Recent Posts

Pages: [1] 2 3 ... 10
1
Post Here for Malware Removal ... / Re: [In progress - K] Slow, freezing
« Last post by lsvetka on Today at 08:00:00 PM »
Frst is attached.

You are right about Windows Update.

The black box appears only for like 2-3 seconds, so I'm not able to take a screenshot of that unfortunately.
2
Post Here for Malware Removal ... / Re: [In progress - K] Slow, freezing
« Last post by lsvetka on Today at 07:58:21 PM »
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-04-2015 01
Ran by SASHAISVETA at 2015-04-27 18:56:59
Running from C:\Users\SASHAISVETA\Desktop\Malware cleaning
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-4184064448-517517793-26037721-500 - Administrator - Disabled)
Guest (S-1-5-21-4184064448-517517793-26037721-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4184064448-517517793-26037721-1002 - Limited - Enabled)
SASHAISVETA (S-1-5-21-4184064448-517517793-26037721-1000 - Administrator - Enabled) => C:\Users\SASHAISVETA

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKLM-x32\...\uTorrent) (Version: 3.3.0.29126 - BitTorrent Inc.)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Photoshop CS3 (HKLM-x32\...\Adobe_2ac78060bc5856b0c1cf873bb919b58) (Version: 10.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2F72F540-1F60-4266-9506-952B21D6640D}) (Version: 6.1.0.13 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\...\avast) (Version: 10.2.2215 - AVAST Software)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 3.19 - Piriform)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Data Vault (Version: 4.2.2.0 - Dell Inc.) Hidden
Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell)
Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell)
Dell Dock (HKLM-x32\...\Dell Dock) (Version:  - Stardock Corporation)
Dell Dock (Version: 2.0 - Stardock Corporation) Hidden
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 1.0.6584.81 - Dell)
Dell SupportAssistAgent (HKLM-x32\...\{287348C8-8B47-4C36-AF28-441A3B7D8722}) (Version: 1.0.3.60494 - Dell)
Dropbox (HKU\S-1-5-21-4184064448-517517793-26037721-1000\...\Dropbox) (Version: 3.0.4 - Dropbox, Inc.)
DVD Photo Slideshow Professional 8.06 (HKLM-x32\...\DVD Photo Slideshow Professional_is1) (Version:  - dvd-photo-slideshow.com)
ERUNT 1.1j (HKLM-x32\...\ERUNT_is1) (Version:  - Lars Hederer)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Google Chrome (HKU\S-1-5-21-4184064448-517517793-26037721-1000\...\Google Chrome) (Version: 42.0.2311.90 - Google Inc.)
GoToAssist 8.0.0.514 (HKLM-x32\...\GoToAssist) (Version:  - )
HP Deskjet 1050 J410 series Basic Device Software (HKLM\...\{BB94D541-A747-4A5D-B0ED-72FA5C158EA5}) (Version: 22.0.334.0 - Hewlett-Packard Co.)
HP Deskjet 1050 J410 series Help (HKLM-x32\...\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
HP Deskjet 1050 J410 series Product Improvement Study (HKLM\...\{5848A26C-E4BC-4A13-AA8D-810BA344475A}) (Version: 22.0.334.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.3341 - HP Photo Creations Powered by RocketLife)
HP Update (HKLM-x32\...\{787D1A33-A97B-4245-87C0-7174609A540C}) (Version: 5.002.005.003 - Hewlett-Packard)
Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2104 - Intel Corporation)
Internet TV for Windows Media Center (HKLM-x32\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 4.2.2.0 - Microsoft Corporation)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\...\{0225AD21-F3E2-4916-BFF3-65D3F9052582}) (Version: 11.0.2.26 - Apple Inc.)
Java 7 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle)
Longman Dictionary of American English, 4th edition (HKLM-x32\...\NSIS_ldae_4) (Version:  - )
Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Mavis Beacon Teaches Typing 16 (HKLM-x32\...\Mavis Beacon Teaches Typing 16) (Version:  - )
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft LifeCam (HKLM\...\{6965A8D2-465D-4F98-9FAA-0E9E2348F329}) (Version: 3.22.270.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 15.0.4701.1002 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 37.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 en-US)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
Multimedia Card Reader (HKLM-x32\...\InstallShield_{23B4636C-A780-4FEB-B4C9-A2564E9B9F7C}) (Version: 1.6.915.87 - Fitipower)
Multimedia Card Reader (x32 Version: 1.6.915.87 - Fitipower) Hidden
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
ooVoo (HKLM-x32\...\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}) (Version: 3.5.9060 - ooVoo LLC.)
Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA)
Opera Stable 28.0.1750.51 (HKLM-x32\...\Opera 28.0.1750.51) (Version: 28.0.1750.51 - Opera Software ASA)
PDF Settings (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
QUICKfind server v1.1 (HKLM-x32\...\QUICKfind) (Version:  - IDM)
QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
RealDownloader (x32 Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6043 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Respondus LockDown Browser (HKLM-x32\...\{C0E5147E-C9F3-4360-9ED0-2E875F11766C}) (Version: 1.02.0001 - Respondus, Inc.)
Roxio Burn (HKLM-x32\...\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.01 - Roxio)
Secunia PSI (2.0.0.4003) (HKLM-x32\...\Secunia PSI) (Version: 2.0.0.4003 - Secunia)
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.6.11664 - Skype Technologies S.A.)
Skype™ 7.1 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Software602 Print2PDF (HKLM-x32\...\{32C74893-0243-4235-A6F3-201F0E5D2C03}) (Version: 9.0.11.0107 - Software602 Inc.)
SopCast 3.8.3 (HKLM-x32\...\SopCast) (Version: 3.8.3 - www.sopcast.com)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\SASHAISVETA\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32 -> c:\windows\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\SASHAISVETA\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\SASHAISVETA\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\SASHAISVETA\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\SASHAISVETA\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\SASHAISVETA\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\SASHAISVETA\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\SASHAISVETA\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\SASHAISVETA\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\SASHAISVETA\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4184064448-517517793-26037721-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\SASHAISVETA\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points  =========================

20-02-2015 13:19:37 Scheduled Checkpoint
28-02-2015 10:08:33 Scheduled Checkpoint
08-03-2015 10:18:30 Scheduled Checkpoint
15-03-2015 18:55:48 Scheduled Checkpoint
18-03-2015 20:23:10 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
18-03-2015 20:23:57 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
18-03-2015 20:24:34 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
18-03-2015 20:25:26 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
18-03-2015 20:49:25 Installed Adobe Acrobat XI Pro.
26-03-2015 15:06:08 Scheduled Checkpoint
28-03-2015 11:53:32 Removed Adobe Acrobat XI Pro.
28-03-2015 12:02:01 Removed Adobe Download Assistant
05-04-2015 08:10:02 Scheduled Checkpoint
12-04-2015 14:42:09 Scheduled Checkpoint
12-04-2015 21:15:23 Windows Update
13-04-2015 13:04:23 Windows Update
14-04-2015 06:20:17 Windows Update
15-04-2015 00:52:29 Windows Update
16-04-2015 07:47:36 Windows Update
19-04-2015 11:23:41 Installed Microsoft Fix it 50535
19-04-2015 11:29:11 Installed Microsoft Fix it 50692
20-04-2015 13:37:20 avast! antivirus system restore point
21-04-2015 19:06:12 Installed Microsoft Fix it 50692
21-04-2015 19:06:43 Installed Microsoft Fix it 50692
21-04-2015 19:09:00 Installed Microsoft Fix it 50692
23-04-2015 14:09:15 Installed Microsoft Fix it 50535
24-04-2015 07:54:08 Windows Update
26-04-2015 10:54:29 Windows Update
26-04-2015 11:10:22 Windows Update
26-04-2015 14:38:04 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2012-03-05 23:54 - 2012-03-05 23:54 - 00000822 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0BA28289-E293-4F8F-92DC-FAC77E8377B7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {25E8F105-5A94-42B1-8A98-B107CCDFD8C8} - System32\Tasks\{F89D5431-2DBE-4430-9C9E-C7CE478B8786} => pcalua.exe -a C:\ProgramData\7531CC927F542C8C49A2299C4F147CE7\7531CC927F542C8C49A2299C4F147CE7.exe -c -u
Task: {29E02982-70E5-425F-B116-E749C3D9FD4F} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-04-20] (Avast Software s.r.o.)
Task: {38F0D98C-09EB-401C-8D39-60CEAF00A660} - System32\Tasks\{F346EE5E-54AC-4052-9CC9-36BCF9879C2A} => C:\Program Files (x86)\Opera\opera.exe [2014-04-22] (Opera Software)
Task: {4EBB31F1-43DE-400F-9AD5-77335ED63C84} - System32\Tasks\{9C6A98CC-DF96-44F1-BCF9-3D1413BC73A3} => pcalua.exe -a C:\Users\SASHAISVETA\Downloads\print2pdf9.exe
Task: {56A79996-C356-43C9-ADA3-82C9329E2A73} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {56BC5F94-2A0D-4CDC-B608-092744CD9993} - System32\Tasks\{655B23AA-8389-4186-80DA-88B9DB4D4D08} => C:\Program Files (x86)\PDFCreator\PDFCreator.exe
Task: {5845E089-4391-43F4-BD17-64DD99F8AE45} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
Task: {5BA131D7-00C2-4A08-8286-64C05A7966F4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {660A4079-6416-41B5-AB29-A2516B457D0F} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-03-20] (PC-Doctor, Inc.)
Task: {6713B316-10A8-454E-81DD-3C2B9FA43C63} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {6932B0C2-17D8-48E2-87C5-BB7183F3CAC3} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
Task: {6E655110-4A8E-4A5C-AF93-E230E9A2278D} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2010-06-14] (Hewlett-Packard Co.)
Task: {745F82E2-E4CB-456C-995D-95CB5DCAC9AE} - System32\Tasks\{B8734217-3CF2-4890-AC0A-A6DAB25AC5B5} => pcalua.exe -a C:\Users\SASHAISVETA\Downloads\SetupT_ailuhin@att!net.exe -d C:\Users\SASHAISVETA\Downloads
Task: {7A8B7202-B30C-44B5-AE99-C06D31CEFA08} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-4184064448-517517793-26037721-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {7D70A29A-A6BC-48B0-B435-F9A97916177B} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2015-03-20] (PC-Doctor, Inc.)
Task: {86D7860A-7921-4170-A675-A39386D38787} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4184064448-517517793-26037721-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {878B59B5-20D8-42E2-ABD4-DA4217778E33} - System32\Tasks\{AF48C592-86E6-4D4F-8058-A67295043928} => C:\Program Files (x86)\ooVoo\ooVoo.exe [2013-09-10] (ooVoo LLC)
Task: {89AC4788-2447-4004-9E8D-5BF4B69BD2D6} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {89C6C1EB-707B-4200-AD52-C20A1E1A010A} - System32\Tasks\Opera scheduled Autoupdate 1429756790 => C:\Program Files (x86)\Opera\launcher.exe [2015-04-07] (Opera Software)
Task: {8C6309E2-E365-40A4-9816-00BEF7B67528} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-14] (Adobe Systems Incorporated)
Task: {8D5F361D-4D7A-4CDA-A0A1-914F1A2723D3} - System32\Tasks\{79602257-B38B-44A4-836C-15C4D8473AF7} => C:\Program Files (x86)\ooVoo\ooVoo.exe [2013-09-10] (ooVoo LLC)
Task: {95F79B02-012E-4EF0-98E9-CA16BBC49162} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2015-02-10] (Microsoft Corporation)
Task: {9CA10FE6-AD6C-44F3-BD89-D28857127661} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4184064448-517517793-26037721-1000Core => C:\Users\SASHAISVETA\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-25] (Google Inc.)
