This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

System Restore Error 0x80070005 [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I installed software whose license key didn't work and I wasn't getting anywhere fast, so I tried to do a system restore to bring the previous version of the software back into the pc. On doing so, I got the above error where windows said it was because an antivirus was stopping the pc from rebooting into windows again.
In frustration, I took my antivirus (bitdefender free)out, same thing happened again, with same result. I tried to reinstall my antivirus, no go. I installed avg free instead. I went looking on the web for the error and found that it was malware was causing it. I have run MS Safety Scanner (took 10 hours to complete), malwarebytes premium, superantispyware and spyware S&D. All returned clean scans.

I also found where it can be related to administrative issues on a pc.

I saw an MS fix for windows xp admin issues, but not one for windows 7. Has anyone any other ideas as to what would be causing this, if all these scans are coming back clean?

I planned to change to a new computer over the weekend and take my settings with me using MS easy transfer, but that would be out the window if there is malware lurking somewhere unforeseen and I take it with me.

Other than that, I have a lot of work ahead of me.

By the way, because of this issue, the software license key is now fixed and working okay, but it brought this issue to light.

This was posted before Easter, but unfortunately something else came up and I didn't get back to my computer until now. My apologies to Ken who answered me at that time, but I was unable to reply to him before the thread was closed.

I still plan to change to my new pc, but would need to be certain this one is clean before I move anything from it to my new one.

I am now reposting and I thank anyone who reads this and also thank you in advance for any help I may receive.
hedley

Good Morning

 

Just so you know threads are closed in no reply in 3 days, forum policy. Lets go ahead and run the scans I asked for previously

 

 
[external image: 1QYkxTZ.jpg] Please download aswMBR to your desktop.
 
  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
  •  
    I just want to see the report….Please Do Not Fix Anything
     
    ============================================================================
     
     
     
     
    Please download Farbar Recovery Scan Tool and save it to your desktop.
     
    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
     
    How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
    A simple way to check your system: Start –> Computer (right click) –> Properties
     
    [external image: FRST_zps5d956a1a.jpg]
     
     
    • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
    • Please make sure All Users is checked
    • Just keep the defaults as in the picture checkmarked
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
    • Hi Ken, thanks for the reply and the help. The requested logs are listed below:

      aswMBR txt
      14:50:31.498 VM: Intel CPU virtualization not supported
      14:51:07.169 AVAST engine defs: 15041600
      14:51:15.888 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
      14:51:15.888 Disk 0 Vendor: MAXTOR_STM3160215A 3.AAD Size: 152627MB BusType: 3
      14:51:15.888 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-3
      14:51:15.904 Disk 1 Vendor: Hitachi_HDT725032VLAT80 V54OA42A Size: 305245MB BusType: 3
      14:51:15.904 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP2T1L0-5
      14:51:15.919 Disk 2 Vendor: ST3500630AS 3.AAK Size: 476940MB BusType: 3
      14:51:15.919 Disk 3 \Device\Harddisk3\DR3 -> \Device\Ide\IdeDeviceP1T1L0-4
      14:51:15.935 Disk 3 Vendor: TOSHIBA_MQ01ABD050D AX001U Size: 476940MB BusType: 3
      14:51:16.110 Disk 0 MBR read successfully
      14:51:16.110 Disk 0 MBR scan
      14:51:16.125 Disk 0 Windows XP default MBR code
      14:51:16.141 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 152625 MB offset 2048
      14:51:16.172 Disk 0 scanning sectors +312578048
      14:51:16.438 Disk 0 scanning C:\Windows\system32\drivers
      14:51:38.114 Service scanning
      14:52:56.598 Modules scanning
      14:52:56.598 Disk 0 trace - called modules:
      14:52:56.614 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS intelide.sys
      14:52:56.629 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f1a030]
      14:52:56.629 3 CLASSPNP.SYS[8c66b59e] -> nt!IofCallDriver -> [0x86e2e7e0]
      14:52:56.645 5 ACPI.sys[8be173d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x86a5b908]
      14:53:01.333 AVAST engine scan C:\Windows
      14:53:16.192 AVAST engine scan C:\Windows\system32
      15:02:04.970 AVAST engine scan C:\Windows\system32\drivers
      15:02:59.471 AVAST engine scan C:\Users\Andrea
      15:17:19.565 AVAST engine scan C:\ProgramData
      15:27:27.627 Disk 0 statistics 3137315/0/0 @ 0.99 MB/s
      15:27:27.659 Scan finished successfully
      15:28:47.737 Disk 0 MBR has been saved successfully to "C:\Users\Andrea\Desktop\MBR.dat"
      15:28:47.768 The log file has been saved successfully to "C:\Users\Andrea\Desktop\aswMBR.txt"

      FRST log:
      Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-04-2015 04
      Ran by [removed] (administrator) on ANDREA-PC on 17-04-2015 14:42:45
      Running from C:\Users\[removed]\Desktop
      [removed]

      I am attaching a FIXLIST file, you need to download it to your desktop where you now have FRST64 or the fix wont work, use your mouse to drag FIXLIST right next to FRST64, either above or below it but not right on top of it, after its downloaded open up FRST64 and click on FIX (Not Scan) it wont take long, after your computer reboots you will find a FIXLOG file on your desktop, post it please and let me know how your system is behaving now

      Attachments:

      Hi Ken, thanks for the reply and the fix. Fix is applied and the log is attached.

      Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 18-04-2015 01
      Ran by [removed] at 2015-04-18 14:31:54 Run:1
      Running from C:\Users\[removed]\Desktop
      [removed]

      As far as office, it may not now that the policies have changed, but if it does we can fix it

       

      Run these programs in the order listed and post the log from each one, this should clean you up nicely

       

       
      -AdwCleaner-by Xplode
       
      Click on this link to download : ADWCleaner To your Desktop
      Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
      Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
       
       
      Do not click on any links in the top Advertisment.
       
      [external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
       
      •  
      • Close all open programs and internet browsers.
      • Double click on AdwCleaner.exe to run the tool.
      • Click on Scan.
      • After the scan is complete click on "Clean"
      • Confirm each time with Ok.
      • Your computer will be rebooted automatically. A text file will open after the restart.
      • Please post the content of that logfile with your next reply.
      • You can find the logfile at C:\AdwCleaner[S1].txt as well.
       
       
       
      ===============================================================================
       
       
      [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
      •  
      • Shut down your protection software now to avoid potential conflicts.
      • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
      • The tool will open and start scanning your system.
      • Please be patient as this can take a while to complete depending on your system's specifications.
      • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
      • Post the contents of JRT.txt into your next message.
       
       
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  to your desktop. <———
       
      •  
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
       
       
       
      [external image: MBAM2.1.4_zpsnwqgubkb.jpg]
       
      •  
      • On the Dashboard click on Update Now
      • Go to the Setting Tab
      • Under Setting go to Detection and Protection
      • Under PUP and PUM make sure both are set to show Treat Detections as Malware
      • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
      • Then on the Dashboard click on Scan
      • Make sure to select THREAT SCAN
      • Then click on Scan
      • When the scan is finished and the log pops up…select Copy to Clipboard
      • Please paste the log back into this thread for review
      • Exit Malwarebytes
       

       

      Hi Ken

       

      Thanks for the reply.  Here are the logs:

       

      Adw Log:

       

      # AdwCleaner v4.201 - Logfile created 18/04/2015 at 17:25:11
      # Updated 08/04/2015 by Xplode
      # Database : 2015-04-18.3 [Server]
      # Operating system : Windows 7 Ultimate Service Pack 1 (x86)
      # Username : Andrea - ANDREA-PC
      # Running from : C:\Users\Andrea\Desktop\adwcleaner_4.201.exe
      # Option : Cleaning

      ***** [ Services ] *****

      ***** [ Files / Folders ] *****

      Folder Deleted : C:\ProgramData\ParetoLogic
      Folder Deleted : C:\Users\Andrea\AppData\LocalLow\HPAppData
      Folder Deleted : C:\Users\Andrea\AppData\Roaming\Solvusoft

      ***** [ Scheduled tasks ] *****

      ***** [ Shortcuts ] *****

      ***** [ Registry ] *****

      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
      Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
      Key Deleted : HKCU\Software\Conduit
      Key Deleted : HKCU\Software\ParetoLogic
      Key Deleted : HKCU\Software\Solvusoft
      Key Deleted : HKLM\SOFTWARE\Conduit
      Key Deleted : HKLM\SOFTWARE\Solvusoft

      ***** [ Web browsers ] *****

      -\\ Internet Explorer v11.0.9600.17728

      -\\ Mozilla Firefox v28.0 (en-GB)

      *************************

      AdwCleaner[R0].txt - [1423 bytes] - [18/04/2015 17:22:17]
      AdwCleaner[S0].txt - [1370 bytes] - [18/04/2015 17:25:11]

      ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1429  bytes] ##########

       

      JRT Log:

       

      Junkware Removal Tool (JRT) by Thisisu
      Version: 6.5.8 (04.17.2015:1)
      OS: Windows 7 Ultimate x86
      Ran by [removed] on 18/04/2015 at 17:35:54.90
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

       

      ~~~ Services

       

      ~~~ Tasks

      Successfully deleted: [Task] C:\Windows\Tasks\DriverDoc_UPDATES.job
      Successfully deleted: [Task] C:\Windows\System32\Tasks\DriverDoc_UPDATES

       

      ~~~ Registry Values

       

      ~~~ Registry Keys

       

      ~~~ Files

       

      ~~~ Folders

      Successfully deleted: [Folder] C:\Windows\system32\ai_recyclebin

       

      ~~~ FireFox

      Successfully deleted the following from C:\Users\Andrea\AppData\Roaming\mozilla\firefox\profiles\8vt9fugd.default\prefs.js

      user_pref(browser.startup.homepage, hxxp://uk.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp;=yhs-fullyhosted_003&type;=wny_ggfc_15_14¶m1=1¶m2=f%3D1%26b%3DFirefox%26c

       

       

      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      Scan was completed on 18/04/2015 at 17:42:18.33
      End of JRT log
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

       

      I have Malwarebytes Premium already on my pc, so I ran it with the settings you gave and the log is below:

       

      Malwarebytes log:

       

      Malwarebytes Anti-Malware
      www.malwarebytes.org

      Scan Date: 18/04/2015
      Scan Time: 20:44:17
      Logfile:
      Administrator: Yes

      Version: 2.01.4.1018
      Malware Database: v2015.04.18.03
      Rootkit Database: v2015.03.31.01
      License: Premium
      Malware Protection: Enabled
      Malicious Website Protection: Enabled
      Self-protection: Enabled

      OS: Windows 7 Service Pack 1
      CPU: x86
      File System: NTFS
      User: Andrea

      Scan Type: Threat Scan
      Result: Completed
      Objects Scanned: 417088
      Time Elapsed: 22 min, 37 sec

      Memory: Enabled
      Startup: Enabled
      Filesystem: Enabled
      Archives: Enabled
      Rootkits: Disabled
      Heuristics: Enabled
      PUP: Enabled
      PUM: Enabled

      Processes: 0
      (No malicious items detected)

      Modules: 0
      (No malicious items detected)

      Registry Keys: 0
      (No malicious items detected)

      Registry Values: 0
      (No malicious items detected)

      Registry Data: 0
      (No malicious items detected)

      Folders: 0
      (No malicious items detected)

      Files: 0
      (No malicious items detected)

      Physical Sectors: 0
      (No malicious items detected)

      (end)

       

      Thanks again for the help, appreciated, as always.

      hedley

      Hi Ken, thanks for the reply.  Here are the logs.

       

      Frst Log:

       

       

      LastRegBack: 2015-04-18 19:55

      ==================== End Of Log ============================

       

      Addition log:

       

      Additional scan result of Farbar Recovery Scan Tool (x86) Version: 18-04-2015 01
      Ran by [removed] at 2015-04-18 23:21:32
      Running from C:\Users\[removed]\Desktop
      Boot Mode: Normal
      ==========================================================

      ==================== Security Center ========================

      (If an entry is included in the fixlist, it will be removed.)

      AV: AVG AntiVirus Free Edition 2015 (Disabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
      AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      AS: AVG AntiVirus Free Edition 2015 (Disabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

      ==================== Installed Programs ======================

      (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

      32 Bit HP CIO Components Installer (Version: 15.1.1 - Hewlett-Packard) Hidden
      Adobe Flash Player 17 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
      Advertising Center (Version: 0.0.0.2 - Nero AG) Hidden
      AIO_CDB_ProductContext (Version: 130.0.365.000 - Hewlett-Packard) Hidden
      AIO_CDB_Software (Version: 130.0.365.000 - Hewlett-Packard) Hidden
      AIO_Scan (Version: 130.0.421.000 - Hewlett-Packard) Hidden
      Amazon Kindle (HKU\S-1-5-21-3904700040-3399039281-2295319414-1000\…\Amazon Kindle) (Version:  - Amazon)
      Amazon Kindle (HKU\S-1-5-21-3904700040-3399039281-2295319414-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Amazon Kindle) (Version:  - Amazon)
      Ashampoo Music Studio 5 v.5.0.7 (HKLM\…\{91B33C97-5BBE-576E-893B-711D4D8298ED}_is1) (Version: 5.0.7 - Ashampoo GmbH & Co. KG)
      Audials (HKLM\…\{526391BC-F777-41FD-AF0C-278168C4B301}) (Version: 11.0.55900.0 - Audials AG)
      Auslogics BoostSpeed 7 (HKLM\…\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1) (Version: 7.2.0.0 - Auslogics Labs Pty Ltd)
      Auslogics DiskDefrag (HKLM\…\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 4.5.4.0 - Auslogics Labs Pty Ltd)
      AVG 2015 (HKLM\…\AVG) (Version: 2015.0.5863 - AVG Technologies)
      AVG 2015 (Version: 15.0.4331 - AVG Technologies) Hidden
      AVG 2015 (Version: 15.0.5863 - AVG Technologies) Hidden
      BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden
      CCleaner (HKLM\…\CCleaner) (Version: 5.04 - Piriform)
      Classic Shell (HKLM\…\{E0E49E80-19DE-43FE-BFF2-8C58DDF3C7F9}) (Version: 4.1.0 - IvoSoft)
      Copy (Version: 130.0.428.000 - Hewlett-Packard) Hidden
      CryptoPrevent v4.2.4 (HKLM\…\{5C5B24E7-4694-4049-A222-CCE7D3FAC63F}_is1) (Version:  - Foolish IT LLC)
      CyberLink PowerDVD 12 (HKLM\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2118.57 - CyberLink Corp.)
      D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
      Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden
      DeviceDiscovery (Version: 130.0.465.000 - Hewlett-Packard) Hidden
      DriverDoc (HKLM\…\DriverDoc_is1) (Version: 1.52.1086.14425 - Solvusoft Corporation)
      EMET 4.1 Update 1 (HKLM\…\{6A09FEB2-691C-456B-B982-2F6D21B19602}) (Version: 4.1.1 - Microsoft Corporation)
      Express Burn (HKLM\…\ExpressBurn) (Version: 4.68 - NCH Software)
      F300 (Version: 130.0.365.000 - Hewlett-Packard) Hidden
      F300_Help (Version: 82.0.242.000 - Hewlett-Packard) Hidden
      F300Trb (Version: 82.0.242.000 - Hewlett-Packard) Hidden
      Fax (Version: 130.0.418.000 - Hewlett-Packard) Hidden
      FileMarker.NET Pro v 1.0 (HKLM\…\{A5A0E0B5-578C-43CE-B201-1C01A0388DA9}_is1) (Version: 1.0 - ArcticLine Software)
      Foxit Cloud (HKLM\…\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 2.9.59.323 - Foxit Software Inc.)
      Foxit Reader (HKLM\…\Foxit Reader_is1) (Version: 7.1.0.306 - Foxit Software Inc.)
      FW LiveUpdate (HKLM\…\{159BC833-0C48-482C-94C4-2DAC8886B142}) (Version: 3.1.1.2 - TSST Korea)
      GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden
      HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP)
      HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP)
      HP Photosmart Essential 3.5 (HKLM\…\HP Photosmart Essential) (Version: 3.5 - HP)
      HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B (HKLM\…\{B61ED343-0B14-4241-999C-490CB1A20DA4}) (Version: 13.0 - HP)
      HP Smart Web Printing 4.51 (HKLM\…\HP Smart Web Printing) (Version: 4.51 - HP)
      HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
      HP Update (HKLM\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
      HPDiagnosticAlert (Version: 1.00.0001 - Microsoft) Hidden
      HPPhotoGadget (Version: 130.0.282.000 - Hewlett-Packard) Hidden
      HPPhotoSmartDiscLabelContent1 (Version: 2.04.0000 - Hewlett-Packard) Hidden
      HPPhotosmartEssential (Version: 2.04.0000 - Hewlett-Packard) Hidden
      HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden
      HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden
      ImgBurn (HKLM\…\ImgBurn) (Version: 2.5.5.0 - LIGHTNING UK!)
      Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
      Intel(R) Processor Identification Utility (HKLM\…\{A92A4DB0-CD37-42D1-BE1D-603D53C24328}) (Version: 1.0.0.0 - Intel Corporation)
      Junk Mail filter update (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
      Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
      MarketResearch (Version: 130.0.374.000 - Hewlett-Packard) Hidden
      Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
      Microsoft Office Professional Plus 2010 (HKLM\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
      Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (HKLM\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
      Microsoft Word 2010 Interactive Guide EN (HKLM\…\{43F912B9-3521-4C2B-8152-A68386C60801}) (Version: 1.2.1 - Microsoft)
      Mozilla Firefox 28.0 (x86 en-GB) (HKLM\…\Mozilla Firefox 28.0 (x86 en-GB)) (Version: 28.0 - Mozilla)
      Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
      MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
      MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
      Nero 12 (HKLM\…\{4744E147-F0F2-4140-825E-B3071FC079F1}) (Version: 12.5.01300 - Nero AG)
      Network (Version: 130.0.572.000 - Hewlett-Packard) Hidden
      Pixillion Image Converter (HKLM\…\Pixillion) (Version: 2.73 - NCH Software)
      Prerequisite installer (Version: 12.0.0003 - Nero AG) Hidden
      Prism Video File Converter (HKLM\…\Prism) (Version: 2.01 - NCH Software)
      Revo Uninstaller Pro 3.0.8 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.0.8 - VS Revo Group, Ltd.)
      Scan (Version: 13.0.0.0 - Hewlett-Packard) Hidden
      Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
      SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden
      Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 13.0 - HP)
      SmartShare (HKLM\…\{BAB337AE-DD9E-45C3-BED6-0EE4732AEC60}) (Version: 2.2.1405.1601 - LG Electronics Inc.)
      SmartWebPrinting (Version: 130.0.457.000 - Hewlett-Packard) Hidden
      SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden
      Spybot - Search & Destroy (HKLM\…\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
      SpywareBlaster 5.0 (HKLM\…\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC)
      Status (Version: 130.0.469.000 - Hewlett-Packard) Hidden
      SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1158 - SUPERAntiSpyware.com)
      System Requirements Lab for Intel (HKLM\…\{04C4B49D-45D9-4A28-9ED1-B45CBD99B8C7}) (Version: 4.5.24.0 - Husdawg, LLC)
      TechPowerUp GPU-Z (HKLM\…\TechPowerUp GPU-Z) (Version:  - TechPowerUp)
      Toolbox (Version: 130.0.648.000 - Hewlett-Packard) Hidden
      TrayApp (Version: 130.0.422.000 - Hewlett-Packard) Hidden
      UnloadSupport (Version: 11.0.0 - Hewlett-Packard) Hidden
      Visual Studio 2012 x86 Redistributables (HKLM\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
      WebReg (Version: 130.0.132.017 - Hewlett-Packard) Hidden
      Welcome App (Start-up experience) (Version: 12.0.15000 - Nero AG) Hidden
      Windows Live Essentials (HKLM\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)

      ==================== Custom CLSID (selected items): ==========================

      (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

      CustomCLSID: HKU\S-1-5-21-3904700040-3399039281-2295319414-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{06A25241-9A21-4D61-A2EA-E8E8531C4FE2}\localserver32 -> C:\Program Files\CyberLink\PowerDVD12\ExecCmd.exe (CyberLink Corp.)
      CustomCLSID: HKU\S-1-5-21-3904700040-3399039281-2295319414-1000_Classes\CLSID\{06A25241-9A21-4D61-A2EA-E8E8531C4FE2}\localserver32 -> C:\Program Files\CyberLink\PowerDVD12\ExecCmd.exe (CyberLink Corp.)

      ==================== Restore Points  =========================

      27-03-2015 18:04:52 Installed Microsoft Office Professional Plus 2010
      27-03-2015 21:21:59 Restore Operation
      04-04-2015 17:11:41 Scheduled Checkpoint
      05-04-2015 15:17:32 Restore Operation
      06-04-2015 09:57:22 Windows Update
      06-04-2015 10:16:39 Installed AVG 2015
      06-04-2015 10:18:14 Installed AVG 2015
      06-04-2015 19:28:44 Revo Uninstaller Pro's restore point - FileOpener
      06-04-2015 19:32:15 Revo Uninstaller Pro's restore point - File Opener Packages
      07-04-2015 16:21:28 Revo Uninstaller Pro's restore point - Microsoft Office Professional Plus 2010
      07-04-2015 16:22:32 Removed Microsoft Office Professional Plus 2010
      07-04-2015 19:34:15 Restore Operation
      08-04-2015 15:09:36 Revo Uninstaller Pro's restore point - Free YouTube Download version 3.2.56.324
      08-04-2015 16:03:13 Installed Microsoft Office Professional Plus 2010
      09-04-2015 20:02:14 Windows Update
      10-04-2015 21:15:47 Windows Update
      12-04-2015 16:30:23 Windows Update
      12-04-2015 16:35:03 Windows Update
      12-04-2015 16:39:47 Windows Update
      12-04-2015 16:54:18 Revo Uninstaller Pro's restore point - Java 8 Update 25
      12-04-2015 19:50:54 Post malware scans restore point
      15-04-2015 17:23:15 Windows Update
      16-04-2015 17:07:46 Revo Uninstaller Pro's restore point - CdCoverCreator 2.5.3
      16-04-2015 17:17:08 Revo Uninstaller Pro's restore point - Java 8 Update 25
      18-04-2015 14:32:12 Restore Point Created by FRST

      ==================== Hosts content: ==========================

      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

      2015-04-18 14:33 - 2015-04-18 14:33 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

      ==================== Scheduled Tasks (whitelisted) =============

      (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

      Task: {270BF75A-F67C-48C9-B359-3D969137A092} - System32\Tasks\Auslogics\BoostSpeed\Scan and Repair => Rundll32.exe TaskSchedulerHelper.dll,RunTask "BoostSpeed.exe" "-UseTray -Schedule"
      Task: {49723B02-ED5A-4286-A0A2-FE63B68EF36E} - System32\Tasks\Auslogics\BoostSpeed\Start BoostSpeed оn Andrea logon => C:\Program Files\Auslogics\BoostSpeed\BoostSpeed.exe [2014-09-11] (Auslogics)
      Task: {4B172EC5-E363-478A-9886-C6BE15614279} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-14] (Adobe Systems Incorporated)
      Task: {5F5B3616-539F-44BB-BA5B-3734D66E7B8A} - System32\Tasks\CryptoPrevent Update => C:\Program Files\Foolish IT\CryptoPrevent\CryptoPrevent.exe [2015-04-11] (Foolish IT LLC)
      Task: {6AFEA384-3C38-48B9-83B5-CA731F7CD033} - System32\Tasks\{3A8C749C-9386-45E6-BF16-9369DBEB5C81} => C:\Users\Andrea\AppData\Local\Amazon\Kindle\application\Kindle.exe [2014-02-26] (Amazon.com)
      Task: {79FAA1A6-8564-4A1F-A965-D8737143688A} - System32\Tasks\SmartShare => C:\Program Files\LG Software\LG Smart Share\SmartShareStart.exe [2014-03-13] (LG Electronics Inc.)
      Task: {7AED35A7-DEE6-48DE-8FBD-4E5C6368F707} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
      Task: {7CB9C1A4-B821-4DB4-A0F4-4A6DFA87A480} - System32\Tasks\{50034DD8-8A2F-415A-BB85-A55A67BBE21F} => pcalua.exe -a "Y:\Programme Setup Files\MS Office Pro Plus 2010 MrHighTech MicrosoftInstaller.exe" -d "Y:\Programme Setup Files"
      Task: {8F775344-49B7-4293-9A84-6CE709AD3E6F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-03-13] (Piriform Ltd)
      Task: {95A40BCA-8FC3-4D74-A07E-8234ABF6BBB3} - System32\Tasks\{7281A56F-667C-4A3A-A5D0-229C06FDF4A6} => C:\Users\Andrea\AppData\Local\Amazon\Kindle\application\Kindle.exe [2014-02-26] (Amazon.com)
      Task: {9BCBA091-C105-4EB3-9793-C637E5754176} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
      Task: {B40D1531-50B5-46F4-866F-AD6177CA654F} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
      Task: {DCFA7812-3178-4B56-B84B-67FC2299160E} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
      Task: {DFA33884-9267-4CD5-9A3D-2F6E84017F46} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)

      (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

      Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

      ==================== Loaded Modules (whitelisted) ==============

      2014-05-28 16:23 - 2014-05-28 16:23 - 00089808 _____ () C:\Program Files\EMET 4.1\EMET_CE.DLL
      2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
      2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
      2014-03-31 21:35 - 2014-03-31 21:35 - 00270016 _____ () C:\Program Files\Windows Live\Writer\en\WindowsLive.Writer.Localization.resources.dll
      2014-03-31 21:35 - 2014-03-31 21:35 - 00270016 _____ () C:\Program Files\Windows Live\Writer\en-GB\WindowsLive.Writer.Localization.resources.dll

      ==================== Alternate Data Streams (whitelisted) =========

      (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

      AlternateDataStreams: C:\ProgramData\TEMP:5C321E34

      ==================== Safe Mode (whitelisted) ===================

      (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptoPreventEventSvc => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"

      ==================== EXE Association (whitelisted) ===============

      (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

      ==================== Other Areas ============================

      (Currently there is no automatic fix for this section.)

      HKU\S-1-5-21-3904700040-3399039281-2295319414-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
      HKU\S-1-5-21-3904700040-3399039281-2295319414-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
      DNS Servers: 192.168.1.254

      ==================== MSCONFIG/TASK MANAGER disabled items ==

      (Currently there is no automatic fix for this section.)

      ==================== Accounts: =============================

      Administrator (S-1-5-21-3904700040-3399039281-2295319414-500 - Administrator - Disabled)
      Andrea (S-1-5-21-3904700040-3399039281-2295319414-1000 - Administrator - Enabled) => C:\Users\Andrea
      Guest (S-1-5-21-3904700040-3399039281-2295319414-501 - Limited - Disabled)
      HomeGroupUser$ (S-1-5-21-3904700040-3399039281-2295319414-1002 - Limited - Enabled)
      NeroMediaHomeUser.4 (S-1-5-21-3904700040-3399039281-2295319414-1003 - Limited - Enabled) => C:\Users\NeroMediaHomeUser.4

      ==================== Faulty Device Manager Devices =============

      Name: MpKsl3d7371d4
      Description: MpKsl3d7371d4
      Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
      Manufacturer:
      Service: MpKsl3d7371d4
      Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
      Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
      Devices stay in this state if they have been prepared for removal.
      After you remove the device, this error disappears.Remove the device, and this error should be resolved.

      ==================== Event log errors: =========================

      Application errors:
      ==================
      Error: (04/18/2015 07:59:31 PM) (Source: SideBySide) (EventID: 33) (User: )
      Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
      Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
      Please use sxstrace.exe for detailed diagnosis.

      Error: (04/18/2015 07:59:17 PM) (Source: SideBySide) (EventID: 33) (User: )
      Description: Activation context generation failed for "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"1".
      Dependent Assembly ACME,processorArchitecture="x86",type="win32",version="12.0.0.0" could not be found.
      Please use sxstrace.exe for detailed diagnosis.

      Error: (04/18/2015 07:57:27 PM) (Source: SideBySide) (EventID: 63) (User: )
      Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
      The value "*" of attribute "language" in element "assemblyIdentity" is invalid.

      Error: (04/18/2015 07:57:10 PM) (Source: SideBySide) (EventID: 33) (User: )
      Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
      Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found.
      Please use sxstrace.exe for detailed diagnosis.

      Error: (04/18/2015 07:57:10 PM) (Source: SideBySide) (EventID: 33) (User: )
      Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
      Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found.
      Please use sxstrace.exe for detailed diagnosis.

      Error: (04/18/2015 07:57:10 PM) (Source: SideBySide) (EventID: 33) (User: )
      Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
      Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" could not be found.
      Please use sxstrace.exe for detailed diagnosis.

      Error: (04/18/2015 05:30:34 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: FWManager.exe, version: 3.1.1.2, time stamp: 0x51393dc4
      Faulting module name: FWManager.exe, version: 3.1.1.2, time stamp: 0x51393dc4
      Exception code: 0xc0000005
      Fault offset: 0x00038fc8
      Faulting process id: 0xe50
      Faulting application start time: 0xFWManager.exe0
      Faulting application path: FWManager.exe1
      Faulting module path: FWManager.exe2
      Report Id: FWManager.exe3

      Error: (04/18/2015 05:29:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
      Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

      Error: (04/18/2015 05:29:14 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
      Description: NvStreamSvcNvVAD initialization failed [6]

      Error: (04/18/2015 05:29:14 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
      Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]

      System errors:
      =============
      Error: (04/18/2015 05:55:02 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The McAfee Validation Trust Protection Service service terminated unexpectedly.  It has done this 1 time(s).

      Error: (04/18/2015 05:37:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: The Windows Modules Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.

      Error: (04/18/2015 05:37:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: The CryptoPrevent Event Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.

      Error: (04/18/2015 05:37:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Nero Update service terminated unexpectedly.  It has done this 1 time(s).

      Error: (04/18/2015 05:37:47 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

      Error: (04/18/2015 05:37:44 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: The CryptoPrevent Event Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.

      Error: (04/18/2015 05:37:44 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The SBSD Security Center Service service terminated unexpectedly.  It has done this 1 time(s).

      Error: (04/18/2015 05:37:44 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The NVIDIA Streamer Service service terminated unexpectedly.  It has done this 1 time(s).

      Error: (04/18/2015 05:37:44 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The NVIDIA Network Service service terminated unexpectedly.  It has done this 1 time(s).

      Error: (04/18/2015 05:37:41 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: The Nero MediaHome 4 Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 1 milliseconds: Restart the service.

      Microsoft Office Sessions:
      =========================
      Error: (04/18/2015 07:59:31 PM) (Source: SideBySide) (EventID: 33) (User: )
      Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Nero\Nero 12\nero backitup\NBVSSTool_x64.exe

      Error: (04/18/2015 07:59:17 PM) (Source: SideBySide) (EventID: 33) (User: )
      Description: ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"c:\program files\Nero\Nero 12\nero recode\NeroBRServer.exe.Manifest

      Error: (04/18/2015 07:57:27 PM) (Source: SideBySide) (EventID: 63) (User: )
      Description: assemblyIdentitylanguage*c:\program files\spybot - search & destroy\DelZip179.dllc:\program files\spybot - search & destroy\DelZip179.dll8

      Error: (04/18/2015 07:57:10 PM) (Source: SideBySide) (EventID: 33) (User: )
      Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files\Audials\Audials 11\tbhsd\tools64\uninstall.exe

      Error: (04/18/2015 07:57:10 PM) (Source: SideBySide) (EventID: 33) (User: )
      Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files\Audials\Audials 11\tbhsd\tools64\install.exe

      Error: (04/18/2015 07:57:10 PM) (Source: SideBySide) (EventID: 33) (User: )
      Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files\Audials\Audials 11\tbhsd\tools64\cleanup.exe

      Error: (04/18/2015 05:30:34 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: FWManager.exe3.1.1.251393dc4FWManager.exe3.1.1.251393dc4c000000500038fc8e5001d079f4dc303f78C:\Program Files\TSST Korea\FW LiveUpdate\FWManager.exeC:\Program Files\TSST Korea\FW LiveUpdate\FWManager.exe3c19821a-e5e8-11e4-9c5e-001f81000830

      Error: (04/18/2015 05:29:40 PM) (Source: WinMgmt) (EventID: 10) (User: )
      Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

      Error: (04/18/2015 05:29:14 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
      Description: NvStreamSvcNvVAD initialization failed [6]

      Error: (04/18/2015 05:29:14 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
      Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]

      ==================== Memory info ===========================

      Processor: Genuine Intel(R) CPU 2140 @ 1.60GHz
      Percentage of memory in use: 55%
      Total physical RAM: 2814.3 MB
      Available physical RAM: 1239.27 MB
      Total Pagefile: 5624.85 MB
      Available Pagefile: 3789.84 MB
      Total Virtual: 2047.88 MB
      Available Virtual: 1913.07 MB

      ==================== Drives ================================

      Drive c: (Windows) (Fixed) (Total:149.05 GB) (Free:81.66 GB) NTFS
      Drive g: (Data2) (Fixed) (Total:116.44 GB) (Free:109.57 GB) NTFS
      Drive h: (Data3) (Fixed) (Total:116.44 GB) (Free:22.18 GB) NTFS
      Drive i: (Data4) (Fixed) (Total:116.44 GB) (Free:17.8 GB) NTFS
      Drive j: (Data5) (Fixed) (Total:116.45 GB) (Free:6.42 GB) NTFS
      Drive k: () (Fixed) (Total:116.44 GB) (Free:16.09 GB) NTFS ==>[System with boot components (obtained from reading drive)]
      Drive l: () (Fixed) (Total:116.44 GB) (Free:111.6 GB) NTFS
      Drive m: () (Fixed) (Total:116.44 GB) (Free:112.62 GB) NTFS
      Drive n: () (Fixed) (Total:116.44 GB) (Free:116.2 GB) NTFS
      Drive o: (Data11) (Fixed) (Total:232.88 GB) (Free:231.3 GB) NTFS
      Drive p: (Data12) (Fixed) (Total:232.88 GB) (Free:227.56 GB) NTFS
      Drive q: (Data13) (Fixed) (Total:232.88 GB) (Free:211.26 GB) NTFS
      Drive r: (Data14) (Fixed) (Total:232.88 GB) (Free:230.98 GB) NTFS
      Drive s: (Data7) (Fixed) (Total:232.88 GB) (Free:181.19 GB) NTFS
      Drive t: (Data8) (Fixed) (Total:232.88 GB) (Free:73.19 GB) NTFS
      Drive u: (Data9) (Fixed) (Total:232.88 GB) (Free:222.27 GB) NTFS
      Drive v: (Data10) (Fixed) (Total:232.88 GB) (Free:202.06 GB) NTFS

      ==================== MBR & Partition Table ==================

      ========================================================
      Disk: 0 (MBR Code: Windows XP) (Size: 149.1 GB) (Disk ID: 00B6C015)
      Partition 1: (Not Active) - (Size=149 GB) - (Type=07 NTFS)

      ========================================================
      Disk: 1 (MBR Code: Windows XP) (Size: 298.1 GB) (Disk ID: DD96AEA9)
      Partition 1: (Not Active) - (Size=298.1 GB) - (Type=07 NTFS)

      ========================================================
      Disk: 2 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 489A5B6E)
      Partition 1: (Active) - (Size=116.4 GB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=116.4 GB) - (Type=07 NTFS)
      Partition 3: (Not Active) - (Size=116.4 GB) - (Type=07 NTFS)
      Partition 4: (Not Active) - (Size=116.4 GB) - (Type=07 NTFS)

      ========================================================
      Disk: 3 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: BB0F1083)
      Partition 1: (Active) - (Size=116.4 GB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=116.4 GB) - (Type=07 NTFS)
      Partition 3: (Not Active) - (Size=116.4 GB) - (Type=07 NTFS)
      Partition 4: (Not Active) - (Size=116.4 GB) - (Type=OF Extended)

      ========================================================
      Disk: 4 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 82E76CCC)
      Partition 1: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
      Partition 3: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
      Partition 4: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)

      ========================================================
      Disk: 5 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 307523DC)
      Partition 1: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
      Partition 3: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
      Partition 4: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)

      ==================== End Of Log ============================

      Thanks for the help, much appreciated, as always.

      hedley

       

       

      Hi Ken, thanks for the reply. Sorry about that. Don't know what happened to the first log, but here it is now along with the Addition log:

      FRST log:

      Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-04-2015 01
      Ran by [removed] (administrator) on ANDREA-PC on 19-04-2015 10:52:45
      Running from C:\Users\[removed]\Desktop
      [removed]

      I am attaching a FIXLIST file, you need to download it to your desktop where you now have FRST or the fix wont work, use your mouse to drag FIXLIST right next to FRST, either above or below it but not right on top of it, after its downloaded open up FRST and click on FIX (Not Scan) it wont take long, after your computer reboots you will find a FIXLOG file on your desktop, post it please and let me know if there has been any improvement with your system.

      Attachments:

      Hi Ken, thanks for the reply. Below is the log requested:

      Fixlog:

      Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 18-04-2015 01
      Ran by [removed] at 2015-04-19 13:29:46 Run:2
      Running from C:\Users\[removed]\Desktop
      [removed]
      Hi Ken, thanks for the reply. Hopefully on the right path this time. Here is the log:
      Fixlog:

      Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 18-04-2015 01
      Ran by [removed] at 2015-04-19 14:59:34 Run:3
      Running from C:\Users\[removed]\Desktop
      [removed]

      Ask AI

      AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

      Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI