This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

dllhost.exe COM surrogate [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

dllhost.exe COM surrogate making my web life hell AGAIN!!!  about 5 months ago it slowed my computer to a screeching halt, and it has returned, not as drastic as the previous infection but getting there rapidly.  Please help, on top of that, I made a purchase through ebay using paypal, and I am afraid my accounts may have been compromised…I changed my passwords this morning, but I am paranoid that too may have been compromised. 

 

I am prepared to follow your instruction diligently, thank you.

 

J.

:welcome:

 

 
[external image: 1QYkxTZ.jpg] Please download aswMBR to your desktop.
 
  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
  •  
    I just want to see the report….Please Do Not Fix Anything
     
    ============================================================================
     
     
     
     
    Please download Farbar Recovery Scan Tool and save it to your desktop.
     
    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
     
    How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
    A simple way to check your system: Start –> Computer (right click) –> Properties
     
    [external image: FRST_zps5d956a1a.jpg]
     
     
    • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
    • Please make sure All Users is checked
    • Just keep the defaults as in the picture checkmarked
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
    • Thank you, as per your instructions:

       

       aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
      Run date: 2015-04-01 10:05:45
      —————————–
      10:05:45.615    OS Version: Windows x64 6.1.7601 Service Pack 1
      10:05:45.615    Number of processors: 4 586 0x503
      10:05:45.616    ComputerName: ORTIZFAMILY-HP  UserName: Ortiz Family
      10:05:48.848    Initialize success
      10:05:48.867    VM: initialized successfully
      10:05:48.868    VM: Amd CPU BiosDisabled
      10:08:00.339    AVAST engine defs: 15040100
      10:31:04.885    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006a
      10:31:04.891    Disk 0 Vendor: ST310005 HP35 Size: 953869MB BusType: 11
      10:31:04.987    Disk 0 MBR read successfully
      10:31:04.994    Disk 0 MBR scan
      10:31:05.117    Disk 0 unknown MBR code
      10:31:05.126    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
      10:31:05.129    Disk 0 default boot code
      10:31:05.155    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       940546 MB offset 206848
      10:31:05.208    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS        13221 MB offset 1926445056
      10:31:05.365    Disk 0 scanning C:\Windows\system32\drivers
      10:31:26.967    Service scanning
      10:32:08.626    Modules scanning
      10:32:08.651    Disk 0 trace - called modules:
      10:32:08.705    ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
      10:32:08.717    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8003aaa790]
      10:32:08.731    3 CLASSPNP.SYS[fffff880018df43f] -> nt!IofCallDriver -> [0xfffffa80039edac0]
      10:32:08.740    5 amd_xata.sys[fffff88000e958b4] -> nt!IofCallDriver -> \Device\0000006a[0xfffffa80039e89c0]
      10:32:14.396    AVAST engine scan C:\Windows
      10:32:23.757    AVAST engine scan C:\Windows\system32
      10:38:22.950    AVAST engine scan C:\Windows\system32\drivers
      10:39:54.201    AVAST engine scan C:\Users\Ortiz Family
      11:24:42.043    AVAST engine scan C:\ProgramData
      11:31:48.877    Disk 0 statistics 4946772/0/0 @ 1.13 MB/s
      11:31:48.878    Scan finished successfully
      12:01:07.353    Disk 0 MBR has been saved successfully to "C:\Users\Ortiz Family\Desktop\MBR.dat"
      12:01:07.409    The log file has been saved successfully to "C:\Users\Ortiz Family\Desktop\aswMBR.txt"

       

       

       

       

      Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
      Ran by [removed] (administrator) on ORTIZFAMILY-HP on 01-04-2015 12:17:57
      Running from C:\Users\[removed]\Desktop
      [removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
      Internet Explorer Version 11 (Default browser: Chrome)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

      ==================== Processes (Whitelisted) =================

      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
      (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
      (Microsoft Corporation) C:\Windows\System32\wlanext.exe
      (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe
      (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe
      (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
      (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
      (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe
      (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
      (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
      (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
      (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
      (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
      (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
      (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
      (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe
      (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
      (Microsoft Corporation) C:\Windows\System32\dllhost.exe
      (Microsoft Corporation) C:\Windows\splwow64.exe
      (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE
      (Microsoft Corporation) C:\Windows\System32\taskmgr.exe
      (Microsoft Corporation) C:\Windows\System32\dllhost.exe
      (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
      (Microsoft Corporation) C:\Windows\System32\printfilterpipelinesvc.exe
      (Microsoft Corporation) C:\Windows\System32\rundll32.exe
      (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
      (Eyeo GmbH) C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe
      (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe

      ==================== Registry (Whitelisted) ==================

      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

      HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
      HKLM-x32\…\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [37624 2014-10-16] (Panda Security, S.L.)
      Winlogon\Notify\!SABWinLogon-x32: C:\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL (SuperAdBlocker.com)

      ==================== Internet (Whitelisted) ====================

      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

      ProxyServer: [S-1-5-21-4195524230-986017159-2191004378-1000] => 127.0.0.1:80
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
      HKU\S-1-5-21-4195524230-986017159-2191004378-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
      HKU\S-1-5-21-4195524230-986017159-2191004378-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
      SearchScopes: HKLM -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = http://rover.ebay.com/rover/1/711-111092-2357-0/4?satitle={searchTerms}&mfe;=Desktops
      SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://www.bing.com/search?q={searchTerms}&form;=HPDTDF&pc;=HPDTDF&src;=IE-SearchBox
      SearchScopes: HKLM-x32 -> Backup.Old.DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
      SearchScopes: HKLM-x32 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = http://rover.ebay.com/rover/1/711-111092-2357-0/4?satitle={searchTerms}&mfe;=Desktops
      SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://www.bing.com/search?q={searchTerms}&form;=HPDTDF&pc;=HPDTDF&src;=IE-SearchBox
      SearchScopes: HKU\S-1-5-21-4195524230-986017159-2191004378-1000 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = https://www.google.com/search?q={searchTerms}
      SearchScopes: HKU\S-1-5-21-4195524230-986017159-2191004378-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = https://www.google.com/search?q={searchTerms}
      BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
      BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
      BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
      BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
      BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
      BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25] (Eyeo GmbH)
      BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
      BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
      BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
      BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
      BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH)
      Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
      Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
      Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
      Toolbar: HKU\S-1-5-21-4195524230-986017159-2191004378-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-03] (Google Inc.)
      DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
      DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
      DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
      DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
      DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.webex.com/client/WBXclient-T27L10NSP32EP5-14362/webex/ieatgpc1.cab
      ShellExecuteHooks-x32:  - {5AE067D3-9AFB-48E0-853A-EBB7F4A000D7} -  No File [ ]
      Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

      FireFox:
      ========
      FF Plugin: @microsoft.com/GENUINE -> disabled No File
      FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
      FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
      FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll [2014-06-24] (Adobe Systems, Inc.)
      FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
      FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
      FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
      FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
      FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
      FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
      FF Plugin HKU\S-1-5-21-4195524230-986017159-2191004378-1000: @hulu.com/Hulu Desktop -> C:\Windows\..\Users\Default\AppData\Local\HuluDesktop\instances\0.9.13.1\npHDPlg.dll [2010-04-09] (Hulu LLC)
      FF Plugin HKU\S-1-5-21-4195524230-986017159-2191004378-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Ortiz Family\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-02-20] (Unity Technologies ApS)

      Chrome:
      =======
      CHR HomePage: Default -> hxxp://www.msn.com/?pc=U142&ocid;=U142DHP
      CHR StartupUrls: Default -> "hxxp://www.msn.com/?pc=U142&ocid;=U142DHP"
      CHR Profile: C:\Users\Ortiz Family\AppData\Local\Google\Chrome\User Data\Default
      CHR Extension: (Google Wallet) - C:\Users\Ortiz Family\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-17]

      ==================== Services (Whitelisted) =================

      (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

      S4 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-01-14] (Adobe Systems) [File not signed]
      S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2011-10-13] (Advanced Micro Devices, Inc.) [File not signed]
      R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
      S4 LightScribeService; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-11-22] (Hewlett-Packard Company) [File not signed]
      S4 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe [237008 2011-06-17] (McAfee, Inc.)
      S4 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [214896 2012-02-06] ()
      R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
      R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [142072 2014-10-13] (Panda Security, S.L.)
      R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
      R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [66808 2014-10-09] (Panda Security, S.L.)
      S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2010-09-16] () [File not signed]
      S4 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1119768 2010-09-28] (PDF Complete Inc)
      R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [38136 2014-10-16] (Panda Security, S.L.)
      S4 RalinkRegistryWriter; C:\Program Files (x86)\Ralink\Common\RaRegistry.exe [372736 2012-01-12] (Ralink Technology, Corp.) [File not signed]
      S4 RalinkRegistryWriter64; C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe [447488 2012-01-12] (Ralink Technology, Corp.) [File not signed]
      S4 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [625728 2011-08-18] ()
      S4 SABSVC; C:\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE [65536 2005-08-31] (SuperAdBlocker.com) [File not signed]
      S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
      S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)

      ==================== Drivers (Whitelisted) ====================

      (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

      S3 ALESIS_USB2; C:\Windows\System32\Drivers\alesis2u.sys [399424 2010-04-22] (Ploytec GmbH)
      S3 ALESIS_USB2_A; C:\Windows\System32\drivers\alesis2a.sys [50240 2010-04-22] (Numark)
      S3 AODDriver4.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55424 2011-06-24] (Advanced Micro Devices)
      U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
      R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
      R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
      R1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [96800 2014-06-04] (Panda Security, S.L.)
      R1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [162336 2014-06-18] (Panda Security, S.L.)
      R1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [112160 2014-06-04] (Panda Security, S.L.)
      R1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [115232 2014-06-04] (Panda Security, S.L.)
      R1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [46336 2014-01-16] (Panda Security, S.L.)
      R1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [95776 2014-06-04] (Panda Security, S.L.)
      R1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [70176 2014-06-04] (Panda Security, S.L.)
      R1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [125984 2014-06-04] (Panda Security, S.L.)
      R1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [306720 2014-06-04] (Panda Security, S.L.)
      R1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [169504 2014-06-04] (Panda Security, S.L.)
      R1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [115744 2014-06-04] (Panda Security, S.L.)
      R1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [261152 2014-06-04] (Panda Security, S.L.)
      R1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [109088 2014-06-04] (Panda Security, S.L.)
      R2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [163088 2014-10-13] (Panda Security, S.L.)
      R2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [121616 2014-10-13] (Panda Security, S.L.)
      R1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [195616 2014-07-24] (Panda Security, S.L.)
      R2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [122400 2014-07-24] (Panda Security, S.L.)
      R2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [132128 2014-07-24] (Panda Security, S.L.)
      R2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [107792 2014-10-13] (Panda Security, S.L.)
      R3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [60400 2014-03-25] (Panda Security, S.L.)
      S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
      S1 SABDIFSV; C:\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SABDIFSV.SYS [5632 2005-09-21] () [File not signed]
      S1 SABKUTIL; C:\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys [32256 2007-02-20] () [File not signed]
      S3 SABProcEnum; C:\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SABProcEnum.sys [4096 2005-03-21] (SuperAdBlocker.com) [File not signed]
      S3 SynasUSB; C:\Windows\System32\drivers\SynUSB64.sys [31248 2006-11-16] (SIA Syncrosoft)
      R3 US122; C:\Windows\System32\Drivers\US122x64.sys [200320 2007-08-29] (Frontier Design Group, LLC)
      S3 US122DL; C:\Windows\System32\Drivers\US122DLx64.sys [20224 2007-08-29] (Frontier Design Group)
      R3 US122WdmService; C:\Windows\System32\Drivers\US122Wdmx64.sys [62976 2007-08-29] (Frontier Design Group, LLC)
      S3 catchme; \??\C:\ComboFix\catchme.sys [X]
      U3 aswMBR; \??\C:\Users\ORTIZF~1\AppData\Local\Temp\aswMBR.sys [X]
      U3 aswVmm; \??\C:\Users\ORTIZF~1\AppData\Local\Temp\aswVmm.sys [X]

      ==================== NetSvcs (Whitelisted) ===================

      (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

      ==================== One Month Created Files and Folders ========

      (If an entry is included in the fixlist, the file\folder will be moved.)

      2015-04-01 12:17 - 2015-04-01 12:18 - 00018983 _____ () C:\Users\Ortiz Family\Desktop\FRST.txt
      2015-04-01 12:15 - 2015-04-01 12:18 - 00000000 ____D () C:\FRST
      2015-04-01 12:14 - 2015-04-01 12:14 - 02095616 _____ (Farbar) C:\Users\Ortiz Family\Desktop\FRST64.exe
      2015-04-01 12:01 - 2015-04-01 12:01 - 00002212 _____ () C:\Users\Ortiz Family\Desktop\aswMBR.txt
      2015-04-01 12:01 - 2015-04-01 12:01 - 00000512 _____ () C:\Users\Ortiz Family\Desktop\MBR.dat
      2015-04-01 10:04 - 2015-04-01 10:04 - 05198336 _____ (AVAST Software) C:\Users\Ortiz Family\Desktop\aswMBR.exe
      2015-03-26 17:28 - 2015-03-29 11:33 - 00492544 _____ () C:\Users\Ortiz Family\Desktop\BMB.ppt
      2015-03-26 17:26 - 2015-03-26 17:26 - 00000000 ____D () C:\Users\Ortiz Family\Documents\DVD Photo Slideshow
      2015-03-26 17:26 - 2015-03-26 17:26 - 00000000 ____D () C:\ProgramData\Socusoft
      2015-03-26 17:20 - 2015-03-26 17:20 - 00001222 _____ () C:\Users\Public\Desktop\DVD Photo Slideshow Professional.lnk
      2015-03-26 17:20 - 2015-03-26 17:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Photo Slideshow Professional
      2015-03-26 17:20 - 2013-05-31 09:00 - 00024064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll
      2015-03-26 17:19 - 2015-03-26 17:20 - 00000000 ____D () C:\Program Files (x86)\DVD Photo Slideshow Professional
      2015-03-26 17:19 - 2015-03-26 17:19 - 00000000 ____D () C:\Program Files (x86)\Socusoft
      2015-03-11 20:38 - 2015-03-11 20:38 - 00002214 _____ () C:\Users\Public\Desktop\Google Earth.lnk
      2015-03-11 20:38 - 2015-03-11 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
      2015-03-11 02:15 - 2015-02-19 22:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
      2015-03-11 02:15 - 2015-02-19 22:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
      2015-03-11 02:15 - 2015-02-19 22:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
      2015-03-11 02:15 - 2015-02-19 22:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
      2015-03-11 02:15 - 2015-02-19 22:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
      2015-03-11 02:15 - 2015-02-19 22:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
      2015-03-11 02:15 - 2015-02-19 22:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
      2015-03-11 02:15 - 2015-02-19 22:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
      2015-03-11 02:15 - 2015-02-19 21:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
      2015-03-11 02:15 - 2015-02-19 21:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
      2015-03-11 02:15 - 2015-02-02 21:34 - 05554104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
      2015-03-11 02:15 - 2015-02-02 21:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
      2015-03-11 02:15 - 2015-02-02 21:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
      2015-03-11 02:15 - 2015-02-02 21:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
      2015-03-11 02:15 - 2015-02-02 21:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
      2015-03-11 02:15 - 2015-02-02 21:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
      2015-03-11 02:15 - 2015-02-02 21:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
      2015-03-11 02:15 - 2015-02-02 21:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
      2015-03-11 02:15 - 2015-02-02 21:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
      2015-03-11 02:15 - 2015-02-02 21:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
      2015-03-11 02:15 - 2015-02-02 21:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
      2015-03-11 02:15 - 2015-02-02 21:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
      2015-03-11 02:15 - 2015-02-02 21:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
      2015-03-11 02:15 - 2015-02-02 21:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
      2015-03-11 02:15 - 2015-02-02 21:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
      2015-03-11 02:15 - 2015-02-02 21:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
      2015-03-11 02:15 - 2015-02-02 21:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
      2015-03-11 02:15 - 2015-02-02 21:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
      2015-03-11 02:15 - 2015-02-02 21:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
      2015-03-11 02:15 - 2015-02-02 21:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
      2015-03-11 02:15 - 2015-02-02 21:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
      2015-03-11 02:15 - 2015-02-02 21:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
      2015-03-11 02:15 - 2015-02-02 21:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
      2015-03-11 02:15 - 2015-02-02 21:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
      2015-03-11 02:15 - 2015-02-02 21:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
      2015-03-11 02:15 - 2015-02-02 21:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
      2015-03-11 02:15 - 2015-02-02 21:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
      2015-03-11 02:15 - 2014-10-31 16:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
      2015-03-11 02:14 - 2015-02-02 21:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
      2015-03-11 02:14 - 2015-02-02 21:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
      2015-03-11 02:14 - 2015-02-02 21:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
      2015-03-11 02:14 - 2015-02-02 21:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
      2015-03-11 02:14 - 2015-02-02 21:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
      2015-03-11 02:14 - 2015-02-02 21:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
      2015-03-11 02:14 - 2015-02-02 21:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
      2015-03-11 02:14 - 2015-02-02 21:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
      2015-03-11 02:14 - 2015-02-02 21:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
      2015-03-11 02:14 - 2015-02-02 21:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
      2015-03-11 02:14 - 2015-02-02 21:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
      2015-03-11 02:14 - 2015-02-02 21:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
      2015-03-11 02:14 - 2015-02-02 21:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
      2015-03-11 02:14 - 2015-02-02 21:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
      2015-03-11 02:14 - 2015-02-02 21:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
      2015-03-11 02:14 - 2015-02-02 21:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
      2015-03-11 02:14 - 2015-02-02 21:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
      2015-03-11 02:14 - 2015-02-02 21:30 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
      2015-03-11 02:14 - 2015-02-02 21:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
      2015-03-11 02:14 - 2015-02-02 21:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
      2015-03-11 02:14 - 2015-02-02 21:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
      2015-03-11 02:14 - 2015-02-02 21:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
      2015-03-11 02:14 - 2015-02-02 21:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
      2015-03-11 02:14 - 2015-02-02 21:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
      2015-03-11 02:14 - 2015-02-02 21:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
      2015-03-11 02:14 - 2015-02-02 21:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
      2015-03-11 02:14 - 2015-02-02 21:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
      2015-03-11 02:14 - 2015-02-02 21:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
      2015-03-11 02:14 - 2015-02-02 21:28 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
      2015-03-11 02:14 - 2015-02-02 21:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
      2015-03-11 02:14 - 2015-02-02 21:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
      2015-03-11 02:14 - 2015-02-02 21:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
      2015-03-11 02:14 - 2015-02-02 21:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
      2015-03-11 02:14 - 2015-02-02 21:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
      2015-03-11 02:14 - 2015-02-02 21:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
      2015-03-11 02:14 - 2015-02-02 21:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
      2015-03-11 02:14 - 2015-02-02 21:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
      2015-03-11 02:14 - 2015-02-02 21:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
      2015-03-11 02:14 - 2015-02-02 21:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
      2015-03-11 02:14 - 2015-02-02 21:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
      2015-03-11 02:14 - 2015-02-02 21:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
      2015-03-11 02:14 - 2015-02-02 21:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
      2015-03-11 02:14 - 2015-02-02 21:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
      2015-03-11 02:14 - 2015-02-02 21:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
      2015-03-11 02:14 - 2015-02-02 21:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
      2015-03-11 02:14 - 2015-02-02 21:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
      2015-03-11 02:14 - 2015-02-02 21:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
      2015-03-11 02:14 - 2015-02-02 20:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
      2015-03-11 02:13 - 2015-03-05 23:56 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
      2015-03-11 02:13 - 2015-03-05 23:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
      2015-03-11 02:13 - 2015-03-05 23:42 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
      2015-03-11 02:13 - 2015-03-05 23:42 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
      2015-03-11 02:13 - 2015-03-05 23:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
      2015-03-11 02:13 - 2015-03-05 23:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
      2015-03-11 02:13 - 2015-03-05 23:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
      2015-03-11 02:13 - 2015-03-05 23:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
      2015-03-11 02:13 - 2015-03-05 23:42 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
      2015-03-11 02:13 - 2015-03-05 23:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
      2015-03-11 02:13 - 2015-03-05 23:42 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
      2015-03-11 02:13 - 2015-03-05 23:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
      2015-03-11 02:13 - 2015-03-05 23:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
      2015-03-11 02:13 - 2015-03-05 23:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
      2015-03-11 02:13 - 2015-03-05 23:41 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
      2015-03-11 02:13 - 2015-03-05 23:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
      2015-03-11 02:13 - 2015-03-05 23:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
      2015-03-11 02:13 - 2015-03-05 23:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
      2015-03-11 02:13 - 2015-03-05 23:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
      2015-03-11 02:13 - 2015-03-05 23:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
      2015-03-11 02:13 - 2015-03-05 23:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
      2015-03-11 02:13 - 2015-03-05 23:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
      2015-03-11 02:13 - 2015-03-05 23:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
      2015-03-11 02:13 - 2015-03-05 23:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
      2015-03-11 02:13 - 2015-03-05 23:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
      2015-03-11 02:13 - 2015-03-05 23:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
      2015-03-11 02:13 - 2015-03-05 23:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
      2015-03-11 02:13 - 2015-03-05 23:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
      2015-03-11 02:13 - 2015-03-05 23:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
      2015-03-11 02:13 - 2015-03-05 23:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
      2015-03-11 02:13 - 2015-03-05 23:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
      2015-03-11 02:13 - 2015-02-12 23:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
      2015-03-11 02:13 - 2015-02-12 23:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
      2015-03-11 02:13 - 2015-02-02 21:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
      2015-03-11 02:13 - 2015-02-02 21:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
      2015-03-11 02:13 - 2015-01-30 17:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
      2015-03-11 02:12 - 2015-02-25 21:25 - 03204096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
      2015-03-11 02:12 - 2015-02-23 21:15 - 00389800 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
      2015-03-11 02:12 - 2015-02-23 20:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
      2015-03-11 02:12 - 2015-02-20 19:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
      2015-03-11 02:12 - 2015-02-20 18:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
      2015-03-11 02:12 - 2015-02-20 18:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
      2015-03-11 02:12 - 2015-02-20 18:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
      2015-03-11 02:12 - 2015-02-20 18:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
      2015-03-11 02:12 - 2015-02-20 17:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
      2015-03-11 02:12 - 2015-02-20 17:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
      2015-03-11 02:12 - 2015-02-19 21:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
      2015-03-11 02:12 - 2015-02-19 21:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
      2015-03-11 02:12 - 2015-02-19 20:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
      2015-03-11 02:12 - 2015-02-19 20:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
      2015-03-11 02:12 - 2015-02-19 20:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
      2015-03-11 02:12 - 2015-02-19 20:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
      2015-03-11 02:12 - 2015-02-19 20:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
      2015-03-11 02:12 - 2015-02-19 20:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
      2015-03-11 02:12 - 2015-02-19 20:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
      2015-03-11 02:12 - 2015-02-19 20:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
      2015-03-11 02:12 - 2015-02-19 20:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
      2015-03-11 02:12 - 2015-02-19 20:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
      2015-03-11 02:12 - 2015-02-19 20:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
      2015-03-11 02:12 - 2015-02-19 20:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
      2015-03-11 02:12 - 2015-02-19 20:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
      2015-03-11 02:12 - 2015-02-19 20:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
      2015-03-11 02:12 - 2015-02-19 20:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
      2015-03-11 02:12 - 2015-02-19 20:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
      2015-03-11 02:12 - 2015-02-19 20:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
      2015-03-11 02:12 - 2015-02-19 20:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
      2015-03-11 02:12 - 2015-02-19 20:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
      2015-03-11 02:12 - 2015-02-19 20:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
      2015-03-11 02:12 - 2015-02-19 20:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
      2015-03-11 02:12 - 2015-02-19 20:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
      2015-03-11 02:12 - 2015-02-19 20:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
      2015-03-11 02:12 - 2015-02-19 20:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
      2015-03-11 02:12 - 2015-02-19 20:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
      2015-03-11 02:12 - 2015-02-19 19:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
      2015-03-11 02:12 - 2015-02-19 19:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
      2015-03-11 02:12 - 2015-02-19 19:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
      2015-03-11 02:12 - 2015-02-19 19:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
      2015-03-11 02:12 - 2015-02-19 19:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
      2015-03-11 02:12 - 2015-02-19 19:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
      2015-03-11 02:12 - 2015-02-19 19:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
      2015-03-11 02:12 - 2015-02-19 19:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
      2015-03-11 02:12 - 2015-02-19 19:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
      2015-03-11 02:12 - 2015-02-19 19:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
      2015-03-11 02:12 - 2015-02-19 19:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
      2015-03-11 02:12 - 2015-02-19 19:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
      2015-03-11 02:12 - 2015-02-19 19:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
      2015-03-11 02:12 - 2015-02-19 19:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
      2015-03-11 02:12 - 2015-02-19 19:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
      2015-03-11 02:12 - 2015-02-19 19:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
      2015-03-11 02:12 - 2015-02-19 19:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
      2015-03-11 02:12 - 2015-02-19 19:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
      2015-03-11 02:12 - 2015-02-19 18:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
      2015-03-11 02:12 - 2015-02-19 18:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
      2015-03-11 02:12 - 2015-02-02 21:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
      2015-03-11 02:12 - 2015-02-02 21:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
      2015-03-11 02:12 - 2015-01-16 20:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
      2015-03-11 02:12 - 2015-01-16 20:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
      2015-03-11 02:11 - 2015-02-03 21:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
      2015-03-11 02:11 - 2015-02-03 20:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
      2015-03-09 10:26 - 2015-03-09 10:26 - 01021011 _____ () C:\Users\Ortiz Family\Desktop\week 2.pptx
      2015-03-09 07:29 - 2015-03-09 08:48 - 00000000 ____D () C:\Users\Ortiz Family\Desktop\UOP

      ==================== One Month Modified Files and Folders =======

      (If an entry is included in the fixlist, the file\folder will be moved.)

      2015-04-01 11:42 - 2012-04-15 14:40 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
      2015-04-01 11:41 - 2011-07-16 11:13 - 00000910 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
      2015-04-01 10:53 - 2011-03-15 21:09 - 01083426 _____ () C:\Windows\WindowsUpdate.log
      2015-04-01 09:24 - 2011-05-17 01:56 - 00000000 ____D () C:\Users\Ortiz Family\Documents\Julio
      2015-03-31 20:41 - 2011-07-16 11:13 - 00000906 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
      2015-03-31 08:06 - 2011-05-30 10:04 - 00000000 ____D () C:\Users\Ortiz Family\Documents\Bobbi
      2015-03-31 07:56 - 2011-05-19 12:48 - 00000000 ____D () C:\Users\Ortiz Family\Documents\Outlook Files
      2015-03-31 06:45 - 2011-08-03 14:59 - 00013288 _____ () C:\Users\Ortiz Family\Desktop\bill (2).xlsx
      2015-03-30 04:05 - 2009-07-13 22:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
      2015-03-30 04:05 - 2009-07-13 22:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
      2015-03-30 04:03 - 2009-07-13 23:13 - 00783464 _____ () C:\Windows\system32\PerfStringBackup.INI
      2015-03-30 03:57 - 2014-06-22 03:37 - 00000360 _____ () C:\Windows\Tasks\HPCeeScheduleForOrtiz Family.job
      2015-03-30 03:57 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
      2015-03-30 03:57 - 2009-07-13 22:51 - 00175031 _____ () C:\Windows\setupact.log
      2015-03-29 21:21 - 2011-03-15 23:18 - 01092086 _____ () C:\Windows\PFRO.log
      2015-03-29 03:22 - 2014-12-28 04:58 - 00003228 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForOrtiz Family
      2015-03-29 03:22 - 2011-05-09 06:06 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
      2015-03-27 03:45 - 2011-06-16 03:45 - 00003230 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForORTIZFAMILY-HP$
      2015-03-27 03:45 - 2011-06-16 03:45 - 00000354 _____ () C:\Windows\Tasks\HPCeeScheduleForORTIZFAMILY-HP$.job
      2015-03-26 18:21 - 2011-05-07 15:23 - 00000000 ____D () C:\Users\Ortiz Family\AppData\Local\CrashDumps
      2015-03-26 02:30 - 2015-02-12 14:02 - 00000394 ____H () C:\Windows\Tasks\{09FFAFCB-9BC4-4AC7-9E74-706F8DAD94E4}.job
      2015-03-21 07:42 - 2012-03-28 07:58 - 00002185 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
      2015-03-14 10:44 - 2015-01-17 09:04 - 00017477 _____ () C:\Users\Ortiz Family\Desktop\Girl Scout Cookie orders 2015.xlsx
      2015-03-11 20:38 - 2011-05-19 12:45 - 00000000 ____D () C:\Program Files (x86)\Google
      2015-03-11 20:36 - 2011-07-16 11:13 - 00003906 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
      2015-03-11 20:36 - 2011-07-16 11:13 - 00003654 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
      2015-03-11 04:28 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\rescache
      2015-03-11 03:52 - 2009-07-13 22:45 - 05052664 _____ () C:\Windows\system32\FNTCACHE.DAT
      2015-03-11 03:50 - 2011-05-08 06:54 - 00000000 ____D () C:\Windows\Minidump
      2015-03-11 03:50 - 2011-03-15 23:18 - 00291359 ____N () C:\Windows\Minidump\031115-105269-01.dmp
      2015-03-11 03:37 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
      2015-03-11 03:37 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Dism
      2015-03-11 03:21 - 2011-05-12 15:27 - 00000000 ____D () C:\ProgramData\Microsoft Help
      2015-03-11 03:20 - 2009-07-13 20:34 - 00000525 _____ () C:\Windows\win.ini
      2015-03-11 03:11 - 2013-07-15 03:00 - 00000000 ____D () C:\Windows\system32\MRT
      2015-03-11 03:06 - 2011-05-12 10:57 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
      2015-03-09 10:25 - 2014-12-09 13:51 - 00000000 ____D () C:\Users\Ortiz Family\Desktop\bshs 355
      2015-03-08 18:59 - 2014-11-12 07:31 - 00000000 ____D () C:\Program Files\Adblock Plus for IE
      2015-03-08 18:55 - 2012-04-15 14:40 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
      2015-03-08 18:55 - 2012-04-15 14:40 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
      2015-03-08 18:55 - 2011-11-15 16:56 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
      2015-03-03 13:08 - 2014-09-30 14:38 - 00000000 ___RD () C:\Users\Ortiz Family\Dropbox
      2015-03-03 07:17 - 2011-05-07 13:19 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
      2015-03-02 06:01 - 2014-09-30 14:35 - 00000000 ____D () C:\Users\Ortiz Family\AppData\Roaming\Dropbox

      ==================== Files in the root of some directories =======

      2014-07-08 15:09 - 2014-07-08 15:56 - 0000132 _____ () C:\Users\Ortiz Family\AppData\Roaming\Adobe PNG Format CS5 Prefs
      2014-01-03 19:16 - 2014-01-03 19:16 - 0000000 _____ () C:\Users\Ortiz Family\AppData\Roaming\pdfconverter
      2014-11-06 12:18 - 2014-11-06 12:22 - 0020932 _____ () C:\Users\Ortiz Family\AppData\Local\893686b8
      2014-05-28 11:12 - 2015-03-01 08:10 - 0001456 _____ () C:\Users\Ortiz Family\AppData\Local\Adobe Save for Web 12.0 Prefs
      2011-09-03 08:09 - 2011-09-03 08:09 - 0000236 _____ () C:\Users\Ortiz Family\AppData\Local\LaunchHomeCenter.log
      2011-09-20 14:59 - 2011-09-20 14:59 - 0007602 _____ () C:\Users\Ortiz Family\AppData\Local\Resmon.ResmonCfg
      2014-10-27 16:08 - 2014-10-27 16:08 - 0000057 _____ () C:\ProgramData\Ament.ini

      Files to move or delete:
      ====================
      C:\Windows\Tasks\{09FFAFCB-9BC4-4AC7-9E74-706F8DAD94E4}.job

      Some content of TEMP:
      ====================
      C:\Users\Ortiz Family\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpc7wqhs.dll
      C:\Users\Ortiz Family\AppData\Local\Temp\jre-8u31-windows-au.exe
      C:\Users\Ortiz Family\AppData\Local\Temp\{2165A870-3F23-4706-B7DB-429C69C7840C}.exe

      ==================== Bamital & volsnap Check =================

      (There is no automatic fix for files that do not pass verification.)

      C:\Windows\System32\winlogon.exe => File is digitally signed
      C:\Windows\System32\wininit.exe => File is digitally signed
      C:\Windows\SysWOW64\wininit.exe => File is digitally signed
      C:\Windows\explorer.exe => File is digitally signed
      C:\Windows\SysWOW64\explorer.exe => File is digitally signed
      C:\Windows\System32\svchost.exe => File is digitally signed
      C:\Windows\SysWOW64\svchost.exe => File is digitally signed
      C:\Windows\System32\services.exe => File is digitally signed
      C:\Windows\System32\User32.dll => File is digitally signed
      C:\Windows\SysWOW64\User32.dll => File is digitally signed
      C:\Windows\System32\userinit.exe => File is digitally signed
      C:\Windows\SysWOW64\userinit.exe => File is digitally signed
      C:\Windows\System32\rpcss.dll => File is digitally signed
      C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

      LastRegBack: 2015-03-30 04:27

      ==================== End Of Log ============================

       

       

       

       

      Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
      Ran by [removed] at 2015-04-01 12:19:02
      Running from C:\Users\[removed]\Desktop
      Boot Mode: Normal
      ==========================================================

      ==================== Security Center ========================

      (If an entry is included in the fixlist, it will be removed.)

      AV: Panda Free Antivirus (Enabled - Up to date) {3456760B-FDAA-FFFD-06C2-7BB528D2066C}
      AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
      AS: Panda Free Antivirus (Enabled - Up to date) {8F3797EF-DB90-F073-3C72-40C753554CD1}
      AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
      AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      FW: Panda Firewall (Disabled) {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117}

      ==================== Installed Programs ======================

      (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

      Adblock Plus for IE (32-bit and 64-bit) (HKLM\…\{77588F59-3C58-4675-8EEE-998E5BC33CF4}) (Version: 1.4 - Eyeo GmbH)
      Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 15.0.0.356 - Adobe Systems Incorporated)
      Adobe Audition 3.0 (HKLM-x32\…\Adobe Audition 3.0) (Version: 3.0 - Adobe Systems Incorporated)
      Adobe Audition 3.0 Vista Compatibility (HKLM\…\{75d2897c-87aa-4a06-8710-3ebda9f02de0}.sdb) (Version:  - )
      Adobe Flash Player 16 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
      Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
      Adobe Photoshop CS5.1 (HKLM-x32\…\{9158FF30-78D7-40EF-B83E-451AC5334640}) (Version: 12.1 - Adobe Systems Incorporated)
      Adobe Reader XI (11.0.10) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
      Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.3.153 - Adobe Systems, Inc.)
      Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Alesis io|2 ASIO Driver (HKLM-x32\…\{311EEFFE-8354-42D8-B2A0-A0666689F69F}) (Version: 1.0.0 - Alesis)
      Alesis USB Audio driver (HKLM\…\USB_AUDIO_DEusb-audio.deAlesis) (Version:  - )
      AMD Catalyst Install Manager (HKLM\…\{6F483F38-6162-7606-1D0B-054852C8E011}) (Version: 3.0.851.0 - Advanced Micro Devices, Inc.)
      Apple Application Support (HKLM-x32\…\{CCE825DB-347A-4004-A186-5F4A6FDD8547}) (Version: 2.3.2 - Apple Inc.)
      Apple Mobile Device Support (HKLM\…\{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}) (Version: 6.0.1.3 - Apple Inc.)
      Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
      Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Bing Bar (HKLM-x32\…\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
      Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
      bl (x32 Version: 1.0.0 - Your Company Name) Hidden
      Blackhawk Striker 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Blasterball 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Blio (HKLM-x32\…\{504CC891-B140-4E1B-860B-5E4C1DFBA9E3}) (Version: 2.0.5350 - K-NFB Reading Technology, Inc.)
      Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
      Bounce Symphony (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Build-a-lot 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
      Cisco LEAP Module (HKLM-x32\…\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
      Cisco PEAP Module (HKLM-x32\…\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
      Cisco WebEx Meetings (HKU\S-1-5-21-4195524230-986017159-2191004378-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
      CyberLink DVD Suite Deluxe (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.3210 - CyberLink Corp.)
      D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
      Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
      DING! (HKLM-x32\…\{84031A18-BA9A-4156-A74F-E05B52DDFCE2}) (Version: 1.05.005 - Southwest Airlines)
      Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Download-Manager (remove only) (HKLM-x32\…\Download-Manager) (Version:  - )
      Driver Detective (HKLM-x32\…\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}) (Version: 8.0.1 - PC Drivers HeadQuarters)
      Dropbox (HKU\S-1-5-21-4195524230-986017159-2191004378-1000\…\Dropbox) (Version: 3.2.6 - Dropbox, Inc.)
      DVD Menu Pack for HP MediaSmart Video (HKLM-x32\…\InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}) (Version: 4.2.4412 - Hewlett-Packard)
      DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.2.4412 - Hewlett-Packard) Hidden
      DVD Photo Slideshow Professional 8.07 (HKLM-x32\…\DVD Photo Slideshow Professional_is1) (Version:  - dvd-photo-slideshow.com)
      eLicenser Control (HKLM-x32\…\eLicenser Control) (Version:  - Steinberg Media Technologies GmbH)
      Escape Rosecliff Island (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden
      FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Final Drive Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
      GetDiz (HKLM-x32\…\GetDiz) (Version: 4.6 - Outertech)
      Google Chrome (HKLM-x32\…\Google Chrome) (Version: 41.0.2272.101 - Google Inc.)
      Google Earth (HKLM-x32\…\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
      Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.)
      Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
      Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
      Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
      Heroes of Hellas 2 - Olympia (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
      HP ENVY 4500 series Basic Device Software (HKLM\…\{6915424E-704F-4F5D-9057-9C7B406B36DB}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
      HP ENVY 4500 series Help (HKLM-x32\…\{95BECC50-22B4-4FCA-8A2E-BF77713E6D3A}) (Version: 30.0.0 - Hewlett Packard)
      HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.1.5 - WildTangent)
      hp LaserJet 1000 (HKLM-x32\…\{975C8028-51D8-44A9-9585-82E9810FE96A}) (Version:  - )
      HP MediaSmart DVD (HKLM-x32\…\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 4.2.4725 - Hewlett-Packard)
      HP MediaSmart Music (HKLM-x32\…\InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}) (Version: 4.2.4517 - Hewlett-Packard)
      HP MediaSmart Photo (HKLM-x32\…\InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}) (Version: 4.2.4513 - Hewlett-Packard)
      HP MediaSmart SmartMenu (HKLM\…\{A40F60B1-F1E1-452E-96A5-FF97F9A2D102}) (Version: 3.1.2.4 - Hewlett-Packard)
      HP MediaSmart Video (HKLM-x32\…\InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}) (Version: 4.2.4522 - Hewlett-Packard)
      HP MediaSmart/TouchSmart Netflix (HKLM-x32\…\{2EA3D6B2-157E-4112-A3AB-BF17E16661C3}) (Version: 1.0.4.0 - Hewlett-Packard)
      HP MovieStore (HKLM-x32\…\{9008D736-35CA-40DB-A2BE-5F32D954E5AA}) (Version: 2.0.2 - Hewlett-Packard)
      HP Odometer (HKLM-x32\…\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
      HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
      HP Product Detection (HKLM-x32\…\{A436F67F-687E-4736-BD2B-537121A804CF}) (Version: 11.14.0001 - HP)
      HP Setup (HKLM-x32\…\{53469506-A37E-4314-A9D9-38724EC23A75}) (Version: 8.4.4400.3525 - Hewlett-Packard Company)
      HP Setup Manager (HKLM-x32\…\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.0.12844.3519 - Hewlett-Packard Company)
      HP Support Assistant (HKLM-x32\…\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
      HP Support Information (HKLM-x32\…\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard)
      HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
      HP Vision Hardware Diagnostics (HKLM\…\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.1.6.0 - Hewlett-Packard)
      HTC BMP USB Driver (HKLM-x32\…\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
      HTC Driver Installer (HKLM-x32\…\{6D6664A9-3342-4948-9B7E-034EFE366F0F}) (Version: 3.0.0.005 - HTC Corporation)
      HTC Sync (HKLM-x32\…\{923E3957-F939-453A-BD55-41CFB8D7F211}) (Version: 3.0.5517 - HTC)
      Hulu Desktop (HKU\S-1-5-21-4195524230-986017159-2191004378-1000\…\HuluDesktop) (Version: 0.9.13 - Hulu LLC)
      HydraVision (x32 Version: 4.2.218.0 - Advanced Micro Devices, Inc.) Hidden
      Java 8 Update 31 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86418031F0}) (Version: 8.0.310 - Oracle Corporation)
      Jewel Quest Solitaire 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
      Kobo (HKLM-x32\…\Kobo) (Version: 1.6 - Kobo Inc.)
      LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3130 - CyberLink Corp.)
      LabelPrint (x32 Version: 2.5.3130 - CyberLink Corp.) Hidden
      LightScribe System Software (HKLM-x32\…\{FD7F0DB8-0E96-4D64-AD4D-9B5A936AF2A8}) (Version: 1.18.20.1 - LightScribe)
      Live Lite Alesis Edition (HKLM-x32\…\Live Lite Alesis Edition) (Version:  - )
      Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
      McAfee Security Scan Plus (HKLM-x32\…\McAfee Security Scan) (Version: 3.0.207.4 - McAfee, Inc.)
      Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
      Microsoft Calculator Plus (HKLM-x32\…\{83073C45-3003-4671-9A86-243AAADD915A}) (Version: 1.0.0 - Microsoft)
      Microsoft IntelliType Pro 8.2 (HKLM\…\Microsoft IntelliType Pro 8.2) (Version: 8.20.469.0 - Microsoft Corporation)
      Microsoft Office Click-to-Run 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
      Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-0081-0409-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
      Microsoft Office Professional 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
      Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
      Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
      Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
      Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\…\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\…\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
      MotoHelper 2.1.41 Driver 5.5.0 (HKLM-x32\…\MotoHelper) (Version: 2.1.41 - Motorola)
      MotoHelper MergeModules (x32 Version: 1.2.0 - Motorola) Hidden
      Motorola Mobile Drivers Installation 5.5.0 (Version: 5.5.0 - Motorola Inc.) Hidden
      Movie Theme Pack for HP MediaSmart Video (HKLM-x32\…\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 4.2.4412 - Hewlett-Packard)
      Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.2.4412 - Hewlett-Packard) Hidden
      MpcStar 5.4 (HKLM-x32\…\MpcStar) (Version: 5.4 - www.mpcstar.com)
      MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
      MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
      MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
      MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\…\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
      MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
      MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\…\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
      Mystery P.I. - The London Caper (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Panda Devices Agent (HKLM-x32\…\Panda Devices Agent) (Version: 1.03.04 - Panda Security)
      Panda Devices Agent (x32 Version: 1.05.00 - Panda Security) Hidden
      Panda Free Antivirus (HKLM-x32\…\Panda Universal Agent Endpoint) (Version: 15.00.04.0002 - Panda Security)
      Panda Free Antivirus (Version: 7.23.00.0000 - Panda Security) Hidden
      PDF Complete Special Edition (HKLM-x32\…\PDF Complete) (Version: 4.0.9 - PDF Complete, Inc)
      PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
      PDF Speed Converter (HKLM\…\{EC38DB84-B902-4F2D-92D7-297E4E3A0A2A}_is1) (Version: 1.0 - )
      Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
      ph (x32 Version: 1.0.0 - Your Company Name) Hidden
      PhotoNow! (HKLM-x32\…\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.7717 - CyberLink Corp.)
      PhotoNow! (x32 Version: 1.1.7717 - CyberLink Corp.) Hidden
      PicPick (HKLM-x32\…\PicPick) (Version: 3.4.0 - NTeWORKS)
      PictureMover (HKLM-x32\…\{264FE20A-757B-492a-B0C3-4009E2997D8A}) (Version: 3.5.0.33 - Hewlett-Packard Company)
      Plants vs. Zombies (x32 Version: 2.2.0.95 - WildTangent) Hidden
      PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
      PlayReady PC Runtime x86 (HKLM-x32\…\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
      Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.4329 - CyberLink Corp.)
      Power2Go (x32 Version: 6.1.4329 - CyberLink Corp.) Hidden
      PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3129 - CyberLink Corp.)
      PowerDirector (x32 Version: 8.0.3129 - CyberLink Corp.) Hidden
      PreReq (x32 Version: 6.2.4.0 - Eastman Kodak Company) Hidden
      PressReader (HKLM-x32\…\{912CED74-88D3-4C5B-ACB0-13231864975E}) (Version: 5.10.1102.0 -  NewspaperDirect Inc.)
      Print Artist Craft Studio (HKLM-x32\…\{54E76A97-D5FB-4EF4-857B-838E47705B98}) (Version: 25.0.1.7 - Nova Development)
      PrintProjects (HKLM-x32\…\PrintProjects) (Version: 1.0.0.9282 - RocketLife Inc.)
      Product Improvement Study for HP ENVY 4500 series (HKLM\…\{58139103-BACF-4BDC-B71C-955F9164ADA6}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
      QuickTime (HKLM-x32\…\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
      Ralink 802.11n Wireless LAN Card (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 3.2.13.0 - Ralink)
      Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6196 - Realtek Semiconductor Corp.)
      Recovery Manager (x32 Version: 5.5.3219 - CyberLink Corp.) Hidden
      Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
      RoxioNow Player (HKLM-x32\…\{0EDEB615-1A60-425E-8306-0E10519C7B55}) (Version: 1.9.5.101 - RoxioNow)
      Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
      Steinberg Cubase LE 4 (HKLM-x32\…\{AB3C4AC6-C401-4132-A8B5-265899A9C0E8}) (Version: 4.1.3.853 - Steinberg Media Technologies GmbH)
      Steinberg HALionOne (HKLM-x32\…\{E70E7159-93B1-470D-9FBD-D8E9EF34B538}) (Version: 1.1.0.457 - Steinberg Media Technologies GmbH)
      Steinberg HALionOne Essential Set (HKLM-x32\…\{C04D5974-F528-4347-A494-EAF56124CC1A}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH)
      swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
      Unity Web Player (HKU\S-1-5-21-4195524230-986017159-2191004378-1000\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
      US-122 (HKLM-x32\…\US-122) (Version:  - )
      US122 Driver 3.40 (HKLM\…\US122 Driver_is1) (Version: 3.40 - Frontier Design Group, LLC)
      Virtual Families (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Waves Diamond Bundle v5.0 (HKLM-x32\…\Waves Diamond Bundle v5.0) (Version:  - )
      Wheel of Fortune 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
      Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
      WinRAR 4.00 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 4.00.0 - win.rar GmbH)
      Zinio Reader 4 (HKLM-x32\…\ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1) (Version: 4.0.3184 - Zinio LLC)
      Zinio Reader 4 (x32 Version: 4.0.3184 - Zinio LLC) Hidden
      Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden

      ==================== Custom CLSID (selected items): ==========================

      (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

      CustomCLSID: HKU\S-1-5-21-4195524230-986017159-2191004378-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Ortiz Family\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-4195524230-986017159-2191004378-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ortiz Family\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-4195524230-986017159-2191004378-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ortiz Family\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-4195524230-986017159-2191004378-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ortiz Family\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-4195524230-986017159-2191004378-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ortiz Family\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-4195524230-986017159-2191004378-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ortiz Family\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-4195524230-986017159-2191004378-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ortiz Family\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-4195524230-986017159-2191004378-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ortiz Family\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
      CustomCLSID: HKU\S-1-5-21-4195524230-986017159-2191004378-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ortiz Family\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

      ==================== Restore Points  =========================

      01-03-2015 08:08:41 Windows Update
      05-03-2015 08:08:33 Windows Update
      07-03-2015 09:55:11 Installed Adblock Plus for IE (32-bit and 64-bit)
      08-03-2015 18:57:19 Installed Adblock Plus for IE (32-bit and 64-bit)
      09-03-2015 19:05:41 Windows Update
      11-03-2015 03:00:59 Windows Update
      14-03-2015 19:08:18 Windows Update
      18-03-2015 19:09:25 Windows Update
      22-03-2015 19:08:24 Windows Update
      25-03-2015 19:11:39 Windows Update
      29-03-2015 19:08:55 Windows Update

      ==================== Hosts content: ==========================

      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

      2013-01-18 01:24 - 2014-11-06 16:09 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
      127.0.0.1       localhost

      ==================== Scheduled Tasks (whitelisted) =============

      (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

      Task: {1C3EE88F-171A-4E9A-B942-78CCDE45BB71} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-18] (Google Inc.)
      Task: {1E86B50D-1A6D-48A0-B736-4C49CBD3B877} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Warranty Opt-In(Yes) => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\Detection_PostWarrantyAlert.exe
      Task: {1F9B7D99-67CD-415C-BE88-34D5033B129F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Warranty Opt-In(No) => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\Detection_PostWarrantyAlert.exe
      Task: {3F21ED5F-7717-4416-9DD8-EB5FAA93B774} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
      Task: {4C7042BD-B66F-4EA8-9DD9-F07151307DD5} - System32\Tasks\{C8AADBFC-F038-4B0F-8099-B7E8B0F6C298} => pcalua.exe -a "E:\Driver Installers\US122_Win2k_3_21.exe" -d "E:\Driver Installers"
      Task: {5509E4E2-7D24-4ED9-B5BE-A3F2D6683A19} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
      Task: {58B04BFE-4C67-4F2A-A33B-03B80A82817D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-18] (Google Inc.)
      Task: {5F97A8E9-E4BD-4F78-97F4-A4D76A35F0C4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2015-03-10] (Hewlett-Packard)
      Task: {61C3BB92-16C7-466D-8F6F-8F5706DE615D} - System32\Tasks\MotoHelper Routing => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-06] ()
      Task: {63C2E8C3-CD65-4A4B-AC53-844DF4A85782} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
      Task: {70C5FCE0-0350-486D-833A-DE40D2722274} - System32\Tasks\{09FFAFCB-9BC4-4AC7-9E74-706F8DAD94E4} => C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe [2014-10-13] (Panda Security, S.L.)
      Task: {72FC9F91-6E69-4D64-8AA3-3E505C5E41CE} - System32\Tasks\MotoHelper Initial Update => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-06] ()
      Task: {77F09001-3CD4-4C5A-9A38-681D630C82B6} - System32\Tasks\Microsoft_Hardware_Launch_IType_exe => c:\Program Files\Microsoft IntelliType Pro\IType.exe [2011-08-10] (Microsoft Corporation)
      Task: {7DB54217-6243-4F24-94B7-010CB07AF260} - System32\Tasks\HPCeeScheduleForOrtiz Family => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
      Task: {85F4A847-B88F-4F50-8D2D-C098ECDE703B} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2011-01-27] ()
      Task: {91FE3263-B1AB-45D9-B959-1DFE6D94C1FA} - System32\Tasks\{95CEE685-1FCC-46CA-9AFE-29B25BF0864C} => pcalua.exe -a "C:\Users\Ortiz Family\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5Y8SRYT8\US122_x64_Win_Install_3_30[1].exe" -d "C:\Users\Ortiz Family\Desktop"
      Task: {9415D7B0-D57C-48E4-A0F3-37558DA3FF41} - System32\Tasks\{5211E010-CA43-4805-AF19-AB18A242C35A} => pcalua.exe -a "C:\Program Files (x86)\Steinberg\Asio\dxfdsetup.exe" -d "C:\Program Files (x86)\Steinberg\Asio"
      Task: {A2F9AC51-A97D-42F0-B365-5AF527BDE0F5} - System32\Tasks\MotoHelper Update => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-06] ()
      Task: {A69131BE-1EE1-4740-B398-91CB05668A74} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
      Task: {B3DAE0C2-1277-4FD2-A8AA-0AFF1F04D672} - System32\Tasks\HPCustParticipation HP ENVY 4500 series => C:\Program Files\HP\HP ENVY 4500 series\Bin\HPCustPartic.exe [2014-07-21] (Hewlett-Packard Development Company, LP)
      Task: {B80BF07E-7B76-414B-B701-FF8A5A03D31D} - System32\Tasks\{5F17E9AC-D659-48AC-8C1F-7585696DBF49} => pcalua.exe -a E:\setup.EXE -d E:\ -c /AUTORUN
      Task: {B8F6A9D3-C311-4216-9A1B-D05DC0096BDD} - System32\Tasks\{C03A7C0C-701B-4C28-9E20-66D1A77BB3C3} => pcalua.exe -a "C:\Downloads\Cool edit pro 2   2.1   Activation patch   manuals.pdf by fabunb\Cool Edit Pro 2 Registration Crack.exe" -d "C:\Downloads\Cool edit pro 2   2.1   Activation patch   manuals.pdf by fabunb"
      Task: {BD959209-A864-485F-9454-919DAB9C9BF2} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
      Task: {CB8D6730-E977-44FA-A204-EF0183E08F6C} - System32\Tasks\{7D1D90CC-214C-4DD5-93E2-419DE1FF060C} => pcalua.exe -a "C:\Users\Ortiz Family\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0MJ43UW0\us122_win_xp_install_3_30.exe" -d "C:\Users\Ortiz Family\Desktop"
      Task: {CBC67988-CBF9-4DEB-A09F-B4F936BE9464} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
      Task: {D4E7EC69-A1D1-4CD9-A40C-25E40DB80587} - System32\Tasks\HPCeeScheduleForORTIZFAMILY-HP$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
      Task: {E0EEFB18-32B6-42AD-B8FC-234C35A896C0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-08] (Adobe Systems Incorporated)
      Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
      Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
      Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
      Task: C:\Windows\Tasks\HPCeeScheduleForOrtiz Family.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
      Task: C:\Windows\Tasks\HPCeeScheduleForORTIZFAMILY-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
      Task: C:\Windows\Tasks\{09FFAFCB-9BC4-4AC7-9E74-706F8DAD94E4}.job => C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe

      ==================== Loaded Modules (whitelisted) ==============

      2012-03-23 08:57 - 2011-03-02 12:40 - 00164864 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll
      2013-04-12 11:23 - 2013-04-12 11:23 - 00612664 _____ () C:\Program Files (x86)\Panda Security\Panda Security Protection\SQLite3.dll
      2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf

      ==================== Alternate Data Streams (whitelisted) =========

      (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

      ==================== Safe Mode (whitelisted) ===================

      (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service"

      ==================== EXE Association (whitelisted) ===============

      (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

      ==================== Other Areas ============================

      (Currently there is no automatic fix for this section.)

      HKU\S-1-5-21-4195524230-986017159-2191004378-1000\Control Panel\Desktop\\Wallpaper ->
      DNS Servers: 192.168.2.1

      ==================== MSCONFIG/TASK MANAGER disabled items ==

      (Currently there is no automatic fix for this section.)

      MSCONFIG\Services: Adobe LM Service => 3
      MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
      MSCONFIG\Services: AMD External Events Utility => 2
      MSCONFIG\Services: AMD FUEL Service => 2
      MSCONFIG\Services: Apple Mobile Device => 2
      MSCONFIG\Services: Bonjour Service => 2
      MSCONFIG\Services: GameConsoleService => 3
      MSCONFIG\Services: gupdate => 2
      MSCONFIG\Services: gupdatem => 3
      MSCONFIG\Services: gusvc => 3
      MSCONFIG\Services: HP Support Assistant Service => 2
      MSCONFIG\Services: HPClientSvc => 2
      MSCONFIG\Services: hpqwmiex => 3
      MSCONFIG\Services: LightScribeService => 2
      MSCONFIG\Services: MBAMScheduler => 2
      MSCONFIG\Services: MBAMService => 2
      MSCONFIG\Services: McComponentHostService => 3
      MSCONFIG\Services: MotoHelper => 2
      MSCONFIG\Services: PassThru Service => 2
      MSCONFIG\Services: pdfcDispatcher => 2
      MSCONFIG\Services: RalinkRegistryWriter => 2
      MSCONFIG\Services: RalinkRegistryWriter64 => 2
      MSCONFIG\Services: RaMediaServer => 2
      MSCONFIG\Services: RoxioNow Service => 2
      MSCONFIG\Services: SABSVC => 2
      MSCONFIG\Services: SwitchBoard => 3
      MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
      MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish PictureMover.lnk => C:\Windows\pss\Snapfish PictureMover.lnk.CommonStartup
      MSCONFIG\startupfolder: C:^Users^Ortiz Family^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^DING!.lnk => C:\Windows\pss\DING!.lnk.Startup
      MSCONFIG\startupfolder: C:^Users^Ortiz Family^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP ENVY 4500 series.lnk => C:\Windows\pss\Monitor Ink Alerts - HP ENVY 4500 series.lnk.Startup
      MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
      MSCONFIG\startupreg: AdobeCS5.5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
      MSCONFIG\startupreg: ApnUpdater => "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
      MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
      MSCONFIG\startupreg: Conime => %windir%\system32\conime.exe
      MSCONFIG\startupreg: EKStatusMonitor => C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe
      MSCONFIG\startupreg: GoogleUpdate => C:\Users\Ortiz Family\AppData\Roaming\FrameworkUpdate7\GoogleUpdate.exe
      MSCONFIG\startupreg: hp 1000 firmware => C:\Program Files (x86)\hp LaserJet 1000\fwdl.exe
      MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
      MSCONFIG\startupreg: hpsysdrv => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
      MSCONFIG\startupreg: HTC Sync Loader => "C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
      MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
      MSCONFIG\startupreg: itype => "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
      MSCONFIG\startupreg: Microsoft Default Manager => "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
      MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
      MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
      MSCONFIG\startupreg: PDF Complete => C:\Program Files (x86)\PDF Complete\pdfsty.exe
      MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
      MSCONFIG\startupreg: ReminderApp_EEAC3053-7055-4143-B8A0-306758055099 => C:\Program Files (x86)\Nova Development\Print Artist Craft Studio\ReminderApp.exe
      MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
      MSCONFIG\startupreg: SmartMenu => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background
      MSCONFIG\startupreg: Spybot-S&D; Cleaning => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
      MSCONFIG\startupreg: SpybotSD TeaTimer => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
      MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
      MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
      MSCONFIG\startupreg: SuperAdBlocker => C:\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SAdBlock.exe
      MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

      ==================== Accounts: =============================

      Administrator (S-1-5-21-4195524230-986017159-2191004378-500 - Administrator - Disabled)
      Guest (S-1-5-21-4195524230-986017159-2191004378-501 - Limited - Disabled)
      HomeGroupUser$ (S-1-5-21-4195524230-986017159-2191004378-1003 - Limited - Enabled)
      Ortiz Family (S-1-5-21-4195524230-986017159-2191004378-1000 - Administrator - Enabled) => C:\Users\Ortiz Family

      ==================== Faulty Device Manager Devices =============

      ==================== Event log errors: =========================

      Application errors:
      ==================
      Error: (03/29/2015 09:27:34 AM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: The program IEXPLORE.EXE version 11.0.9600.17689 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

      Process ID: 9c30

      Start Time: 01d06a1c76ae276c

      Termination Time: 689

      Application Path: C:\Program Files\Internet Explorer\IEXPLORE.EXE

      Report Id: 1924b855-d628-11e4-8819-78acc0bf4e7d

      Error: (03/27/2015 00:50:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: The program IEXPLORE.EXE version 11.0.9600.17689 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

      Process ID: b28

      Start Time: 01d068becf96fc1f

      Termination Time: 23

      Application Path: C:\Program Files\Internet Explorer\IEXPLORE.EXE

      Report Id: 25892b94-d4b2-11e4-8819-78acc0bf4e7d

      Error: (03/27/2015 00:49:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: The program IEXPLORE.EXE version 11.0.9600.17689 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

      Process ID: 18690

      Start Time: 01d068bc268af061

      Termination Time: 63

      Application Path: C:\Program Files\Internet Explorer\IEXPLORE.EXE

      Report Id: 063cc792-d4b2-11e4-8819-78acc0bf4e7d

      Error: (03/27/2015 05:04:38 AM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: The program IEXPLORE.EXE version 11.0.9600.17689 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

      Process ID: 1c6f8

      Start Time: 01d068780592621d

      Termination Time: 951

      Application Path: C:\Program Files\Internet Explorer\IEXPLORE.EXE

      Report Id: 0644d031-d471-11e4-8819-78acc0bf4e7d

      Error: (03/26/2015 06:21:10 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17689, time stamp: 0x54e6869b
      Faulting module name: Flash64_16_0_0_305.ocx, version: 16.0.0.305, time stamp: 0x54cfff80
      Exception code: 0xc0000005
      Fault offset: 0x00000000008ef74d
      Faulting process id: 0x111ec
      Faulting application start time: 0xIEXPLORE.EXE0
      Faulting application path: IEXPLORE.EXE1
      Faulting module path: IEXPLORE.EXE2
      Report Id: IEXPLORE.EXE3

      Error: (03/10/2015 10:15:38 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17631, time stamp: 0x54b31bdf
      Faulting module name: Flash64_16_0_0_305.ocx, version: 16.0.0.305, time stamp: 0x54cfff80
      Exception code: 0xc0000005
      Fault offset: 0x00000000008ef74d
      Faulting process id: 0x4190
      Faulting application start time: 0xIEXPLORE.EXE0
      Faulting application path: IEXPLORE.EXE1
      Faulting module path: IEXPLORE.EXE2
      Report Id: IEXPLORE.EXE3

      Error: (03/09/2015 10:25:50 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: POWERPNT.EXE, version: 14.0.7138.5000, time stamp: 0x544d6cf3
      Faulting module name: ppcore.dll, version: 14.0.7141.5000, time stamp: 0x54814564
      Exception code: 0xc0000005
      Fault offset: 0x0031950a
      Faulting process id: 0x526c
      Faulting application start time: 0xPOWERPNT.EXE0
      Faulting application path: POWERPNT.EXE1
      Faulting module path: POWERPNT.EXE2
      Report Id: POWERPNT.EXE3

      Error: (03/08/2015 01:05:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: The program IEXPLORE.EXE version 11.0.9600.17631 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

      Process ID: 22788

      Start Time: 01d059ce5ac99f51

      Termination Time: 30

      Application Path: C:\Program Files\Internet Explorer\IEXPLORE.EXE

      Report Id: 610cd1c0-c5c2-11e4-a230-78acc0bf4e7d

      Error: (03/08/2015 10:28:43 AM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: The program IEXPLORE.EXE version 11.0.9600.17631 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

      Process ID: 16008

      Start Time: 01d059bb49e35f68

      Termination Time: 25

      Application Path: C:\Program Files\Internet Explorer\IEXPLORE.EXE

      Report Id: 2a803cb1-c5b0-11e4-a230-78acc0bf4e7d

      Error: (03/08/2015 08:01:11 AM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: The program IEXPLORE.EXE version 11.0.9600.17631 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

      Process ID: ab30

      Start Time: 01d059a7ae738853

      Termination Time: 0

      Application Path: C:\Program Files\Internet Explorer\IEXPLORE.EXE

      Report Id: 8c0c2163-c59b-11e4-a230-78acc0bf4e7d

      System errors:
      =============
      Error: (03/31/2015 04:07:51 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
      Description: The ScRegSetValueExW call failed for FailureCommand with the following error:
      %%5

      Error: (03/31/2015 04:07:49 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
      Description: The ScRegSetValueExW call failed for Start with the following error:
      %%5

      Error: (03/30/2015 11:13:42 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
      Description: The following fatal alert was received: 20.

      Error: (03/30/2015 11:08:16 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
      Description: The following fatal alert was received: 20.

      Error: (03/30/2015 11:07:50 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
      Description: The following fatal alert was received: 20.

      Error: (03/30/2015 03:58:30 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
      Description: The following boot-start or system-start driver(s) failed to load:
      SABDIFSV
      SABKUTIL

      Error: (03/30/2015 03:58:26 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
      Description: The ScRegSetValueExW call failed for FailureActions with the following error:
      %%5

      Error: (03/30/2015 03:57:11 AM) (Source: Application Popup) (EventID: 1060) (User: )
      Description: \??\C:\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\ has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

      Error: (03/30/2015 03:57:11 AM) (Source: Application Popup) (EventID: 1060) (User: )
      Description: \??\C:\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\ has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

      Error: (03/29/2015 09:22:58 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
      Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
      %%1068

      Microsoft Office Sessions:
      =========================
      Error: (03/29/2015 09:27:34 AM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: IEXPLORE.EXE11.0.9600.176899c3001d06a1c76ae276c689C:\Program Files\Internet Explorer\IEXPLORE.EXE1924b855-d628-11e4-8819-78acc0bf4e7d

      Error: (03/27/2015 00:50:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: IEXPLORE.EXE11.0.9600.17689b2801d068becf96fc1f23C:\Program Files\Internet Explorer\IEXPLORE.EXE25892b94-d4b2-11e4-8819-78acc0bf4e7d

      Error: (03/27/2015 00:49:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: IEXPLORE.EXE11.0.9600.176891869001d068bc268af06163C:\Program Files\Internet Explorer\IEXPLORE.EXE063cc792-d4b2-11e4-8819-78acc0bf4e7d

      Error: (03/27/2015 05:04:38 AM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: IEXPLORE.EXE11.0.9600.176891c6f801d068780592621d951C:\Program Files\Internet Explorer\IEXPLORE.EXE0644d031-d471-11e4-8819-78acc0bf4e7d

      Error: (03/26/2015 06:21:10 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: IEXPLORE.EXE11.0.9600.1768954e6869bFlash64_16_0_0_305.ocx16.0.0.30554cfff80c000000500000000008ef74d111ec01d068219e01cd55C:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Windows\system32\Macromed\Flash\Flash64_16_0_0_305.ocx2b1216c8-d417-11e4-8819-78acc0bf4e7d

      Error: (03/10/2015 10:15:38 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: IEXPLORE.EXE11.0.9600.1763154b31bdfFlash64_16_0_0_305.ocx16.0.0.30554cfff80c000000500000000008ef74d419001d05b496c5620cbC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Windows\system32\Macromed\Flash\Flash64_16_0_0_305.ocxb028d189-c740-11e4-b841-78acc0bf4e7d

      Error: (03/09/2015 10:25:50 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: POWERPNT.EXE14.0.7138.5000544d6cf3ppcore.dll14.0.7141.500054814564c00000050031950a526c01d05a82b5bacb86C:\PROGRA~2\MICROS~1\Office14\POWERPNT.EXEC:\PROGRA~2\MICROS~1\Office14\ppcore.dllf253e305-c678-11e4-b841-78acc0bf4e7d

      Error: (03/08/2015 01:05:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: IEXPLORE.EXE11.0.9600.176312278801d059ce5ac99f5130C:\Program Files\Internet Explorer\IEXPLORE.EXE610cd1c0-c5c2-11e4-a230-78acc0bf4e7d

      Error: (03/08/2015 10:28:43 AM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: IEXPLORE.EXE11.0.9600.176311600801d059bb49e35f6825C:\Program Files\Internet Explorer\IEXPLORE.EXE2a803cb1-c5b0-11e4-a230-78acc0bf4e7d

      Error: (03/08/2015 08:01:11 AM) (Source: Application Hang) (EventID: 1002) (User: )
      Description: IEXPLORE.EXE11.0.9600.17631ab3001d059a7ae7388530C:\Program Files\Internet Explorer\IEXPLORE.EXE8c0c2163-c59b-11e4-a230-78acc0bf4e7d

      CodeIntegrity Errors:
      ===================================
        Date: 2015-03-30 03:57:11.830
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\sabdifsv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

        Date: 2015-03-30 03:57:11.706
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\sabdifsv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

        Date: 2015-03-30 03:57:11.534
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

        Date: 2015-03-30 03:57:11.347
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

        Date: 2015-03-11 18:56:25.685
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\sabdifsv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

        Date: 2015-03-11 18:56:25.560
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\sabdifsv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

        Date: 2015-03-11 18:56:25.420
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

        Date: 2015-03-11 18:56:25.280
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

        Date: 2015-03-11 03:50:11.047
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\sabdifsv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

        Date: 2015-03-11 03:50:10.907
        Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\sabdifsv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      ==================== Memory info ===========================

      Processor: AMD Athlon™ II X4 640 Processor
      Percentage of memory in use: 68%
      Total physical RAM: 3839.29 MB
      Available physical RAM: 1223.89 MB
      Total Pagefile: 7676.76 MB
      Available Pagefile: 4712.02 MB
      Total Virtual: 8192 MB
      Available Virtual: 8191.83 MB

      ==================== Drives ================================

      Drive c: (OS) (Fixed) (Total:918.5 GB) (Free:588.39 GB) NTFS
      Drive d: (HP_RECOVERY) (Fixed) (Total:12.91 GB) (Free:1.55 GB) NTFS ==>[System with boot components (obtained from reading drive)]

      ==================== MBR & Partition Table ==================

      ========================================================
      Disk: 0 (Size: 931.5 GB) (Disk ID: 04103EB4)
      Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=918.5 GB) - (Type=07 NTFS)
      Partition 3: (Not Active) - (Size=12.9 GB) - (Type=07 NTFS)

      ==================== End Of Log ============================

      Lets do a few things 

       

      Download MiniToolBox and save it to your desktop,  right click on it and select RUN AS ADMINISTRATOR
       
      Checkmark the following boxes:
      •  
      • Flush DNS 
      • Reset IE Proxy Settings 
       
       
      Click Go and post the result (Result.txt) that pops up. A copy of result.txt will be saved in the same directory the tool is run.
       
       
       
      ========================================================================
       
       
       

       
      -AdwCleaner-by Xplode
       
      Click on this link to download : ADWCleaner
      Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
      Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
       
       
      Do not click on any links in the top Advertisment.
       
      •  
      • Close all open programs and internet browsers.
      • Double click on AdwCleaner.exe to run the tool.
      • Click on Scan.
      • After the scan is complete click on "Clean"
      • Confirm each time with Ok.
      • Your computer will be rebooted automatically. A text file will open after the restart.
      • Please post the content of that logfile with your next reply.
      • You can find the logfile at C:\AdwCleaner[S1].txt as well.
       
       
       
      ===============================================================================
       
       
      [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
      •  
      • Shut down your protection software now to avoid potential conflicts.
      • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
      • The tool will open and start scanning your system.
      • Please be patient as this can take a while to complete depending on your system's specifications.
      • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
      • Post the contents of JRT.txt into your next message.
       
       
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  to your desktop. 
       
      •  
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
       
       
      [external image: MBAMDashboard_zpsddef9b5f.gif]
       
      •  
      • On the Dashboard click on Update Now
      • Go to the Setting Tab
      • Under Setting go to Detection and Protection
      • Under PUP and PUM make sure both are set to show Treat Detections as Malware
      • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
      • Then on the Dashboard click on Scan
      • Make sure to select THREAT SCAN
      • Then click on Scan
      • When the scan is finished and the log pops up…select Copy to Clipboard
      • Please paste the log back into this thread for review
      • Exit Malwarebytes
       

       

      Ask AI

      AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

      Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI