This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

adcash adware [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,


My system is infected with some sort of adware. When I am using firefox or internet explorer I get popups from adcash,alibaba, and mgid. Primarily the popups come from adcash. I also get redirected to another site whenever I click on anything. When I click on a link a new tab opens from adcash then it redirects to another site usually to buy handbags or play some stupid flash game. I use norton internet security and its scans find nothing. I have used malwarebytes and again it finds nothing. I used hitman pro and it found about 10 things and deleted them but the problem still exists. I have uninstalled and reinstalled firefox (didn't help). I have also reset firefox and internet explorer (didn't help). I made a post on the norton forums and I was advised to make a post on this site. Here is the text from my farbar recovery scan tool. I also have a hijackthis log and aswMBR has been updating for a while now but when it is done I can add that too. Thanks in advance to any and all help!


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-05-2015
Ran by [removed] (administrator) on MITCH-PC on 30-05-2015 10:10:37
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security\Engine\22.2.0.31\ns.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security\Engine\22.2.0.31\ns.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
() C:\Users\Mitch\AppData\Local\Viber\Viber.exe
(GoPro) D:\GoProStudio\GoPro\Tools\Importer\GoPro Importer.exe
(Apple Inc.) D:\itunes\iTunesHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11905128 2011-06-28] (Realtek Semiconductor)
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2685072 2015-05-02] (NVIDIA Corporation)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [CanonSolutionMenu] => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [767312 2009-09-04] (CANON INC.)
HKLM\…\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2710856 2009-11-02] (CANON INC.)
HKLM-x32\…\Run: [iTunesHelper] => D:\itunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKU\S-1-5-21-2063529352-2004629126-3488318073-1002\…\Run: [Viber] => C:\Users\Mitch\AppData\Local\Viber\Viber.exe [80036560 2015-05-26] ()
HKU\S-1-5-21-2063529352-2004629126-3488318073-1002\…\Run: [Google Update] => C:\Users\Mitch\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-04-04] (Google Inc.)
HKU\S-1-5-21-2063529352-2004629126-3488318073-1002\…\MountPoints2: {c4f6b297-b40a-11e1-943d-00309140007e} - F:\MotoCastSetup.exe -a
HKU\S-1-5-21-2063529352-2004629126-3488318073-1002\…\MountPoints2: {f5825d47-4d41-11e1-bb50-806e6f6e6963} - E:\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GoPro Importer.lnk [2015-01-04]
ShortcutTarget: GoPro Importer.lnk -> D:\GoProStudio\GoPro\Tools\Importer\GoPro Importer.exe (GoPro)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2063529352-2004629126-3488318073-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security\Engine64\22.2.0.31\coIEPlg.dll [2015-03-30] (Symantec Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security\Engine\22.2.0.31\coIEPlg.dll [2015-03-30] (Symantec Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine64\22.2.0.31\coIEPlg.dll [2015-03-30] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine\22.2.0.31\coIEPlg.dll [2015-03-30] (Symantec Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]

FireFox:
========
FF ProfilePath: C:\Users\Mitch\AppData\Roaming\Mozilla\Firefox\Profiles\a51xhlfg.default-1432937755150
FF Homepage: google.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-16] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-16] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll [2013-12-05] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> D:\itunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-02-05] (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-04-09] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-04-09] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-02] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2063529352-2004629126-3488318073-1002: @talk.google.com/GoogleTalkPlugin -> C:\Users\Mitch\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll No File
FF Plugin HKU\S-1-5-21-2063529352-2004629126-3488318073-1002: @talk.google.com/O1DPlugin -> C:\Users\Mitch\AppData\Roaming\Mozilla\plugins\npo1d.dll No File
FF Plugin HKU\S-1-5-21-2063529352-2004629126-3488318073-1002: @tools.google.com/Google Update;version=3 -> C:\Users\Mitch\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-2063529352-2004629126-3488318073-1002: @tools.google.com/Google Update;version=9 -> C:\Users\Mitch\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Extension: Self-Destructing Cookies - C:\Users\Mitch\AppData\Roaming\Mozilla\Firefox\Profiles\a51xhlfg.default-1432937755150\Extensions\[removed] [2015-05-30]
FF HKLM-x32\…\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.1.0.9\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.1.0.9\coFFPlgn [2015-05-30]

Chrome:
=======
CHR Profile: C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security\Engine\22.2.0.31\Exts\Chrome.crx [2015-04-14]
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security\Engine\22.2.0.31\Exts\Chrome.crx [2015-04-14]
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-05-02] (NVIDIA Corporation)
R2 NS; C:\Program Files (x86)\Norton Security\Engine\22.2.0.31\NS.exe [282528 2015-04-01] (Symantec Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1884304 2015-05-02] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22997648 2015-05-02] (NVIDIA Corporation)
S2 SkypeUpdate; D:\Skypee\Updater\Updater.exe [315488 2015-02-18] (Skype Technologies)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx64; C:\Program Files (x86)\Norton Security\NortonData\22.1.0.9\Definitions\BASHDefs\20150521.001\BHDrvx64.sys [1640152 2015-05-22] (Symantec Corporation)
R1 ccSet_NS; C:\Windows\system32\drivers\NSx64\1602000.01F\ccSetx64.sys [165080 2014-09-09] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [489776 2015-05-27] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [145200 2015-05-27] (Symantec Corporation)
R3 GUKBFLTR; C:\Windows\System32\drivers\GUKBFLTR.sys [29440 2010-02-06] ()
R1 IDSVia64; C:\Program Files (x86)\Norton Security\NortonData\22.1.0.9\Definitions\IPSDefs\20150522.001\IDSvia64.sys [684248 2015-05-26] (Symantec Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Security\NortonData\22.1.0.9\Definitions\VirusDefs\20150528.037\ENG64.SYS [129752 2015-03-15] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Security\NortonData\22.1.0.9\Definitions\VirusDefs\20150528.037\EX64.SYS [2137304 2015-03-15] (Symantec Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-05-02] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R3 RTL8192cu; C:\Windows\System32\DRIVERS\rtwlanu.sys [1041000 2012-02-23] (Realtek Semiconductor Corporation                           )
R1 SRTSP; C:\Windows\System32\Drivers\NSx64\1602000.01F\SRTSP64.SYS [916184 2015-03-27] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NSx64\1602000.01F\SRTSPX64.SYS [42200 2014-12-02] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NSx64\1602000.01F\SYMDS64.SYS [490712 2014-09-09] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NSx64\1602000.01F\SYMEFA64.SYS [1151704 2014-09-09] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [102616 2015-03-09] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NSx64\1602000.01F\Ironx64.SYS [271576 2014-09-09] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NSx64\1602000.01F\SYMNETS.SYS [565464 2014-09-09] (Symantec Corporation)
S4 athur; system32\DRIVERS\athurx.sys [X]
S3 cpuz135; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X]
R3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-30 10:10 - 2015-05-30 10:10 - 00014660 _____ () C:\Users\Mitch\Desktop\FRST.txt
2015-05-30 10:10 - 2015-05-30 10:10 - 00000000 ____D () C:\FRST
2015-05-30 10:09 - 2015-05-30 10:10 - 02108928 _____ (Farbar) C:\Users\Mitch\Desktop\FRST64.exe
2015-05-30 10:03 - 2015-05-30 10:03 - 02108928 _____ (Farbar) C:\Users\Mitch\Downloads\FRST64.exe
2015-05-30 09:41 - 2015-05-30 09:41 - 00008854 _____ () C:\Users\Mitch\Desktop\hijackthis.log
2015-05-30 09:34 - 2015-05-30 09:34 - 00008329 _____ () C:\Users\Mitch\Downloads\hijackthis.log
2015-05-30 09:34 - 2015-05-30 09:34 - 00003128 _____ () C:\Windows\System32\Tasks\{5D116863-4995-4F28-9428-F9487793FA5A}
2015-05-30 09:33 - 2015-05-30 09:33 - 00388608 _____ (Trend Micro Inc.) C:\Users\Mitch\Downloads\HijackThis.exe
2015-05-30 08:28 - 2015-05-30 08:28 - 00008464 _____ () C:\Windows\system32\.crusader
2015-05-30 08:19 - 2015-05-30 08:38 - 00000000 ____D () C:\ProgramData\HitmanPro
2015-05-30 08:06 - 2015-05-30 08:13 - 00000000 ____D () C:\AdwCleaner
2015-05-30 01:01 - 2015-05-30 01:03 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Mozilla
2015-05-30 01:01 - 2015-05-30 01:01 - 00001170 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-05-30 01:01 - 2015-05-30 01:01 - 00001158 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-05-30 01:01 - 2015-05-30 01:01 - 00000000 ____D () C:\ProgramData\Mozilla
2015-05-30 01:01 - 2015-05-30 01:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-30 01:01 - 2015-05-30 01:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-29 23:59 - 2015-05-29 23:59 - 00013411 _____ () C:\Users\Mitch\Documents\bookmarks-2015-05-29.json
2015-05-29 23:29 - 2015-05-30 07:49 - 00000000 ____D () C:\Users\Mitch\AppData\Local\LogMeIn Rescue Applet
2015-05-29 22:24 - 2015-05-29 22:24 - 00000000 ____D () C:\NPE
2015-05-29 22:17 - 2015-05-29 22:17 - 00000961 _____ () C:\Users\Mitch\Desktop\Viber.lnk
2015-05-29 22:16 - 2015-05-30 08:30 - 00001568 _____ () C:\Windows\setupact.log
2015-05-29 22:16 - 2015-05-30 00:42 - 00009230 _____ () C:\Windows\PFRO.log
2015-05-29 22:16 - 2015-05-29 22:16 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-29 22:05 - 2015-05-29 22:27 - 00000000 ____D () C:\Users\Mitch\AppData\Local\NPE
2015-05-29 21:50 - 2015-05-29 22:16 - 00000000 ____D () C:\Program Files\Webroot
2015-05-15 12:24 - 2015-05-15 12:24 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\java
2015-05-14 14:27 - 2015-05-14 14:27 - 00000000 ____D () C:\Windows\rescache
2015-05-13 23:58 - 2015-05-01 23:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 23:58 - 2015-05-01 23:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 12:45 - 2015-04-22 12:28 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-13 12:45 - 2015-04-22 11:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-13 12:45 - 2015-04-22 03:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 12:45 - 2015-04-22 03:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-13 12:45 - 2015-04-22 03:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 12:45 - 2015-04-22 02:51 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-05-13 12:45 - 2015-04-22 02:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 12:45 - 2015-04-22 02:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 12:45 - 2015-04-22 02:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-05-13 12:45 - 2015-04-22 02:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 12:45 - 2015-04-22 02:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-05-13 12:45 - 2015-04-22 02:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-13 12:45 - 2015-04-22 02:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-05-13 12:45 - 2015-04-22 02:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 12:45 - 2015-04-22 02:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 12:45 - 2015-04-22 02:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-13 12:45 - 2015-04-22 02:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-05-13 12:45 - 2015-04-22 02:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-05-13 12:45 - 2015-04-22 02:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 12:45 - 2015-04-22 02:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 12:45 - 2015-04-22 02:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-05-13 12:45 - 2015-04-22 02:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-13 12:45 - 2015-04-22 02:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-13 12:45 - 2015-04-22 02:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 12:45 - 2015-04-22 02:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-13 12:45 - 2015-04-22 02:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-05-13 12:45 - 2015-04-22 02:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-05-13 12:45 - 2015-04-22 02:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-13 12:45 - 2015-04-22 02:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-05-13 12:45 - 2015-04-22 02:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 12:45 - 2015-04-22 02:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-05-13 12:45 - 2015-04-22 02:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 12:45 - 2015-04-22 02:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-13 12:45 - 2015-04-22 02:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-05-13 12:45 - 2015-04-22 02:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-05-13 12:45 - 2015-04-22 02:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-05-13 12:45 - 2015-04-22 01:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-13 12:45 - 2015-04-22 01:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-05-13 12:45 - 2015-04-22 01:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-05-13 12:45 - 2015-04-22 01:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 12:45 - 2015-04-22 01:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-13 12:45 - 2015-04-22 01:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-05-13 12:45 - 2015-04-22 01:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-05-13 12:45 - 2015-04-22 01:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 12:45 - 2015-04-22 01:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-05-13 12:45 - 2015-04-22 01:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 12:45 - 2015-04-22 01:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-05-13 12:45 - 2015-04-22 01:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-13 12:45 - 2015-04-22 01:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-13 12:45 - 2015-04-22 01:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-13 12:45 - 2015-04-22 01:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 12:45 - 2015-04-22 01:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-13 12:45 - 2015-04-22 01:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-13 12:45 - 2015-04-22 01:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-05-13 12:45 - 2015-04-22 01:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-13 12:45 - 2015-04-22 01:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 12:45 - 2015-04-22 01:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-13 12:45 - 2015-04-22 01:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-13 12:45 - 2015-04-22 00:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-13 12:45 - 2015-04-22 00:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-13 11:17 - 2015-05-05 11:29 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 11:17 - 2015-05-05 11:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-13 11:17 - 2015-04-18 13:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-13 11:17 - 2015-04-18 12:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-13 11:12 - 2015-04-28 05:28 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-05-13 11:12 - 2015-04-28 05:28 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-05-13 11:12 - 2015-04-28 05:28 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-05-13 11:12 - 2015-04-28 05:26 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 01254400 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-05-13 11:12 - 2015-04-28 05:23 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-05-13 11:12 - 2015-04-28 05:22 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-05-13 11:12 - 2015-04-28 05:22 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-05-13 11:12 - 2015-04-28 05:22 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-05-13 11:12 - 2015-04-28 05:22 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-05-13 11:12 - 2015-04-28 05:22 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-05-13 11:12 - 2015-04-28 05:22 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-05-13 11:12 - 2015-04-28 05:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-05-13 11:12 - 2015-04-28 05:22 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-05-13 11:12 - 2015-04-28 05:22 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-05-13 11:12 - 2015-04-28 05:21 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-05-13 11:12 - 2015-04-28 05:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-05-13 11:12 - 2015-04-28 05:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 05:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-05-13 11:12 - 2015-04-28 05:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-05-13 11:12 - 2015-04-28 05:08 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-05-13 11:12 - 2015-04-28 05:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-05-13 11:12 - 2015-04-28 05:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-05-13 11:12 - 2015-04-28 05:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-05-13 11:12 - 2015-04-28 05:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-05-13 11:12 - 2015-04-28 05:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-05-13 11:12 - 2015-04-28 05:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-05-13 11:12 - 2015-04-28 05:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-05-13 11:12 - 2015-04-28 05:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-05-13 11:12 - 2015-04-28 05:05 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-05-13 11:12 - 2015-04-28 05:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-05-13 11:12 - 2015-04-28 05:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-05-13 11:12 - 2015-04-28 05:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-05-13 11:12 - 2015-04-28 05:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-05-13 11:12 - 2015-04-28 05:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
2015-05-13 11:12 - 2015-04-28 05:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2015-05-13 11:12 - 2015-04-28 05:04 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-05-13 11:12 - 2015-04-28 05:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-05-13 11:12 - 2015-04-28 05:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-05-13 11:12 - 2015-04-28 05:03 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-05-13 11:12 - 2015-04-28 05:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-05-13 11:12 - 2015-04-28 05:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-05-13 11:12 - 2015-04-28 05:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
2015-05-13 11:12 - 2015-04-28 05:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-05-13 11:12 - 2015-04-28 05:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-05-13 11:12 - 2015-04-28 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 04:06 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-13 11:12 - 2015-04-28 03:57 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-05-13 11:12 - 2015-04-28 03:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-05-13 11:12 - 2015-04-28 03:55 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 03:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 03:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-13 11:12 - 2015-04-28 03:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-13 11:12 - 2015-04-13 13:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-13 11:10 - 2015-04-20 13:17 - 01647104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 11:10 - 2015-04-20 13:17 - 01179136 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 11:10 - 2015-04-20 12:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-13 11:10 - 2015-04-20 12:11 - 03204608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 11:10 - 2015-04-08 13:29 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-05-13 11:10 - 2015-04-08 13:29 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-05-13 11:10 - 2015-04-08 13:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-05-13 11:09 - 2015-03-04 14:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-13 11:09 - 2015-03-04 14:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-13 11:09 - 2015-03-04 14:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-13 11:09 - 2015-03-04 14:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-13 11:09 - 2015-03-04 14:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-05-13 11:09 - 2015-03-04 14:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-05-13 11:09 - 2015-03-04 14:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-05-13 11:09 - 2015-02-18 17:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2015-05-13 11:09 - 2015-02-18 17:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-13 11:09 - 2015-01-29 13:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-13 11:09 - 2015-01-29 13:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2015-05-06 12:34 - 2015-04-09 06:32 - 00560968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-05-06 12:33 - 2015-04-09 10:58 - 31570064 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 30397072 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 25375048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 24053576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 17176128 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 15818528 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 15716232 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 14006752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 12852784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 11380728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 10423952 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-05-06 12:33 - 2015-04-09 10:58 - 02935416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 02896528 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 02573456 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 01895568 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435012.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435012.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 01086424 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 01047368 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 01037640 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 00970568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 00962192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 00927440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 00195728 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-05-06 12:33 - 2015-04-09 10:58 - 00175880 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 00154256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 00150648 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 00128512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-05-06 12:33 - 2015-04-09 10:58 - 00030536 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-30 10:07 - 2009-07-14 14:45 - 00028944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-30 10:07 - 2009-07-14 14:45 - 00028944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-30 10:00 - 2015-04-11 18:11 - 01300168 _____ () C:\Windows\WindowsUpdate.log
2015-05-30 09:53 - 2012-05-14 19:17 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-30 09:51 - 2012-04-04 23:47 - 00000908 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2063529352-2004629126-3488318073-1002UA.job
2015-05-30 08:36 - 2009-07-14 15:13 - 00782510 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-30 08:30 - 2014-01-20 09:28 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\ViberPC
2015-05-30 08:30 - 2012-02-03 04:12 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-30 08:30 - 2009-07-14 15:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-29 22:44 - 2013-02-03 13:12 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Adobe
2015-05-29 22:17 - 2014-01-20 09:28 - 00000969 _____ () C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber.lnk
2015-05-29 22:17 - 2014-01-20 09:27 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Viber
2015-05-29 22:06 - 2012-02-08 07:36 - 00000000 ____D () C:\ProgramData\Norton
2015-05-29 21:51 - 2012-04-04 23:47 - 00000856 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2063529352-2004629126-3488318073-1002Core.job
2015-05-29 21:29 - 2012-02-25 11:10 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\Skype
2015-05-29 20:09 - 2013-12-20 18:49 - 00000000 ____D () C:\Users\Mitch\AppData\Local\Battle.net
2015-05-23 09:33 - 2012-04-16 04:33 - 00000000 ____D () C:\Windows\Minidump
2015-05-20 23:31 - 2015-04-04 13:37 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-05-20 23:31 - 2015-04-04 13:37 - 00000000 ___SD () C:\Windows\system32\GWX
2015-05-16 21:46 - 2012-04-04 23:47 - 00003878 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2063529352-2004629126-3488318073-1002UA
2015-05-16 21:46 - 2012-04-04 23:47 - 00003482 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2063529352-2004629126-3488318073-1002Core
2015-05-15 21:40 - 2013-02-03 13:11 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-05-15 18:10 - 2012-02-20 06:25 - 00000000 ____D () C:\Users\Mitch\AppData\Roaming\.minecraft
2015-05-14 10:41 - 2009-07-14 14:45 - 00294496 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-14 10:40 - 2010-11-21 17:17 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-14 10:40 - 2009-07-14 13:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-05-14 00:01 - 2013-08-19 13:44 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-13 23:59 - 2012-02-18 04:26 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-06 12:34 - 2014-11-27 20:43 - 00000000 ____D () C:\temp
2015-05-06 12:34 - 2012-12-19 12:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-05-06 12:33 - 2012-02-03 04:11 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-05-06 12:24 - 2013-07-17 16:12 - 00001388 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk
2015-05-06 12:23 - 2012-02-08 11:39 - 00000000 ____D () C:\Users\Mitch\AppData\Local\CrashDumps
2015-05-06 09:23 - 2012-02-25 11:09 - 00000000 ____D () C:\ProgramData\Skype
2015-05-02 02:51 - 2014-07-21 17:11 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-05-02 02:51 - 2014-07-21 17:09 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-05-02 02:50 - 2014-07-21 17:11 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-05-02 02:50 - 2014-07-21 17:09 - 01570672 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll

==================== Files in the root of some directories =======

2012-02-08 08:20 - 2012-02-08 08:20 - 0001603 _____ () C:\ProgramData\repository.xml

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-24 10:35

==================== End of log ============================




Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-05-2015
Ran by [removed] at 2015-05-30 10:10:50
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2063529352-2004629126-3488318073-500 - Administrator - Disabled)
Guest (S-1-5-21-2063529352-2004629126-3488318073-501 - Limited - Disabled)
Mitch (S-1-5-21-2063529352-2004629126-3488318073-1002 - Administrator - Enabled) => C:\Users\Mitch

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Security (Enabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Security (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton Security (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 17 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.11) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASIO4ALL (HKLM-x32\…\ASIO4ALL) (Version: 2.10 - Michael Tippach)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.12.5.0 - Asmedia Technology)
Battle.net (HKLM-x32\…\Battle.net) (Version:  - Blizzard Entertainment)
Belkin N600 DB USB Wireless Adapter (HKLM-x32\…\{B20F9D1C-A0A5-4CD8-8306-DA03872311B1}) (Version: 1.00.0184.2 - Belkin International, Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Canon iP2700 series Printer Driver (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2700_series) (Version:  - Canon Inc.)
Canon iP2700 series User Registration (HKLM-x32\…\Canon iP2700 series User Registration) (Version:  - )
Canon Utilities Easy-PhotoPrint EX (HKLM-x32\…\Easy-PhotoPrint EX) (Version:  - )
Canon Utilities My Printer (HKLM-x32\…\CanonMyPrinter) (Version:  - )
Canon Utilities Solution Menu (HKLM-x32\…\CanonSolutionMenu) (Version:  - )
Command and Conquer: Red Alert 3 (HKLM-x32\…\Steam App 17480) (Version:  - EA Los Angeles)
Counter-Strike (HKLM-x32\…\Steam App 10) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\…\Steam App 240) (Version:  - Valve)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DayZ (HKLM-x32\…\Steam App 221100) (Version:  - Bohemia Interactive)
Diablo III (HKLM-x32\…\Diablo III) (Version:  - Blizzard Entertainment)
Dota 2 (HKLM-x32\…\Steam App 570) (Version:  - Valve)
Fallout: New Vegas (HKLM-x32\…\Steam App 22380) (Version:  - Bethesda Softworks)
FL Studio 10 (HKLM-x32\…\FL Studio 10) (Version:  - Image-Line)
FrostWire 6.0.4 (HKLM-x32\…\FrostWire 6) (Version: 6.0.4.1 - FrostWire LLC)
Garry's Mod (HKLM-x32\…\Steam App 4000) (Version:  - Garry)
Google Talk Plugin (HKLM-x32\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (x32 Version: 1.3.25.0 - Google Inc.) Hidden
GoPro Studio 2.5.4 (HKLM-x32\…\GoPro Studio) (Version: 2.5.4 - GoPro, Inc.)
Guild Wars 2 (HKLM-x32\…\Guild Wars 2) (Version:  - NCsoft Corporation, Ltd.)
Hearthstone (HKLM-x32\…\Hearthstone) (Version:  - Blizzard Entertainment)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
iTunes (HKLM\…\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 8 Update 40 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Just Cause 2 (HKLM-x32\…\Steam App 8190) (Version:  - Avalanche Studios)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\…\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 38.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 38.0.1 (x86 en-US)) (Version: 38.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 38.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Norton Security (HKLM-x32\…\NS) (Version: 22.2.0.31 - Symantec Corporation)
NVIDIA 3D Vision Controller Driver 349.95 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 349.95 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 350.12 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 350.12 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.4.3.22 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.3.22 - NVIDIA Corporation)
NVIDIA Graphics Driver 350.12 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 350.12 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.33.0 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0324 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0324 - NVIDIA Corporation)
OpenOffice 4.1.1 (HKLM-x32\…\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Portal 2 (HKLM-x32\…\Steam App 620) (Version:  - Valve)
Quake Live (HKLM-x32\…\Steam App 282440) (Version:  - id Software)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6402 - Realtek Semiconductor Corp.)
Rosetta Stone Version 3 (HKLM-x32\…\{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}) (Version: 3.4.7.0 - Rosetta Stone Ltd.)
Saints Row: The Third (HKLM-x32\…\Steam App 55230) (Version:  - Volition)
Sanctum 2 (HKLM-x32\…\Steam App 210770) (Version:  - Coffee Stain Studios)
SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.3.22 - NVIDIA Corporation) Hidden
Skype™ 7.4 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.4.102 - Skype Technologies S.A.)
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Fortress 2 (HKLM-x32\…\Steam App 440) (Version:  - Valve)
Tt eSPORTS Challenger gaming keyboard Driver V1.0 (HKLM-x32\…\{1C0A8AE2-C207-49EF-A2FC-12981E460B55}_is1) (Version:  - Ttesports Inc.)
Unturned (HKLM-x32\…\Steam App 304930) (Version:  - Nelson Sexton)
Ventrilo Client (HKLM-x32\…\{789289CA-F73A-4A16-A331-54D498CE069F}) (Version: 3.0.8 - Flagship Industries, Inc.)
Viber (HKU\S-1-5-21-2063529352-2004629126-3488318073-1002\…\Viber) (Version: 5.1.1.15 - Viber Media Inc)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
World of Warcraft (HKLM-x32\…\World of Warcraft) (Version:  - Blizzard Entertainment)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2063529352-2004629126-3488318073-1002_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Mitch\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2063529352-2004629126-3488318073-1002_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Mitch\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2063529352-2004629126-3488318073-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Mitch\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll (Google Inc.)

==================== Restore Points =========================


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 12:34 - 2009-06-11 07:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {263F1974-5686-4AA6-99A7-35F3FD7871D8} - System32\Tasks\Norton Security\Norton Error Processor => C:\Program Files (x86)\Norton Security\Engine\22.2.0.31\SymErr.exe [2015-02-25] (Symantec Corporation)
Task: {29F21D99-5A19-40B3-93B2-3F2E2C3CDC85} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-08] (Microsoft Corporation)
Task: {32E49CD3-5201-4B8D-80EB-D166F34878A0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {49785E47-0D81-4D0F-8E67-F73175FB3237} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe
Task: {50D4AF54-FEF2-4E6F-AA35-5DB1D5EA1400} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-16] (Adobe Systems Incorporated)
Task: {5B74125E-3176-4230-B6E4-5691C1FFDC91} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Security\Engine\22.2.0.31\WSCStub.exe [2015-04-01] (Symantec Corporation)
Task: {75B1C61C-49DD-484F-9668-7A5670686C5F} - System32\Tasks\Norton Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Security\Engine\22.2.0.31\SymErr.exe [2015-02-25] (Symantec Corporation)
Task: {7F4926D2-E65C-4FA1-BCB6-A38F04DCC414} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2063529352-2004629126-3488318073-1002UA => C:\Users\Mitch\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04] (Google Inc.)
Task: {97480409-A177-498F-A351-F6D79942E80C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2063529352-2004629126-3488318073-1002Core => C:\Users\Mitch\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04] (Google Inc.)
Task: {99948493-97E6-4246-997D-BF342A9773E9} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-08] (Microsoft Corporation)
Task: {A5180723-9A38-467A-9631-61A0392812A1} - System32\Tasks\{5D116863-4995-4F28-9428-F9487793FA5A} => pcalua.exe -a C:\Users\Mitch\Downloads\HijackThis.exe -d C:\Users\Mitch\Downloads
Task: {C7E9C0D1-FF9D-41D4-BF59-228D2583E4B1} - System32\Tasks\{595AB3C1-07BE-4BE5-A704-CCB65D6A8E04} => pcalua.exe -a "C:\Users\Mitch\Downloads\World of Warcraft Beta Setup.exe" -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {CAE22EFE-5391-4206-92FA-1F92993CC213} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2012-02-08] (Microsoft Corporation)
Task: {CD0A40F3-69CB-4237-84DF-A0E756B1E02E} - System32\Tasks\{5870225C-3B3B-453C-8795-1E9AC949DD65} => pcalua.exe -a "C:\Program Files (x86)\iWebar\Uninstall.exe" -c /fcp=1
Task: {F32247C2-B5AB-4DBC-AD80-F5FFF217AEF5} - System32\Tasks\{C5AEE7C6-011A-44A8-ADA2-11711E14E0E3} => pcalua.exe -a C:\Users\Mitch\AppData\Local\Temp\Shockwave_Installer_FF-1.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {F5B81C00-7572-48CF-B9BA-71E19D62358D} - System32\Tasks\{0B5B9A1E-9B2F-4AC9-8E71-68DF085B5A6E} => pcalua.exe -a C:\Users\Mitch\Downloads\Diablo-III-8370-enUS-Installer-downloader.exe -d C:\Users\Mitch\Downloads
Task: {F87D4F17-22A3-4C2D-89FA-AC7A466DC655} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-02] (Apple Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2063529352-2004629126-3488318073-1002Core.job => C:\Users\Mitch\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2063529352-2004629126-3488318073-1002UA.job => C:\Users\Mitch\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2012-02-03 04:12 - 2015-04-09 07:30 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-01-20 09:28 - 2015-05-26 00:39 - 80036560 _____ () C:\Users\Mitch\AppData\Local\Viber\Viber.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-05-06 12:24 - 2015-05-02 02:52 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-05-29 22:17 - 2015-02-25 17:21 - 01507328 _____ () C:\Users\Mitch\AppData\Local\Viber\libGLESv2.dll
2015-05-29 22:17 - 2015-05-26 00:03 - 00100864 _____ () C:\Users\Mitch\AppData\Local\Viber\qfacebook.dll
2015-05-29 22:17 - 2015-05-26 00:02 - 00171008 _____ () C:\Users\Mitch\AppData\Local\Viber\exif.dll
2015-05-29 22:17 - 2015-02-25 17:21 - 00063488 _____ () C:\Users\Mitch\AppData\Local\Viber\libEGL.dll
2015-05-29 22:17 - 2015-02-25 17:36 - 00010240 _____ () C:\Users\Mitch\AppData\Local\Viber\QtQuick.2\qtquick2plugin.dll
2014-12-17 08:37 - 2014-12-17 08:37 - 01800192 _____ () D:\GoProStudio\GoPro\Tools\Importer\GPSDKAnalyticsNet.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:054203E4
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2063529352-2004629126-3488318073-1002\Control Panel\Desktop\\Wallpaper ->
DNS Servers: [removed] - [removed]

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{A2CE2911-1476-4E85-B49F-C2F2919DAE8D}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{59CE9ED5-E4DF-4C01-9F55-B243297E604D}] => (Allow) LPort=2869
FirewallRules: [{5BCBE92F-39F1-4B81-891A-D19AC5A9B50B}] => (Allow) LPort=1900
FirewallRules: [{474F3568-53A2-4C04-B23F-8877DBC3799C}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{39FCEAD8-37B4-43F5-8548-54C8BBAC4BB5}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{E6D42CAA-DF98-4A73-BC04-1A1288AD6D68}] => (Allow) LPort=1542
FirewallRules: [{58B387DC-1564-4ACE-9164-92578ABF9CE9}] => (Allow) LPort=1542
FirewallRules: [{19577F52-C8AB-4A74-8758-FAF23490FB76}] => (Allow) LPort=53
FirewallRules: [{82A34540-A7B9-4EB9-9C30-98E51655D949}] => (Allow) LPort=3724
FirewallRules: [{7C9EA485-F924-4842-B92B-B0A4017FD63E}] => (Allow) F:\Games\World of Warcraft\Launcher.exe
FirewallRules: [{7B07BC29-3C64-4EB9-9B37-BB03F0B12D07}] => (Allow) F:\Games\World of Warcraft\Launcher.exe
FirewallRules: [{55A2E447-9030-4CC0-81D5-B739578D5C84}] => (Allow) F:\Games\World of Warcraft\Launcher.patch.exe
FirewallRules: [{118EC019-402C-498B-8FD0-A690B09C7029}] => (Allow) F:\Games\World of Warcraft\Launcher.patch.exe
FirewallRules: [{489E4D2D-77B7-4873-87FE-0D5A673F637C}] => (Allow) D:\Steam\steamapps\common\Just Cause 2\JustCause2.exe
FirewallRules: [{C3F6470F-0D39-46FD-BC00-B9AE709E551A}] => (Allow) D:\Steam\steamapps\common\Just Cause 2\JustCause2.exe
FirewallRules: [{4979C5EA-1754-4D85-A116-3651E7417C83}] => (Allow) D:\Steam\steamapps\common\saints row the third\saintsrowthethird.exe
FirewallRules: [{F1B803CD-F076-4B9C-A3D7-06547943EF76}] => (Allow) D:\Steam\steamapps\common\saints row the third\saintsrowthethird.exe
FirewallRules: [{BD2C3565-0DBB-4D9B-9BBC-095EAAC9DEAE}] => (Allow) D:\Steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe
FirewallRules: [{D9BF44CF-D8EE-4D07-80C8-DCFE87CD5D24}] => (Allow) D:\Steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe
FirewallRules: [{6B9B5C2B-8066-4F11-AD6C-C07D6E61FD66}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{98DFDC0E-55D2-4727-A20E-13FE7AFF7816}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{ABE83468-F3EB-4D59-88CD-BABD7AB430C3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{7051EE0C-150B-4A36-BB88-6541F05CB4DB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E68AE523-213F-47B0-96B4-6807AFF564DD}] => (Allow) D:\Steam\steamapps\common\fallout new vegas\FalloutNVLauncher.exe
FirewallRules: [{CE7B7987-BC0B-49C8-8C42-D57CEB3BA67B}] => (Allow) D:\Steam\steamapps\common\fallout new vegas\FalloutNVLauncher.exe
FirewallRules: [{0C8C8FDB-B40D-41E6-A9E3-CD7F7C548AA0}] => (Allow) LPort=443
FirewallRules: [{ED563653-150F-4FCB-AD5D-5BEDEBE2A6EA}] => (Allow) LPort=443
FirewallRules: [{A417F758-1CDD-48E2-86C5-F701005B4765}] => (Allow) LPort=37674
FirewallRules: [{88A737D9-0D27-409D-A98C-E81FBC40BB69}] => (Allow) LPort=37674
FirewallRules: [{AB4F1E79-98F5-42F6-A883-C01C22ED90EF}] => (Allow) LPort=37675
FirewallRules: [{460444F4-DD4C-477C-8829-E06964C55F87}] => (Allow) D:\Steam\steamapps\common\saints row the third\game_launcher.exe
FirewallRules: [{45D05E63-2261-427D-BE77-05518F936E5B}] => (Allow) D:\Steam\steamapps\common\saints row the third\game_launcher.exe
FirewallRules: [{5FDBCCD1-671F-4B4B-9C9F-2FD3369CBE6C}] => (Allow) C:\Users\Mitch\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
FirewallRules: [{D43C8A50-44CA-470D-B245-512F68688073}] => (Allow) C:\Users\Mitch\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
FirewallRules: [TCP Query User{D7F39039-7EE9-465D-8F4A-2094BCFE43E5}D:\guild wars 2\gw2.exe] => (Allow) D:\guild wars 2\gw2.exe
FirewallRules: [UDP Query User{C4CF7277-B437-4B99-A163-D1DFBC723D2A}D:\guild wars 2\gw2.exe] => (Allow) D:\guild wars 2\gw2.exe
FirewallRules: [{73587B27-24BB-4686-8C13-5B7FB3FA5CA2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{6B237673-7759-429F-82B8-429C0D15BDEF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{D14494D6-9BE2-4983-ABB9-BFB2C9E14437}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{B33673CA-DB89-4A4F-A027-8B967EC6C5E3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{171D4D1C-EA0D-470F-9776-18DEDD4D92F5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{6E8D987A-1887-4A5C-A5D4-0112BF785396}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{F209D354-D65B-487C-A362-49AE73AFA691}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5F771093-A5AB-4451-81E0-89A1592AA7E6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{EC6C8922-0588-49E4-9A3D-A15145D25098}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{5E6DBF03-1AC9-4CFA-B142-C2B14A73312A}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{E80FDB09-1FBD-4506-9664-C74B1253BB2E}] => (Allow) D:\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{335E85C5-7056-4050-AFD8-BAF2EE42FD2B}] => (Allow) D:\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{D72783DE-B821-439D-81DC-B3A3F2A7F46E}] => (Allow) C:\Users\Mitch\AppData\Local\Viber\Viber.exe
FirewallRules: [{E2829757-B78F-4E72-BA36-4309CECEE1A9}] => (Allow) D:\Hearthstone\Hearthstone.exe
FirewallRules: [{AB0841EA-6ABE-4A33-AE63-BF91BB7A8E6A}] => (Allow) D:\Hearthstone\Hearthstone.exe
FirewallRules: [{5EB9C278-D09D-4BDD-8BE6-463837507AC4}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{723EA430-7B89-4B34-B18E-B57472BB6259}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{C67CF0F8-CC4F-47BB-8C54-DB8011E1354F}] => (Allow) D:\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{66511915-6C9F-4433-99AA-76C3292D8654}] => (Allow) D:\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{380FDA56-3F0A-4F45-B53D-0DEDA7CD7A2F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{42F5A71B-3DB0-4F09-ABA1-8591286391FF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{D6C50FD6-130C-4BCE-89D3-9D99EC1CD0F5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{F491A29A-592D-41EE-8BED-02989E35A85C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{9438BD55-D0DE-469A-B5CE-C01A7AAC4DCC}] => (Allow) D:\Rosetta\RosettaStoneVersion3.exe
FirewallRules: [{70D16CCD-F1D1-40AF-84DF-E3599ADCD4D6}] => (Allow) D:\Rosetta\RosettaStoneVersion3.exe
FirewallRules: [{8A653677-2A95-4823-993D-23EA8B3A6FF2}] => (Allow) D:\Rosetta\support\bin\win\RosettaStoneLtdServices.exe
FirewallRules: [{93CCB687-67E7-4615-8876-5258E8F9BD5A}] => (Allow) D:\Rosetta\support\bin\win\RosettaStoneLtdServices.exe
FirewallRules: [{96E6B571-D04E-4A44-9BE7-75761AB1C0C1}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{AE6EA942-0526-4912-92BC-F1E0253F5F9C}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{6482BA2F-BB0E-4644-943C-9E5366B0C9B1}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{47867E61-E368-4168-AA6C-E58B20559196}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{A6720207-578B-43AA-B964-F435B9204CC8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{E1A5DA6B-C005-4C53-AD5D-80998854893D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{B11C0DB2-9663-4CF4-AAAA-A460A38D32F4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{66E83E2B-463B-4DBD-A61A-16FAEF6F80B6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{3C9FE056-34DE-4D5F-9717-E0A98AACE90A}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{4CDFFD50-C410-4D1F-ADEE-667419CB7808}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{76FDD86B-06E3-4730-97BF-E1D328E245C6}] => (Allow) D:\Steam\steamapps\common\Team Fortress 2\hl2.exe
FirewallRules: [{2A197C72-EBC5-4B52-A31B-9CA6B5D93595}] => (Allow) D:\Steam\steamapps\common\Team Fortress 2\hl2.exe
FirewallRules: [{2F6B7CA6-C317-4418-8E6A-6BF0610BEAAE}] => (Allow) D:\Skypee\Phone\Skype.exe
FirewallRules: [{BA260F14-7C9F-41CD-94FE-9A9162D729CA}] => (Allow) D:\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{469F4BCB-4BBD-4DB4-970D-7247C1DC8BD4}] => (Allow) D:\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{5EA4FC5A-D46E-4FA9-B7F1-1B914F7B6D2F}] => (Allow) D:\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{DAEC03B5-EABE-4A58-8B6B-6DFD61198ACA}] => (Allow) D:\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{CCB79A62-23B4-42D0-8402-FA7938353B97}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{D305BC03-DFBF-4C9A-A63A-E7B3FFAFD6F4}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{BA2FCEC0-9AAF-41CC-B35B-D18E7CCF053D}] => (Allow) D:\Steam\steamapps\common\Sanctum2\Binaries\Win32\SanctumGame-Win32-Shipping.exe
FirewallRules: [{59B43C68-0D07-4442-A0F4-36C37883CFC0}] => (Allow) D:\Steam\steamapps\common\Sanctum2\Binaries\Win32\SanctumGame-Win32-Shipping.exe
FirewallRules: [{6BFF3C97-7A19-4E44-A050-788CB1360B86}] => (Allow) D:\Diablo III\Diablo III.exe
FirewallRules: [{E4C6696A-6F25-497D-941A-DF8A7D83CC02}] => (Allow) D:\Diablo III\Diablo III.exe
FirewallRules: [{09813AA6-2770-409F-B91A-A69B34C0A477}] => (Allow) D:\Steam\steamapps\common\Quake Live\quakelive_steam.exe
FirewallRules: [{30C1CD79-38E8-43D2-99A6-1A094CF8C182}] => (Allow) D:\Steam\steamapps\common\Quake Live\quakelive_steam.exe
FirewallRules: [{48D4A9B7-76CF-49D7-AD86-4927F353064D}] => (Allow) D:\Steam\steamapps\common\Command and Conquer Red Alert 3\runme.exe
FirewallRules: [{9AD15B7E-CCE9-464D-9F3D-7B0412E4A66B}] => (Allow) D:\Steam\steamapps\common\Command and Conquer Red Alert 3\runme.exe
FirewallRules: [{8241AB5E-D7AA-4533-9A40-9384D7A380A4}] => (Allow) D:\Steam\steamapps\common\Half-Life\hl.exe
FirewallRules: [{1F9BDDC1-2C0E-42FC-AC01-43A14EA27A20}] => (Allow) D:\Steam\steamapps\common\Half-Life\hl.exe
FirewallRules: [{A156F6AC-1594-44DD-8DE3-A764AA5B6E63}] => (Allow) D:\itunes\iTunes.exe
FirewallRules: [{4371E899-2BC0-4193-A78A-0D1E32F9FD77}] => (Allow) D:\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [{D8363970-7E53-4C3C-98EE-B33617891B4B}] => (Allow) D:\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [{C0503036-6F49-4722-94D5-D44752B68417}] => (Allow) D:\Frost\FrostWire.exe
FirewallRules: [{FAB93417-6B0E-42F4-B51D-44E1048DEE67}] => (Allow) D:\Frost\FrostWire.exe
FirewallRules: [TCP Query User{64D1BC2C-97A2-4507-92FC-E6FC8F928673}D:\fruity\diablo 3\diablo iii\diablo iii.exe] => (Allow) D:\fruity\diablo 3\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{03C81D50-E551-409A-AC6F-5D10A9FF444F}D:\fruity\diablo 3\diablo iii\diablo iii.exe] => (Allow) D:\fruity\diablo 3\diablo iii\diablo iii.exe
FirewallRules: [{0FA40C89-5ED1-4C8E-BB89-1B32CA608BBE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{879E3950-D543-4D48-BF4E-84ADA23C32DF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/30/2015 08:30:22 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000002f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,0000000001FDEFA0.72).  hr = 0x80070005, Access is denied.
.

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000083c,(null),0,REG_BINARY,0000000003ABE360.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {bb406f53-d141-42a1-a143-e412829dcfd9}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001d4,(null),0,REG_BINARY,0000000002E6F560.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {542da469-d3e1-473c-9f4f-7847f01fc64f}
   Writer Name: COM+ REGDB Writer
   Writer Instance ID: {5e24f548-b03d-48ae-84fc-f81c84cbb933}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000089c,(null),0,REG_BINARY,000000000743E4C0.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2}
   Writer Name: MSSearch Service Writer
   Writer Instance ID: {9e510401-0c92-41a9-aa72-ed09569f85cd}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001c8,(null),0,REG_BINARY,000000000206EDE0.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {afbab4a2-367d-4d15-a586-71dbb18f8485}
   Writer Name: Registry Writer
   Writer Instance ID: {15de834e-f34b-4b32-aba8-cf5a765edc5d}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000208,(null),0,REG_BINARY,00000000018BEB40.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
   Writer Name: Shadow Copy Optimization Writer
   Writer Instance ID: {06ba761b-e0ca-46c0-86b7-0ac19f063e1d}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000083c,(null),0,REG_BINARY,0000000003ABE360.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {bb406f53-d141-42a1-a143-e412829dcfd9}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000089c,(null),0,REG_BINARY,000000000743E4C0.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2}
   Writer Name: MSSearch Service Writer
   Writer Instance ID: {9e510401-0c92-41a9-aa72-ed09569f85cd}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001d4,(null),0,REG_BINARY,0000000002E6F560.72).  hr = 0x80070005, Access is denied.
.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {542da469-d3e1-473c-9f4f-7847f01fc64f}
   Writer Name: COM+ REGDB Writer
   Writer Instance ID: {5e24f548-b03d-48ae-84fc-f81c84cbb933}


System errors:
=============
Error: (05/30/2015 08:30:31 AM) (Source: volsnap) (EventID: 36) (User: )
Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.

Error: (05/30/2015 08:30:15 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 126

Error: (05/30/2015 08:30:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Coupon Printer Service service failed to start due to the following error:
%%2

Error: (05/30/2015 08:30:14 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The HitmanPro 3.7 Crusader (Boot) service terminated with service-specific error %%0.

Error: (05/30/2015 08:10:02 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 126

Error: (05/30/2015 08:09:59 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Coupon Printer Service service failed to start due to the following error:
%%2

Error: (05/30/2015 08:09:06 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Coupon Printer Service service failed to start due to the following error:
%%2

Error: (05/30/2015 08:09:02 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (05/30/2015 08:09:01 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Modules Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.

Error: (05/30/2015 08:09:01 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.


Microsoft Office:
=========================
Error: (05/30/2015 08:30:22 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000002f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,0000000001FDEFA0.72)0x80070005, Access is denied.

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x0000083c,(null),0,REG_BINARY,0000000003ABE360.72)0x80070005, Access is denied.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {bb406f53-d141-42a1-a143-e412829dcfd9}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000001d4,(null),0,REG_BINARY,0000000002E6F560.72)0x80070005, Access is denied.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {542da469-d3e1-473c-9f4f-7847f01fc64f}
   Writer Name: COM+ REGDB Writer
   Writer Instance ID: {5e24f548-b03d-48ae-84fc-f81c84cbb933}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x0000089c,(null),0,REG_BINARY,000000000743E4C0.72)0x80070005, Access is denied.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2}
   Writer Name: MSSearch Service Writer
   Writer Instance ID: {9e510401-0c92-41a9-aa72-ed09569f85cd}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000001c8,(null),0,REG_BINARY,000000000206EDE0.72)0x80070005, Access is denied.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {afbab4a2-367d-4d15-a586-71dbb18f8485}
   Writer Name: Registry Writer
   Writer Instance ID: {15de834e-f34b-4b32-aba8-cf5a765edc5d}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x00000208,(null),0,REG_BINARY,00000000018BEB40.72)0x80070005, Access is denied.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
   Writer Name: Shadow Copy Optimization Writer
   Writer Instance ID: {06ba761b-e0ca-46c0-86b7-0ac19f063e1d}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x0000083c,(null),0,REG_BINARY,0000000003ABE360.72)0x80070005, Access is denied.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {bb406f53-d141-42a1-a143-e412829dcfd9}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x0000089c,(null),0,REG_BINARY,000000000743E4C0.72)0x80070005, Access is denied.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2}
   Writer Name: MSSearch Service Writer
   Writer Instance ID: {9e510401-0c92-41a9-aa72-ed09569f85cd}

Error: (05/30/2015 08:28:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000001d4,(null),0,REG_BINARY,0000000002E6F560.72)0x80070005, Access is denied.


Operation:
   BackupShutdown Event

Context:
   Execution Context: Writer
   Writer Class Id: {542da469-d3e1-473c-9f4f-7847f01fc64f}
   Writer Name: COM+ REGDB Writer
   Writer Instance ID: {5e24f548-b03d-48ae-84fc-f81c84cbb933}


CodeIntegrity Errors:
===================================
  Date: 2015-02-28 09:43:42.919
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\jswpslwfx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-02-28 09:43:42.872
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\jswpslwfx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-02-28 09:39:17.147
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\jswpslwfx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-02-28 09:39:17.100
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\jswpslwfx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-02-28 09:31:17.225
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\jswpslwfx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-02-28 09:31:17.178
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\jswpslwfx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-02-27 12:49:08.305
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\jswpslwfx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-02-27 12:49:08.256
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\jswpslwfx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-02-27 12:36:13.116
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\jswpslwfx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-02-27 12:36:13.069
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\jswpslwfx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-2600K CPU @ 3.40GHz
Percentage of memory in use: 26%
Total physical RAM: 8173.2 MB
Available physical RAM: 5982.82 MB
Total Pagefile: 16344.61 MB
Available Pagefile: 14041.38 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:55.8 GB) (Free:9.33 GB) NTFS
Drive d: (New Volume) (Fixed) (Total:1863.01 GB) (Free:1630.16 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: EEE001EA)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 55.9 GB) (Disk ID: 3E3EA135)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=55.8 GB) - (Type=07 NTFS)

==================== End of log ============================

Hello sublux and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Your problem doesn’t lie with Firefox or IE, it is Chrome, as usual, that is the culprit but we can deal with it quite easily.

I suggest uninstalling/re-installing Chrome as it’s the most reliable way of getting rid of unwanted extensions.

Uninstall/Reinstall Google Chrome

First save all your bookmarks/favourites.


  • open Chrome, click on the 3 bars in the top right hand corner, select Bookmarks and then Bookmarks Manager
  • click on Organise and then select Export Bookmarks to HTML file, then choose Desktop to save it
  • again, click on the three bars in the top right hand corner and select Settings
  • in the list of Settings under “Sign in” click on Disconnect your Google Account
  • in the text of the next window click on “Google Dashboard” then, at the “Chrome sync” screen, click on Stop and Clear at the bottom
  • a box will open and ask for confirmation, click on OK (wait for this to complete before doing the next step)
  • when confirmation appears close that page and then click on Disconnect account
  • shut Google Chrome, click on Start > Control Panel > Programs and Features (or Add/Remove Programs in XP) and uninstall Google Chrome. Select Everything for removal if asked.

Reboot the system and then reinstall Google Chrome from here

Repeat the process to reinstate your bookmarks by going to Bookmarks > Bookmarks Manager > Organise and select Import Bookmarks.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

When you’ve done the above, please run FRST again and send the new log

Logs to include with next post:

AdwCleaner log
JRT.txt
Frst.txt


Can you tell me if that has dealt with the problem.

Thanks

Satchfan

 

Thanks for the quick response! I did everything in the order that you said except uninstalling/reinstalling chrome only because I did NOT have chrome installed to begin with. With regards to adware cleaner when I open it it is already selected to the services tab so thats what I left it on when I ran the scan. Attached are the documents you asked for and the problem still exists.

I did NOT have chrome installed to begin with

 

Apologies, I should have checked that. :oops:

The reason for assuming it is that there are remnants in your log that contain the problem.

You've run AdwCleaner before so that found nothing but JRT got rid of some nasties.

 

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below.

CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

How is it now?
 

 

I did that but the problem still exists. I tested it by going to pandora.com and clicking sign in and a new tab opens to a adcash.com but then is quickly redirected to alibaba.com to shop for some new handbags. I use to get multiple pop ups on pandora for some asian dating website and thats gone now so I think we are making progress! I have attached the fixlog like you asked.

Attachments:

They were removed once but Google Chrome is infamous for this kind of behaviour.

We’ll use another tool.

Run Zoek

Download zoek.exe to your Desktop:

Important : Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here.

 

  • on Windows Vista, 7, and 8, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    Iikflkcanblccfahdhdonehdalibjnif;chr
    emptyCHRcache;
    emptyalltemp;
    emptyclsid;
    autoclean;
    ipconfig /flushdns;b
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

Thanks

Satchfan

 

 

My wife had mentioned that the internet was being weird on the ipad this week but I didn't think anything of it because we live in Guam and the internet is ok at best. Last night she showed me what was happening and it was an adcash advertisement! I remember reading in another forum that sometimes routers can get infected so I figured I would hard reset the router just to see if maybe that was it. Sure enough after the reset I got on my pc and went to a couple sites that normally blow up with adcash popups and nothing happened. I went ahead and did the zoek because you were nice enough provide me with that resource so here is my log. I think I'm good over here but I will wait for your opinion.

I would say that we had possibly got rid of the worst and the reset helped but you still had the adware there as your log has shown, and could possibly have reared its ugly head again.

 

Zoek however did its job and has got rid of the bad extension that was the culprit.

 

I'm glad your computer is OK now but I would suggest running an online scan to see if there are any infections left that haven't shown up. It's your choice and if you decide not to bother, please let me know and I'll send instructions to tidy up the tools we've used.

 

Run ESET Online Scan

Note: This may take a long time so please be patient.

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use Internet Explorer, FireFox or  Chrome for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan

  • click the Eset online Scanner button
  • for alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


    o    click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
    o    double click on the Eset installer icon on your desktop.
     

  • check Yes, I accept the Terms of Use
  • click the Start button
  • accept any security warnings from your browser
  • check Enable detection of potentially unwanted applications
  • click Advanced settings and select the following:


    o    scan archives
    o    scan for potentially unsafe applications
    o    enable Anti-Stealth technology


    Note: Do not check Remove found threats
     

  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • when the scan completes, push List of found threats
  • push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.


    Note - if ESET doesn't find any threats, no report will be created.
     

  • push the back button.
  • push Finish

When the scan is complete:

If no threats were found:
 


o    put a checkmark in "Uninstall application on close"
o    close program
o    report to me that nothing was found.
 

If threats were found:


o    click on "list of threats found"
o    click on "export to text file" and save it as ESET results and save to the desktop
o    Click on back
o    put a checkmark in "Uninstall application on close"
o    click on finish
o    close program
o    copy and paste the report here.
 

Please reply one way or another so that I can mark this as “solved”.

Thanks

Satchfan

 

 

P2P

Those were installation files that we can get rid of but first….

I meant to address this before regarding FrostWire. We are not here to pass judgment on file-sharing as a concept but I will warn you that engaging in this activity will always make your computer very susceptible to infection and re-infection.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. Those who write malware use P2P file-sharing as a major vehicle to spread their wares.

Please see this topic for more information:

P2P File Sharing Risks.

I would strongly recommend that you uninstall FrostWire now. You can do so via Control Panel, Programs, and then Programs and Features.

===================================================

Please copy all text in the code box below and paste it into Notepad:
 

@echo off
del /f /s /q "C:\Users\Mitch\.frostwire5\updates\frostwire-setup.exe”
del /f /s /q “D:\Frost\frostwire-installer.exe”
del %0
  • save the Notepad file to your desktop and name it delfiles.bat
  • save type as "All Files"
  • on your desktop, double-click on delfiles.bat to run it, (a black CMD window will flash, then disappear - this is normal).

The files/folders, if found, will have been deleted and the "delfile.bat" file will also be deleted.

Can you tell me if you’re happy to tidy up.

Satchfan

 

Yea I think I will take your advice and remove frostwire. I honestly don't even remember the last time I used it lol. I ran the delfiles.bat so I think I am ready to tidy up!

Good move getting rid of Frostwire.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

Uninstall AdwCleaner

  • double click on adwcleaner.exe to run the tool
  • click on Uninstall
  • confirm with Yes.

===================================================

Download & run Delfix

  • download Delfix from here to remove many of the tools we've used during the cleaning process.
  • ensure “Remove disinfection tools” is checked.

Also place a checkmark next to:


o    Create registry backup
o    Purge system restore


  • click the Run button.

You can delete all other logs and programs we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Update installed programs

Your version of Java is out-of-date and need to be removed and updated.

Having the latest updates and removing old versions ensures there are no security vulnerabilities in your system.

To remove it:

  • click Start, Control Panel, Programs and Features.
  • click on Java 8 Update 40 and then on Uninstall:

NEXT

Install the latest version of Java:

Java

NOTE – when you install Java, before clicking on Install, be sure to Uncheck “Install the Ask Toolbar and make Ask my default search provider”

🖼Click to load external image (Java.gif)

Even though I just had you get the latest version of Java, there is a vulnerability with regards to Java and web browsers. Therefore, we recommend to disable java in web browsers.

More information can be found here.

===================================================

Recommended programs

SpywareBlaster. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them. It blocks over 11,000 bad sites and uses no resources of your computer.

======================

In your first post you mentioned having run Malwarebytes but there is no evidence of it on your computer.

Download Malwarebytes' Anti-Malware. This really is an excellent program that you should update and run on a regular basis, probably weekly.

======================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

======================

Download WOT

Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:


green if it's safe
yellow for caution
red for unsafe
 

You can download the WOT add-on for Firefox, Chrome, Internet Explorer, Opera, and Safari browsers. It does not slow down your browsing experience, it is easy to use and free. Just click “Download” and you are ready to go!

======================

MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

A couple of links with information here and here which can answer any questions you might have about installing/using it.

======================

Unchecky

Be careful when downloading free software. Many free programs come bundled with adware, many of which cause redirects/popups and verge on being malware. There is a program that automatically “unckecks” the boxes you may not notice when downloading programs.

Download and install Unchecky .

======================

Download and install CryptoPrevent

Crypto Ransomware Warning

There are particularly nasty “Ransomware” infections out there at the moment that encrypt your files and the only way possible to get them “de-crypted” is to pay a ransome. You can read more about this here.

  • download CryptoPrevent
  • save the file to your Desktop and then open the program by clicking Run when prompted from your browser or by going to the desktop where the file was saved and double-clicking.
  • accept all the defaults during the install. The last screen of the install has a checkmark in "Launch CryptoPrevent". This will launch the program once you click Finish
  • you will get a prompt asking if you purchased a Product Key for Automatic Updates. Click No
  • you will then be prompted to learn more about automatic updates or if you want to purchase a key. This is up to you but you don't have to
  • click OK to continue and select your protection level. Go ahead and click OK.
  • click the Apply button to set Default protection
  • you may get a message stating that Windows Sidebar and Desktop Gadgets are a major security vulnerability and asking you if you want to disable them. If you don't use these features, answer Yes.

You are now protected.

Note: The free version doesn't provide automatic updates but should be updated often, (at least weekly), as this infection has serious consequences. To update it manually, open the program, select the “Updates” menu then select Check for Updates to see if there are any available.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

Help! My computer is slow! by miekiemoes

Simple and easy ways to keep your computer safe and secure on the Internet  by Lawrence Abrams

I will keep this open for 24 hours in case you have any problems, after which I’ll close the topic.

Safe computing and enjoy Guam - it sounds lovely.

Satchfan

 

Thank you so much for all your help! Your knowledge, timely responses, and professionalism were greatly appreciated. I was starting to lose my mind before I found this forum! I just have a couple closing questions.

After you close this thread will I still be able to look at it so I can look at all the links you provided in your last reply?
Also, would you recommend purchasing malware bytes? I used it in the past and my trial license expired so I uninstalled it.

 

And Guam is a pretty cool place to visit at least once!

 

 

Thanks again,

 

-Sublux

Thank you so much for all your help!

 

You're welcome and thank you for your kind words.

 

After you close this thread will I still be able to look at it so I can look at all the links you provided in your last reply?

 

Yes; it will just be "locked" so that no more posts can be added, (you can always start a new topic if you need further help).
 

 

Also, would you recommend purchasing malware bytes?

 

The choice is yours. There are some added features in the paid version, (the free version is only an on-demand scanner and there is no real-time protection or scheduled scans/updates). However, I just use the free version but even if you had the trial version, it would have automatically reverted to the standard version once the trial was up.

 

If you don't want the trial, when you download it, remove the checkmark to activate the 14 day trial.

 

Guam is a pretty cool place to visit at least once

 

Oh that I had the time. It is also a long way from here, (UK), and I'm not happy flying that far these days - must be old age creeping in. :)

 

Take care

 

Satchfan

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI