My computer is fairly new and as of this morning everything has been running slow, especially IE.
swMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2014-12-21 07:15:03
—————————–
07:15:03.733 OS Version: Windows x64 6.1.7601 Service Pack 1
07:15:03.733 Number of processors: 8 586 0x3C03
07:15:03.733 ComputerName: SCOTT-PC UserName: Scott
07:15:15.934 Initialize success
07:15:16.724 VM: initialized successfully
07:15:16.724 VM: Intel CPU supported
07:15:23.365 VM: not used
07:16:14.367 AVAST engine defs: 14122100
07:16:38.219 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006f
07:16:38.229 Disk 0 Vendor: ATA_____ 1A01 Size: 953869MB BusType: 11
07:16:38.459 Disk 0 MBR read successfully
07:16:38.469 Disk 0 MBR scan
07:16:38.479 Disk 0 Windows VISTA default MBR code
07:16:38.509 Disk 0 Partition 1 00 DE Dell Utility DELL 4.1 39 MB offset 63
07:16:38.529 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 24802 MB offset 81920
07:16:38.549 Disk 0 Boot: NTFS code=1
07:16:38.579 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 929026 MB offset 50876416
07:16:38.609 Disk 0 scanning C:\Windows\system32\drivers
07:16:48.520 Service scanning
07:16:54.740 Service BHDrvx64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\BASHDefs\20141209.001\BHDrvx64.sys **LOCKED** 5
07:16:57.551 Service eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys **LOCKED** 5
07:16:57.911 Service EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys **LOCKED** 5
07:16:59.331 Service IDSVia64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\IPSDefs\20141219.001\IDSvia64.sys **LOCKED** 5
07:17:01.371 Service NAVENG C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\VirusDefs\20141220.002\ENG64.SYS **LOCKED** 5
07:17:01.481 Service NAVEX15 C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\VirusDefs\20141220.002\EX64.SYS **LOCKED** 5
07:17:17.442 Modules scanning
07:17:17.442 Disk 0 trace - called modules:
07:17:17.482 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys storport.sys hal.dll iaStorA.sys
07:17:17.492 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007650790]
07:17:17.502 3 CLASSPNP.SYS[fffff8800143b43f] -> nt!IofCallDriver -> [0xfffffa80073308a0]
07:17:17.512 5 iaStorF.sys[fffff88001a9fa2c] -> nt!IofCallDriver -> \Device\0000006f[0xfffffa80071dd9c0]
07:17:19.773 AVAST engine scan C:\Windows
07:17:23.213 AVAST engine scan C:\Windows\system32
07:19:22.693 AVAST engine scan C:\Windows\system32\drivers
07:19:37.986 AVAST engine scan C:\Users\Scott
07:21:53.929 Disk 0 MBR has been saved successfully to "C:\MBR.dat"
07:21:53.929 The log file has been saved successfully to "C:\aswMBR.txt"
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2014-12-21 07:15:03
—————————–
07:15:03.733 OS Version: Windows x64 6.1.7601 Service Pack 1
07:15:03.733 Number of processors: 8 586 0x3C03
07:15:03.733 ComputerName: SCOTT-PC UserName: Scott
07:15:15.934 Initialize success
07:15:16.724 VM: initialized successfully
07:15:16.724 VM: Intel CPU supported
07:15:23.365 VM: not used
07:16:14.367 AVAST engine defs: 14122100
07:16:38.219 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006f
07:16:38.229 Disk 0 Vendor: ATA_____ 1A01 Size: 953869MB BusType: 11
07:16:38.459 Disk 0 MBR read successfully
07:16:38.469 Disk 0 MBR scan
07:16:38.479 Disk 0 Windows VISTA default MBR code
07:16:38.509 Disk 0 Partition 1 00 DE Dell Utility DELL 4.1 39 MB offset 63
07:16:38.529 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 24802 MB offset 81920
07:16:38.549 Disk 0 Boot: NTFS code=1
07:16:38.579 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 929026 MB offset 50876416
07:16:38.609 Disk 0 scanning C:\Windows\system32\drivers
07:16:48.520 Service scanning
07:16:54.740 Service BHDrvx64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\BASHDefs\20141209.001\BHDrvx64.sys **LOCKED** 5
07:16:57.551 Service eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys **LOCKED** 5
07:16:57.911 Service EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys **LOCKED** 5
07:16:59.331 Service IDSVia64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\IPSDefs\20141219.001\IDSvia64.sys **LOCKED** 5
07:17:01.371 Service NAVENG C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\VirusDefs\20141220.002\ENG64.SYS **LOCKED** 5
07:17:01.481 Service NAVEX15 C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\VirusDefs\20141220.002\EX64.SYS **LOCKED** 5
07:17:17.442 Modules scanning
07:17:17.442 Disk 0 trace - called modules:
07:17:17.482 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys storport.sys hal.dll iaStorA.sys
07:17:17.492 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007650790]
07:17:17.502 3 CLASSPNP.SYS[fffff8800143b43f] -> nt!IofCallDriver -> [0xfffffa80073308a0]
07:17:17.512 5 iaStorF.sys[fffff88001a9fa2c] -> nt!IofCallDriver -> \Device\0000006f[0xfffffa80071dd9c0]
07:17:19.773 AVAST engine scan C:\Windows
07:17:23.213 AVAST engine scan C:\Windows\system32
07:19:22.693 AVAST engine scan C:\Windows\system32\drivers
07:19:37.986 AVAST engine scan C:\Users\Scott
07:21:53.929 Disk 0 MBR has been saved successfully to "C:\MBR.dat"
07:21:53.929 The log file has been saved successfully to "C:\aswMBR.txt"
07:22:00.759 Disk 0 statistics 3413468/0/0 @ 7.42 MB/s
07:22:00.759 Scan stopped
07:22:06.089 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006f
07:22:06.099 Disk 0 Vendor: ATA_____ 1A01 Size: 953869MB BusType: 11
07:22:06.119 Disk 0 MBR read successfully
07:22:06.129 Disk 0 MBR scan
07:22:06.149 Disk 0 Windows VISTA default MBR code
07:22:06.179 Disk 0 Partition 1 00 DE Dell Utility DELL 4.1 39 MB offset 63
07:22:06.209 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 24802 MB offset 81920
07:22:06.229 Disk 0 Boot: NTFS code=1
07:22:06.239 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 929026 MB offset 50876416
07:22:06.249 Disk 0 scanning C:\Windows\system32\drivers
07:22:06.259 Service scanning
07:22:10.460 Service BHDrvx64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\BASHDefs\20141209.001\BHDrvx64.sys **LOCKED** 5
07:22:14.701 Service eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys **LOCKED** 5
07:22:15.101 Service EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys **LOCKED** 5
07:22:19.533 Service IDSVia64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\IPSDefs\20141219.001\IDSvia64.sys **LOCKED** 5
07:22:24.473 Service NAVENG C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\VirusDefs\20141220.002\ENG64.SYS **LOCKED** 5
07:22:24.603 Service NAVEX15 C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\VirusDefs\20141220.002\EX64.SYS **LOCKED** 5
07:22:33.224 Modules scanning
07:22:33.234 Disk 0 trace - called modules:
07:22:33.264 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys storport.sys hal.dll iaStorA.sys
07:22:33.264 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007650790]
07:22:33.264 3 CLASSPNP.SYS[fffff8800143b43f] -> nt!IofCallDriver -> [0xfffffa80073308a0]
07:22:33.264 5 iaStorF.sys[fffff88001a9fa2c] -> nt!IofCallDriver -> \Device\0000006f[0xfffffa80071dd9c0]
07:22:34.574 AVAST engine scan C:\Windows
07:22:40.315 AVAST engine scan C:\Windows\system32
07:24:28.407 AVAST engine scan C:\Windows\system32\drivers
07:24:40.108 AVAST engine scan C:\Users\Scott
07:25:12.753 Disk 0 MBR has been saved successfully to "C:\MBR.dat"
07:25:12.753 The log file has been saved successfully to "C:\aswMBR.txt"
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-12-2014 01
Ran by [removed] (administrator) on SCOTT-PC on 21-12-2014 07:26:13
Running from C:\Scott's Files
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe
() C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
( ) C:\Windows\System32\dleacoms.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\nis.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Atheros) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe
(Atheros) C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\nis.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Toaster.exe
() C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7188040 2013-05-10] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1307720 2013-04-24] (Realtek Semiconductor)
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286192 2013-02-06] (Intel Corporation)
HKLM\…\Run: [AtherosBtStack] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\btvstack.exe [1023104 2012-12-27] (Atheros Commnucations)
HKLM\…\Run: [AthBtTray] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\athbttray.exe [801920 2012-12-27] (Atheros Commnucations)
HKLM\…\Run: [dleamon.exe] => C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe [770728 2011-01-23] ()
HKLM\…\Run: [EzPrint] => C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe [139944 2011-01-23] ()
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-12] (NVIDIA Corporation)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-25] (Intel Corporation)
HKLM-x32\…\Run: [Dell V310-V510 Series] => C:\Program Files (x86)\Dell V310-V510 Series\fm3032.exe [316072 2011-01-23] ()
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\…\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft anti-malware\a2guard.exe [4954576 2014-12-01] (Emsisoft GmbH)
HKU\S-1-5-21-2748532688-3923759273-2942247134-1000\…\Run: [DellSystemDetect] => C:\Users\Scott\AppData\Local\Apps\2.0\N8QBTQ4R.NWN\YH4ZB9KY.JY3\dell..tion_e30b47f5d4a30e9e_0005.000b_1df8a3cb60a9209e\DellSystemDetect.exe
HKU\S-1-5-21-2748532688-3923759273-2942247134-1000\…\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7780120 2014-12-15] (SUPERAntiSpyware)
HKU\S-1-5-21-2748532688-3923759273-2942247134-1000\…A8F59079A8D5}\localserver32: <==== ATTENTION!
ShellIconOverlayIdentifiers: [DBARFileBackuped] -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DBARFileNotBackuped] -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2748532688-3923759273-2942247134-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dell13.msn.com/?pc=DCJB
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2748532688-3923759273-2942247134-1000 -> DefaultScope {901C6264-F237-4797-8633-8BF4CA2674EC} URL =
SearchScopes: HKU\S-1-5-21-2748532688-3923759273-2942247134-1000 -> {901C6264-F237-4797-8633-8BF4CA2674EC} URL =
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine64\21.6.0.32\coIEPlg.dll (Symantec Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Dell Toolbar -> {09B71986-2AC5-482d-B6CB-42EA34F4F85B} -> C:\Program Files\Dell Printable Web\toolband.dll ()
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.6.0.32\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Dell Toolbar - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Printable Web\toolband.dll ()
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF HKLM-x32\…\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.5.0.19\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.5.0.19\IPSFF [2014-09-25]
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.5.0.19\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.5.0.19\coFFPlgn [2014-12-21]
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK
Chrome:
=======
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
CHR HKLM\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\Exts\Chrome.crx [2014-09-25]
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
CHR HKLM-x32\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\Exts\Chrome.crx [2014-09-25]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4907232 2014-12-01] (Emsisoft GmbH)
S2 dleaCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\dleaserv.exe [45224 2010-05-21] ()
R2 dlea_device; C:\Windows\system32\dleacoms.exe [1052328 2010-05-21] ( )
R2 dlea_device; C:\Windows\SysWOW64\dleacoms.exe [598696 2010-05-21] ( )
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-02-06] (Intel Corporation)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-02-19] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-02-19] (Intel Corporation)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\NIS.exe [276376 2014-09-21] (Symantec Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-12] (NVIDIA Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [224840 2013-05-10] (Realtek Semiconductor)
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [1915920 2013-11-21] (SoftThinks SAS)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe [327296 2012-12-27] (Atheros)
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [81536 2012-12-25] (Atheros)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [23088 2014-05-12] (Emsisoft GmbH)
R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\BASHDefs\20141209.001\BHDrvx64.sys [1587416 2014-10-03] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1506000.020\ccSetx64.sys [162392 2014-02-20] (Symantec Corporation)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-11] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-11] (Symantec Corporation)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28656 2013-01-15] (Intel Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\IPSDefs\20141219.001\IDSvia64.sys [637656 2014-11-18] (Symantec Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [116736 2014-02-19] (Intel Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\VirusDefs\20141220.002\ENG64.SYS [129752 2014-09-24] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.5.0.19\Definitions\VirusDefs\20141220.002\EX64.SYS [2137304 2014-09-24] (Symantec Corporation)
S1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
R1 SRTSP; C:\Windows\System32\Drivers\NISx64\1506000.020\SRTSP64.SYS [876248 2014-08-25] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1506000.020\SRTSPX64.SYS [37592 2014-08-25] (Symantec Corporation)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2014-09-29] ()
R0 SymDS; C:\Windows\System32\drivers\NISx64\1506000.020\SYMDS64.SYS [493656 2014-07-23] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1506000.020\SYMEFA64.SYS [1148120 2014-07-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-09-25] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1506000.020\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1506000.020\SYMNETS.SYS [593112 2014-07-23] (Symantec Corporation)
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
U3 aswMBR; \??\C:\Users\Scott\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Scott\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-21 07:25 - 2014-12-21 07:26 - 00000000 ____D () C:\FRST
2014-12-21 07:21 - 2014-12-21 07:25 - 00008375 _____ () C:\aswMBR.txt
2014-12-21 07:21 - 2014-12-21 07:25 - 00000512 _____ () C:\MBR.dat
2014-12-21 07:14 - 2014-12-21 07:14 - 05198336 _____ (AVAST Software) C:\Users\Scott\Downloads\aswMBR.exe
2014-12-21 06:59 - 2014-12-21 07:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-12-21 06:59 - 2014-12-21 07:00 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-12-21 06:59 - 2014-12-21 06:59 - 00003584 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 38877689-3997-4fc9-b6d4-0e336e85b125
2014-12-21 06:59 - 2014-12-21 06:59 - 00003510 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 008704f4-0625-4f5f-89b3-9b3e4c9b748e
2014-12-21 06:59 - 2014-12-21 06:59 - 00001810 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
2014-12-21 06:59 - 2014-12-21 06:59 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 38877689-3997-4fc9-b6d4-0e336e85b125.job
2014-12-21 06:59 - 2014-12-21 06:59 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 008704f4-0625-4f5f-89b3-9b3e4c9b748e.job
2014-12-21 06:59 - 2014-12-21 06:59 - 00000000 ____D () C:\Users\Scott\AppData\Roaming\SUPERAntiSpyware.com
2014-12-21 06:59 - 2014-12-21 06:59 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-12-21 06:41 - 2014-12-21 06:41 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-12-21 06:38 - 2014-12-21 06:38 - 00000000 ___RD () C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-12-21 06:34 - 2014-12-21 07:15 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware
2014-12-21 06:34 - 2014-12-21 06:34 - 170178096 _____ (Emsisoft Ltd ) C:\EmsisoftAntiMalwareSetup.exe
2014-12-21 06:34 - 2014-12-21 06:34 - 00001097 _____ () C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2014-12-21 06:34 - 2014-12-21 06:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2014-12-20 17:04 - 2014-12-20 17:04 - 00000000 ____D () C:\NPE
2014-12-20 16:55 - 2014-12-20 16:59 - 00000987 _____ () C:\Users\Scott\Desktop\FixPoweliks64.log
2014-12-20 16:47 - 2014-12-20 17:06 - 00000000 ____D () C:\Users\Scott\AppData\Local\NPE
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00031705.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00030811.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00030194.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00029823.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00029386.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00028673.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00028581.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00027888.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00027747.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00027020.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00026293.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00026063.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00023500.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00022826.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00021995.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00021903.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00021678.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00021636.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00020042.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00019882.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00019866.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00019758.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00018312.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00017481.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00016939.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00011912.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00011192.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00010148.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00009364.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00008892.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00007285.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00006728.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00006358.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00006256.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00006015.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00005858.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00005737.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00005544.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00005288.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00004915.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00004539.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00004527.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00004433.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00004306.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00004049.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00003950.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00003898.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00003845.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00002796.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00002246.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00001967.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00001806.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00001730.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00001549.tmp
2014-12-20 15:44 - 2014-12-20 15:44 - 01188456 ____T () C:\Windows\SysWOW64\00000297.tmp
2014-12-17 16:00 - 2014-12-17 16:00 - 00000000 ____D () C:\Users\Scott\AppData\Roaming\NVIDIA
2014-12-17 15:59 - 2014-12-17 16:00 - 00000000 ____D () C:\Users\Scott\Documents\Apowersoft Screen Recorder Pro
2014-12-17 15:59 - 2014-12-17 15:59 - 00000000 ____D () C:\Users\Scott\AppData\Roaming\Apowersoft
2014-12-17 15:59 - 2014-12-17 15:59 - 00000000 ____D () C:\Program Files (x86)\Apowersoft
2014-12-17 15:59 - 2014-04-09 20:50 - 00443568 ____H (Bytescout) C:\Windows\SysWOW64\ApowersoftScreenCapturing.dll
2014-12-17 15:59 - 2014-04-09 20:50 - 00271536 ____H (Bytescout) C:\Windows\SysWOW64\ApowersoftScreenCapturingFilter.dll
2014-12-17 15:59 - 2014-04-09 20:50 - 00181424 ____H (Bytescout) C:\Windows\SysWOW64\ApowersoftVideoMixerFilter.dll
2014-12-17 15:58 - 2014-12-17 15:58 - 21097216 _____ (APOWERSOFT LIMITED ) C:\Users\Scott\Downloads\apowersoft-screen-recorder-pro.exe
2014-12-17 14:30 - 2014-12-13 00:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-17 14:30 - 2014-12-12 22:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-13 02:14 - 2014-12-13 02:14 - 00084992 _____ () C:\Users\Scott\Documents\2014 ornament.pub
2014-12-13 02:11 - 2014-12-13 02:12 - 00080384 _____ () C:\Users\Scott\Documents\Publication3.pub
2014-12-13 01:58 - 2014-12-13 02:08 - 00129536 _____ () C:\Users\Scott\Documents\2014 candy guess.pub
2014-12-10 15:52 - 2014-12-10 15:52 - 00016672 _____ () C:\Users\Scott\Documents\Copy of APL000001_APPLE CONFIDENTIAL (June 2 to July 2).xlsx
2014-12-09 20:50 - 2014-12-09 20:50 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-09 20:05 - 2014-10-17 21:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-09 20:05 - 2014-10-17 20:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-09 20:04 - 2014-11-26 20:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-09 20:04 - 2014-11-26 20:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-09 20:04 - 2014-11-21 22:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-09 20:04 - 2014-11-21 22:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-09 20:04 - 2014-11-21 22:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-09 20:04 - 2014-11-21 21:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-09 20:04 - 2014-11-21 21:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-09 20:04 - 2014-11-21 21:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-09 20:04 - 2014-11-21 21:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-09 20:04 - 2014-11-21 21:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-09 20:04 - 2014-11-21 21:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-09 20:04 - 2014-11-21 21:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-09 20:04 - 2014-11-21 21:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-09 20:04 - 2014-11-21 21:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-09 20:04 - 2014-11-21 21:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-09 20:04 - 2014-11-21 21:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-09 20:04 - 2014-11-21 21:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-09 20:04 - 2014-11-21 21:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-09 20:04 - 2014-11-21 21:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-09 20:04 - 2014-11-21 21:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-09 20:04 - 2014-11-21 21:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-09 20:04 - 2014-11-21 21:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-09 20:04 - 2014-11-21 21:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-09 20:04 - 2014-11-21 21:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-09 20:04 - 2014-11-21 21:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-09 20:04 - 2014-11-21 21:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-09 20:04 - 2014-11-21 21:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-09 20:04 - 2014-11-21 21:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-09 20:04 - 2014-11-21 21:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-09 20:04 - 2014-11-21 20:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-09 20:04 - 2014-11-21 20:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-09 20:04 - 2014-11-21 20:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-09 20:04 - 2014-11-21 20:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-09 20:04 - 2014-11-21 20:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-09 20:04 - 2014-11-21 20:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-09 20:04 - 2014-11-21 20:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-09 20:04 - 2014-11-21 20:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-09 20:04 - 2014-11-21 20:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-09 20:04 - 2014-11-21 20:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-09 20:04 - 2014-11-21 20:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-09 20:04 - 2014-11-21 20:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-09 20:04 - 2014-11-21 20:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-09 20:04 - 2014-11-21 20:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-09 20:04 - 2014-11-21 20:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-09 20:04 - 2014-11-21 20:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-09 20:04 - 2014-11-21 20:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-09 20:04 - 2014-11-21 20:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-09 20:04 - 2014-11-21 20:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-09 20:04 - 2014-11-21 20:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-09 20:04 - 2014-11-21 20:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-09 20:04 - 2014-11-21 20:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-09 20:04 - 2014-11-21 20:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-09 20:04 - 2014-11-21 19:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-09 20:04 - 2014-11-21 19:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-09 19:32 - 2014-12-03 21:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-09 19:32 - 2014-12-03 21:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-09 19:32 - 2014-12-03 21:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-09 19:32 - 2014-12-03 21:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-09 19:32 - 2014-12-03 21:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-09 19:32 - 2014-12-03 21:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-09 19:32 - 2014-12-03 21:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-09 19:32 - 2014-12-01 18:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-09 19:30 - 2014-11-10 22:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-09 19:30 - 2014-11-10 21:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-09 19:30 - 2014-11-10 20:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-09 19:29 - 2014-11-07 22:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-09 19:29 - 2014-11-07 21:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-09 19:29 - 2014-10-29 21:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-09 19:29 - 2014-10-29 20:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-09 19:29 - 2014-10-02 21:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-09 19:29 - 2014-10-02 21:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-09 19:29 - 2014-10-02 21:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-09 19:29 - 2014-10-02 21:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-09 19:29 - 2014-10-02 21:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-09 19:29 - 2014-10-02 20:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-09 19:29 - 2014-10-02 20:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-09 19:29 - 2014-10-02 20:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-09 19:29 - 2014-10-02 20:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-09 19:29 - 2014-10-02 20:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-09 00:29 - 2014-12-09 00:29 - 00000000 ____D () C:\Users\Scott\AppData\Roaming\EncryptStick
2014-12-08 12:20 - 2014-12-08 12:20 - 00212313 _____ () C:\Users\Scott\Downloads\ticket (5).mht
2014-12-03 14:54 - 2014-12-03 14:54 - 00220095 _____ () C:\Users\Scott\Downloads\ticket (4).mht
2014-12-03 14:53 - 2014-12-03 14:53 - 00212324 _____ () C:\Users\Scott\Downloads\ticket (3).mht
2014-12-03 09:29 - 2014-12-03 09:29 - 00220097 _____ () C:\Users\Scott\Downloads\ticket (2).mht
2014-12-03 09:27 - 2014-12-03 09:27 - 00220097 _____ () C:\Users\Scott\Downloads\ticket (1).mht
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-21 07:26 - 2014-09-25 13:34 - 00000000 ____D () C:\Scott's Files
2014-12-21 07:07 - 2014-09-25 13:15 - 00000000 ____D () C:\Users\Scott\AppData\Local\VirtualStore
2014-12-21 06:47 - 2009-07-13 23:45 - 00028352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-21 06:47 - 2009-07-13 23:45 - 00028352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-21 06:46 - 2014-06-03 18:03 - 00000000 ____D () C:\Program Files (x86)\Dell Backup and Recovery
2014-12-21 06:43 - 2014-06-04 08:42 - 01839317 _____ () C:\Windows\WindowsUpdate.log
2014-12-21 06:42 - 2014-09-29 21:08 - 00000000 ____D () C:\Users\Scott\AppData\Local\SlimWare Utilities Inc
2014-12-21 06:42 - 2014-09-29 21:08 - 00000000 ____D () C:\Users\Public\Documents\Downloaded Installers
2014-12-21 06:40 - 2014-06-03 18:09 - 00006464 _____ () C:\Windows\SysWOW64\Gms.log
2014-12-21 06:38 - 2014-09-25 15:27 - 00024974 _____ () C:\ProgramData\dleascan.log
2014-12-21 06:38 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-21 06:36 - 2014-06-04 08:42 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-12-21 06:36 - 2009-07-13 23:51 - 00073213 _____ () C:\Windows\setupact.log
2014-12-20 16:55 - 2014-09-29 21:05 - 00000000 ____D () C:\Users\Scott\AppData\Local\CrashDumps
2014-12-20 16:47 - 2014-09-25 14:57 - 00000000 ____D () C:\ProgramData\Norton
2014-12-20 16:11 - 2009-07-14 00:13 - 00783606 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-20 15:58 - 2014-09-29 21:13 - 00000000 ____D () C:\Users\Scott\AppData\Local\NVIDIA
2014-12-20 15:58 - 2014-09-29 21:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-12-20 15:58 - 2014-06-04 08:42 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-12-20 15:58 - 2014-06-04 08:42 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-12-20 15:58 - 2014-06-04 08:42 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-12-20 15:57 - 2014-09-29 21:13 - 00000000 ____D () C:\Users\Scott\AppData\Local\NVIDIA Corporation
2014-12-20 15:35 - 2010-11-20 22:47 - 00174074 _____ () C:\Windows\PFRO.log
2014-12-20 15:33 - 2014-06-03 18:03 - 00000000 ____D () C:\ProgramData\Adobe
2014-12-20 13:32 - 2014-09-25 15:33 - 00000000 ____D () C:\ProgramData\Dl_cats
2014-12-20 13:29 - 2014-09-25 15:44 - 00037460 _____ () C:\ProgramData\dleaJSW.log
2014-12-20 11:34 - 2014-09-25 13:21 - 00003440 _____ () C:\Windows\System32\Tasks\PCDEventLauncherTask
2014-12-19 14:04 - 2014-09-25 14:50 - 00000000 ____D () C:\Users\Scott\AppData\Local\Adobe
2014-12-17 14:37 - 2014-09-25 16:04 - 00000000 ____D () C:\Users\Scott\AppData\Roaming\mIRC
2014-12-12 21:48 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
2014-12-09 20:50 - 2014-09-25 17:02 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-09 20:50 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-09 20:50 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-09 20:08 - 2014-09-25 14:16 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-09 20:07 - 2014-09-25 16:37 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-09 20:06 - 2014-09-25 16:37 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-04 01:12 - 2014-09-25 13:16 - 00000000 ____D () C:\Users\Scott\Documents\Bluetooth Folder
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-15 14:56
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-12-2014 01
Ran by [removed] at 2014-12-21 07:26:30
Running from C:\Scott's Files
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Emsisoft Anti-Malware (Enabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Norton Internet Security (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton Internet Security (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
FW: Norton Internet Security (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Accidental Damage Services Agreement (HKLM-x32\…\{EF85FEF4-EB92-4075-A6D2-5F519BB30A2C}) (Version: 2.0.0 - Dell Inc.)
Apple Application Support (HKLM-x32\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Bluetooth Suite (64) (HKLM\…\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.170 - Atheros)
Banctec Service Agreement (HKLM-x32\…\{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}) (Version: 2.0.0 - Dell Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Complete Care Business Service Agreement (HKLM-x32\…\{0ECFCB07-9BFE-4970-ACA1-D568D982760B}) (Version: 2.0.0 - Dell Inc.)
Consumer In-Home Service Agreement (HKLM-x32\…\{F47C37A4-7189-430A-B81D-739FF8A7A554}) (Version: 2.0.0 - Dell Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Backup and Recovery - Support Software (HKLM-x32\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 1.6.2.0 - Dell Inc.)
Dell Backup and Recovery (HKLM-x32\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.6.2.0 - Dell Inc.)
Dell Digital Delivery (HKLM-x32\…\{D850CB7E-72BC-4510-BA4F-48932BFAB295}) (Version: 2.9.901.0 - Dell Products, LP)
Dell Edoc Viewer (HKLM\…\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Home Systems Service Agreement (HKLM-x32\…\{AB2FDE4F-6BED-4E9E-B676-3DCCEBB1FBFE}) (Version: 2.0.0 - Dell Inc.)
Dell Toolbar (HKLM-x32\…\{09B71986-2AC5-482d-B6CB-42EA34F4F85B}) (Version: 1.8.12.0 - )
Dell V310-V510 Series (HKLM\…\Dell V310-V510 Series) (Version: - Dell, Inc.)
Dell WLAN and Bluetooth Client Installation (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Dell Inc.)
DSC/AA Factory Installer (Version: 3.5.6426.22 - PC-Doctor, Inc.) Hidden
Emsisoft Anti-Malware (HKLM-x32\…\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 9.0 - Emsisoft Ltd)
Intel(R) Chipset Device Software (x32 Version: 10.0.13 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.0.1168 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.2.1001 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\…\{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}) (Version: 2.3.1338 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
iTunes (HKLM\…\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (HKLM-x32\…\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
mIRC (HKLM-x32\…\mIRC) (Version: 7.36 - mIRC Co. Ltd.)
My Dell (HKLM\…\PC-Doctor for Windows) (Version: 3.5.6426.22 - PC-Doctor, Inc.)
Norton Internet Security (HKLM-x32\…\NIS) (Version: 21.6.0.32 - Symantec Corporation)
NVIDIA 3D Vision Controller Driver 344.75 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.75 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 344.75 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.75 - NVIDIA Corporation)
NVIDIA Graphics Driver 344.75 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.75 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.32.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.14.0702 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
Premium Service Agreement (HKLM-x32\…\{C33AA6D6-F5EC-48F3-AFDC-8141345D473A}) (Version: 2.0.0 - Dell Inc.)
QualxServ Service Agreement (HKLM-x32\…\{903679E8-44C8-4C07-9600-05C92654FC50}) (Version: 2.0.0 - Dell Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6909 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.2.8400.30137 - Realtek Semiconductor Corp.)
Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1168 - SUPERAntiSpyware.com)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2748532688-3923759273-2942247134-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> No File Path
==================== Restore Points =========================
Check "winmgmt" service or repair WMI.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {01E64E36-2B1A-475F-B8F0-04158802D60A} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2014-01-10] (PC-Doctor, Inc.)
Task: {02AFBB49-2F20-4CD8-AC5D-AFFF9307FA25} - System32\Tasks\SUPERAntiSpyware Scheduled Task 008704f4-0625-4f5f-89b3-9b3e4c9b748e => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {2E301596-6331-4AA3-853B-063ADB7B248B} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {33CBFEAA-6928-4DF7-BFB2-9C9DA88AE4B5} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {38720960-E703-4D2C-9FB6-8B00FB0543F4} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {4E1DBC5C-ABE2-473D-9D8A-7205481B1EFB} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {4EF5214E-F89E-484F-9F0C-E06E7637D814} - System32\Tasks\SUPERAntiSpyware Scheduled Task 38877689-3997-4fc9-b6d4-0e336e85b125 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {5DAD844B-6DCF-4851-A50B-E1E2015F3A1C} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2014-01-10] (PC-Doctor, Inc.)
Task: {A5E71851-7AE6-4B83-850C-AA4D4964E3A1} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {B710FDF1-638F-4656-BF30-D5A5976E8EDF} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {EEA8AF0B-6BB7-4EC6-A338-2280AF553B54} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation)
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 008704f4-0625-4f5f-89b3-9b3e4c9b748e.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 38877689-3997-4fc9-b6d4-0e336e85b125.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
==================== Loaded Modules (whitelisted) =============
2014-06-04 08:42 - 2014-11-12 16:56 - 00118080 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-06-03 18:03 - 2013-08-18 20:21 - 00020256 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIcon.dll
2014-06-03 18:03 - 2013-08-18 20:21 - 00019232 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayNotBackuped.dll
2014-09-25 15:27 - 2009-12-31 01:17 - 00053760 _____ () C:\Windows\System32\DLEAPMON.DLL
2014-09-25 15:27 - 2009-01-13 08:15 - 05709824 _____ () C:\Windows\System32\DLEAOEM.DLL
2014-09-25 15:28 - 2009-11-04 08:17 - 00189440 _____ () C:\Windows\system32\spool\PRTPROCS\x64\dleadrpp.dll
2014-09-25 15:26 - 2011-01-23 20:22 - 00770728 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe
2014-09-25 15:26 - 2011-01-23 20:22 - 00139944 _____ () C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe
2014-06-03 18:03 - 2013-11-21 04:22 - 00484880 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe
2014-07-31 11:16 - 2014-07-31 11:16 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-09-25 15:25 - 2009-11-26 03:49 - 00086180 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleacfg.dll
2014-09-25 15:26 - 2010-04-01 12:23 - 00389120 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleascw.dll
2014-09-25 15:26 - 2009-05-27 07:16 - 00192512 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleadatr.dll
2014-09-25 15:26 - 2010-04-01 12:24 - 01159168 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleaDRS.dll
2014-09-25 15:26 - 2009-03-10 00:43 - 00155648 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleacaps.dll
2014-09-25 15:26 - 2009-03-05 12:55 - 00059904 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleacnv4.dll
2014-09-25 15:23 - 2009-02-20 03:50 - 00381440 _____ () C:\Windows\system32\dleasm.dll
2014-09-25 15:23 - 2009-02-20 03:50 - 00028672 _____ () C:\Windows\system32\dleasmr.dll
2014-09-25 15:26 - 2009-06-22 08:08 - 00708608 _____ () C:\Program Files (x86)\Dell V310-V510 Series\Epwizard.DLL
2014-09-25 15:26 - 2009-06-22 08:06 - 00159744 _____ () C:\Program Files (x86)\Dell V310-V510 Series\customui.dll
2014-09-25 15:26 - 2009-06-22 08:06 - 00114688 _____ () C:\Program Files (x86)\Dell V310-V510 Series\Eputil.DLL
2014-09-25 15:26 - 2009-06-22 08:05 - 00139264 _____ () C:\Program Files (x86)\Dell V310-V510 Series\Imagutil.DLL
2014-09-25 15:26 - 2009-06-22 08:06 - 00061440 _____ () C:\Program Files (x86)\Dell V310-V510 Series\Epfunct.DLL
2014-09-25 15:26 - 2009-06-22 08:08 - 02203648 _____ () C:\Program Files (x86)\Dell V310-V510 Series\EPWizRes.dll
2014-09-25 15:26 - 2009-06-22 08:08 - 00045056 _____ () C:\Program Files (x86)\Dell V310-V510 Series\epstring.dll
2014-09-25 15:26 - 2009-06-22 08:08 - 00196608 _____ () C:\Program Files (x86)\Dell V310-V510 Series\EPOEMDll.dll
2014-09-25 15:26 - 2009-04-07 14:25 - 00409600 _____ () C:\Program Files (x86)\Dell V310-V510 Series\iptk.dll
2014-09-25 15:26 - 2009-03-02 09:25 - 00151552 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleaptp.dll
2014-02-19 05:51 - 2014-02-19 05:51 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-06-03 18:03 - 2013-11-21 02:00 - 01904928 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\STRestoreAPI.dll
2014-06-03 18:03 - 2012-11-25 09:20 - 01153384 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\libxml2.dll
2014-06-03 18:03 - 2012-11-25 09:20 - 00117608 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\zlib1.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-2748532688-3923759273-2942247134-500 - Administrator - Disabled)
Guest (S-1-5-21-2748532688-3923759273-2942247134-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2748532688-3923759273-2942247134-1003 - Limited - Enabled)
Scott (S-1-5-21-2748532688-3923759273-2942247134-1000 - Administrator - Enabled) => C:\Users\Scott
==================== Faulty Device Manager Devices =============
Could not list Devices. Check "winmgmt" service or repair WMI.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/21/2014 06:38:14 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/21/2014 06:34:19 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/21/2014 06:20:28 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/20/2014 05:10:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/20/2014 05:05:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/20/2014 04:55:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17496, time stamp: 0x4a5bc96f
Faulting module name: MSHTML.dll, version: 11.0.9600.17496, time stamp: 0x546ff2f9
Exception code: 0xc00000fd
Fault offset: 0x001202bc
Faulting process id: 0x25b4
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
Error: (12/20/2014 03:58:08 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [0]
Error: (12/20/2014 03:48:47 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/20/2014 03:48:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BtvStack.exe, version: 7.4.0.170, time stamp: 0x50dc4cb3
Faulting module name: BtvStack.exe, version: 7.4.0.170, time stamp: 0x50dc4cb3
Exception code: 0xc0000005
Fault offset: 0x000000000007e1a8
Faulting process id: 0xf34
Faulting application start time: 0xBtvStack.exe0
Faulting application path: BtvStack.exe1
Faulting module path: BtvStack.exe2
Report Id: BtvStack.exe3
Error: (12/20/2014 03:36:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (12/21/2014 07:13:48 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/21/2014 07:13:44 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/21/2014 07:13:40 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/21/2014 07:13:37 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/21/2014 07:13:33 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/21/2014 06:45:59 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/21/2014 06:45:55 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/21/2014 06:45:51 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/21/2014 06:45:47 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (12/21/2014 06:45:44 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz
Percentage of memory in use: 34%
Total physical RAM: 8143.23 MB
Available physical RAM: 5305.97 MB
Total Pagefile: 16284.63 MB
Available Pagefile: 13072.43 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:907.25 GB) (Free:815.53 GB) NTFS
Drive y: (RECOVERY) (Fixed) (Total:24.22 GB) (Free:13.49 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 92DC09DE)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=24.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=907.3 GB) - (Type=07 NTFS)
==================== End Of Log ============================