First two logs:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-07-2015
Ran by [removed] (administrator) on PETE-05F6D62355 (25-07-2015 11:43:47)
Running from C:\Documents and Settings\[removed]\Desktop
[removed]
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\pg_ctl.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
() C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe
(Dropbox, Inc.) C:\Documents and Settings\Dad\Application Data\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [TkBellExe] => C:\program files\real\realplayer\update\realsched.exe [295512 2013-09-04] (RealNetworks, Inc.)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-04-07] (Apple Inc.)
HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [30878816 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\Run: [CPN Notifier] => C:\Program Files\Juicy Stakes 2.0\PokerNotifier.exe
HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\Run: [Dropbox Update] => C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\DropboxUpdate.exe [134512 2015-07-24] (Dropbox, Inc.)
HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\Run: [DellSystemDetect] => C:\Documents and Settings\Dad\Local Settings\Apps\2.0\WQRE5RQW.GQX\MEOK2BTQ.M23\dell..tion_e30b47f5d4a30e9e_0005.000c_1df9a4898fae00de\DellSystemDetect.exe [264488 2014-11-15] (Dell)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WNDA3100v2 Genie.lnk [2014-11-14]
ShortcutTarget: NETGEAR WNDA3100v2 Genie.lnk -> C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe ()
Startup: C:\Documents and Settings\Caitlin.PETE-05F6D62355\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2011-11-23]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\Dad\Start Menu\Programs\Startup\Dropbox.lnk [2015-04-25]
ShortcutTarget: Dropbox.lnk -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Documents and Settings\Dad\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2011-03-21]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
BootExecute: autocheck autochk * sprestrt
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?ocid=OIE8HP&PC;=B8DF
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE8HP&PC;=B8DF
HKU\S-1-5-21-1844237615-515967899-725345543-1005\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
HKU\S-1-5-21-1844237615-515967899-725345543-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE8HP&PC;=B8DF
URLSearchHook: [S-1-5-21-1844237615-515967899-725345543-1006] ATTENTION ==> Default URLSearchHook is missing.
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.5.0_16\bin\ssv.dll [2008-05-28] (Sun Microsystems, Inc.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.5.0_16\bin\jp2ssv.dll No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{11877365-053F-4884-B042-84371189536B}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{766B7B5B-9266-46F2-8FC2-DFD346ECFEF4}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{B4DB4529-26B2-4B92-9EB9-D8F3F46C8702}: [DhcpNameServer] [removed] [removed]
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\ndwc8g77.default-1413647459921
FF DefaultSearchUrl:
FF SelectedSearchEngine: Yahoo
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-24] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1217157.dll [2015-02-16] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll [2013-09-04] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.1.13 -> C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2011-12-18] (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.5.109 -> C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-07-01] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll [2013-09-04] (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-03-21]
FF HKLM\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-06-05]
FF HKLM\…\Firefox\Extensions: [{C3949AC2-4B17-43ee-B4F1-D26B9D42404D}] - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKLM\…\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-04]
FF Extension: No Name - C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\ndwc8g77.default-1413647459921\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [not found]
Chrome:
=======
CHR Profile: C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bojhhinnlgdmcajekighmiiehpofkodp [2015-07-24]
CHR Extension: (No Name) - C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-07-24]
CHR Extension: (No Name) - C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-24]
CHR Extension: (No Name) - C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24]
CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 FlipShare Service; C:\Program Files\Flip Video\FlipShare\FlipShareService.exe [451904 2009-06-04] ()
S2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 postgresql-8.4; C:\Program Files\PostgreSQL\8.4\bin\pg_ctl.exe [66048 2009-09-08] (PostgreSQL Global Development Group) [File not signed]
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 WSWNDA3100v2; C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe [307928 2013-11-11] ()
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 BCMH43XX; C:\WINDOWS\System32\DRIVERS\bcmwlhigh5.sys [1034240 2011-03-28] (Broadcom Corporation)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S0 cercsr6; C:\WINDOWS\system32\Drivers\cercsr6.sys [39904 2004-12-13] (Adaptec, Inc.) [File not signed]
S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2005-01-07] (Windows (R) Server 2003 DDK provider)
S3 ManyCam; C:\WINDOWS\System32\DRIVERS\mcvidrv.sys [47728 2014-07-28] (Visicom Media Inc.)
R2 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [54360 2014-11-21] (Malwarebytes Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
S3 mcaudrv_simple; C:\WINDOWS\System32\drivers\mcaudrv.sys [29936 2014-05-13] (Visicom Media Inc.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S3 NPF; C:\WINDOWS\System32\DRIVERS\npf.sys [50704 2010-02-03] (CACE Technologies, Inc.)
R1 OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [10368 2001-05-14] (Dell Computer Corporation) [File not signed]
R3 SenFiltService; C:\WINDOWS\System32\drivers\Senfilt.sys [392960 2006-03-17] (Sensaura)
R3 vsc32; C:\WINDOWS\System32\DRIVERS\vsc.sys [951284 2001-04-16] (Roland) [File not signed]
S3 wlags51b; C:\WINDOWS\System32\DRIVERS\wlags51b.sys [177664 2002-04-30] (Agere Systems)
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
U1 WS2IFSL; No ImagePath
S2 zumbus; system32\DRIVERS\zumbus.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-25 11:43 - 2015-07-25 11:44 - 00016438 _____ C:\Documents and Settings\Dad\Desktop\FRST.txt
2015-07-25 11:42 - 2015-07-25 11:42 - 01650688 _____ (Farbar) C:\Documents and Settings\Dad\Desktop\FRST.exe
2015-07-25 11:36 - 2015-07-25 11:41 - 00126821 _____ C:\WINDOWS\system32\DB284806105
2015-07-24 16:20 - 2015-07-24 16:20 - 00000724 _____ C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
2015-07-24 15:56 - 2015-07-24 15:56 - 00000917 _____ C:\Documents and Settings\Dad\Desktop\Revo Uninstaller.lnk
2015-07-24 15:55 - 2015-07-24 15:55 - 02623656 _____ (VS Revo Group Ltd.) C:\Documents and Settings\Dad\Desktop\revosetup.exe
2015-07-24 14:12 - 2015-07-24 15:12 - 18524336 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2015-07-24 14:00 - 2015-07-24 14:00 - 00000000 ____D C:\Documents and Settings\Dad\Start Menu\Programs\Dropbox
2015-07-24 13:58 - 2015-07-24 13:58 - 00000000 ____D C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox
2015-07-24 13:57 - 2015-07-24 14:16 - 00000000 ____D C:\Documents and Settings\Dad\Desktop\Misc Desktop Files
2015-07-24 13:51 - 2015-07-24 16:20 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-07-24 13:47 - 2015-07-24 13:48 - 00000000 ____D C:\Documents and Settings\Dad\Start Menu\Programs\Dell
2015-07-24 13:46 - 2015-07-24 16:03 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-24 13:46 - 2015-07-24 13:49 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-07-24 13:41 - 2015-07-24 15:56 - 00000000 ____D C:\Program Files\VS Revo Group
2015-07-24 13:40 - 2015-07-24 13:40 - 00000000 ____D C:\Documents and Settings\Dad\Application Data\DriverFinder
2015-07-24 13:40 - 2015-07-24 13:40 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Coupons
2015-07-24 13:40 - 2015-07-24 13:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\EmailNotifier
2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ___HD C:\WINDOWS\msdownld.tmp
2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ___HD C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ____D C:\WINDOWS\XSxS
2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy
2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ____D C:\Documents and Settings\Dad\WINDOWS
2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TEMP
2015-07-23 10:58 - 2015-07-23 21:25 - 00022538 _____ C:\WINDOWS\bitssetup.log
2015-07-23 10:57 - 2015-07-23 21:17 - 00001670 _____ C:\WINDOWS\Windows Update.log
2015-07-23 10:45 - 2015-07-23 10:45 - 00000000 ____D C:\RegBackup
2015-07-23 10:45 - 2015-07-23 10:45 - 00000000 ____D C:\Program Files\Tweaking.com
2015-07-22 11:15 - 2015-07-24 13:36 - 00000000 ____D C:\Documents and Settings\Dad\Start Menu\Programs\Dropbox(3)
2015-07-22 11:13 - 2015-07-25 11:08 - 00000980 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1844237615-515967899-725345543-1005UA.job
2015-07-22 11:13 - 2015-07-24 14:08 - 00000928 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1844237615-515967899-725345543-1005Core.job
2015-07-21 14:05 - 2015-07-24 13:37 - 00000000 __SHD C:\RECYCLER(2)
2015-07-21 13:58 - 2015-07-24 13:37 - 00000000 ____D C:\ComboFix(2)
2015-07-19 10:17 - 2015-07-25 11:44 - 00000000 ____D C:\Documents and Settings\Dad\Local Settings\temp
2015-07-19 10:17 - 2015-07-19 22:00 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\temp
2015-07-19 10:17 - 2015-07-19 10:17 - 00017636 _____ C:\ComboFix.txt
2015-07-19 10:17 - 2015-07-19 10:17 - 00000000 ____D C:\Documents and Settings\postgres.PETE-05F6D62355\Local Settings\temp
2015-07-19 10:17 - 2015-07-19 10:17 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\temp
2015-07-19 10:17 - 2015-07-19 10:17 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\temp
2015-07-19 10:17 - 2015-07-19 10:17 - 00000000 ____D C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\temp
2015-07-19 10:17 - 2015-07-19 10:17 - 00000000 ____D C:\Documents and Settings\Administrator.PETE-05F6D62355\Local Settings\temp
2015-07-18 19:18 - 2015-07-18 19:18 - 00008192 ____H C:\WINDOWS\system32\config\security.tmp.LOG
2015-07-18 19:18 - 2015-07-18 19:18 - 00000000 ____H C:\WINDOWS\system32\config\system.tmp.LOG
2015-07-18 19:18 - 2015-07-18 19:18 - 00000000 ____H C:\WINDOWS\system32\config\software.tmp.LOG
2015-07-18 19:18 - 2015-07-18 19:18 - 00000000 ____H C:\WINDOWS\system32\config\sam.tmp.LOG
2015-07-18 19:18 - 2015-07-18 19:18 - 00000000 ____H C:\WINDOWS\system32\config\default.tmp.LOG
2015-07-18 18:49 - 2015-07-24 13:37 - 00000000 ____D C:\cmdcons
2015-07-18 18:49 - 2014-10-14 16:37 - 00000245 _____ C:\Boot.bak
2015-07-18 18:49 - 2004-08-03 23:00 - 00260272 __RSH C:\cmldr
2015-07-17 18:46 - 2015-07-24 13:37 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2015-07-17 14:04 - 2015-07-24 13:37 - 00000000 ____D C:\WINDOWS\erdnt
2015-07-17 14:04 - 2015-07-24 13:37 - 00000000 ____D C:\Qoobox
2015-07-16 21:36 - 2015-07-16 21:36 - 00065536 _____ C:\WINDOWS\Minidump\Mini071615-01.dmp
2015-07-16 15:33 - 2015-07-16 15:33 - 00000000 ____D C:\Program Files\VS Revo Group(2)
2015-07-15 05:35 - 2015-07-24 13:40 - 00000000 ____D C:\Documents and Settings\Dad\Desktop\New Folder
2015-07-14 20:51 - 2015-07-21 18:03 - 00000384 _____ C:\runcheck.txt
2015-07-11 22:26 - 2015-07-11 22:26 - 00065536 _____ C:\WINDOWS\Minidump\Mini071115-01.dmp
2015-07-10 12:40 - 2015-07-10 12:40 - 00000000 ____D C:\Program Files\360
2015-07-09 22:28 - 2015-07-24 13:42 - 00000000 ____D C:\Program Files\Mozilla Firefox(2).bak
2015-07-09 20:58 - 2015-07-24 13:46 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\tor
2015-07-08 15:48 - 2015-07-25 01:02 - 00049556 _____ C:\WINDOWS\system32\CFG284806105
2015-07-08 14:27 - 2015-07-24 13:46 - 00000000 ___HD C:\Documents and Settings\All Users\Application Data\{F87DCEF6-04DD-4A4E-8B0F-729ABCA4B397}
2015-07-07 13:45 - 2015-07-24 16:22 - 00000664 _____ C:\Documents and Settings\Dad\Local Settings\Application Data\d3d9caps.dat
2015-06-28 15:38 - 2015-07-24 13:47 - 00000000 ____D C:\Program Files\Dell Support Center
2015-06-28 15:38 - 2015-06-28 15:38 - 00000000 ____D C:\Program Files\Dell
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-25 11:43 - 2014-10-15 13:33 - 00000000 ____D C:\FRST
2015-07-25 11:43 - 2011-10-16 10:17 - 00000426 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{DFAC5F52-F896-4C64-B364-5AA672E62C68}.job
2015-07-25 11:36 - 2011-03-21 10:38 - 00000000 ____D C:\TEMP
2015-07-25 11:12 - 2012-08-05 07:08 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-07-25 10:15 - 2011-03-20 19:11 - 01090154 _____ C:\WINDOWS\WindowsUpdate.log
2015-07-25 01:04 - 2011-03-21 10:34 - 00000418 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{C1600535-C1FD-474A-9F2E-A1BAED631CC7}.job
2015-07-25 01:04 - 2011-03-20 19:16 - 00032592 _____ C:\WINDOWS\SchedLgU.Txt
2015-07-25 01:02 - 2013-11-24 18:20 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2015-07-25 01:01 - 2014-04-30 13:15 - 00000000 ___RD C:\Documents and Settings\Dad\My Documents\Dropbox
2015-07-25 01:01 - 2014-04-30 13:09 - 00000000 ____D C:\Documents and Settings\Dad\Application Data\Dropbox
2015-07-25 01:01 - 2014-02-21 22:41 - 00000000 ____D C:\Documents and Settings\Dad\Application Data\Skype
2015-07-25 01:00 - 2014-10-16 07:40 - 00000274 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job
2015-07-25 01:00 - 2014-03-27 06:57 - 00000218 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-07-25 01:00 - 2013-07-27 09:46 - 00000282 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1004.job
2015-07-25 01:00 - 2013-04-27 08:59 - 00000296 _____ C:\WINDOWS\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job
2015-07-25 01:00 - 2013-04-26 09:13 - 00000282 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job
2015-07-25 01:00 - 2011-11-24 15:56 - 00000274 _____ C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job
2015-07-25 01:00 - 2011-06-03 13:00 - 00000282 _____ C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1004.job
2015-07-25 01:00 - 2011-03-20 08:20 - 01415385 _____ C:\WINDOWS\setupapi.log
2015-07-25 00:58 - 2014-06-22 10:21 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-07-25 00:58 - 2011-03-20 19:16 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-07-25 00:58 - 2011-03-19 15:30 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-07-25 00:58 - 2011-03-19 15:30 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-07-24 17:15 - 2011-03-20 19:35 - 00000178 ___SH C:\Documents and Settings\Dad\ntuser.ini
2015-07-24 16:20 - 2014-06-22 10:21 - 00000730 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-24 16:00 - 2011-03-21 10:37 - 00000000 ____D C:\Program Files\Google
2015-07-24 15:12 - 2012-08-05 07:08 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-24 15:12 - 2011-08-14 07:58 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-07-24 14:40 - 2011-03-21 13:17 - 00031512 ____C C:\Documents and Settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2015-07-24 14:21 - 2013-08-15 03:16 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-07-24 14:21 - 2004-08-04 06:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-07-24 14:10 - 2011-03-21 14:00 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Microsoft Help
2015-07-24 14:00 - 2013-07-27 09:46 - 00000290 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1004.job
2015-07-24 13:55 - 2011-03-19 15:17 - 00159544 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-07-24 13:54 - 2011-09-19 16:38 - 00000000 ____D C:\Documents and Settings\Administrator.PETE-05F6D62355
2015-07-24 13:54 - 2011-03-22 17:42 - 00000000 ____D C:\Documents and Settings\Caitlin.PETE-05F6D62355
2015-07-24 13:54 - 2011-03-21 13:43 - 00000000 ____D C:\Documents and Settings\postgres.PETE-05F6D62355
2015-07-24 13:54 - 2011-03-20 19:35 - 00000000 ____D C:\Documents and Settings\Dad
2015-07-24 13:54 - 2011-03-20 19:16 - 00000000 __SHD C:\Documents and Settings\LocalService
2015-07-24 13:54 - 2011-03-20 19:15 - 00000000 __SHD C:\Documents and Settings\NetworkService
2015-07-24 13:54 - 2011-03-20 19:08 - 00000000 ____D C:\WINDOWS\Registration
2015-07-24 13:52 - 2014-02-22 00:59 - 00000000 ___RD C:\Program Files\Skype
2015-07-24 13:50 - 2014-07-08 21:46 - 00000000 ____D C:\Documents and Settings\Dad\Local Settings\Application Data\Adobe
