This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

slow weird browser norton pop up ... think I'm infected :( [Closed

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer's been running slow and weird for a few days and my browser's also not working quite as it should (fonts are different, etc). Then today I got an emergency Norton popup (I don't have Norton) and it looks like a popup virus.

 

Also, (and I'm sure this is a really stupid question) but can a virus cause my computer to get overly hot? Or is that likely a separate issue?

 

Thanks so much in advance for you help. You guys have helped me remove viruses before and it's been flawless :)

My MBR log is below. I was not able to go to the other link for the program listed in the "what to do before posting" post.

 

This is the MBR log.

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-05-18 19:42:47
—————————–
19:42:47.960    OS Version: Windows x64 6.2.9200
19:42:47.960    Number of processors: 8 586 0x3C03
19:42:47.961    ComputerName: LISASCOMPUTER  UserName: lisa
19:43:10.293    Initialze error C000010E - driver not loaded
19:51:41.158    AVAST engine defs: 15051801
19:52:49.446    Service scanning
19:55:31.568    Modules scanning
19:55:31.570    Disk 0 trace - called modules:
19:55:31.571    
19:55:38.756    AVAST engine scan C:\WINDOWS
19:56:45.213    AVAST engine scan C:\WINDOWS\system32
20:22:02.539    AVAST engine scan C:\WINDOWS\system32\drivers
20:27:14.076    AVAST engine scan C:\Users\lisa
20:46:56.443    The log file has been saved successfully to "C:\Users\lisa\Desktop\aswMBR log.txt"


aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-05-18 19:42:10
—————————–
19:42:10.321    OS Version: Windows x64 6.2.9200
19:42:10.321    Number of processors: 8 586 0x3C03
19:42:10.322    ComputerName: LISASCOMPUTER  UserName: lisa
19:42:21.591    Initialize success
19:42:23.879    VM: initialized successfully
19:42:23.880    VM: Intel CPU supported
20:47:27.161    VM: disk I/O iaStorA.sys
20:47:35.805    write error "aswCmnB.dll". The process cannot access the file because it is being used by another process.
20:47:36.121    AVAST engine defs: 15051801
20:47:44.246    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000035
20:47:44.248    Disk 0 Vendor: HGST_HTS541075A9E680 JA2OA700 Size: 715404MB BusType: 11
20:47:44.504    Disk 0 MBR read successfully
20:47:44.510    Disk 0 MBR scan
20:47:44.555    Disk 0 unknown MBR code
20:47:44.561    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
20:47:44.929    Disk 0 scanning C:\WINDOWS\system32\drivers
20:48:57.934    Service scanning
20:51:58.120    Modules scanning
20:51:58.453    Disk 0 trace - called modules:
20:51:58.507    ntoskrnl.exe CLASSPNP.SYS disk.sys Wdf01000.sys THAccel.sys thpdrv.sys hal.dll
20:51:58.517    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe001c1fcf540]
20:51:58.526    3 CLASSPNP.SYS[fffff8014da02170] -> nt!IofCallDriver -> [0xffffe001c1fd1040]
20:51:58.534    5 Wdf01000.sys[fffff8014ccea0a8] -> nt!IofCallDriver -> \Device\THPDRV1[0xffffe001c1fd6130]
20:53:03.794    AVAST engine scan C:\WINDOWS
20:54:17.315    AVAST engine scan C:\WINDOWS\system32
21:11:52.468    AVAST engine scan C:\WINDOWS\system32\drivers
21:14:23.247    AVAST engine scan C:\Users\lisa
21:31:40.555    Disk 0 MBR has been saved successfully to "C:\Users\lisa\Desktop\MBR.dat"
21:31:40.564    The log file has been saved successfully to "C:\Users\lisa\Desktop\aswMBR log.txt"

 

 

 

Hello Selene and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download RogueKiller to your desktop


  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

Logs to include with next post:

RKreport.txt
Frst.txt
Addition.txt


Thanks

Satchfan

 

Thanks for working with me, Satchfan :)

 

report is below …


RogueKiller V10.6.4.0 [May 18 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 8.1 (6.3.9200 ) 64 bits version
Started in : Normal mode
User : lisa [Administrator]
Started from : C:\Users\lisa\Downloads\RogueKiller.exe
Mode : Scan – Date : 05/19/2015  12:53:48

¤¤¤ Processes : 1 ¤¤¤
[Suspicious.Path] BitTorrent.exe(3708) – C:\Users\lisa\AppData\Roaming\BitTorrent\BitTorrent.exe[7] -> Killed [TermProc]

¤¤¤ Registry : 32 ¤¤¤
[PUM.Orphan] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}  -> Found
[PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}  -> Found
[PUM.Orphan] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1 | (default) : {F241C880-6982-4CE5-8CF7-7085BA96DA5A}  -> Found
[PUM.Orphan] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2 | (default) : {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}  -> Found
[PUM.Orphan] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3 | (default) : {BBACC218-34EA-4666-9D7A-C78F2274A524}  -> Found
[PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1 | (default) : {F241C880-6982-4CE5-8CF7-7085BA96DA5A}  -> Found
[PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2 | (default) : {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}  -> Found
[PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3 | (default) : {BBACC218-34EA-4666-9D7A-C78F2274A524}  -> Found
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1534849743-2360249728-2914029306-1001\Software\Microsoft\Windows\CurrentVersion\Run | BitTorrent : "C:\Users\lisa\AppData\Roaming\BitTorrent\BitTorrent.exe"  /MINIMIZED [7][x] -> Found
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1534849743-2360249728-2914029306-1001\Software\Microsoft\Windows\CurrentVersion\Run | BitTorrent : "C:\Users\lisa\AppData\Roaming\BitTorrent\BitTorrent.exe"  /MINIMIZED [7][x] -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iscFlash (\??\C:\Windows\Temp\ArchesP10SP10SG_BIOS_V150_WIN\x64\iscflashx64.sys) -> Found
[Suspicious.Path|Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aswMBR (\??\C:\Users\lisa\AppData\Local\Temp\aswMBR.sys) -> Found
[Suspicious.Path|Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aswVmm (\??\C:\Users\lisa\AppData\Local\Temp\aswVmm.sys) -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iscFlash (\??\C:\Windows\Temp\ArchesP10SP10SG_BIOS_V150_WIN\x64\iscflashx64.sys) -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aswMBR (\??\C:\Users\lisa\AppData\Local\Temp\aswMBR.sys) -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aswVmm (\??\C:\Users\lisa\AppData\Local\Temp\aswVmm.sys) -> Found
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://toshiba13.msn.com/?pc=TNJB -> Found
[PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://toshiba13.msn.com/?pc=TNJB -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1534849743-2360249728-2914029306-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://toshiba13.msn.com/?pc=TNJB -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1534849743-2360249728-2914029306-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://toshiba13.msn.com/?pc=TNJB -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{68506E78-EE61-472C-8A08-E1B54C4F4BDF} | DhcpNameServer : [removed] [removed] [UNITED STATES (US)][UNITED STATES (US)]  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{68506E78-EE61-472C-8A08-E1B54C4F4BDF} | DhcpNameServer : [removed] [removed] [UNITED STATES (US)][UNITED STATES (US)]  -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found
[Hj.KnownDLL] (X64) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64cpu : Wow64cpu.dll  -> Found
[Hj.KnownDLL] (X64) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64win : Wow64win.dll  -> Found
[Hj.KnownDLL] (X64) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64 : Wow64.dll  -> Found
[Hj.KnownDLL] (X86) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64cpu : Wow64cpu.dll  -> Found
[Hj.KnownDLL] (X86) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64win : Wow64win.dll  -> Found
[Hj.KnownDLL] (X86) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | _Wow64 : Wow64.dll  -> Found

¤¤¤ Tasks : 1 ¤¤¤
[Suspicious.Path] \\Microsoft OneDrive Auto Update Task-S-1-5-21-1534849743-2360249728-2914029306-1001 – %localappdata%\Microsoft\OneDrive\OneDrive.exe -> Found

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 2 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1       localhost
[C:\Windows\System32\drivers\etc\hosts] ::1             localhost

¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: HGST HTS541075A9E680 +++++
— User —
[MBR] a84dd93b5b19931ceaddbccc47850486
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 1024 MB
1 - [MAN-MOUNT] Basic data partition | Offset (sectors): 2099200 | Size: 260 MB
2 - [MAN-MOUNT] Basic data partition | Offset (sectors): 2631680 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 2893824 | Size: 701107 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1438760960 | Size: 450 MB
5 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 1439682560 | Size: 12434 MB
User = LL1 … OK
User = LL2 … OK


============================================
RKreport_SCN_05192015_124818.log

Farbar scan

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-05-2015 02
Ran by [removed] (administrator) on LISASCOMPUTER on 19-05-2015 12:57:39
Running from C:\Users\[removed]\Downloads
[removed] Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\Dragon Assistant\Core\DACore.exe
() C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Toshiba Corporation) C:\Program Files\Toshiba\Teco\TecoService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Hotkey\TCrdMain_Win8.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Teco\TecoResident.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
() C:\Program Files\Toshiba\Hotkey\Hotkey\TCrdKBB.exe
() C:\Program Files (x86)\Toshiba\System Setting\TODDMain.exe
(Neuber Software) C:\Program Files (x86)\Typograf\FontSets.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
() C:\Users\lisa\Downloads\RogueKiller.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2565472 2013-04-22] (TOSHIBA Corporation)
HKLM\…\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [178016 2013-08-21] (TOSHIBA Corporation)
HKLM\…\Run: [ThpSrv] => C:\windows\system32\thpsrv /logon
HKLM\…\Run: [TSleepSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSleepSrv.exe [1549392 2013-03-04] (TOSHIBA Corporation)
HKLM\…\Run: [TODDMain] => C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe [213136 2012-08-04] ()
HKLM\…\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-01-18] (IvoSoft)
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-15] (Apple Inc.)
HKLM-x32\…\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [835288 2014-07-22] (BlueStack Systems, Inc.)
HKLM-x32\…\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\…\Run: [BitTorrent] => C:\Users\lisa\AppData\Roaming\BitTorrent\BitTorrent.exe [1696104 2015-05-12] (BitTorrent Inc.)
HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\…\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [4272840 2014-03-31] (Microsoft Corporation)
HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\…\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\…\Run: [TypografFontSets] => c:\program files (x86)\typograf\fontsets.exe [121720 2011-12-21] (Neuber Software)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://toshiba13.msn.com/?pc=TNJB
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com/?pc=TNJB
HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com/?pc=TNJB
HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://mystart.toshiba.com
SearchScopes: HKU\S-1-5-21-1534849743-2360249728-2914029306-1001 -> DefaultScope {76E032BA-CE72-471D-B671-2AB1A12DCBED} URL =
SearchScopes: HKU\S-1-5-21-1534849743-2360249728-2914029306-1001 -> {76E032BA-CE72-471D-B671-2AB1A12DCBED} URL =
SearchScopes: HKU\S-1-5-21-1534849743-2360249728-2914029306-1001 -> {7C65B0C5-B202-40E1-A4B2-C6F57D5CE4D9} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2014-03-18] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2014-03-18] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2014-03-18] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2014-03-18] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2014-03-18] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2012-06-01] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254

FireFox:
========
FF ProfilePath: C:\Users\lisa\AppData\Roaming\Mozilla\Firefox\Profiles\e1rp9nct.default
FF DefaultSearchEngine: Yahoo!
FF DefaultSearchEngine.US: Google
FF SelectedSearchEngine: Yahoo!
FF Homepage: https://search.yahoo.com/?type=916552&fr=spigot-yhp-ff
FF Keyword.URL: https://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=916552&p=
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-02-15] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-02-15] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-03-18] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-10-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Extension: WOT - C:\Users\lisa\AppData\Roaming\Mozilla\Firefox\Profiles\e1rp9nct.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-04-18]
FF Extension: Pin It Button - C:\Users\lisa\AppData\Roaming\Mozilla\Firefox\Profiles\e1rp9nct.default\Extensions\[removed] [2014-12-17]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [409304 2014-07-22] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384728 2014-07-22] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [777944 2014-07-22] (BlueStack Systems, Inc.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 DACoreService; C:\Program Files (x86)\Nuance\Dragon Assistant\Core\DACore.exe [432528 2013-05-02] (Nuance Communications, Inc.)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1429504 2015-03-04] (Microsoft Corporation)
R2 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [19792 2013-09-10] ()
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129848 2013-02-22] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736 2013-02-22] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1854056 2012-12-07] (Microsoft Corporation)
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S4 THAccelSvc; C:\Program Files\TOSHIBA\HDD Accelerator\THAccelSvc.exe [216976 2013-03-26] (TOSHIBA CORPORATION)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122072 2014-07-22] (BlueStack Systems)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 iscFlash; C:\Windows\Temp\ArchesP10SP10SG_BIOS_V150_WIN\x64\iscflashx64.sys [60680 2013-02-24] (Insyde Software)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-19] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-09] (Intel Corporation)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [288328 2013-01-23] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-28] (Synaptics Incorporated)
S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-16] (Anchorfree Inc.)
R0 THAccel; C:\Windows\System32\DRIVERS\THAccel.sys [110976 2013-03-25] (TOSHIBA Corporation)
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [32624 2013-08-19] (Windows (R) Win 7 DDK provider)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-05-19] ()
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [48024 2013-01-28] (Windows (R) Win 7 DDK provider)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [194456 2013-01-28] (Windows (R) Win 7 DDK provider)
S1 BAPIDRV; system32\DRIVERS\BAPIDRV64.sys [X]
U3 aswMBR; \??\C:\Users\lisa\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\lisa\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-19 12:57 - 2015-05-19 12:58 - 00018282 _____ () C:\Users\lisa\Downloads\FRST.txt
2015-05-19 12:57 - 2015-05-19 12:57 - 02107392 _____ (Farbar) C:\Users\lisa\Downloads\FRST64.exe
2015-05-19 12:57 - 2015-05-19 12:57 - 00000000 ____D () C:\FRST
2015-05-19 12:43 - 2015-05-19 12:43 - 00035064 _____ () C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-05-19 12:42 - 2015-05-19 12:42 - 00000000 ____D () C:\ProgramData\RogueKiller
2015-05-19 12:41 - 2015-05-19 12:42 - 16980568 _____ () C:\Users\lisa\Downloads\RogueKiller.exe
2015-05-18 21:31 - 2015-05-18 21:31 - 00000512 _____ () C:\Users\lisa\Desktop\MBR.dat
2015-05-18 19:41 - 2015-05-18 19:41 - 05198336 _____ (AVAST Software) C:\Users\lisa\Downloads\aswMBR.exe
2015-05-18 02:13 - 2015-05-18 02:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-15 17:37 - 2015-05-19 12:36 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-05-15 17:37 - 2015-05-15 17:37 - 00001129 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-15 17:37 - 2015-05-15 17:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-15 17:37 - 2015-05-15 17:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-15 17:37 - 2015-05-15 17:37 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-15 17:37 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-05-15 17:37 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-05-15 17:37 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-05-15 17:34 - 2015-05-15 17:35 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\lisa\Downloads\mbam-setup-2.1.6.1022.exe
2015-05-12 20:28 - 2015-04-30 16:35 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-12 20:28 - 2015-04-30 16:35 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-12 20:06 - 2015-05-12 20:47 - 00000000 ____D () C:\Users\lisa\Downloads\Strange Magic 2015 DVDRIP x264 AC3 TiTAN
2015-05-12 20:04 - 2015-05-13 22:29 - 00000000 ____D () C:\Users\lisa\Downloads\Jupiter.Ascending.2015.HDRip.XviD-ETRG
2015-05-12 19:35 - 2015-04-21 13:14 - 24971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-05-12 19:35 - 2015-04-21 12:50 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-05-12 19:35 - 2015-04-21 12:50 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-05-12 19:35 - 2015-04-21 12:49 - 02885120 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-05-12 19:35 - 2015-04-21 12:37 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-05-12 19:35 - 2015-04-21 12:35 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-05-12 19:35 - 2015-04-21 12:31 - 06025728 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-05-12 19:35 - 2015-04-21 12:24 - 19691008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-05-12 19:35 - 2015-04-21 12:13 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\inseng.dll
2015-05-12 19:35 - 2015-04-21 12:11 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-05-12 19:35 - 2015-04-21 12:09 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-05-12 19:35 - 2015-04-21 12:08 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-05-12 19:35 - 2015-04-21 12:07 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-05-12 19:35 - 2015-04-21 12:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-05-12 19:35 - 2015-04-21 12:04 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-05-12 19:35 - 2015-04-21 11:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-05-12 19:35 - 2015-04-21 11:58 - 00664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-05-12 19:35 - 2015-04-21 11:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-05-12 19:35 - 2015-04-21 11:49 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-05-12 19:35 - 2015-04-21 11:49 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-05-12 19:35 - 2015-04-21 11:49 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-05-12 19:35 - 2015-04-21 11:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-05-12 19:35 - 2015-04-21 11:40 - 14401536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-05-12 19:35 - 2015-04-21 11:38 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-05-12 19:35 - 2015-04-21 11:37 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-05-12 19:35 - 2015-04-21 11:36 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-05-12 19:35 - 2015-04-21 11:32 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-05-12 19:35 - 2015-04-21 11:31 - 04305920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-05-12 19:35 - 2015-04-21 11:28 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-05-12 19:35 - 2015-04-21 11:27 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-05-12 19:35 - 2015-04-21 11:26 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-05-12 19:35 - 2015-04-21 11:26 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-05-12 19:35 - 2015-04-21 11:25 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-05-12 19:35 - 2015-04-21 11:17 - 12828672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-05-12 19:35 - 2015-04-21 11:15 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-05-12 19:35 - 2015-04-21 11:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-05-12 19:35 - 2015-04-21 11:02 - 01882112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-05-12 19:35 - 2015-04-21 10:58 - 01310208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-05-12 19:35 - 2015-04-21 10:56 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-05-12 19:30 - 2015-04-09 20:34 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-05-12 19:30 - 2015-04-09 20:11 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-05-12 19:30 - 2015-03-17 13:26 - 00467776 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-05-12 19:30 - 2015-03-08 22:02 - 00057856 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-05-12 19:24 - 2015-04-30 19:05 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-05-12 19:24 - 2015-04-30 18:48 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2015-05-12 19:24 - 2015-04-24 17:32 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-05-12 19:24 - 2015-04-13 18:48 - 04180480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-05-12 19:24 - 2015-04-09 21:00 - 01996800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-05-12 19:24 - 2015-04-09 20:50 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-05-12 19:24 - 2015-04-09 20:26 - 01560576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-05-12 19:24 - 2015-04-08 18:55 - 00410128 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2015-05-12 19:24 - 2015-04-02 20:35 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2015-05-12 19:24 - 2015-04-02 20:14 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2015-05-12 19:24 - 2015-04-01 18:22 - 02985984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2015-05-12 19:24 - 2015-04-01 18:20 - 04417536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2015-05-12 19:24 - 2015-03-31 23:45 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2015-05-12 19:24 - 2015-03-31 22:31 - 01207296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2015-05-12 19:24 - 2015-03-19 21:56 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-05-12 19:24 - 2015-03-12 22:02 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys
2015-05-12 19:24 - 2015-03-12 21:11 - 02162176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-05-12 19:24 - 2015-03-12 20:39 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-05-12 19:24 - 2015-03-10 21:49 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe
2015-05-12 19:24 - 2015-03-10 21:09 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe
2015-05-12 19:24 - 2015-03-05 22:47 - 01696256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2015-05-12 19:24 - 2015-03-04 19:09 - 01429504 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-05-12 19:24 - 2015-03-03 21:32 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2015-05-12 19:24 - 2015-03-03 21:12 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2015-05-12 19:24 - 2015-02-17 19:19 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2015-05-12 19:24 - 2015-01-29 20:53 - 02819584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2015-05-12 19:24 - 2014-11-14 02:58 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsDatabase.dll
2015-05-12 19:23 - 2015-03-30 01:47 - 00561928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-05-12 19:23 - 2015-03-26 23:27 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-05-12 19:23 - 2015-03-26 22:50 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-05-12 19:23 - 2015-03-26 22:48 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-05-12 19:23 - 2015-03-13 00:03 - 00239424 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-05-12 19:23 - 2015-03-13 00:03 - 00154432 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2015-05-12 19:23 - 2015-03-12 20:29 - 00410017 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-05-12 19:23 - 2015-03-05 23:08 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2015-05-12 19:23 - 2015-03-05 22:43 - 01969664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll
2015-05-09 18:09 - 2015-05-13 22:30 - 00000000 ____D () C:\Users\lisa\Downloads\Skin.Traffik.2015.BDRip.XviD.AC3-EVO
2015-05-09 15:52 - 2015-05-10 04:01 - 00000000 ____D () C:\Users\lisa\Downloads\Still.Alice.2014.DVDSCR.XviD.AC3-EVO
2015-05-09 15:02 - 2015-05-10 00:15 - 00000000 ____D () C:\Users\lisa\Downloads\Careful.What.You.Wish.For.2015.DVDRip.XviD-EVO
2015-05-09 14:56 - 2015-05-10 04:01 - 00000000 ____D () C:\Users\lisa\Downloads\The Ninth Gate (1999)
2015-05-09 12:58 - 2015-05-10 23:43 - 00000000 ____D () C:\Users\lisa\Downloads\Dreamcatcher (2003) [1080p]
2015-05-09 12:29 - 2015-05-10 00:30 - 00000000 ____D () C:\Users\lisa\Downloads\Lord of the Flies (1963) [1080p]
2015-05-09 11:21 - 2015-05-10 00:30 - 00000000 ____D () C:\Users\lisa\Downloads\House of 1000 Corpses (2003) [1080p]
2015-05-09 09:58 - 2015-05-10 00:30 - 00000000 ____D () C:\Users\lisa\Downloads\Housebound (2014)
2015-05-09 05:08 - 2015-05-10 04:01 - 00000000 ____D () C:\Users\lisa\Downloads\The Hand That Rocks the Cradle (1992) [1080p]
2015-05-09 05:04 - 2015-05-13 22:30 - 00000000 ____D () C:\Users\lisa\Downloads\The Apple Dumpling Gang (1975)
2015-05-09 04:58 - 2015-05-10 04:01 - 00000000 ____D () C:\Users\lisa\Downloads\The Money Pit (1986) [1080p]
2015-05-09 02:23 - 2015-05-13 22:30 - 00000000 ____D () C:\Users\lisa\Downloads\The Book of Life (2014) [3D] [HSBS]
2015-05-09 01:33 - 2015-05-10 00:16 - 00000000 ____D () C:\Users\lisa\Downloads\Extraterrestrial (2014)
2015-05-08 23:48 - 2015-05-10 00:15 - 00000000 ____D () C:\Users\lisa\Downloads\David and Lisa (1962)
2015-05-08 20:33 - 2015-05-10 00:16 - 00000000 ____D () C:\Users\lisa\Downloads\F.X (1986)
2015-05-08 19:37 - 2015-05-10 00:30 - 00000000 ____D () C:\Users\lisa\Downloads\Imitation of Life (1934)
2015-05-08 19:34 - 2015-05-10 00:16 - 00000000 ____D () C:\Users\lisa\Downloads\Fifty Shades of Grey (2015)
2015-05-08 19:34 - 2015-05-10 00:15 - 00000000 ____D () C:\Users\lisa\Downloads\1984 (1984)
2015-05-08 18:53 - 2015-05-13 22:27 - 00000000 ____D () C:\Users\lisa\Downloads\Chocolat {2000} 720p BRRip x264 - HDMiCRO by Mr. KickASS
2015-05-08 18:52 - 2015-05-13 22:30 - 00000000 ____D () C:\Users\lisa\Downloads\Stripes (1981)
2015-05-08 18:52 - 2015-05-10 00:15 - 00000000 ____D () C:\Users\lisa\Downloads\Barefoot (2014)
2015-05-08 18:51 - 2015-05-13 22:27 - 00000000 ____D () C:\Users\lisa\Downloads\5_Hot_Stories_for_Her
2015-05-08 18:51 - 2015-05-10 00:31 - 00000000 ____D () C:\Users\lisa\Downloads\Predestination (2014)
2015-05-08 18:51 - 2015-05-10 00:16 - 00000000 ____D () C:\Users\lisa\Downloads\Ferris Bueller's Day Off (1986) [1080p]
2015-05-08 18:51 - 2015-05-10 00:15 - 00000000 ____D () C:\Users\lisa\Downloads\Desperately Seeking Susan (1985)
2015-05-08 18:51 - 2015-05-10 00:15 - 00000000 ____D () C:\Users\lisa\Downloads\Big Eyes (2014)
2015-05-08 17:32 - 2015-05-10 00:30 - 00000000 ____D () C:\Users\lisa\Downloads\Gallipoli (1981)
2015-05-08 17:32 - 2015-05-10 00:16 - 00000000 ____D () C:\Users\lisa\Downloads\Excalibur (1981)
2015-05-08 15:51 - 2015-05-10 04:01 - 00000000 ____D () C:\Users\lisa\Downloads\To Kill a Mockingbird (1962)
2015-05-08 15:47 - 2015-05-10 00:15 - 00000000 ____D () C:\Users\lisa\Downloads\Barbarella
2015-05-08 15:40 - 2015-05-10 00:15 - 00000000 ____D () C:\Users\lisa\Downloads\Coming Home (1978)
2015-05-08 15:39 - 2015-05-10 00:15 - 00000000 ____D () C:\Users\lisa\Downloads\Unfaithful (2002)
2015-05-08 15:38 - 2015-05-10 00:30 - 00000000 ____D () C:\Users\lisa\Downloads\Klute.1971.DVDRip.XviD-VLiS
2015-04-29 15:08 - 2015-04-29 15:08 - 00043995 _____ () C:\Users\lisa\Downloads\download.OFX
2015-04-29 15:06 - 2015-04-29 15:06 - 00025250 _____ () C:\Users\lisa\Downloads\download(1).CSV
2015-04-29 15:04 - 2015-04-29 15:04 - 00000767 _____ () C:\Users\lisa\Downloads\download.CSV
2015-04-23 19:17 - 2015-04-23 19:18 - 00000000 ____D () C:\Users\lisa\AppData\Roaming\Typograf
2015-04-23 19:17 - 2015-04-23 19:17 - 01620336 _____ () C:\Users\lisa\Downloads\Typograph_Setup.exe
2015-04-23 19:17 - 2015-04-23 19:17 - 00001052 _____ () C:\Users\Public\Desktop\Typograf.lnk
2015-04-23 19:17 - 2015-04-23 19:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Typograf
2015-04-23 19:17 - 2015-04-23 19:17 - 00000000 ____D () C:\Program Files (x86)\Typograf
2015-04-21 12:00 - 2015-04-21 12:00 - 00000000 ____D () C:\Users\lisa\Documents\fil_sans
2015-04-21 11:58 - 2015-04-21 11:58 - 00000000 ____D () C:\Users\lisa\Documents\frenchpress
2015-04-21 11:57 - 2015-04-21 11:57 - 00000000 ____D () C:\Users\lisa\Documents\iron_brine
2015-04-21 11:55 - 2015-04-21 11:55 - 00000000 ____D () C:\Users\lisa\Documents\hand_stencil
2015-04-21 11:55 - 2015-04-21 11:55 - 00000000 ____D () C:\Users\lisa\Documents\d_day_stencil
2015-04-21 11:53 - 2015-04-21 11:53 - 00000000 ____D () C:\Users\lisa\Documents\splatter
2015-04-21 11:52 - 2015-04-21 11:52 - 00000000 ____D () C:\Users\lisa\Documents\tarjustamonday
2015-04-21 11:50 - 2015-04-21 11:50 - 00000000 ____D () C:\Users\lisa\Documents\telegraphem
2015-04-21 11:50 - 2015-04-21 11:50 - 00000000 ____D () C:\Users\lisa\Documents\indierock
2015-04-21 11:49 - 2015-04-21 11:49 - 00000000 ____D () C:\Users\lisa\Documents\typewriter_condensed
2015-04-21 11:48 - 2015-04-21 11:48 - 00000000 ____D () C:\Users\lisa\Documents\veteran_typewriter
2015-04-21 11:47 - 2015-04-21 11:47 - 00000000 ____D () C:\Users\lisa\Documents\albertsthal_typewriter
2015-04-21 11:46 - 2015-04-21 11:46 - 00000000 ____D () C:\Users\lisa\Documents\linowrite
2015-04-21 11:45 - 2015-04-21 11:45 - 00000000 ____D () C:\Users\lisa\Documents\moms_typewriter
2015-04-21 11:43 - 2015-04-21 11:44 - 00000000 ____D () C:\Users\lisa\Documents\traveling_typewriter
2015-04-19 21:42 - 2015-04-19 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-04-19 21:42 - 2015-04-19 21:42 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2015-04-19 21:41 - 2015-04-19 21:41 - 01182190 _____ () C:\Users\lisa\Downloads\7z938.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-19 12:53 - 2015-02-05 11:14 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-05-19 12:51 - 2014-04-14 21:26 - 00004988 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for LISASCOMPUTER-lisa LisasComputer
2015-05-19 12:48 - 2014-03-11 17:56 - 01852772 _____ () C:\WINDOWS\WindowsUpdate.log
2015-05-19 12:42 - 2014-03-07 10:11 - 00000000 ____D () C:\Users\lisa\AppData\Roaming\BitTorrent
2015-05-19 12:41 - 2014-04-07 12:58 - 00003942 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{20700F04-C092-433C-8AA2-6EF339919B18}
2015-05-19 12:36 - 2014-03-11 18:07 - 00000000 __RDO () C:\Users\lisa\SkyDrive
2015-05-19 12:34 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-05-19 00:27 - 2014-03-07 10:06 - 00000000 ____D () C:\Users\lisa\AppData\Roaming\ClassicShell
2015-05-18 22:53 - 2013-08-22 10:46 - 00302078 _____ () C:\WINDOWS\setupact.log
2015-05-18 21:52 - 2014-03-11 17:48 - 00000000 ____D () C:\Users\lisa
2015-05-18 19:03 - 2014-03-05 18:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-18 19:03 - 2013-11-14 03:20 - 00049754 _____ () C:\WINDOWS\PFRO.log
2015-05-18 19:03 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\security
2015-05-18 19:03 - 2013-08-22 10:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-18 02:00 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-05-17 10:29 - 2014-03-07 15:25 - 02953216 ___SH () C:\Users\lisa\Downloads\Thumbs.db
2015-05-15 20:11 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2015-05-15 18:37 - 2014-03-05 18:22 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1534849743-2360249728-2914029306-1001
2015-05-15 17:26 - 2014-03-15 13:00 - 00001058 _____ () C:\Users\lisa\Desktop\PhotoScape.lnk
2015-05-15 17:26 - 2014-03-15 13:00 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2015-05-14 20:11 - 2014-09-26 14:39 - 00000000 ____D () C:\Users\lisa\Downloads\ZUMBA VIDEOS FROM YT
2015-05-14 09:38 - 2014-03-07 10:22 - 00000000 ____D () C:\Users\lisa\AppData\Roaming\vlc
2015-05-12 21:59 - 2013-08-22 11:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-05-12 20:59 - 2014-10-14 21:41 - 00003104 _____ () C:\WINDOWS\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-1534849743-2360249728-2914029306-1001
2015-05-12 20:59 - 2014-03-11 11:11 - 00000000 ___RD () C:\Users\lisa\OneDrive
2015-05-12 20:40 - 2014-03-06 00:15 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-05-12 20:40 - 2014-03-06 00:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-05-12 20:40 - 2013-08-22 10:44 - 05432808 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-05-12 20:37 - 2013-08-22 09:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-05-12 20:34 - 2013-08-22 11:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2015-05-12 20:34 - 2013-08-22 09:36 - 00000000 ____D () C:\WINDOWS\system32\AdvancedInstallers
2015-05-12 20:29 - 2012-07-26 03:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-05-12 20:28 - 2014-03-05 22:55 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-05-12 20:24 - 2014-03-05 22:55 - 140425016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-05-12 20:23 - 2014-03-06 00:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-12 20:19 - 2013-11-14 03:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-09 09:45 - 2014-03-05 18:15 - 00000000 ____D () C:\Users\lisa\AppData\Local\Packages
2015-05-05 13:59 - 2014-08-15 09:25 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-05-05 13:59 - 2014-08-15 09:25 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-19 22:04 - 2015-04-18 12:06 - 00000000 ____D () C:\Users\lisa\Downloads\(000) Diamond Dallas Page - DDP Yoga COMBO Pack
2015-04-19 21:34 - 2014-09-20 11:51 - 00000000 ____D () C:\Users\lisa\Downloads\(000) Les Mills PUMP Complete

==================== Files in the root of some directories =======

2014-09-18 13:21 - 2014-09-18 13:21 - 0001456 _____ () C:\Users\lisa\AppData\Local\Adobe Save for Web 13.0 Prefs
2014-08-01 22:14 - 2010-05-28 23:37 - 0015086 _____ () C:\ProgramData\Amazon.ico
2015-04-09 15:46 - 2015-04-09 15:46 - 0000057 _____ () C:\ProgramData\Ament.ini
2014-09-25 17:38 - 2014-09-25 17:43 - 0000365 _____ () C:\ProgramData\hpzinstall.log

Some content of TEMP:
====================
C:\Users\ADMINI~1\AppData\Local\Temp\CreateToastShortcut.exe
C:\Users\ADMINI~1\AppData\Local\Temp\CreateToastShortcutDll.dll
C:\Users\ADMINI~1\AppData\Local\Temp\StartMenu.exe
C:\Users\ADMINI~1\AppData\Local\Temp\TosNoRestart.exe
C:\Users\lisa\AppData\Local\Temp\0khuip0z.exe
C:\Users\lisa\AppData\Local\Temp\2144a3fc.exe
C:\Users\lisa\AppData\Local\Temp\2de3q4pw.exe
C:\Users\lisa\AppData\Local\Temp\30lgxs3n.exe
C:\Users\lisa\AppData\Local\Temp\dllnt_dump.dll
C:\Users\lisa\AppData\Local\Temp\ICReinstall_FreeYouTubeDownloaderIC.exe
C:\Users\lisa\AppData\Local\Temp\jppp4ima.exe
C:\Users\lisa\AppData\Local\Temp\KUIU.EXE
C:\Users\lisa\AppData\Local\Temp\OfficeSetup.exe
C:\Users\lisa\AppData\Local\Temp\SetupO365HomePremRetail.x86.en-US_O365HomePremRetail_2YN83-2CCRJ-M2DJH-Q9Q4K-T8X8R_act_1_.exe
C:\Users\lisa\AppData\Local\Temp\vlc-2.1.5-win32.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-12 04:04

==================== End Of Log ============================

addition txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-05-2015 02
Ran by [removed] at 2015-05-19 12:58:31
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1534849743-2360249728-2914029306-500 - Administrator - Disabled)
Guest (S-1-5-21-1534849743-2360249728-2914029306-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1534849743-2360249728-2914029306-1005 - Limited - Enabled)
lisa (S-1-5-21-1534849743-2360249728-2914029306-1001 - Administrator - Enabled) => C:\Users\lisa

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
7-Zip 9.38 beta (HKLM-x32\…\7-Zip) (Version:  - )
Adobe After Effects CS5.5 (HKLM-x32\…\{E82097B9-A3B8-404A-9A92-AC16A8AC9576}) (Version: 10.5 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Illustrator CS6 (HKLM-x32\…\{4869414E-7AEA-4C8E-BE1C-8D40977FD517}) (Version: 16.0 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\…\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08)  MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Adobe Story (HKLM-x32\…\com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.0.571 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\…\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
BitTorrent (HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\…\BitTorrent) (Version: 7.9.3.40299 - BitTorrent Inc.)
BlueStacks Notification Center (HKLM-x32\…\{50DA15C1-0161-40EE-A325-0BE5BA03C026}) (Version: 0.9.0.4049 - BlueStack Systems, Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Classic Shell (HKLM\…\{2368907C-E8F6-4750-A023-254C3E2B5E8D}) (Version: 4.0.4 - IvoSoft)
Cook'n (HKLM-x32\…\Cook'n) (Version:  - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DJ_AIO_03_F2200_Software_Min (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden
Dragon Assistant Application en-US version 1.5.7 (HKLM-x32\…\{1CCBE73F-4948-4711-8D12-22E2FD65D706}_is1) (Version: 1.5.7 - Nuance Communications, Inc.)
Dragon Assistant Core Recognition Service version 1.1.10 (HKLM-x32\…\{E97BA7A6-46FC-4EBF-B24A-B8362948C696}_is1) (Version: 1.1.10 - Nuance Communications, Inc.)
Dragon Assistant Language Data en-US version 1.1.3 (HKLM-x32\…\{4C0C1E4E-D3B1-4496-98EC-DA14D45EC855}_is1) (Version: 1.1.3 - Nuance Communications, Inc.)
Dragon Assistant version 1.5.7 (HKLM-x32\…\{D57A8269-3BE5-4D10-B882-64D0F2D448BF}_is1) (Version: 1.5.7 - Nuance Communications, Inc.)
DTS Studio Sound (HKLM-x32\…\{2DFA9084-CEB3-4A48-B9F7-9038FEF1B8F4}) (Version: 1.01.2700 - DTS, Inc.)
DVDStyler v2.7.2 (HKLM-x32\…\DVDStyler_is1) (Version:  - )
Elementals - The Magic Key (x32 Version: 2.2.0.97 - WildTangent) Hidden
F2200 (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden
Free YouTube Downloader 4.0.361 (HKLM-x32\…\{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1) (Version:  - HOW Inc.)
HP Deskjet 3510 series Basic Device Software (HKLM\…\{7F20F2D1-C425-4432-96BA-EBD0C2181493}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet F2200 All-In-One Driver Software 14.0 Rel. 6 (HKLM\…\{60D6AAC5-FDC1-49BA-867B-3135F4726156}) (Version: 14.0 - HP)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3345 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.2.1000 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.63463 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\…\{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}) (Version: 2.3.1338 - Intel Corporation)
Intel(R) WiDi (HKLM\…\{62E7C369-64FF-452C-8F46-6BE9B77FF097}) (Version: 4.0.18.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)
iTunes (HKLM\…\{1CF5754A-545B-4360-BFDE-2847BC728DFC}) (Version: 11.2.0.115 - Apple Inc.)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
King Oddball (x32 Version: 3.0.2.48 - WildTangent) Hidden
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft Office (HKLM-x32\…\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Office 365 Home Premium - en-us (HKLM\…\O365HomePremRetail - en-us) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\…\OneDriveSetup.exe) (Version: 17.3.5849.0427 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\…\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 38.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 38.0.1 (x86 en-US)) (Version: 38.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Office 15 Click-to-Run Licensing Component (Version: 15.0.4454.1510 - Microsoft Corporation) Hidden
Pattern Wizard (HKLM-x32\…\Pattern Wizard_is1) (Version:  - Patrick Roberts Software)
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
PhotoScape (HKLM-x32\…\PhotoScape) (Version:  - )
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Pokki (HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\…\Pokki) (Version: 0.262.11.408 - Pokki)
Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\…\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.13 - Qualcomm Atheros Communications Inc.)
Realtek PCIE Card Reader (HKLM-x32\…\{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}) (Version: 6.2.9200.29053 - Realtek Semiconductor Corp.)
Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.8.21 - Synaptics Incorporated)
Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden
TOSHIBA Application Installer (HKLM-x32\…\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.1.5 - TOSHIBA)
TOSHIBA Audio Enhancement (HKLM\…\{1515F5E3-29EA-4CD1-A981-032D88880F09}) (Version: 2.0.15.4 - Toshiba Corporation)
Toshiba Book Place (HKLM-x32\…\{11244D6B-9842-440F-8579-6A4D771A0D9B}) (Version: 3.3.9661 - K-NFB Reading Technology, Inc.)
TOSHIBA eco Utility (HKLM\…\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.2.0.6404 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\…\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.00.6630.6403 - Toshiba Corporation)
TOSHIBA HDD Accelerator (HKLM\…\{DB4D9937-0B14-4EF1-BF9A-BB7E3B9DCB04}) (Version: 2.0.0001 - Toshiba Corporation)
TOSHIBA HDD Protection (HKLM\…\{94A90C69-71C1-470A-88F5-AA47ECC96B40}) (Version: 2.5.0002.64002 - Toshiba Corporation)
TOSHIBA Password Utility (HKLM-x32\…\InstallShield_{26BB68BB-CF93-4A12-BC6D-A3B6F53AC8D9}) (Version: 4.0.5.0 - Toshiba Corporation)
TOSHIBA Quality Application (HKLM-x32\…\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.8 - TOSHIBA)
TOSHIBA Recovery Media Creator (HKLM-x32\…\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.0.01.55004008 - Toshiba Corporation)
TOSHIBA Resolution+ Plug-in for Windows Media Player (HKLM-x32\…\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}) (Version: 1.2.7.0 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\…\{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}) (Version: 2.6.8 - Toshiba Corporation)
Toshiba Start (HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\…\Pokki_b52b7a05ea010d22183cece45cbb6e86cf917a76) (Version: 1.0.0.0 - Pokki)
TOSHIBA System Driver (HKLM-x32\…\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0032 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\…\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.00.0007.32003 - Toshiba Corporation)
TOSHIBA User's Guide (HKLM-x32\…\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
TOSHIBA VIDEO PLAYER (HKLM\…\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 5.3.27.102  - Toshiba Corporation)
TOSHIBARegistration (HKLM-x32\…\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.1.6 - TOSHIBA)
Typograf 5.1e (HKLM-x32\…\Typograf) (Version: 5.1e - Neuber Software)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.1.5 - VideoLAN)
WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (Toshiba Games) (x32 Version: 4.0.10.15 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Wonderland Solitaire (x32 Version: 2.2.0.110 - WildTangent) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1534849743-2360249728-2914029306-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\lisa\AppData\Local\Microsoft\OneDrive\17.3.5849.0427\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points  =========================

01-05-2015 04:22:07 Scheduled Checkpoint
08-05-2015 23:43:38 Scheduled Checkpoint
12-05-2015 20:18:14 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 09:25 - 2014-04-19 01:21 - 00000822 __ASH C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {00201A1C-7AA5-4911-9D71-BA95B2EA8555} - System32\Tasks\Microsoft Office 15 Sync Maintenance for LISASCOMPUTER-lisa LisasComputer => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2014-03-18] (Microsoft Corporation)
Task: {0C48BD55-7932-4B3E-8AD7-1E5543FF40FE} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.38\SymErr.exe
Task: {15AB8256-2072-45DE-9286-F1FFC3B287D7} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-03-18] (Microsoft Corporation)
Task: {20F0547A-22C3-40E0-9341-E7E8F7685A2C} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-08-28] (Synaptics Incorporated)
Task: {3E0872E1-D13B-4134-99BE-DA4416375E1D} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {5AF18109-91CA-4896-A0EE-9332774DF735} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-1534849743-2360249728-2914029306-1001 => %localappdata%\Microsoft\OneDrive\OneDrive.exe
Task: {6BCA22A2-F067-4A6D-AAA4-A019B18A2C20} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.38\SymErr.exe
Task: {6DD51425-4902-4C41-9877-0774B2336761} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2013-07-31] (TOSHIBA Corporation)
Task: {74B56FF5-EBF8-4B28-A7D8-3611F2207371} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
Task: {7603EE78-D803-415B-BC7D-F765C0B0DB26} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-05-12] (Microsoft Corporation)
Task: {91D756CA-2A5C-40C3-B2D5-AC8D6E70C9CE} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
Task: {9F27A4CE-C080-4FEA-912C-94ABE0082A25} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-23] (Microsoft Corporation)
Task: {B9E32C99-8712-47D0-88FA-891C5BC6A038} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-23] (Microsoft Corporation)
Task: {C4C3FD82-1AC6-4E9C-82A5-033E7E109882} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {ECCED0DF-C98D-404E-A763-80F2215000C4} - System32\Tasks\Microsoft\Office\Office First Run Task => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2012-12-07] (Microsoft Corporation)
Task: {F2FC9EC7-46F3-4C84-8522-4871B8225EC1} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-14] (Adobe Systems Incorporated)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (Whitelisted) ==============

2013-09-10 12:54 - 2013-09-10 12:54 - 00019792 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
2014-03-18 13:17 - 2012-11-24 17:13 - 00373312 _____ () C:\Program Files\Microsoft Office 15\ClientX64\c2rui.dll
2014-03-18 13:17 - 2012-12-07 07:04 - 00513616 _____ () C:\Program Files\Microsoft Office 15\ClientX64\c2r64.dll
2014-03-18 13:17 - 2012-12-07 07:05 - 00607312 _____ () C:\Program Files\Microsoft Office 15\ClientX64\StreamServer.dll
2014-03-18 13:19 - 2014-03-18 13:19 - 06522944 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2012-07-18 21:38 - 2012-07-18 21:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll
2011-08-12 17:57 - 2011-08-12 17:57 - 00437632 _____ () C:\Program Files\TOSHIBA\Hotkey\Hotkey\TcrdKBB.exe
2012-08-04 18:01 - 2012-08-04 18:01 - 00213136 _____ () C:\Program Files (x86)\Toshiba\System Setting\TODDMain.exe
2013-08-22 03:19 - 2013-08-22 02:54 - 00174592 _____ () C:\WINDOWS\system32\WinMetadata\Windows.UI.winmd
2013-08-22 03:19 - 2013-08-22 02:54 - 00050176 _____ () C:\WINDOWS\system32\WinMetadata\Windows.Data.winmd
2013-08-22 03:19 - 2013-08-22 02:54 - 00030208 _____ () C:\WINDOWS\system32\WinMetadata\Windows.Foundation.winmd
2015-05-19 12:41 - 2015-05-19 12:42 - 16980568 _____ () C:\Users\lisa\Downloads\RogueKiller.exe
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-10-22 08:24 - 2013-05-02 14:26 - 00387984 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\fl_core.dll
2013-10-22 08:24 - 2013-05-02 14:26 - 01165712 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_asr.dll
2013-10-22 08:24 - 2013-05-02 14:26 - 00199056 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_base.dll
2013-10-22 08:24 - 2013-05-02 14:26 - 01132944 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_pron.dll
2013-10-22 08:24 - 2013-05-02 14:26 - 00035216 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_platform.dll
2013-10-22 08:24 - 2013-05-02 14:26 - 00229264 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\sdxg.dll
2013-10-22 08:24 - 2013-05-02 14:25 - 00027648 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\WASAPIResamplingStreamCOMServer.dll
2013-10-22 07:45 - 2013-02-15 19:17 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-03-18 13:17 - 2014-03-18 13:19 - 00312896 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
2014-03-18 13:17 - 2014-03-18 13:20 - 00354368 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\c2r32.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\lisa\SkyDrive:ms-properties

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\lisa\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
DNS Servers: 192.168.254.254

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1534849743-2360249728-2914029306-1001\…\StartupApproved\Run: => "msnmsgr"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{39129AA4-BAAC-4C44-8519-EB16BEAFEBB4}] => (Allow) C:\Users\lisa\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [UDP Query User{7BE9C124-ED71-4D6C-9615-36DAEDB8941D}C:\users\lisa\appdata\local\dvo\cook'n11app\cook'n.exe] => (Allow) C:\users\lisa\appdata\local\dvo\cook'n11app\cook'n.exe
FirewallRules: [TCP Query User{F1D785B5-D38F-4036-80F0-D4F09762F2AE}C:\users\lisa\appdata\local\dvo\cook'n11app\cook'n.exe] => (Allow) C:\users\lisa\appdata\local\dvo\cook'n11app\cook'n.exe
FirewallRules: [{C3F1E823-6A92-4F88-A5E7-504AB0AB27C9}] => (Allow) C:\Users\lisa\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{D84119F5-E48D-4C6B-B0C6-962F4244CFCF}] => (Allow) C:\Users\lisa\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{4E518E67-5EF9-4D3A-99F7-4B855D7FD40C}] => (Allow) C:\Users\lisa\Downloads\BitTorrent.exe
FirewallRules: [{0C1A6F55-B43B-44E4-B997-B2347185239E}] => (Allow) C:\Users\lisa\Downloads\BitTorrent.exe
FirewallRules: [{B45E8E18-F3D6-4716-97CF-1D94DCD45ED2}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{F2895DE0-E5E6-4D99-8AE0-E08213C769B0}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{FE3ED9FF-FCBF-4A28-9643-F40120FE3950}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{B9B975A9-A459-43A8-8369-14BCD96B4B71}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1B2DEEA3-C2B8-4608-8521-3FD92F7EFD64}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C93B31A7-4AEB-4389-86FB-03024B5F41DB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{09E6CE16-EBF3-4AA8-BB47-284E5E4BE94D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{D2CBB744-FE92-4FD2-A35D-AD9E51210A06}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [TCP Query User{3BC30520-042A-430C-84A3-67E9590ACF8D}C:\users\lisa\appdata\local\dvo\cook'n11app\cook'n.exe] => (Allow) C:\users\lisa\appdata\local\dvo\cook'n11app\cook'n.exe
FirewallRules: [UDP Query User{6610C342-9AE8-44CA-9653-BA11EA426986}C:\users\lisa\appdata\local\dvo\cook'n11app\cook'n.exe] => (Allow) C:\users\lisa\appdata\local\dvo\cook'n11app\cook'n.exe
FirewallRules: [{3E50F616-D92C-4A2D-88FA-BADAB4E86C17}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{5864E6A5-4F7F-4B0F-9485-7B9024AA7360}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{27835C96-4AB8-4C0D-BF24-FE975E2D5963}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{BF941761-0EDD-487D-872A-3674D580DB64}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{4D856189-650A-4A5E-BF9E-16A73939172A}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{5951CE3B-2940-46B6-A779-144F0A685EFC}] => (Allow) LPort=2869
FirewallRules: [{1E26CA59-8673-4484-AB45-CBF158619195}] => (Allow) LPort=1900
FirewallRules: [{3385ABAC-963D-4183-B3A1-EA01A83AF8E2}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{98F869D7-34ED-470E-A522-F3E93C43C2F7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C3C8B9E7-1B84-4A81-85D6-DF864F4193D2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{F682C41A-30C6-4743-B8CE-DD8EF44210E2}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{09DCFCA3-1D4C-4676-AB9D-C3F53D8FAD38}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{78157483-CE5F-47B8-A699-56D1868FF263}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{76256D2D-DE6E-4754-9FF0-8392B136D3BA}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{898F3E80-DD24-4A89-8B67-D205ECA44D8D}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{96BD9797-4673-471A-AF88-89EE378AAF0B}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{C48EFA1B-1715-4756-96AF-250690A89041}] => (Allow) C:\Program Files\HP\HP Deskjet 3510 series\Bin\DeviceSetup.exe
FirewallRules: [{7071D33C-F40F-493A-B2EB-C80A7D439CB6}] => (Allow) C:\Program Files\HP\HP Deskjet 3510 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{2BC83413-C012-4F4E-BEA6-7098E22F4594}] => (Allow) C:\Program Files\HP\HP Deskjet 3510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{CEB8D2A2-A360-4DE1-8035-A6C08B84BCF7}] => (Allow) C:\Users\lisa\AppData\Local\Temp\nsiE1CE.tmp\CnetInstaller-10015432.exe
FirewallRules: [{C29E24C2-4A0C-40AE-8BBE-1E477B8048F0}] => (Allow) C:\Users\lisa\AppData\Local\Temp\nsiE1CE.tmp\CnetInstaller-10015432.exe
FirewallRules: [{042A94F7-D2D1-4101-A94C-61BD9981AEC0}] => (Allow) C:\Users\lisa\AppData\Local\Temp\nsmD19C.tmp\CnetInstaller-10015432.exe
FirewallRules: [{8B97A043-6DD8-42B9-A7AB-1830FF37A515}] => (Allow) C:\Users\lisa\AppData\Local\Temp\nsmD19C.tmp\CnetInstaller-10015432.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/19/2015 00:44:47 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -2143485933

Error: (05/19/2015 00:44:47 PM) (Source: Microsoft Office 15) (EventID: 2011) (User: )
Description: Office Subscription licensing exception: Error Code: 0x5; CorrelationId: {77CA3CEE-B9EA-418E-A413-8ABCF72DC194}

Error: (05/19/2015 00:31:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 12766

Error: (05/19/2015 00:31:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 12766

Error: (05/19/2015 00:31:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (05/18/2015 11:55:30 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/18/2015 11:55:30 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/18/2015 11:55:30 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/18/2015 11:55:30 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (05/18/2015 11:43:47 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.


System errors:
=============
Error: (05/19/2015 00:43:02 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Windows\System32\drivers\TrueSight.sys

Error: (05/18/2015 07:08:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) PROSet/Wireless Zero Configuration Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/18/2015 07:04:16 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The BlueStacks Android Service service terminated with the following error:
%%1064

Error: (05/18/2015 07:03:11 PM) (Source: BTHUSB) (EventID: 30) (User: )
Description: The local adapter does not support an important Low Energy controller state.  The minimum required supported state mask is 0x1f7fffff, got 0x1f3fffff.  Low Energy functionality will be disabled.

Error: (05/18/2015 07:03:19 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 5:40:54 PM on ‎5/‎18/‎2015 was unexpected.

Error: (05/15/2015 06:24:57 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.

Error: (05/15/2015 06:22:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) PROSet/Wireless Zero Configuration Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (05/15/2015 06:21:40 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The BlueStacks Android Service service terminated with the following error:
%%1064

Error: (05/15/2015 06:20:46 PM) (Source: BTHUSB) (EventID: 30) (User: )
Description: The local adapter does not support an important Low Energy controller state.  The minimum required supported state mask is 0x1f7fffff, got 0x1f3fffff.  Low Energy functionality will be disabled.

Error: (05/15/2015 06:20:54 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 5:53:57 PM on ‎5/‎15/‎2015 was unexpected.


Microsoft Office Sessions:
=========================
Error: (05/19/2015 00:44:47 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -2143485933

Error: (05/19/2015 00:44:47 PM) (Source: Microsoft Office 15) (EventID: 2011) (User: )
Description: Office Subscription licensing exception: Error Code: 0x5; CorrelationId: {77CA3CEE-B9EA-418E-A413-8ABCF72DC194}

Error: (05/19/2015 00:31:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 12766

Error: (05/19/2015 00:31:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 12766

Error: (05/19/2015 00:31:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (05/18/2015 11:55:30 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe after effects cs5.5\support files\(PCI)\Setup\resources\libraries\ARKEngine.dll

Error: (05/18/2015 11:55:30 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe after effects cs5.5\support files\(PCI)\Setup\resources\libraries\ARKCmdFS.dll

Error: (05/18/2015 11:55:30 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe after effects cs5.5\support files\(PCI)\Setup\resources\libraries\ARKCmdCaps.dll

Error: (05/18/2015 11:55:30 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe after effects cs5.5\support files\(PCI)\Setup\resources\libraries\ARKCmdDefrag.dll

Error: (05/18/2015 11:43:47 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe after effects cs5.5\support files\(PCI)\Setup\resources\libraries\ARKEngine.dll


CodeIntegrity Errors:
===================================
  Date: 2015-05-11 12:06:45.078
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-11 12:06:44.864
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-11 12:06:44.544
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-11 12:06:44.335
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-11 12:06:43.545
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-11 12:06:43.314
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-11 12:06:43.031
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-11 12:06:42.801
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-11 12:06:42.164
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-11 12:06:41.983
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-4700MQ CPU @ 2.40GHz
Percentage of memory in use: 44%
Total physical RAM: 8116.09 MB
Available physical RAM: 4510.71 MB
Total Pagefile: 9396.09 MB
Available Pagefile: 5822.01 MB
Total Virtual: 131072 MB
Available Virtual: 131071.78 MB

==================== Drives ================================

Drive c: (TI10671100B) (Fixed) (Total:684.67 GB) (Free:64.19 GB) NTFS
Drive e: (TOSHIBA EXT) (Fixed) (Total:465.66 GB) (Free:13.63 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 1EE33B89)
Partition 1: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Hi Selene and thank you for the logs.

Unfortunately your screenshot didn’t seem to work.

I’d like you to run another couple of scans please.


Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

Logs to include with next post:

AdwCleaner log
JRT.txt


Thanks

Satchfan

 

thank you SO much for all your help … will look for your reply when you can get to it :)

 

adware cleaner log

 

# AdwCleaner v4.204 - Logfile created 19/05/2015 at 19:24:38
# Updated 12/05/2015 by Xplode
# Database : 2015-05-12.2 [Server]
# Operating system : Windows 8.1  (x64)
# Username : lisa - LISASCOMPUTER
# Running from : C:\Users\lisa\Downloads\adwcleaner_4.204.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\lisa\AppData\Local\pokki
File Deleted : C:\Users\lisa\AppData\Roaming\Mozilla\Firefox\Profiles\e1rp9nct.default\invalidprefs.js

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Pokki
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.ask.com
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Mozilla Firefox v38.0.1 (x86 en-US)

[e1rp9nct.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxps://search.yahoo.com/?type=916552&fr=spigot-yhp-ff");

*************************

AdwCleaner[R0].txt - [1454 bytes] - [19/05/2015 19:22:36]
AdwCleaner[S0].txt - [1365 bytes] - [19/05/2015 19:24:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1424  bytes] ##########
 

junkware removal tool log

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.7.4 (05.19.2015:1)
OS: Windows 8.1 x64
Ran by [removed] on Tue 05/19/2015 at 19:35:14.28
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks

Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-1534849743-2360249728-2914029306-1001
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-1534849743-2360249728-2914029306-500
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-1552460959-2917427732-1605978890-500



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] C:\Program Files (x86)\free youtube downloader
Successfully deleted: [Folder] C:\ProgramData\free youtube downloader
Successfully deleted: [Folder] C:\Users\lisa\appdata\local\free youtube downloader



~~~ FireFox

Emptied folder: C:\Users\lisa\AppData\Roaming\mozilla\firefox\profiles\e1rp9nct.default\minidumps [27 files]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 05/19/2015 at 19:36:54.21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

It’s a good idea to move Farbar Recovery Scan Tool to your desktop otherwise future fixes may not work.

  • go to your Downloads folder and locate Farbar Recovery Scan Tool
  • right click and select Cut
  • go to an empty spot on your desktop, right click and select Paste

Farbar Recovery Scan Tool should now be on your desktop.

===================================================

P2P - I see you have P2P software, (BitTorrent ), installed on your machine. Although BitTorrent itself is a legitimate program, it is usually seen here in conjunction with other programs used for P2P file-sharing.

We are not here to pass judgment on file-sharing as a concept but we will warn you that engaging in this activity will always make your computer very susceptible to infection and re-infection.

It has almost certainly contributed to your current situation and with all that has been downloaded via this, cleaning your computer is definitely only a temporary measure as you will become re-infected.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. Those who write malware use P2P file-sharing as a major vehicle to spread their wares.

Please see this topic for more information:

P2P File Sharing Risks.

I would strongly recommend that you uninstall it now and get rid of the downloads. You can do so via Control Panel, Programs, and then Programs and Features and by deleting what is in your Downloads folder that originated from torrent downloads.

Should you decide to keep using it, please don’t use it until we have finished up here.

===================================================

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below.
 

ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
S3 iscFlash; C:\Windows\Temp\ArchesP10SP10SG_BIOS_V150_WIN\x64\iscflashx64.sys [60680 2013-02-24] (Insyde Software)
T8X8R_act_1_.exe
C:\Users\lisa\AppData\Local\Temp\vlc-2.1.5-win32.exe
FirewallRules: [{78157483-CE5F-47B8-A699-56D1868FF263}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{76256D2D-DE6E-4754-9FF0-8392B136D3BA}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{898F3E80-DD24-4A89-8B67-D205ECA44D8D}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{96BD9797-4673-471A-AF88-89EE378AAF0B}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
FirewallRules: [{CEB8D2A2-A360-4DE1-8035-A6C08B84BCF7}] => (Allow) C:\Users\lisa\AppData\Local\Temp\nsiE1CE.tmp\CnetInstaller-10015432.exe
FirewallRules: [{C29E24C2-4A0C-40AE-8BBE-1E477B8048F0}] => (Allow) C:\Users\lisa\AppData\Local\Temp\nsiE1CE.tmp\CnetInstaller-10015432.exe
FirewallRules: [{042A94F7-D2D1-4101-A94C-61BD9981AEC0}] => (Allow) C:\Users\lisa\AppData\Local\Temp\nsmD19C.tmp\CnetInstaller-10015432.exe
FirewallRules: [{8B97A043-6DD8-42B9-A7AB-1830FF37A515}] => (Allow) C:\Users\lisa\AppData\Local\Temp\nsmD19C.tmp\CnetInstaller-10015432.exe
C:\Users\ADMINI~1\AppData\Local\Temp\CreateToastShortcut.exe
C:\Users\ADMINI~1\AppData\Local\Temp\CreateToastShortcutDll.dll
C:\Users\ADMINI~1\AppData\Local\Temp\StartMenu.exe
C:\Users\ADMINI~1\AppData\Local\Temp\TosNoRestart.exe
C:\Users\lisa\AppData\Local\Temp\0khuip0z.exe
C:\Users\lisa\AppData\Local\Temp\2144a3fc.exe
C:\Users\lisa\AppData\Local\Temp\2de3q4pw.exe
C:\Users\lisa\AppData\Local\Temp\30lgxs3n.exe
C:\Users\lisa\AppData\Local\Temp\dllnt_dump.dll
C:\Users\lisa\AppData\Local\Temp\ICReinstall_FreeYouTubeDownloaderIC.exe
C:\Users\lisa\AppData\Local\Temp\jppp4ima.exe
C:\Users\lisa\AppData\Local\Temp\KUIU.EXE
C:\Users\lisa\AppData\Local\Temp\OfficeSetup.exe
C:\Users\lisa\AppData\Local\Temp\SetupO365HomePremRetail.x86.en-US_O365HomePremRetail_2YN83-2CCRJ-M2DJH-Q9Q4K-
C:\Program Files (x86)\360\Total Security
C:\Users\lisa\AppData\Local\Temp\nsiE1CE.tmp\CnetInstaller-10015432.exe
C:\Users\lisa\AppData\Local\Temp\nsmD19C.tmp\CnetInstaller-10015432.exe

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

===================================================

Run CKScanner

Download CKScanner by askey127 from here & save it to your Desktop.

  • double-click CKScanner.exe then click Search For Files
  • when the cursor hourglass disappears, click Save List To File
  • a message box will verify the file saved
  • double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply.

Satchfan

 

Hi Selene

It has been several days since I sent my last set of instructions to help with your computer problem.

Please let me know if you are having problems and still need help.

Thanks

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI