hey ken…heres the log…(its 32bit…its a tablet..)
FRSTlog
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-04-2015 01
Ran by [removed] (administrator) on RDK-SAM-XE500T1 on 01-05-2015 02:38:09
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Microsoft Windows 8.1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantDisplayService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Settings\CmdServer\EasyLauncher.exe
(SecureSoft) C:\Windows\mlwps.exe
() C:\ProgramData\Samsung\Service\SamsungConfiguration.exe
(Sierra Wireless, Inc.) C:\Program Files\Sierra Wireless Inc\Utils\SwiService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
() C:\ProgramData\Samsung\William_USB_HUB_SS_Disable.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Settings\sSettings.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe
(Intel(R) Corporation) C:\Windows\System32\hsmon.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Dropbox, Inc.) C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Mini S Note\MiniSNoteAgent.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x86__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [71992 2013-09-03] (Intel Corporation)
HKLM\…\Run: [RtkNGUI] => C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe [2760408 2013-10-20] (Realtek Semiconductor)
HKLM\…\Run: [IntelHeadphoneMonitor] => C:\Windows\system32\hsmon.exe [101888 2013-07-03] (Intel(R) Corporation)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-04-07] (Apple Inc.)
HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\…\RunOnce: [Application Restart #1] => C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe [394752 2014-10-28] (Microsoft Corporation)
HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\Screen_Samsung.scr [23830066 2012-10-29] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-07-28]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-03-03]
ShortcutTarget: Dropbox.lnk -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-2135967233-3606984290-4105762919-1001] => 127.0.0.1:8118
HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.msn.com/
BHO: SecureWebBHO Class -> {D3C24E2B-C820-4492-9B69-11BF7163F998} -> C:\Program Files\Alfasistem Memory\jswie.dll [2015-04-25] (SecureSoft)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.5
FireFox:
========
FF ProfilePath: C:\Users\Koonsman\AppData\Roaming\Mozilla\Firefox\Profiles\xel5hxa5.default
FF NewTab: https://gosearch.me/?u=6f0fb051f2933489997ebfe8b072f5d7&c;=up1&src;=hp&inst;=1430355271
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google Default
FF Homepage: hxxp://www.google.com/
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF SearchPlugin: C:\Users\Koonsman\AppData\Roaming\Mozilla\Firefox\Profiles\xel5hxa5.default\searchplugins\google-default.xml [2015-04-27]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\GoSearch.xml [2015-04-29]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-04-03]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [1678040 2013-08-08] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [250880 2014-10-28] (Microsoft Corporation)
R2 DptfParticipantDisplayService; C:\Windows\system32\DptfParticipantDisplayService.exe [104248 2013-09-03] (Intel Corporation)
R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [76088 2013-09-03] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [63288 2013-09-03] (Intel Corporation)
S2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [82232 2013-09-03] (Intel Corporation)
R2 Easy Launcher; C:\Program Files\Samsung\Settings\CmdServer\EasyLauncher.exe [1594416 2013-03-19] (Samsung Electronics CO., LTD.)
R2 Live Malware Protection; C:\Windows\mlwps.exe [242688 2015-04-25] (SecureSoft) [File not signed] <==== ATTENTION
S4 PrivoxyService; C:\Program Files\Alfasistem Memory\privoxy.exe [371200 2015-04-25] (The Privoxy team - www.privoxy.org) [File not signed] <==== ATTENTION
R2 SamsungConfigurationWinService; C:\Programdata\Samsung\Service\SamsungConfiguration.exe [29744 2013-06-26] ()
S3 ScDeviceEnum; C:\Windows\System32\ScDeviceEnum.dll [103936 2014-10-28] (Microsoft Corporation)
R2 SwiService; C:\Program Files\Sierra Wireless Inc\Utils\SWIService.exe [320816 2013-10-25] (Sierra Wireless, Inc.)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3020632 2014-04-04] (Samsung Electronics CO., LTD.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [284488 2015-02-03] (Microsoft Corporation)
S3 WEPHOSTSVC; C:\Windows\system32\wephostsvc.dll [20992 2014-10-28] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22200 2015-02-03] (Microsoft Corporation)
S3 workfolderssvc; C:\Windows\system32\workfolderssvc.dll [1269248 2014-10-28] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 BasicRender; C:\Windows\System32\drivers\BasicRender.sys [25600 2014-03-18] (Microsoft Corporation)
R3 BCMSDH43XX; C:\Windows\system32\DRIVERS\bcmdhd63.sys [833816 2012-10-02] (Broadcom)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [186880 2014-03-18] (Microsoft Corporation)
R3 BthMini; C:\Windows\System32\Drivers\BTHMINI.sys [23552 2014-10-28] (Microsoft Corporation)
R3 btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [144600 2013-09-05] (Broadcom Corporation.)
R3 BtwSerialBus; C:\Windows\system32\DRIVERS\BtwSerialBus.sys [130776 2013-09-10] (Broadcom Corporation.)
R3 camera; C:\Windows\system32\DRIVERS\camera.sys [207872 2013-09-03] (Intel Corporation)
R0 ChaabiDriver; C:\Windows\System32\drivers\ChaabiDriver.sys [74256 2013-09-03] (Intel Corporation)
R0 clvpep; C:\Windows\System32\drivers\clvpep.sys [81648 2013-09-03] (Intel Corporation)
R3 DptfDevDisplay; C:\Windows\system32\DRIVERS\DptfDevDisplay.sys [44256 2013-09-03] (Intel Corporation)
R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [49888 2013-09-03] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [69344 2013-09-03] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [163552 2013-09-03] (Intel Corporation)
S3 GPIO; C:\Windows\System32\drivers\iaiogpio.sys [22016 2013-07-23] (Intel Corporation)
R3 GPIOCLV; C:\Windows\System32\drivers\GPIOCLV.sys [22016 2013-09-03] (Intel Corporation)
R3 igdperf32; C:\Windows\system32\DRIVERS\igdperf32.sys [4096 2013-11-20] ()
R0 inteli2c; C:\Windows\System32\drivers\inteli2c.sys [48880 2013-09-03] (Intel Corporation)
R3 IntelSST; C:\Windows\system32\drivers\isstrtc.sys [241152 2013-07-03] (Intel(R) Corporation)
R0 Lm3554; C:\Windows\System32\drivers\lm3554.sys [34816 2013-09-03] (Intel Corporation)
R0 LNWIPC; C:\Windows\System32\drivers\LNWIPC.sys [25840 2013-09-03] (Intel Corporation)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [16112 2013-09-03] (Intel Corporation)
R1 MpKsl09b151c6; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BAB6FA0F-20EB-4AFB-9CAA-D7C6BDCEA567}\MpKsl09b151c6.sys [39464 2015-04-30] (Microsoft Corporation)
R3 MSICReg; C:\Windows\System32\drivers\MSICReg.sys [17408 2013-09-03] (Intel Corporation)
R3 mxtBootBridge; C:\Windows\System32\drivers\mxtBootBridge.sys [25088 2012-09-11] (Windows (R) Win 7 DDK provider)
R3 ov2720; C:\Windows\System32\drivers\ov2720.sys [46592 2013-09-03] (Intel Corporation)
R3 ov8830; C:\Windows\system32\DRIVERS\ov8830.sys [63488 2013-09-03] (Intel Corporation)
R3 rtii2sac; C:\Windows\system32\DRIVERS\rtii2sac.sys [142552 2013-10-20] (Realtek Semiconductor Corp.)
R3 SensorsHIDClassDriver; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)
R3 spi; C:\Windows\System32\drivers\spi.sys [46592 2013-09-03] (Intel Corporation)
R3 Uart16550pc; C:\Windows\System32\drivers\Uart16550pc.sys [40960 2013-09-03] (Intel Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [84800 2015-02-03] (Microsoft Corporation)
R0 Wof; C:\Windows\system32\Drivers\Wof.sys [138584 2014-06-11] (Microsoft Corporation)
R3 WUDFSensorLP; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)
R3 WUDFWpdMtp; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)
U3 aswMBR; \??\C:\Users\Koonsman\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Koonsman\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-01 02:38 - 2015-05-01 02:38 - 00014215 _____ () C:\Users\Koonsman\Downloads\FRST.txt
2015-05-01 02:37 - 2015-05-01 02:38 - 00000000 ____D () C:\FRST
2015-05-01 02:37 - 2015-05-01 02:37 - 02101248 _____ (Farbar) C:\Users\Koonsman\Downloads\FRST64.exe
2015-05-01 02:37 - 2015-05-01 02:37 - 01140736 _____ (Farbar) C:\Users\Koonsman\Downloads\FRST.exe
2015-04-30 07:50 - 2015-04-30 07:50 - 00000579 _____ () C:\Users\Koonsman\Desktop\aswMBR.txt
2015-04-30 07:42 - 2015-04-30 07:42 - 05198336 _____ (AVAST Software) C:\Users\Koonsman\Downloads\aswMBR.exe
2015-04-30 07:37 - 2015-04-30 07:37 - 00000000 ____D () C:\Users\Koonsman\Desktop\backups
2015-04-30 07:34 - 2015-04-30 07:34 - 00005597 _____ () C:\Users\Koonsman\Desktop\hijackthis.log
2015-04-30 07:26 - 2015-04-30 07:26 - 00388608 _____ (Trend Micro Inc.) C:\Users\Koonsman\Desktop\HijackThis.exe
2015-04-29 19:54 - 2015-04-29 19:54 - 00000000 ____D () C:\Program Files\Common Service
2015-04-27 20:49 - 2015-04-30 06:33 - 00070144 _____ () C:\Windows\system32\tasks.dll
2015-04-25 06:32 - 2015-04-25 06:33 - 00000000 ____D () C:\Users\Koonsman\AppData\Local\Updater
2015-04-25 06:32 - 2015-04-25 06:33 - 00000000 ____D () C:\Program Files\Alfasistem Memory
2015-04-25 06:32 - 2015-04-25 06:32 - 00803840 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp.exe
2015-04-25 06:32 - 2015-04-25 06:32 - 00242688 _____ (SecureSoft) C:\Windows\mlwps.exe
2015-04-25 06:32 - 2015-04-25 06:32 - 00000000 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp
2015-04-15 18:27 - 2015-04-15 18:27 - 00001765 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-04-15 18:27 - 2015-04-15 18:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-04-15 18:25 - 2015-04-15 18:27 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-04-15 18:25 - 2015-04-15 18:27 - 00000000 ____D () C:\Program Files\iTunes
2015-04-15 18:25 - 2015-04-15 18:25 - 00000000 ____D () C:\Program Files\iPod
2015-04-15 18:10 - 2015-03-22 17:44 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 18:10 - 2015-03-22 17:07 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 18:10 - 2015-03-22 17:07 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 18:10 - 2015-03-22 17:07 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 18:10 - 2015-03-22 17:07 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 18:10 - 2015-03-22 17:07 - 00330752 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 18:10 - 2015-03-22 17:07 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 18:10 - 2015-03-14 03:13 - 01124352 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-04-15 02:44 - 2015-03-12 22:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 02:44 - 2015-03-12 22:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 02:44 - 2015-03-12 22:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 02:44 - 2015-03-12 22:16 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-04-15 02:44 - 2015-03-12 21:50 - 00880128 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-04-15 02:44 - 2015-03-12 21:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 02:44 - 2015-03-12 21:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 02:44 - 2015-03-12 21:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 02:44 - 2015-03-12 21:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 02:44 - 2015-03-12 21:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 02:44 - 2015-03-12 21:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 02:44 - 2015-03-12 21:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 02:43 - 2015-03-23 16:45 - 05782848 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 02:43 - 2015-03-23 16:45 - 01468920 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 02:43 - 2015-03-23 16:45 - 00257216 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-04-15 02:43 - 2015-03-19 22:25 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-system-events.dll
2015-04-15 02:43 - 2015-03-19 21:41 - 00369152 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-04-15 02:43 - 2015-03-19 21:16 - 00749568 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-04-15 02:43 - 2015-03-14 03:40 - 00125472 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 02:43 - 2015-03-13 20:14 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 02:43 - 2015-03-13 20:14 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-15 02:43 - 2015-03-13 20:11 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 02:43 - 2015-03-13 19:59 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 02:43 - 2015-03-13 19:03 - 03040768 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 02:43 - 2015-03-13 19:02 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 02:43 - 2015-03-13 19:02 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 02:43 - 2015-03-13 19:00 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2015-04-15 02:43 - 2015-03-13 18:59 - 00721920 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-15 02:43 - 2015-03-13 18:59 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2015-04-15 02:43 - 2015-03-13 18:59 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 02:43 - 2015-03-13 18:55 - 02309120 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 02:43 - 2015-03-12 21:37 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2015-04-15 02:43 - 2015-02-24 03:20 - 00738112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 02:42 - 2015-03-04 05:05 - 00279360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2015-04-15 02:42 - 2015-03-03 21:19 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 02:42 - 2015-02-20 18:24 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
2015-04-08 07:57 - 2015-04-08 07:57 - 00000000 ___SD () C:\Windows\system32\GWX
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-01 01:11 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\system32\sru
2015-04-30 09:01 - 2014-07-28 01:33 - 01060356 _____ () C:\Windows\WindowsUpdate.log
2015-04-30 08:17 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-30 07:36 - 2014-03-18 03:01 - 00818732 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-30 07:32 - 2015-03-03 05:32 - 00000000 ___RD () C:\Users\Koonsman\Dropbox
2015-04-30 07:32 - 2015-03-03 05:24 - 00000000 ____D () C:\Users\Koonsman\AppData\Roaming\Dropbox
2015-04-30 07:32 - 2014-07-28 01:18 - 00000000 ___DO () C:\Users\Koonsman\OneDrive
2015-04-30 07:31 - 2013-08-22 02:23 - 00027333 _____ () C:\Windows\setupact.log
2015-04-30 07:31 - 2013-08-22 02:23 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-30 07:31 - 2013-08-22 01:13 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-04-30 07:17 - 2014-07-28 01:34 - 00000000 ____D () C:\Users\Koonsman\AppData\Local\VirtualStore
2015-04-30 07:09 - 2015-03-03 05:40 - 00000000 ____D () C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth
2015-04-30 06:34 - 2014-07-28 01:34 - 00001341 _____ () C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-30 06:26 - 2015-02-24 09:28 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-30 06:26 - 2014-03-18 02:48 - 00016616 _____ () C:\Windows\PFRO.log
2015-04-30 06:23 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\AppCompat
2015-04-30 06:19 - 2014-12-13 12:04 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-30 06:19 - 2014-07-30 16:21 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-30 06:08 - 2014-11-03 10:51 - 00000000 ____D () C:\Users\Koonsman\AppData\Local\Unity
2015-04-25 05:15 - 2015-03-03 05:32 - 00001038 _____ () C:\Users\Koonsman\Desktop\Dropbox.lnk
2015-04-25 05:15 - 2015-03-03 05:27 - 00000000 ____D () C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-04-24 18:03 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\AppReadiness
2015-04-22 02:16 - 2013-08-22 03:05 - 00000000 ____D () C:\Windows\CbsTemp
2015-04-17 19:48 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\rescache
2015-04-16 06:11 - 2014-07-30 16:20 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-16 06:07 - 2014-07-30 16:20 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-15 18:25 - 2014-08-02 14:01 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-04-13 18:24 - 2015-03-16 13:49 - 00792056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-13 18:24 - 2015-03-16 13:49 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2015-04-25 06:32 - 2015-04-25 06:32 - 0000000 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp
2015-04-25 06:32 - 2015-04-25 06:32 - 0803840 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp.exe
2015-04-27 20:51 - 2015-04-27 20:51 - 0009662 _____ () C:\Users\Koonsman\AppData\Roaming\em_64x64.ico
2014-08-06 10:44 - 2014-08-06 10:44 - 0007605 _____ () C:\Users\Koonsman\AppData\Local\resmon.resmoncfg
Some content of TEMP:
====================
C:\Users\Koonsman\AppData\Local\Temp\41AA.tmp.exe
C:\Users\Koonsman\AppData\Local\Temp\41AB.tmp.exe
C:\Users\Koonsman\AppData\Local\Temp\447E.tmp.exe
C:\Users\Koonsman\AppData\Local\Temp\447F.tmp.exe
C:\Users\Koonsman\AppData\Local\Temp\44AF.tmp.exe
C:\Users\Koonsman\AppData\Local\Temp\560.tmp.exe
C:\Users\Koonsman\AppData\Local\Temp\6B3.tmp.exe
C:\Users\Koonsman\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkaa69u.dll
C:\Users\Koonsman\AppData\Local\Temp\GPUpd553EE7BD0.exe
C:\Users\Koonsman\AppData\Local\Temp\GPUpd553EE7BF2.exe
C:\Users\Koonsman\AppData\Local\Temp\GPUpd553EE7C03.exe
C:\Users\Koonsman\AppData\Local\Temp\GPUpd55417D450.exe
C:\Users\Koonsman\AppData\Local\Temp\tasks.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-28 06:55
==================== End Of Log ============================
additional
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-04-2015 01
Ran by [removed] at 2015-05-01 02:39:23
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2135967233-3606984290-4105762919-500 - Administrator - Disabled)
Guest (S-1-5-21-2135967233-3606984290-4105762919-501 - Limited - Disabled)
Koonsman (S-1-5-21-2135967233-3606984290-4105762919-1001 - Administrator - Enabled) => C:\Users\Koonsman
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Apple Application Support (32-bit) (HKLM\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Dropbox (HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\…\Dropbox) (Version: 3.4.4 - Dropbox, Inc.)
iCloud (HKLM\…\{760BB327-3973-4608-85C8-88162E2FF3B6}) (Version: 4.0.6.28 - Apple Inc.)
Intel(R) Processor Graphics (HKLM\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.14.3.1177 - Intel Corporation)
iTunes (HKLM\…\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Mini S Note (HKLM\…\{D3D81CA0-B970-43A0-ACD0-DC7A36B85910}) (Version: 1.0.28.3 - Samsung Electronics CO. LTD)
myVapors (HKLM\…\{FD719CB3-73F1-478A-8A13-92586FBB669C}) (Version: 1.00.0000 - Joyetech)
QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Realtek I2S Audio (HKLM\…\{89A448AA-3301-46AA-AFC3-34F2D7C670E8}) (Version: 6.2.9600.3082 - Realtek Semiconductor Corp.)
S Agent (Version: 1.1.47 - Samsung Electronics CO., LTD.) Hidden
Samsung Kies3 (HKLM\…\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.) Hidden
Settings (HKLM\…\{8CB5C357-12E5-41B1-A024-D57D4E6F32D9}) (Version: 2.0.1 - Samsung Electronics CO., LTD.)
Sierra Wireless Mobile Broadband Driver Package (HKLM\…\SWIQMIDrvInstaller) (Version: 3.11.1310.3981 - Sierra Wireless, Inc.)
SW Update (HKLM\…\{DA06101F-FD76-4BF0-88BD-B26A197005E3}) (Version: 2.1.21 - Samsung Electronics CO., LTD.)
WIDCOMM Bluetooth Software (HKLM\…\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.8030 - Broadcom Corporation)
Windows Driver Package - Broadcom (bcmfn2) System (08/30/2012 20.43.14.119) (HKLM\…\8ACEFA31AC73553F5EEFA5785AD8D4D0E850401F) (Version: 08/30/2012 20.43.14.119 - Broadcom)
Windows Driver Package - Broadcom (BCMSDH43XX) Net (09/28/2012 5.93.97.76) (HKLM\…\D5631A91EBAF24FAF75D27148329D007EA6B8580) (Version: 09/28/2012 5.93.97.76 - Broadcom)
Windows Driver Package - Nuvoton Technology Corporation (WUDFRd) System (05/20/2013 8.1.111.5007) (HKLM\…\74C44B2BCC752410B3995F9DD1E138E6170380DF) (Version: 05/20/2013 8.1.111.5007 - Nuvoton Technology Corporation)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
==================== Restore Points =========================
ATTENTION: System Restore is disabled.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-04-30 07:29 - 2015-04-30 07:29 - 00000797 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {039231BB-BDC6-4F5B-BD3D-F39747444F31} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-23] (Microsoft Corporation)
Task: {19677A92-0F41-4D37-9CEB-9665F0725659} - System32\Tasks\Settings => C:\Program Files\Samsung\Settings\sSettings.exe [2013-03-19] (Samsung Electronics CO., LTD.)
Task: {253E7A9D-638D-450D-BDB4-4A14C309B087} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-03-19] (Samsung Electronics CO., LTD.)
Task: {267A9B11-8FB2-4458-AEAD-F9DCD15F4EF1} - System32\Tasks\TP_SS_D => C:ProgramData\Samsung\William_USB_HUB_SS_Disable.exe
Task: {3DA74E6F-1452-4EB4-9D3C-74FAA60D5659} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
Task: {6CD14856-E0B9-4C78-984B-2251D0113040} - System32\Tasks\Common Service Job => C:\Program Files\Common Service\CommonService.exe [2015-04-29] (Secure Updater)
Task: {7F43AA89-F04C-484A-880F-3087AE94BEF2} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
Task: {8C7D7F24-C593-4740-B118-2A61D6F3871D} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
Task: {AC038432-5CA6-4865-867B-49460FEBCE99} - System32\Tasks\SNoteAgent => C:\Program Files\Samsung\Mini S Note\MiniSNoteAgent.exe [2013-04-06] (Samsung Electronics CO., LTD.)
Task: {CD0541C1-3EC9-4614-8E6C-0871FC6119F8} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {CF7175A6-D34A-493F-82CC-D454AFC14836} - System32\Tasks\Malware Cleaner => C:\Users\Koonsman\AppData\Roaming\48E2.tmp.exe [2015-04-25] () <==== ATTENTION
Task: {D85249D7-4565-4718-B4D3-BCE2379FC533} - System32\Tasks\Alfasistem Memory Job => C:\Program Files\Alfasistem Memory\ tmjob.exe [2015-04-25] (SecureSoft)
Task: {E8A13984-065D-4EAC-A0D6-F57D41519A5B} - System32\Tasks\Windows Defrag => C:\Users\Koonsman\AppData\Local\Updater\winupd.exe [2015-04-25] ()
Task: {FB0E22DE-F12C-4203-8ADE-B5445C59DAD9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-04-16] (Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Loaded Modules (whitelisted) ==============
2013-03-19 16:11 - 2013-03-19 16:11 - 00211064 _____ () C:\Program Files\Samsung\Settings\CmdServer\WinCRT.dll
2014-07-03 13:20 - 2014-07-03 13:20 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-09-25 16:21 - 2013-09-25 16:21 - 00044760 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btwleapi.dll
2014-07-28 02:42 - 2013-06-26 12:18 - 00029744 _____ () C:\Programdata\Samsung\Service\SamsungConfiguration.exe
2013-03-19 16:11 - 2013-03-19 16:11 - 00085040 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
2013-03-19 16:10 - 2013-03-19 16:10 - 00029232 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll
2013-03-19 16:11 - 2013-03-19 16:11 - 01121328 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmd.dll
2013-03-19 16:11 - 2013-03-19 16:11 - 00111152 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsBase.dll
2013-03-19 16:11 - 2013-03-19 16:11 - 00056440 _____ () C:\Program Files\Samsung\Settings\CmdServer\HookDllPS2.dll
2014-07-28 01:07 - 2013-10-29 20:16 - 01737096 _____ () C:\ProgramData\Samsung\William_USB_HUB_SS_Disable.exe
2013-03-19 16:10 - 2013-03-19 16:10 - 00027184 _____ () C:\Program Files\Samsung\Settings\EasySettingsAPI.dll
2013-03-19 16:11 - 2013-03-19 16:11 - 00111152 _____ () C:\Program Files\Samsung\Settings\EasySettingsBase.dll
2013-03-19 16:11 - 2013-03-19 16:11 - 00060976 _____ () C:\Program Files\Samsung\Settings\EasyMovieEnhancer.dll
2013-03-19 16:10 - 2013-03-19 16:10 - 00103984 _____ () C:\Program Files\Samsung\Settings\EasySettingsCmdClient.dll
2015-04-30 07:32 - 2015-04-30 07:32 - 00043008 _____ () c:\users\koonsman\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkaa69u.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00750080 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00047616 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00865280 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00200704 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2014-03-19 11:39 - 2014-03-19 11:39 - 00081456 _____ () C:\Program Files\Samsung\S Agent\ToastDLL.dll
2014-11-29 12:30 - 2014-11-29 12:31 - 00143360 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x86__8wekyb3d8bbwe\ErrorReporting.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Windows\Samsung.png:ms-properties
AlternateDataStreams: C:\Windows\Screen_Samsung.scr:ms-properties
AlternateDataStreams: C:\Users\Koonsman\OneDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\gpioclv.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\inteli2c.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lnwipc.sys => ""="Driver"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Koonsman\Pictures\20140827_172915.jpg
DNS Servers: 192.168.1.5
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\…\StartupApproved\Run: => "Persistence"
HKLM\…\StartupApproved\Run: => "iTunesHelper"
HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\…\StartupApproved\Run: => "NetMon"
==================== FirewallRules (whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{AB9576D0-3789-4BBE-B91D-7E299426EDEF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{F05C7C44-1B78-4D18-B9CE-B7795C4737AA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B63CE1EE-C23A-4174-A90D-1939994192AC}] => (Allow) C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{344BD084-7F91-4165-BCF3-CE426726D30E}] => (Allow) C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{EDDAF735-1009-4821-9EA9-C64832641724}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{8C523F64-9446-4B31-8C23-43EFF71478C6}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{020BBDAD-41F7-496F-86C7-0E04B54BB6FE}] => (Allow) C:\Program Files\iTunes\iTunes.exe
==================== Faulty Device Manager Devices =============
Name: I2C HID Device
Description: I2C HID Device
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: Microsoft
Service: hidi2c
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/30/2015 08:32:13 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (04/30/2015 08:32:11 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (04/30/2015 08:32:10 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (04/30/2015 08:27:51 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (04/30/2015 08:27:48 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (04/30/2015 08:27:46 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (04/30/2015 07:31:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: EasySettingsCmdServer.exe, version: 0.0.0.0, time stamp: 0x5147f18e
Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f42bd
Exception code: 0xc0000374
Fault offset: 0x000d0982
Faulting process id: 0x4b0
Faulting application start time: 0xEasySettingsCmdServer.exe0
Faulting application path: EasySettingsCmdServer.exe1
Faulting module path: EasySettingsCmdServer.exe2
Report Id: EasySettingsCmdServer.exe3
Faulting package full name: EasySettingsCmdServer.exe4
Faulting package-relative application ID: EasySettingsCmdServer.exe5
Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
System errors:
=============
Error: (04/30/2015 09:21:09 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 106.
Error: (04/30/2015 07:30:16 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.
Error: (04/30/2015 07:08:07 AM) (Source: DCOM) (EventID: 10010) (User: RDK-SAM-XE500T1)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca
Error: (04/30/2015 07:08:07 AM) (Source: DCOM) (EventID: 10010) (User: RDK-SAM-XE500T1)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca
Error: (04/30/2015 07:08:07 AM) (Source: DCOM) (EventID: 10010) (User: RDK-SAM-XE500T1)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca
Error: (04/30/2015 06:31:07 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Live Malware Protection service terminated unexpectedly. It has done this 1 time(s).
Error: (04/29/2015 05:02:56 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the btwdins service.
Error: (04/28/2015 11:32:24 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WSearch service.
Error: (04/26/2015 00:05:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Software Protection service failed to start due to the following error:
%%1053
Error: (04/26/2015 00:05:53 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Software Protection service to connect.
Microsoft Office Sessions:
=========================
Error: (04/30/2015 08:32:13 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\ExpressCacheRun64.exe
Error: (04/30/2015 08:32:11 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\VendorAPIRun64.exe
Error: (04/30/2015 08:32:10 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\Touchpad\x64\SetTouchpadControl64.exe
Error: (04/30/2015 08:27:51 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\ExpressCacheRun64.exe
Error: (04/30/2015 08:27:48 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\VendorAPIRun64.exe
Error: (04/30/2015 08:27:46 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\Touchpad\x64\SetTouchpadControl64.exe
Error: (04/30/2015 07:31:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: EasySettingsCmdServer.exe0.0.0.05147f18entdll.dll6.3.9600.17736550f42bdc0000374000d09824b001d0834189e5c167C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdServer.exeC:\Windows\SYSTEM32\ntdll.dllc8e76579-ef34-11e4-9747-dc714460f8e7
Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141
Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141
Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141
CodeIntegrity Errors:
===================================
Date: 2015-04-30 07:17:13.361
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-04-30 07:17:13.361
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-03-03 05:01:49.600
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-03-03 05:01:49.588
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-03-02 19:38:16.140
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-03-02 19:38:16.125
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-03-02 19:38:16.093
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-03-02 19:38:16.078
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-03-02 19:38:16.031
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-03-02 19:38:16.015
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Atom(TM) CPU Z2760 @ 1.80GHz
Percentage of memory in use: 55%
Total physical RAM: 1962.45 MB
Available physical RAM: 875.25 MB
Total Pagefile: 3924.45 MB
Available Pagefile: 2646.33 MB
Total Virtual: 2047.88 MB
Available Virtual: 1859.05 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:57.83 GB) (Free:40.35 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 58.3 GB) (Disk ID: 0990F021)
Partition: GPT Partition Type.
==================== End Of Log ============================