017-11-09 22:20 - 2017-11-09 22:20 - 000000000 ____D C:\Program Files (x86)\Mouse Server
2017-12-04 17:07 - 2017-10-11 02:22 - 000000000 ___RD C:\Users\Win 7\Creative Cloud Files
2017-11-13 16:37 - 2017-08-10 22:55 - 000000000 ____D C:\Program Files (x86)\Popcorn Time
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\FreeLAN\bin\freelan.exe
(Avira Operations Gmbh & Co. KG) C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe Shopping.exe
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will
not be moved.)
HKLM-x32\...\Run: [Avira Safe Shopping] => C:\Program Files (x86)\Avira\Safe Shopping\Avira Safe
Shopping.exe [546960 2017-10-30] (Avira Operations Gmbh & Co. KG)
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: G - G:\stp-fm2017.exe
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\MountPoints2: {d2c0facc-7de3-11e7-
85e9-4061861f71d2} - H:\Autoplay.exe -auto
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Internet Explorer:
==================
HKU\S-1-5-21-2737374540-661935763-2935816294-1000\Software\Microsoft\Internet
Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
========
Chrome:
=======
Opera:
=======
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072
2016-05-30] (Disc Soft Ltd)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved
unless listed separately.)
Error(1) reading file: "C:\Users\Win 7\Downloads\THE PAPER PEGASUS HEXAGON PS BRUSHES "
2017-11-16 20:58 - 2012-07-20 02:06 - 000068656 _____ C:\Users\Win 7\Desktop\good times rg.ttf
2017-11-09 22:20 - 2017-11-09 22:20 - 000000000 ____D C:\Program Files (x86)\Mouse Server
2017-11-13 16:37 - 2017-08-10 22:55 - 000000000 ____D C:\Program Files (x86)\Popcorn Time