Task: {9F0D4634-7881-4422-BCAA-BBA7A46583AB} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-4184064448-517517793-26037721-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {9F2AD6DA-A6E0-4982-8CEC-015144612744} - System32\Tasks\{9F70B393-FACC-4732-8136-066C380596DE} => C:\Program Files (x86)\PDFCreator\PDFCreator.exe
Task: {AF063A7A-A714-4495-B72D-D1D414984E0C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-02-03] (Microsoft Corporation)
Task: {AF546E69-B850-46B5-A48B-5679F73B29A0} - System32\Tasks\{5DAEFE6B-77E5-4DC7-B756-19E3A1039166} => C:\Program Files (x86)\ooVoo\ooVoo.exe [2013-09-10] (ooVoo LLC)
Task: {B3D457B4-7D21-49EC-9CC2-E957525ED9BD} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2015-04-10] (Dell Inc.)
Task: {BE74F203-A9C4-41DB-B2AD-E56373B5697C} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation)
Task: {BF20B59B-6EC4-405C-BB78-D05A51236976} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-02-03] (Microsoft Corporation)
Task: {D8893FC1-0F12-49D1-89F6-F6499D10A9DF} - System32\Tasks\{8E179E37-4F54-4EC0-BB5B-CBF4851DC8E9} => pcalua.exe -a "C:\Users\SASHAISVETA\Desktop\movies\office 2007 (D)\setup.exe" -d "C:\Users\SASHAISVETA\Desktop\movies\office 2007 (D)"
Task: {DA940A0F-F6A6-486C-8051-1485DDDB4060} - System32\Tasks\Microsoft Office 15 Sync Maintenance for SASHAISVETA-PC-SASHAISVETA SASHAISVETA-PC => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation)
Task: {DC26A411-C02A-4CC0-9371-832930961B57} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4184064448-517517793-26037721-1000UA => C:\Users\SASHAISVETA\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-25] (Google Inc.)
Task: {E047ABB2-9A26-49FE-A238-DB7B7683B788} - System32\Tasks\{A939A5FC-E8DB-49E1-ABAE-6874094FE2AD} => C:\Program Files (x86)\ooVoo\ooVoo.exe [2013-09-10] (ooVoo LLC)
Task: {ED99670E-329F-4CF6-9F10-85335D1554B0} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {EF21D2CE-35A7-4767-AFA5-E7B84535FA17} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {F8E47635-663A-41D8-B19D-E50BE62DC80C} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4184064448-517517793-26037721-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4184064448-517517793-26037721-1000Core.job => C:\Users\SASHAISVETA\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4184064448-517517793-26037721-1000UA.job => C:\Users\SASHAISVETA\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2015-02-11 15:13 - 2015-02-11 15:13 - 00997536 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2015-03-14 08:27 - 2015-01-27 08:29 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2011-02-08 21:22 - 2010-12-02 02:13 - 00216576 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\Software602.dll
2015-01-19 13:53 - 2014-05-20 08:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2010-10-22 07:58 - 2011-08-18 08:05 - 02751808 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
2012-01-10 21:12 - 2012-01-10 21:12 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-04-14 09:45 - 2015-04-14 09:45 - 00472576 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\c29d8779b3a3599f44e21e017541cd0c\VistaBridgeLibrary.ni.dll
2009-10-15 01:10 - 2009-10-15 01:10 - 00498160 _____ () C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
2015-03-30 15:04 - 2015-02-25 15:22 - 00107256 _____ () C:\Program Files\Dell\SupportAssist\libCSharpCommonCS.dll
2015-03-30 15:04 - 2015-02-25 15:22 - 00545528 _____ () C:\Program Files\Dell\SupportAssist\libAsapiCSharp.dll
2015-04-20 13:39 - 2015-04-20 13:39 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-04-20 13:39 - 2015-04-20 13:39 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-04-26 15:30 - 2015-04-26 15:30 - 02927104 _____ () C:\Program Files\AVAST Software\Avast\defs\15042601\algo.dll
2015-04-27 14:54 - 2015-04-27 14:54 - 02925568 _____ () C:\Program Files\AVAST Software\Avast\defs\15042701\algo.dll
2011-09-27 08:23 - 2011-09-27 08:23 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-09-27 08:22 - 2011-09-27 08:22 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-03-14 08:27 - 2015-01-27 07:13 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
2011-02-08 21:22 - 2008-09-29 14:09 - 00073728 _____ () C:\Program Files (x86)\Software602\Print2PDF\wcs.dll
2011-02-08 21:22 - 2008-09-29 14:09 - 00532480 _____ () C:\Program Files (x86)\Software602\Print2PDF\wc.dll
2015-04-20 13:39 - 2015-04-20 13:39 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-04-19 17:08 - 2015-04-13 14:55 - 01252680 _____ () C:\Users\SASHAISVETA\AppData\Local\Google\Chrome\Application\42.0.2311.90\libglesv2.dll
2015-04-19 17:08 - 2015-04-13 14:55 - 00080712 _____ () C:\Users\SASHAISVETA\AppData\Local\Google\Chrome\Application\42.0.2311.90\libegl.dll
2015-04-19 17:08 - 2015-04-13 14:55 - 14980424 _____ () C:\Users\SASHAISVETA\AppData\Local\Google\Chrome\Application\42.0.2311.90\PepperFlash\pepflashplayer.dll
2015-01-19 13:53 - 2015-01-19 13:53 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\AppVIsvStream32.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-4184064448-517517793-26037721-1000\...\sharepoint.com -> hxxps://appslosrios.sharepoint.com


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4184064448-517517793-26037721-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\SASHAISVETA\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [TCP Query User{AB7796FD-3278-4B85-BC84-25707A4018A0}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{7AAA7349-70FB-40D8-9CFA-1E76E49D27D5}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{8E048ACD-DAA7-4228-BD5C-9078DB7F869D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{72EBDA85-45BA-4FD8-ADB6-03C0102BD11A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{676C05D5-5DC8-4FA8-9BFB-93D2AAE9FF61}C:\program files (x86)\sopcast\sopcast.exe] => (Allow) C:\program files (x86)\sopcast\sopcast.exe
FirewallRules: [UDP Query User{C137C214-3571-45DE-B9C1-E0DE019E1568}C:\program files (x86)\sopcast\sopcast.exe] => (Allow) C:\program files (x86)\sopcast\sopcast.exe
FirewallRules: [{059E068E-813A-4EDA-810D-6AB40DC66FBA}] => (Allow) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
FirewallRules: [TCP Query User{2837DFF9-2D98-4F9D-B227-BF6235F904F2}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{CDC601B3-15E9-49BE-864C-63A48272268E}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/27/2015 10:36:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Skype.exe, version: 7.1.0.105, time stamp: 0x54c25acc
Faulting module name: jscript9.dll, version: 11.0.9600.17728, time stamp: 0x5502500e
Exception code: 0xc0000005
Fault offset: 0x000fe415
Faulting process id: 0x1294
Faulting application start time: 0xSkype.exe0
Faulting application path: Skype.exe1
Faulting module path: Skype.exe2
Report Id: Skype.exe3

Error: (04/27/2015 08:51:26 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9952

Error: (04/27/2015 08:51:26 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9952

Error: (04/27/2015 08:51:26 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (04/26/2015 03:36:49 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 630

Start Time: 01d080703fcbef59

Termination Time: 41

Application Path: C:\Windows\Explorer.EXE

Report Id: b0b2e78e-ec64-11e4-9f35-842b2bad37cf

Error: (04/24/2015 06:48:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10000

Error: (04/24/2015 06:48:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 10000

Error: (04/24/2015 06:48:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (04/24/2015 00:47:34 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/24/2015 00:47:25 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.


System errors:
=============
Error: (04/27/2015 11:24:36 AM) (Source: DCOM) (EventID: 10016) (User: SASHAISVETA-PC)
Description: application-specificLocalActivation{8BC3F05E-D86B-11D0-A075-00C04FB68820}{8BC3F05E-D86B-11D0-A075-00C04FB68820}SASHAISVETA-PCSASHAISVETAS-1-5-21-4184064448-517517793-26037721-1000LocalHost (Using LRPC)

Error: (04/26/2015 03:36:45 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}

Error: (04/26/2015 03:28:57 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.

Error: (04/26/2015 03:28:27 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.

Error: (04/26/2015 00:15:20 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a171\??\Volume{39d508ed-ddfc-11df-9edd-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{82E3584F-45A7-4C8E-9637-F11B381E1E5F}

Error: (04/26/2015 00:12:41 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a171\??\Volume{39d508ed-ddfc-11df-9edd-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{A3336F2F-3C62-4D93-A649-37A4D6B74A6B}

Error: (04/26/2015 11:25:12 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.

Error: (04/26/2015 11:24:42 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.

Error: (04/26/2015 11:02:43 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.

Error: (04/26/2015 11:02:13 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3 CPU 540 @ 3.07GHz
Percentage of memory in use: 58%
Total physical RAM: 5943.12 MB
Available physical RAM: 2450.39 MB
Total Pagefile: 11884.43 MB
Available Pagefile: 7235.16 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:921.59 GB) (Free:531.15 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 259D4594)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=9.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=921.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================
3
Hi seedy21,

I ran the commands with command Prompt.

Then ran MiniToolbox and attached it below but it is too large, how shall I
send it to you?

Nancy

4
Hi crxb5

Thanks for the update. Lets try another Tool


Please Download Farbar Recovery Scan Tool 64-Bit and save it to your Desktop.

  • Double Click the Program to Run it.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log FRST.txt and Additional.txt which will open in Notepad. Please copy and paste it to your reply.

5
Current News / Police breaks up cybergang
« Last post by bamajim on Today at 06:54:08 AM »
Police breaks up cybergang that stole over $15 million from banks

LINK

Quote
Romanian authorities executed 42 house search warrants in six cities on Sunday, seizing laptops and mobile phones believed to have been used by the gang’s members. They also seized €150,000 ($163,000) in cash, gold bars weighing 2 kilograms and paintings.
6
Hello lsvetka,

If you manually checked for updates and installed what was available it should be ok...

Regarding the black box you mention, are you able to take a screen shot and post the image?

next,

Run FRST one more time, ensure all boxes are checkmarked under "Whitelist" but only Addition.txt under "Optional scan" Select scan, when done post the two logs....

Next,

Select start orb, type or copy paste services.msc into the search box, tap enter. The services window will open. Scroll to "Windows Update" it should be started and its Startup Type should be "Automatic (delayed)" is that correct...

Thanks...
7
I have done exactly as you have requested but the program still doesn't seem to finish.  It never opens a log file as stated.  I have waited 15 minutes.  Please see the following error that popped up when running this program. 
8
Hi Crxb5

Please close the program and then restart your computer.

When your computer has loaded up again please Right Click on Zoek and select Run as Administrator

Then run this new scripted instead

Code: [Select]
systemspecs;
services-list;
filesrcm;
emptyfolderscheck;
startupall;
firefoxlook;
chromelook;
skipfix-iedefaults;
msconfigcheck;
9
Hello sir I Have tried what you have recommended however it seems as if the virus or malware that's in my laptop is preventing this program from running properly.  I have turned off and disabled all antivirus- however the ZOEK program will run for 2 hours and not create a log nor say it has finished??? is this normal???  What should I do? 
This is what remains in the script screen in the program:
===== Runcheck 14:41:39.80 =====

--- Create Environment Variables 14:41:40.76
--- Create System Restore Point 14:41:45.62
--- Checking Input 14:41:48.89
--- Empty Folders Check 14:41:59.16
--- Processes 14:41:59.21

This is what the two text files it created read.
Zoek-results :

==== System Restore Info ======================

4/26/2015 2:41:47 PM Zoek.exe System Restore Point Created Successfully.


Runcheck results:


===== Runcheck 14:41:39.80 =====

--- Create Environment Variables 14:41:40.76
--- Create System Restore Point 14:41:45.62
--- Checking Input 14:41:48.89
--- Empty Folders Check 14:41:59.16
--- Processes 14:41:59.21



PLEASE HELP thanks
10
Post Here for Malware Removal ... / Re: [In progress - K] Slow, freezing
« Last post by lsvetka on Yesterday at 11:59:18 AM »
I went to Windows Update and installed available updates. Is there a way to check there are any problems with windows update?

The system itself is pretty slow, especially boot time. Also, sometimes when I'm online  a black box pops up  for a few seconds and then goes away. Do you know what is it?

Thanks.
Pages: [1] 2 3 ... 10
Click Here