Author Topic: [Inactive] 4 BSOD in a row when starting up my comp this AM, error: 0x0000001e  (Read 1208 times)

Offline darmab

  • Bronze Member
  • Posts: 24
I am able to use my computer only in safe mode. I tried a system restore but it didn't work. I ran malware bytes and super anti spyware but didn't come up with anything. Then I downloaded a utility to identify the driver, blue screen view was the software. It found one driver that was involved, ntoskrnl.exe. That's all I have.

thanks for any help you can give me,

Kathy



DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 11.0.9600.18205  BrowserJavaVersion: 11.66.2
Run by kathy at 15:48:21 on 2016-03-07
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.16298.14194 [GMT -5:00]
.
AV: ESET NOD32 Antivirus 8.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: ESET NOD32 Antivirus 8.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = www.google.com
uDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uURLSearchHooks: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - <orphaned>
mWinlogon: Userinit = userinit.exe,
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [WinPatrol] C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe -expressboot
uRun: [AB2BD042E0BA24084910E3A45D408EF5B31CB3BA._service_run] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
dRunOnce: [adaware] reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f
dRunOnce: [adaware_XP] reg.exe delete "HKCU\Software\adaware" /f
StartupFolder: C:\Users\kathy\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SNAGIT~1.LNK - C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: EnableSecureUIAPath = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Download current page with FreshWebSuction - C:\Program Files (x86)\FreshWebmaster\FreshWebSuction\obiectx_all.htm
IE: Download using FreshWebSuction - C:\Program Files (x86)\FreshWebmaster\FreshWebSuction\obiectx.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
Trusted Zone: dell.com
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
TCP: NameServer = 192.168.40.254
TCP: Interfaces\{2B00193A-C0DE-4811-B67E-08A2155D61C3} : DHCPNameServer = 192.168.40.254
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = www.google.com
x64-mDefault_Page_URL = www.google.com
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
x64-Run: [RtHDVBg_DTS] "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /DTSU2P
x64-Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2013-11-5 83176]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2013-11-5 43240]
R0 amdkmpfd;AMD PCI Root Bus Lower Filter;C:\Windows\System32\drivers\amdkmpfd.sys [2014-10-27 62152]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2013-8-16 140032]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2013-8-16 424192]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2015-2-3 58536]
S1 eamonm;eamonm;C:\Windows\System32\drivers\eamonm.sys [2015-7-13 255240]
S1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
S1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
S2 AcerSyncServiceWinService;AcerSyncServiceWinService;C:\Program Files\Acer\AcerSync\AcerSyncService.exe -p --> C:\Program Files\Acer\AcerSync\AcerSyncService.exe -p [?]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2014-11-20 244736]
S2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2014-11-20 344064]
S2 AODDriver4.3;AODDriver4.3;C:\Program Files\AMD\ATI.ACE\Fuel\amd64\aoddriver2.sys [2014-2-11 59616]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-5 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-5 125112]
S2 DTSAudioSvc;DTSAudioSvc;C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [2015-2-3 240584]
S2 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2015-7-8 1353720]
S2 epfwwfpr;epfwwfpr;C:\Windows\System32\drivers\epfwwfpr.sys [2015-7-13 168208]
S2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe [2015-3-28 89840]
S2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2013-1-3 183200]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-8-15 1133880]
S2 NVWMI;NVIDIA WMI Provider;C:\Windows\System32\nvwmi64.exe [2015-2-3 2683736]
S2 SkypeUpdate;Skype Updater;"E:\Kathy\Windows.old\Program Files\Skype\Updater\Updater.exe" --> E:\Kathy\Windows.old\Program Files\Skype\Updater\Updater.exe [?]
S2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2015-4-15 6583160]
S2 TechSmith Uploader Service;TechSmith Uploader Service;C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [2015-1-26 3408384]
S2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2015-4-15 528760]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2014-6-21 94720]
S3 cleanhlp;cleanhlp;C:\EEK\Run\cleanhlp64.sys [2014-3-18 57024]
S3 G311N6;NETGEAR GA311 Gigabit Driver;C:\Windows\System32\drivers\G311N6.sys [2011-11-9 347680]
S3 hidkmdf;KMDF Driver;C:\Windows\System32\drivers\hidkmdf.sys [2013-12-5 14136]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2016-2-9 114688]
S3 LVcKap64;Logitech AEC Driver;C:\Windows\System32\drivers\LVCKap64.sys [2007-2-6 1013024]
S3 lvpepf64;Volume Adapter;C:\Windows\System32\drivers\lv302a64.sys [2008-7-26 15768]
S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2008-7-26 790424]
S3 LVUSBS64;Logitech USB Monitor Filter;C:\Windows\System32\drivers\LVUSBS64.sys [2008-7-26 50072]
S3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-11-9 25816]
S3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2014-8-15 63704]
S3 MHIKEY10;MHIKEY10;C:\Windows\System32\drivers\MHIKEY10x64.sys [2010-9-15 60288]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-3-15 19456]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 SWDUMon;SWDUMon;C:\Windows\System32\drivers\SWDUMon.sys [2014-6-20 16056]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-3-15 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-3-15 30208]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\System32\drivers\wacmoumonitor.sys [2015-4-15 13312]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-11-11 1255736]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2015-4-30 23200]
S4 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2012-7-11 172344]
S4 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-1-19 77128]
.
=============== File Associations ===============
.
FileExt: .inf: inffile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2016-03-07 19:54:52   50320   ----a-w-   C:\Windows\System32\drivers\PSKMAD.sys
2016-03-07 19:54:52   39672   ----a-w-   C:\Windows\System32\drivers\DasPtct.SYS
2016-03-07 19:54:43   --------   d-----w-   C:\Program Files (x86)\Panda Security
2016-03-07 19:33:57   75888   ----a-w-   C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FB3C9D3C-A735-42F8-9715-EA7C421DF0F9}\offreg.2036.dll
2016-03-07 17:20:16   --------   d-----w-   C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-03-07 14:26:09   --------   d-----w-   C:\Program Files\CPUID
2016-03-07 11:42:51   11154520   ----a-w-   C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FB3C9D3C-A735-42F8-9715-EA7C421DF0F9}\mpengine.dll
2016-03-01 21:11:51   --------   d-----w-   C:\Users\kathy\AppData\Roaming\CELSYS_EN
2016-03-01 20:58:57   --------   d-----w-   C:\ProgramData\CELSYS_EN
2016-03-01 20:58:26   --------   d-----w-   C:\Program Files\CELSYS
2016-02-24 13:36:14   --------   d-----w-   C:\Users\kathy\AppData\Local\assembly
2016-02-24 13:36:11   --------   d-----w-   C:\Users\kathy\AppData\Local\TechSmith
2016-02-24 13:35:35   --------   d-----w-   C:\ProgramData\regid.1995-08.com.techsmith
2016-02-24 13:34:58   --------   d-----w-   C:\Program Files (x86)\Common Files\TechSmith Shared
2016-02-23 15:15:08   --------   d-----w-   C:\Users\kathy\AppData\Roaming\CELSYS
2016-02-23 14:09:05   --------   d-----w-   C:\ProgramData\FEA3F5DE-0F10-454D-B6C0-55E35B170A9D
2016-02-23 14:09:05   --------   d-----w-   C:\ProgramData\69B6DBD2-8E05-476F-B662-CF8D235FD499
2016-02-23 14:08:52   --------   d-----w-   C:\Users\kathy\AppData\Roaming\Smith Micro
2016-02-23 13:47:46   --------   d-----w-   C:\ProgramData\Smith Micro
2016-02-09 20:48:14   141312   ----a-w-   C:\Windows\System32\drivers\mrxdav.sys
2016-02-09 20:48:13   3180544   ----a-w-   C:\Windows\System32\rdpcorets.dll
2016-02-09 20:48:13   243200   ----a-w-   C:\Windows\System32\rdpudd.dll
2016-02-09 20:48:13   16384   ----a-w-   C:\Windows\System32\RdpGroupPolicyExtension.dll
2016-02-09 20:48:12   3211776   ----a-w-   C:\Windows\System32\win32k.sys
2016-02-09 20:47:46   2085888   ----a-w-   C:\Windows\System32\ole32.dll
2016-02-09 20:47:44   1413632   ----a-w-   C:\Windows\SysWow64\ole32.dll
2016-02-09 18:45:17   677376   ----a-w-   C:\Windows\System32\generaltel.dll
2016-02-09 18:44:39   3231232   ----a-w-   C:\Windows\explorer.exe
2016-02-09 18:44:38   2973184   ----a-w-   C:\Windows\SysWow64\explorer.exe
2016-02-09 18:44:38   1940992   ----a-w-   C:\Windows\System32\authui.dll
2016-02-09 18:44:38   1866752   ----a-w-   C:\Windows\System32\ExplorerFrame.dll
2016-02-09 18:44:37   1805824   ----a-w-   C:\Windows\SysWow64\authui.dll
2016-02-09 18:44:37   1498624   ----a-w-   C:\Windows\SysWow64\ExplorerFrame.dll
.
==================== Find3M  ====================
.
2016-03-07 18:43:07   16056   ----a-w-   C:\Windows\System32\drivers\SWDUMon.sys
2016-03-07 17:20:16   192216   ----a-w-   C:\Windows\System32\drivers\MBAMSwissArmy.sys
2016-03-07 17:19:25   109272   ----a-w-   C:\Windows\System32\drivers\mbamchameleon.sys
2016-02-10 06:55:22   796864   ----a-w-   C:\Windows\SysWow64\FlashPlayerApp.exe
2016-02-10 06:55:22   142528   ----a-w-   C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2016-02-06 10:32:57   2724864   ----a-w-   C:\Windows\System32\mshtml.tlb
2016-02-06 10:10:21   144384   ----a-w-   C:\Windows\System32\ieUnatt.exe
2016-02-06 09:54:50   2724864   ----a-w-   C:\Windows\SysWow64\mshtml.tlb
2016-02-06 09:37:23   115712   ----a-w-   C:\Windows\SysWow64\ieUnatt.exe
2016-01-22 06:56:05   4096   ----a-w-   C:\Windows\System32\ieetwcollectorres.dll
2016-01-22 06:41:35   66560   ----a-w-   C:\Windows\System32\iesetup.dll
2016-01-22 06:40:50   48640   ----a-w-   C:\Windows\System32\ieetwproxystub.dll
2016-01-22 06:40:43   417792   ----a-w-   C:\Windows\System32\html.iec
2016-01-22 06:40:13   88064   ----a-w-   C:\Windows\System32\MshtmlDac.dll
2016-01-22 06:40:12   571904   ----a-w-   C:\Windows\System32\vbscript.dll
2016-01-22 06:29:43   6052352   ----a-w-   C:\Windows\System32\jscript9.dll
2016-01-22 06:27:40   114688   ----a-w-   C:\Windows\System32\ieetwcollector.exe
2016-01-22 06:27:24   814080   ----a-w-   C:\Windows\System32\jscript9diag.dll
2016-01-22 06:27:10   5573056   ----a-w-   C:\Windows\System32\ntoskrnl.exe
2016-01-22 06:27:08   95680   ----a-w-   C:\Windows\System32\drivers\ksecdd.sys
2016-01-22 06:27:08   154560   ----a-w-   C:\Windows\System32\drivers\ksecpkg.sys
2016-01-22 06:24:12   1733592   ----a-w-   C:\Windows\System32\ntdll.dll
2016-01-22 06:20:53   362496   ----a-w-   C:\Windows\System32\wow64win.dll
2016-01-22 06:20:53   243712   ----a-w-   C:\Windows\System32\wow64.dll
2016-01-22 06:20:53   13312   ----a-w-   C:\Windows\System32\wow64cpu.dll
2016-01-22 06:20:36   215040   ----a-w-   C:\Windows\System32\winsrv.dll
2016-01-22 06:20:33   968704   ----a-w-   C:\Windows\System32\MsSpellCheckingFacility.exe
2016-01-22 06:20:31   210432   ----a-w-   C:\Windows\System32\wdigest.dll
2016-01-22 06:20:20   86528   ----a-w-   C:\Windows\System32\TSpkg.dll
2016-01-22 06:20:10   28672   ----a-w-   C:\Windows\System32\sspisrv.dll
2016-01-22 06:20:10   135680   ----a-w-   C:\Windows\System32\sspicli.dll
2016-01-22 06:20:08   503808   ----a-w-   C:\Windows\System32\srcore.dll
2016-01-22 06:20:08   50176   ----a-w-   C:\Windows\System32\srclient.dll
2016-01-22 06:19:06   28160   ----a-w-   C:\Windows\System32\secur32.dll
2016-01-22 06:19:04   344064   ----a-w-   C:\Windows\System32\schannel.dll
2016-01-22 06:19:02   1214464   ----a-w-   C:\Windows\System32\rpcrt4.dll
2016-01-22 06:18:49   961024   ----a-w-   C:\Windows\System32\CPFilters.dll
2016-01-22 06:18:49   723968   ----a-w-   C:\Windows\System32\EncDec.dll
2016-01-22 06:18:32   16384   ----a-w-   C:\Windows\System32\ntvdm64.dll
2016-01-22 06:17:03   312320   ----a-w-   C:\Windows\System32\ncrypt.dll
2016-01-22 06:17:01   159744   ----a-w-   C:\Windows\System32\mtxoci.dll
2016-01-22 06:17:00   315392   ----a-w-   C:\Windows\System32\msv1_0.dll
2016-01-22 06:16:55   60416   ----a-w-   C:\Windows\System32\msobjs.dll
2016-01-22 06:16:39   146432   ----a-w-   C:\Windows\System32\msaudite.dll
2016-01-22 06:16:00   1461248   ----a-w-   C:\Windows\System32\lsasrv.dll
2016-01-22 06:15:31   730112   ----a-w-   C:\Windows\System32\kerberos.dll
2016-01-22 06:15:31   422400   ----a-w-   C:\Windows\System32\KernelBase.dll
2016-01-22 06:13:15   3993536   ----a-w-   C:\Windows\SysWow64\ntkrnlpa.exe
2016-01-22 06:13:15   3938752   ----a-w-   C:\Windows\SysWow64\ntoskrnl.exe
2016-01-22 06:13:06   43520   ----a-w-   C:\Windows\System32\csrsrv.dll
2016-01-22 06:13:04   43520   ----a-w-   C:\Windows\System32\cryptbase.dll
2016-01-22 06:13:03   22016   ----a-w-   C:\Windows\System32\credssp.dll
2016-01-22 06:09:40   1314328   ----a-w-   C:\Windows\SysWow64\ntdll.dll
2016-01-22 06:09:06   77824   ----a-w-   C:\Windows\System32\JavaScriptCollectionAgent.dll
2016-01-22 06:06:50   96768   ----a-w-   C:\Windows\SysWow64\sspicli.dll
2016-01-22 06:06:50   665088   ----a-w-   C:\Windows\SysWow64\rpcrt4.dll
2016-01-22 06:06:50   5120   ----a-w-   C:\Windows\SysWow64\wow32.dll
2016-01-22 06:06:50   275456   ----a-w-   C:\Windows\SysWow64\KernelBase.dll
2016-01-22 06:06:30   171520   ----a-w-   C:\Windows\SysWow64\wdigest.dll
2016-01-22 06:06:19   65536   ----a-w-   C:\Windows\SysWow64\TSpkg.dll
2016-01-22 06:06:11   43008   ----a-w-   C:\Windows\SysWow64\srclient.dll
2016-01-22 06:05:27   22016   ----a-w-   C:\Windows\SysWow64\secur32.dll
2016-01-22 06:05:20   251392   ----a-w-   C:\Windows\SysWow64\schannel.dll
2016-01-22 06:04:36   642048   ----a-w-   C:\Windows\SysWow64\CPFilters.dll
2016-01-22 06:04:36   535040   ----a-w-   C:\Windows\SysWow64\EncDec.dll
2016-01-22 06:02:58   223232   ----a-w-   C:\Windows\SysWow64\ncrypt.dll
2016-01-22 06:02:56   114176   ----a-w-   C:\Windows\SysWow64\mtxoci.dll
2016-01-22 06:02:55   259584   ----a-w-   C:\Windows\SysWow64\msv1_0.dll
2016-01-22 06:02:52   176128   ----a-w-   C:\Windows\SysWow64\msorcl32.dll
2016-01-22 06:02:49   60416   ----a-w-   C:\Windows\SysWow64\msobjs.dll
2016-01-22 06:02:26   146432   ----a-w-   C:\Windows\SysWow64\msaudite.dll
2016-01-22 06:02:01   62464   ----a-w-   C:\Windows\SysWow64\iesetup.dll
2016-01-22 06:02:01   496640   ----a-w-   C:\Windows\SysWow64\vbscript.dll
2016-01-22 06:02:00   553472   ----a-w-   C:\Windows\SysWow64\kerberos.dll
2016-01-22 06:01:26   47616   ----a-w-   C:\Windows\SysWow64\ieetwproxystub.dll
2016-01-22 06:01:17   341504   ----a-w-   C:\Windows\SysWow64\html.iec
2016-01-22 06:00:26   64000   ----a-w-   C:\Windows\SysWow64\MshtmlDac.dll
2016-01-22 05:51:37   620032   ----a-w-   C:\Windows\SysWow64\jscript9diag.dll
2016-01-22 05:46:10   2123264   ----a-w-   C:\Windows\System32\inetcpl.cpl
2016-01-22 05:46:00   1359360   ----a-w-   C:\Windows\System32\mshtmlmedia.dll
2016-01-22 05:39:38   60416   ----a-w-   C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2016-01-22 05:35:15   4611072   ----a-w-   C:\Windows\SysWow64\jscript9.dll
2016-01-22 05:31:43   2597376   ----a-w-   C:\Windows\System32\wininet.dll
2016-01-22 05:24:59   2050560   ----a-w-   C:\Windows\SysWow64\inetcpl.cpl
2016-01-22 05:24:40   1155072   ----a-w-   C:\Windows\SysWow64\mshtmlmedia.dll
2016-01-22 05:13:56   64000   ----a-w-   C:\Windows\System32\auditpol.exe
2016-01-22 05:07:28   2120704   ----a-w-   C:\Windows\SysWow64\wininet.dll
2016-01-22 05:07:16   338432   ----a-w-   C:\Windows\System32\conhost.exe
2016-01-22 05:07:09   50176   ----a-w-   C:\Windows\SysWow64\auditpol.exe
2016-01-22 05:05:44   296960   ----a-w-   C:\Windows\System32\rstrui.exe
2016-01-22 04:59:53   159232   ----a-w-   C:\Windows\System32\drivers\mrxsmb.sys
2016-01-22 04:58:52   290816   ----a-w-   C:\Windows\System32\drivers\mrxsmb10.sys
2016-01-22 04:58:46   129024   ----a-w-   C:\Windows\System32\drivers\mrxsmb20.sys
2016-01-22 04:57:17   30720   ----a-w-   C:\Windows\System32\lsass.exe
2016-01-22 04:57:09   112640   ----a-w-   C:\Windows\System32\smss.exe
2016-01-22 04:53:59   25600   ----a-w-   C:\Windows\SysWow64\setup16.exe
2016-01-22 04:53:56   7680   ----a-w-   C:\Windows\SysWow64\instnm.exe
2016-01-22 04:53:56   14336   ----a-w-   C:\Windows\SysWow64\ntvdm64.dll
2016-01-22 04:53:55   2048   ----a-w-   C:\Windows\SysWow64\user.exe
2016-01-22 04:51:55   36352   ----a-w-   C:\Windows\SysWow64\cryptbase.dll
.
============= FINISH: 15:49:40.74 ===============



.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 11/9/2011 1:58:23 PM
System Uptime: 3/7/2016 2:30:22 PM (1 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. |  | CROSSHAIR V FORMULA-Z
Processor: AMD Phenom(tm) II X6 1100T Processor | Socket 942 | 3311/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 2048 GiB total, 1199.567 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is FIXED (NTFS) - 1863 GiB total, 712.351 GiB free.
G: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: ehdrv
Device ID: ROOT\LEGACY_EHDRV\0000
Manufacturer:
Name: ehdrv
PNP Device ID: ROOT\LEGACY_EHDRV\0000
Service: ehdrv
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: Security Processor Loader Driver
Device ID: ROOT\LEGACY_SPLDR\0000
Manufacturer:
Name: Security Processor Loader Driver
PNP Device ID: ROOT\LEGACY_SPLDR\0000
Service: spldr
.
==== System Restore Points ===================
.
RP555: 3/4/2016 4:00:38 PM - Windows Update
.
==== Installed Programs ======================
.
6300
6300_Help
6300Trb
64 Bit HP CIO Components Installer
7-Zip 9.20 (x64 edition)
Adobe AIR
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Download Assistant
Adobe Flash Player 20 ActiveX
Adobe Flash Player 20 NPAPI
Adobe Help Center 1.0
Adobe InDesign CS2
Adobe Media Player
Adobe PageMaker 7.0
Adobe Photoshop CS5.1
Adobe Reader XI (11.0.14)
Adobe Refresh Manager
Adobe Shockwave Player 12.1
Adobe Stock Photos 1.0
Adobe SVG Viewer 3.0
AIO_CDB_ProductContext
AIO_CDB_Software
AIO_Scan
Amazon Kindle
Amazon MP3 Downloader 1.0.17
AMD Accelerated Video Transcoding
AMD APP SDK Runtime
AMD Catalyst Control Center
AMD Catalyst Install Manager
AMD Drag and Drop Transcoding
AMD Fuel
AMD Media Foundation Decoders
AMD Wireless Display v3.0
Apple Application Support (32-bit)
Apple Application Support (64-bit)
Apple Mobile Device Support
Apple Software Update
Asmedia ASM104x USB 3.0 Host Controller Driver
ATI AVIVO64 Codecs
ATI Problem Report Wizard
Audacity 2.0.4
AudibleManager
Bamboo
Bonjour
BufferChm
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Chessmaster Grandmaster Edition
CLIP STUDIO PAINT
Copy
CPUID CPU-Z 1.75
D3DX10
Definition Update for Microsoft Office 2010 (KB3114758) 32-Bit Edition
Destinations
DeviceDiscovery
DivX Web Player
DocProc
ESET NOD32 Antivirus
ESET Online Scanner v3
Fax
foobar2000 v1.1.1
Google Chrome
Google Update Helper
GPBaseService2
HiJackThis
HP Customer Participation Program 13.0
HP Imaging Device Functions 13.0
HP Photosmart Essential 3.5
HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B
HP Smart Web Printing 4.51
HP Solution Center 13.0
HP Support Solutions Framework
HPPhotoGadget
HPPhotoSmartDiscLabelContent1
HPPhotosmartEssential
HPProductAssistant
Intel(R) Network Connections 18.1.59.0
iTunes
Java 8 Update 66
Java Auto Updater
JMicron JMB36X Driver
Logitech Audio Echo Cancellation Component for 64-bit Windows
Logitech Video Enumerator
Logitech® Camera Driver
Malwarebytes Anti-Malware version 2.1.8.1057
MarketResearch
Microsoft .NET Framework 4.6.1
Microsoft Application Error Reporting
Microsoft Mouse and Keyboard Center
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Office 64-bit Components 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared 64-bit MUI (English) 2010
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server Compact 3.5 SP1 ????
Microsoft SQL Server Compact 3.5 SP1 x64 ????
Microsoft Sync Framework Runtime v1.0 (x64)
Microsoft Sync Framework Services v1.0 (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
Microsoft_VC80_ATL_x86_x64
Microsoft_VC80_CRT_x86
Microsoft_VC80_CRT_x86_x64
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFC_x86_x64
Microsoft_VC80_MFCLOC_x86
Microsoft_VC80_MFCLOC_x86_x64
Microsoft_VC90_ATL_x86
Microsoft_VC90_ATL_x86_x64
Microsoft_VC90_CRT_x86
Microsoft_VC90_CRT_x86_x64
Microsoft_VC90_MFC_x86
Microsoft_VC90_MFC_x86_x64
Microsoft_VC90_MFCLOC_x86
Microsoft_VC90_MFCLOC_x86_x64
Movie Maker
MSVCRT
MSVCRT110
MSVCRT110_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MVisn64
Network64
NVIDIA 3D Vision Controller Driver 340.50
NVIDIA Control Panel 340.52
NVIDIA Graphics Driver 340.52
NVIDIA HD Audio Driver 1.3.30.2
NVIDIA Install Application
NVIDIA nView 141.24
NVIDIA WMI 2.18.0
OCR Software by I.R.I.S. 13.0
OpenOffice 4.1.1
Panda Cloud Cleaner
PDF Settings CS5
Photo Common
Photo Gallery
QuickTime 7
Raptr
Realtek High Definition Audio Driver
Scan
Scrivener
SeaTools for Windows
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4.6.1 (KB3122661)
Security Update for Microsoft .NET Framework 4.6.1 (KB3127233)
Security Update for Microsoft Access 2010 (KB3101544) 32-Bit Edition
Security Update for Microsoft Excel 2010 (KB3114759) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2878230) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553313) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2880971) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2881029) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2881071) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2920748) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2965310) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB3054848) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB3085528) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB3085560) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB3114396) 32-Bit Edition
Security Update for Microsoft Publisher 2010 (KB2817478) 32-Bit Edition
Security Update for Microsoft Visio 2010 (KB3114402) 32-Bit Edition
Security Update for Microsoft Word 2010 (KB2965313) 32-Bit Edition
Security Update for Microsoft Word 2010 (KB3114755) 32-Bit Edition
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
Skype Click to Call
Skype™ 5.8
SlimDrivers
SmartWebPrinting
Snagit 12
SolutionCenter
SRWare Iron version SRWare Iron 39.2100.0
StationRipper 2.98.6
Status
Streamripper (Remove only)
SUPERAntiSpyware
swMSM
Toolbox
TrayApp
UnloadSupport
Update for Microsoft Excel 2010 (KB2589348) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2999508) 32-Bit Edition
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553140) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553347) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553388) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589318) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589386) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597089) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687275) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2791057) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition
Update for Microsoft Office 2010 (KB2883019) 32-Bit Edition
Update for Microsoft Office 2010 (KB2889828) 32-Bit Edition
Update for Microsoft Office 2010 (KB2910896) 32-Bit Edition
Update for Microsoft Office 2010 (KB3054873) 32-Bit Edition
Update for Microsoft Office 2010 (KB3054886) 32-Bit Edition
Update for Microsoft Office 2010 (KB3055042) 32-Bit Edition
Update for Microsoft Office 2010 (KB3055047) 32-Bit Edition
Update for Microsoft Office 2010 (KB3085512) 32-Bit Edition
Update for Microsoft Office 2010 (KB3114555) 32-Bit Edition
Update for Microsoft Office 2010 (KB3114750) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2956075) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB3114410) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2760779) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB3114756) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553308) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2880517) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2881021) 32-Bit Edition
VC 9.0 Runtime
VC_CRT_x64
VC80CRTRedist - 8.0.50727.762
Visual Studio 2008 x64 Redistributables
Visual Studio 2010 x64 Redistributables
VLC media player
Waterfox 43.0.4 (x64 en-US)
WebReg
WebTablet FB Plugin
WebTablet IE Plugin
WebTablet Netscape Plugin
WhoCrashed 5.01
Winamp
Winamp Detector Plug-in
Windows Driver Package - ACER Incorporated (qcusbser) Modem  (10/12/2009 2.0.6.6)
Windows Driver Package - ACER Incorporated (qcusbser) Ports  (10/12/2009 2.0.6.6)
Windows Driver Package - ACER, Inc (androidusb) USB  (10/12/2009 1.0.0010.00000)
Windows Installer Clean Up
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Player Firefox Plugin
WinPatrol
ZoneAlarm Antivirus
.
==== Event Viewer Messages From Past Week ========
.
3/7/2016 6:40:20 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80003ee1d5b, 0x0000000000000000, 0xffffffffffffffff). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 030716-25615-01.
3/7/2016 6:38:15 AM, Error: Service Control Manager [7024]  - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
3/7/2016 6:36:39 AM, Error: Service Control Manager [7024]  - The Windows Firewall service terminated with service-specific error Access is denied..
3/7/2016 6:29:23 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80003ecdd5b, 0x0000000000000000, 0xffffffffffffffff). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 030716-24726-01.
3/7/2016 6:26:12 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80003f2dd5b, 0x0000000000000000, 0xffffffffffffffff). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 030716-26878-01.
3/7/2016 3:48:50 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service NVSvc with arguments "" in order to run the server: {DCAB0989-1301-4319-BE5F-ADE89F88581C}
3/7/2016 2:42:50 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
3/7/2016 2:31:18 PM, Error: Service Control Manager [7001]  - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:  The dependency service or group failed to start.
3/7/2016 2:31:17 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
3/7/2016 2:31:17 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
3/7/2016 2:31:16 PM, Error: Microsoft-Windows-DNS-Client [1012]  - There was an error while attempting to read the local hosts file.
3/7/2016 2:31:15 PM, Error: Service Control Manager [7001]  - The Computer Browser service depends on the Server service which failed to start because of the following error:  The dependency service or group failed to start.
3/7/2016 2:31:12 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
3/7/2016 2:31:05 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
3/7/2016 2:30:54 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service TermService with arguments "" in order to run the server: {F9A874B6-F8A8-4D73-B5A8-AB610816828B}
3/7/2016 2:30:53 PM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  discache eamonm ehdrv SASDIFSV SASKUTIL spldr Wanarpv6
3/7/2016 2:30:52 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000003b (0x00000000c0000005, 0xfffff960000c9760, 0xfffff8800da32f10, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 030716-23852-01.
3/7/2016 2:28:31 PM, Error: Service Control Manager [7000]  - The Skype Updater service failed to start due to the following error:  The system cannot find the file specified.
3/7/2016 2:28:15 PM, Error: Service Control Manager [7000]  - The AODDriver4.2.0 service failed to start due to the following error:  The system cannot find the path specified.
3/7/2016 2:28:12 PM, Error: Service Control Manager [7000]  - The AcerSyncServiceWinService service failed to start due to the following error:  The system cannot find the file specified.
3/7/2016 2:28:11 PM, Error: Microsoft-Windows-DistributedCOM [10016]  - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID  {22279AF5-03AE-4CAF-989D-2530918B2F1C}  and APPID  {0773CCD6-59A2-4D26-B235-19247767E645}  to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
3/7/2016 2:24:20 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
3/7/2016 2:20:25 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}
3/7/2016 2:20:25 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
3/7/2016 12:20:54 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service stisvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
3/4/2016 6:13:19 AM, Error: volsnap [36]  - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
3/4/2016 5:43:02 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000003b (0x00000000c0000005, 0xfffff88004b149c0, 0xfffff88005db0820, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 030416-22978-01.
3/3/2016 4:01:34 PM, Error: Service Control Manager [7031]  - The Superfetch service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/2/2016 9:04:52 AM, Error: Disk [11]  - The driver detected a controller error on \Device\Harddisk2\DR3.
3/2/2016 1:07:54 PM, Error: Disk [11]  - The driver detected a controller error on \Device\Harddisk2\DR4.
.
==== End Of File ===========================
« Last Edit: March 07, 2016, 07:22:49 PM by Hoov »



Offline Hoov

  • Malware Removal Mentors
  • Administrator
  • Diamond Member
  • Posts: 27056
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
PLATYPUSS will be helping you with your problem, please wait for the first post with instructions.

Former Consumer Security MVP
2011-2014

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline Foxfire

  • Malware Removal Staff
  • Bronze Member
  • Posts: 443

 Hello  darnab,

Just to let you know that I am going through your log currently.

Platypuss

Offline Foxfire

  • Malware Removal Staff
  • Bronze Member
  • Posts: 443


       I am Platypuss, I will be helping you with your problem.
   
Before we begin, please follow my simple rules:-
  • If you do not understand any instructions, Stop & Ask do not risk creating
          further problems.
  • Please do not run any tools unless instructed to do so because it may well
          cause unforseen damage to your machine.
  • It may help you to print out my instructions, so that mistakes are not made.
  • I am a trainee here but my instructions are checked by my mentor, there may be some delay but you will get a high quality of service.
  • Malware removal is frequently complex, it takes time to analyse logs, please be patient.   
  • I will advise you as soon as your computer is clean, until then it may still be infected !

Please Change your  Downloads  to Desktop http://www.thewindowsclub.com/change-download-location-ie-chrome



>>>>>>>>>>>>>>>
Step1

Since you are able to boot into safe mode. I would suggest you to do a clean boot from safe mode.

Clean Boot will help you start your computer by using a minimal set of drivers and startup programs so that you can determine whether a background program or any of the third party service is interfering with your program.
To perform clean boot in, please follow the steps below.
  • Click Start on your Desktop
  • Type msconfig in the Start Search box and then press ENTER.

If you are prompted for an administrator password or for a confirmation, type the password, or click   Continue.
  • On the General tab, click Selective Startup.
  • . Under Selective Startup, click to  the Load Startup Items check box.
  • Click the Services tab, click to select the Hide All Microsoft Services check box, and then click Disable All.
  • Click OK.
  • When you are prompted, click Restart.
  • [/b]
  Step 2

To return your computer back to normal boot:
  • Click Start on your Desktop
  • Type msconfig in the Start Search box and then press ENTER.

If you are prompted for an administrator password or for a confirmation, type the password, or click   Continue.
  • Click the General tab.
  • Click Normal Startup - load all device drivers and services, and then click OK.
  • When you are prompted, click Restart to restart the computer.
For information on using “Clean Boot”, see the following Microsoft Article:
http://support.microsoft.com/kb/331796

Once you finish with the clean boot from safe mode, you can try to boot in normal mode. If that doesn’t help then I woulde like you to download & run FRST in Safemode:-

Please download Farbar Recovery Scan Tool and save it to your Desktop.
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
The latest version of Farbar's Recovery Scan Tool may be downloaded from http://www.bleepingc...very-scan-tool/

platypuss


Offline darmab

  • Bronze Member
  • Posts: 24
Sorry I couldn't find the reply button before. I am getting error messages that I've exceeded the 65000 character limit when I paste the text docs so I've attached a zip file with both results of the test.

Offline Hoov

  • Malware Removal Mentors
  • Administrator
  • Diamond Member
  • Posts: 27056
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
I am posting here just to keep the ball rolling faster. You need to separate your post into two or more posts. Make sure to get the entire log. We don't like attachments, especially in the beginning of the removal process because it is a risk for your helper, and for anyone using your thread as research.

Former Consumer Security MVP
2011-2014

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline darmab

  • Bronze Member
  • Posts: 24
Okay. FRST. txt is as follows:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by kathy (administrator) on KATHYSBEAST-PC (09-03-2016 07:56:18)
Running from C:\Users\kathy\Desktop
Loaded Profiles: kathy (Available Profiles: kathy & nonadmin acct & Administrator)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files\Waterfox\waterfox.exe" -osint -url "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Windows\System32\nvwmi64.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Windows\System32\nvwmi64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Ruiware LLC) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe
(ATI Technologies Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\TscHelp.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagitEditor.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7200984 2013-10-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1353432 2013-09-26] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-13] (Adobe Systems Incorporated)
HKU\S-1-5-21-1474584281-122529757-4205316068-1000\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1154112 2014-07-20] (Ruiware LLC)
HKU\S-1-5-21-1474584281-122529757-4205316068-1000\...\Run: [AB2BD042E0BA24084910E3A45D408EF5B31CB3BA._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [746648 2016-02-17] (Google Inc.)
HKU\S-1-5-21-1474584281-122529757-4205316068-1000\...\MountPoints2: G - G:\LaunchU3.exe -a
HKU\S-1-5-18\...\RunOnce: [adaware] => reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f
HKU\S-1-5-18\...\RunOnce: [adaware_XP] => reg.exe delete "HKCU\Software\adaware" /f
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 12.lnk [2016-02-24]
ShortcutTarget: Snagit 12.lnk -> C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe (TechSmith Corporation)
Startup: C:\Users\kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-01-09]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 192.168.40.254
Tcpip\..\Interfaces\{2B00193A-C0DE-4811-B67E-08A2155D61C3}: [DhcpNameServer] 192.168.40.254

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
URLSearchHook: HKU\S-1-5-21-1474584281-122529757-4205316068-1000 - (No Name) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - No File
SearchScopes: HKU\S-1-5-21-1474584281-122529757-4205316068-1000 -> DefaultScope {1453F6D4-647B-433C-9D0C-587D9B807514} URL =
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-01] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-01] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKU\S-1-5-21-1474584281-122529757-4205316068-1000 -> No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} -  No File
Toolbar: HKU\S-1-5-21-1474584281-122529757-4205316068-1000 -> No Name - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} -  No File
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - E:\Kathy\Windows.old\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2011-11-03] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\91apipzn.default-1447001461029
FF Homepage: hxxp://www.drudgereport.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-10] ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-11-11] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-10] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1212152.dll [2014-05-30] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2009-05-12] (DivX,Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-01] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-11-11] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @oberon-media.com/ONCAdapter -> C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll [2012-05-31] (Oberon-Media )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.)
FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.10 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll [2011-04-20] (Wacom, Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.0.0.1 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2011-05-30] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-17] (Adobe Systems Inc.)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2011-05-30] (Wacom)
FF Plugin HKU\S-1-5-21-1474584281-122529757-4205316068-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10171.dll [2012-07-24] (Amazon.com, Inc.)
FF Plugin HKU\S-1-5-21-1474584281-122529757-4205316068-1000: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2011-05-30] (Wacom)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\libdivx.dll [2009-05-01] (The OpenSSL Project, http://www.openssl.org/)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdivx32.dll [2009-05-12] (DivX,Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-26] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-06-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-06-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-06-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-06-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-06-12] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ssldivx.dll [2009-05-01] (The OpenSSL Project, http://www.openssl.org/)
FF SearchPlugin: C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\91apipzn.default-1447001461029\searchplugins\ixquick-https.xml [2015-11-08]
FF Extension: Adblock Plus Pop-up Addon - C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\91apipzn.default-1447001461029\extensions\adblockpopups@jessehakanen.net.xpi [2015-11-08]
FF Extension: 1-Click YouTube Video Downloader - C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\91apipzn.default-1447001461029\extensions\YoutubeDownloader@PeterOlayev.com.xpi [2015-12-30]
FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\91apipzn.default-1447001461029\extensions\artur.dubovoy@gmail.com [2016-01-19]
FF Extension: Flash and Video Download - C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\91apipzn.default-1447001461029\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2016-02-26]
FF Extension: Adguard AdBlocker - C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\91apipzn.default-1447001461029\Extensions\adguardadblocker@adguard.com.xpi [2016-02-10]
FF Extension: Video DownloadHelper - C:\Users\kathy\AppData\Roaming\Mozilla\Firefox\Profiles\91apipzn.default-1447001461029\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-01-23]
FF Extension: Anti-Banner - C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru [2015-11-04] [not signed]
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2015-11-04] [not signed]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-11-04] [not signed]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-11-04] [not signed]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-10-03] [not signed]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
FF HKU\S-1-5-21-1474584281-122529757-4205316068-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: Default -> hxxp://www.drudgereport.com/
CHR StartupUrls: Default -> "hxxp://www.drudgereport.com/","hxxp://www.theguardian.com/childrens-books-site/gallery/2015/nov/13/best-space-facts-ever-astro-cat","hxxps://www.google.com/cloudprint/enable_chrome_connector/enable.html?proxy=E03203D1-0632-4CB7-A817-7A157472C7FB"
CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> duckduckgo.com
CHR DefaultSuggestURL: Default -> hxxps://ac.duckduckgo.com/ac/?q={searchTerms}&type=list
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\pdf.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\gcswf32.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => No File
CHR Plugin: (Skype Toolbars) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll => No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll => No File
CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\Mozilla Firefox\plugins\npdivx32.dll (DivX,Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll => No File
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll => No File
CHR Plugin: ( Wacom Dynamic Link Library) - C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (npFFApi) - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll => No File
CHR Plugin: (Google Update) - C:\Users\kathy\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll => No File
CHR Profile: C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Flash Video Downloader) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiimdkdngfcipjohbjenkahhlhccpdbc [2016-03-09]
CHR Extension: (GreaseGoogle) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apeeedokdcajckokidhdkbkflkpfpgko [2011-12-16]
CHR Extension: (Fair AdBlock App (by STANDS)) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcnofaichneijfbkdkghmhjjbepjmble [2015-11-17]
CHR Extension: (Google Calendar) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2015-10-16]
CHR Extension: (Blur) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd [2016-01-31]
CHR Extension: (AdBlock) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-02-17]
CHR Extension: (FlashBlock) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gofhjkjmkpinhpoiabjplobcaignabnl [2014-07-02]
CHR Extension: (Flash Video Downloader) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpjfocihhfgighbkleiolokddfmhcdpm [2011-12-12]
CHR Extension: (Google Voice (by Google)) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo [2014-04-13]
CHR Extension: (Popup Blocker Pro) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiodaajmphnkcajieajajinghpejdjai [2015-11-17]
CHR Extension: (ICE Quick Stream) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mapljocpedaolbooelchgnkkaplpadgp [2012-06-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-29]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx <not found>

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2015-04-09] (SUPERAntiSpyware.com)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2011-11-11] (Adobe Systems) [File not signed]
R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-11-20] (Advanced Micro Devices, Inc.) [File not signed]
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [240584 2012-10-02] (DTS, Inc)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1037824 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
S2 LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [173344 2007-02-06] (Logitech Inc.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 NVWMI; C:\Windows\system32\nvwmi64.exe [2683736 2014-07-02] ()
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 AcerSyncServiceWinService; C:\Program Files\Acer\AcerSync\AcerSyncService.exe -p [X]
S2 SkypeUpdate; "E:\Kathy\Windows.old\Program Files\Skype\Updater\Updater.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [62152 2014-10-27] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S3 cleanhlp; C:\EEK\Run\cleanhlp64.sys [57024 2014-03-17] (Emsisoft GmbH)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 G311N6; C:\Windows\System32\DRIVERS\G311N6.sys [347680 2010-05-05] (Netgear)
S3 LVcKap64; C:\Windows\System32\DRIVERS\LVcKap64.sys [1013024 2007-02-06] (Logitech Inc.)
S3 LVMVDrv; C:\Windows\System32\DRIVERS\LVMVDrv.sys [2346016 2007-02-06] (Logitech Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
S3 MHIKEY10; C:\Windows\System32\Drivers\MHIKEY10x64.sys [60288 2010-09-15] (Generic USB smartcard reader)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [50320 2015-01-29] (Panda Security, S.L.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16056 2016-03-08] (SlimWare Utilities, Inc.)
U3 TrueSight; C:\Windows\SysWOW64\drivers\TrueSight.sys [33512 2014-09-08] ()
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [52736 2012-07-09] (Apple, Inc.) [File not signed]
S2 AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
S3 MFE_RR; \??\C:\Users\kathy\AppData\Local\Temp\mfe_rr.sys [X]
S3 WacHidRouter; system32\DRIVERS\wachidrouter.sys [X]
S3 wacomrouterfilter; system32\DRIVERS\wacomrouterfilter.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)



Offline darmab

  • Bronze Member
  • Posts: 24
FRST.text continued:


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-09 07:56 - 2016-03-09 07:56 - 00029217 _____ C:\Users\kathy\Desktop\FRST.txt
2016-03-09 07:54 - 2016-03-09 07:53 - 02374144 _____ (Farbar) C:\Users\kathy\Desktop\FRST64.exe
2016-03-09 07:53 - 2016-03-09 07:53 - 02374144 _____ (Farbar) C:\Users\kathy\Downloads\FRST64.exe
2016-03-08 06:51 - 2016-03-08 06:51 - 00002052 _____ C:\Windows\epplauncher.mif
2016-03-08 06:50 - 2016-03-08 06:50 - 00002117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2016-03-08 06:50 - 2016-03-08 06:50 - 00000000 ____D C:\Program Files\Microsoft Security Client
2016-03-08 06:50 - 2016-03-08 06:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2016-03-08 06:49 - 2016-03-08 06:51 - 00000000 ____D C:\ad2eb0e29b77113813cc0cdb301d
2016-03-08 06:20 - 2016-03-08 06:21 - 14243008 _____ (Microsoft Corporation) C:\Users\kathy\Downloads\MSEInstall.exe
2016-03-08 06:08 - 2016-03-08 06:09 - 11646112 _____ (ESET) C:\Users\kathy\Downloads\avremover_nt64_enu.exe
2016-03-08 05:10 - 2016-03-08 05:10 - 00337544 _____ C:\Windows\Minidump\030816-33899-01.dmp
2016-03-07 16:53 - 2016-03-07 16:53 - 04952336 _____ (Advanced Micro Devices, Inc.) C:\Users\kathy\Downloads\autodetectutility (1).exe
2016-03-07 15:52 - 2016-03-07 15:52 - 00005145 _____ C:\Users\kathy\Desktop\attach.7z
2016-03-07 15:49 - 2016-03-07 15:51 - 00019267 _____ C:\Users\kathy\Desktop\attach.txt
2016-03-07 15:49 - 2016-03-07 15:50 - 00023601 _____ C:\Users\kathy\Desktop\dds.txt
2016-03-07 15:46 - 2016-03-07 15:46 - 00688992 _____ (Swearware) C:\Users\kathy\Downloads\dds.com
2016-03-07 15:29 - 2016-03-07 15:29 - 00784152 _____ (McAfee, Inc.) C:\Users\kathy\Downloads\rootkitremover.exe
2016-03-07 14:54 - 2016-03-07 14:54 - 00000000 ____D C:\Program Files (x86)\Panda Security
2016-03-07 14:54 - 2015-09-14 13:03 - 00039672 _____ C:\Windows\system32\Drivers\DasPtct.SYS
2016-03-07 14:54 - 2015-01-29 18:21 - 00050320 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\PSKMAD.sys
2016-03-07 14:51 - 2016-03-07 14:52 - 35811936 _____ (Panda Security ) C:\Users\kathy\Downloads\PandaCloudCleaner.exe
2016-03-07 14:50 - 2016-03-07 14:50 - 00524248 _____ (F-Secure Corporation) C:\Users\kathy\Downloads\F-SecureOnlineScanner.exe
2016-03-07 14:48 - 2016-03-07 14:49 - 16563352 _____ (Malwarebytes Corp.) C:\Users\kathy\Downloads\mbar-1.09.3.1001 (1).exe
2016-03-07 14:30 - 2016-03-07 14:30 - 00336640 _____ C:\Windows\Minidump\030716-23852-01.dmp
2016-03-07 14:16 - 2016-03-07 14:16 - 00055897 _____ C:\Users\kathy\Downloads\memtest86+-5.01.zip
2016-03-07 14:16 - 2016-03-07 14:16 - 00055897 _____ C:\Users\kathy\Desktop\memtest86+-5.01.zip
2016-03-07 12:20 - 2016-03-07 12:20 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-03-07 12:19 - 2016-03-07 12:21 - 00000000 ____D C:\Users\kathy\Desktop\mbar
2016-03-07 12:18 - 2016-03-07 12:19 - 16563352 _____ (Malwarebytes Corp.) C:\Users\kathy\Downloads\mbar-1.09.3.1001.exe
2016-03-07 11:04 - 2016-03-07 11:04 - 00000056 _____ C:\Users\kathy\Desktop\(27) Stephen Pepe.url
2016-03-07 09:26 - 2016-03-07 09:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2016-03-07 09:26 - 2016-03-07 09:26 - 00000000 ____D C:\Program Files\CPUID
2016-03-07 09:25 - 2016-03-07 09:25 - 01665568 _____ ( ) C:\Users\kathy\Downloads\cpu-z_1.75-en.exe
2016-03-07 08:22 - 2016-03-07 08:22 - 01860664 _____ C:\Users\kathy\Desktop\KATHYSBEAST-PC-Mon_03_07_2016__81819_80.zip
2016-03-07 07:03 - 2016-03-07 07:03 - 00314008 _____ C:\Users\kathy\Downloads\dm log collector.exe
2016-03-07 06:51 - 2016-03-07 06:51 - 00067310 _____ C:\Users\kathy\Downloads\bluescreenview.zip
2016-03-07 06:40 - 2016-03-07 06:40 - 00339064 _____ C:\Windows\Minidump\030716-25615-01.dmp
2016-03-07 06:27 - 2016-03-07 06:27 - 00000000 ____D C:\Users\Administrator\AppData\Local\TechSmith
2016-03-04 15:44 - 2016-03-04 15:44 - 00038400 _____ C:\Users\kathy\Desktop\Untitled-1.pmd
2016-03-04 15:07 - 2016-03-04 15:08 - 00000000 ____D C:\Users\kathy\Desktop\random gnu pages on desktop
2016-03-04 14:55 - 2016-03-04 15:04 - 00000000 ____D C:\Users\kathy\Desktop\writing
2016-03-04 12:54 - 2016-03-04 13:31 - 111271618 _____ C:\Users\kathy\Downloads\Monster_Book_of_Manga_Drawing.epub
2016-03-04 12:37 - 2016-03-04 12:37 - 00269838 _____ C:\Users\kathy\Desktop\Untitled-3.psd
2016-03-02 17:32 - 2016-03-02 17:33 - 00000000 ____D C:\Users\kathy\Desktop\books on dig illustration and manga studio
2016-03-02 16:34 - 2016-03-02 17:00 - 79927747 _____ C:\Users\kathy\Downloads\IllustrateWithPhotoshopVolume2RevisedEdition.pdf
2016-03-02 14:04 - 2015-11-18 17:01 - 43983780 _____ C:\Users\kathy\Desktop\Illustrate_with_Photoshop_Genius_Guide_Vol_1_Revised_Edition.pdf
2016-03-02 12:09 - 2016-03-02 07:55 - 35631375 _____ C:\Users\kathy\Desktop\Illustrate_with_Photoshop_Genius_Guide_Vol_1_Revised_Edition.rar
2016-03-02 12:08 - 2016-03-02 12:22 - 40765436 _____ C:\Users\kathy\Downloads\184969768X_Mastering.epub
2016-03-02 07:44 - 2016-03-02 07:55 - 35631375 _____ C:\Users\kathy\Downloads\Illustrate_with_Photoshop_Genius_Guide_Vol_1_Revised_Edition.rar
2016-03-02 07:34 - 2016-03-02 07:43 - 26688176 _____ C:\Users\kathy\Downloads\0823016714_Ex.epub
2016-03-02 07:18 - 2016-03-02 07:18 - 01008640 _____ C:\Users\kathy\Desktop\New canvas.lip
2016-03-01 16:11 - 2016-03-01 17:23 - 00000000 ____D C:\Users\kathy\Documents\CELSYS_EN
2016-03-01 16:11 - 2016-03-01 16:11 - 00000000 ____D C:\Users\kathy\AppData\Roaming\CELSYS_EN
2016-03-01 15:58 - 2016-03-01 15:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CLIP STUDIO
2016-03-01 15:58 - 2016-03-01 15:58 - 00000000 ____D C:\ProgramData\CELSYS_EN
2016-03-01 15:58 - 2016-03-01 15:58 - 00000000 ____D C:\Program Files\CELSYS
2016-03-01 15:51 - 2016-03-01 15:51 - 00025559 _____ C:\Users\kathy\Desktop\Untitled 1.odt
2016-03-01 15:33 - 2016-03-01 16:10 - 00000000 ____D C:\Users\kathy\Desktop\manga studio 5 full program
2016-03-01 14:31 - 2016-03-01 15:08 - 825162376 _____ C:\Users\kathy\Downloads\CSP_141_Materials.zip
2016-03-01 14:31 - 2016-03-01 15:00 - 313855611 _____ C:\Users\kathy\Downloads\CSP_141EN_Windows_app.zip
2016-03-01 14:31 - 2016-03-01 14:56 - 371139368 _____ C:\Users\kathy\Downloads\CSP_144ENm_app.dmg
2016-03-01 14:31 - 2016-03-01 14:46 - 180004217 _____ C:\Users\kathy\Downloads\CSP_141_Manuals.zip
2016-03-01 14:30 - 2016-03-01 14:30 - 00000080 _____ C:\Users\kathy\Desktop\Smith Micro Software, Inc. Store.url
2016-02-29 16:38 - 2016-02-29 16:40 - 40103880 _____ C:\Users\kathy\Downloads\pentablet_5.3.5-3 (1).exe
2016-02-29 16:16 - 2016-02-29 16:50 - 1047558144 _____ C:\Users\kathy\Downloads\4942981.avi
2016-02-28 16:29 - 2016-02-28 17:01 - 1032807875 _____ C:\Users\kathy\Downloads\4943454.mp4
2016-02-27 12:02 - 2016-02-27 13:11 - 1217544128 _____ C:\Users\kathy\Downloads\The.Keeper.Of.Lost.Causes.2013.720p.BRRip.h264.AAC-RARBG (1).mp4
2016-02-24 11:21 - 2016-02-24 11:20 - 29287521 _____ C:\Users\kathy\Desktop\blzlo.141970429X.epub
2016-02-24 11:10 - 2016-02-24 11:20 - 29287521 _____ C:\Users\kathy\Downloads\blzlo.141970429X.epub
2016-02-24 08:36 - 2016-02-24 09:43 - 00000000 ____D C:\Users\kathy\Documents\Snagit
2016-02-24 08:36 - 2016-02-24 08:37 - 00000000 ____D C:\Users\kathy\AppData\Local\TechSmith
2016-02-24 08:36 - 2016-02-24 08:36 - 00003816 _____ C:\Windows\System32\Tasks\TechSmith Updater
2016-02-24 08:35 - 2016-02-24 08:35 - 00000000 ____D C:\ProgramData\regid.1995-08.com.techsmith
2016-02-24 08:35 - 2016-02-24 08:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2016-02-24 08:35 - 2016-02-24 07:07 - 40765438 _____ C:\Users\kathy\Desktop\hxt8o.Mastering.Manga.Studio.5.epub
2016-02-24 08:34 - 2016-02-24 08:36 - 00000000 ____D C:\ProgramData\TechSmith
2016-02-24 08:34 - 2016-02-24 08:34 - 00034048 _____ C:\Users\kathy\Desktop\Untitled-11.psd
2016-02-24 08:34 - 2016-02-24 08:34 - 00000000 ____D C:\Program Files (x86)\TechSmith
2016-02-24 08:33 - 2016-02-24 08:33 - 78706712 _____ (TechSmith Corporation) C:\Users\kathy\Desktop\snagit.exe
2016-02-24 08:31 - 2016-02-24 08:33 - 78706712 _____ (TechSmith Corporation) C:\Users\kathy\Downloads\snagit.exe
2016-02-23 14:27 - 2016-03-03 09:18 - 00000000 ____D C:\Users\kathy\Desktop\critique
2016-02-23 10:15 - 2016-03-01 16:13 - 00000000 ____D C:\Users\kathy\AppData\Roaming\CELSYS
2016-02-23 09:09 - 2016-03-01 15:48 - 00000000 ____D C:\ProgramData\69B6DBD2-8E05-476F-B662-CF8D235FD499
2016-02-23 09:09 - 2016-02-23 09:09 - 00000000 ____D C:\ProgramData\FEA3F5DE-0F10-454D-B6C0-55E35B170A9D
2016-02-23 09:08 - 2016-02-23 09:09 - 00000000 ____D C:\Users\kathy\AppData\Roaming\Smith Micro
2016-02-23 09:08 - 2016-02-23 09:08 - 00000000 ____D C:\Users\kathy\Documents\Smith Micro
2016-02-23 08:47 - 2016-02-23 08:47 - 00000000 ____D C:\ProgramData\Smith Micro
2016-02-19 08:02 - 2016-02-19 08:30 - 298083204 _____ C:\Users\kathy\Downloads\v (1).mp4
2016-02-19 05:36 - 2016-02-19 05:36 - 06737904 _____ C:\Users\kathy\Downloads\Steve Vai Vs Eugene Nicolo Paganini, Caprice No 5 Crossroads Guitar Duel.mp4
2016-02-19 05:18 - 2016-03-04 14:49 - 00000000 ____D C:\Users\kathy\Desktop\new youtube 80s music
2016-02-17 12:18 - 2016-02-17 12:25 - 128953754 _____ C:\Users\kathy\Downloads\v.mp4
2016-02-16 14:04 - 2016-02-16 14:33 - 864477339 _____ C:\Users\kathy\Downloads\4943101.mp4
2016-02-15 13:16 - 2016-02-15 13:16 - 00000139 _____ C:\Users\kathy\Desktop\this is jabba the toad toad s best worst friend and a movie and toad ..-.url
2016-02-15 11:20 - 2016-02-15 11:20 - 00000067 _____ C:\Users\kathy\Desktop\ALONGTIMEALONE.url
2016-02-15 11:18 - 2016-02-15 11:18 - 00000075 _____ C:\Users\kathy\Desktop\Pinterest- Discover and save creative ideas.url
2016-02-11 09:47 - 2016-02-11 09:47 - 00000147 _____ C:\Users\kathy\Desktop\Altec Lansing IMT520 iPod iPhone 4 inMotion Speaker Dock with Handle Stand - eBay.url
2016-02-10 18:59 - 2016-02-10 19:59 - 659176664 _____ C:\Users\kathy\Downloads\4920855.avi
2016-02-09 15:50 - 2016-02-06 05:48 - 25839104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-02-09 15:50 - 2016-02-06 05:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-02-09 15:50 - 2016-02-06 05:24 - 02887680 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-02-09 15:50 - 2016-02-06 05:11 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-02-09 15:50 - 2016-02-06 05:10 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-02-09 15:50 - 2016-02-06 05:01 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-02-09 15:50 - 2016-02-06 04:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-02-09 15:50 - 2016-02-06 04:43 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-02-09 15:50 - 2016-02-06 04:38 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-02-09 15:50 - 2016-02-06 04:37 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-02-09 15:50 - 2016-02-06 04:32 - 14458368 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-02-09 15:50 - 2016-02-06 04:16 - 12857856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-02-09 15:50 - 2016-02-06 04:09 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-02-09 15:50 - 2016-02-06 03:54 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-02-09 15:50 - 2016-01-06 14:02 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2016-02-09 15:50 - 2016-01-06 13:41 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2016-02-09 15:49 - 2016-01-22 15:31 - 00387784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-02-09 15:49 - 2016-01-22 15:10 - 00341200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-02-09 15:49 - 2016-01-22 01:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-02-09 15:49 - 2016-01-22 01:41 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-02-09 15:49 - 2016-01-22 01:40 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-02-09 15:49 - 2016-01-22 01:40 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-02-09 15:49 - 2016-01-22 01:40 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-02-09 15:49 - 2016-01-22 01:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-02-09 15:49 - 2016-01-22 01:33 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-02-09 15:49 - 2016-01-22 01:32 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-02-09 15:49 - 2016-01-22 01:29 - 06052352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-02-09 15:49 - 2016-01-22 01:27 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-02-09 15:49 - 2016-01-22 01:27 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-02-09 15:49 - 2016-01-22 01:27 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-02-09 15:49 - 2016-01-22 01:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-02-09 15:49 - 2016-01-22 01:17 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-02-09 15:49 - 2016-01-22 01:09 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-02-09 15:49 - 2016-01-22 01:08 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-02-09 15:49 - 2016-01-22 01:05 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-02-09 15:49 - 2016-01-22 01:04 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-02-09 15:49 - 2016-01-22 01:02 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-02-09 15:49 - 2016-01-22 01:02 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-02-09 15:49 - 2016-01-22 01:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-02-09 15:49 - 2016-01-22 01:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-02-09 15:49 - 2016-01-22 01:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-02-09 15:49 - 2016-01-22 01:00 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-02-09 15:49 - 2016-01-22 01:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-02-09 15:49 - 2016-01-22 00:55 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-02-09 15:49 - 2016-01-22 00:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-02-09 15:49 - 2016-01-22 00:51 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-02-09 15:49 - 2016-01-22 00:51 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-02-09 15:49 - 2016-01-22 00:50 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-02-09 15:49 - 2016-01-22 00:48 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-02-09 15:49 - 2016-01-22 00:47 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-02-09 15:49 - 2016-01-22 00:46 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-02-09 15:49 - 2016-01-22 00:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-02-09 15:49 - 2016-01-22 00:43 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-02-09 15:49 - 2016-01-22 00:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-02-09 15:49 - 2016-01-22 00:38 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-02-09 15:49 - 2016-01-22 00:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-02-09 15:49 - 2016-01-22 00:35 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-02-09 15:49 - 2016-01-22 00:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-02-09 15:49 - 2016-01-22 00:34 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-02-09 15:49 - 2016-01-22 00:33 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-02-09 15:49 - 2016-01-22 00:31 - 02597376 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-02-09 15:49 - 2016-01-22 00:27 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-02-09 15:49 - 2016-01-22 00:25 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-02-09 15:49 - 2016-01-22 00:24 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-02-09 15:49 - 2016-01-22 00:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-02-09 15:49 - 2016-01-22 00:08 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-02-09 15:49 - 2016-01-22 00:07 - 02120704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-02-09 15:49 - 2016-01-22 00:02 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-02-09 15:48 - 2016-01-07 12:53 - 03211776 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-02-09 15:48 - 2016-01-07 12:42 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-02-09 15:48 - 2015-12-20 13:50 - 03180544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2016-02-09 15:48 - 2015-12-20 13:50 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2016-02-09 15:48 - 2015-12-20 09:08 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2016-02-09 15:47 - 2016-01-16 14:01 - 02085888 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-02-09 15:47 - 2016-01-16 13:36 - 01413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-02-09 15:46 - 2016-01-22 01:27 - 05573056 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-02-09 15:46 - 2016-01-22 01:27 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-02-09 15:46 - 2016-01-22 01:27 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-02-09 15:46 - 2016-01-22 01:24 - 01733592 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-02-09 15:46 - 2016-01-22 01:20 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-02-09 15:46 - 2016-01-22 01:20 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-02-09 15:46 - 2016-01-22 01:20 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-02-09 15:46 - 2016-01-22 01:20 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-02-09 15:46 - 2016-01-22 01:20 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-02-09 15:46 - 2016-01-22 01:20 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-02-09 15:46 - 2016-01-22 01:20 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-02-09 15:46 - 2016-01-22 01:20 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-02-09 15:46 - 2016-01-22 01:20 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-02-09 15:46 - 2016-01-22 01:20 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-02-09 15:46 - 2016-01-22 01:19 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-02-09 15:46 - 2016-01-22 01:19 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-02-09 15:46 - 2016-01-22 01:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-02-09 15:46 - 2016-01-22 01:18 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2016-02-09 15:46 - 2016-01-22 01:18 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2016-02-09 15:46 - 2016-01-22 01:18 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-02-09 15:46 - 2016-01-22 01:17 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-02-09 15:46 - 2016-01-22 01:17 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-02-09 15:46 - 2016-01-22 01:17 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-02-09 15:46 - 2016-01-22 01:16 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-02-09 15:46 - 2016-01-22 01:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-02-09 15:46 - 2016-01-22 01:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-02-09 15:46 - 2016-01-22 01:15 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-02-09 15:46 - 2016-01-22 01:15 - 00730112 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-02-09 15:46 - 2016-01-22 01:15 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-02-09 15:46 - 2016-01-22 01:13 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-02-09 15:46 - 2016-01-22 01:13 - 03938752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-02-09 15:46 - 2016-01-22 01:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-02-09 15:46 - 2016-01-22 01:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-02-09 15:46 - 2016-01-22 01:13 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00880128 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 01:09 - 01314328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-02-09 15:46 - 2016-01-22 01:06 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-02-09 15:46 - 2016-01-22 01:06 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-02-09 15:46 - 2016-01-22 01:06 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-02-09 15:46 - 2016-01-22 01:06 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-02-09 15:46 - 2016-01-22 01:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-02-09 15:46 - 2016-01-22 01:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-02-09 15:46 - 2016-01-22 01:06 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-02-09 15:46 - 2016-01-22 01:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-02-09 15:46 - 2016-01-22 01:05 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-02-09 15:46 - 2016-01-22 01:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-02-09 15:46 - 2016-01-22 01:04 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2016-02-09 15:46 - 2016-01-22 01:04 - 00535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2016-02-09 15:46 - 2016-01-22 01:02 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-02-09 15:46 - 2016-01-22 01:02 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-02-09 15:46 - 2016-01-22 01:02 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-02-09 15:46 - 2016-01-22 01:02 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-02-09 15:46 - 2016-01-22 01:02 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-02-09 15:46 - 2016-01-22 01:02 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-02-09 15:46 - 2016-01-22 01:02 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00642560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-02-09 15:46 - 2016-01-22 00:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-02-09 15:46 - 2016-01-22 00:07 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-02-09 15:46 - 2016-01-22 00:07 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-02-09 15:46 - 2016-01-22 00:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-02-09 15:46 - 2016-01-21 23:59 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-02-09 15:46 - 2016-01-21 23:58 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-02-09 15:46 - 2016-01-21 23:58 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-02-09 15:46 - 2016-01-21 23:57 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-02-09 15:46 - 2016-01-21 23:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-02-09 15:46 - 2016-01-21 23:53 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-02-09 15:46 - 2016-01-21 23:53 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-02-09 15:46 - 2016-01-21 23:53 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-02-09 15:46 - 2016-01-21 23:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-02-09 15:46 - 2016-01-21 23:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-02-09 15:46 - 2016-01-21 23:51 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-02-09 15:46 - 2016-01-21 23:51 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-02-09 15:46 - 2016-01-21 23:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-02-09 15:46 - 2016-01-21 23:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-02-09 13:45 - 2016-01-16 14:06 - 00025024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-02-09 13:45 - 2016-01-16 13:54 - 01162240 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-02-09 13:45 - 2016-01-11 14:05 - 03169792 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2016-02-09 13:45 - 2016-01-11 14:05 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2016-02-09 13:45 - 2016-01-11 14:05 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2016-02-09 13:45 - 2016-01-11 13:52 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2016-02-09 13:45 - 2016-01-11 13:47 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2016-02-09 13:45 - 2016-01-11 13:26 - 02610176 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-02-09 13:45 - 2016-01-11 13:24 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2016-02-09 13:45 - 2016-01-11 13:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-02-09 13:45 - 2016-01-11 13:23 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2016-02-09 13:45 - 2016-01-11 13:23 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2016-02-09 13:45 - 2016-01-11 13:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2016-02-09 13:45 - 2016-01-11 13:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2016-02-09 13:45 - 2016-01-11 13:14 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2016-02-09 13:45 - 2016-01-11 13:14 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2016-02-09 13:45 - 2016-01-11 13:14 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2016-02-09 13:45 - 2016-01-11 13:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2016-02-09 13:45 - 2016-01-11 09:08 - 01362944 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-02-09 13:45 - 2016-01-11 09:08 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-02-09 13:45 - 2016-01-11 09:08 - 00677376 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-02-09 13:45 - 2016-01-11 09:08 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-02-09 13:45 - 2016-01-11 09:08 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-02-09 13:44 - 2016-01-22 01:19 - 14179840 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-02-09 13:44 - 2016-01-22 01:15 - 01866752 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2016-02-09 13:44 - 2016-01-22 01:12 - 01940992 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-02-09 13:44 - 2016-01-22 01:05 - 12877824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-02-09 13:44 - 2016-01-22 01:00 - 01498624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2016-02-09 13:44 - 2016-01-22 00:59 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2016-02-09 13:44 - 2016-01-22 00:19 - 03231232 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-02-09 13:44 - 2016-01-22 00:12 - 02973184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-02-08 17:32 - 2016-02-08 17:51 - 890559310 _____ C:\Users\kathy\Downloads\GOSEBP.2015.720p.HDRiP.850MB.ShAaNiG.rar

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-09 07:56 - 2014-08-14 13:15 - 00000000 ____D C:\FRST
2016-03-09 07:55 - 2012-06-13 06:44 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-03-09 07:51 - 2014-11-12 20:40 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cffee2dc356a48.job
2016-03-09 07:45 - 2015-02-05 04:46 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0412894529565.job
2016-03-09 07:45 - 2014-10-19 22:34 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cfec16b8b41df0.job
2016-03-09 07:39 - 2013-02-18 13:56 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-09 07:20 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\tracing
2016-03-09 04:51 - 2013-02-18 13:56 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-09 02:00 - 2014-07-01 05:50 - 00000000 ____D C:\Users\kathy\AppData\Local\Adobe
2016-03-08 21:45 - 2015-02-05 04:46 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d04128941eb421.job
2016-03-08 20:37 - 2009-07-13 23:45 - 00026880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-03-08 20:37 - 2009-07-13 23:45 - 00026880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-03-08 06:50 - 2015-11-23 07:20 - 00000000 ____D C:\Program Files\Waterfox
2016-03-08 06:28 - 2013-12-14 09:32 - 00000000 ____D C:\Users\kathy\AppData\Local\Windows Live
2016-03-08 06:28 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-03-08 06:27 - 2012-08-29 06:34 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-03-08 05:22 - 2009-07-14 00:13 - 00782510 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-08 05:22 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf
2016-03-08 05:17 - 2015-12-09 08:45 - 00002836 _____ C:\Windows\System32\Tasks\SlimDrivers Startup
2016-03-08 05:17 - 2015-12-09 08:45 - 00000410 _____ C:\Windows\Tasks\SlimDrivers Startup.job
2016-03-08 05:16 - 2014-06-20 07:41 - 00016056 _____ (SlimWare Utilities, Inc.) C:\Windows\system32\Drivers\SWDUMon.sys
2016-03-08 05:16 - 2013-04-25 21:55 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2016-03-08 05:16 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-03-08 05:10 - 2011-11-10 17:14 - 00000000 ____D C:\Windows\Minidump
2016-03-08 05:09 - 2015-12-08 20:23 - 770235809 _____ C:\Windows\MEMORY.DMP
2016-03-07 18:00 - 2015-04-22 14:33 - 00000000 ____D C:\Users\kathy\AppData\Roaming\vlc
2016-03-07 16:10 - 2011-11-09 17:06 - 00000000 ____D C:\Users\kathy\Documents\My Computer Data
2016-03-07 16:08 - 2011-11-11 14:41 - 00000000 ____D C:\Users\kathy\Documents\Adobe Photoshop CS5.1 Extended Edition
2016-03-07 16:03 - 2011-11-11 18:47 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1 (64 Bit).lnk
2016-03-07 15:27 - 2014-09-03 08:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol
2016-03-07 15:27 - 2012-06-13 05:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scratch
2016-03-07 14:54 - 2015-12-10 08:30 - 00201342 _____ C:\Windows\ntbtlog.txt
2016-03-07 14:26 - 2011-12-18 14:55 - 00000000 ____D C:\Users\kathy\Calibre Library
2016-03-07 12:20 - 2014-08-15 06:41 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-07 12:19 - 2014-08-15 06:41 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-03-07 06:35 - 2015-12-31 12:26 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2016-03-07 06:35 - 2015-12-31 12:26 - 00000000 ___SD C:\Windows\system32\GWX
2016-03-07 06:35 - 2015-01-18 06:19 - 00000000 ____D C:\Users\Administrator
2016-03-07 06:35 - 2014-08-13 11:01 - 00000000 ____D C:\Users\kathy\Documents\food
2016-03-07 06:35 - 2012-03-09 09:06 - 00000000 ____D C:\Users\nonadmin acct
2016-03-07 06:35 - 2011-11-09 13:58 - 00000000 ____D C:\Users\kathy
2016-03-07 06:35 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\registration
2016-03-04 14:51 - 2015-01-27 09:07 - 00000000 ____D C:\Users\kathy\Desktop\2015 NEW, gnu pages to keep
2016-03-04 12:01 - 2016-02-07 06:16 - 00000000 ____D C:\Users\kathy\Desktop\SVS
2016-03-01 16:22 - 2015-08-10 05:21 - 00000000 ____D C:\Users\kathy\Desktop\artist websites and files for photoshop to format art
2016-03-01 16:20 - 2016-01-23 10:45 - 00000000 ____D C:\Users\kathy\Desktop\illustrations with good perspective and composition
2016-03-01 16:16 - 2015-05-29 06:06 - 00000000 ____D C:\Users\kathy\Desktop\food
2016-03-01 16:16 - 2014-06-04 16:27 - 00000000 ____D C:\Users\kathy\Desktop\Kathy Work in progress-2
2016-03-01 16:11 - 2015-04-09 02:57 - 00000000 ____D C:\Users\kathy\Desktop\kaylewisarts websits
2016-03-01 15:58 - 2011-11-09 16:59 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-02-29 08:46 - 2012-01-16 08:08 - 00001456 _____ C:\Users\kathy\AppData\Local\Adobe Save for Web 12.0 Prefs
2016-02-26 14:27 - 2014-09-08 11:46 - 00000000 ____D C:\Users\kathy\AppData\Local\CrashDumps
2016-02-26 00:11 - 2012-05-07 09:41 - 00000000 ____D C:\Users\kathy\dwhelper
2016-02-25 04:40 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\NDF
2016-02-24 08:34 - 2014-03-18 03:37 - 00000000 ____D C:\ProgramData\Package Cache
2016-02-24 08:33 - 2013-09-20 14:58 - 00000000 ____D C:\Users\kathy\AppData\Roaming\foobar2000
2016-02-23 14:37 - 2015-04-13 05:04 - 00000000 ____D C:\Users\kathy\Desktop\movie and music and books links
2016-02-21 19:05 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2016-02-21 15:40 - 2013-02-18 13:56 - 00002212 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-21 15:20 - 2009-07-13 23:45 - 05039944 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-21 15:17 - 2015-04-19 14:58 - 00000000 ____D C:\Windows\system32\appraiser
2016-02-21 15:17 - 2014-05-28 05:28 - 00000000 ___SD C:\Windows\system32\CompatTel
2016-02-19 11:32 - 2013-08-21 07:23 - 00000000 ____D C:\Windows\system32\MRT
2016-02-19 11:21 - 2011-12-31 06:06 - 146614896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-02-19 11:20 - 2009-07-13 21:34 - 00000513 _____ C:\Windows\win.ini
2016-02-19 11:06 - 2014-03-18 04:04 - 00774632 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-02-14 15:22 - 2015-02-21 11:09 - 00000000 ____D C:\Users\kathy\Desktop\new music 2015
2016-02-11 04:18 - 2016-01-19 13:05 - 00026289 _____ C:\Users\kathy\Desktop\word book dummy jodell sadler style final version.odt
2016-02-10 01:55 - 2012-06-13 06:44 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-02-10 01:55 - 2012-06-13 06:44 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-02-10 01:55 - 2011-11-10 08:24 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories =======

2013-10-09 13:10 - 2013-10-09 13:10 - 0000288 _____ () C:\Users\kathy\AppData\Roaming\.backup.dm
2014-01-08 08:55 - 2016-01-27 11:36 - 0000132 _____ () C:\Users\kathy\AppData\Roaming\Adobe PNG Format CS5 Prefs
2012-01-16 08:08 - 2016-02-29 08:46 - 0001456 _____ () C:\Users\kathy\AppData\Local\Adobe Save for Web 12.0 Prefs
2012-06-07 09:45 - 2012-06-07 09:45 - 0091597 _____ () C:\Users\kathy\AppData\Local\ars.cache
2012-06-07 09:45 - 2012-06-07 09:45 - 0193495 _____ () C:\Users\kathy\AppData\Local\census.cache
2012-06-07 09:34 - 2012-06-07 09:34 - 0000036 _____ () C:\Users\kathy\AppData\Local\housecall.guid.cache
2012-12-25 22:47 - 2013-04-14 16:52 - 0733496 ___SH () C:\Users\kathy\AppData\Local\netsockio.drv
2009-11-04 05:48 - 2012-09-23 04:27 - 0075944 ___SH () C:\Users\kathy\AppData\Local\ntfsdrv.mgr
2015-10-21 06:20 - 2015-10-21 06:20 - 0000758 _____ () C:\Users\kathy\AppData\Local\recently-used.xbel
2011-11-10 05:24 - 2015-02-04 20:50 - 0007667 _____ () C:\Users\kathy\AppData\Local\resmon.resmoncfg
2014-06-20 08:21 - 2014-06-20 08:21 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2011-11-12 16:43 - 2011-11-12 16:43 - 0000008 __RSH () C:\ProgramData\F13FCC03DB.sys
2014-09-25 11:52 - 2014-12-15 12:07 - 0002805 _____ () C:\ProgramData\hpzinstall.log
2011-11-12 16:43 - 2013-10-31 15:28 - 0002568 ___SH () C:\ProgramData\KGyGaAvL.sys

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-03-09 00:18

==================== End of FRST.txt ============================

Offline darmab

  • Bronze Member
  • Posts: 24
Addition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by kathy (2016-03-09 07:57:38)
Running from C:\Users\kathy\Desktop
Windows 7 Professional Service Pack 1 (X64) (2011-11-09 18:58:23)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1474584281-122529757-4205316068-500 - Administrator - Enabled) => C:\Users\Administrator
Guest (S-1-5-21-1474584281-122529757-4205316068-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1474584281-122529757-4205316068-1013 - Limited - Enabled)
kathy (S-1-5-21-1474584281-122529757-4205316068-1000 - Administrator - Enabled) => C:\Users\kathy
nonadmin acct (S-1-5-21-1474584281-122529757-4205316068-1003 - Limited - Enabled) => C:\Users\nonadmin acct

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

6300 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
6300_Help (x32 Version: 82.0.242.000 - Hewlett-Packard) Hidden
6300Trb (x32 Version: 82.0.242.000 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 13.0.0.111 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.0.6 - Adobe Systems Incorporated)
Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.306 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.306 - Adobe Systems Incorporated)
Adobe InDesign CS2 (HKLM-x32\...\Adobe InDesign CS2 - {7F4C8163-F259-49A0-A018-2857A90578BC}) (Version: 004.000.000 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
Adobe PageMaker 7.0 (HKLM-x32\...\Adobe PageMaker 7.0) (Version: 7.0 - Adobe Systems, Inc.)
Adobe Photoshop CS5.1 (HKLM-x32\...\{9158FF30-78D7-40EF-B83E-451AC5334640}) (Version: 12.1 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.14) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.14 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.2.152 - Adobe Systems, Inc.)
Adobe SVG Viewer 3.0 (HKLM-x32\...\Adobe SVG Viewer) (Version:  3.0 - Adobe Systems, Inc.)
AIO_CDB_ProductContext (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_CDB_Software (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_Scan (x32 Version: 130.0.421.000 - Hewlett-Packard) Hidden
Amazon Kindle (HKU\S-1-5-21-1474584281-122529757-4205316068-1000\...\Amazon Kindle) (Version:  - Amazon)
Amazon MP3 Downloader 1.0.17 (HKLM-x32\...\Amazon MP3 Downloader) (Version: 1.0.17 - Amazon Services LLC)
AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{C6579A65-9CAE-4B31-8B6B-3306E0630A66}) (Version: 2.1.3.127 - Apple Inc.)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology)
ATI AVIVO64 Codecs (Version: 11.6.0.50930 - ATI Technologies Inc.) Hidden
ATI Problem Report Wizard (Version: 3.0.795.0 - ATI Technologies) Hidden
Audacity 2.0.4 (HKLM-x32\...\Audacity_is1) (Version: 2.0.4 - Audacity Team)
AudibleManager (HKLM-x32\...\AudibleManager) (Version: 2007907566.48.56.44698994 - Audible, Inc.)
Bamboo (HKLM\...\Pen Tablet Driver) (Version: 5.2.5-5 - Wacom Technology Corp.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform)
Chessmaster Grandmaster Edition (HKLM-x32\...\InstallShield_{27614800-84A9-484E-9CCB-43ED2F1205F5}) (Version: 1.00.0000 - Ubisoft)
Chessmaster Grandmaster Edition (x32 Version: 1.00.0000 - Ubisoft) Hidden
CLIP STUDIO PAINT (HKLM-x32\...\{E4F184C1-E62E-44F0-B142-AB6197490834}) (Version: 1.4.1 - CELSYS)
Copy (x32 Version: 130.0.428.000 - Hewlett-Packard) Hidden
CPUID CPU-Z 1.75 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden
DivX Web Player (HKLM-x32\...\{B7050CBDB2504B34BC2A9CA0A692CC29}) (Version: 1.5.0 - DivX,Inc.)
DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden
foobar2000 v1.1.1 (HKLM-x32\...\foobar2000) (Version: 1.1.1 - Peter Pawlowski)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 48.0.2564.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HiJackThis (HKLM-x32\...\{45A66726-69BC-466B-A7A4-12FCBA4883D7}) (Version: 1.0.0 - Trend Micro)
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Photosmart Essential 3.5 (HKLM\...\HP Photosmart Essential) (Version: 3.5 - HP)
HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B (HKLM\...\{B61ED343-0B14-4241-999C-490CB1A20DA4}) (Version: 13.0 - HP)
HP Smart Web Printing 4.51 (HKLM\...\HP Smart Web Printing) (Version: 4.51 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Support Solutions Framework (HKLM-x32\...\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company)
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Intel(R) Network Connections 18.1.59.0 (HKLM\...\PROSetDX) (Version: 18.1.59.0 - Intel)
iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
JMicron JMB36X Driver (HKLM-x32\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.17.65.11 - JMicron Technology Corp.)
Logitech® Camera Driver (HKLM-x32\...\QcDrv) (Version:  - )
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP1 x64 繁體中文 (HKLM\...\{A423B3FB-C9E6-4953-9A83-2A5F45CAF466}) (Version: 3.5.5692.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP1 繁體中文 (HKLM-x32\...\{0BE37B03-93EF-4B46-A4F3-30ED22569D1A}) (Version: 3.5.5692.0 - Microsoft Corporation)
Microsoft Sync Framework Runtime v1.0 (x64) (HKLM\...\{53D7A054-4598-4947-A159-E8FCC77720AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services v1.0 (x64) (HKLM\...\{32508A23-C9EA-4D29-83CA-97A42A13701E}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MVisn64 (Version: 10.51.2027 - Logitech Inc.) Hidden
Network64 (Version: 130.0.572.000 - Hewlett-Packard) Hidden
NVIDIA 3D Vision Controller Driver 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.2 - NVIDIA Corporation)
NVIDIA nView 141.24 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 141.24 - NVIDIA Corporation)
NVIDIA WMI 2.18.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 2.18.0 - NVIDIA Corporation)
OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP)
OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Raptr (HKLM-x32\...\Raptr) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7058 - Realtek Semiconductor Corp.)
Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
SeaTools for Windows (HKLM-x32\...\SeaTools for Windows) (Version:  - Seagate Technology)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.9.9216 - Skype Technologies S.A.)
Skype™ 5.8 (HKLM-x32\...\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}) (Version: 5.8.158 - Skype Technologies S.A.)
SlimDrivers (HKLM-x32\...\{746AB259-6474-4111-8966-1C62F9A6E063}) (Version: 2.3.1 - SlimWare Utilities, Inc.)
SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden
Snagit 12 (HKLM-x32\...\{ec29af82-9c9e-420e-ab18-53821c36ac3c}) (Version: 12.4.1.3036 - TechSmith Corporation)
Snagit 12 (x32 Version: 12.4.1 - TechSmith Corporation) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SRWare Iron version SRWare Iron 39.2100.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: SRWare Iron 39.2100.0 - SRWare)
StationRipper 2.98.6 (HKU\S-1-5-21-1474584281-122529757-4205316068-1000\...\StationRipper) (Version: 2.98.6 - Ratajik Software)
Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden
Streamripper (Remove only) (HKLM-x32\...\Streamripper) (Version:  - )
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1008 - SUPERAntiSpyware.com)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden
UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden
VC 9.0 Runtime (x32 Version: 1.0.0 - Check Point Software Technologies Ltd) Hidden
VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden
VC80CRTRedist - 8.0.50727.762 (x32 Version: 1.0.0 - DivX, Inc) Hidden
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Waterfox 43.0.4 (x64 en-US) (HKLM\...\Waterfox 43.0.4 (x64 en-US)) (Version: 43.0.4 - Mozilla)
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
WebTablet FB Plugin (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.0.0.1 - Wacom Technology Corp.)
WebTablet IE Plugin (HKLM-x32\...\Wacom WebTabletPlugin for IE) (Version: 1.1.0.12 - Wacom Technology Corp.)
WebTablet Netscape Plugin (HKLM-x32\...\Wacom WebTabletPlugin for Netscape) (Version: 1.1.0.10 - Wacom Technology Corp.)
WhoCrashed 5.01 (HKLM\...\WhoCrashed_is1) (Version:  - Resplendence Software Projects Sp.)
Winamp (HKLM-x32\...\Winamp) (Version: 5.623  - Nullsoft, Inc)
Winamp Detector Plug-in (HKU\S-1-5-21-1474584281-122529757-4205316068-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows Driver Package - ACER Incorporated (qcusbser) Modem  (10/12/2009 2.0.6.6) (HKLM\...\BF39BAA13199B9BFDFC03B6C26851E9F3246C6A2) (Version: 10/12/2009 2.0.6.6 - ACER Incorporated)
Windows Driver Package - ACER Incorporated (qcusbser) Ports  (10/12/2009 2.0.6.6) (HKLM\...\5F3015F0AD4F9F61F4D01EAE1AF322C1A901C27C) (Version: 10/12/2009 2.0.6.6 - ACER Incorporated)
Windows Driver Package - ACER, Inc (androidusb) USB  (10/12/2009 1.0.0010.00000) (HKLM\...\A61AC676A7F61C423134B0621CBA2D4134507A2D) (Version: 10/12/2009 1.0.0010.00000 - ACER, Inc)
Windows Installer Clean Up (HKLM-x32\...\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}) (Version: 3.00.00.0000 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinPatrol (HKLM\...\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 32.0.2014.5 - Ruiware)
ZoneAlarm Antivirus (x32 Version: 10.2.047.000 - Check Point Software Technologies Ltd.) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


Offline darmab

  • Bronze Member
  • Posts: 24
Addition.txt continued:


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {02A3C9DA-FF5C-484A-B6EC-AB100CE49A3A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd)
Task: {07C5F1D0-AA9F-4EF2-B020-A0AFF06378F7} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {0849E789-5098-45C2-82DD-FD2D963EE41F} - System32\Tasks\{A3E49FA0-3C41-40F5-87A4-97E32278D26E} => C:\Program Files (x86)\Opera\Opera.exe
Task: {0855867E-5623-4181-886E-456D22F79761} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {20531535-C577-4FBE-87FB-F58CBAE44F90} - System32\Tasks\SlimDrivers Startup => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe [2015-08-19] (SlimWare Utilities, Inc.)
Task: {244C02C9-BA32-428E-8CA6-B2B5F7BA7CF2} - System32\Tasks\{EEC58E4F-446A-4C41-A78A-FE48BD750658} => C:\Program Files (x86)\Opera\Opera.exe
Task: {246CD143-19C6-4601-9192-F438A50FCD49} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {25AE064E-8B42-48D6-847B-02AE61464403} - System32\Tasks\{B7485E70-788A-49E6-BB69-563E18941147} => C:\Program Files (x86)\Opera\Opera.exe
Task: {26707F0E-AF5A-4EC0-80AA-FD414ABD31BF} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {29C7B1D5-49FF-46EA-9FB2-3DD94987B5D8} - System32\Tasks\{D2D17885-7A8A-4756-87C8-3BAC634DFEFC} => C:\Program Files (x86)\Opera\Opera.exe
Task: {3401E918-9B39-45CC-9418-ED8512C3DFAE} - System32\Tasks\{BA813E3C-2811-450A-8B0F-B2BB56750FEE} => C:\Program Files (x86)\Opera\Opera.exe
Task: {3B75CE18-0AD0-4622-A1BB-2CDD81EE7D43} - System32\Tasks\{A6E279E1-60BE-4B8D-B3FD-7534AC5142EE} => C:\Program Files (x86)\Opera\Opera.exe
Task: {3CD66659-60DB-4056-A86B-018BD697FA19} - System32\Tasks\GoogleUpdateTaskMachineUA1d0412894529565 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {4526C88C-700B-4EFC-A8A2-768567EEABDA} - System32\Tasks\{56AF1F5A-BEF9-49AB-887E-F945B44E0ACD} => pcalua.exe -a "C:\Users\kathy\Desktop\Adobe Pagemaker 7.0 with Serial.exe" -d C:\Users\kathy\Desktop
Task: {4555BF62-F731-4117-AF7F-A0BDF2F41365} - System32\Tasks\GoogleUpdateTaskMachineCore1d04128941eb421 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {4D17E6DB-FAB0-4C42-A00A-4A0A905D2A91} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [2015-08-11] (TechSmith Corporation)
Task: {5479333A-166F-4DED-B2F7-A2C1E479EA56} - System32\Tasks\{0AA5BC6D-551E-434E-9B9A-D2872B29B744} => C:\Program Files (x86)\Opera\Opera.exe
Task: {56BA436F-A62B-470C-BFE0-18BA9DAF6355} - System32\Tasks\{5F5C03CE-7D0B-4B9F-A4DF-4EA00CBF1018} => pcalua.exe -a "C:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
Task: {742B9852-70AE-4555-83B9-1C46FB3D6270} - System32\Tasks\{B4FFCBB5-35E8-42C8-BE84-A712CB704165} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{27614800-84A9-484E-9CCB-43ED2F1205F5}\setup.exe" -c -runfromtemp -l0x0409
Task: {7AB6A2E4-EE34-4EA2-BEB5-5780207F03A8} - System32\Tasks\{51700A44-044C-4EB3-BA5A-475E1257F116} => C:\Program Files (x86)\Opera\Opera.exe
Task: {7D5AECC8-8399-4FFB-8607-67E494EED4A0} - System32\Tasks\{E9FCD061-D3E4-46A4-93F9-AF09F588AD2B} => pcalua.exe -a C:\Users\kathy\Downloads\vpsupd.exe -d C:\Users\kathy\Downloads
Task: {83948916-1ED8-45DB-A1C2-80232D5F26D4} - System32\Tasks\GoogleUpdateTaskMachineUA1cffee2dc356a48 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {83E5D034-AB52-495C-8218-56DFDAF43A21} - System32\Tasks\{F8D9061C-941E-472F-BBFD-FAF3CE0D7FE1} => C:\Program Files (x86)\Opera\Opera.exe
Task: {85553FF9-364F-4A4D-8E11-E2EF82E0BF53} - System32\Tasks\{E3787E20-F5D5-48AB-AE1B-FA6E7A94DF01} => C:\Program Files (x86)\Opera\Opera.exe
Task: {8758A5D6-CB47-43A6-B39A-4D925B44CACF} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: {8DF6E08F-84C4-4558-AA5F-03B8D0663AFD} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {8F221572-F1E3-4561-B34F-3FC6BB75BA86} - System32\Tasks\GoogleUpdateTaskMachineUA1cfec16b8b41df0 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {991FD6BA-C1BF-4AD2-9F8E-795F3D71C706} - System32\Tasks\AdobeAAMUpdater-1.0-kathysbeast-PC-kathy => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated)
Task: {A797163F-3EC0-4826-AF1D-9BE9E563DEF5} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {AF8AFE6D-402F-4950-9C39-AE9D0AE9D7BF} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {B01C972F-1358-43BF-B183-B4A1B3BE473C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {BABACD84-EE36-4FD4-BCFF-3EADE44C4D9C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated)
Task: {BD34175E-15CA-4DDA-B23E-2212BF2F2D02} - System32\Tasks\{B21A0BBD-0A4A-4207-AC58-7E9D9C2DFFA0} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{1FA08A70-6E60-4E06-90B6-7B96A741E9E0}\setup.exe" -c -runfromtemp -l0x0009 -removeonly
Task: {C0F7AEA3-7423-4F6C-84AD-BDFB1D4A7AB8} - \SoftPlanet Software Assistant -> No File <==== ATTENTION
Task: {D1277AE5-571F-4B99-9351-7031A8391421} - System32\Tasks\{201E9658-65A9-4003-B2BC-04D98BCEF463} => pcalua.exe -a D:\setup.exe -d D:\
Task: {D2EA33EA-1F57-4A1A-A3CC-71812C88999A} - System32\Tasks\{0C82451B-C5BC-4A29-BAD3-02511C98A8DB} => C:\Program Files (x86)\Opera\Opera.exe
Task: {E5E0831D-B976-44F7-8362-309D97A135F7} - System32\Tasks\{B8B0468E-1345-46CD-8060-2E919D9C802B} => pcalua.exe -a C:\Users\kathy\Desktop\iPod_Support_v3_10.exe -d C:\Users\kathy\Desktop
Task: {F1D2787D-94D7-40D3-AF13-8EB737BBDCB2} - System32\Tasks\{7335D42C-9798-4681-B87D-D7005735462B} => pcalua.exe -a "c:\Program Files (x86)\Corel\Corel Painter 11\Setup\SetupARP.exe" -c /arp
Task: {F85CBFA4-871D-418F-A6C9-2FA5943E1659} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {F8CBA898-2573-452E-8120-4EE7C435D625} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {FA9FCE2B-4198-4E3F-9545-3A120965E176} - System32\Tasks\{2138D6BD-B086-451C-B455-AB5D98E1E7CA} => C:\Program Files (x86)\Opera\Opera.exe
Task: {FF8A63DD-EF62-4B45-AA51-D87C64607910} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-10] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d04128941eb421.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cfec16b8b41df0.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cffee2dc356a48.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0412894529565.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SlimDrivers Startup.job => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-02-03 07:27 - 2014-07-02 15:48 - 02683736 ____R () C:\Windows\system32\nvwmi64.exe
2015-02-03 07:26 - 2014-07-02 13:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-11-20 21:23 - 2014-11-20 21:23 - 00214528 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2014-02-11 06:08 - 2014-02-11 06:08 - 00817152 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Device.dll
2014-02-11 06:08 - 2014-02-11 06:08 - 03650560 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Platform.dll
2015-04-15 04:41 - 2011-09-08 16:48 - 01183096 _____ () C:\Program Files\Tablet\Pen\libxml2.dll
2014-11-20 21:23 - 2014-11-20 21:23 - 00102400 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2015-03-20 17:12 - 2015-03-20 17:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 17:12 - 2015-03-20 17:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-08-14 10:57 - 2015-08-14 10:57 - 02099200 _____ () C:\Program Files (x86)\TechSmith\Snagit 12\opencv_core249.dll
2015-08-14 10:57 - 2015-08-14 10:57 - 01914368 _____ () C:\Program Files (x86)\TechSmith\Snagit 12\opencv_imgproc249.dll
2016-02-21 15:40 - 2016-02-17 23:14 - 01630360 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libglesv2.dll
2016-02-21 15:40 - 2016-02-17 23:14 - 00085656 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-1474584281-122529757-4205316068-1000\...\dell.com -> dell.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1474584281-122529757-4205316068-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\kathy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.40.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^Users^kathy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{99240F3A-3A33-472C-9818-E02D481F74EE}C:\program files (x86)\winamp\winamp.exe] => (Allow) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [UDP Query User{495112E6-B021-4414-AACF-3D1B673CEFED}C:\program files (x86)\winamp\winamp.exe] => (Allow) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [{ADE5D21E-6E3F-45FE-AA85-275D73BE4C9B}] => (Allow) E:\Kathy\Windows.old\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{11D1BA88-F427-4D73-8F1C-EDD5FC3BA7F2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{4EEF269E-AC78-4C42-93DA-5688A9177564}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{56003E5E-480E-4C24-BA13-2266073AA7BE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{FAE7CE20-D44C-48E7-92D9-115A28882405}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{A35C4A75-030E-4FB3-9F80-E0C47BC25631}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{5CBF045C-53D3-4103-AE98-A0F14039A70B}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{59541038-10FF-487A-9836-5E898EDDDF53}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{92E65751-50AC-4F49-9125-168D7E4170E7}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{C023D3A7-AFBA-4C60-B4BD-9BB9885BBBD0}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [UDP Query User{5F57DBA8-8151-46C2-9224-E544403F7E74}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [{62673387-7BED-4702-80BB-5EEE3B802260}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{7601BFFD-CBC2-4BD9-8ABB-5D9F6CB7B07F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{D0D00270-CA71-479A-9AC2-271BBE593228}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{4C02835C-8607-401C-AB21-BFF9FAB1254B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{64AB2F61-C8F3-4147-A0BE-0F34FCBC6B53}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{E9B6BB4C-DC31-4F5E-9DF5-E8BBA8000087}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{8CE9321A-BC37-476E-8519-61D8E6FDAA4C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe
FirewallRules: [{29333563-474E-4854-A794-ED5D9BFF75C5}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{DA9D2ECF-CACA-4C7F-B8DC-A707CF441680}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{4D864288-EA74-4185-A5BE-62B1E74AE6A1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{EA3AE5E6-75E6-413D-B1A5-CF1F42868E7C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe
FirewallRules: [{83D9D780-8C83-4F7F-B6CF-245B11D86FDE}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{31DE55F6-4A19-4455-B0FD-0E225C0A5F36}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe
FirewallRules: [{FB15EE2C-BDB0-490C-808B-F6E68F14B8C3}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe
FirewallRules: [{A0304D12-59FA-4611-BE67-EF17F002DD0B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe
FirewallRules: [{AC6FA7AB-97EA-49FD-AC72-DA52A505A9F3}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{2E3A08FE-4458-4465-B347-29FFFE0386B0}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{C760E6A4-800F-40E6-A5AC-1C614CAA6464}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe
FirewallRules: [{D6C0FD36-D80A-45FD-8213-33AD2DA9EC6A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{D93A8A18-5B30-4C54-A990-A2341DA7E154}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{E68D1859-C629-4558-878E-B1EDC882AE26}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{DC6D57F1-A980-4FEE-A160-F565D6A5FAC9}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{47D049DD-91B9-4065-9B45-A67200EA804C}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [TCP Query User{E3161800-97D9-4EB7-9CAE-74C306ED5A1C}C:\program files (x86)\ratajik software\stationripper\stationripperconsole.exe] => (Allow) C:\program files (x86)\ratajik software\stationripper\stationripperconsole.exe
FirewallRules: [UDP Query User{EA26131C-A4D7-4F9B-ABF7-BDF798222DE3}C:\program files (x86)\ratajik software\stationripper\stationripperconsole.exe] => (Allow) C:\program files (x86)\ratajik software\stationripper\stationripperconsole.exe
FirewallRules: [{E3C74B0C-518C-490F-A47B-9F09EE132C3C}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{E1F6B87A-468D-4211-BC48-A507AD555BC0}] => (Allow) C:\Program Files\Waterfox\waterfox.exe
FirewallRules: [{455E8131-8D25-4E81-8C79-D0DD5178B010}] => (Allow) C:\Program Files\Waterfox\waterfox.exe
FirewallRules: [{F525F666-BE10-4BAB-AD2C-63FFCE143714}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{88EC908A-C154-4B9D-AA10-F40F9D080E91}] => (Allow) LPort=8298

==================== Restore Points =========================

08-03-2016 06:26:04 WLSetup
08-03-2016 06:29:21 Removed Skype Click to Call
08-03-2016 13:04:18 Microsoft Antimalware Checkpoint

==================== Faulty Device Manager Devices =============

Name: AODDriver4.2.0
Description: AODDriver4.2.0
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: AODDriver4.2.0
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/08/2016 01:04:17 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.


Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {639208d5-d724-4352-b942-fa2d1aa29542}

Error: (03/08/2016 06:51:07 AM) (Source: Microsoft Security Client Setup) (EventID: 100) (User: kathysbeast-PC)
Description: HRESULT:0x8004FF0A
Description:Microsoft Security Essentials installation was canceled. You canceled the Security Essentials installation on your computer. Error code:0x8004FF0A.

Error: (03/08/2016 06:30:06 AM) (Source: MsiInstaller) (EventID: 11324) (User: kathysbeast-PC)
Description: Product: Skype Click to Call -- Error 1324. The folder path 'Program Files' contains an invalid character.

Error: (03/08/2016 06:29:56 AM) (Source: MsiInstaller) (EventID: 11324) (User: kathysbeast-PC)
Description: Product: Skype Click to Call -- Error 1324. The folder path 'Program Files' contains an invalid character.

Error: (03/08/2016 05:26:32 AM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location G:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).

Error: (03/08/2016 05:15:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: sysmain.dll, version: 6.1.7601.18933, time stamp: 0x55a6a1d1
Exception code: 0xc0000005
Fault offset: 0x0000000000004e03
Faulting process id: 0xc48
Faulting application start time: 0xsvchost.exe_SysMain0
Faulting application path: svchost.exe_SysMain1
Faulting module path: svchost.exe_SysMain2
Report Id: svchost.exe_SysMain3

Error: (03/07/2016 02:21:33 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe Files (x86)\SlimDrivers\SlimDrivers.exe" /byUser; Description = SlimDrivers Installing Drivers; Error = 0x8007043c).

Error: (03/07/2016 06:21:13 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: services.exe, version: 6.1.7601.18829, time stamp: 0x552b23d3
Faulting module name: ntdll.dll, version: 6.1.7601.19135, time stamp: 0x56a1c9c5
Exception code: 0xc0000005
Fault offset: 0x0000000000016191
Faulting process id: 0x2cc
Faulting application start time: 0xservices.exe0
Faulting application path: services.exe1
Faulting module path: services.exe2
Report Id: services.exe3

Error: (03/03/2016 04:01:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: sysmain.dll, version: 6.1.7601.18933, time stamp: 0x55a6a1d1
Exception code: 0xc0000005
Fault offset: 0x0000000000054500
Faulting process id: 0x1270
Faulting application start time: 0xsvchost.exe_SysMain0
Faulting application path: svchost.exe_SysMain1
Faulting module path: svchost.exe_SysMain2
Report Id: svchost.exe_SysMain3

Error: (02/28/2016 07:00:04 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location G:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).


System errors:
=============
Error: (03/09/2016 07:38:03 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (03/09/2016 07:36:56 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (03/09/2016 06:19:26 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (03/09/2016 06:18:19 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (03/09/2016 06:18:19 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (03/09/2016 05:16:14 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (03/09/2016 04:14:44 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (03/09/2016 04:13:24 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (03/09/2016 03:57:49 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (03/09/2016 03:54:36 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.


CodeIntegrity:
===================================
  Date: 2016-03-08 05:16:52.996
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-08 05:13:54.238
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-07 06:38:02.486
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-07 06:27:30.440
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-07 06:21:32.608
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-04 17:47:05.394
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-02 08:07:07.770
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-26 19:43:55.315
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-25 14:30:54.810
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-25 14:03:29.307
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: AMD Phenom(tm) II X6 1100T Processor
Percentage of memory in use: 17%
Total physical RAM: 16297.75 MB
Available physical RAM: 13451.05 MB
Total Virtual: 32595.5 MB
Available Virtual: 28488.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:2047.9 GB) (Free:1198.69 GB) NTFS
Drive f: (FantomHD) (Fixed) (Total:1863.01 GB) (Free:661.22 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 2794.5 GB) (Disk ID: 1FE2F86C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=2047.9 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 1863 GB) (Disk ID: 3E12CCE9)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Offline Foxfire

  • Malware Removal Staff
  • Bronze Member
  • Posts: 443


 
 Hello darmab,

I see that you are simultaneously asking for help here :-http://www.sevenforums.com/bsod-help-support/392735-4-bsod-row-when-starting-up-my-computer-am-error-0x0000.
Windows 7: 4 BSOD in a row when starting up my computer this am error: 0x0000001e
http://www.sevenforums.com/bsod-help-support/392735-4-bsod-row-when-starting-up-my-computer-am-error-0x0000001e.html

 Please only use 1 forum to help clear up your problem. Posting on more than 1 and following instructions from more than 1 forum will cause frustrationt for those helping you.

If you wish to continue with help here please annotate the post on the Win7 board that you are now getting help elsewhere.

Platypuss

 

Click Here