This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow laptop, delayed data entry and webpage loading [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please find recommended logs for review.

Laptop has become painfully solw in accepting any alphanumeric data entry

Website page loading is also crawling

 

Thanks for any help

Brian

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-05-24 10:12:15
—————————–
10:12:15.159    OS Version: Windows x64 6.0.6002 Service Pack 2
10:12:15.159    Number of processors: 2 586 0x170A
10:12:15.160    ComputerName: DADSSTUDIO-PC  UserName: Dads  Studio
10:12:17.431    Initialize success
10:12:17.718    VM: initialized successfully
10:12:17.721    VM: Intel CPU BiosDisabled
10:14:50.671    AVAST engine defs: 15052400
10:15:10.242    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
10:15:10.249    Disk 0 Vendor: ST500LT012-1DG142 0001SDM1 Size: 476940MB BusType: 3
10:15:10.546    Disk 0 MBR read successfully
10:15:10.554    Disk 0 MBR scan
10:15:10.623    Disk 0 Windows VISTA default MBR code
10:15:10.673    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       476938 MB offset 2048
10:15:11.201    Disk 0 scanning C:\Windows\system32\drivers
10:15:30.016    Service scanning
10:16:17.815    Modules scanning
10:16:17.818    Disk 0 trace - called modules:
10:16:17.858    ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
10:16:17.900    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800293d5a0]
10:16:17.901    3 CLASSPNP.SYS[fffffa6000dc6c33] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8002782590]
10:16:19.709    AVAST engine scan C:\Windows
10:16:32.191    AVAST engine scan C:\Windows\system32
10:26:12.768    AVAST engine scan C:\Windows\system32\drivers
10:26:48.583    AVAST engine scan C:\Users\Dads  Studio
10:35:11.440    Disk 0 MBR has been saved successfully to "C:\Users\Dads  Studio\Desktop\What the tech 052015\MBR.dat"
10:35:11.440    The log file has been saved successfully to "C:\Users\Dads  Studio\Desktop\What the tech 052015\aswMBR.txt"

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-05-2015
Ran by [removed] (administrator) on DADSSTUDIO-PC on 24-05-2015 10:24:17
Running from C:\Users\[removed]\Downloads
[removed] Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(SugarSync, Inc.) C:\Program Files (x86)\SugarSync\SugarSync.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
() C:\Program Files (x86)\SurfEasy VPN\client\SurfEasyService.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(AVAST Software) C:\Users\Dads  Studio\Downloads\aswMBR.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-20] (Microsoft Corporation)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1822504 2009-08-24] (Synaptics Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3745744 2015-05-18] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\Run: [SugarSync] => C:\Program Files (x86)\SugarSync\SugarSync.exe [13119328 2014-05-06] (SugarSync, Inc.)
HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2014-03-26] (Google Inc.)
HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8204056 2015-04-23] (Piriform Ltd)
HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\MountPoints2: {3ff4a206-b3a4-11e3-9313-806e6f6e6963} - D:\TnT.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2014-04-23]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll No File
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2014-05-06] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2014-05-06] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {39D54CC2-69CF-43b4-B167-577D25E7F496} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2014-05-06] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2014-05-06] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncSharedPending] -> {F7395C2E-A5D8-4a32-9536-5C6A9F1DC450} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2014-05-06] (SugarSync, Inc.)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

SearchScopes: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000 -> DefaultScope {E76CC469-6279-4733-B834-25E493546AA9} URL = http://www.google.com/search?q={searchTerms}&rls;=com.microsoft:{language}&ie;={inputEncoding}&oe;={outputEncoding}&startIndex;={startIndex?}&startPage;={startPage}&rlz;=1I7PRFD_enUS582
SearchScopes: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000 -> {E76CC469-6279-4733-B834-25E493546AA9} URL = http://www.google.com/search?q={searchTerms}&rls;=com.microsoft:{language}&ie;={inputEncoding}&oe;={outputEncoding}&startIndex;={startIndex?}&startPage;={startPage}&rlz;=1I7PRFD_enUS582
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-01] (Google Inc.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-01] (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-01] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-01] (Google Inc.)
Toolbar: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-01] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]

FireFox:
========
FF ProfilePath: C:\Users\Dads  Studio\AppData\Roaming\Mozilla\Firefox\Profiles\ae25cr0d.default
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google
FF Homepage: about:home
FF Keyword.URL:
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1214154.dll [2014-11-26] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
FF HKLM-x32\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-03-25]

Chrome:
=======
CHR Profile: C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-26]
CHR Extension: (Google Drive) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-26]
CHR Extension: (YouTube) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-26]
CHR Extension: (Google Search) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-26]
CHR Extension: (Bookmark Manager) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-27]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Google Wallet) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-26]
CHR Extension: (Gmail) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-26]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3438544 2015-05-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [311792 2015-05-18] (AVG Technologies CZ, s.r.o.)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-02-28] (Hewlett-Packard Co.) []
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-02-28] (Hewlett-Packard Co.) []
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) []
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) []
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 SurfEasyVPN; C:\Program Files (x86)\SurfEasy VPN\client\SurfEasyService.exe [3186360 2014-08-26] ()
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-20] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [260888 2014-12-08] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [203544 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [256992 2015-04-15] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [220128 2015-05-07] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [270616 2014-07-02] (AVG Technologies CZ, s.r.o.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 OA008Ufd; C:\Windows\System32\DRIVERS\OA008Ufd.sys [159840 2009-03-06] (Creative Technology Ltd.)
R3 OA008Vid; C:\Windows\System32\DRIVERS\OA008Vid.sys [313696 2009-05-06] (Creative Technology Ltd.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
R3 SSCBFS3; C:\Windows\System32\DRIVERS\sscbfs3.sys [347904 2013-01-30] (EldoS Corporation)
R3 tapse01; C:\Windows\System32\DRIVERS\tapse01.sys [39608 2014-05-14] (The OpenVPN Project)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U3 aswMBR; \??\C:\Users\DADSST~1\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\DADSST~1\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-24 10:24 - 2015-05-24 10:26 - 00014333 _____ () C:\Users\Dads  Studio\Downloads\FRST.txt
2015-05-24 10:21 - 2015-05-24 10:24 - 00000000 ____D () C:\FRST
2015-05-24 10:20 - 2015-05-24 10:21 - 02108416 _____ (Farbar) C:\Users\Dads  Studio\Downloads\FRST64.exe
2015-05-24 10:11 - 2015-05-24 10:11 - 05198336 _____ (AVAST Software) C:\Users\Dads  Studio\Downloads\aswMBR.exe
2015-05-23 10:55 - 2015-05-23 10:55 - 00000354 _____ () C:\Windows\PFRO.log
2015-05-23 05:09 - 2015-05-23 05:09 - 00000000 ____D () C:\Users\Dads  Studio\AppData\Local\Avg
2015-05-22 10:03 - 2015-05-22 10:03 - 00002814 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-05-22 10:03 - 2015-05-22 10:03 - 00000770 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-05-22 10:03 - 2015-05-22 10:03 - 00000000 ____D () C:\Program Files\CCleaner
2015-05-22 10:00 - 2015-05-22 10:00 - 06484352 _____ (Piriform Ltd) C:\Users\Dads  Studio\Downloads\ccsetup505.exe
2015-05-19 16:21 - 2015-05-19 16:21 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-05-19 11:14 - 2015-05-19 11:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-14 22:43 - 2015-05-14 22:44 - 71807792 _____ (Apple Inc.) C:\Users\Dads  Studio\Downloads\iCloudSetup(1).exe
2015-05-13 03:45 - 2015-04-19 17:24 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2015-05-13 03:45 - 2015-04-19 17:24 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2015-05-13 03:45 - 2015-04-19 17:24 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2015-05-13 03:45 - 2015-04-19 17:24 - 00160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2015-05-13 03:45 - 2015-04-19 16:19 - 01172480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2015-05-13 03:45 - 2015-04-19 16:18 - 00486400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2015-05-13 03:45 - 2015-04-19 16:13 - 00682496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2015-05-13 03:45 - 2015-04-19 16:12 - 01072640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-13 03:45 - 2015-04-17 20:16 - 01268224 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-05-13 03:45 - 2015-04-17 20:16 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-05-13 03:45 - 2015-04-17 20:16 - 00287232 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-05-13 03:45 - 2015-04-17 20:16 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-05-13 03:45 - 2015-04-17 19:45 - 02002944 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-05-13 03:45 - 2015-04-17 19:44 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-05-13 03:45 - 2015-04-17 19:35 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-05-13 03:45 - 2015-04-17 19:33 - 01561088 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 03:45 - 2015-04-17 19:33 - 01154048 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 03:45 - 2015-04-17 19:30 - 02793472 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 03:12 - 2015-04-30 12:03 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-13 03:12 - 2015-04-30 11:41 - 00347648 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 03:05 - 2015-04-10 19:33 - 00384512 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-13 03:05 - 2015-04-10 19:22 - 00279552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\services.exe
2015-05-13 03:04 - 2015-04-30 09:14 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 03:04 - 2015-04-30 09:14 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 01:24 - 2015-04-09 19:52 - 02339840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 01:24 - 2015-04-09 19:47 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 01:24 - 2015-04-09 19:46 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 01:24 - 2015-04-09 19:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-13 01:24 - 2015-04-09 19:45 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-13 01:24 - 2015-04-09 19:45 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 01:24 - 2015-04-09 19:45 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 01:24 - 2015-04-09 19:14 - 12379136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-13 01:24 - 2015-04-09 19:10 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-13 01:24 - 2015-04-09 19:05 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-13 01:24 - 2015-04-09 19:04 - 00421888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-13 01:24 - 2015-04-09 19:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-05-13 01:24 - 2015-04-09 19:03 - 00718336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-13 01:24 - 2015-04-09 19:03 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-05-13 01:24 - 2015-04-09 19:03 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-13 01:24 - 2015-04-09 19:03 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-05-13 01:24 - 2015-04-09 19:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-13 01:23 - 2015-04-09 20:10 - 17881088 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 01:23 - 2015-04-09 19:55 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 01:23 - 2015-04-09 19:53 - 10935808 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 01:23 - 2015-04-09 19:48 - 01388032 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 01:23 - 2015-04-09 19:46 - 02158080 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 01:23 - 2015-04-09 19:46 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 01:23 - 2015-04-09 19:46 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 01:23 - 2015-04-09 19:46 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 01:23 - 2015-04-09 19:46 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-13 01:23 - 2015-04-09 19:46 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 01:23 - 2015-04-09 19:46 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-05-13 01:23 - 2015-04-09 19:46 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-13 01:23 - 2015-04-09 19:45 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-05-13 01:23 - 2015-04-09 19:45 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-05-13 01:23 - 2015-04-09 19:45 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-05-13 01:23 - 2015-04-09 19:08 - 09750528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-13 01:23 - 2015-04-09 19:08 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-13 01:23 - 2015-04-09 19:05 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-13 01:23 - 2015-04-09 19:04 - 01804288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-13 01:23 - 2015-04-09 19:04 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-13 01:23 - 2015-04-09 19:04 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-05-13 01:23 - 2015-04-09 19:04 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-05-13 01:23 - 2015-04-09 19:03 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-13 01:23 - 2015-04-09 19:03 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-05-13 01:23 - 2015-04-09 19:03 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-05-13 01:23 - 2015-04-09 19:03 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-05-13 01:23 - 2015-04-09 19:03 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2015-05-07 13:50 - 2015-05-07 13:50 - 00378336 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
2015-05-07 13:49 - 2015-05-07 13:49 - 00220128 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2015-05-07 00:07 - 2015-05-07 00:07 - 00768899 _____ () C:\Users\Dads  Studio\Downloads\electronically signed form
2015-05-04 17:22 - 2015-05-13 12:08 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Bronco Wine Company
2015-04-29 11:47 - 2015-04-29 11:47 - 00000000 ____D () C:\Users\Dads  Studio\Documents\A CUSTOMER REPORT
2015-04-29 11:02 - 2015-04-29 11:02 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Vcard
2015-04-24 15:22 - 2015-05-22 09:51 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Frolish Wine Merchants

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-24 10:14 - 2014-03-24 15:43 - 00000732 _____ () C:\Users\Dads  Studio\AppData\Local\d3d9caps64.dat
2015-05-24 10:14 - 2006-11-02 11:22 - 00003712 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-24 10:14 - 2006-11-02 11:22 - 00003712 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-24 10:02 - 2014-12-01 12:23 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-24 10:01 - 2014-03-26 16:08 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-24 09:58 - 2008-01-20 21:53 - 01896782 _____ () C:\Windows\WindowsUpdate.log
2015-05-24 09:44 - 2014-03-26 15:58 - 00002651 _____ () C:\Users\Dads  Studio\Desktop\Microsoft Office Word 2007.lnk
2015-05-24 05:13 - 2014-10-30 10:05 - 00000872 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2015-05-24 05:13 - 2014-03-25 12:55 - 00000000 ____D () C:\ProgramData\MFAData
2015-05-23 16:01 - 2014-03-26 16:08 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-23 11:28 - 2015-03-30 11:50 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Conquer Cancer Ride
2015-05-23 10:56 - 2006-11-02 11:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-22 10:47 - 2006-11-02 11:42 - 00032536 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-22 10:16 - 2014-03-26 13:42 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-22 10:16 - 2014-03-26 13:42 - 00000941 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-22 10:16 - 2014-03-26 13:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-22 10:16 - 2014-03-26 13:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-22 10:14 - 2014-05-10 11:15 - 00000000 ____D () C:\Users\Dads  Studio\AppData\Roaming\TeamViewer
2015-05-22 10:12 - 2014-03-24 19:32 - 00000000 ____D () C:\Windows\Panther
2015-05-20 10:32 - 2014-04-09 14:06 - 00000680 _____ () C:\Users\Dads  Studio\AppData\Local\d3d9caps.dat
2015-05-19 19:13 - 2014-03-31 14:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-19 16:22 - 2014-04-12 09:41 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2015-05-19 16:16 - 2014-03-26 16:09 - 00002025 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-19 16:00 - 2006-11-02 08:46 - 00762930 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-19 15:59 - 2014-06-23 14:34 - 00000000 ____D () C:\Users\Dads  Studio\Documents\My Scans
2015-05-19 15:50 - 2006-11-02 08:34 - 00000275 _____ () C:\Windows\win.ini
2015-05-18 13:41 - 2014-03-26 15:58 - 00002609 _____ () C:\Users\Dads  Studio\Desktop\Microsoft Office Excel 2007.lnk
2015-05-16 15:56 - 2014-03-26 16:08 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-16 15:56 - 2014-03-26 16:08 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-14 22:55 - 2015-02-26 17:34 - 00047616 _____ () C:\Users\Dads  Studio\Desktop\Backup Assistant 022615.xlsx
2015-05-14 14:12 - 2014-04-16 10:34 - 00000000 ____D () C:\Users\Dads  Studio\AppData\Local\SugarSync
2015-05-13 04:10 - 2006-11-02 11:21 - 00282760 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-13 04:09 - 2014-04-07 10:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-05-13 04:04 - 2006-11-02 11:07 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-13 03:38 - 2014-03-26 15:38 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-05-13 03:37 - 2014-03-25 02:05 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-13 03:18 - 2006-11-02 08:35 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-05-13 03:05 - 2006-11-02 11:07 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
2015-05-13 03:03 - 2014-04-07 10:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-12 19:14 - 2014-09-02 19:03 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Boys stuff
2015-05-07 14:20 - 2014-10-29 10:23 - 00000000 ____D () C:\Users\Dads  Studio\Desktop\Winejob.com
2015-05-06 12:09 - 2014-07-02 14:22 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Photos
2015-05-06 11:46 - 2014-04-15 01:25 - 00000000 ____D () C:\Users\Dads  Studio\Desktop\Irish Language
2015-04-24 14:35 - 2014-11-06 17:20 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Franki Wines

==================== Files in the root of some directories =======

2014-04-13 10:16 - 2014-04-13 10:16 - 0000552 _____ () C:\Users\Dads  Studio\AppData\Local\d3d8caps.dat
2014-04-09 14:06 - 2015-05-20 10:32 - 0000680 _____ () C:\Users\Dads  Studio\AppData\Local\d3d9caps.dat
2014-03-24 15:43 - 2015-05-24 10:14 - 0000732 _____ () C:\Users\Dads  Studio\AppData\Local\d3d9caps64.dat
2014-07-02 14:21 - 2014-07-02 14:21 - 0003584 _____ () C:\Users\Dads  Studio\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-23 14:04 - 2014-06-25 15:05 - 0001329 _____ () C:\ProgramData\hpzinstall.log
2014-04-14 13:26 - 2014-04-14 14:20 - 0000298 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-23 23:34

==================== End of log ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-05-2015
Ran by [removed] at 2015-05-24 10:26:51
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2950505590-1508067594-3318522798-500 - Administrator - Disabled)
Dads  Studio (S-1-5-21-2950505590-1508067594-3318522798-1000 - Administrator - Enabled) => C:\Users\Dads  Studio
Guest (S-1-5-21-2950505590-1508067594-3318522798-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader X (10.1.14) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.14 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.4.154 - Adobe Systems, Inc.)
AIO_CDA_ProductContext (x32 Version: 82.0.233.000 - Hewlett-Packard) Hidden
AIO_CDA_Software (x32 Version: 82.0.233.000 - Hewlett-Packard) Hidden
AIO_CDA_ToolboxIni64 (Version: 82.0.233.000 - Hewlett-Packard) Hidden
AIO_Scan (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AudioNote (HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\edac8a894d3918af) (Version: 2.4.0.21 - AudioNote)
AVG 2015 (HKLM\…\AVG) (Version: 2015.0.5961 - AVG Technologies)
AVG 2015 (Version: 15.0.4347 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.5961 - AVG Technologies) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom Gigabit NetLink Controller (HKLM\…\{9AF0B106-56F1-461B-A270-95BC1682E282}) (Version: 11.22.02 - Broadcom Corporation)
BufferChm (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
C3100 (x32 Version: 82.0.233.000 - Hewlett-Packard) Hidden
c3100_Help (x32 Version: 82.0.233.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.05 - Piriform)
Copy (x32 Version: 82.0.188.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
Dell Resource CD (HKLM-x32\…\{42929F0F-CE14-47AF-9FC7-FF297A603021}) (Version: 1.00.0000 - Dell Inc.)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.0.6584.52 - Dell)
Dell System Detect (HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\73f463568823ebbe) (Version: 5.14.0.9 - Dell)
Dell Touchpad (HKLM\…\SynTPDeinstKey) (Version: 14.0.2.0 - Synaptics Incorporated)
Destinations (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
DocProc (x32 Version: 8.1.0.0 - Hewlett-Packard) Hidden
DocProcQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
eSupportQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
Fax (x32 Version: 82.0.188.000 - Hewlett-Packard) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 43.0.2357.65 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.1.0.0 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
HP Customer Participation Program 8.0 (HKLM\…\HPExtendedCapabilities) (Version: 8.0 - HP)
HP Imaging Device Functions 8.0 (HKLM\…\HP Imaging Device Functions) (Version: 8.0 - HP)
HP OCR Software 8.0 (HKLM\…\HPOCR) (Version: 8.0 - HP)
HP Photosmart Essential (HKLM-x32\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
HP Photosmart.All-In-One Driver Software 8.0 .A (HKLM\…\{282E5AB2-8E47-4571-B6FA-6B512555B557}) (Version: 8.0 - HP)
HP Product Detection (HKLM-x32\…\{A436F67F-687E-4736-BD2B-537121A804CF}) (Version: 11.14.0001 - HP)
HP Solution Center 8.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 8.0 - HP)
HP Support Solutions Framework (HKLM-x32\…\{E35601C0-BA8E-4F32-919A-C7EF4CA81F67}) (Version: 11.51.0048 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPProductAssistant (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
HPSSupply (HKLM-x32\…\{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}) (Version: 2.1.3.0000 - Hewlett Packard Development Company L.P.)
Integrated Webcam Driver (1.04.01.0601)   (HKLM\…\Creative OA008) (Version: 1.04.01.0601 - Creative Technology Ltd.)
Intel(R) PROSet/Wireless WiFi Driver (HKLM\…\{AFE36C05-B442-4DEA-9BFB-2D72C8A1E153}) (Version: 12.00.2000 - Intel(R) Corporation)
iTunes (HKLM\…\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MarketResearch (x32 Version: 82.0.174.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Standard Edition 2003 (HKLM-x32\…\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Mozilla Firefox 38.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 38.0.1 (x86 en-US)) (Version: 38.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
MSXML 4.0 SP2 (KB927978) (HKLM-x32\…\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Scan (x32 Version: 8.1.0.0 - Hewlett-Packard) Hidden
Secunia PSI (3.0.0.9016) (HKLM-x32\…\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
Sharepod 4.0.3.0 (HKLM-x32\…\{085BCFB8-F6FB-4600-AFAB-1F6DBC7F5F99}_is1) (Version:  - Macroplant LLC)
SolutionCenter (x32 Version: 82.0.188.000 - Hewlett-Packard) Hidden
Speccy (HKLM\…\Speccy) (Version: 1.25 - Piriform)
Status (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
SugarSync (HKLM-x32\…\SugarSync) (Version: 2.0.46.127183 - SugarSync, Inc.)
SurfEasy VPN 1.1.244 (HKLM-x32\…\SurfEasy VPN) (Version: 1.1.244 - SurfEasy Inc)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TaxACT 2014 - 1040 Edition (HKLM-x32\…\TaxACT 2014 - 1040 Edition) (Version: 1.07 - TaxACT, Inc.)
TaxACT 2014 New York (HKLM-x32\…\TaxACT 2014 New York) (Version: 1.01 - TaxACT, Inc.)
Toolbox (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 82.0.188.000 - Hewlett-Packard) Hidden
TurboTax 2013 (HKLM-x32\…\TurboTax 2013) (Version: 2013.0 - Intuit, Inc)
UnloadSupport (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WebReg (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{0567D11D-2F6E-4683-8028-A2807502980B}\InprocServer32 -> C:\Users\Dads  Studio\AppData\Local\Apps\2.0\4PXPGMY8.1LV\YH6NXN33.E9G\audi..tion_73447d47768363b2_0002.0004_9d08baecd2a6a08c\Tools\AudioNoteIFilter\x64\AudioNoteFilter.DLL ()
CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{3A999A50-AB25-4A20-90A9-08F71FCE320F}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\x64\3\HPCDMC64.DLL (HP)
CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{7c478185-9d61-48db-b80f-aab34c598056}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{98087D89-B93F-4BCF-A998-AE4D9F607C14}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\x64\3\HPCDMC64.DLL (HP)
CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{ac97aa90-7827-458c-85e7-9108e267c8c6}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{B286F068-5B17-4AE8-989B-8F9A199C47BA}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\x64\3\HPCDMC64.DLL (HP)
CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{d2d3ab63-fa40-4490-b717-ae00bc9258a2}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)

==================== Restore Points =========================

02-05-2015 11:33:08 Scheduled Checkpoint
03-05-2015 00:00:09 Scheduled Checkpoint
03-05-2015 13:17:20 Scheduled Checkpoint
04-05-2015 09:49:57 Scheduled Checkpoint
05-05-2015 13:50:09 Scheduled Checkpoint
06-05-2015 11:20:40 Scheduled Checkpoint
07-05-2015 13:30:19 Scheduled Checkpoint
11-05-2015 12:58:26 Scheduled Checkpoint
13-05-2015 03:00:36 Windows Update
14-05-2015 00:00:19 Scheduled Checkpoint
15-05-2015 10:17:26 Scheduled Checkpoint
16-05-2015 00:00:04 Scheduled Checkpoint
17-05-2015 00:06:16 Scheduled Checkpoint
18-05-2015 00:00:12 Scheduled Checkpoint
19-05-2015 00:15:47 Scheduled Checkpoint
19-05-2015 21:09:50 Scheduled Checkpoint
20-05-2015 11:52:27 Scheduled Checkpoint
21-05-2015 00:00:13 Scheduled Checkpoint
22-05-2015 00:00:20 Scheduled Checkpoint
23-05-2015 00:00:10 Scheduled Checkpoint
23-05-2015 13:01:40 Scheduled Checkpoint

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 08:34 - 2006-09-18 17:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {2CF0DD28-652A-4A6D-9E33-348FD63FF5BC} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {396A6BB3-7B4C-40C9-8D18-56EF345ADE29} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-02-03] (PC-Doctor, Inc.)
Task: {42319CD8-FBFA-4A35-A018-C11BE1C485C8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-23] (Piriform Ltd)
Task: {98422CB0-DCAE-4D8B-85D0-D9A9DC02FC18} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-26] (Google Inc.)
Task: {A4143DEB-7DD6-4840-8A87-41F3C0B2978B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-26] (Google Inc.)
Task: {A6831919-408C-4A5E-8A34-52E56C9150CF} - System32\Tasks\{60DD20DA-BF68-4485-9483-3E1FE174D8C4} => pcalua.exe -a "C:\Program Files (x86)\Print Server\PTP\SetupWizard.exe" -d "C:\Program Files (x86)\Print Server\PTP"
Task: {BF46079D-C61B-4E14-8C1D-C0244170C8FB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {DC8824F2-C9F6-4A20-A4A9-6E65BB058AAD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-14] (Adobe Systems Incorporated)
Task: {F2EE882F-37C3-4828-8E1C-B780784B8876} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Dads  Studio => C:\Program Files (x86)\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-09-08 10:59 - 2014-08-26 14:29 - 03186360 _____ () C:\Program Files (x86)\SurfEasy VPN\client\SurfEasyService.exe
2013-10-03 18:28 - 2013-10-03 18:28 - 00052736 _____ () C:\Program Files (x86)\SugarSync\librsync.dll
2014-02-26 23:16 - 2014-05-06 14:35 - 00238944 _____ () C:\Program Files (x86)\SugarSync\SugarSyncVFSNamespace32.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\dell.com -> dell.com
IE trusted site: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\intuit.com -> hxxps://accounts.intuit.com


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\img16.jpg
DNS Servers: [removed] - [removed]

==================== MSCONFIG/TASK MANAGER Error getting ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: DellSystemDetect => C:\Users\Dads  Studio\AppData\Local\Apps\2.0\4PXPGMY8.1LV\YH6NXN33.E9G\dell..tion_e30b47f5d4a30e9e_0005.000c_1df9a4898fae00de\DellSystemDetect.exe
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: PrintServer Diagnostic => "C:\Program Files (x86)\Print Server\PTP\PSDiagnostic.exe"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [{59711385-82A6-477E-8339-CA9436EA03B1}] => (Allow) LPort=80
FirewallRules: [{D2128CC5-9561-4905-8E7B-07CBB19954A7}] => (Allow) LPort=80
FirewallRules: [{8B1F54C4-B388-4FA6-BA7D-55DD6B6F1C81}] => (Allow) LPort=80
FirewallRules: [{A14C5AE7-9B05-4D46-8C44-3E9DA15E0E46}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{32EE2F16-EC02-436F-B11C-053AA42A2F27}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7AFA0116-4423-465E-A603-858E7A11DD8C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{D340763F-9692-4051-9360-2887B6FB5CAB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8582A5AF-B567-40F3-B149-02047244A7E1}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{44E1DAEA-597F-40F6-B4B2-394004F8983B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{EB2640C8-9900-4EEF-BBAD-DF85831FC4B9}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{EED3B340-2842-4C41-B02C-1E4144E1D65A}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{56B6AF93-8A6B-4241-973D-65939DC78308}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{9FC71F8B-851F-4B87-9851-DD99B5976F83}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{2393F930-DB94-4774-A4CC-9A5036A422B2}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{AD9C9053-D10E-4B92-A427-88458C629B02}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [TCP Query User{BF92A00D-892C-4449-AC15-53AFBBB2E367}C:\users\dads  studio\appdata\local\com.surfeasy.se0200\updater\update\installer\seupdmonitor.exe] => (Allow) C:\users\dads  studio\appdata\local\com.surfeasy.se0200\updater\update\installer\seupdmonitor.exe
FirewallRules: [UDP Query User{415BA7B9-65F4-4D29-ABED-DA09281FB704}C:\users\dads  studio\appdata\local\com.surfeasy.se0200\updater\update\installer\seupdmonitor.exe] => (Allow) C:\users\dads  studio\appdata\local\com.surfeasy.se0200\updater\update\installer\seupdmonitor.exe
FirewallRules: [{61622E86-F9EE-4333-8EC9-7E17B61457A8}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{59AA6083-4150-4AA7-9ED1-2A7244B266EF}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{0485061C-92E0-4607-B00F-12E0249A7C45}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6EDCE1E6-F16F-4DEE-ABEE-F9921C58F7B1}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{5AAD3761-BCEA-4E0B-9621-6E566D42229C}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{E6A5EDA0-E7AD-4107-AB62-55C98A6833A6}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{219B2DC4-C032-4AAF-9503-3E66FD19A463}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{FC6AB86B-A2AB-4E83-85A7-7F0750A3E354}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{77F6E756-78E7-4B45-9135-075E05FD8ABA}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{53C9455C-A2AD-488F-9F7E-1C8EF4F4BF53}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{7E1C3318-2393-4C1E-80CA-FA6C702F95F6}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{68A45443-F566-4D63-9416-AFBE8603687C}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{B587CDC1-7EF2-4FB9-B44E-6FEFCA852C07}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{604FCDD2-45FA-4ED8-B4E2-093221C8ADB0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{B4FB657D-E7F6-489B-BE3C-DA845CE48238}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{1987AB73-FA8B-4D5E-AFEA-1AE1AE014B3E}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{025A8C94-09F1-4849-AFDF-89858D0E44C2}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{340DCFE0-7F85-4FE1-8307-3897E8C2513F}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{7782B181-9661-4830-9A09-CF77E00D32C6}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{669ACE6F-C5A2-4CD6-94C6-59A70EE67B01}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe

==================== Faulty Device Manager Devices =============

Name: Standard VGA Graphics Adapter
Description: Standard VGA Graphics Adapter
Class Guid: {4d36e968-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard display types)
Service: vga
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Base System Device
Description: Base System Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: SM Bus Controller
Description: SM Bus Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: StorLib bus (virtual storages support)
Description: StorLib bus (virtual storages support)
Class Guid: {1378e71b-ab4d-4348-af26-cba56b12969e}
Manufacturer: EldoS Corporation
Service: cbfs3
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.


==================== Event log errors: =========================

Application errors:
==================
Error: (05/23/2015 10:56:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/23/2015 10:45:09 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program OUTLOOK.EXE version 11.0.8326.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: cb8
Start Time: 01d094de7fcfdb26
Termination Time: 15

Error: (05/22/2015 10:50:39 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.

Context: Windows Application


Details:
    The content index metadata cannot be read.   (0xc0041801)

Error: (05/22/2015 10:50:39 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: The gatherer object cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
    The content index metadata cannot be read.   (0xc0041801)

Error: (05/22/2015 10:50:39 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
    Element not found.   (0x80070490)

Error: (05/22/2015 10:50:35 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in cannot be initialized.

Context: Windows Application, SystemIndex Catalog


Details:
    The content index metadata cannot be read.   (0xc0041801)

Error: (05/22/2015 10:50:35 AM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: The Windows Search Service cannot load the property store information.

Context: Windows Application, SystemIndex Catalog


Details:
    0x%08x (0x8004117f - The content index server cannot update or access information because of a database error.  Stop and restart the search service.  If the problem persists, reset and recrawl the content index.  In some cases it may be necessary to delete and recreate the content index.  )

Error: (05/22/2015 10:50:17 AM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: The Windows Search Service cannot open the Jet property store.


Details:
    0x%08x (0x8004117f - The content index server cannot update or access information because of a database error.  Stop and restart the search service.  If the problem persists, reset and recrawl the content index.  In some cases it may be necessary to delete and recreate the content index.  )

Error: (05/22/2015 10:50:10 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/22/2015 10:14:39 AM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.

Context:  Application, SystemIndex Catalog


Details:
    A device attached to the system is not functioning.   (0x8007001f)


System errors:
=============
Error: (05/24/2015 09:11:27 AM) (Source: ACPI) (EventID: 13) (User: )
Description: : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.

Error: (05/24/2015 09:11:22 AM) (Source: ACPI) (EventID: 13) (User: )
Description: : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.

Error: (05/24/2015 05:09:44 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: AVGIDSAgent3758213661 (0xE001CA1D)

Error: (05/24/2015 02:33:40 AM) (Source: ACPI) (EventID: 13) (User: )
Description: : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.

Error: (05/23/2015 11:01:02 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: AVGIDSAgent3758213661 (0xE001CA1D)

Error: (05/23/2015 06:44:42 PM) (Source: ACPI) (EventID: 13) (User: )
Description: : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.

Error: (05/23/2015 04:17:58 PM) (Source: ACPI) (EventID: 13) (User: )
Description: : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.

Error: (05/23/2015 04:17:53 PM) (Source: ACPI) (EventID: 13) (User: )
Description: : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.

Error: (05/23/2015 11:00:33 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: AVGIDSAgent3758213661 (0xE001CA1D)

Error: (05/23/2015 10:56:55 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: AVGIDSAgent3758213661 (0xE001CA1D)


Microsoft Office:
=========================

CodeIntegrity Errors:
===================================
  Date: 2015-05-24 10:25:31.399
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-05-24 10:25:31.258
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-05-24 10:25:31.109
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-05-24 10:25:30.932
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-05-24 10:25:11.757
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-05-24 10:25:11.576
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-05-24 10:25:11.426
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-05-24 10:25:11.274
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-05-24 10:25:09.755
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsdrivera.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-05-24 10:25:09.542
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsdrivera.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz
Percentage of memory in use: 89%
Total physical RAM: 2042.07 MB
Available physical RAM: 215.11 MB
Total Pagefile: 4333.42 MB
Available Pagefile: 1199 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.76 GB) (Free:338.01 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (TNT) (CDROM) (Total:0.63 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 1B428473)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End of log ============================

 

 

 

:welcome:

 

Nothing really earth shattering jumping out at me, I see your using CCleaner, its a nice program but if you use the registry part of the program to remove entries, unless you know 100% what those entries are before you remove them it could cause problems.

 

Lets run some general clean up  and go from there

 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner To your Desktop
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
Do not click on any links in the top Advertisment.
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
    [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  to your desktop. <———
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
      •  
        [external image: MBAM2010601022_zpsyvzbaddn.jpg]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished and the log pops up…select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • Hi ken545

           

          Thanks for your help, here are some of the logs:

           

          # AdwCleaner v4.205 - Logfile created 26/05/2015 at 16:57:52
          # Updated 21/05/2015 by Xplode
          # Database : 2015-05-25.3 [Server]
          # Operating system : Windows (TM) Vista Home Premium Service Pack 2 (x64)
          # Username : Dads  Studio - DADSSTUDIO-PC
          # Running from : C:\Users\Dads  Studio\Downloads\AdwCleaner.exe
          # Option : Cleaning

          ***** [ Services ] *****


          ***** [ Files / Folders ] *****

          [!] Folder Deleted : C:\ProgramData\AVG Security Toolbar

          ***** [ Scheduled tasks ] *****


          ***** [ Shortcuts ] *****


          ***** [ Registry ] *****

          Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
          Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
          Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

          ***** [ Web browsers ] *****

          -\\ Internet Explorer v9.0.8112.16644


          -\\ Mozilla Firefox v38.0.1 (x86 en-US)


          -\\ Google Chrome v43.0.2357.81

          [C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
          [C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

          *************************

          AdwCleaner[R0].txt - [1408 bytes] - [26/05/2015 16:54:25]
          AdwCleaner[S0].txt - [1349 bytes] - [26/05/2015 16:57:52]

          ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1408  bytes] ##########
           

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Thisisu
          Version: 6.8.0 (05.25.2015:1)
          OS: Windows (TM) Vista Home Premium x64
          Ran by [removed] on Tue 05/26/2015 at 17:14:07.56
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




          ~~~ Services

          Successfully stopped: [Service] SurfEasyVPN
          Successfully deleted: [Service] SurfEasyVPN



          ~~~ Tasks

          Successfully deleted: [Task] C:\Windows\system32\tasks\PCDEventLauncherTask



          ~~~ Registry Values



          ~~~ Registry Keys



          ~~~ Files



          ~~~ Folders

          Successfully deleted: [Folder] C:\Program Files (x86)\surfeasy vpn
          Successfully deleted: [Folder] C:\ProgramData\pcdr
          Successfully deleted: [Folder] C:\ProgramData\surfeasy vpn
          Successfully deleted: [Folder] C:\Users\Dads  Studio\appdata\locallow\avg web tuneup
          Successfully deleted: [Folder] C:\Users\Dads  Studio\appdata\locallow\pcdr
          Successfully deleted: [Folder] C:\Users\Dads  Studio\AppData\Roaming\pcdr



          ~~~ FireFox

          Emptied folder: C:\Users\Dads  Studio\AppData\Roaming\mozilla\firefox\profiles\ae25cr0d.default\minidumps [20 files]



          ~~~ Chrome


          [C:\Users\Dads  Studio\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

          [C:\Users\Dads  Studio\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

          [C:\Users\Dads  Studio\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

          [C:\Users\Dads  Studio\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
          [
            ndibdjnfmopecpmkdieinmbadjfpblof
          ]





          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Tue 05/26/2015 at 17:18:14.93
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           

          Where on a roll, lets see what Malwarebytes finds. You have it installed already so just open it, check for updates and run the Threat Scan

          Malwarebytes Anti-Malware
          www.malwarebytes.org

          Scan Date: 5/26/2015
          Scan Time: 5:30:31 PM
          Logfile:
          Administrator: Yes

          Version: 2.01.6.1022
          Malware Database: v2015.05.26.07
          Rootkit Database: v2015.05.24.01
          License: Free
          Malware Protection: Disabled
          Malicious Website Protection: Disabled
          Self-protection: Disabled

          OS: Windows Vista Service Pack 2
          CPU: x64
          File System: NTFS
          User: Dads  Studio

          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 360402
          Time Elapsed: 34 min, 26 sec

          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Disabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled

          Processes: 0
          (No malicious items detected)

          Modules: 0
          (No malicious items detected)

          Registry Keys: 0
          (No malicious items detected)

          Registry Values: 0
          (No malicious items detected)

          Registry Data: 0
          (No malicious items detected)

          Folders: 0
          (No malicious items detected)

          Files: 0
          (No malicious items detected)

          Physical Sectors: 0
          (No malicious items detected)


          (end)

          Open up FRST64 and be sure to checkmark Additions, run a new scan and post both the FRST64 and Additions log and let me take a final look

          Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-05-2015
          Ran by [removed] (administrator) on DADSSTUDIO-PC on 27-05-2015 09:13:28
          Running from C:\Users\[removed]\Downloads
          [removed] Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: English (United States)
          Internet Explorer Version 9 (Default browser: FF)
          Boot Mode: Normal
          Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

          ==================== Processes (Whitelisted) =================

          (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

          (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
          (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
          (Microsoft Corporation) C:\Windows\System32\SLsvc.exe
          (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
          (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
          (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
          (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
          (Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe
          (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
          (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
          (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
          (SugarSync, Inc.) C:\Program Files (x86)\SugarSync\SugarSync.exe
          (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
          (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
          (Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
          (Microsoft Corporation) C:\Windows\System32\mobsync.exe
          (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
          (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
          (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
          (Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
          (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE
          (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
          (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
          (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
          (Farbar) C:\Users\Dads  Studio\Downloads\FRST64(1).exe


          ==================== Registry (Whitelisted) ==================

          (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

          HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-20] (Microsoft Corporation)
          HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1822504 2009-08-24] (Synaptics Incorporated)
          HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
          HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3745744 2015-05-18] (AVG Technologies CZ, s.r.o.)
          HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
          HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\Run: [SugarSync] => C:\Program Files (x86)\SugarSync\SugarSync.exe [13119328 2014-05-06] (SugarSync, Inc.)
          HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2014-03-26] (Google Inc.)
          HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8204056 2015-04-23] (Piriform Ltd)
          HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\MountPoints2: {3ff4a206-b3a4-11e3-9313-806e6f6e6963} - D:\TnT.exe
          Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2014-04-23]
          ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
          SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll No File
          ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2014-05-06] (SugarSync, Inc.)
          ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2014-05-06] (SugarSync, Inc.)
          ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {39D54CC2-69CF-43b4-B167-577D25E7F496} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2014-05-06] (SugarSync, Inc.)
          ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2014-05-06] (SugarSync, Inc.)
          ShellIconOverlayIdentifiers: [SugarSyncSharedPending] -> {F7395C2E-A5D8-4a32-9536-5C6A9F1DC450} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2014-05-06] (SugarSync, Inc.)
          ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll No File

          ==================== Internet (Whitelisted) ====================

          (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

          SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
          SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
          SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
          SearchScopes: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000 -> {E76CC469-6279-4733-B834-25E493546AA9} URL = http://www.google.com/search?q={searchTerms}&rls;=com.microsoft:{language}&ie;={inputEncoding}&oe;={outputEncoding}&startIndex;={startIndex?}&startPage;={startPage}&rlz;=1I7PRFD_enUS582
          BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-01] (Google Inc.)
          BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-01] (Google Inc.)
          Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-01] (Google Inc.)
          Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-01] (Google Inc.)
          Toolbar: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-01] (Google Inc.)
          Tcpip\Parameters: [DhcpNameServer] [removed] [removed]

          FireFox:
          ========
          FF ProfilePath: C:\Users\Dads  Studio\AppData\Roaming\Mozilla\Firefox\Profiles\ae25cr0d.default
          FF DefaultSearchEngine: Google
          FF DefaultSearchEngine.US: Google
          FF Homepage: about:home
          FF Keyword.URL:
          FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-05-25] ()
          FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-25] ()
          FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1214154.dll [2014-11-26] (Adobe Systems, Inc.)
          FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
          FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
          FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
          FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
          FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
          FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
          FF HKLM-x32\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
          FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-03-25]

          Chrome:
          =======
          CHR Profile: C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default
          CHR Extension: (Google Docs) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-26]
          CHR Extension: (Google Drive) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-26]
          CHR Extension: (YouTube) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-26]
          CHR Extension: (Google Search) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-26]
          CHR Extension: (Bookmark Manager) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-27]
          CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
          CHR Extension: (Google Wallet) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-26]
          CHR Extension: (Gmail) - C:\Users\Dads  Studio\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-26]

          ==================== Services (Whitelisted) =================

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

          R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
          S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3438544 2015-05-18] (AVG Technologies CZ, s.r.o.)
          R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [311792 2015-05-18] (AVG Technologies CZ, s.r.o.)
          R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-02-28] (Hewlett-Packard Co.) [File not signed]
          R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-02-28] (Hewlett-Packard Co.) [File not signed]
          R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
          S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
          R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
          R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
          R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
          S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
          S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-20] (Microsoft Corporation)

          ==================== Drivers (Whitelisted) ====================

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

          R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
          R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [260888 2014-12-08] (AVG Technologies CZ, s.r.o.)
          R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [203544 2014-11-18] (AVG Technologies CZ, s.r.o.)
          R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [256992 2015-04-15] (AVG Technologies CZ, s.r.o.)
          R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.)
          R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [220128 2015-05-07] (AVG Technologies CZ, s.r.o.)
          R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.)
          R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [270616 2014-07-02] (AVG Technologies CZ, s.r.o.)
          R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
          S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
          R3 OA008Ufd; C:\Windows\System32\DRIVERS\OA008Ufd.sys [159840 2009-03-06] (Creative Technology Ltd.)
          R3 OA008Vid; C:\Windows\System32\DRIVERS\OA008Vid.sys [313696 2009-05-06] (Creative Technology Ltd.)
          R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
          R3 SSCBFS3; C:\Windows\System32\DRIVERS\sscbfs3.sys [347904 2013-01-30] (EldoS Corporation)
          R3 tapse01; C:\Windows\System32\DRIVERS\tapse01.sys [39608 2014-05-14] (The OpenVPN Project)
          S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
          S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
          S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

          ==================== NetSvcs (Whitelisted) ===================

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


          ==================== One Month Created files and folders ========

          (If an entry is included in the fixlist, the file/folder will be moved.)

          2015-05-27 09:12 - 2015-05-27 09:12 - 02108928 _____ (Farbar) C:\Users\Dads  Studio\Downloads\FRST64(1).exe
          2015-05-27 09:10 - 2015-05-27 09:10 - 00000000 ____D () C:\Users\Dads  Studio\Downloads\FRST-OlderVersion
          2015-05-26 17:18 - 2015-05-26 17:18 - 00001877 _____ () C:\Users\Dads  Studio\Desktop\JRT.txt
          2015-05-26 17:14 - 2015-05-26 17:14 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DADSSTUDIO-PC-Windows-Vista-(TM)-Home-Premium-(64-bit).dat
          2015-05-26 17:14 - 2015-05-26 17:14 - 00000000 ____D () C:\RegBackup
          2015-05-26 17:12 - 2015-05-26 17:12 - 02946703 _____ (Thisisu) C:\Users\Dads  Studio\Downloads\JRT.exe
          2015-05-26 16:53 - 2015-05-26 16:58 - 00000000 ____D () C:\AdwCleaner
          2015-05-26 16:51 - 2015-05-26 16:51 - 02223104 _____ () C:\Users\Dads  Studio\Downloads\AdwCleaner.exe
          2015-05-24 10:30 - 2015-05-24 10:35 - 00000000 ____D () C:\Users\Dads  Studio\Desktop\What the tech 052015
          2015-05-24 10:26 - 2015-05-24 10:27 - 00035977 _____ () C:\Users\Dads  Studio\Downloads\Addition.txt
          2015-05-24 10:24 - 2015-05-27 09:14 - 00014107 _____ () C:\Users\Dads  Studio\Downloads\FRST.txt
          2015-05-24 10:21 - 2015-05-27 09:13 - 00000000 ____D () C:\FRST
          2015-05-24 10:20 - 2015-05-27 09:10 - 02108928 _____ (Farbar) C:\Users\Dads  Studio\Downloads\FRST64.exe
          2015-05-24 10:11 - 2015-05-24 10:11 - 05198336 _____ (AVAST Software) C:\Users\Dads  Studio\Downloads\aswMBR.exe
          2015-05-23 10:55 - 2015-05-23 10:55 - 00000354 _____ () C:\Windows\PFRO.log
          2015-05-23 05:09 - 2015-05-23 05:09 - 00000000 ____D () C:\Users\Dads  Studio\AppData\Local\Avg
          2015-05-22 10:03 - 2015-05-22 10:03 - 00002814 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
          2015-05-22 10:03 - 2015-05-22 10:03 - 00000770 _____ () C:\Users\Public\Desktop\CCleaner.lnk
          2015-05-22 10:03 - 2015-05-22 10:03 - 00000000 ____D () C:\Program Files\CCleaner
          2015-05-22 10:00 - 2015-05-22 10:00 - 06484352 _____ (Piriform Ltd) C:\Users\Dads  Studio\Downloads\ccsetup505.exe
          2015-05-19 16:21 - 2015-05-19 16:21 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
          2015-05-19 11:14 - 2015-05-19 11:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
          2015-05-14 22:43 - 2015-05-14 22:44 - 71807792 _____ (Apple Inc.) C:\Users\Dads  Studio\Downloads\iCloudSetup(1).exe
          2015-05-13 03:45 - 2015-04-19 17:24 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
          2015-05-13 03:45 - 2015-04-19 17:24 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
          2015-05-13 03:45 - 2015-04-19 17:24 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
          2015-05-13 03:45 - 2015-04-19 17:24 - 00160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
          2015-05-13 03:45 - 2015-04-19 16:19 - 01172480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
          2015-05-13 03:45 - 2015-04-19 16:18 - 00486400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
          2015-05-13 03:45 - 2015-04-19 16:13 - 00682496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
          2015-05-13 03:45 - 2015-04-19 16:12 - 01072640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
          2015-05-13 03:45 - 2015-04-17 20:16 - 01268224 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
          2015-05-13 03:45 - 2015-04-17 20:16 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
          2015-05-13 03:45 - 2015-04-17 20:16 - 00287232 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
          2015-05-13 03:45 - 2015-04-17 20:16 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
          2015-05-13 03:45 - 2015-04-17 19:45 - 02002944 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
          2015-05-13 03:45 - 2015-04-17 19:44 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
          2015-05-13 03:45 - 2015-04-17 19:35 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
          2015-05-13 03:45 - 2015-04-17 19:33 - 01561088 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
          2015-05-13 03:45 - 2015-04-17 19:33 - 01154048 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
          2015-05-13 03:45 - 2015-04-17 19:30 - 02793472 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
          2015-05-13 03:12 - 2015-04-30 12:03 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
          2015-05-13 03:12 - 2015-04-30 11:41 - 00347648 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
          2015-05-13 03:05 - 2015-04-10 19:33 - 00384512 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
          2015-05-13 03:05 - 2015-04-10 19:22 - 00279552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\services.exe
          2015-05-13 03:04 - 2015-04-30 09:14 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
          2015-05-13 03:04 - 2015-04-30 09:14 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
          2015-05-13 01:24 - 2015-04-09 19:52 - 02339840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
          2015-05-13 01:24 - 2015-04-09 19:47 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
          2015-05-13 01:24 - 2015-04-09 19:46 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
          2015-05-13 01:24 - 2015-04-09 19:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
          2015-05-13 01:24 - 2015-04-09 19:45 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
          2015-05-13 01:24 - 2015-04-09 19:45 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
          2015-05-13 01:24 - 2015-04-09 19:45 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
          2015-05-13 01:24 - 2015-04-09 19:14 - 12379136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
          2015-05-13 01:24 - 2015-04-09 19:10 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
          2015-05-13 01:24 - 2015-04-09 19:05 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
          2015-05-13 01:24 - 2015-04-09 19:04 - 00421888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
          2015-05-13 01:24 - 2015-04-09 19:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
          2015-05-13 01:24 - 2015-04-09 19:03 - 00718336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
          2015-05-13 01:24 - 2015-04-09 19:03 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
          2015-05-13 01:24 - 2015-04-09 19:03 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
          2015-05-13 01:24 - 2015-04-09 19:03 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
          2015-05-13 01:24 - 2015-04-09 19:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
          2015-05-13 01:23 - 2015-04-09 20:10 - 17881088 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
          2015-05-13 01:23 - 2015-04-09 19:55 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
          2015-05-13 01:23 - 2015-04-09 19:53 - 10935808 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
          2015-05-13 01:23 - 2015-04-09 19:48 - 01388032 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
          2015-05-13 01:23 - 2015-04-09 19:46 - 02158080 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
          2015-05-13 01:23 - 2015-04-09 19:46 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
          2015-05-13 01:23 - 2015-04-09 19:46 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
          2015-05-13 01:23 - 2015-04-09 19:46 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
          2015-05-13 01:23 - 2015-04-09 19:46 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
          2015-05-13 01:23 - 2015-04-09 19:46 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
          2015-05-13 01:23 - 2015-04-09 19:46 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
          2015-05-13 01:23 - 2015-04-09 19:46 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
          2015-05-13 01:23 - 2015-04-09 19:45 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
          2015-05-13 01:23 - 2015-04-09 19:45 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
          2015-05-13 01:23 - 2015-04-09 19:45 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
          2015-05-13 01:23 - 2015-04-09 19:08 - 09750528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
          2015-05-13 01:23 - 2015-04-09 19:08 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
          2015-05-13 01:23 - 2015-04-09 19:05 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
          2015-05-13 01:23 - 2015-04-09 19:04 - 01804288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
          2015-05-13 01:23 - 2015-04-09 19:04 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
          2015-05-13 01:23 - 2015-04-09 19:04 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
          2015-05-13 01:23 - 2015-04-09 19:04 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
          2015-05-13 01:23 - 2015-04-09 19:03 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
          2015-05-13 01:23 - 2015-04-09 19:03 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
          2015-05-13 01:23 - 2015-04-09 19:03 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
          2015-05-13 01:23 - 2015-04-09 19:03 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
          2015-05-13 01:23 - 2015-04-09 19:03 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
          2015-05-07 13:50 - 2015-05-07 13:50 - 00378336 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys
          2015-05-07 13:49 - 2015-05-07 13:49 - 00220128 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
          2015-05-07 00:07 - 2015-05-07 00:07 - 00768899 _____ () C:\Users\Dads  Studio\Downloads\electronically signed form
          2015-05-04 17:22 - 2015-05-13 12:08 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Bronco Wine Company
          2015-04-29 11:47 - 2015-04-29 11:47 - 00000000 ____D () C:\Users\Dads  Studio\Documents\A CUSTOMER REPORT
          2015-04-29 11:02 - 2015-04-29 11:02 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Vcard

          ==================== One Month Modified files and folders ========

          (If an entry is included in the fixlist, the file/folder will be moved.)

          2015-05-27 09:02 - 2014-12-01 12:23 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
          2015-05-27 09:01 - 2014-03-26 16:08 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
          2015-05-27 08:56 - 2008-01-20 21:53 - 01981948 _____ () C:\Windows\WindowsUpdate.log
          2015-05-27 08:45 - 2014-03-25 12:55 - 00000000 ____D () C:\ProgramData\MFAData
          2015-05-27 08:40 - 2014-03-26 16:08 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
          2015-05-27 08:40 - 2014-03-24 15:43 - 00000732 _____ () C:\Users\Dads  Studio\AppData\Local\d3d9caps64.dat
          2015-05-27 08:40 - 2006-11-02 11:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
          2015-05-27 08:40 - 2006-11-02 11:22 - 00003712 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
          2015-05-27 08:40 - 2006-11-02 11:22 - 00003712 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
          2015-05-27 00:44 - 2006-11-02 11:42 - 00032536 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
          2015-05-26 17:29 - 2014-03-26 13:42 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
          2015-05-25 16:30 - 2015-03-30 11:50 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Conquer Cancer Ride
          2015-05-25 15:14 - 2014-03-26 16:09 - 00002025 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
          2015-05-25 11:00 - 2014-12-01 12:23 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
          2015-05-25 11:00 - 2014-12-01 12:23 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
          2015-05-25 11:00 - 2014-12-01 12:23 - 00003682 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
          2015-05-25 11:00 - 2014-08-18 09:15 - 00000000 ____D () C:\Users\Dads  Studio\AppData\Local\Adobe
          2015-05-24 09:44 - 2014-03-26 15:58 - 00002651 _____ () C:\Users\Dads  Studio\Desktop\Microsoft Office Word 2007.lnk
          2015-05-24 05:13 - 2014-10-30 10:05 - 00000872 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
          2015-05-22 10:16 - 2014-03-26 13:42 - 00000941 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
          2015-05-22 10:16 - 2014-03-26 13:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
          2015-05-22 10:16 - 2014-03-26 13:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
          2015-05-22 10:14 - 2014-05-10 11:15 - 00000000 ____D () C:\Users\Dads  Studio\AppData\Roaming\TeamViewer
          2015-05-22 10:12 - 2014-03-24 19:32 - 00000000 ____D () C:\Windows\Panther
          2015-05-22 09:51 - 2015-04-24 15:22 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Frolish Wine Merchants
          2015-05-20 10:32 - 2014-04-09 14:06 - 00000680 _____ () C:\Users\Dads  Studio\AppData\Local\d3d9caps.dat
          2015-05-19 19:13 - 2014-03-31 14:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
          2015-05-19 16:22 - 2014-04-12 09:41 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
          2015-05-19 16:00 - 2006-11-02 08:46 - 00762930 _____ () C:\Windows\system32\PerfStringBackup.INI
          2015-05-19 15:59 - 2014-06-23 14:34 - 00000000 ____D () C:\Users\Dads  Studio\Documents\My Scans
          2015-05-19 15:50 - 2006-11-02 08:34 - 00000275 _____ () C:\Windows\win.ini
          2015-05-18 13:41 - 2014-03-26 15:58 - 00002609 _____ () C:\Users\Dads  Studio\Desktop\Microsoft Office Excel 2007.lnk
          2015-05-16 15:56 - 2014-03-26 16:08 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
          2015-05-16 15:56 - 2014-03-26 16:08 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
          2015-05-14 22:55 - 2015-02-26 17:34 - 00047616 _____ () C:\Users\Dads  Studio\Desktop\Backup Assistant 022615.xlsx
          2015-05-14 14:12 - 2014-04-16 10:34 - 00000000 ____D () C:\Users\Dads  Studio\AppData\Local\SugarSync
          2015-05-13 04:10 - 2006-11-02 11:21 - 00282760 _____ () C:\Windows\system32\FNTCACHE.DAT
          2015-05-13 04:09 - 2014-04-07 10:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
          2015-05-13 04:04 - 2006-11-02 11:07 - 00000000 ____D () C:\Program Files\Windows Journal
          2015-05-13 03:38 - 2014-03-26 15:38 - 00000000 ____D () C:\ProgramData\Microsoft Help
          2015-05-13 03:37 - 2014-03-25 02:05 - 00000000 ____D () C:\Windows\system32\MRT
          2015-05-13 03:18 - 2006-11-02 08:35 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
          2015-05-13 03:05 - 2006-11-02 11:07 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
          2015-05-13 03:03 - 2014-04-07 10:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
          2015-05-12 19:14 - 2014-09-02 19:03 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Boys stuff
          2015-05-07 14:20 - 2014-10-29 10:23 - 00000000 ____D () C:\Users\Dads  Studio\Desktop\Winejob.com
          2015-05-06 12:09 - 2014-07-02 14:22 - 00000000 ____D () C:\Users\Dads  Studio\Documents\Photos
          2015-05-06 11:46 - 2014-04-15 01:25 - 00000000 ____D () C:\Users\Dads  Studio\Desktop\Irish Language

          ==================== Files in the root of some directories =======

          2014-04-13 10:16 - 2014-04-13 10:16 - 0000552 _____ () C:\Users\Dads  Studio\AppData\Local\d3d8caps.dat
          2014-04-09 14:06 - 2015-05-20 10:32 - 0000680 _____ () C:\Users\Dads  Studio\AppData\Local\d3d9caps.dat
          2014-03-24 15:43 - 2015-05-27 08:40 - 0000732 _____ () C:\Users\Dads  Studio\AppData\Local\d3d9caps64.dat
          2014-07-02 14:21 - 2014-07-02 14:21 - 0003584 _____ () C:\Users\Dads  Studio\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
          2014-06-23 14:04 - 2014-06-25 15:05 - 0001329 _____ () C:\ProgramData\hpzinstall.log
          2014-04-14 13:26 - 2014-04-14 14:20 - 0000298 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

          Some files in TEMP:
          ====================
          C:\Users\Dads  Studio\AppData\Local\Temp\Quarantine.exe
          C:\Users\Dads  Studio\AppData\Local\Temp\sqlite3.dll


          ==================== Bamital & volsnap Check =================

          (There is no automatic fix for files that do not pass verification.)

          C:\Windows\System32\winlogon.exe => File is digitally signed
          C:\Windows\System32\wininit.exe => File is digitally signed
          C:\Windows\SysWOW64\wininit.exe => File is digitally signed
          C:\Windows\explorer.exe => File is digitally signed
          C:\Windows\SysWOW64\explorer.exe => File is digitally signed
          C:\Windows\System32\svchost.exe => File is digitally signed
          C:\Windows\SysWOW64\svchost.exe => File is digitally signed
          C:\Windows\System32\services.exe => File is digitally signed
          C:\Windows\System32\User32.dll => File is digitally signed
          C:\Windows\SysWOW64\User32.dll => File is digitally signed
          C:\Windows\System32\userinit.exe => File is digitally signed
          C:\Windows\SysWOW64\userinit.exe => File is digitally signed
          C:\Windows\System32\rpcss.dll => File is digitally signed
          C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


          LastRegBack: 2015-05-27 08:51

          ==================== End of log ============================

           

           

           

          Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-05-2015
          Ran by [removed] at 2015-05-27 09:15:04
          Running from C:\Users\[removed]\Downloads
          Boot Mode: Normal
          ==========================================================


          ==================== Accounts: =============================

          Administrator (S-1-5-21-2950505590-1508067594-3318522798-500 - Administrator - Disabled)
          Dads  Studio (S-1-5-21-2950505590-1508067594-3318522798-1000 - Administrator - Enabled) => C:\Users\Dads  Studio
          Guest (S-1-5-21-2950505590-1508067594-3318522798-501 - Limited - Disabled)

          ==================== Security Center ========================

          (If an entry is included in the fixlist, it will be removed.)

          AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
          AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

          ==================== Installed Programs ======================

          (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

          64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
          Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
          Adobe Reader X (10.1.14) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.14 - Adobe Systems Incorporated)
          Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.4.154 - Adobe Systems, Inc.)
          AIO_CDA_ProductContext (x32 Version: 82.0.233.000 - Hewlett-Packard) Hidden
          AIO_CDA_Software (x32 Version: 82.0.233.000 - Hewlett-Packard) Hidden
          AIO_CDA_ToolboxIni64 (Version: 82.0.233.000 - Hewlett-Packard) Hidden
          AIO_Scan (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
          Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
          Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
          Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
          Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
          AudioNote (HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\edac8a894d3918af) (Version: 2.4.0.21 - AudioNote)
          AVG 2015 (HKLM\…\AVG) (Version: 2015.0.5961 - AVG Technologies)
          AVG 2015 (Version: 15.0.4354 - AVG Technologies) Hidden
          AVG 2015 (Version: 15.0.5961 - AVG Technologies) Hidden
          Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
          Broadcom Gigabit NetLink Controller (HKLM\…\{9AF0B106-56F1-461B-A270-95BC1682E282}) (Version: 11.22.02 - Broadcom Corporation)
          BufferChm (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
          C3100 (x32 Version: 82.0.233.000 - Hewlett-Packard) Hidden
          c3100_Help (x32 Version: 82.0.233.000 - Hewlett-Packard) Hidden
          CCleaner (HKLM\…\CCleaner) (Version: 5.05 - Piriform)
          Copy (x32 Version: 82.0.188.000 - Hewlett-Packard) Hidden
          CustomerResearchQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
          Dell Resource CD (HKLM-x32\…\{42929F0F-CE14-47AF-9FC7-FF297A603021}) (Version: 1.00.0000 - Dell Inc.)
          Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.0.6584.52 - Dell)
          Dell System Detect (HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\73f463568823ebbe) (Version: 5.14.0.9 - Dell)
          Dell Touchpad (HKLM\…\SynTPDeinstKey) (Version: 14.0.2.0 - Synaptics Incorporated)
          Destinations (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
          DeviceManagementQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
          DocProc (x32 Version: 8.1.0.0 - Hewlett-Packard) Hidden
          DocProcQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
          eSupportQFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
          Fax (x32 Version: 82.0.188.000 - Hewlett-Packard) Hidden
          Google Chrome (HKLM-x32\…\Google Chrome) (Version: 43.0.2357.81 - Google Inc.)
          Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.)
          Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
          Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
          Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
          Hewlett-Packard ACLM.NET v1.1.0.0 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
          HP Customer Participation Program 8.0 (HKLM\…\HPExtendedCapabilities) (Version: 8.0 - HP)
          HP Imaging Device Functions 8.0 (HKLM\…\HP Imaging Device Functions) (Version: 8.0 - HP)
          HP OCR Software 8.0 (HKLM\…\HPOCR) (Version: 8.0 - HP)
          HP Photosmart Essential (HKLM-x32\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
          HP Photosmart.All-In-One Driver Software 8.0 .A (HKLM\…\{282E5AB2-8E47-4571-B6FA-6B512555B557}) (Version: 8.0 - HP)
          HP Product Detection (HKLM-x32\…\{A436F67F-687E-4736-BD2B-537121A804CF}) (Version: 11.14.0001 - HP)
          HP Solution Center 8.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 8.0 - HP)
          HP Support Solutions Framework (HKLM-x32\…\{E35601C0-BA8E-4F32-919A-C7EF4CA81F67}) (Version: 11.51.0048 - Hewlett-Packard Company)
          HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
          HPProductAssistant (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
          HPSSupply (HKLM-x32\…\{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}) (Version: 2.1.3.0000 - Hewlett Packard Development Company L.P.)
          Integrated Webcam Driver (1.04.01.0601)   (HKLM\…\Creative OA008) (Version: 1.04.01.0601 - Creative Technology Ltd.)
          Intel(R) PROSet/Wireless WiFi Driver (HKLM\…\{AFE36C05-B442-4DEA-9BFB-2D72C8A1E153}) (Version: 12.00.2000 - Intel(R) Corporation)
          iTunes (HKLM\…\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
          Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
          MarketResearch (x32 Version: 82.0.174.000 - Hewlett-Packard) Hidden
          Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
          Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
          Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
          Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
          Microsoft Office Home and Student 2007 (HKLM-x32\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
          Microsoft Office Standard Edition 2003 (HKLM-x32\…\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
          Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
          Mozilla Firefox 38.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 38.0.1 (x86 en-US)) (Version: 38.0.1 - Mozilla)
          Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
          MSXML 4.0 SP2 (KB927978) (HKLM-x32\…\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
          MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
          MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
          MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
          MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
          QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
          Scan (x32 Version: 8.1.0.0 - Hewlett-Packard) Hidden
          Secunia PSI (3.0.0.9016) (HKLM-x32\…\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
          Sharepod 4.0.3.0 (HKLM-x32\…\{085BCFB8-F6FB-4600-AFAB-1F6DBC7F5F99}_is1) (Version:  - Macroplant LLC)
          SolutionCenter (x32 Version: 82.0.188.000 - Hewlett-Packard) Hidden
          Speccy (HKLM\…\Speccy) (Version: 1.25 - Piriform)
          Status (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
          SugarSync (HKLM-x32\…\SugarSync) (Version: 2.0.46.127183 - SugarSync, Inc.)
          SurfEasy VPN 1.1.244 (HKLM-x32\…\SurfEasy VPN) (Version: 1.1.244 - SurfEasy Inc)
          swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
          TaxACT 2014 - 1040 Edition (HKLM-x32\…\TaxACT 2014 - 1040 Edition) (Version: 1.07 - TaxACT, Inc.)
          TaxACT 2014 New York (HKLM-x32\…\TaxACT 2014 New York) (Version: 1.01 - TaxACT, Inc.)
          Toolbox (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden
          TrayApp (x32 Version: 82.0.188.000 - Hewlett-Packard) Hidden
          TurboTax 2013 (HKLM-x32\…\TurboTax 2013) (Version: 2013.0 - Intuit, Inc)
          UnloadSupport (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
          Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
          Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
          Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
          WebReg (x32 Version: 82.0.173.000 - Hewlett-Packard) Hidden

          ==================== Custom CLSID (Whitelisted): ==========================

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

          CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{0567D11D-2F6E-4683-8028-A2807502980B}\InprocServer32 -> C:\Users\Dads  Studio\AppData\Local\Apps\2.0\4PXPGMY8.1LV\YH6NXN33.E9G\audi..tion_73447d47768363b2_0002.0004_9d08baecd2a6a08c\Tools\AudioNoteIFilter\x64\AudioNoteFilter.DLL ()
          CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{3A999A50-AB25-4A20-90A9-08F71FCE320F}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\x64\3\HPCDMC64.DLL (HP)
          CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{7c478185-9d61-48db-b80f-aab34c598056}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{98087D89-B93F-4BCF-A998-AE4D9F607C14}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\x64\3\HPCDMC64.DLL (HP)
          CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{ac97aa90-7827-458c-85e7-9108e267c8c6}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)
          CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{B286F068-5B17-4AE8-989B-8F9A199C47BA}\InprocServer32 -> C:\Windows\system32\spool\DRIVERS\x64\3\HPCDMC64.DLL (HP)
          CustomCLSID: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000_Classes\CLSID\{d2d3ab63-fa40-4490-b717-ae00bc9258a2}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)

          ==================== Restore Points =========================

          03-05-2015 13:17:20 Scheduled Checkpoint
          04-05-2015 09:49:57 Scheduled Checkpoint
          05-05-2015 13:50:09 Scheduled Checkpoint
          06-05-2015 11:20:40 Scheduled Checkpoint
          07-05-2015 13:30:19 Scheduled Checkpoint
          11-05-2015 12:58:26 Scheduled Checkpoint
          13-05-2015 03:00:36 Windows Update
          14-05-2015 00:00:19 Scheduled Checkpoint
          15-05-2015 10:17:26 Scheduled Checkpoint
          16-05-2015 00:00:04 Scheduled Checkpoint
          17-05-2015 00:06:16 Scheduled Checkpoint
          18-05-2015 00:00:12 Scheduled Checkpoint
          19-05-2015 00:15:47 Scheduled Checkpoint
          19-05-2015 21:09:50 Scheduled Checkpoint
          20-05-2015 11:52:27 Scheduled Checkpoint
          21-05-2015 00:00:13 Scheduled Checkpoint
          22-05-2015 00:00:20 Scheduled Checkpoint
          23-05-2015 00:00:10 Scheduled Checkpoint
          23-05-2015 13:01:40 Scheduled Checkpoint
          25-05-2015 00:00:17 Scheduled Checkpoint
          26-05-2015 08:41:05 Scheduled Checkpoint

          ==================== Hosts content: ===============================

          (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

          2006-11-02 08:34 - 2006-09-18 17:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
          127.0.0.1       localhost
          ::1             localhost

          ==================== Scheduled Tasks (Whitelisted) =============

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

          Task: {2CF0DD28-652A-4A6D-9E33-348FD63FF5BC} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
          Task: {396A6BB3-7B4C-40C9-8D18-56EF345ADE29} - \PCDEventLauncherTask No Task File <==== ATTENTION
          Task: {42319CD8-FBFA-4A35-A018-C11BE1C485C8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-23] (Piriform Ltd)
          Task: {98422CB0-DCAE-4D8B-85D0-D9A9DC02FC18} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-26] (Google Inc.)
          Task: {A4143DEB-7DD6-4840-8A87-41F3C0B2978B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-26] (Google Inc.)
          Task: {A6831919-408C-4A5E-8A34-52E56C9150CF} - System32\Tasks\{60DD20DA-BF68-4485-9483-3E1FE174D8C4} => pcalua.exe -a "C:\Program Files (x86)\Print Server\PTP\SetupWizard.exe" -d "C:\Program Files (x86)\Print Server\PTP"
          Task: {BF46079D-C61B-4E14-8C1D-C0244170C8FB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
          Task: {DB7F5586-2F05-498F-A4FF-939BE569A012} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Dads  Studio => C:\Program Files (x86)\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation)
          Task: {DC8824F2-C9F6-4A20-A4A9-6E65BB058AAD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-25] (Adobe Systems Incorporated)
          Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

          ==================== Loaded Modules (Whitelisted) ==============

          2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
          2015-01-20 23:35 - 2015-01-20 23:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
          2013-10-03 18:28 - 2013-10-03 18:28 - 00052736 _____ () C:\Program Files (x86)\SugarSync\librsync.dll
          2014-02-26 23:16 - 2014-05-06 14:35 - 00238944 _____ () C:\Program Files (x86)\SugarSync\SugarSyncVFSNamespace32.dll

          ==================== Alternate Data Streams (Whitelisted) =========

          (If an entry is included in the fixlist, only the ADS will be removed.)


          ==================== Safe Mode (Whitelisted) ===================

          (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


          ==================== EXE Association (Whitelisted) ===============

          (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


          ==================== Internet Explorer trusted/restricted ===============

          (If an entry is included in the fixlist, it will be removed from the registry.)

          IE trusted site: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\dell.com -> dell.com
          IE trusted site: HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\…\intuit.com -> hxxps://accounts.intuit.com


          ==================== Other Areas ============================

          (Currently there is no automatic fix for this section.)

          HKU\S-1-5-21-2950505590-1508067594-3318522798-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\img16.jpg
          DNS Servers: [removed] - [removed]

          ==================== MSCONFIG/TASK MANAGER disabled items ==

          (Currently there is no automatic fix for this section.)

          MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
          MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
          MSCONFIG\startupreg: DellSystemDetect => C:\Users\Dads  Studio\AppData\Local\Apps\2.0\4PXPGMY8.1LV\YH6NXN33.E9G\dell..tion_e30b47f5d4a30e9e_0005.000c_1df9a4898fae00de\DellSystemDetect.exe
          MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
          MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
          MSCONFIG\startupreg: PrintServer Diagnostic => "C:\Program Files (x86)\Print Server\PTP\PSDiagnostic.exe"
          MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
          MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

          ==================== FirewallRules (Whitelisted) ===============

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

          FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
          FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
          FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
          FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
          FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
          FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
          FirewallRules: [{59711385-82A6-477E-8339-CA9436EA03B1}] => (Allow) LPort=80
          FirewallRules: [{D2128CC5-9561-4905-8E7B-07CBB19954A7}] => (Allow) LPort=80
          FirewallRules: [{8B1F54C4-B388-4FA6-BA7D-55DD6B6F1C81}] => (Allow) LPort=80
          FirewallRules: [{A14C5AE7-9B05-4D46-8C44-3E9DA15E0E46}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{32EE2F16-EC02-436F-B11C-053AA42A2F27}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{7AFA0116-4423-465E-A603-858E7A11DD8C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
          FirewallRules: [{D340763F-9692-4051-9360-2887B6FB5CAB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
          FirewallRules: [{8582A5AF-B567-40F3-B149-02047244A7E1}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
          FirewallRules: [{44E1DAEA-597F-40F6-B4B2-394004F8983B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
          FirewallRules: [{EB2640C8-9900-4EEF-BBAD-DF85831FC4B9}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
          FirewallRules: [{EED3B340-2842-4C41-B02C-1E4144E1D65A}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
          FirewallRules: [{56B6AF93-8A6B-4241-973D-65939DC78308}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
          FirewallRules: [{9FC71F8B-851F-4B87-9851-DD99B5976F83}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
          FirewallRules: [{2393F930-DB94-4774-A4CC-9A5036A422B2}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
          FirewallRules: [{AD9C9053-D10E-4B92-A427-88458C629B02}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
          FirewallRules: [TCP Query User{BF92A00D-892C-4449-AC15-53AFBBB2E367}C:\users\dads  studio\appdata\local\com.surfeasy.se0200\updater\update\installer\seupdmonitor.exe] => (Allow) C:\users\dads  studio\appdata\local\com.surfeasy.se0200\updater\update\installer\seupdmonitor.exe
          FirewallRules: [UDP Query User{415BA7B9-65F4-4D29-ABED-DA09281FB704}C:\users\dads  studio\appdata\local\com.surfeasy.se0200\updater\update\installer\seupdmonitor.exe] => (Allow) C:\users\dads  studio\appdata\local\com.surfeasy.se0200\updater\update\installer\seupdmonitor.exe
          FirewallRules: [{61622E86-F9EE-4333-8EC9-7E17B61457A8}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
          FirewallRules: [{59AA6083-4150-4AA7-9ED1-2A7244B266EF}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
          FirewallRules: [{0485061C-92E0-4607-B00F-12E0249A7C45}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
          FirewallRules: [{6EDCE1E6-F16F-4DEE-ABEE-F9921C58F7B1}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
          FirewallRules: [TCP Query User{5AAD3761-BCEA-4E0B-9621-6E566D42229C}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
          FirewallRules: [UDP Query User{E6A5EDA0-E7AD-4107-AB62-55C98A6833A6}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
          FirewallRules: [{219B2DC4-C032-4AAF-9503-3E66FD19A463}] => (Allow) C:\Program Files\iTunes\iTunes.exe
          FirewallRules: [{FC6AB86B-A2AB-4E83-85A7-7F0750A3E354}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
          FirewallRules: [{77F6E756-78E7-4B45-9135-075E05FD8ABA}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
          FirewallRules: [{53C9455C-A2AD-488F-9F7E-1C8EF4F4BF53}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
          FirewallRules: [{7E1C3318-2393-4C1E-80CA-FA6C702F95F6}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
          FirewallRules: [{68A45443-F566-4D63-9416-AFBE8603687C}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
          FirewallRules: [{B587CDC1-7EF2-4FB9-B44E-6FEFCA852C07}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
          FirewallRules: [{B4FB657D-E7F6-489B-BE3C-DA845CE48238}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
          FirewallRules: [{1987AB73-FA8B-4D5E-AFEA-1AE1AE014B3E}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
          FirewallRules: [{025A8C94-09F1-4849-AFDF-89858D0E44C2}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
          FirewallRules: [{340DCFE0-7F85-4FE1-8307-3897E8C2513F}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
          FirewallRules: [{7782B181-9661-4830-9A09-CF77E00D32C6}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
          FirewallRules: [{669ACE6F-C5A2-4CD6-94C6-59A70EE67B01}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
          FirewallRules: [{0D167765-DD19-4AA7-A8A7-D37F0B26F350}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

          ==================== Faulty Device Manager Devices =============

          Name: Standard VGA Graphics Adapter
          Description: Standard VGA Graphics Adapter
          Class Guid: {4d36e968-e325-11ce-bfc1-08002be10318}
          Manufacturer: (Standard display types)
          Service: vga
          Problem: : This device cannot start. (Code10)
          Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
          On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

          Name: Base System Device
          Description: Base System Device
          Class Guid:
          Manufacturer:
          Service:
          Problem: : The drivers for this device are not installed. (Code 28)
          Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

          Name: SM Bus Controller
          Description: SM Bus Controller
          Class Guid:
          Manufacturer:
          Service:
          Problem: : The drivers for this device are not installed. (Code 28)
          Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

          Name: StorLib bus (virtual storages support)
          Description: StorLib bus (virtual storages support)
          Class Guid: {1378e71b-ab4d-4348-af26-cba56b12969e}
          Manufacturer: EldoS Corporation
          Service: cbfs3
          Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
          Resolution: A registry problem was detected.
           This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
          On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
          Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.


          ==================== Event log errors: =========================

          Application errors:
          ==================
          Error: (05/27/2015 08:41:22 AM) (Source: WinMgmt) (EventID: 10) (User: )
          Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

          Error: (05/26/2015 05:00:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
          Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

          Error: (05/26/2015 07:48:34 AM) (Source: WinMgmt) (EventID: 10) (User: )
          Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

          Error: (05/25/2015 04:28:13 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
          Description: The entry in the hash map cannot be updated.

          Context:  Application, SystemIndex Catalog


          Details:
              A device attached to the system is not functioning.   (0x8007001f)

          Error: (05/25/2015 04:28:13 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
          Description: The entry in the hash map cannot be updated.

          Context:  Application, SystemIndex Catalog


          Details:
              A device attached to the system is not functioning.   (0x8007001f)

          Error: (05/25/2015 09:13:15 AM) (Source: WinMgmt) (EventID: 10) (User: )
          Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

          Error: (05/23/2015 10:56:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
          Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

          Error: (05/23/2015 10:45:09 AM) (Source: Application Hang) (EventID: 1002) (User: )
          Description: The program OUTLOOK.EXE version 11.0.8326.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
          Process ID: cb8
          Start Time: 01d094de7fcfdb26
          Termination Time: 15

          Error: (05/22/2015 10:50:39 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
          Description: The application cannot be initialized.

          Context: Windows Application


          Details:
              The content index metadata cannot be read.   (0xc0041801)

          Error: (05/22/2015 10:50:39 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
          Description: The gatherer object cannot be initialized.

          Context: Windows Application, SystemIndex Catalog


          Details:
              The content index metadata cannot be read.   (0xc0041801)


          System errors:
          =============
          Error: (05/27/2015 08:44:44 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
          Description: AVGIDSAgent3758213661 (0xE001CA1D)

          Error: (05/27/2015 08:41:22 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
          Description: AVGIDSAgent3758213661 (0xE001CA1D)

          Error: (05/26/2015 07:53:23 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
          Description: AVGIDSAgent3758213661 (0xE001CA1D)

          Error: (05/26/2015 07:33:02 PM) (Source: ACPI) (EventID: 13) (User: )
          Description: : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.

          Error: (05/26/2015 07:32:57 PM) (Source: ACPI) (EventID: 13) (User: )
          Description: : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.

          Error: (05/26/2015 05:14:44 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
          Description: Windows Media Player Network Sharing Service1300001Restart the service

          Error: (05/26/2015 05:14:44 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
          Description: Intuit Update Service v41

          Error: (05/26/2015 05:14:44 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
          Description: iPod Service1

          Error: (05/26/2015 05:14:43 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
          Description: SurfEasy Service1

          Error: (05/26/2015 05:14:43 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
          Description: Secunia PSI Agent1


          Microsoft Office:
          =========================

          CodeIntegrity Errors:
          ===================================
            Date: 2015-05-27 09:14:07.979
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

            Date: 2015-05-27 09:14:07.846
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

            Date: 2015-05-27 09:14:07.711
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

            Date: 2015-05-27 09:14:07.550
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

            Date: 2015-05-27 09:13:57.781
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

            Date: 2015-05-27 09:13:57.648
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

            Date: 2015-05-27 09:13:57.512
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

            Date: 2015-05-27 09:13:57.368
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

            Date: 2015-05-27 09:13:57.081
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsdrivera.sys because the set of per-page image hashes could not be found on the system.

            Date: 2015-05-27 09:13:56.945
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsdrivera.sys because the set of per-page image hashes could not be found on the system.


          ==================== Memory info ===========================

          Processor: Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz
          Percentage of memory in use: 67%
          Total physical RAM: 2042.07 MB
          Available physical RAM: 656.79 MB
          Total Pagefile: 4339.43 MB
          Available Pagefile: 2518.39 MB
          Total Virtual: 8192 MB
          Available Virtual: 8191.85 MB

          ==================== Drives ================================

          Drive c: () (Fixed) (Total:465.76 GB) (Free:337.42 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
          Drive d: (TNT) (CDROM) (Total:0.63 GB) (Free:0 GB) CDFS

          ==================== MBR & Partition Table ==================

          ========================================================
          Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 1B428473)
          Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

          ==================== End of log ============================

          I see under your firewall rules that Firefox is blocked, have you done this yourself ?

           

          I also see a lot of activity in relation to SurfEasy, its a legit program, do you use and want this program ?

          Hi ken545,

           

          I have not tried to block Firefox, actually that is my default browser.  I do use SurfEasy but really only on my mobile devices for vpn connectivity.

          It works but very slow. eveerything is slow, just typing this has about 3-4 second delay before anything populates on reply box

          Your running FRST64 from your downloads folder, our tools and scanners work more efficiently when run from the Desktop in lieu of being buried in some folder, so go to your Downloads folder and look for FRST64, right click on it and select CUT, then come back to your Desktop and right click on a blank space and select PASTE, then we will have FRST64 exactly where we want it to be. 

           

           

           

          I am attaching a FIXLIST file, you need to download it to your desktop where you now have FRST64 or the fix wont work, use your mouse to drag FIXLIST right next to FRST64, either above or below it but not right on top of it, after its downloaded open up FRST64 and click on FIX (Not Scan) it wont take long, after your computer reboots you will find a FIXLOG file on your desktop, post it please and let me know how your system is behaving now

          Attachments:

          Fix result of Farbar Recovery Scan Tool (x64) Version: 27-05-2015
          Ran by [removed] at 2015-05-27 12:22:24 Run:1
          Running from C:\Users\[removed]\Desktop
          [removed] Boot Mode: Normal
          ==============================================

          fixlist content:
          *****************
          Start
          CloseProcesses:
          CreateRestorePoint:
          FirewallRules: [TCP Query User{5AAD3761-BCEA-4E0B-9621-6E566D42229C}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
          FirewallRules: [UDP Query User{E6A5EDA0-E7AD-4107-AB62-55C98A6833A6}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
          CMD: ipconfig /flushdns
          Hosts:
          EmptyTemp:
          End















          *****************

          Processes closed successfully.
          Restore point was successfully created.
          HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5AAD3761-BCEA-4E0B-9621-6E566D42229C}C:\program files (x86)\mozilla firefox\firefox.exe => value Removed successfully
          HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{E6A5EDA0-E7AD-4107-AB62-55C98A6833A6}C:\program files (x86)\mozilla firefox\firefox.exe => value Removed successfully

          =========  ipconfig /flushdns =========


          Windows IP Configuration

          Successfully flushed the DNS Resolver Cache.

          ========= End of CMD: =========

          C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
          Hosts restored successfully.
          EmptyTemp: => Removed 775.1 MB temporary data.


          The system needed a reboot.

          ==== End of Fixlog 12:33:18 ====

          Things any better ?  How old is your laptop, with Vista it cant be to new ?

           

          Lets try setting FF back to defaults and see if that helps

           

          •  
          • Open Firefox
          • Click on Help > Troubleshooting Information > Reset Firefox to its default state
           
          ==============================================================================
           
           
           
          Although I don't see markers in your logs for a serious rootkit type of infection lets run Combofix and see if it finds anything bad
           
           

           

           
          Download ComboFix from one of these locations:
           
          Link 1
          Link 2
           
           
          * IMPORTANT !!! Save ComboFix.exe to your Desktop
           
           
          • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
        • See this Link  for programs that need to be disabled and instruction on how to disable them.
        • Remember to re-enable them when we're done.
        •  
        • Double click on ComboFix.exe & follow the prompts.
        •  
          For Windows XP Users
           
        • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. 
        •  
           
        • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
        •  
           
          **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
           
           
          [external image: RC1.png]
           
           
          Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
          [external image: RC2-1.png]
           
          Click on Yes, to continue scanning for malware.
           
          When finished, it shall produce a log for you.  Please include the C:\ComboFix.txt in your next reply.
           
          *If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
           
           

          Ask AI

          AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

          Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI