My apologies for the delay in responding. Holidays prep is consuming more time than normal.
Installed and ran Malwarebytes. During setup, it had me close all open windows, and I had failed to remember the direction to check Scan for all Rootkits, so, after the initial scan, I checked Rootkits in settings and re-ran the scan. Here are both reports.
Malwarebytes
www.malwarebytes.com-Log Details-
Scan Date: 12/8/16
Scan Time: 7:47 AM
Logfile: Malwarebytesthreats.txt
Administrator: Yes
-Software Information-
Version: 3.0.4.1269
Components Version: 1.0.39
Update Package Version: 1.0.655
License: Trial
-System Information-
OS: Windows 10
CPU: x64
File System: NTFS
User: Tom-PC\Tom
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 477985
Time Elapsed: 12 min, 5 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 19
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\APPID\{F85FA3F2-D2C8-4D4D-BB1C-3181E691AF2B}, No Action By User, [8908], [161629],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{F85FA3F2-D2C8-4D4D-BB1C-3181E691AF2B}, No Action By User, [8908], [161629],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{F85FA3F2-D2C8-4D4D-BB1C-3181E691AF2B}, No Action By User, [8908], [161629],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\INTERFACE\{D6975F9E-15B2-4FE7-9D16-FC2E85CB201B}, No Action By User, [8908], [161631],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D6975F9E-15B2-4FE7-9D16-FC2E85CB201B}, No Action By User, [8908], [161631],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{D6975F9E-15B2-4FE7-9D16-FC2E85CB201B}, No Action By User, [8908], [161631],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A3F56272-CDB4-4310-9BB1-9A0D0757A3B3}, No Action By User, [8908], [161631],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{A3F56272-CDB4-4310-9BB1-9A0D0757A3B3}, No Action By User, [8908], [161631],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\TYPELIB\{A3F56272-CDB4-4310-9BB1-9A0D0757A3B3}, No Action By User, [8908], [161631],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}, No Action By User, [343], [168276],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}, No Action By User, [343], [168276],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{60E91567-EF8A-4520-BCE2-83ABA5256799}, No Action By User, [343], [168328],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{60E91567-EF8A-4520-BCE2-83ABA5256799}, No Action By User, [343], [168328],1.0.655
PUP.Optional.SelectionLinks, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2}, No Action By User, [11870], [161094],1.0.655
PUP.Optional.SelectionLinks, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2}, No Action By User, [11870], [161094],1.0.655
PUP.Optional.SelectionLinks, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2}, No Action By User, [11870], [161094],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{7B9F8C21-46EC-4C0B-8683-E755EF84577A}, No Action By User, [343], [168358],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3462C343-BE19-4143-AF70-CEFB56F46FC6}, No Action By User, [343], [168265],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3462C343-BE19-4143-AF70-CEFB56F46FC6}, No Action By User, [343], [168265],1.0.655
Registry Value: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 0
(No malicious items detected)
File: 0
(No malicious items detected)
Physical Sector: 0
(No malicious items detected)
(end)
And the second report:
Malwarebytes
www.malwarebytes.com-Log Details-
Scan Date: 12/8/16
Scan Time: 7:47 AM
Logfile: Malwarebytesquarrantine.txt
Administrator: Yes
-Software Information-
Version: 3.0.4.1269
Components Version: 1.0.39
Update Package Version: 1.0.655
License: Trial
-System Information-
OS: Windows 10
CPU: x64
File System: NTFS
User: Tom-PC\Tom
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 477985
Time Elapsed: 12 min, 5 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 19
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\APPID\{F85FA3F2-D2C8-4D4D-BB1C-3181E691AF2B}, Quarantined, [8908], [161629],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{F85FA3F2-D2C8-4D4D-BB1C-3181E691AF2B}, Quarantined, [8908], [161629],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{F85FA3F2-D2C8-4D4D-BB1C-3181E691AF2B}, Quarantined, [8908], [161629],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\INTERFACE\{D6975F9E-15B2-4FE7-9D16-FC2E85CB201B}, Quarantined, [8908], [161631],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D6975F9E-15B2-4FE7-9D16-FC2E85CB201B}, Quarantined, [8908], [161631],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{D6975F9E-15B2-4FE7-9D16-FC2E85CB201B}, Quarantined, [8908], [161631],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A3F56272-CDB4-4310-9BB1-9A0D0757A3B3}, Quarantined, [8908], [161631],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{A3F56272-CDB4-4310-9BB1-9A0D0757A3B3}, Quarantined, [8908], [161631],1.0.655
PUP.Optional.FaceThemes, HKLM\SOFTWARE\CLASSES\TYPELIB\{A3F56272-CDB4-4310-9BB1-9A0D0757A3B3}, Quarantined, [8908], [161631],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}, Quarantined, [343], [168276],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3A421C8F-E238-4AEB-8874-B8B5F2CC4772}, Quarantined, [343], [168276],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{60E91567-EF8A-4520-BCE2-83ABA5256799}, Quarantined, [343], [168328],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{60E91567-EF8A-4520-BCE2-83ABA5256799}, Quarantined, [343], [168328],1.0.655
PUP.Optional.SelectionLinks, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2}, Quarantined, [11870], [161094],1.0.655
PUP.Optional.SelectionLinks, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2}, Quarantined, [11870], [161094],1.0.655
PUP.Optional.SelectionLinks, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FDCC62B4-8059-4FCF-8B69-BD2EC413A6F2}, Quarantined, [11870], [161094],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{7B9F8C21-46EC-4C0B-8683-E755EF84577A}, Quarantined, [343], [168358],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3462C343-BE19-4143-AF70-CEFB56F46FC6}, Quarantined, [343], [168265],1.0.655
PUP.Optional.MindSpark, HKU\S-1-5-21-1175564447-90967221-3468872393-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3462C343-BE19-4143-AF70-CEFB56F46FC6}, Quarantined, [343], [168265],1.0.655
Registry Value: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 0
(No malicious items detected)
File: 0
(No malicious items detected)
Physical Sector: 0
(No malicious items detected)
(end)
I didn't see an option to remove, only to quarantine.
Anything further? System continues to run smoothly.
Tom Tobin