2015-07-24 13:50 - 2013-10-13 19:24 - 00000000 ____D C:\Program Files\Juicy Stakes 2.0
2015-07-24 13:50 - 2013-02-28 08:10 - 00000000 ____D C:\Documents and Settings\Dad\Start Menu\Programs\Juicy Stakes 2.0
2015-07-24 13:50 - 2011-04-15 19:57 - 00000000 ____D C:\Program Files\Cake Poker 2.0
2015-07-24 13:48 - 2015-06-17 22:39 - 00000000 ____D C:\Documents and Settings\Dad\Start Menu\Programs\Dropbox(2)
2015-07-24 13:47 - 2014-02-22 14:02 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Dell
2015-07-24 13:47 - 2014-02-22 14:02 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\PCDr
2015-07-24 13:47 - 2014-02-22 13:56 - 00000000 ____D C:\Documents and Settings\Dad\Application Data\PCDr
2015-07-24 13:43 - 2011-06-24 20:13 - 00000000 ____D C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\Application Data\Coupons.com
2015-07-24 13:42 - 2011-03-20 19:37 - 00000000 ____D C:\Documents and Settings\Dad\Desktop\Wealth Beyond Reason
2015-07-24 13:40 - 2011-04-12 12:15 - 00000000 ____D C:\Documents and Settings\Dad\Application Data\Ahead
2015-07-24 13:39 - 2011-03-21 10:38 - 00000000 ____D C:\Documents and Settings\Dad\Local Settings\Application Data\Google
2015-07-24 10:31 - 2013-04-27 08:59 - 00000304 _____ C:\WINDOWS\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job
2015-07-24 08:23 - 2011-03-22 17:40 - 00000282 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job
2015-07-23 21:28 - 2014-11-12 13:59 - 00005778 _____ C:\WINDOWS\COM+.log
2015-07-23 18:09 - 2014-01-30 18:48 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2015-07-23 11:46 - 2004-08-04 06:00 - 00000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_21
2015-07-23 11:07 - 2004-08-04 06:00 - 00000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_860
2015-07-21 14:19 - 2013-06-03 17:15 - 00000000 ____D C:\Documents and Settings\Dad\My Documents\Holly Scans
2015-07-21 14:19 - 2011-03-20 19:37 - 00000000 ____D C:\Documents and Settings\Dad\My Documents\1968 Fender Precision
2015-07-21 14:16 - 2011-03-19 15:21 - 02323960 _____ C:\WINDOWS\FaxSetup.log
2015-07-21 14:16 - 2011-03-19 15:21 - 01159178 _____ C:\WINDOWS\ocgen.log
2015-07-21 14:16 - 2011-03-19 15:21 - 01088957 _____ C:\WINDOWS\tsoc.log
2015-07-21 14:16 - 2011-03-19 15:21 - 00755889 _____ C:\WINDOWS\iis6.log
2015-07-21 14:16 - 2011-03-19 15:21 - 00736088 _____ C:\WINDOWS\msmqinst.log
2015-07-21 14:16 - 2011-03-19 15:21 - 00666573 _____ C:\WINDOWS\comsetup.log
2015-07-21 14:16 - 2011-03-19 15:21 - 00411892 _____ C:\WINDOWS\netfxocm.log
2015-07-21 14:16 - 2011-03-19 15:21 - 00410430 _____ C:\WINDOWS\ntdtcsetup.log
2015-07-21 14:16 - 2011-03-19 15:21 - 00163691 _____ C:\WINDOWS\MedCtrOC.log
2015-07-21 14:16 - 2011-03-19 15:21 - 00120188 _____ C:\WINDOWS\tabletoc.log
2015-07-21 14:16 - 2011-03-19 15:21 - 00118105 _____ C:\WINDOWS\msgsocm.log
2015-07-21 14:16 - 2011-03-19 15:21 - 00109201 _____ C:\WINDOWS\ocmsn.log
2015-07-21 14:16 - 2011-03-19 15:21 - 00001917 _____ C:\WINDOWS\imsins.log
2015-07-20 16:19 - 2013-04-27 08:59 - 00000322 _____ C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job
2015-07-20 15:45 - 2011-06-03 13:00 - 00000290 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1004.job
2015-07-19 21:43 - 2014-10-14 20:08 - 00000000 ____D C:\AdwCleaner
2015-07-19 10:15 - 2004-08-04 06:00 - 00000227 _____ C:\WINDOWS\system.ini
2015-07-18 19:20 - 2004-08-04 06:00 - 00000027 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_259
2015-07-18 19:19 - 2011-03-19 15:17 - 00073728 _____ C:\WINDOWS\system32\config\security.bak
2015-07-18 19:19 - 2011-03-19 15:17 - 00028672 _____ C:\WINDOWS\system32\config\sam.bak
2015-07-18 19:19 - 2011-03-19 15:16 - 38535168 _____ C:\WINDOWS\system32\config\software.bak
2015-07-18 19:19 - 2011-03-19 15:16 - 11272192 _____ C:\WINDOWS\system32\config\system.bak
2015-07-18 19:19 - 2011-03-19 15:16 - 00524288 _____ C:\WINDOWS\system32\config\default.bak
2015-07-17 13:47 - 2011-03-20 19:08 - 00048276 _____ C:\WINDOWS\wmsetup.log
2015-07-17 13:47 - 2004-08-04 06:00 - 00000726 _____ C:\WINDOWS\win.ini
2015-07-16 21:36 - 2011-03-20 03:10 - 2145386496 _____ C:\WINDOWS\MEMORY.DMP
2015-07-16 21:36 - 2011-03-19 15:19 - 00000000 ____D C:\WINDOWS\Minidump
2015-07-03 08:49 - 2011-03-21 10:25 - 127070192 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-06-30 07:39 - 2013-11-13 04:23 - 01197296 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2015-06-28 16:32 - 2014-02-22 09:09 - 00000000 ____D C:\Documents and Settings\Dad\Local Settings\Application Data\Deployment
==================== Files in the root of some directories =======
2011-03-21 13:44 - 2011-03-21 13:44 - 0068381 ____C () C:\Program Files\hminstalllog.txt
2015-07-07 13:45 - 2015-07-24 16:22 - 0000664 _____ () C:\Documents and Settings\Dad\Local Settings\Application Data\d3d9caps.dat
2011-03-23 16:29 - 2014-10-05 09:30 - 0029696 ____C () C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-04-24 18:03 - 2013-04-24 18:03 - 0002243 ____C () C:\Documents and Settings\Dad\Local Settings\Application Data\recently-used.xbel
2007-01-16 20:36 - 2007-01-16 20:36 - 1468195 ____C () C:\Documents and Settings\All Users\P1160014.JPG
Some files in TEMP:
====================
C:\Documents and Settings\Dad\Local Settings\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp9l73kt.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================
Now The Addition Txt.
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 25-07-2015
Ran by [removed] at 2015-07-25 11:45:41
Running from C:\Documents and Settings\[removed]\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1844237615-515967899-725345543-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator.PETE-05F6D62355
Caitlin (S-1-5-21-1844237615-515967899-725345543-1004 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Caitlin.PETE-05F6D62355
Dad (S-1-5-21-1844237615-515967899-725345543-1005 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Dad
Guest (S-1-5-21-1844237615-515967899-725345543-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-1844237615-515967899-725345543-1000 - Limited - Disabled)
postgres (S-1-5-21-1844237615-515967899-725345543-1006 - Limited - Enabled) => %SystemDrive%\Documents and Settings\postgres.PETE-05F6D62355
SUPPORT_388945a0 (S-1-5-21-1844237615-515967899-725345543-1002 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Disabled - Up to date) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
3ivx MPEG-4 5.0.3 (remove only) (HKLM\…\3ivx MPEG-4 5.0.3) (Version: 5.0.3 - 3ivx Technologies, Pty. Ltd.)
AAC/MP4 Plugin (Free/GPL) 1.1 (HKLM\…\AAC/MP4 Plugin (Free/GPL), install for Mind Stereo_is1) (Version: - Transparent Corporation)
Adobe Acrobat 4.0 (HKLM\…\Adobe Acrobat 4.0) (Version: 4.0 - Adobe Systems, Inc.)
Adobe AIR (HKLM\…\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM\…\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.5 - Adobe Systems Incorporated)
Adobe Flash Player 18 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe PhotoDeluxe Home Edition 4.0 (HKLM\…\Adobe PhotoDeluxe Home Edition 4.0) (Version: 4.0 - Adobe Systems, Inc.)
Adobe Reader XI (11.0.08) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM\…\Adobe Shockwave Player) (Version: 12.1.7.157 - Adobe Systems, Inc.)
Amazon Kindle (HKLM\…\Amazon Kindle) (Version: - Amazon)
Apple Application Support (32-bit) (HKLM\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atmosphere Lite v5.0 (HKLM\…\Atmosphere Lite (Boundless Living Edition)_is1) (Version: - Vectormedia Software)
Atmosphere Lite v7.0 (HKLM\…\Atmosphere Lite_is1) (Version: - Vectormedia Software.)
Audacity 1.3.12 (Unicode) (HKLM\…\Audacity 1.3 Beta (Unicode)_is1) (Version: - Audacity Team)
Audacity 2.0 (HKLM\…\Audacity_is1) (Version: - Audacity Team)
Audible Download Manager (HKLM\…\AudibleDownloadManager) (Version: 6.6.0.15 - Audible, Inc.)
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Canon MP250 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series) (Version: - )
CutePDF Writer 3.0 (HKLM\…\CutePDF Writer Installation) (Version: 3.0 - CutePDF.com)
Dell ResourceCD (HKLM\…\{D78653C3-A8FF-415F-92E6-D774E634FF2D}) (Version: - )
Dell System Detect (HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\73f463568823ebbe) (Version: 5.12.0.3 - Dell)
Drivers (HKLM\…\{6ABA1658-6429-4D01-875C-0EA6EE851AD1}) (Version: - )
Dropbox (HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\Dropbox) (Version: 3.6.9 - Dropbox, Inc.)
Extended Asian Language font pack for Adobe Reader XI (HKLM\…\{AC76BA86-7AD7-2530-0000-A00000000004}) (Version: 11.0.0 - Adobe Systems Incorporated)
FlipShare (HKLM\…\{0D3F9802-689F-9B6D-8E44-B55971F0CCBB}) (Version: 4.5.0.39816 - Flip Video)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
GPL Ghostscript (HKLM\…\GPL Ghostscript 9.06) (Version: 9.06 - Artifex Software Inc.)
High Definition Audio Driver Package - KB888111 (HKLM\…\KB888111WXPSP2) (Version: 20040219.000000 - Microsoft Corporation)
Holdem Manager (HKLM\…\HoldemManager) (Version: - )
iSEEK AnswerWorks English Runtime (HKLM\…\{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}) (Version: [removed] - Vantage Linguistics)
iTunes (HKLM\…\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.)
J2SE Runtime Environment 5.0 Update 16 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0150160}) (Version: 1.5.0.160 - Sun Microsystems, Inc.)
Juicy Stakes 2.0 (HKLM\…\Juicy Stakes 2.0) (Version: 2.0.1.8336 - Juicy Stakes)
LAME v3.99.3 (for Windows) (HKLM\…\LAME_is1) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\…\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.9 (HKLM\…\Wudf01009) (Version: - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\…\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft WinUsb 1.0 (HKLM\…\winusb0100) (Version: - Microsoft Corporation)
Mind Stereo 1.1.3 (HKLM\…\Mind Stereo_is1) (Version: - Transparent Corporation)
Mozilla Firefox 39.0 (x86 en-US) (HKLM\…\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 39.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 6 Service Pack 2 (KB973686) (HKLM\…\{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}) (Version: 6.20.2003.0 - Microsoft Corporation)
Nero Suite (HKLM\…\NeroMultiInstaller!UninstallKey) (Version: - )
NETGEAR WNDA3100v2 wireless USB 2.0 adapter (HKLM\…\{3C7839E7-21F4-49E0-B4D5-AC8ED818CCB0}) (Version: 2.2.0.3 - NETGEAR)
PDF to JPG Converter 1.3 (HKLM\…\PDF to JPG Converter) (Version: 1.3 - )
Poker Calculator Pro (HKLM\…\Poker Calculator Pro) (Version: - Poker Pro Labs)
PokerStars.net (HKLM\…\PokerStars.net) (Version: - PokerStars.net)
PostgreSQL 8.4 (HKLM\…\PostgreSQL 8.4) (Version: 8.4 - PostgreSQL Global Development Group)
Quicken 2011 (HKLM\…\{5FE545A1-D215-4216-9189-E7B39C9D1CC1}) (Version: 20.1.8.6 - Intuit)
QuickShare (HKLM\…\{11D4FAA0-A577-4FA8-B24E-D24283D861D1}) (Version: 11.24.60.15709 - Linkury Inc.) <==== ATTENTION
QuickTime (HKLM\…\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)
RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\…\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
Realtek AC'97 Audio (HKLM\…\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version: 5.36 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.7083 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Revo Uninstaller 1.95 (HKLM\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Skype™ 7.0 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SoundMAX (HKLM\…\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 5.10.01.4541 - Analog Devices)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TomTom HOME (HKLM\…\{99072AB4-D795-44D5-9D65-E3C9F8322C97}) (Version: 2.9.7 - TomTom)
TomTom HOME Visual Studio Merge Modules (HKLM\…\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Virtual Sound Canvas 3.2 (HKLM\…\VSC32) (Version: - )
VoiceOver Kit (HKLM\…\{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}) (Version: 1.42.128.0 - Apple Inc.)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Imaging Component (HKLM\…\WIC) (Version: 3.0.0.0 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\…\Windows Media Format Runtime) (Version: - )
Windows Media Player 11 (HKLM\…\Windows Media Player) (Version: - )
Windows PowerShell(TM) 1.0 (HKLM\…\KB926139-v2) (Version: 2 - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
WinZip 17.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DC}) (Version: 17.5.10562 - WinZip Computing, S.L. )
Wireless Client Manager (HKLM\…\{27678F85-7234-4CEB-B84D-2C44E9C4B18E}) (Version: - )
Yahoo! Detect (HKLM\…\YTdetect) (Version: - )
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.29\psuser.dll No (the data entry has 5 more characters).
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{E69341A3-E6D2-4175-B60C-C9D3D6FA40F6}\localserver32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
==================== Restore Points =========================
26-04-2015 21:15:19 System Checkpoint
27-04-2015 21:49:07 System Checkpoint
28-04-2015 21:50:54 System Checkpoint
29-04-2015 22:39:56 System Checkpoint
30-04-2015 22:43:50 System Checkpoint
01-05-2015 22:51:17 System Checkpoint
02-05-2015 23:31:49 System Checkpoint
04-05-2015 00:33:19 System Checkpoint
05-05-2015 01:21:45 System Checkpoint
06-05-2015 01:45:07 System Checkpoint
07-05-2015 02:32:32 System Checkpoint
08-05-2015 06:38:48 System Checkpoint
09-05-2015 12:47:59 System Checkpoint
10-05-2015 12:58:35 System Checkpoint
11-05-2015 13:13:11 System Checkpoint
12-05-2015 14:08:31 System Checkpoint
13-05-2015 07:25:40 Software Distribution Service 3.0
14-05-2015 15:08:11 System Checkpoint
15-05-2015 16:12:00 System Checkpoint
16-05-2015 17:20:04 System Checkpoint
17-05-2015 18:16:07 System Checkpoint
18-05-2015 18:40:08 System Checkpoint
19-05-2015 19:29:44 System Checkpoint
20-05-2015 20:00:53 System Checkpoint
21-05-2015 20:33:01 System Checkpoint
23-05-2015 00:24:14 System Checkpoint
24-05-2015 00:53:03 System Checkpoint
25-05-2015 01:45:56 System Checkpoint
26-05-2015 02:37:25 System Checkpoint
27-05-2015 07:54:46 System Checkpoint
28-05-2015 08:03:47 System Checkpoint
29-05-2015 11:02:55 System Checkpoint
30-05-2015 11:53:37 System Checkpoint
31-05-2015 18:53:38 System Checkpoint
01-06-2015 19:05:02 System Checkpoint
02-06-2015 19:25:57 System Checkpoint
03-06-2015 20:07:02 System Checkpoint
04-06-2015 20:16:26 System Checkpoint
05-06-2015 23:49:04 System Checkpoint
07-06-2015 00:05:46 System Checkpoint
08-06-2015 01:12:47 System Checkpoint
09-06-2015 02:05:59 System Checkpoint
10-06-2015 02:58:42 System Checkpoint
10-06-2015 09:00:16 Software Distribution Service 3.0
11-06-2015 13:18:59 System Checkpoint
12-06-2015 13:35:26 System Checkpoint
13-06-2015 23:07:12 System Checkpoint
14-06-2015 23:42:34 System Checkpoint
15-06-2015 23:48:26 System Checkpoint
16-06-2015 23:58:20 System Checkpoint
18-06-2015 00:39:41 System Checkpoint
19-06-2015 01:30:34 System Checkpoint
20-06-2015 02:22:23 System Checkpoint
21-06-2015 07:54:02 System Checkpoint
22-06-2015 15:02:49 System Checkpoint
23-06-2015 15:18:30 System Checkpoint
24-06-2015 15:21:50 System Checkpoint
25-06-2015 16:04:10 System Checkpoint
26-06-2015 16:58:03 System Checkpoint
27-06-2015 17:09:57 System Checkpoint
28-06-2015 17:10:16 System Checkpoint
29-06-2015 17:19:00 System Checkpoint
30-06-2015 17:49:46 System Checkpoint
01-07-2015 18:08:15 System Checkpoint
02-07-2015 18:08:58 System Checkpoint
03-07-2015 18:43:09 System Checkpoint
04-07-2015 19:31:49 System Checkpoint
05-07-2015 19:41:23 System Checkpoint
06-07-2015 20:09:32 System Checkpoint
07-07-2015 20:47:54 System Checkpoint
08-07-2015 15:43:20 Restore Operation
09-07-2015 06:46:06 Restore Operation
09-07-2015 21:18:52 Restore Operation
09-07-2015 22:03:42 Software Distribution Service 3.0
09-07-2015 22:30:41 Restore Operation
10-07-2015 22:46:19 System Checkpoint
11-07-2015 22:47:54 Restore Operation
12-07-2015 23:18:08 System Checkpoint
14-07-2015 00:16:29 System Checkpoint
15-07-2015 00:39:38 System Checkpoint
15-07-2015 09:00:40 Software Distribution Service 3.0
16-07-2015 06:09:07 Removed Google Earth.
16-07-2015 06:12:26 Removed Fuze Meeting
16-07-2015 15:34:15 Revo Uninstaller's restore point - HijackThis Packages
16-07-2015 17:07:03 Revo Uninstaller's restore point - Google Chrome
16-07-2015 17:11:32 Revo Uninstaller's restore point - Chromium
16-07-2015 17:48:56 Revo Uninstaller's restore point - Google Chrome
16-07-2015 17:59:56 Revo Uninstaller's restore point - Google Chrome
16-07-2015 18:01:07 Revo Uninstaller's restore point - Google Chrome
18-07-2015 18:46:59 ComboFix created restore point
19-07-2015 22:26:19 System Checkpoint
20-07-2015 06:05:03 Revo Uninstaller's restore point - Malwarebytes Anti-Malware version 2.0.4.1028
21-07-2015 06:15:10 System Checkpoint
22-07-2015 06:48:27 System Checkpoint
22-07-2015 11:28:27 Revo Uninstaller's restore point - Google Chrome
23-07-2015 12:23:42 System Checkpoint
24-07-2015 12:32:46 System Checkpoint
24-07-2015 13:34:48 Restore Operation
24-07-2015 14:03:34 Software Distribution Service 3.0
24-07-2015 14:31:31 Removed Fuze Meeting
24-07-2015 15:56:54 Revo Uninstaller's restore point - Mozilla Firefox 37.0.2 (x86 en-US)
24-07-2015 15:59:29 Revo Uninstaller's restore point - Mozilla Firefox 37.0.2 (x86 en-US)
24-07-2015 16:00:24 Revo Uninstaller's restore point - Google Earth
24-07-2015 16:00:37 Removed Google Earth.
24-07-2015 16:02:17 Revo Uninstaller's restore point - Malwarebytes Anti-Malware version 2.0.4.1028
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2004-08-04 06:00 - 2015-07-23 21:24 - 00000855 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1844237615-515967899-725345543-1005Core.job => C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1844237615-515967899-725345543-1005UA.job => C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
Task: C:\WINDOWS\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{C1600535-C1FD-474A-9F2E-A1BAED631CC7}.job => C:\WINDOWS\system32\msfeedssync.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{DFAC5F52-F896-4C64-B364-5AA672E62C68}.job => C:\WINDOWS\system32\msfeedssync.exe
==================== Loaded Modules (Whitelisted) ==============
2013-03-09 14:25 - 2012-10-04 19:50 - 00088688 _____ () C:\WINDOWS\system32\cpwmon2k.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2009-06-04 17:41 - 2009-06-04 17:41 - 00451904 _____ () C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
2009-06-04 17:37 - 2009-06-04 17:37 - 01581056 _____ () C:\Program Files\Flip Video\FlipShare\QtCore4.dll
2011-03-21 13:41 - 2009-09-08 03:48 - 00172032 _____ () C:\Program Files\PostgreSQL\8.4\bin\LIBPQ.dll
2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
2011-03-21 13:41 - 2009-02-12 15:01 - 00976384 _____ () C:\Program Files\PostgreSQL\8.4\bin\libxml2.dll
2011-03-21 13:41 - 2005-07-20 06:48 - 00059904 _____ () C:\Program Files\PostgreSQL\8.4\bin\zlib1.dll
2014-11-15 13:26 - 2013-11-11 16:10 - 00307928 _____ () C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe
2014-11-15 13:26 - 2013-12-05 15:06 - 00319488 _____ () C:\Program Files\NETGEAR\WNDA3100v2\WifiLib.dll
2014-11-15 13:26 - 2013-12-09 18:01 - 08385240 _____ () C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe
2014-11-15 13:26 - 2013-11-01 18:31 - 00278528 _____ () C:\Program Files\NETGEAR\WNDA3100v2\WifiSvcLib.dll
2015-07-25 01:00 - 2015-07-25 01:00 - 00043008 _____ () c:\Documents and Settings\Dad\Local Settings\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp9l73kt.dll
2015-03-04 17:45 - 2015-03-19 03:15 - 00750080 _____ () C:\Documents and Settings\Dad\Application Data\Dropbox\bin\libGLESv2.dll
2015-03-04 17:45 - 2015-03-19 03:15 - 00047616 _____ () C:\Documents and Settings\Dad\Application Data\Dropbox\bin\libEGL.dll
2015-03-04 17:45 - 2015-03-19 03:15 - 00865280 _____ () C:\Documents and Settings\Dad\Application Data\Dropbox\bin\plugins\platforms\qwindows.dll
2015-03-04 17:45 - 2015-03-19 03:15 - 00200704 _____ () C:\Documents and Settings\Dad\Application Data\Dropbox\bin\plugins\imageformats\qjpeg.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Documents and Settings\Dad\My Documents\My Ideal Day.docx:com.dropbox.attributes
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\dell.com -> dell.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1844237615-515967899-725345543-1005\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Dad\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
HKU\S-1-5-21-1844237615-515967899-725345543-1006\Control Panel\Desktop\\Wallpaper -> (None)
DNS Servers: [removed] - [removed]
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE] => Enabled:Microsoft Office OneNote
StandardProfile\AuthorizedApplications: [C:\Program Files\PPN Poker\PokerClient.exe] => Enabled:PPN Poker
StandardProfile\AuthorizedApplications: [C:\Program Files\PPN Poker\PokerUpdate.exe] => Disabled:PokerUpdate
StandardProfile\AuthorizedApplications: [C:\Program Files\Cake Poker 2.0\PokerClient.exe] => Enabled:Cake Poker 2.0
StandardProfile\AuthorizedApplications: [C:\Program Files\FrostWire 5\FrostWire.exe] => Enabled:FrostWire
StandardProfile\AuthorizedApplications: [C:\Program Files\Java\jre6\bin\javaw.exe] => Enabled:Java(TM) Platform SE binary
StandardProfile\AuthorizedApplications: [C:\Program Files\Pure Poker 2.0\PokerClient.exe] => Enabled:Pure Poker 2.0
StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Dad\Local Settings\Application Data\Fuze Box\Fuze Meeting\Fuze_Meeting.exe] => Enabled:Fuze Meeting
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Dad\Application Data\Dropbox\bin\Dropbox.exe] => Enabled:Dropbox
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\All Users\Application Data\EmailNotifier\EmailNotifier.exe] => Enabled:Email Notifier
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Google Talk\googletalk.exe] => Enabled:Google Talk
StandardProfile\AuthorizedApplications: [C:\Program Files\Skype\Phone\Skype.exe] => Enabled:Skype
StandardProfile\AuthorizedApplications: [C:\Program Files\Juicy Stakes 2.0\PokerClient.exe] => Enabled:Juicy Stakes 2.0
StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)
StandardProfile\GloballyOpenPorts: [5432:TCP] => Enabled:postgres
==================== Faulty Device Manager Devices =============
Name: Video Controller (VGA Compatible)
Description: Video Controller (VGA Compatible)
Class Guid: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: SM Bus Controller
Description: SM Bus Controller
Class Guid: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: PCI Simple Communications Controller
Description: PCI Simple Communications Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Ethernet Controller
Description: Ethernet Controller
Class Guid:
Manufacturer:
Service:
Problem: : This device is not configured correctly. (Code1)
Resolution: You may be prompted to provide the path of the driver. Windows may have the driver built-in, or may still have the driver files installed from the last time that you set up the device. If you are asked for the driver and you do not have it, you can try to download the latest driver from the hardware vendor�s Web site.
In the device properties dialog box, click the "Driver" tab, and then click "Update Driver" to start the "Hardware Update Wizard". Follow the instructions to update the driver. If updating the driver does not work, see your hardware documentation for more information.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/25/2015 12:58:51 AM) (Source: PostgreSQL) (EventID: 0) (User: )
Description: 2015-07-25 00:58:51 EDTFATAL: the database system is starting up
Error: (07/24/2015 04:07:51 PM) (Source: PostgreSQL) (EventID: 0) (User: )
Description: 2015-07-24 16:07:51 EDTFATAL: the database system is starting up
Error: (07/24/2015 03:48:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module unknown, version 0.0.0.0, fault address 0x00013e58.
Processing media-specific event for [iexplore.exe!ws!]
Error: (07/24/2015 03:41:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module unknown, version 0.0.0.0, fault address 0x00013e58.
Processing media-specific event for [iexplore.exe!ws!]
Error: (07/24/2015 03:40:30 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (07/24/2015 03:36:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application chrome.exe, version 42.0.2311.90, faulting module chrome.dll, version 42.0.2311.90, fault address 0x0051f9eb.
Processing media-specific event for [chrome.exe!ws!]
Error: (07/24/2015 02:41:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application chrome.exe, version 42.0.2311.90, faulting module chrome.dll, version 42.0.2311.90, fault address 0x0051f9eb.
Processing media-specific event for [chrome.exe!ws!]
Error: (07/24/2015 02:40:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application chrome.exe, version 42.0.2311.90, faulting module chrome.dll, version 42.0.2311.90, fault address 0x0051f9eb.
Processing media-specific event for [chrome.exe!ws!]
Error: (07/24/2015 02:40:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application chrome.exe, version 42.0.2311.90, faulting module chrome.dll, version 42.0.2311.90, fault address 0x0051f9eb.
Processing media-specific event for [chrome.exe!ws!]
Error: (07/24/2015 02:36:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module unknown, version 0.0.0.0, fault address 0x00013e58.
Processing media-specific event for [iexplore.exe!ws!]
System errors:
=============
Error: (07/25/2015 12:58:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The MBAMService service failed to start due to the following error:
%%1053
Error: (07/25/2015 12:58:51 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the MBAMService service to connect.
Error: (07/25/2015 12:58:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The MBAMScheduler service failed to start due to the following error:
%%1053
Error: (07/25/2015 12:58:51 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the MBAMScheduler service to connect.
Error: (07/25/2015 12:58:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Zune Bus Enumerator Driver service failed to start due to the following error:
%%2
Error: (07/24/2015 04:07:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The MBAMService service failed to start due to the following error:
%%1053
Error: (07/24/2015 04:07:51 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the MBAMService service to connect.
Error: (07/24/2015 04:07:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The MBAMScheduler service failed to start due to the following error:
%%1053
Error: (07/24/2015 04:07:51 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Timeout (30000 milliseconds) waiting for the MBAMScheduler service to connect.
Error: (07/24/2015 04:07:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Zune Bus Enumerator Driver service failed to start due to the following error:
%%2
Microsoft Office:
=========================
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU 3.06GHz
Percentage of memory in use: 22%
Total physical RAM: 3037.93 MB
Available physical RAM: 2357.88 MB
Total Virtual: 4924.02 MB
Available Virtual: 4438.65 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:931.5 GB) (Free:845.72 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: (My Disc) (CDROM) (Total:0.04 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: D04FD04F)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
==================== End of log ============================