This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

BHO i cant get rid of..and maybe other issues [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi yall.. I know..its been a very long time.. hope everyone is well. Ive been away and couldn't be helped.. anyway.. I have a hijack this log and a log from that avast scan… the frst link ( http://api.viglink.com/api/click?format=go&jsonp=vglnk_143039844551217&key=bf4adfcbb328b51c165afd7f95bfc060&libId=i945tkju010000j1000DAxuqv029&loc=http%3A%2F%2Fforums.whatthetech.com%2Findex.php%3Fshowtopic%3D106388&v=1&out=http%3A%2F%2Fwww.geekstogo.com%2Fforum%2Ffiles%2Fgetdownload%2F692-frst-farbars-recovery-scan-tool%2F&ref=http%3A%2F%2Fforums.whatthetech.com%2Findex.php%3Fshowforum%3D116&title=Are%20you%20Infected%3F%20Need%20Help%3F%20-%20What%20the%20Tech&txt=Download%20link%20for%20FRST%2032-bit ) doesn't work..anyway heres logs

 

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 7:34:47 AM, on 4/30/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)

Boot mode: Normal

Running processes:
C:\Windows\system32\taskhostex.exe
C:\Windows\Explorer.EXE
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x86__8wekyb3d8bbwe\LiveComm.exe
C:\Windows\System32\skydrive.exe
C:\Windows\System32\SettingSyncHost.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe
C:\Windows\System32\hsmon.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Users\Koonsman\Desktop\HijackThis.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8118
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SecureWebBHO - {D3C24E2B-C820-4492-9B69-11BF7163F998} - C:\Program Files\Alfasistem Memory\jswie.dll
O4 - HKLM\..\Run: [DptfPolicyLpmServiceHelper] C:\Windows\system32\DptfPolicyLpmServiceHelper.exe
O4 - HKLM\..\Run: [RtkNGUI] C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe /s
O4 - HKLM\..\Run: [IntelHeadphoneMonitor] C:\Windows\system32\hsmon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\RunOnce: [Application Restart #1] C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe "C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe" "C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe" "C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe" -Embedding
O4 - Startup: Dropbox.lnk = C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Bluetooth.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: @oem27.inf,%BcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Broadcom Corporation. - C:\Windows\system32\BtwRSupportService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @oem19.inf,%WIN32_DPTF_PARTICIPANT_DISPLAY_SERVICE_DISPLAY_NAME%;Intel(R) Dynamic Platform & Thermal Framework Display Participant Service Application (DptfParticipantDisplayService) - Intel Corporation - C:\Windows\system32\DptfParticipantDisplayService.exe
O23 - Service: @oem19.inf,%WIN32_DPTF_PARTICIPANT_PROC_SERVICE_DISPLAY_NAME%;Intel(R) Dynamic Platform & Thermal Framework Processor Participant Service Application (DptfParticipantProcessorService) - Intel Corporation - C:\Windows\system32\DptfParticipantProcessorService.exe
O23 - Service: @oem19.inf,%WIN32_DPTF_POLICY_CRITICAL_SERVICE_DISPLAY_NAME%;Intel(R) Dynamic Platform & Thermal Framework Critical Service Application (DptfPolicyCriticalService) - Intel Corporation - C:\Windows\system32\DptfPolicyCriticalService.exe
O23 - Service: @oem19.inf,%WIN32_DPTF_POLICY_LPM_SERVICE_DISPLAY_NAME%;Intel(R) Dynamic Platform & Thermal Framework Low Power Mode Service Application (DptfPolicyLpmService) - Intel Corporation - C:\Windows\system32\DptfPolicyLpmService.exe
O23 - Service: Easy Launcher - Samsung Electronics CO., LTD. - C:\Program Files\Samsung\Settings\CmdServer\EasyLauncher.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Live Malware Protection - SecureSoft - C:\Windows\mlwps.exe
O23 - Service: SamsungConfiguration (SamsungConfigurationWinService) - Unknown owner - C:\Programdata\Samsung\Service\SamsungConfiguration.exe
O23 - Service: Sierra Wireless Service (SwiService) - Sierra Wireless, Inc. - C:\Program Files\Sierra Wireless Inc\Utils\SWIService.exe
O23 - Service: SW Update Service (SWUpdateService) - Samsung Electronics CO., LTD. - C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe

–
End of file - 5596 bytes

 

 

 

this is the log..? doesn't look right but I downloaded updates and scanned and saved log…anyway here it is

 

 

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-04-30 07:43:00
—————————–
07:43:00.619    OS Version: Windows 6.2.9200
07:43:00.619    Number of processors: 4 586 0x3501
07:43:00.619    ComputerName: RDK-SAM-XE500T1  UserName: Koonsman
07:43:15.059    Initialize success
07:43:15.153    VM: initialized successfully
07:43:15.153    VM: Intel CPU virtualization not supported
07:50:13.431    AVAST engine defs: 15043000
07:50:24.034    The log file has been saved successfully to "C:\Users\Koonsman\Desktop\aswMBR.txt"

 

 

thanks is advance yall
 

Welcome Crow

 

It looks like your running Windows 8.1, you will need the 64 bit version of FRST

 

Please download Farbar Recovery Scan Tool and save it to your DESKTOP
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Please make sure All Users is checked
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
  • hey ken…heres the log…(its 32bit…its a tablet..)

     

    FRSTlog

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-04-2015 01
    Ran by [removed] (administrator) on RDK-SAM-XE500T1 on 01-05-2015 02:38:09
    Running from C:\Users\[removed]\Downloads
    [removed] Platform: Microsoft Windows 8.1 (X86) OS Language: English (United States)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    (Intel Corporation) C:\Windows\System32\DptfParticipantDisplayService.exe
    (Microsoft Corporation) C:\Windows\System32\dasHost.exe
    (Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
    (Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
    (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Settings\CmdServer\EasyLauncher.exe
    (SecureSoft) C:\Windows\mlwps.exe
    () C:\ProgramData\Samsung\Service\SamsungConfiguration.exe
    (Sierra Wireless, Inc.) C:\Program Files\Sierra Wireless Inc\Utils\SwiService.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
    () C:\ProgramData\Samsung\William_USB_HUB_SS_Disable.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
    (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Settings\sSettings.exe
    (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
    (Intel Corporation) C:\Windows\System32\igfxext.exe
    (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe
    (Intel(R) Corporation) C:\Windows\System32\hsmon.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
    (Dropbox, Inc.) C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe
    (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Mini S Note\MiniSNoteAgent.exe
    (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
    (Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
    (Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x86__8wekyb3d8bbwe\livecomm.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\…\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [71992 2013-09-03] (Intel Corporation)
    HKLM\…\Run: [RtkNGUI] => C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe [2760408 2013-10-20] (Realtek Semiconductor)
    HKLM\…\Run: [IntelHeadphoneMonitor] => C:\Windows\system32\hsmon.exe [101888 2013-07-03] (Intel(R) Corporation)
    HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
    HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
    HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-04-07] (Apple Inc.)
    HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\…\RunOnce: [Application Restart #1] => C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe [394752 2014-10-28] (Microsoft Corporation)
    HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\Screen_Samsung.scr [23830066 2012-10-29] ()
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-07-28]
    ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
    Startup: C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-03-03]
    ShortcutTarget: Dropbox.lnk -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    ProxyServer: [S-1-5-21-2135967233-3606984290-4105762919-1001] => 127.0.0.1:8118
    HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.msn.com/
    BHO: SecureWebBHO Class -> {D3C24E2B-C820-4492-9B69-11BF7163F998} -> C:\Program Files\Alfasistem Memory\jswie.dll [2015-04-25] (SecureSoft)
    Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.5

    FireFox:
    ========
    FF ProfilePath: C:\Users\Koonsman\AppData\Roaming\Mozilla\Firefox\Profiles\xel5hxa5.default
    FF NewTab: https://gosearch.me/?u=6f0fb051f2933489997ebfe8b072f5d7&c;=up1&src;=hp&inst;=1430355271
    FF DefaultSearchEngine: Google
    FF DefaultSearchEngine.US: Google Default
    FF Homepage: hxxp://www.google.com/
    FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
    FF SearchPlugin: C:\Users\Koonsman\AppData\Roaming\Mozilla\Firefox\Profiles\xel5hxa5.default\searchplugins\google-default.xml [2015-04-27]
    FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\GoSearch.xml [2015-04-29]
    FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
    FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-04-03]

    ========================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [1678040 2013-08-08] (Broadcom Corporation.)
    S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [250880 2014-10-28] (Microsoft Corporation)
    R2 DptfParticipantDisplayService; C:\Windows\system32\DptfParticipantDisplayService.exe [104248 2013-09-03] (Intel Corporation)
    R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [76088 2013-09-03] (Intel Corporation)
    R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [63288 2013-09-03] (Intel Corporation)
    S2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [82232 2013-09-03] (Intel Corporation)
    R2 Easy Launcher; C:\Program Files\Samsung\Settings\CmdServer\EasyLauncher.exe [1594416 2013-03-19] (Samsung Electronics CO., LTD.)
    R2 Live Malware Protection; C:\Windows\mlwps.exe [242688 2015-04-25] (SecureSoft) [File not signed] <==== ATTENTION
    S4 PrivoxyService; C:\Program Files\Alfasistem Memory\privoxy.exe [371200 2015-04-25] (The Privoxy team - www.privoxy.org) [File not signed] <==== ATTENTION
    R2 SamsungConfigurationWinService; C:\Programdata\Samsung\Service\SamsungConfiguration.exe [29744 2013-06-26] ()
    S3 ScDeviceEnum; C:\Windows\System32\ScDeviceEnum.dll [103936 2014-10-28] (Microsoft Corporation)
    R2 SwiService; C:\Program Files\Sierra Wireless Inc\Utils\SWIService.exe [320816 2013-10-25] (Sierra Wireless, Inc.)
    R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3020632 2014-04-04] (Samsung Electronics CO., LTD.)
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [284488 2015-02-03] (Microsoft Corporation)
    S3 WEPHOSTSVC; C:\Windows\system32\wephostsvc.dll [20992 2014-10-28] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22200 2015-02-03] (Microsoft Corporation)
    S3 workfolderssvc; C:\Windows\system32\workfolderssvc.dll [1269248 2014-10-28] (Microsoft Corporation)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R1 BasicRender; C:\Windows\System32\drivers\BasicRender.sys [25600 2014-03-18] (Microsoft Corporation)
    R3 BCMSDH43XX; C:\Windows\system32\DRIVERS\bcmdhd63.sys [833816 2012-10-02] (Broadcom)
    R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [186880 2014-03-18] (Microsoft Corporation)
    R3 BthMini; C:\Windows\System32\Drivers\BTHMINI.sys [23552 2014-10-28] (Microsoft Corporation)
    R3 btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [144600 2013-09-05] (Broadcom Corporation.)
    R3 BtwSerialBus; C:\Windows\system32\DRIVERS\BtwSerialBus.sys [130776 2013-09-10] (Broadcom Corporation.)
    R3 camera; C:\Windows\system32\DRIVERS\camera.sys [207872 2013-09-03] (Intel Corporation)
    R0 ChaabiDriver; C:\Windows\System32\drivers\ChaabiDriver.sys [74256 2013-09-03] (Intel Corporation)
    R0 clvpep; C:\Windows\System32\drivers\clvpep.sys [81648 2013-09-03] (Intel Corporation)
    R3 DptfDevDisplay; C:\Windows\system32\DRIVERS\DptfDevDisplay.sys [44256 2013-09-03] (Intel Corporation)
    R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [49888 2013-09-03] (Intel Corporation)
    R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [69344 2013-09-03] (Intel Corporation)
    R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [163552 2013-09-03] (Intel Corporation)
    S3 GPIO; C:\Windows\System32\drivers\iaiogpio.sys [22016 2013-07-23] (Intel Corporation)
    R3 GPIOCLV; C:\Windows\System32\drivers\GPIOCLV.sys [22016 2013-09-03] (Intel Corporation)
    R3 igdperf32; C:\Windows\system32\DRIVERS\igdperf32.sys [4096 2013-11-20] ()
    R0 inteli2c; C:\Windows\System32\drivers\inteli2c.sys [48880 2013-09-03] (Intel Corporation)
    R3 IntelSST; C:\Windows\system32\drivers\isstrtc.sys [241152 2013-07-03] (Intel(R) Corporation)
    R0 Lm3554; C:\Windows\System32\drivers\lm3554.sys [34816 2013-09-03] (Intel Corporation)
    R0 LNWIPC; C:\Windows\System32\drivers\LNWIPC.sys [25840 2013-09-03] (Intel Corporation)
    R0 MBI; C:\Windows\System32\drivers\MBI.sys [16112 2013-09-03] (Intel Corporation)
    R1 MpKsl09b151c6; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BAB6FA0F-20EB-4AFB-9CAA-D7C6BDCEA567}\MpKsl09b151c6.sys [39464 2015-04-30] (Microsoft Corporation)
    R3 MSICReg; C:\Windows\System32\drivers\MSICReg.sys [17408 2013-09-03] (Intel Corporation)
    R3 mxtBootBridge; C:\Windows\System32\drivers\mxtBootBridge.sys [25088 2012-09-11] (Windows (R) Win 7 DDK provider)
    R3 ov2720; C:\Windows\System32\drivers\ov2720.sys [46592 2013-09-03] (Intel Corporation)
    R3 ov8830; C:\Windows\system32\DRIVERS\ov8830.sys [63488 2013-09-03] (Intel Corporation)
    R3 rtii2sac; C:\Windows\system32\DRIVERS\rtii2sac.sys [142552 2013-10-20] (Realtek Semiconductor Corp.)
    R3 SensorsHIDClassDriver; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)
    R3 SensorsServiceDriver; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)
    R3 spi; C:\Windows\System32\drivers\spi.sys [46592 2013-09-03] (Intel Corporation)
    R3 Uart16550pc; C:\Windows\System32\drivers\Uart16550pc.sys [40960 2013-09-03] (Intel Corporation)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [84800 2015-02-03] (Microsoft Corporation)
    R0 Wof; C:\Windows\system32\Drivers\Wof.sys [138584 2014-06-11] (Microsoft Corporation)
    R3 WUDFSensorLP; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)
    R3 WUDFWpdMtp; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)
    U3 aswMBR; \??\C:\Users\Koonsman\AppData\Local\Temp\aswMBR.sys [X]
    U3 aswVmm; \??\C:\Users\Koonsman\AppData\Local\Temp\aswVmm.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-05-01 02:38 - 2015-05-01 02:38 - 00014215 _____ () C:\Users\Koonsman\Downloads\FRST.txt
    2015-05-01 02:37 - 2015-05-01 02:38 - 00000000 ____D () C:\FRST
    2015-05-01 02:37 - 2015-05-01 02:37 - 02101248 _____ (Farbar) C:\Users\Koonsman\Downloads\FRST64.exe
    2015-05-01 02:37 - 2015-05-01 02:37 - 01140736 _____ (Farbar) C:\Users\Koonsman\Downloads\FRST.exe
    2015-04-30 07:50 - 2015-04-30 07:50 - 00000579 _____ () C:\Users\Koonsman\Desktop\aswMBR.txt
    2015-04-30 07:42 - 2015-04-30 07:42 - 05198336 _____ (AVAST Software) C:\Users\Koonsman\Downloads\aswMBR.exe
    2015-04-30 07:37 - 2015-04-30 07:37 - 00000000 ____D () C:\Users\Koonsman\Desktop\backups
    2015-04-30 07:34 - 2015-04-30 07:34 - 00005597 _____ () C:\Users\Koonsman\Desktop\hijackthis.log
    2015-04-30 07:26 - 2015-04-30 07:26 - 00388608 _____ (Trend Micro Inc.) C:\Users\Koonsman\Desktop\HijackThis.exe
    2015-04-29 19:54 - 2015-04-29 19:54 - 00000000 ____D () C:\Program Files\Common Service
    2015-04-27 20:49 - 2015-04-30 06:33 - 00070144 _____ () C:\Windows\system32\tasks.dll
    2015-04-25 06:32 - 2015-04-25 06:33 - 00000000 ____D () C:\Users\Koonsman\AppData\Local\Updater
    2015-04-25 06:32 - 2015-04-25 06:33 - 00000000 ____D () C:\Program Files\Alfasistem Memory
    2015-04-25 06:32 - 2015-04-25 06:32 - 00803840 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp.exe
    2015-04-25 06:32 - 2015-04-25 06:32 - 00242688 _____ (SecureSoft) C:\Windows\mlwps.exe
    2015-04-25 06:32 - 2015-04-25 06:32 - 00000000 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp
    2015-04-15 18:27 - 2015-04-15 18:27 - 00001765 _____ () C:\Users\Public\Desktop\iTunes.lnk
    2015-04-15 18:27 - 2015-04-15 18:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2015-04-15 18:25 - 2015-04-15 18:27 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
    2015-04-15 18:25 - 2015-04-15 18:27 - 00000000 ____D () C:\Program Files\iTunes
    2015-04-15 18:25 - 2015-04-15 18:25 - 00000000 ____D () C:\Program Files\iPod
    2015-04-15 18:10 - 2015-03-22 17:44 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00330752 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
    2015-04-15 18:10 - 2015-03-14 03:13 - 01124352 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
    2015-04-15 02:44 - 2015-03-12 22:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-04-15 02:44 - 2015-03-12 22:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-04-15 02:44 - 2015-03-12 22:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-04-15 02:44 - 2015-03-12 22:16 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-04-15 02:44 - 2015-03-12 21:50 - 00880128 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
    2015-04-15 02:44 - 2015-03-12 21:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-04-15 02:44 - 2015-03-12 21:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-04-15 02:44 - 2015-03-12 21:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-04-15 02:44 - 2015-03-12 21:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-04-15 02:44 - 2015-03-12 21:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-04-15 02:44 - 2015-03-12 21:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-04-15 02:44 - 2015-03-12 21:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-04-15 02:43 - 2015-03-23 16:45 - 05782848 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-04-15 02:43 - 2015-03-23 16:45 - 01468920 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2015-04-15 02:43 - 2015-03-23 16:45 - 00257216 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
    2015-04-15 02:43 - 2015-03-19 22:25 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-system-events.dll
    2015-04-15 02:43 - 2015-03-19 21:41 - 00369152 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
    2015-04-15 02:43 - 2015-03-19 21:16 - 00749568 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
    2015-04-15 02:43 - 2015-03-14 03:40 - 00125472 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-04-15 02:43 - 2015-03-13 20:14 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-04-15 02:43 - 2015-03-13 20:14 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-04-15 02:43 - 2015-03-13 20:11 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-04-15 02:43 - 2015-03-13 19:59 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-04-15 02:43 - 2015-03-13 19:03 - 03040768 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-04-15 02:43 - 2015-03-13 19:02 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-04-15 02:43 - 2015-03-13 19:02 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-04-15 02:43 - 2015-03-13 19:00 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
    2015-04-15 02:43 - 2015-03-13 18:59 - 00721920 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-04-15 02:43 - 2015-03-13 18:59 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
    2015-04-15 02:43 - 2015-03-13 18:59 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-04-15 02:43 - 2015-03-13 18:55 - 02309120 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-04-15 02:43 - 2015-03-12 21:37 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
    2015-04-15 02:43 - 2015-02-24 03:20 - 00738112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
    2015-04-15 02:42 - 2015-03-04 05:05 - 00279360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
    2015-04-15 02:42 - 2015-03-03 21:19 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
    2015-04-15 02:42 - 2015-02-20 18:24 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
    2015-04-08 07:57 - 2015-04-08 07:57 - 00000000 ___SD () C:\Windows\system32\GWX

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-05-01 01:11 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\system32\sru
    2015-04-30 09:01 - 2014-07-28 01:33 - 01060356 _____ () C:\Windows\WindowsUpdate.log
    2015-04-30 08:17 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\Microsoft.NET
    2015-04-30 07:36 - 2014-03-18 03:01 - 00818732 _____ () C:\Windows\system32\PerfStringBackup.INI
    2015-04-30 07:32 - 2015-03-03 05:32 - 00000000 ___RD () C:\Users\Koonsman\Dropbox
    2015-04-30 07:32 - 2015-03-03 05:24 - 00000000 ____D () C:\Users\Koonsman\AppData\Roaming\Dropbox
    2015-04-30 07:32 - 2014-07-28 01:18 - 00000000 ___DO () C:\Users\Koonsman\OneDrive
    2015-04-30 07:31 - 2013-08-22 02:23 - 00027333 _____ () C:\Windows\setupact.log
    2015-04-30 07:31 - 2013-08-22 02:23 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2015-04-30 07:31 - 2013-08-22 01:13 - 00262144 ___SH () C:\Windows\system32\config\BBI
    2015-04-30 07:17 - 2014-07-28 01:34 - 00000000 ____D () C:\Users\Koonsman\AppData\Local\VirtualStore
    2015-04-30 07:09 - 2015-03-03 05:40 - 00000000 ____D () C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth
    2015-04-30 06:34 - 2014-07-28 01:34 - 00001341 _____ () C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-04-30 06:26 - 2015-02-24 09:28 - 00000000 ____D () C:\Program Files\Mozilla Firefox
    2015-04-30 06:26 - 2014-03-18 02:48 - 00016616 _____ () C:\Windows\PFRO.log
    2015-04-30 06:23 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\AppCompat
    2015-04-30 06:19 - 2014-12-13 12:04 - 00000000 ____D () C:\Windows\system32\appraiser
    2015-04-30 06:19 - 2014-07-30 16:21 - 00000000 ___SD () C:\Windows\system32\CompatTel
    2015-04-30 06:08 - 2014-11-03 10:51 - 00000000 ____D () C:\Users\Koonsman\AppData\Local\Unity
    2015-04-25 05:15 - 2015-03-03 05:32 - 00001038 _____ () C:\Users\Koonsman\Desktop\Dropbox.lnk
    2015-04-25 05:15 - 2015-03-03 05:27 - 00000000 ____D () C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
    2015-04-24 18:03 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\AppReadiness
    2015-04-22 02:16 - 2013-08-22 03:05 - 00000000 ____D () C:\Windows\CbsTemp
    2015-04-17 19:48 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\rescache
    2015-04-16 06:11 - 2014-07-30 16:20 - 00000000 ____D () C:\Windows\system32\MRT
    2015-04-16 06:07 - 2014-07-30 16:20 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-04-15 18:25 - 2014-08-02 14:01 - 00000000 ____D () C:\Program Files\Common Files\Apple
    2015-04-13 18:24 - 2015-03-16 13:49 - 00792056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
    2015-04-13 18:24 - 2015-03-16 13:49 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl

    ==================== Files in the root of some directories =======

    2015-04-25 06:32 - 2015-04-25 06:32 - 0000000 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp
    2015-04-25 06:32 - 2015-04-25 06:32 - 0803840 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp.exe
    2015-04-27 20:51 - 2015-04-27 20:51 - 0009662 _____ () C:\Users\Koonsman\AppData\Roaming\em_64x64.ico
    2014-08-06 10:44 - 2014-08-06 10:44 - 0007605 _____ () C:\Users\Koonsman\AppData\Local\resmon.resmoncfg

    Some content of TEMP:
    ====================
    C:\Users\Koonsman\AppData\Local\Temp\41AA.tmp.exe
    C:\Users\Koonsman\AppData\Local\Temp\41AB.tmp.exe
    C:\Users\Koonsman\AppData\Local\Temp\447E.tmp.exe
    C:\Users\Koonsman\AppData\Local\Temp\447F.tmp.exe
    C:\Users\Koonsman\AppData\Local\Temp\44AF.tmp.exe
    C:\Users\Koonsman\AppData\Local\Temp\560.tmp.exe
    C:\Users\Koonsman\AppData\Local\Temp\6B3.tmp.exe
    C:\Users\Koonsman\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkaa69u.dll
    C:\Users\Koonsman\AppData\Local\Temp\GPUpd553EE7BD0.exe
    C:\Users\Koonsman\AppData\Local\Temp\GPUpd553EE7BF2.exe
    C:\Users\Koonsman\AppData\Local\Temp\GPUpd553EE7C03.exe
    C:\Users\Koonsman\AppData\Local\Temp\GPUpd55417D450.exe
    C:\Users\Koonsman\AppData\Local\Temp\tasks.dll

    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2015-04-28 06:55

    ==================== End Of Log ============================

     

     

    additional

     

    Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-04-2015 01
    Ran by [removed] at 2015-05-01 02:39:23
    Running from C:\Users\[removed]\Downloads
    Boot Mode: Normal
    ==========================================================

    ==================== Accounts: =============================

    Administrator (S-1-5-21-2135967233-3606984290-4105762919-500 - Administrator - Disabled)
    Guest (S-1-5-21-2135967233-3606984290-4105762919-501 - Limited - Disabled)
    Koonsman (S-1-5-21-2135967233-3606984290-4105762919-1001 - Administrator - Enabled) => C:\Users\Koonsman

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Apple Application Support (32-bit) (HKLM\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
    Apple Mobile Device Support (HKLM\…\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
    Dropbox (HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\…\Dropbox) (Version: 3.4.4 - Dropbox, Inc.)
    iCloud (HKLM\…\{760BB327-3973-4608-85C8-88162E2FF3B6}) (Version: 4.0.6.28 - Apple Inc.)
    Intel(R) Processor Graphics (HKLM\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.14.3.1177 - Intel Corporation)
    iTunes (HKLM\…\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.)
    Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Mini S Note (HKLM\…\{D3D81CA0-B970-43A0-ACD0-DC7A36B85910}) (Version: 1.0.28.3 - Samsung Electronics CO. LTD)
    myVapors (HKLM\…\{FD719CB3-73F1-478A-8A13-92586FBB669C}) (Version: 1.00.0000 - Joyetech)
    QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
    Realtek I2S Audio (HKLM\…\{89A448AA-3301-46AA-AFC3-34F2D7C670E8}) (Version: 6.2.9600.3082 - Realtek Semiconductor Corp.)
    S Agent (Version: 1.1.47 - Samsung Electronics CO., LTD.) Hidden
    Samsung Kies3 (HKLM\…\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.)
    Samsung Kies3 (Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.) Hidden
    Settings (HKLM\…\{8CB5C357-12E5-41B1-A024-D57D4E6F32D9}) (Version: 2.0.1 - Samsung Electronics CO., LTD.)
    Sierra Wireless Mobile Broadband Driver Package (HKLM\…\SWIQMIDrvInstaller) (Version: 3.11.1310.3981 - Sierra Wireless, Inc.)
    SW Update (HKLM\…\{DA06101F-FD76-4BF0-88BD-B26A197005E3}) (Version: 2.1.21 - Samsung Electronics CO., LTD.)
    WIDCOMM Bluetooth Software (HKLM\…\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.8030 - Broadcom Corporation)
    Windows Driver Package - Broadcom (bcmfn2) System  (08/30/2012 20.43.14.119) (HKLM\…\8ACEFA31AC73553F5EEFA5785AD8D4D0E850401F) (Version: 08/30/2012 20.43.14.119 - Broadcom)
    Windows Driver Package - Broadcom (BCMSDH43XX) Net  (09/28/2012 5.93.97.76) (HKLM\…\D5631A91EBAF24FAF75D27148329D007EA6B8580) (Version: 09/28/2012 5.93.97.76 - Broadcom)
    Windows Driver Package - Nuvoton Technology Corporation (WUDFRd) System  (05/20/2013 8.1.111.5007) (HKLM\…\74C44B2BCC752410B3995F9DD1E138E6170380DF) (Version: 05/20/2013 8.1.111.5007 - Nuvoton Technology Corporation)

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)

    ==================== Restore Points  =========================

    ATTENTION: System Restore is disabled.

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2015-04-30 07:29 - 2015-04-30 07:29 - 00000797 ____A C:\Windows\system32\Drivers\etc\hosts

    ==================== Scheduled Tasks (whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

    Task: {039231BB-BDC6-4F5B-BD3D-F39747444F31} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-23] (Microsoft Corporation)
    Task: {19677A92-0F41-4D37-9CEB-9665F0725659} - System32\Tasks\Settings => C:\Program Files\Samsung\Settings\sSettings.exe [2013-03-19] (Samsung Electronics CO., LTD.)
    Task: {253E7A9D-638D-450D-BDB4-4A14C309B087} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-03-19] (Samsung Electronics CO., LTD.)
    Task: {267A9B11-8FB2-4458-AEAD-F9DCD15F4EF1} - System32\Tasks\TP_SS_D => C:ProgramData\Samsung\William_USB_HUB_SS_Disable.exe
    Task: {3DA74E6F-1452-4EB4-9D3C-74FAA60D5659} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
    Task: {6CD14856-E0B9-4C78-984B-2251D0113040} - System32\Tasks\Common Service Job => C:\Program Files\Common Service\CommonService.exe [2015-04-29] (Secure Updater)
    Task: {7F43AA89-F04C-484A-880F-3087AE94BEF2} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
    Task: {8C7D7F24-C593-4740-B118-2A61D6F3871D} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
    Task: {AC038432-5CA6-4865-867B-49460FEBCE99} - System32\Tasks\SNoteAgent => C:\Program Files\Samsung\Mini S Note\MiniSNoteAgent.exe [2013-04-06] (Samsung Electronics CO., LTD.)
    Task: {CD0541C1-3EC9-4614-8E6C-0871FC6119F8} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {CF7175A6-D34A-493F-82CC-D454AFC14836} - System32\Tasks\Malware Cleaner => C:\Users\Koonsman\AppData\Roaming\48E2.tmp.exe [2015-04-25] () <==== ATTENTION
    Task: {D85249D7-4565-4718-B4D3-BCE2379FC533} - System32\Tasks\Alfasistem Memory Job => C:\Program Files\Alfasistem Memory\ tmjob.exe [2015-04-25] (SecureSoft)
    Task: {E8A13984-065D-4EAC-A0D6-F57D41519A5B} - System32\Tasks\Windows Defrag => C:\Users\Koonsman\AppData\Local\Updater\winupd.exe [2015-04-25] ()
    Task: {FB0E22DE-F12C-4203-8ADE-B5445C59DAD9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-04-16] (Microsoft Corporation)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    ==================== Loaded Modules (whitelisted) ==============

    2013-03-19 16:11 - 2013-03-19 16:11 - 00211064 _____ () C:\Program Files\Samsung\Settings\CmdServer\WinCRT.dll
    2014-07-03 13:20 - 2014-07-03 13:20 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2015-01-20 23:35 - 2015-01-20 23:35 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2013-09-25 16:21 - 2013-09-25 16:21 - 00044760 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btwleapi.dll
    2014-07-28 02:42 - 2013-06-26 12:18 - 00029744 _____ () C:\Programdata\Samsung\Service\SamsungConfiguration.exe
    2013-03-19 16:11 - 2013-03-19 16:11 - 00085040 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
    2013-03-19 16:10 - 2013-03-19 16:10 - 00029232 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll
    2013-03-19 16:11 - 2013-03-19 16:11 - 01121328 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmd.dll
    2013-03-19 16:11 - 2013-03-19 16:11 - 00111152 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsBase.dll
    2013-03-19 16:11 - 2013-03-19 16:11 - 00056440 _____ () C:\Program Files\Samsung\Settings\CmdServer\HookDllPS2.dll
    2014-07-28 01:07 - 2013-10-29 20:16 - 01737096 _____ () C:\ProgramData\Samsung\William_USB_HUB_SS_Disable.exe
    2013-03-19 16:10 - 2013-03-19 16:10 - 00027184 _____ () C:\Program Files\Samsung\Settings\EasySettingsAPI.dll
    2013-03-19 16:11 - 2013-03-19 16:11 - 00111152 _____ () C:\Program Files\Samsung\Settings\EasySettingsBase.dll
    2013-03-19 16:11 - 2013-03-19 16:11 - 00060976 _____ () C:\Program Files\Samsung\Settings\EasyMovieEnhancer.dll
    2013-03-19 16:10 - 2013-03-19 16:10 - 00103984 _____ () C:\Program Files\Samsung\Settings\EasySettingsCmdClient.dll
    2015-04-30 07:32 - 2015-04-30 07:32 - 00043008 _____ () c:\users\koonsman\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkaa69u.dll
    2015-03-04 16:45 - 2015-03-04 16:45 - 00750080 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\libGLESv2.dll
    2015-03-04 16:45 - 2015-03-04 16:45 - 00047616 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\libEGL.dll
    2015-03-04 16:45 - 2015-03-04 16:45 - 00865280 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
    2015-03-04 16:45 - 2015-03-04 16:45 - 00200704 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
    2014-03-19 11:39 - 2014-03-19 11:39 - 00081456 _____ () C:\Program Files\Samsung\S Agent\ToastDLL.dll
    2014-11-29 12:30 - 2014-11-29 12:31 - 00143360 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x86__8wekyb3d8bbwe\ErrorReporting.dll

    ==================== Alternate Data Streams (whitelisted) =========

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

    AlternateDataStreams: C:\Windows\Samsung.png:ms-properties
    AlternateDataStreams: C:\Windows\Screen_Samsung.scr:ms-properties
    AlternateDataStreams: C:\Users\Koonsman\OneDrive:ms-properties

    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\gpioclv.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\inteli2c.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lnwipc.sys => ""="Driver"

    ==================== EXE Association (whitelisted) ===============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, the associated entry will be removed from the registry.)

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Koonsman\Pictures\20140827_172915.jpg
    DNS Servers: 192.168.1.5

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    HKLM\…\StartupApproved\Run: => "Persistence"
    HKLM\…\StartupApproved\Run: => "iTunesHelper"
    HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\…\StartupApproved\Run: => "NetMon"

    ==================== FirewallRules (whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [{AB9576D0-3789-4BBE-B91D-7E299426EDEF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{F05C7C44-1B78-4D18-B9CE-B7795C4737AA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{B63CE1EE-C23A-4174-A90D-1939994192AC}] => (Allow) C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe
    FirewallRules: [{344BD084-7F91-4165-BCF3-CE426726D30E}] => (Allow) C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe
    FirewallRules: [TCP Query User{EDDAF735-1009-4821-9EA9-C64832641724}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
    FirewallRules: [UDP Query User{8C523F64-9446-4B31-8C23-43EFF71478C6}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
    FirewallRules: [{020BBDAD-41F7-496F-86C7-0E04B54BB6FE}] => (Allow) C:\Program Files\iTunes\iTunes.exe

    ==================== Faulty Device Manager Devices =============

    Name: I2C HID Device
    Description: I2C HID Device
    Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
    Manufacturer: Microsoft
    Service: hidi2c
    Problem: : Windows has stopped this device because it has reported problems. (Code 43)
    Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.

    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (04/30/2015 08:32:13 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 08:32:11 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 08:32:10 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 08:27:51 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 08:27:48 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 08:27:46 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 07:31:12 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: EasySettingsCmdServer.exe, version: 0.0.0.0, time stamp: 0x5147f18e
    Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f42bd
    Exception code: 0xc0000374
    Fault offset: 0x000d0982
    Faulting process id: 0x4b0
    Faulting application start time: 0xEasySettingsCmdServer.exe0
    Faulting application path: EasySettingsCmdServer.exe1
    Faulting module path: EasySettingsCmdServer.exe2
    Report Id: EasySettingsCmdServer.exe3
    Faulting package full name: EasySettingsCmdServer.exe4
    Faulting package-relative application ID: EasySettingsCmdServer.exe5

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    System errors:
    =============
    Error: (04/30/2015 09:21:09 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 106.

    Error: (04/30/2015 07:30:16 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
    Description: There was an error while attempting to read the local hosts file.

    Error: (04/30/2015 07:08:07 AM) (Source: DCOM) (EventID: 10010) (User: RDK-SAM-XE500T1)
    Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca

    Error: (04/30/2015 07:08:07 AM) (Source: DCOM) (EventID: 10010) (User: RDK-SAM-XE500T1)
    Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca

    Error: (04/30/2015 07:08:07 AM) (Source: DCOM) (EventID: 10010) (User: RDK-SAM-XE500T1)
    Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca

    Error: (04/30/2015 06:31:07 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Live Malware Protection service terminated unexpectedly.  It has done this 1 time(s).

    Error: (04/29/2015 05:02:56 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the btwdins service.

    Error: (04/28/2015 11:32:24 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WSearch service.

    Error: (04/26/2015 00:05:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Software Protection service failed to start due to the following error:
    %%1053

    Error: (04/26/2015 00:05:53 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
    Description: A timeout was reached (30000 milliseconds) while waiting for the Software Protection service to connect.

    Microsoft Office Sessions:
    =========================
    Error: (04/30/2015 08:32:13 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\ExpressCacheRun64.exe

    Error: (04/30/2015 08:32:11 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\VendorAPIRun64.exe

    Error: (04/30/2015 08:32:10 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\Touchpad\x64\SetTouchpadControl64.exe

    Error: (04/30/2015 08:27:51 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\ExpressCacheRun64.exe

    Error: (04/30/2015 08:27:48 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\VendorAPIRun64.exe

    Error: (04/30/2015 08:27:46 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\Touchpad\x64\SetTouchpadControl64.exe

    Error: (04/30/2015 07:31:12 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: EasySettingsCmdServer.exe0.0.0.05147f18entdll.dll6.3.9600.17736550f42bdc0000374000d09824b001d0834189e5c167C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdServer.exeC:\Windows\SYSTEM32\ntdll.dllc8e76579-ef34-11e4-9747-dc714460f8e7

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

    CodeIntegrity Errors:
    ===================================
      Date: 2015-04-30 07:17:13.361
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-04-30 07:17:13.361
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-03-03 05:01:49.600
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-03-03 05:01:49.588
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-03-02 19:38:16.140
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-03-02 19:38:16.125
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-03-02 19:38:16.093
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-03-02 19:38:16.078
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-03-02 19:38:16.031
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-03-02 19:38:16.015
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    ==================== Memory info ===========================

    Processor: Intel(R) Atom(TM) CPU Z2760 @ 1.80GHz
    Percentage of memory in use: 55%
    Total physical RAM: 1962.45 MB
    Available physical RAM: 875.25 MB
    Total Pagefile: 3924.45 MB
    Available Pagefile: 2646.33 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1859.05 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:57.83 GB) (Free:40.35 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 58.3 GB) (Disk ID: 0990F021)

    Partition: GPT Partition Type.

    ==================== End Of Log ============================

    by the way… tell tashi and LDtate and doug and everyone else I said hello please sir… they will know me…thanks again for your help

    Morning Crow, I will tell them, I relocated back to Florida a few years ago and see Rich (Zdtruker) on occasion

     

    I see some bad things going on on your system, what I like to do is run some tools to remove as much as they can and then do a final clean up with FRST on any leftovers I see. 

     

    Your running FRST from your downloads folder, our tools and scanners work more efficiently when run from the Desktop in lieu of being buried in some folder, so go to your Downloads folder and look for FRST, right click on it and select CUT, then come back to your Desktop and right click on a blank space and select PASTE, then we will have FRST exactly where we want it to be. 

     

     

    Download MiniToolBox and save it to your desktop,  right click on it and select RUN AS ADMINISTRATOR
     
    Checkmark the following boxes:
    •  
    • Flush DNS 
    • Reset IE Proxy Settings 
     
     
    Click Go and post the result (Result.txt) that pops up. A copy of result.txt will be saved in the same directory the tool is run.
     
     
     
     
    =============================================================
     
     
     

     
    -AdwCleaner-by Xplode
     
    Click on this link to download : ADWCleaner To your Desktop
    Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
    Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
     
     
    Do not click on any links in the top Advertisment.
     
    [external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
     
    •  
    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Scan.
    • After the scan is complete click on "Clean"
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the content of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.
     
     
     
    ===============================================================================
     
     
    [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
    •  
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
     
     
     
     
    ===============================================================================
     
    Download Malwarebytes' Anti-Malware  to your desktop. <———
     
    •  
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
     
     
     
    [external image: MBAM2010601022_zpsyvzbaddn.jpg]
     
    •  
    • On the Dashboard click on Update Now
    • Go to the Setting Tab
    • Under Setting go to Detection and Protection
    • Under PUP and PUM make sure both are set to show Treat Detections as Malware
    • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
    • Then on the Dashboard click on Scan
    • Make sure to select THREAT SCAN
    • Then click on Scan
    • When the scan is finished and the log pops up…select Copy to Clipboard
    • Please paste the log back into this thread for review
    • Exit Malwarebytes
     

     

    I can do some of that from the command line.. but I will use the tools…and post back when I get done.. hope you are well.. its been awhile since ive talked to anyone..

    I had to flush the dns and then change the host file just in order to get here…anyway here is that report

    MiniToolBox by Farbar  Version: 14-04-2015
    Ran by [removed] (administrator) on 01-05-2015 at 18:28:19
    Running from "C:\Users\Koonsman\Desktop"
    Microsoft Windows 8.1  (X86)
    Model: 500T Manufacturer: SAMSUNG ELECTRONICS CO., LTD.
    Boot Mode: Normal
    ***************************************************************************

    ========================= Flush DNS: ===================================

    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    "Reset IE Proxy Settings": IE Proxy Settings were reset.

    **** End of log ****

    # AdwCleaner v4.203 - Logfile created 01/05/2015 at 18:35:42
    # Updated 30/04/2015 by Xplode
    # Database : 2015-04-30.2 [Server]
    # Operating system : Windows 8.1  (x86)
    # Username : Koonsman - RDK-SAM-XE500T1
    # Running from : C:\Users\Koonsman\Desktop\adwcleaner_4.203.exe
    # Option : Cleaning

    ***** [ Services ] *****

    [#] Service Deleted : Live Malware Protection
    [#] Service Deleted : PrivoxyService

    ***** [ Files / Folders ] *****

    Folder Deleted : C:\Users\Koonsman\AppData\Local\Updater
    File Deleted : C:\Windows\mlwps.exe
    File Deleted : C:\Program Files\Mozilla Firefox\browser\searchplugins\GoSearch.xml
    File Deleted : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js

    ***** [ Scheduled tasks ] *****

    Task Deleted : Malware Cleaner

    ***** [ Shortcuts ] *****

    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D3C24E2B-C820-4492-9B69-11BF7163F998}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3C24E2B-C820-4492-9B69-11BF7163F998}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3C24E2B-C820-4492-9B69-11BF7163F998}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D3C24E2B-C820-4492-9B69-11BF7163F998}
    Key Deleted : HKCU\Software\NetMon
    Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

    ***** [ Web browsers ] *****

    -\\ Internet Explorer v11.0.9600.17416

    -\\ Mozilla Firefox v

    [xel5hxa5.default\prefs.js] - Line Deleted : user_pref("browser.newtab.url", "hxxps://gosearch.me/?u=6f0fb051f2933489997ebfe8b072f5d7&c=up1&src=hp&inst=1430355271");

    *************************

    AdwCleaner[R0].txt - [2293 bytes] - [01/05/2015 18:33:45]
    AdwCleaner[S0].txt - [2275 bytes] - [01/05/2015 18:35:42]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2334  bytes] ##########

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.6.7 (04.30.2015:1)
    OS: Windows 8.1 x86
    Ran by [removed] on Fri 05/01/2015 at 18:41:11.93
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

     

    ~~~ Services

     

    ~~~ Tasks

    Successfully deleted: [Task] C:\Windows\System32\tasks\Optimize Start Menu Cache Files-S-1-5-21-2135967233-3606984290-4105762919-1001

     

    ~~~ Registry Values

     

    ~~~ Registry Keys

     

    ~~~ Files

     

    ~~~ Folders

     

     

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on Fri 05/01/2015 at 18:44:21.73
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 5/1/2015
    Scan Time: 6:50:35 PM
    Logfile:
    Administrator: Yes

    Version: 2.01.6.1022
    Malware Database: v2015.05.01.07
    Rootkit Database: v2015.04.21.01
    License: Trial
    Malware Protection: Enabled
    Malicious Website Protection: Enabled
    Self-protection: Disabled

    OS: Windows 8.1
    CPU: x86
    File System: NTFS
    User: Koonsman

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 297796
    Time Elapsed: 15 min, 15 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 0
    (No malicious items detected)

    Modules: 0
    (No malicious items detected)

    Registry Keys: 0
    (No malicious items detected)

    Registry Values: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Folders: 0
    (No malicious items detected)

    Files: 9
    Trojan.Downloader, C:\Users\Koonsman\AppData\Roaming\48E2.tmp.exe, Quarantined, [f982632bc8c21e18d2abba886c9706fa],
    Trojan.Agent, C:\Windows\System32\tasks.dll, Quarantined, [94e7ade1fe8c1224c6b30a3841c2926e],
    Trojan.Downloader, C:\Users\Koonsman\AppData\Local\Temp\41AB.tmp.exe, Quarantined, [e794a6e899f1f442edfa2e1d6d950df3],
    Trojan.Agent, C:\Users\Koonsman\AppData\Local\Temp\tasks.dll, Quarantined, [007b2866c5c5b581e891a89af211669a],
    PUP.Optional.OpenCandy, C:\Users\Koonsman\AppData\Local\Temp\utt48F.tmp, Quarantined, [6417325c5634ac8afe70d2642adce21e],
    Trojan.Downloader, C:\Users\Koonsman\AppData\Local\Temp\447F.tmp.exe, Quarantined, [a7d4cac4494137ff05e281ca8b778d73],
    Trojan.Downloader, C:\Users\Koonsman\AppData\Local\Temp\44AF.tmp.exe, Quarantined, [aad189055d2de6507177cb80828007f9],
    Trojan.Dropper, C:\Users\Koonsman\AppData\Local\Temp\560.tmp.exe, Quarantined, [b6c5cbc37911a195a2cbb0c519e79868],
    Trojan.Dropper, C:\Users\Koonsman\AppData\Local\Temp\6B3.tmp.exe, Quarantined, [5a2197f7ef9b52e46805532257a98e72],

    Physical Sectors: 0
    (No malicious items detected)

    (end)

    ok sir… that looks pretty good to me. What do you need next..? (I knew when I got my tablet back and the first thing I seen was utorrent on my desktop I was in trouble…anyway I am at your mercy sir just tell me what you need next..if anything)

    Crow,  almost anything downloaded via the torrents are infected, not all but most are.

     

    Your cleaning up quite well. Open up FRST, put  a checkmark in Additions, run a new scan and post both new logs please

    yessir…its what I get for letting others use my things…ugh…

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-04-2015 01
    Ran by [removed] (administrator) on RDK-SAM-XE500T1 on 01-05-2015 20:10:22
    Running from C:\Users\[removed]\Desktop
    [removed] Platform: Microsoft Windows 8.1 (X86) OS Language: English (United States)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    (Intel Corporation) C:\Windows\System32\DptfParticipantDisplayService.exe
    (Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
    (Microsoft Corporation) C:\Windows\System32\dasHost.exe
    (Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
    (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Settings\CmdServer\EasyLauncher.exe
    () C:\ProgramData\Samsung\Service\SamsungConfiguration.exe
    (Sierra Wireless, Inc.) C:\Program Files\Sierra Wireless Inc\Utils\SwiService.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
    (Intel Corporation) C:\Windows\System32\igfxext.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
    () C:\ProgramData\Samsung\William_USB_HUB_SS_Disable.exe
    (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
    (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Settings\sSettings.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe
    (Intel(R) Corporation) C:\Windows\System32\hsmon.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
    (Dropbox, Inc.) C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe
    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
    (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Mini S Note\MiniSNoteAgent.exe
    (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
    (Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\…\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [71992 2013-09-03] (Intel Corporation)
    HKLM\…\Run: [RtkNGUI] => C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe [2760408 2013-10-20] (Realtek Semiconductor)
    HKLM\…\Run: [IntelHeadphoneMonitor] => C:\Windows\system32\hsmon.exe [101888 2013-07-03] (Intel(R) Corporation)
    HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
    HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
    HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-04-07] (Apple Inc.)
    HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\…\RunOnce: [Application Restart #1] => C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe [394752 2014-10-28] (Microsoft Corporation)
    HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\Screen_Samsung.scr [23830066 2012-10-29] ()
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-07-28]
    ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
    Startup: C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-03-03]
    ShortcutTarget: Dropbox.lnk -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.msn.com/
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.5

    FireFox:
    ========
    FF ProfilePath: C:\Users\Koonsman\AppData\Roaming\Mozilla\Firefox\Profiles\xel5hxa5.default
    FF DefaultSearchEngine: Google
    FF DefaultSearchEngine.US: Google Default
    FF Homepage: hxxp://www.google.com/
    FF NetworkProxy: "type", 5
    FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
    FF SearchPlugin: C:\Users\Koonsman\AppData\Roaming\Mozilla\Firefox\Profiles\xel5hxa5.default\searchplugins\google-default.xml [2015-04-27]
    FF Extension: Firefox Helper - C:\Program Files\Mozilla Firefox\distribution\bundles\6f0fb051f2933489997ebfe8b072f5d7 [2015-05-01]
    FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]

    ========================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [1678040 2013-08-08] (Broadcom Corporation.)
    S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [250880 2014-10-28] (Microsoft Corporation)
    R2 DptfParticipantDisplayService; C:\Windows\system32\DptfParticipantDisplayService.exe [104248 2013-09-03] (Intel Corporation)
    R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [76088 2013-09-03] (Intel Corporation)
    R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [63288 2013-09-03] (Intel Corporation)
    S2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [82232 2013-09-03] (Intel Corporation)
    R2 Easy Launcher; C:\Program Files\Samsung\Settings\CmdServer\EasyLauncher.exe [1594416 2013-03-19] (Samsung Electronics CO., LTD.)
    S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
    S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
    R2 SamsungConfigurationWinService; C:\Programdata\Samsung\Service\SamsungConfiguration.exe [29744 2013-06-26] ()
    S3 ScDeviceEnum; C:\Windows\System32\ScDeviceEnum.dll [103936 2014-10-28] (Microsoft Corporation)
    R2 SwiService; C:\Program Files\Sierra Wireless Inc\Utils\SWIService.exe [320816 2013-10-25] (Sierra Wireless, Inc.)
    R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3020632 2014-04-04] (Samsung Electronics CO., LTD.)
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [284488 2015-02-03] (Microsoft Corporation)
    S3 WEPHOSTSVC; C:\Windows\system32\wephostsvc.dll [20992 2014-10-28] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22200 2015-02-03] (Microsoft Corporation)
    S3 workfolderssvc; C:\Windows\system32\workfolderssvc.dll [1269248 2014-10-28] (Microsoft Corporation)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R1 BasicRender; C:\Windows\System32\drivers\BasicRender.sys [25600 2014-03-18] (Microsoft Corporation)
    R3 BCMSDH43XX; C:\Windows\system32\DRIVERS\bcmdhd63.sys [833816 2012-10-02] (Broadcom)
    R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [186880 2014-03-18] (Microsoft Corporation)
    R3 BthMini; C:\Windows\System32\Drivers\BTHMINI.sys [23552 2014-10-28] (Microsoft Corporation)
    R3 btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [144600 2013-09-05] (Broadcom Corporation.)
    R3 BtwSerialBus; C:\Windows\system32\DRIVERS\BtwSerialBus.sys [130776 2013-09-10] (Broadcom Corporation.)
    R3 camera; C:\Windows\system32\DRIVERS\camera.sys [207872 2013-09-03] (Intel Corporation)
    R0 ChaabiDriver; C:\Windows\System32\drivers\ChaabiDriver.sys [74256 2013-09-03] (Intel Corporation)
    R0 clvpep; C:\Windows\System32\drivers\clvpep.sys [81648 2013-09-03] (Intel Corporation)
    R3 DptfDevDisplay; C:\Windows\system32\DRIVERS\DptfDevDisplay.sys [44256 2013-09-03] (Intel Corporation)
    R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [49888 2013-09-03] (Intel Corporation)
    R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [69344 2013-09-03] (Intel Corporation)
    R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [163552 2013-09-03] (Intel Corporation)
    S3 GPIO; C:\Windows\System32\drivers\iaiogpio.sys [22016 2013-07-23] (Intel Corporation)
    R3 GPIOCLV; C:\Windows\System32\drivers\GPIOCLV.sys [22016 2013-09-03] (Intel Corporation)
    R3 igdperf32; C:\Windows\system32\DRIVERS\igdperf32.sys [4096 2013-11-20] ()
    R0 inteli2c; C:\Windows\System32\drivers\inteli2c.sys [48880 2013-09-03] (Intel Corporation)
    R3 IntelSST; C:\Windows\system32\drivers\isstrtc.sys [241152 2013-07-03] (Intel(R) Corporation)
    R0 Lm3554; C:\Windows\System32\drivers\lm3554.sys [34816 2013-09-03] (Intel Corporation)
    R0 LNWIPC; C:\Windows\System32\drivers\LNWIPC.sys [25840 2013-09-03] (Intel Corporation)
    S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
    R0 MBI; C:\Windows\System32\drivers\MBI.sys [16112 2013-09-03] (Intel Corporation)
    R3 MSICReg; C:\Windows\System32\drivers\MSICReg.sys [17408 2013-09-03] (Intel Corporation)
    R3 mxtBootBridge; C:\Windows\System32\drivers\mxtBootBridge.sys [25088 2012-09-11] (Windows (R) Win 7 DDK provider)
    R3 ov2720; C:\Windows\System32\drivers\ov2720.sys [46592 2013-09-03] (Intel Corporation)
    R3 ov8830; C:\Windows\system32\DRIVERS\ov8830.sys [63488 2013-09-03] (Intel Corporation)
    R3 rtii2sac; C:\Windows\system32\DRIVERS\rtii2sac.sys [142552 2013-10-20] (Realtek Semiconductor Corp.)
    R3 SensorsHIDClassDriver; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)
    R3 SensorsServiceDriver; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)
    R3 spi; C:\Windows\System32\drivers\spi.sys [46592 2013-09-03] (Intel Corporation)
    R3 Uart16550pc; C:\Windows\System32\drivers\Uart16550pc.sys [40960 2013-09-03] (Intel Corporation)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [84800 2015-02-03] (Microsoft Corporation)
    R0 Wof; C:\Windows\system32\Drivers\Wof.sys [138584 2014-06-11] (Microsoft Corporation)
    R3 WUDFSensorLP; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)
    R3 WUDFWpdMtp; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-28] (Microsoft Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-05-01 20:10 - 2015-05-01 20:11 - 00013906 _____ () C:\Users\Koonsman\Desktop\FRST.txt
    2015-05-01 18:50 - 2015-05-01 19:07 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2015-05-01 18:49 - 2015-05-01 18:49 - 00001076 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-05-01 18:49 - 2015-05-01 18:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-05-01 18:48 - 2015-05-01 18:49 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
    2015-05-01 18:48 - 2015-05-01 18:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2015-05-01 18:48 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2015-05-01 18:48 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2015-05-01 18:48 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2015-05-01 18:46 - 2015-05-01 18:47 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Koonsman\Desktop\mbam-setup-2.1.6.1022.exe
    2015-05-01 18:44 - 2015-05-01 18:44 - 00000737 _____ () C:\Users\Koonsman\Desktop\JRT.txt
    2015-05-01 18:41 - 2015-05-01 18:41 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-RDK-SAM-XE500T1-Windows-8.1-(32-bit).dat
    2015-05-01 18:41 - 2015-05-01 18:41 - 00000000 ____D () C:\RegBackup
    2015-05-01 18:39 - 2015-05-01 18:39 - 02716306 _____ (Thisisu) C:\Users\Koonsman\Desktop\JRT.exe
    2015-05-01 18:33 - 2015-05-01 18:35 - 00000000 ____D () C:\AdwCleaner
    2015-05-01 18:32 - 2015-05-01 18:33 - 02204160 _____ () C:\Users\Koonsman\Desktop\adwcleaner_4.203.exe
    2015-05-01 18:28 - 2015-05-01 18:28 - 00000567 _____ () C:\Users\Koonsman\Desktop\Result.txt
    2015-05-01 18:25 - 2015-05-01 18:25 - 00402944 _____ (Farbar) C:\Users\Koonsman\Desktop\MiniToolBox.exe
    2015-05-01 02:39 - 2015-05-01 02:40 - 00029517 _____ () C:\Users\Koonsman\Downloads\Addition.txt
    2015-05-01 02:38 - 2015-05-01 02:40 - 00026300 _____ () C:\Users\Koonsman\Downloads\FRST.txt
    2015-05-01 02:37 - 2015-05-01 20:10 - 00000000 ____D () C:\FRST
    2015-05-01 02:37 - 2015-05-01 02:37 - 02101248 _____ (Farbar) C:\Users\Koonsman\Downloads\FRST64.exe
    2015-05-01 02:37 - 2015-05-01 02:37 - 01140736 _____ (Farbar) C:\Users\Koonsman\Desktop\FRST.exe
    2015-04-30 07:50 - 2015-04-30 07:50 - 00000579 _____ () C:\Users\Koonsman\Desktop\aswMBR.txt
    2015-04-30 07:42 - 2015-04-30 07:42 - 05198336 _____ (AVAST Software) C:\Users\Koonsman\Downloads\aswMBR.exe
    2015-04-30 07:37 - 2015-04-30 07:37 - 00000000 ____D () C:\Users\Koonsman\Desktop\backups
    2015-04-30 07:34 - 2015-04-30 07:34 - 00005597 _____ () C:\Users\Koonsman\Desktop\hijackthis.log
    2015-04-30 07:26 - 2015-04-30 07:26 - 00388608 _____ (Trend Micro Inc.) C:\Users\Koonsman\Desktop\HijackThis.exe
    2015-04-29 19:54 - 2015-04-29 19:54 - 00000000 ____D () C:\Program Files\Common Service
    2015-04-25 06:32 - 2015-04-25 06:33 - 00000000 ____D () C:\Program Files\Alfasistem Memory
    2015-04-25 06:32 - 2015-04-25 06:32 - 00000000 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp
    2015-04-15 18:27 - 2015-04-15 18:27 - 00001765 _____ () C:\Users\Public\Desktop\iTunes.lnk
    2015-04-15 18:27 - 2015-04-15 18:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2015-04-15 18:25 - 2015-04-15 18:27 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
    2015-04-15 18:25 - 2015-04-15 18:27 - 00000000 ____D () C:\Program Files\iTunes
    2015-04-15 18:25 - 2015-04-15 18:25 - 00000000 ____D () C:\Program Files\iPod
    2015-04-15 18:10 - 2015-03-22 17:44 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00330752 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
    2015-04-15 18:10 - 2015-03-22 17:07 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
    2015-04-15 18:10 - 2015-03-14 03:13 - 01124352 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
    2015-04-15 02:44 - 2015-03-12 22:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-04-15 02:44 - 2015-03-12 22:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-04-15 02:44 - 2015-03-12 22:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-04-15 02:44 - 2015-03-12 22:16 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-04-15 02:44 - 2015-03-12 21:50 - 00880128 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
    2015-04-15 02:44 - 2015-03-12 21:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-04-15 02:44 - 2015-03-12 21:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-04-15 02:44 - 2015-03-12 21:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-04-15 02:44 - 2015-03-12 21:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-04-15 02:44 - 2015-03-12 21:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-04-15 02:44 - 2015-03-12 21:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-04-15 02:44 - 2015-03-12 21:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-04-15 02:43 - 2015-03-23 16:45 - 05782848 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-04-15 02:43 - 2015-03-23 16:45 - 01468920 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2015-04-15 02:43 - 2015-03-23 16:45 - 00257216 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
    2015-04-15 02:43 - 2015-03-19 22:25 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\microsoft-windows-system-events.dll
    2015-04-15 02:43 - 2015-03-19 21:41 - 00369152 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
    2015-04-15 02:43 - 2015-03-19 21:16 - 00749568 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
    2015-04-15 02:43 - 2015-03-14 03:40 - 00125472 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-04-15 02:43 - 2015-03-13 20:14 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-04-15 02:43 - 2015-03-13 20:14 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-04-15 02:43 - 2015-03-13 20:11 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-04-15 02:43 - 2015-03-13 19:59 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-04-15 02:43 - 2015-03-13 19:03 - 03040768 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-04-15 02:43 - 2015-03-13 19:02 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-04-15 02:43 - 2015-03-13 19:02 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-04-15 02:43 - 2015-03-13 19:00 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
    2015-04-15 02:43 - 2015-03-13 18:59 - 00721920 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-04-15 02:43 - 2015-03-13 18:59 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
    2015-04-15 02:43 - 2015-03-13 18:59 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-04-15 02:43 - 2015-03-13 18:55 - 02309120 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-04-15 02:43 - 2015-03-12 21:37 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
    2015-04-15 02:43 - 2015-02-24 03:20 - 00738112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
    2015-04-15 02:42 - 2015-03-04 05:05 - 00279360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
    2015-04-15 02:42 - 2015-03-03 21:19 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
    2015-04-15 02:42 - 2015-02-20 18:24 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
    2015-04-08 07:57 - 2015-04-08 07:57 - 00000000 ___SD () C:\Windows\system32\GWX

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-05-01 20:00 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\system32\sru
    2015-05-01 19:11 - 2014-03-18 03:01 - 00818732 _____ () C:\Windows\system32\PerfStringBackup.INI
    2015-05-01 19:08 - 2015-03-03 05:32 - 00000000 ___RD () C:\Users\Koonsman\Dropbox
    2015-05-01 19:08 - 2015-03-03 05:24 - 00000000 ____D () C:\Users\Koonsman\AppData\Roaming\Dropbox
    2015-05-01 19:07 - 2014-07-28 01:18 - 00000000 __RDO () C:\Users\Koonsman\OneDrive
    2015-05-01 19:07 - 2013-08-22 02:23 - 00027565 _____ () C:\Windows\setupact.log
    2015-05-01 19:07 - 2013-08-22 02:23 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2015-05-01 19:06 - 2014-07-28 01:33 - 01565417 _____ () C:\Windows\WindowsUpdate.log
    2015-05-01 19:06 - 2014-03-18 02:48 - 00019036 _____ () C:\Windows\PFRO.log
    2015-05-01 19:06 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\security
    2015-05-01 19:06 - 2013-08-22 01:13 - 00262144 ___SH () C:\Windows\system32\config\BBI
    2015-05-01 19:05 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\AppReadiness
    2015-05-01 18:20 - 2015-02-24 09:28 - 00000000 ____D () C:\Program Files\Mozilla Firefox
    2015-05-01 18:20 - 2014-07-28 01:34 - 00001341 _____ () C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-05-01 18:20 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\system32\NDF
    2015-04-30 08:17 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\Microsoft.NET
    2015-04-30 07:17 - 2014-07-28 01:34 - 00000000 ____D () C:\Users\Koonsman\AppData\Local\VirtualStore
    2015-04-30 07:09 - 2015-03-03 05:40 - 00000000 ____D () C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth
    2015-04-30 06:23 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\AppCompat
    2015-04-30 06:19 - 2014-12-13 12:04 - 00000000 ____D () C:\Windows\system32\appraiser
    2015-04-30 06:19 - 2014-07-30 16:21 - 00000000 ___SD () C:\Windows\system32\CompatTel
    2015-04-30 06:08 - 2014-11-03 10:51 - 00000000 ____D () C:\Users\Koonsman\AppData\Local\Unity
    2015-04-25 05:15 - 2015-03-03 05:32 - 00001038 _____ () C:\Users\Koonsman\Desktop\Dropbox.lnk
    2015-04-25 05:15 - 2015-03-03 05:27 - 00000000 ____D () C:\Users\Koonsman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
    2015-04-22 02:16 - 2013-08-22 03:05 - 00000000 ____D () C:\Windows\CbsTemp
    2015-04-17 19:48 - 2013-08-22 03:17 - 00000000 ____D () C:\Windows\rescache
    2015-04-16 06:11 - 2014-07-30 16:20 - 00000000 ____D () C:\Windows\system32\MRT
    2015-04-16 06:07 - 2014-07-30 16:20 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-04-15 18:25 - 2014-08-02 14:01 - 00000000 ____D () C:\Program Files\Common Files\Apple
    2015-04-13 18:24 - 2015-03-16 13:49 - 00792056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
    2015-04-13 18:24 - 2015-03-16 13:49 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl

    ==================== Files in the root of some directories =======

    2015-04-25 06:32 - 2015-04-25 06:32 - 0000000 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp
    2015-04-27 20:51 - 2015-04-27 20:51 - 0009662 _____ () C:\Users\Koonsman\AppData\Roaming\em_64x64.ico
    2014-08-06 10:44 - 2014-08-06 10:44 - 0007605 _____ () C:\Users\Koonsman\AppData\Local\resmon.resmoncfg

    Some content of TEMP:
    ====================
    C:\Users\Koonsman\AppData\Local\Temp\41AA.tmp.exe
    C:\Users\Koonsman\AppData\Local\Temp\447E.tmp.exe
    C:\Users\Koonsman\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpa8atu4.dll
    C:\Users\Koonsman\AppData\Local\Temp\GPUpd553EE7BD0.exe
    C:\Users\Koonsman\AppData\Local\Temp\GPUpd553EE7BF2.exe
    C:\Users\Koonsman\AppData\Local\Temp\GPUpd553EE7C03.exe
    C:\Users\Koonsman\AppData\Local\Temp\GPUpd55417D450.exe
    C:\Users\Koonsman\AppData\Local\Temp\Quarantine.exe
    C:\Users\Koonsman\AppData\Local\Temp\sqlite3.dll

    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2015-04-28 06:55

    ==================== End Of Log ============================

     

     

    Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-04-2015 01
    Ran by [removed] at 2015-05-01 20:12:03
    Running from C:\Users\[removed]\Desktop
    Boot Mode: Normal
    ==========================================================

    ==================== Accounts: =============================

    Administrator (S-1-5-21-2135967233-3606984290-4105762919-500 - Administrator - Disabled)
    Guest (S-1-5-21-2135967233-3606984290-4105762919-501 - Limited - Disabled)
    Koonsman (S-1-5-21-2135967233-3606984290-4105762919-1001 - Administrator - Enabled) => C:\Users\Koonsman

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Apple Application Support (32-bit) (HKLM\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
    Apple Mobile Device Support (HKLM\…\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
    Dropbox (HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\…\Dropbox) (Version: 3.4.4 - Dropbox, Inc.)
    iCloud (HKLM\…\{760BB327-3973-4608-85C8-88162E2FF3B6}) (Version: 4.0.6.28 - Apple Inc.)
    Intel(R) Processor Graphics (HKLM\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.14.3.1177 - Intel Corporation)
    iTunes (HKLM\…\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.)
    Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
    Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Mini S Note (HKLM\…\{D3D81CA0-B970-43A0-ACD0-DC7A36B85910}) (Version: 1.0.28.3 - Samsung Electronics CO. LTD)
    myVapors (HKLM\…\{FD719CB3-73F1-478A-8A13-92586FBB669C}) (Version: 1.00.0000 - Joyetech)
    QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
    Realtek I2S Audio (HKLM\…\{89A448AA-3301-46AA-AFC3-34F2D7C670E8}) (Version: 6.2.9600.3082 - Realtek Semiconductor Corp.)
    S Agent (Version: 1.1.47 - Samsung Electronics CO., LTD.) Hidden
    Samsung Kies3 (HKLM\…\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.)
    Samsung Kies3 (Version: 3.2.15022.8 - Samsung Electronics Co., Ltd.) Hidden
    Settings (HKLM\…\{8CB5C357-12E5-41B1-A024-D57D4E6F32D9}) (Version: 2.0.1 - Samsung Electronics CO., LTD.)
    Sierra Wireless Mobile Broadband Driver Package (HKLM\…\SWIQMIDrvInstaller) (Version: 3.11.1310.3981 - Sierra Wireless, Inc.)
    SW Update (HKLM\…\{DA06101F-FD76-4BF0-88BD-B26A197005E3}) (Version: 2.1.21 - Samsung Electronics CO., LTD.)
    WIDCOMM Bluetooth Software (HKLM\…\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.8030 - Broadcom Corporation)
    Windows Driver Package - Broadcom (bcmfn2) System  (08/30/2012 20.43.14.119) (HKLM\…\8ACEFA31AC73553F5EEFA5785AD8D4D0E850401F) (Version: 08/30/2012 20.43.14.119 - Broadcom)
    Windows Driver Package - Broadcom (BCMSDH43XX) Net  (09/28/2012 5.93.97.76) (HKLM\…\D5631A91EBAF24FAF75D27148329D007EA6B8580) (Version: 09/28/2012 5.93.97.76 - Broadcom)
    Windows Driver Package - Nuvoton Technology Corporation (WUDFRd) System  (05/20/2013 8.1.111.5007) (HKLM\…\74C44B2BCC752410B3995F9DD1E138E6170380DF) (Version: 05/20/2013 8.1.111.5007 - Nuvoton Technology Corporation)

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-2135967233-3606984290-4105762919-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)

    ==================== Restore Points  =========================

    ATTENTION: System Restore is disabled.

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2015-04-30 07:29 - 2015-04-30 07:29 - 00000797 ____A C:\Windows\system32\Drivers\etc\hosts

    ==================== Scheduled Tasks (whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

    Task: {039231BB-BDC6-4F5B-BD3D-F39747444F31} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-23] (Microsoft Corporation)
    Task: {1339EF97-BEEA-4E14-8CB9-2511CEBC4970} - System32\Tasks\Alfasistem Memory Job => C:\Program Files\Alfasistem Memory\ tmjob.exe [2015-04-25] (SecureSoft)
    Task: {19677A92-0F41-4D37-9CEB-9665F0725659} - System32\Tasks\Settings => C:\Program Files\Samsung\Settings\sSettings.exe [2013-03-19] (Samsung Electronics CO., LTD.)
    Task: {253E7A9D-638D-450D-BDB4-4A14C309B087} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-03-19] (Samsung Electronics CO., LTD.)
    Task: {267A9B11-8FB2-4458-AEAD-F9DCD15F4EF1} - System32\Tasks\TP_SS_D => C:ProgramData\Samsung\William_USB_HUB_SS_Disable.exe
    Task: {3DA74E6F-1452-4EB4-9D3C-74FAA60D5659} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
    Task: {6CD14856-E0B9-4C78-984B-2251D0113040} - System32\Tasks\Common Service Job => C:\Program Files\Common Service\CommonService.exe [2015-04-29] (Secure Updater)
    Task: {7F43AA89-F04C-484A-880F-3087AE94BEF2} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
    Task: {8C7D7F24-C593-4740-B118-2A61D6F3871D} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
    Task: {AC038432-5CA6-4865-867B-49460FEBCE99} - System32\Tasks\SNoteAgent => C:\Program Files\Samsung\Mini S Note\MiniSNoteAgent.exe [2013-04-06] (Samsung Electronics CO., LTD.)
    Task: {B615ADFD-26D9-4183-9E27-C11EEBE94246} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-04-16] (Microsoft Corporation)
    Task: {CD0541C1-3EC9-4614-8E6C-0871FC6119F8} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {E8A13984-065D-4EAC-A0D6-F57D41519A5B} - System32\Tasks\Windows Defrag => C:\Users\Koonsman\AppData\Local\Updater\winupd.exe

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    ==================== Loaded Modules (whitelisted) ==============

    2013-03-19 16:11 - 2013-03-19 16:11 - 00211064 _____ () C:\Program Files\Samsung\Settings\CmdServer\WinCRT.dll
    2014-07-03 13:20 - 2014-07-03 13:20 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2015-01-20 23:35 - 2015-01-20 23:35 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2013-09-25 16:21 - 2013-09-25 16:21 - 00044760 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btwleapi.dll
    2014-07-28 02:42 - 2013-06-26 12:18 - 00029744 _____ () C:\Programdata\Samsung\Service\SamsungConfiguration.exe
    2013-03-19 16:11 - 2013-03-19 16:11 - 00085040 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
    2013-03-19 16:10 - 2013-03-19 16:10 - 00029232 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll
    2013-03-19 16:11 - 2013-03-19 16:11 - 01121328 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmd.dll
    2013-03-19 16:11 - 2013-03-19 16:11 - 00111152 _____ () C:\Program Files\Samsung\Settings\CmdServer\EasySettingsBase.dll
    2013-03-19 16:11 - 2013-03-19 16:11 - 00056440 _____ () C:\Program Files\Samsung\Settings\CmdServer\HookDllPS2.dll
    2014-07-28 01:07 - 2013-10-29 20:16 - 01737096 _____ () C:\ProgramData\Samsung\William_USB_HUB_SS_Disable.exe
    2013-03-19 16:10 - 2013-03-19 16:10 - 00027184 _____ () C:\Program Files\Samsung\Settings\EasySettingsAPI.dll
    2013-03-19 16:11 - 2013-03-19 16:11 - 00111152 _____ () C:\Program Files\Samsung\Settings\EasySettingsBase.dll
    2013-03-19 16:11 - 2013-03-19 16:11 - 00060976 _____ () C:\Program Files\Samsung\Settings\EasyMovieEnhancer.dll
    2013-03-19 16:10 - 2013-03-19 16:10 - 00103984 _____ () C:\Program Files\Samsung\Settings\EasySettingsCmdClient.dll
    2015-05-01 19:07 - 2015-05-01 19:07 - 00043008 _____ () c:\users\koonsman\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpa8atu4.dll
    2015-03-04 16:45 - 2015-03-04 16:45 - 00750080 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\libGLESv2.dll
    2015-03-04 16:45 - 2015-03-04 16:45 - 00047616 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\libEGL.dll
    2015-03-04 16:45 - 2015-03-04 16:45 - 00865280 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
    2015-03-04 16:45 - 2015-03-04 16:45 - 00200704 _____ () C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
    2014-03-19 11:39 - 2014-03-19 11:39 - 00081456 _____ () C:\Program Files\Samsung\S Agent\ToastDLL.dll

    ==================== Alternate Data Streams (whitelisted) =========

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

    AlternateDataStreams: C:\Windows\Samsung.png:ms-properties
    AlternateDataStreams: C:\Windows\Screen_Samsung.scr:ms-properties
    AlternateDataStreams: C:\Users\Koonsman\OneDrive:ms-properties

    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\gpioclv.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\inteli2c.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lnwipc.sys => ""="Driver"

    ==================== EXE Association (whitelisted) ===============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, the associated entry will be removed from the registry.)

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Koonsman\Pictures\20140827_172915.jpg
    DNS Servers: 192.168.1.5

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    HKLM\…\StartupApproved\Run: => "Persistence"
    HKLM\…\StartupApproved\Run: => "iTunesHelper"
    HKU\S-1-5-21-2135967233-3606984290-4105762919-1001\…\StartupApproved\Run: => "NetMon"

    ==================== FirewallRules (whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [{AB9576D0-3789-4BBE-B91D-7E299426EDEF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{F05C7C44-1B78-4D18-B9CE-B7795C4737AA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{B63CE1EE-C23A-4174-A90D-1939994192AC}] => (Allow) C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe
    FirewallRules: [{344BD084-7F91-4165-BCF3-CE426726D30E}] => (Allow) C:\Users\Koonsman\AppData\Roaming\Dropbox\bin\Dropbox.exe
    FirewallRules: [TCP Query User{EDDAF735-1009-4821-9EA9-C64832641724}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
    FirewallRules: [UDP Query User{8C523F64-9446-4B31-8C23-43EFF71478C6}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
    FirewallRules: [{020BBDAD-41F7-496F-86C7-0E04B54BB6FE}] => (Allow) C:\Program Files\iTunes\iTunes.exe

    ==================== Faulty Device Manager Devices =============

    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (04/30/2015 08:32:13 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 08:32:11 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 08:32:10 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 08:27:51 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 08:27:48 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 08:27:46 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
    Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/30/2015 07:31:12 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: EasySettingsCmdServer.exe, version: 0.0.0.0, time stamp: 0x5147f18e
    Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f42bd
    Exception code: 0xc0000374
    Fault offset: 0x000d0982
    Faulting process id: 0x4b0
    Faulting application start time: 0xEasySettingsCmdServer.exe0
    Faulting application path: EasySettingsCmdServer.exe1
    Faulting module path: EasySettingsCmdServer.exe2
    Report Id: EasySettingsCmdServer.exe3
    Faulting package full name: EasySettingsCmdServer.exe4
    Faulting package-relative application ID: EasySettingsCmdServer.exe5

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    System errors:
    =============
    Error: (05/01/2015 06:41:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The SW Update Service service terminated unexpectedly.  It has done this 1 time(s).

    Error: (05/01/2015 06:41:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Sierra Wireless Service service terminated unexpectedly.  It has done this 1 time(s).

    Error: (05/01/2015 06:41:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The SamsungConfiguration service terminated unexpectedly.  It has done this 1 time(s).

    Error: (05/01/2015 06:41:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Easy Launcher service terminated unexpectedly.  It has done this 1 time(s).

    Error: (05/01/2015 06:41:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Bluetooth Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

    Error: (05/01/2015 06:41:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Bonjour Service service terminated unexpectedly.  It has done this 1 time(s).

    Error: (05/01/2015 06:41:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Print Spooler service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.

    Error: (05/01/2015 06:35:44 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Windows Search service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

    Error: (05/01/2015 06:35:42 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The SW Update Service service terminated unexpectedly.  It has done this 1 time(s).

    Error: (05/01/2015 06:35:41 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

    Microsoft Office Sessions:
    =========================
    Error: (04/30/2015 08:32:13 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\ExpressCacheRun64.exe

    Error: (04/30/2015 08:32:11 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\VendorAPIRun64.exe

    Error: (04/30/2015 08:32:10 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\Touchpad\x64\SetTouchpadControl64.exe

    Error: (04/30/2015 08:27:51 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\ExpressCacheRun64.exe

    Error: (04/30/2015 08:27:48 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\VendorAPIRun64.exe

    Error: (04/30/2015 08:27:46 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Settings\CmdServer\Touchpad\x64\SetTouchpadControl64.exe

    Error: (04/30/2015 07:31:12 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: EasySettingsCmdServer.exe0.0.0.05147f18entdll.dll6.3.9600.17736550f42bdc0000374000d09824b001d0834189e5c167C:\Program Files\Samsung\Settings\CmdServer\EasySettingsCmdServer.exeC:\Windows\SYSTEM32\ntdll.dllc8e76579-ef34-11e4-9747-dc714460f8e7

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

    Error: (04/30/2015 07:08:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: RDK-SAM-XE500T1)
    Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141

    CodeIntegrity Errors:
    ===================================
      Date: 2015-05-01 18:33:26.213
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-05-01 18:33:26.197
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-05-01 18:31:11.426
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-05-01 18:31:11.426
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-05-01 18:25:26.900
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-05-01 18:25:26.884
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-04-30 07:17:13.361
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-04-30 07:17:13.361
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-03-03 05:01:49.600
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2015-03-03 05:01:49.588
      Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    ==================== Memory info ===========================

    Processor: Intel(R) Atom(TM) CPU Z2760 @ 1.80GHz
    Percentage of memory in use: 44%
    Total physical RAM: 1962.45 MB
    Available physical RAM: 1089.68 MB
    Total Pagefile: 3924.45 MB
    Available Pagefile: 2880.94 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1905.67 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:57.83 GB) (Free:40.17 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 58.3 GB) (Disk ID: 0990F021)

    Partition: GPT Partition Type.

    ==================== End Of Log ============================

    I am attaching a FIXLIST file, you need to download it to your desktop where you now have FRST or the fix wont work, use your mouse to drag FIXLIST right next to FRST, either above or below it but not right on top of it, after its downloaded open up FRST and click on FIX (Not Scan) it wont take long, after your computer reboots you will find a FIXLOG file on your desktop, post it please and let me know if there has been any improvement with your system.

     

     

    Attachments:

    Thank you sir… runs fine.. very much appreciate your time …

     

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 29-04-2015 01
    Ran by [removed] at 2015-05-02 05:41:47 Run:1
    Running from C:\Users\[removed]\Desktop
    [removed] Boot Mode: Normal

    ==============================================

    Content of fixlist:
    *****************
    Start
    CloseProcesses:
    CreateRestorePoint:
    FF NetworkProxy: "type", 5
    2015-04-25 06:32 - 2015-04-25 06:32 - 00000000 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp
    2015-04-25 06:32 - 2015-04-25 06:32 - 0000000 _____ () C:\Users\Koonsman\AppData\Roaming\48E2.tmp
    2015-04-25 06:32 - 2015-04-25 06:33 - 00000000 ____D () C:\Program Files\Alfasistem Memory
    Task: {1339EF97-BEEA-4E14-8CB9-2511CEBC4970} - System32\Tasks\Alfasistem Memory Job => C:\Program Files\Alfasistem Memory\ tmjob.exe [2015-04-25] (SecureSoft)
    Task: {E8A13984-065D-4EAC-A0D6-F57D41519A5B} - System32\Tasks\Windows Defrag => C:\Users\Koonsman\AppData\Local\Updater\winupd.exe
    C:\Users\Koonsman\AppData\Local\Updater\winupd.exe
    CMD: ipconfig /flushdns
    Hosts:
    EmptyTemp:
    End

     

     

     

     

     

    *****************

    Processes closed successfully.
    Error: (0) Failed to create a restore point.
    Firefox Proxy settings were reset.
    C:\Users\Koonsman\AppData\Roaming\48E2.tmp => Moved successfully.
    "C:\Users\Koonsman\AppData\Roaming\48E2.tmp" => File/Directory not found.
    C:\Program Files\Alfasistem Memory => Moved successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1339EF97-BEEA-4E14-8CB9-2511CEBC4970}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1339EF97-BEEA-4E14-8CB9-2511CEBC4970}" => Key deleted successfully.
    C:\Windows\System32\Tasks\Alfasistem Memory Job => Moved successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Alfasistem Memory Job" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E8A13984-065D-4EAC-A0D6-F57D41519A5B}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E8A13984-065D-4EAC-A0D6-F57D41519A5B}" => Key deleted successfully.
    C:\Windows\System32\Tasks\Windows Defrag => Moved successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Windows Defrag" => Key deleted successfully.
    "C:\Users\Koonsman\AppData\Local\Updater\winupd.exe" => File/Directory not found.

    =========  ipconfig /flushdns =========

    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========= End of CMD: =========

    C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
    Hosts was reset successfully.
    EmptyTemp: => Removed 1.1 GB temporary data.

    The system needed a reboot.

    ==== End of Fixlog 05:43:08 ====

    Ask AI

    AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

    Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI