This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Old windows has issues [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

S1 FILE

 

# AdwCleaner v4.206 - Logfile created 13/06/2015 at 20:09:50

# Updated 01/06/2015 by Xplode
# Database : 2015-05-31.5 [Local]
# Operating system : Microsoft Windows XP Service Pack 3 (x86)
# Username : Owner - PAPACOYOTE
# Running from : C:\Documents and Settings\Owner\Desktop\AdwCleaner.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v8.0.6001.18702
 
 
-\\ Mozilla Firefox v22.0 (en-US)
 
 
-\\ Google Chrome v43.0.2357.124
 
 
*************************
 
AdwCleaner[R0].txt - [12837 bytes] - [13/06/2015 16:34:34]
AdwCleaner[R1].txt - [22226 bytes] - [13/06/2015 16:37:29]
AdwCleaner[R2].txt - [980 bytes] - [13/06/2015 20:02:51]
AdwCleaner[R3].txt - [1038 bytes] - [13/06/2015 20:07:58]
AdwCleaner[S0].txt - [16154 bytes] - [13/06/2015 16:47:50]
AdwCleaner[S1].txt - [965 bytes] - [13/06/2015 20:09:50]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1023  bytes] ##########
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015
Ran by [removed] (administrator) on PAPACOYOTE on 13-06-2015 21:04:34
Running from C:\Documents and Settings\[removed]\Desktop
[removed]
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(SEIKO EPSON CORPORATION) C:\WINDOWS\system32\ENAgent.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
(Seiko Epson Corporation) C:\WINDOWS\system32\escsvc.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE
(LogMeIn, Inc.) C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
(LogMeIn, Inc.) C:\Program Files\LogMeIn\x86\ramaint.exe
(LogMeIn, Inc.) C:\Program Files\LogMeIn\x86\LogMeIn.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Hewlett-Packard Company) C:\WINDOWS\system\hpsysdrv.exe
(Hewlett-Packard) C:\WINDOWS\system32\hphmon05.exe
(Agere Systems) C:\WINDOWS\ltmsg.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\Alcxmntr.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Hewlett-Packard Company) C:\hp\KBD\kbd.exe
(Alcor Micro, Corp.) C:\Program Files\Multimedia Card Reader\shwicon2k.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Cisco Systems, Inc.) C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
(Linksys, LLC) C:\Program Files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\FAX Utility\FUFAXRCV.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\FAX Utility\FUFAXSTM.exe
(LogMeIn, Inc.) C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Arcsoft, Inc.) C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [hpsysdrv] => c:\windows\system\hpsysdrv.exe [52736 1998-05-07] (Hewlett-Packard Company)
HKLM\…\Run: [HPHUPD05] => c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe [49152 2003-08-21] (Hewlett-Packard)
HKLM\…\Run: [HPHmon05] => C:\WINDOWS\System32\hphmon05.exe [483328 2003-08-21] (Hewlett-Packard)
HKLM\…\Run: [Recguard] => C:\WINDOWS\SMINST\RECGUARD.EXE [221184 2003-11-03] ()
HKLM\…\Run: [VTTimer] => VTTimer.exe
HKLM\…\Run: [LTMSG] => LTMSG.exe 7
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [nwiz] => nwiz.exe /installquiet /keeploaded /nodetect
HKLM\…\Run: [AlcxMonitor] => C:\WINDOWS\ALCXMNTR.EXE [57344 2004-09-07] (Realtek Semiconductor Corp.)
HKLM\…\Run: [KBD] => C:\HP\KBD\KBD.EXE [61440 2005-02-02] (Hewlett-Packard Company)
HKLM\…\Run: [Sunkist2k] => C:\Program Files\Multimedia Card Reader\shwicon2k.exe [135168 2004-02-27] (Alcor Micro, Corp.)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\…\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM\…\Run: [nmctxth] => C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe [642856 2008-12-12] (Cisco Systems, Inc.)
HKLM\…\Run: [Linksys Wireless Manager] => C:\Program Files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe [1358384 2009-02-16] (Linksys, LLC)
HKLM\…\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1058400 2012-01-26] (SEIKO EPSON CORPORATION)
HKLM\…\Run: [FUFAXRCV] => C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe [502912 2012-02-29] (SEIKO EPSON CORPORATION)
HKLM\…\Run: [FUFAXSTM] => C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [863360 2012-02-29] (SEIKO EPSON CORPORATION)
HKLM\…\Run: [LogMeIn GUI] => C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [63048 2013-04-30] (LogMeIn, Inc.)
HKLM\…\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-06-20] (Microsoft Corporation)
HKLM\…\Run: [] => [X]
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxsrvc.dll [2003-11-18] (Intel Corporation)
Winlogon\Notify\LMIinit: C:\WINDOWS\system32\LMIinit.dll [2013-06-07] (LogMeIn, Inc.)
HKLM\…\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-1489619779-1396043273-266004695-1003\…\Run: [BackupNotify] => c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe [32768 2004-01-09] (Hewlett-Packard Company)
HKU\S-1-5-21-1489619779-1396043273-266004695-1003\…\Run: [Google Update] => C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [116648 2012-09-27] (Google Inc.)
HKU\S-1-5-18\…\Run: [DWQueuedReporting] => c:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [437160 2007-02-26] (Microsoft Corporation)
HKU\S-1-5-18\…\RunOnce: [RunNarrator] => C:\WINDOWS\system32\Narrator.exe [53760 2008-04-13] (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2004-01-20]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Media Card Companion Monitor.lnk [2012-02-28]
ShortcutTarget: Media Card Companion Monitor.lnk -> C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\AutoTBar.exe [2013-07-20] (Hewlett-Packard)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-1489619779-1396043273-266004695-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
HKU\S-1-5-21-1489619779-1396043273-266004695-1003\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
HKU\S-1-5-21-1489619779-1396043273-266004695-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={96211E0F-148F-4486-90A2-C700654052FA}∣=256174646cbd4596a312ebda400eb2e5-89315e00ac81f121d4ef749ca57c4981f0771d55⟨=en&ds;=or011≺=sa&d;=2013-07-1601:07:58&v;=15.3.0.11&pid;=safeguard&sg;=0&sap;=dsp&q;={searchTerms}
BHO: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files\Epson Software\E-Web Print\ewps_tb.dll [2013-02-28] (SEIKO EPSON CORPORATION)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-06-13] (Oracle Corporation)
BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO: CNavExtBho Class -> {BDF3E430-B101-42AD-A544-FADC6B084872} -> c:\Program Files\Norton AntiVirus\NavShExt.dll No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-13] (Oracle Corporation)
Toolbar: HKLM - HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll [2003-11-21] (Hewlett-Packard Company)
Toolbar: HKLM - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files\Epson Software\E-Web Print\ewps_tb.dll [2013-02-28] (SEIKO EPSON CORPORATION)
Toolbar: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll [2003-11-21] (Hewlett-Packard Company)
Toolbar: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll No File
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect118.cab
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll [2009-02-13] (Cisco Systems, Inc.)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.knoxnews.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-06-13] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll [2013-04-03] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2013-04-08] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-13] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-13] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.10.835 -> C:\Program Files\Real\RealOne Player\Netscape6\nppl3260.dll [2004-01-20] (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.2.1136 -> C:\Program Files\Real\RealOne Player\Netscape6\nprjplug.dll [2004-01-20] (RealNetworks)
FF Plugin: @real.com/nprpjplug;version=6.0.11.847 -> C:\Program Files\Real\RealOne Player\Netscape6\nprpjplug.dll [2004-01-20] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-13] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-13] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-08-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1489619779-1396043273-266004695-1003: @talk.google.com/GoogleTalkPlugin -> C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1489619779-1396043273-266004695-1003: @talk.google.com/O1DPlugin -> C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1489619779-1396043273-266004695-1003: @tools.google.com/Google Update;version=3 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-13] (Google Inc.)
FF Plugin HKU\S-1-5-21-1489619779-1396043273-266004695-1003: @tools.google.com/Google Update;version=9 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-13] (Google Inc.)
FF Plugin HKU\S-1-5-21-1489619779-1396043273-266004695-1003: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll [2013-05-11] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\Owner\Application Data\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\Owner\Application Data\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\searchplugins\startpage-http.xml [2013-08-10]
FF Extension: DoNotTrackMe - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\[removed] [2013-07-11]
FF Extension: Adblock Plus Pop-up Addon - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\[removed] [2012-03-01]
FF Extension: Element Hiding Helper for Adblock Plus - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\[removed] [2012-03-01]
FF Extension: Ghostery - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\[removed] [2013-08-03]
FF Extension: Online HD TV - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\[removed] [2012-10-24]
FF Extension: Adblock Plus - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-03-01]
FF Extension: BetterPrivacy - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2012-03-01]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-01-22]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Epson Software\E-Web Print\Firefox Add-on
FF Extension: E-Web Print - C:\Program Files\Epson Software\E-Web Print\Firefox Add-on [2013-08-02]
 
Chrome: 
=======
CHR Profile: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-13]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 ENAgent; C:\WINDOWS\system32\ENAgent.exe [4209856 2013-01-22] (SEIKO EPSON CORPORATION)
R2 EpsonCustomerParticipation; C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [539744 2012-05-10] (SEIKO EPSON CORPORATION)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation)
R2 EPSON_PM_RPCV4_05; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE [142432 2013-01-22] (SEIKO EPSON CORPORATION)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-06-20] (Microsoft Corporation)
S2 nmservice; C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [642856 2008-12-12] (Cisco Systems, Inc.)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 AFS2K; C:\WINDOWS\system32\Drivers\AFS2K.sys [35840 2004-10-07] (Oak Technology Inc.)
S3 ALCXSENS; C:\WINDOWS\System32\drivers\ALCXSENS.SYS [391424 2003-12-12] (Sensaura Ltd)
R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [2279424 2004-10-01] (Realtek Semiconductor Corp.)
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [35328 2003-11-07] (Advanced Micro Devices)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [37664 2013-08-14] (AVG Technologies)
R0 fasttx2k; C:\WINDOWS\System32\DRIVERS\fasttx2k.sys [142336 2003-12-02] (Promise Technology, Inc.)
R2 fssfltr; C:\WINDOWS\System32\DRIVERS\fssfltr_tdi.sys [54760 2010-04-28] (Microsoft Corporation)
R3 ltmodem5; C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys [652689 2003-12-12] (Agere Systems)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-13] (Malwarebytes Corporation)
R0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
R3 NVENET; C:\WINDOWS\System32\DRIVERS\NVENET.sys [54784 2003-04-22] (NVIDIA Corporation)
R0 nv_agp; C:\WINDOWS\System32\DRIVERS\nv_agp.sys [21120 2003-09-03] (NVIDIA Corporation)
R3 Pfc; C:\WINDOWS\System32\drivers\pfc.sys [10368 2003-09-19] (Padus, Inc.) [File not signed]
R2 pnarp; C:\WINDOWS\System32\DRIVERS\pnarp.sys [23984 2008-12-12] (Cisco Systems, Inc.)
R2 purendis; C:\WINDOWS\System32\DRIVERS\purendis.sys [25264 2008-12-12] (Cisco Systems, Inc.)
R0 PxHelp20; C:\WINDOWS\System32\DRIVERS\PxHelp20.sys [17168 2003-07-30] (Sonic Solutions) [File not signed]
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\R8139n51.SYS [46976 2002-10-04] (Realtek Semiconductor Corporation       )
S3 SiS315; C:\WINDOWS\System32\DRIVERS\sisgrp.sys [429440 2003-12-06] (Silicon Integrated Systems Corporation)
R1 SiSkp; C:\WINDOWS\System32\DRIVERS\srvkp.sys [11392 2003-12-05] (Silicon Integrated Systems Corporation)
R3 SunkFilt; C:\WINDOWS\System32\Drivers\sunkfilt.sys [39904 2004-03-22] (Alcor Micro Corp.) [File not signed]
S3 taphss; C:\WINDOWS\System32\DRIVERS\taphss.sys [33512 2013-02-12] (AnchorFree Inc)
R0 viaagp1; C:\WINDOWS\System32\DRIVERS\viaagp1.sys [27904 2003-07-02] (VIA Technologies, Inc.)
S3 viagfx; C:\WINDOWS\System32\DRIVERS\vtmini.sys [117760 2003-10-17] (Copyright (C) VIA/S3 Graphics, Inc.)
S3 WUSB54GCv3; C:\WINDOWS\System32\DRIVERS\WUSB54GCv3.sys [627072 2008-12-04] (Ralink Technology, Corp.)
S3 {6080A529-897E-4629-A488-ABA0C29B635E}; C:\WINDOWS\System32\drivers\ialmsbw.sys [122110 2003-11-20] (Intel Corporation)
S3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}; C:\WINDOWS\System32\drivers\ialmkchw.sys [99002 2003-11-20] (Intel Corporation)
S4 LMIRfsClientNP; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 Sunkfiltp; \??\C:\WINDOWS\System32\Drivers\sunkfiltp.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-13 17:26 - 2015-06-13 20:16 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-06-13 17:25 - 2015-06-13 17:25 - 00000788 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-13 17:25 - 2015-06-13 17:25 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-06-13 17:25 - 2015-06-13 17:25 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-13 17:25 - 2015-06-13 17:25 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2015-06-13 17:25 - 2015-04-14 09:37 - 00120024 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-06-13 17:25 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-06-13 17:07 - 2015-06-13 17:07 - 00000000 ____D C:\RegBackup
2015-06-13 16:34 - 2015-06-13 20:09 - 00000000 ____D C:\AdwCleaner
2015-06-13 16:33 - 2015-06-13 16:33 - 21546080 _____ (Malwarebytes Corporation ) C:\Documents and Settings\Owner\Desktop\mbam-setup-2.1.6.1022.exe
2015-06-13 16:32 - 2015-06-13 16:32 - 02943739 _____ (Thisisu) C:\Documents and Settings\Owner\Desktop\JRT.exe
2015-06-13 16:31 - 2015-06-13 16:31 - 02231296 _____ C:\Documents and Settings\Owner\Desktop\AdwCleaner.exe
2015-06-13 15:43 - 2015-06-13 15:43 - 00000000 ____D C:\Program Files\Common Files\Java
2015-06-13 15:42 - 2015-06-13 15:42 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Java
2015-06-13 15:42 - 2015-06-13 15:41 - 00146432 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2015-06-13 15:42 - 2015-06-13 15:41 - 00096352 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2015-06-13 15:26 - 2015-06-13 15:26 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Oracle
2015-06-13 14:41 - 2015-06-13 17:11 - 00003952 _____ C:\WINDOWS\KB2916036.log
2015-06-13 14:41 - 2015-06-13 17:11 - 00003905 _____ C:\WINDOWS\KB2868626.log
2015-06-13 14:41 - 2015-06-13 17:11 - 00003904 _____ C:\WINDOWS\KB2922229.log
2015-06-13 14:40 - 2015-06-13 17:10 - 00006759 _____ C:\WINDOWS\KB2847311.log
2015-06-13 14:39 - 2015-06-13 14:52 - 00003920 _____ C:\WINDOWS\KB2898715.log
2015-06-13 14:39 - 2015-06-13 14:51 - 00003920 _____ C:\WINDOWS\KB2929961.log
2015-06-13 14:38 - 2015-06-13 14:51 - 00003960 _____ C:\WINDOWS\KB2876217.log
2015-06-13 14:37 - 2015-06-13 14:51 - 00004436 _____ C:\WINDOWS\KB2930275.log
2015-06-13 14:36 - 2015-06-13 14:50 - 00003899 _____ C:\WINDOWS\KB2864063.log
2015-06-13 14:35 - 2015-06-13 14:49 - 00003915 _____ C:\WINDOWS\KB2862152.log
2015-06-13 14:35 - 2015-06-13 14:47 - 00003964 _____ C:\WINDOWS\KB2876331.log
2015-06-13 14:33 - 2015-06-13 14:41 - 00003897 _____ C:\WINDOWS\KB2893294.log
2015-06-13 14:32 - 2015-06-13 14:41 - 00003954 _____ C:\WINDOWS\KB2892075.log
2015-06-13 14:22 - 2015-06-13 14:23 - 00037732 _____ C:\Documents and Settings\Owner\Desktop\Addition.txt
2015-06-13 14:19 - 2015-06-13 21:05 - 00021900 _____ C:\Documents and Settings\Owner\Desktop\FRST.txt
2015-06-13 14:18 - 2015-06-13 21:04 - 00000000 ____D C:\FRST
2015-06-13 14:02 - 2015-06-13 14:16 - 00001862 _____ C:\Documents and Settings\Owner\Desktop\aswMBR.txt
2015-06-13 13:58 - 2015-06-13 11:08 - 01148416 _____ (Farbar) C:\Documents and Settings\Owner\Desktop\FRST.exe
2015-06-13 13:58 - 2014-11-14 04:16 - 05198336 _____ (AVAST Software) C:\Documents and Settings\Owner\Desktop\aswMBR.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-13 21:05 - 2004-01-20 21:19 - 00000000 ____D C:\Documents and Settings\Owner\Local Settings\Temp
2015-06-13 21:03 - 2013-01-21 23:38 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-06-13 20:43 - 2012-09-27 18:07 - 00000978 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1489619779-1396043273-266004695-1003UA.job
2015-06-13 20:34 - 2012-01-22 01:16 - 01395682 _____ C:\WINDOWS\WindowsUpdate.log
2015-06-13 20:29 - 2013-08-10 17:30 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-13 20:22 - 2013-08-20 15:10 - 00000384 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2015-06-13 20:13 - 2013-08-10 17:30 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-13 20:13 - 2012-01-22 00:37 - 00000186 _____ C:\WINDOWS\system\hpsysdrv.DAT
2015-06-13 20:13 - 2004-01-20 13:11 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-06-13 20:13 - 2004-01-20 13:11 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-06-13 20:12 - 2004-01-20 21:16 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-06-13 20:10 - 2004-01-20 21:19 - 00032558 _____ C:\WINDOWS\SchedLgU.Txt
2015-06-13 20:10 - 2004-01-20 21:19 - 00000278 ___SH C:\Documents and Settings\Owner\ntuser.ini
2015-06-13 20:10 - 2004-01-20 21:19 - 00000000 ____D C:\Documents and Settings\Owner
2015-06-13 19:44 - 2012-01-22 06:00 - 00000000 ____D C:\Documents and Settings\Owner\Application Data\Mozilla
2015-06-13 19:43 - 2012-09-27 18:07 - 00000926 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1489619779-1396043273-266004695-1003Core.job
2015-06-13 18:34 - 2012-01-22 02:32 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB979683$
2015-06-13 16:20 - 2012-07-22 11:57 - 00000000 ____D C:\Documents and Settings\Owner\My Documents\6-21-12 photos and stuff from HP
2015-06-13 15:41 - 2004-01-20 21:53 - 00000000 ____D C:\Program Files\Java
2015-06-13 15:13 - 2004-01-20 21:19 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Temp
2015-06-13 15:06 - 2012-01-22 06:10 - 00002347 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
2015-06-13 15:04 - 2012-01-22 06:09 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-06-13 14:10 - 2013-01-21 23:37 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-06-13 14:10 - 2013-01-21 23:37 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-06-13 12:01 - 2013-07-09 16:48 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\LogMeIn
2015-06-13 12:00 - 2004-01-20 20:04 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
 
==================== Files in the root of some directories =======
 
2013-07-16 01:07 - 2013-08-25 17:30 - 0003725 _____ () C:\Program Files\Mozilla Firefoxsafeguard-secure-search.xml
2012-07-09 14:54 - 2012-07-09 14:56 - 0005632 _____ () C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2004-01-21 00:04 - 2004-01-21 00:04 - 0000128 _____ () C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
2013-01-18 13:12 - 2013-01-18 13:12 - 0000218 _____ () C:\Documents and Settings\Owner\Local Settings\Application Data\recently-used.xbel
 
Some files in TEMP:
====================
C:\Documents and Settings\Owner\Local Settings\Temp\Miro_Installer.exe
C:\Documents and Settings\Owner\Local Settings\Temp\oi_{A7A1DE9E-C1B8-48CC-B7FC-8F9BAA18C94B}.exe
C:\Documents and Settings\Owner\Local Settings\Temp\QTInstallerHelper.dll
C:\Documents and Settings\Owner\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\Owner\Local Settings\Temp\SecurityScan_Release.exe
C:\Documents and Settings\Owner\Local Settings\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 

 

==================== End of log ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-06-2015
Ran by [removed] at 2015-06-13 21:06:35
Running from C:\Documents and Settings\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1489619779-1396043273-266004695-500 - Administrator - Enabled)
ASPNET (S-1-5-21-1489619779-1396043273-266004695-1007 - Limited - Enabled)
Guest (S-1-5-21-1489619779-1396043273-266004695-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-1489619779-1396043273-266004695-1006 - Limited - Disabled)
LogMeInRemoteUser (S-1-5-21-1489619779-1396043273-266004695-1009 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\LogMeInRemoteUser
Owner (S-1-5-21-1489619779-1396043273-266004695-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Owner
SUPPORT_388945a0 (S-1-5-21-1489619779-1396043273-266004695-1002 - Limited - Disabled)
SUPPORT_fddfa904 (S-1-5-21-1489619779-1396043273-266004695-1005 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
ABBYY FineReader 9.0 Sprint (HKLM\…\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY)
ABBYY FineReader 9.0 Sprint (Version: 9.01.513.58212 - ABBYY) Hidden
Adobe AIR (HKLM\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader X (10.1.11) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM\…\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.)
AiO_Scan (Version: 5.31.1.27 - Hewlett-Packard) Hidden
AIOMinimal (Version: 5.31.1.27 - Hewlett-Packard) Hidden
AiOSoftware (Version: 5.31.1.27 - Hewlett-Packard) Hidden
Amazon Kindle (HKLM\…\Amazon Kindle) (Version:  - Amazon)
Apple Application Support (HKLM\…\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{E14ADE0E-75F3-4A46-87E5-26692DD626EC}) (Version: 6.1.0.13 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft Media Card Companion (HKLM\…\{AC0C7D59-DE76-4AC0-9A84-A3B4D315CE11}) (Version:  - ArcSoft)
ArcSoft PhotoStudio 5.5 (HKLM\…\{85309D89-7BE9-4094-BB17-24999C6118FC}) (Version:  - ArcSoft)
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Bonjour Print Services (HKLM\…\{9D210D79-AEC5-453B-960C-4DD2C73931E1}) (Version: 2.0.2.0 - Apple Inc.)
CameraDrivers (Version: 3.1.0 - Hewlett-Packard) Hidden
Canon MP Navigator 2.0 (HKLM\…\MP Navigator 2.0) (Version:  - )
Canon MP500 (HKLM\…\{BA4DF4C3-196E-4128-969A-00996B5A46F8}) (Version:  - )
Canon Utilities Easy-PhotoPrint (HKLM\…\Easy-PhotoPrint) (Version:  - )
Cisco WebEx Meetings (HKLM\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Copy (Version: 5.35.0.065 - Hewlett-Packard) Hidden
CreativeProjects (Version: 5.35.0.059 - Hewlett-Packard) Hidden
Director (Version: 5.35.0.051 - Hewlett-Packard) Hidden
DocProc (Version: 3.5.0.0 - Hewlett-Packard) Hidden
Easy-WebPrint (HKLM\…\Easy-WebPrint) (Version:  - )
Enhanced Multimedia Keyboard Solution (HKLM\…\KBD) (Version:  - )
Epson Connect Printer Setup (HKLM\…\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.1.1 - SEIKO EPSON CORPORATION)
EPSON Connect version 1.0 (HKLM\…\EPSON Connect_is1) (Version: 1.0 - Epson America Inc.)
Epson Customer Participation (HKLM\…\{814FA673-A085-403C-9545-747FC1495069}) (Version: 1.4.0.0 - SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM\…\{44F72193-F59C-4303-BAE8-E3E4BC1C122C}) (Version: 3.01.0003 - Seiko Epson Corporation)
Epson E-Web Print (HKLM\…\{695C8469-7822-4B31-A673-5ED84815B649}) (Version: 1.17.0000 - SEIKO EPSON CORPORATION)
Epson FAX Utility (HKLM\…\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.30.00 - SEIKO EPSON CORPORATION)
Epson PC-FAX Driver (HKLM\…\EPSON PC-FAX Driver 2) (Version:  - )
EPSON Printer Finder (HKLM\…\{B8ECD0D3-AE08-4891-B6C7-32F96B75EB6C}) (Version: 1.0.0 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON WF-3520 Series Printer Uninstall (HKLM\…\EPSON WF-3520 Series) (Version:  - SEIKO EPSON Corporation)
EpsonNet Print (HKLM\…\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.5.00 - SEIKO EPSON CORPORATION)
Fax (Version: 5.31.1.27 - Hewlett-Packard) Hidden
Google Chrome (HKLM\…\Google Chrome) (Version: 43.0.2357.124 - Google Inc.)
Google Talk Plugin (HKLM\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (Version: 1.3.21.153 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.1.0.0 (Version: 1.00.0000 - Hewlett-Packard) Hidden
HP Deskjet Preloaded Printer Drivers (HKLM\…\{F419D20A-7719-4639-8E30-C073A040D878}) (Version: 8.3.3.0 - Hewlett-Packard Company)
HP Image Zone 3.5 (HKLM\…\HP Photo & Imaging) (Version: 3.5 - HP)
HP Image Zone Plus 3.5 (HKLM\…\{C6C44651-7C66-4b11-92E8-17565D3D22DD}) (Version: 3.5 - HP)
HP Instant Support (HKLM\…\HP Instant Support) (Version:  - )
HP Organize (HKLM\…\{D0122362-6333-4DE4-93F6-A5A2F3CC101A}) (Version:  - )
HP Photo & Imaging 3.5 - HP Devices (HKLM\…\{15B9DC72-73F9-4d99-9E28-848D66DA8D99}) (Version: 3.0 - HP)
HP Product Detection (HKLM\…\{A436F67F-687E-4736-BD2B-537121A804CF}) (Version: 11.14.0001 - HP)
HP PSC & OfficeJet 3.0 (HKLM\…\{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}) (Version: 3.0 - HP)
HP Update (HKLM\…\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard)
hpg2436 (Version: 3.5.0.0 - Hewlett-Packard) Hidden
hpg3970 (Version: 3.5.0.0 - Hewlett-Packard) Hidden
hpg4600 (Version: 3.5.0.0 - Hewlett-Packard) Hidden
hpg5530 (Version: 3.5.0.0 - Hewlett-Packard) Hidden
hpg8200 (Version: 3.5.0.0 - Hewlett-Packard) Hidden
HPIZ350 (Version: 35.1.2 - Hewlett-Packard) Hidden
hpmdtab (Version: 2.0.479.1607 - Hewlett-Packard) Hidden
HpSdpAppCoreApp (Version: 2.00.0000 - Hewlett-Packard) Hidden
HPSystemDiagnostics (Version: 1.5.0.0 - Your Company Name) Hidden
InstantShare (Version: 3.5.0.21 - Hewlett-Packard) Hidden
InstantShareAlert (Version: 1.00.0000 - HP) Hidden
IntelliMover Data Transfer Demo (HKLM\…\{14589F05-C658-4594-9429-D437BA688686}) (Version:  - )
InterActual Player (HKLM\…\InterActual Player) (Version:  - )
InterVideo WinDVD Creator 2 (HKLM\…\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}) (Version: 2.0.14.248 - InterVideo Inc.)
InterVideo WinDVD Player (HKLM\…\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}) (Version: 5.0-B11.896 - InterVideo Inc.)
iTunes (HKLM\…\{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}) (Version: 11.0.4.4 - Apple Inc.)
Java 8 Update 45 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Linksys Wireless Manager (HKLM\…\Linksys Wireless Manager) (Version: 4.9.9047.0 - Linksys, LLC)
LogMeIn (HKLM\…\{CB7AF84A-1B7F-4C6B-8A58-EB7CDE48C23A}) (Version: 4.1.3268 - LogMeIn, Inc.)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Memories Disc Creator 2.0 (HKLM\…\{2E132061-C78A-48D4-A899-1D13B9D189FA}) (Version: 2.0.481.1611 - Memories Disc Creator 2.0)
Microsoft .NET Framework 1.1 (HKLM\…\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\…\M2698023) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\…\M2833941) (Version:  - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Base Smart Card Cryptographic Service Provider Package (HKLM\…\KB909520) (Version:  - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\…\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM\…\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM\…\{95120000-0122-0409-0000-0000000FF1CE}) (Version: 12.0.6423.1000 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM\…\{91110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office Standard Edition 2003 (HKLM\…\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM\…\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Plus! Digital Media Edition (HKLM\…\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}) (Version: 1.1.0.2423 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM\…\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.3.215.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\…\Wudf01000) (Version:  - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\…\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Works 7.0 (HKLM\…\{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}) (Version: 07.02.0808 - Microsoft Corporation)
Miro (HKLM\…\Miro) (Version: 6.0 - Participatory Culture Foundation)
Mozilla Firefox 22.0 (x86 en-US) (HKLM\…\Mozilla Firefox 22.0 (x86 en-US)) (Version: 22.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 22.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Multimedia Card Reader (HKLM\…\InstallShield_{B662D841-AAA0-41E8-B2AB-E374560DC5B1}) (Version: 6.14 - )
Multimedia Card Reader (Version: 6.14 - ) Hidden
Nikon Message Center (HKLM\…\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}) (Version: 0.91.000 - )
NVIDIA Display Driver (HKLM\…\NVIDIA Display Driver) (Version:  - )
NVIDIA Ethernet Driver (HKLM\…\NVIDIA Ethernet Driver) (Version:  - )
NVIDIA GART Driver (HKLM\…\NVIDIA GART Driver) (Version:  - )
OmniPage SE 2.0 (HKLM\…\{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}) (Version: 2.00.0004 - ScanSoft, Inc.)
PC-Doctor for Windows (HKLM\…\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}) (Version:  - )
PhotoGallery (Version: 5.35.0.059 - Hewlett-Packard) Hidden
Photosmart 140,240,7200,7600,7700,7900 Series (HKLM\…\{45B6180B-DCAB-4093-8EE8-6164457517F0}) (Version: 2.0 - Hewlett-Packard)
PictureProject (HKLM\…\{FF3999BE-1A7B-4738-88AA-97BF14094A4A}) (Version: 1.0 - )
PictureProject In Touch Downloader 1.0 (HKLM\…\PictureProject In Touch Downloader) (Version: 1.0 - Fotonation Inc.)
PrintScreen (Version: 5.35.0.035 - Hewlett-Packard) Hidden
PS2 (HKLM\…\PS2) (Version:  - )
PSShortcutsP (Version: 1.00.0000 - Hewlett-Packard) Hidden
Pure Networks Platform (Version: 11.1.9044.0 - Pure Networks) Hidden
Python 2.2 combined Win32 extensions (HKLM\…\Python 2.2 combined Win32 extensions) (Version:  - )
Python 2.2.1 (HKLM\…\Python 2.2.1) (Version: 2.2.1 - PythonLabs at Zope Corporation)
QFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
QuickProjects (Version: 5.35.0.047 - Hewlett-Packard) Hidden
QuickTime (HKLM\…\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
Readme (Version: 5.31.1.27 - Hewlett-Packard) Hidden
RealOne Player (HKLM\…\RealPlayer 6.0) (Version:  - )
Realtek AC'97 Audio (HKLM\…\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version:  - )
RecordNow! (HKLM\…\{9541FED0-327F-4DF0-8B96-EF57EF622F19}) (Version: 6.5.1 - Hewlett-Packard)
Scan (Version: 3.5.0.0 - Hewlett-Packard) Hidden
Segoe UI (Version: 14.0.4327.805 - Microsoft Corp) Hidden
SkinsHP1 (Version: 5.35.0.043 - Hewlett-Packard) Hidden
SkinsHP2 (Version: 5.35.0.043 - Hewlett-Packard) Hidden
Software Updater (HKLM\…\{A737E18A-5171-40D0-8034-7DD243420081}) (Version: 4.1.1 - SEIKO EPSON CORPORATION)
Sonic Update Manager (HKLM\…\{09DA4F91-2A09-4232-AB8C-6BC740096DE3}) (Version: 2.9 - Sonic Solutions)
SpamSubtract (HKLM\…\SpamSubtract) (Version:  - interMute, Inc.)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Toolkit View(HP) (HKLM\…\HPTOOLKIT) (Version:  - )
TrayApp (Version: 5.35.0.035 - Hewlett-Packard) Hidden
Unity Web Player (HKU\S-1-5-21-1489619779-1396043273-266004695-1003\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Unload (Version: 3.5.0 - Hewlett-Packard) Hidden
Updates from HP (HKLM\…\BackWeb-137903 Uninstaller) (Version:  - )
WebFldrs XP (Version: 9.50.6513 - Microsoft Corporation) Hidden
WebReg (Version: 5.31.0.147 - Hewlett-Packard) Hidden
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray (HKLM\…\KB952011) (Version: 1.0 - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\KB892130) (Version:  - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Live Essentials (HKLM\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Management Framework Core (HKLM\…\KB968930) (Version:  - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\…\Windows Media Format Runtime) (Version:  - )
Windows Media Player 11 (HKLM\…\Windows Media Player) (Version:  - )
Windows Search 4.0 (HKLM\…\KB940157) (Version: 04.00.6001.503 - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.135\psuser.dll  (the data entry has 7 more characters).
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{047466F1-82AE-455A-AFC4-D3AC463FBF6B}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.27.5\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.27.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.27.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{39125640-8D80-11DC-A2FE-C5C455D89593}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.27.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.145\psuser.dll  (the data entry has 7 more characters).
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.123\psuser.dll  (the data entry has 7 more characters).
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.153\psuser.dll  (the data entry has 7 more characters).
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.149\psuser.dll  (the data entry has 7 more characters).
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{97090E2F-3062-4459-855B-014F0D3CDBB1}\InprocServer32 -> C:\Program Files\Windows Desktop Search\deskbar.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{AB9F4455-E591-4132-A386-0B91EAEDB96C}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\o1dax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.27.5\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.27.5\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.27.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.27.5\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.111\psuser.dll  (the data entry has 7 more characters).
 
==================== Restore Points =========================
 
13-06-2015 14:47:41 Software Distribution Service 3.0
13-06-2015 15:10:59 Software Distribution Service 3.0
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2004-01-20 20:04 - 2013-07-11 22:46 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1       localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1489619779-1396043273-266004695-1003Core.job => C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1489619779-1396043273-266004695-1003UA.job => C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2011-09-27 07:23 - 2011-09-27 07:23 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2011-09-27 07:22 - 2011-09-27 07:22 - 01242472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2003-10-15 14:03 - 2003-10-15 14:03 - 00163840 _____ () c:\Program Files\HP\Digital Imaging\bin\HpqUtil.dll
2012-02-28 11:17 - 2003-10-21 17:45 - 00442368 _____ () C:\Program Files\ArcSoft\Media Card Companion\fpxlib.dll
2012-02-28 11:17 - 2004-09-22 13:02 - 00053248 _____ () C:\Program Files\ArcSoft\Media Card Companion\ustor.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UploadMgr => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1489619779-1396043273-266004695-1003\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk => C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk => C:\WINDOWS\pss\Windows Search.lnkCommon Startup
MSCONFIG\startupfolder: C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Organize.lnk => C:\WINDOWS\pss\Organize.lnkStartup
MSCONFIG\startupfolder: C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk => C:\WINDOWS\pss\spamsubtract.lnkStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Google Update => "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: MSMSGS => "C:\Program Files\Messenger\msmsgs.exe" /background
MSCONFIG\startupreg: OpwareSE2 => "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RecordNow! => 
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: TkBellExe => "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
MSCONFIG\startupreg: UpdateManager => "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
DomainProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe] => Enabled:Windows Live Sync
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Owner\Local Settings\Temp\7zS6.tmp\SymNRT.exe] => Disabled:Norton Removal Tool
StandardProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe] => Enabled:Windows Live Sync
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe] => Enabled:Google Talk Plugin
StandardProfile\AuthorizedApplications: [C:\Program Files\Participatory Culture Foundation\Miro\Miro_Downloader.exe] => Enabled:Miro_Downloader
StandardProfile\AuthorizedApplications: [C:\Program Files\Participatory Culture Foundation\Miro\Miro.exe] => Enabled:Miro
StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service
StandardProfile\AuthorizedApplications: [E:\Common\EpsonNet Setup\ENEasyApp.exe] => Enabled:EpsonNet Setup
StandardProfile\AuthorizedApplications: [C:\Program Files\EPSON Software\Event Manager\EEventManager.exe] => Enabled:EEventManager Application
StandardProfile\AuthorizedApplications: [C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe] => Enabled:Epson Connect Printer Setup
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe] => Enabled:WebKit
StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:Google Chrome
StandardProfile\GloballyOpenPorts: [5985:TCP] => Disabled:Windows Remote Management 
StandardProfile\GloballyOpenPorts: [80:TCP] => Disabled:Windows Remote Management - Compatibility Mode (HTTP-In) 
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/13/2015 08:14:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application nmsrvc.exe, version 11.0.8268.0, faulting module nmcore.dll, version 11.1.9044.0, fault address 0x001d3d50.
Processing media-specific event for [nmsrvc.exe!ws!]
 
Error: (06/13/2015 06:37:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application nmsrvc.exe, version 11.0.8268.0, faulting module nmcore.dll, version 11.1.9044.0, fault address 0x001d3d50.
Processing media-specific event for [nmsrvc.exe!ws!]
 
Error: (06/13/2015 06:37:15 PM) (Source: MPSampleSubmission) (EventID: 5000) (User: )
Description: EventType mptelemetry, P1 2152759308, P2 unspecified, P3 scanfile, P4 4.3.215.0, P5 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P6 unspecified, P7 unspecified, P8 NIL, P9 mptelemetry0, P10 mptelemetry1.
 
Error: (06/13/2015 04:53:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application nmsrvc.exe, version 11.0.8268.0, faulting module nmcore.dll, version 11.1.9044.0, fault address 0x001d3d50.
Processing media-specific event for [nmsrvc.exe!ws!]
 
Error: (06/13/2015 03:29:42 PM) (Source: MsiInstaller) (EventID: 11722) (User: PAPACOYOTE)
Description: Product: Java 8 Update 45 – Error 1722. There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor. Action installexe, location: C:\Program Files\Java\jre1.8.0_45\installer.exe, command: /s INSTALLDIR="C:\Program Files\Java\jre1.8.0_45\\" REPAIRMODE=0
 
Error: (06/13/2015 02:54:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application nmsrvc.exe, version 11.0.8268.0, faulting module nmcore.dll, version 11.1.9044.0, fault address 0x001d3d50.
Processing media-specific event for [nmsrvc.exe!ws!]
 
Error: (06/13/2015 01:55:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application nmsrvc.exe, version 11.0.8268.0, faulting module nmcore.dll, version 11.1.9044.0, fault address 0x001d3d50.
Processing media-specific event for [nmsrvc.exe!ws!]
 
Error: (06/13/2015 00:04:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application nmsrvc.exe, version 11.0.8268.0, faulting module nmcore.dll, version 11.1.9044.0, fault address 0x001d3d50.
Processing media-specific event for [nmsrvc.exe!ws!]
 
Error: (06/13/2015 00:03:42 PM) (Source: crypt32) (EventID: 11) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
 
Error: (06/13/2015 00:03:41 PM) (Source: crypt32) (EventID: 11) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
 
 
System errors:
=============
Error: (06/13/2015 08:39:24 PM) (Source: 0) (EventID: 7) (User: )
Description: \Device\Harddisk0\D
 
Error: (06/13/2015 08:20:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Pure Networks Platform Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (06/13/2015 08:15:36 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Pure Networks Platform Service service hung on starting.
 
Error: (06/13/2015 08:09:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Application Layer Gateway Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (06/13/2015 08:09:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (06/13/2015 08:09:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NVIDIA Display Driver Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (06/13/2015 08:09:48 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The MBAMService service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (06/13/2015 08:09:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The LogMeIn Maintenance Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (06/13/2015 08:09:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The MBAMScheduler service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (06/13/2015 08:09:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The EPSON V3 Service4(05) service terminated unexpectedly.  It has done this 1 time(s).
 
 
Microsoft Office:
=========================
Error: (06/13/2015 08:14:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nmsrvc.exe11.0.8268.0nmcore.dll11.1.9044.0001d3d50
 
Error: (06/13/2015 06:37:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nmsrvc.exe11.0.8268.0nmcore.dll11.1.9044.0001d3d50
 
Error: (06/13/2015 06:37:15 PM) (Source: MPSampleSubmission) (EventID: 5000) (User: )
Description: mptelemetry2152759308unspecifiedscanfile4.3.215.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)unspecifiedunspecifiedNILNILNIL
 
Error: (06/13/2015 04:53:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nmsrvc.exe11.0.8268.0nmcore.dll11.1.9044.0001d3d50
 
Error: (06/13/2015 03:29:42 PM) (Source: MsiInstaller) (EventID: 11722) (User: PAPACOYOTE)
Description: Product: Java 8 Update 45 – Error 1722. There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor. Action installexe, location: C:\Program Files\Java\jre1.8.0_45\installer.exe, command: /s INSTALLDIR="C:\Program Files\Java\jre1.8.0_45\\" REPAIRMODE=0 (NULL)(NULL)(NULL)
 
Error: (06/13/2015 02:54:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nmsrvc.exe11.0.8268.0nmcore.dll11.1.9044.0001d3d50
 
Error: (06/13/2015 01:55:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nmsrvc.exe11.0.8268.0nmcore.dll11.1.9044.0001d3d50
 
Error: (06/13/2015 00:04:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nmsrvc.exe11.0.8268.0nmcore.dll11.1.9044.0001d3d50
 
Error: (06/13/2015 00:03:42 PM) (Source: crypt32) (EventID: 11) (User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabArequired certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
 
Error: (06/13/2015 00:03:41 PM) (Source: crypt32) (EventID: 11) (User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabArequired certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ 64 Processor 3200+
Percentage of memory in use: 52%
Total physical RAM: 1023.3 MB
Available physical RAM: 485.75 MB
Total Pagefile: 1692.91 MB
Available Pagefile: 971.93 MB
Total Virtual: 2047.88 MB
Available Virtual: 1937.47 MB
 
==================== Drives ================================
 
Drive c: (HP_PAVILION) (Fixed) (Total:182.1 GB) (Free:139.09 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: (HP_RECOVERY) (Fixed) (Total:4.19 GB) (Free:0.61 GB) FAT32 ==>[Drive with boot components (Windows XP)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 186.3 GB) (Disk ID: F806F806)
Partition 1: (Not Active) - (Size=4.2 GB) - (Type=0B)
Partition 2: (Active) - (Size=182.1 GB) - (Type=07 NTFS)
 
==================== End of log ============================

i ran MBAM again and this time it had no infections to detect. I was going to save the file after the finish part, unlike I did last time, but this time  MBAM went right back to the scan page. 

 

Let me know what to do next and I will give it a go. 

As long as Malwarebytes came back clean then your fine, no need to see the log

 

 

Open notepad (Start –> All Programs –> Accessories –> Notepad).
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file FIXLIST, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . After you download it, open up FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
Start
CloseProcesses:
CreateRestorePoint: 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg….sa&d=2013-07-1601:07:58&v=15.3.0.11&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
C:\Documents and Settings\Owner\Local Settings\Temp\Miro_Installer.exe
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Sorry for the DUH moment/stupid question. Just been a while since I have been on a windows computer. I figured it out on my own but needed a moment to swallow my pride and get my ego out of the way to admit…

 

 

seems to be rebooting just a bit faster, though still slow due to being old. 

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 13-06-2015

Ran by [removed] at 2015-06-13 22:45:10 Run:1
Running from C:\Documents and Settings\[removed]\Desktop
[removed]
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint: 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg….sa&d=2013-07-1601:07:58&v=15.3.0.11&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
C:\Documents and Settings\Owner\Local Settings\Temp\Miro_Installer.exe
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
"HKU\S-1-5-21-1489619779-1396043273-266004695-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}" => key removed successfully.
HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => key not found. 
C:\Documents and Settings\Owner\Local Settings\Temp\Miro_Installer.exe => moved successfully.
 
=========  ipconfig /flushdns =========
 
Windows IP ConfigurationSuccessfully flushed the DNS Resolver Cache.
========= End of CMD: =========
 
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 3.3 GB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 22:48:18 ====

As for the Pure Networks Network Magic Service:

 

​I was able to rid the problem by searching the problem. I found a MS page on it and found people saying that the issue was not fixed by doing there work around. 

I got to thinking about it and found 1 cisco and 1 linksys in my add remove page. I feel it was the Linksys as that had to do with wireless tech. I am hard wired right now and since I upgraded my router to a new AC I no longer use my linksys USB wireless g. Once I removed the two programs that seems to have fixed the problem on reboot.

 

As for how things are going. Well, it is s  l  oooooooo  w. I think that has a lot to do with deleting 3.3 gig of temp files. I believe it will speed up as it is used and the temp files grow again. I am working on doing updates to things I can think of that you all used to recommend and deleting things I no longer need on the computer to free up space. 

 

​I know the system is archaic but it will work for children's programs and school work and basic email and news reading. I think we are good for now unless there is anything else you would like me to check. Let me know about the ATF cleaner. I am using MS security essentials for antivirus, would you make recommendations for free software? 

and should I delete all you had me put on the computer?

Great, looks like your right on top of it.  As far as ATF Cleaner, a few years back during the windows 98 and into the beginning of XP days, the prevalent infection at the time was Vundo, Atribune the author of ATF cleaner also wrote some wonderful programs to remove Vundo, but he has moved on to other things in his carrier so even though the tool is still available there is no more support for it. Out of the 100s of times I have used it on the forums and some friends computers I had two instances of it causing problems. If you use it you may want to create a restore point prior to running it, also I found it better to run was to click each module one at time to clean in lieu of selecting all.  You can also run CLEANMGR which is built into your system

https://support.microsoft.com/en-us/kb/315246

 

I have both a desktop and laptop and have Microsoft Security Essentials and I am pretty happy with it. Thinking though that since XP is no longer supported you may need something a bit stronger, heard good things about the free version of BitDefender

http://www.bitdefender.com/solutions/free.html

 

You may also want to think about upgrading Malwarebytes to the Pro Version, it has a Protection Module , if you wander into a bad site by accident Malwarebytes will block access to that site with a pop warning, the cost is minimal but this is totally up to you

 

 

Double click on AdwCleaner.exe to run the tool again.
  •  
  • Click on the Uninstall button.
  • Click Yes when asked are you sure you want to uninstall.
  • Both AdwCleaner.exe, its folder and all logs will be removed.
 
 
 
==========================================================
 
 
Please download DelFix and save the file to your Desktop.
 
[external image: DelFix_zps139e2ea1.jpg]
 
  •  
  • Windows XP Double Click DelFix.exe to run the program. 
  • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
  • Checkmark " Remove Disinfection Tools"
  • Click the Run button
 
 
This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
 
 
 
==========================================================
 
 
 
  •  
How did I get infected in the first place ?
 
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports
 
 
 
Safe Surfn
Ken

 

YEAH! Thanks Ken. In under 24 hours we went from crazy what to do to a running computer. Thanks a bunch. I had an hour long or better update process from all the files that ended updating from shut down last night. I have done all you stated and am installing bit defender now. MS security essentials is uninstalling. I already have requests to go onto ABCmouse dot com!

 

I think we are good to go. Need to start a new computer fund now. Oh well…

 

Thanks again I believe this issue has been resolved and thread can be closed.  :banana:

after having installed bitdefender things seem to be locking up. Doing a series of reboots. will keep you informed. Hope it is just an age related issue. Let you know in a bit  :wall:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI