This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malawarebytes Will Not Load, Some Streaming Too [Closed]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK…..hope I did this right.

Thanks so much for your patience. I too have been busy and think that if I was around more, we would have this before now.

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 20-07-2015

Ran by [removed] at 2015-07-22 06:28:17 Run:4

Running from C:\Documents and Settings\[removed]\Desktop

[removed]

Boot Mode: Normal

 

==============================================

 

fixlist content:

*****************

BootExecute: autocheck autochk * sprestrt

CHR Extension: (No Name) - C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bojhhinnlgdmcajekighmiiehpofkodp [2015-07-09]

S1 BAPIDRV; system32\DRIVERS\BAPIDRV.sys [X]

S4 IntelIde; No ImagePath

U1 WS2IFSL; No ImagePath

S2 zumbus; system32\DRIVERS\zumbus.sys [X]

2015-07-10 12:46 - 2015-07-14 13:46 - 00000468 _____ C:\WINDOWS\Tasks\At1.job

2015-07-10 12:40 - 2015-07-10 12:42 - 01402880 _____ C:\Documents and Settings\Dad\Downloads\HijackThisSetup [1].exe

2015-07-10 12:40 - 2015-07-10 12:40 - 00000000 ____D C:\Program Files\360

Task: C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job => 0x01050100950876D8A309B84DAE729EB3FE27536146004E0100000000F0000100200000000014730F000000000313040050028821000000000000000000000000000000000000380063003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F0066007400200053006500630075007200690074007900200043006C00690065006E0074005C004D00700043006D006400520075006E002E00650078006500000026005300630061006E0020002D005300630068006500640075006C0065004A006F00620020002D0052006500730074007200690063007400500072006900760069006C006500670065007300000000000700530059005300540045004D000000140050006500720069006F0064006900630020007300630061006E0020007400610073006B002E000000000008000300078000000000010030000000DE07060003000000000000000100200000000000000000000000000002000000010001000000000000000000

AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:CDF51F17

AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

*****************

 

hklm\System\CurrentControlSet\Control\Session Manager\\BootExecute => value restored successfully

C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bojhhinnlgdmcajekighmiiehpofkodp folder not found.

BAPIDRV => Service removed successfully.

IntelIde => Service removed successfully.

WS2IFSL => Service stopped successfully.

WS2IFSL => Service removed successfully.

zumbus => Service removed successfully.

"C:\WINDOWS\Tasks\At1.job" => File/Folder not found.

"C:\Documents and Settings\Dad\Downloads\HijackThisSetup [1].exe" => File/Folder not found.

C:\Program Files\360 => moved successfully.

C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job not found.

"C:\Documents and Settings\All Users\Application Data\TEMP" => ":CDF51F17" ADS not found.

"C:\Documents and Settings\All Users\Application Data\TEMP" => ":D1B5B4F1" ADS not found.

 

==== End of Fixlog 06:28:17 ====

Let's try this one.

 

Run aswMBR

  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply

Thanks

Satchfan
 

 

Sorry, like most of our tries….this one will not run either.

That is what is frustrating as some do and most don't.

Acts exactly like Malwarebytes when I have attempted to run it at the beginning of this.

Let’s try resetting some of your Windows settings.

Download and run Tweaking.com - Windows Repair

Download Windows Repair from here

  • install and then run the program
  • ignore steps 1-5 and click on + Repair
  • then, in the same window, click on the “Open Repairs” tab:
  • click Start
  • leave the default selected items as they are and check Restart System When Finished
  • now press Start.

Once that is complete, please try running TDSSKiller again.

If neither still works, try both in safe mode.

Satchfan
 

I’d like a bit more information on one of the entries.

Run Farbar Recovery Scan Tool

Open notepad (Start >All Programs > Accessories > Notepad). Please copy the entire contents of the code box below and paste it into Notepad.

Folder: C:\Documents and Settings\All Users\Application Data\{F87DCEF6-04DD-4A4E-8B0F-729ABCA4B397}
  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

Satchfan
 

 

OK

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 20-07-2015

Ran by [removed] at 2015-07-24 10:27:33 Run:5

Running from C:\Documents and Settings\[removed]\Desktop

[removed]

Boot Mode: Normal

 

==============================================

 

fixlist content:

*****************

Folder: C:\Documents and Settings\All Users\Application Data\{F87DCEF6-04DD-4A4E-8B0F-729ABCA4B397}

*****************

 

 

========================= Folder: C:\Documents and Settings\All Users\Application Data\{F87DCEF6-04DD-4A4E-8B0F-729ABCA4B397} ========================

 

2015-07-08 14:27 - 2015-07-08 14:28 - 0114864 ____H () C:\Documents and Settings\All Users\Application Data\{F87DCEF6-04DD-4A4E-8B0F-729ABCA4B397}\3f1ad9cb9f4

 

====== End of Folder: ======

 

 

==== End of Fixlog 10:27:33 ====

Let’s try restoring your computer and then take another look. Please make sure that you choose an early enough date before your computer was acting this way.

Restore Windows XP to a previous state

Let’s see if restoring the system to an earlier state helps.

  • log on to Windows as an administrator.
  • click Start, All Programs, Accessories, System Tools and then click System Restore.
  • on the “Welcome to System Restore” page, click to select the Restore my computer to an earlier time option, and then click Next.
  • on the “Select a Restore Point" page, click the most recent system restore point when you believe your system was working OK and then click Next.
    Note A System Restore message may appear that lists configuration changes that System Restore will make. Click OK.
  • on the “Confirm Restore Point Selection” page, click Next. System Restore restores the previous Windows XP configuration, and then restarts the computer.
  • log on to the computer as an Administrator. Then click OK on the System Restore “Restoration Complete” page.

Let me know what happens.

I am leaving to travel home again today so another delay I’m afraid, (real life gets in the way sometimes).

Satchfan

 

OK….did a system restore all the way back to April as I was sure there wasn't a problem then.

When everything was said and done, I have browser icons but, only window's explorer works.

There are some window's updates running at present.

None of the exe.s files you had me download to deskstop are present but, some of the logs remain.

I won't reinstall browsers until you give me permission.

Let me know what you want me to do next.

Thanks so much!

Good work. I don't know what you mean about "browsers" as you must be using one to access the forum.

Please delete the old logs from your desktop.and we'll have a look and see the state of your computer now.

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

================================================

Run Security Check

Download Security Check by screen317 from here or here.

  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE: If you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED!, try rebooting the system and then run SecurityCheck again.

Logs to include with next post:

Frst.txt
Addition.txt
checkup.txt


Thanks

Satchfan

 

First two logs:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-07-2015

Ran by [removed] (administrator) on PETE-05F6D62355 (25-07-2015 11:43:47)

Running from C:\Documents and Settings\[removed]\Desktop

[removed]

Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)

Internet Explorer Version 8 (Default browser: FF)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

() C:\Program Files\Flip Video\FlipShare\FlipShareService.exe

(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\pg_ctl.exe

() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe

(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\postgres.exe

() C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe

(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\postgres.exe

(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\postgres.exe

(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\postgres.exe

(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\8.4\bin\postgres.exe

(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe

(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe

(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

() C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe

(Dropbox, Inc.) C:\Documents and Settings\Dad\Application Data\Dropbox\bin\Dropbox.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

 

 

==================== Registry (Whitelisted) ==================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\…\Run: [TkBellExe] => C:\program files\real\realplayer\update\realsched.exe [295512 2013-09-04] (RealNetworks, Inc.)

HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-04-07] (Apple Inc.)

HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [30878816 2014-12-11] (Skype Technologies S.A.)

HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\Run: [CPN Notifier] => C:\Program Files\Juicy Stakes 2.0\PokerNotifier.exe

HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\Run: [Dropbox Update] => C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\DropboxUpdate.exe [134512 2015-07-24] (Dropbox, Inc.)

HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\Run: [DellSystemDetect] => C:\Documents and Settings\Dad\Local Settings\Apps\2.0\WQRE5RQW.GQX\MEOK2BTQ.M23\dell..tion_e30b47f5d4a30e9e_0005.000c_1df9a4898fae00de\DellSystemDetect.exe [264488 2014-11-15] (Dell)

Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WNDA3100v2 Genie.lnk [2014-11-14]

ShortcutTarget: NETGEAR WNDA3100v2 Genie.lnk -> C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe ()

Startup: C:\Documents and Settings\Caitlin.PETE-05F6D62355\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2011-11-23]

ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

Startup: C:\Documents and Settings\Dad\Start Menu\Programs\Startup\Dropbox.lnk [2015-04-25]

ShortcutTarget: Dropbox.lnk -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

Startup: C:\Documents and Settings\Dad\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2011-03-21]

ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)

BootExecute: autocheck autochk * sprestrt

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?ocid=OIE8HP&PC;=B8DF

HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE8HP&PC;=B8DF

HKU\S-1-5-21-1844237615-515967899-725345543-1005\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

HKU\S-1-5-21-1844237615-515967899-725345543-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE8HP&PC;=B8DF

URLSearchHook: [S-1-5-21-1844237615-515967899-725345543-1006] ATTENTION ==> Default URLSearchHook is missing.

BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)

BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.5.0_16\bin\ssv.dll [2008-05-28] (Sun Microsystems, Inc.)

BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.5.0_16\bin\jp2ssv.dll No File

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab

DPF: {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_16-windows-i586.cab

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)

Tcpip\Parameters: [DhcpNameServer] [removed] [removed]

Tcpip\..\Interfaces\{11877365-053F-4884-B042-84371189536B}: [DhcpNameServer] [removed] [removed]

Tcpip\..\Interfaces\{766B7B5B-9266-46F2-8FC2-DFD346ECFEF4}: [DhcpNameServer] [removed] [removed]

Tcpip\..\Interfaces\{B4DB4529-26B2-4B92-9EB9-D8F3F46C8702}: [DhcpNameServer] [removed] [removed]

 

FireFox:

========

FF ProfilePath: C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\ndwc8g77.default-1413647459921

FF DefaultSearchUrl:

FF SelectedSearchEngine: Yahoo

FF Homepage: about:home

FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-24] ()

FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1217157.dll [2015-02-16] (Adobe Systems, Inc.)

FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()

FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll No File

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)

FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)

FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll [2013-09-04] (RealNetworks, Inc.)

FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)

FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)

FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)

FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.1.13 -> C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2011-12-18] (RealNetworks, Inc.)

FF Plugin: @real.com/nprphtml5videoshim;version=15.0.5.109 -> C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-07-01] (RealNetworks, Inc.)

FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll [2013-09-04] (RealPlayer)

FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)

FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)

FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-03-21]

FF HKLM\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

FF Extension: RealPlayer Browser Record Plugin - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-06-05]

FF HKLM\…\Firefox\Extensions: [{C3949AC2-4B17-43ee-B4F1-D26B9D42404D}] - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

FF HKLM\…\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF Extension: RealDownloader - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-04]

FF Extension: No Name - C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\ndwc8g77.default-1413647459921\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [not found]

 

Chrome:

=======

CHR Profile: C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default

CHR Extension: (No Name) - C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bojhhinnlgdmcajekighmiiehpofkodp [2015-07-24]

CHR Extension: (No Name) - C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-07-24]

CHR Extension: (No Name) - C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-24]

CHR Extension: (No Name) - C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24]

CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]

 

========================== Services (Whitelisted) =================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 FlipShare Service; C:\Program Files\Flip Video\FlipShare\FlipShareService.exe [451904 2009-06-04] ()

S2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)

S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)

R2 postgresql-8.4; C:\Program Files\PostgreSQL\8.4\bin\pg_ctl.exe [66048 2009-09-08] (PostgreSQL Global Development Group) [File not signed]

R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()

R2 WSWNDA3100v2; C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe [307928 2013-11-11] ()

 

==================== Drivers (Whitelisted) ====================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R3 BCMH43XX; C:\WINDOWS\System32\DRIVERS\bcmwlhigh5.sys [1034240 2011-03-28] (Broadcom Corporation)

S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)

S0 cercsr6; C:\WINDOWS\system32\Drivers\cercsr6.sys [39904 2004-12-13] (Adaptec, Inc.) [File not signed]

S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [145920 2005-01-07] (Windows (R) Server 2003 DDK provider)

S3 ManyCam; C:\WINDOWS\System32\DRIVERS\mcvidrv.sys [47728 2014-07-28] (Visicom Media Inc.)

R2 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [54360 2014-11-21] (Malwarebytes Corporation)

R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)

S3 mcaudrv_simple; C:\WINDOWS\System32\drivers\mcaudrv.sys [29936 2014-05-13] (Visicom Media Inc.)

S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)

S3 NPF; C:\WINDOWS\System32\DRIVERS\npf.sys [50704 2010-02-03] (CACE Technologies, Inc.)

R1 OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [10368 2001-05-14] (Dell Computer Corporation) [File not signed]

R3 SenFiltService; C:\WINDOWS\System32\drivers\Senfilt.sys [392960 2006-03-17] (Sensaura)

R3 vsc32; C:\WINDOWS\System32\DRIVERS\vsc.sys [951284 2001-04-16] (Roland) [File not signed]

S3 wlags51b; C:\WINDOWS\System32\DRIVERS\wlags51b.sys [177664 2002-04-30] (Agere Systems)

S4 IntelIde; No ImagePath

U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)

U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)

U1 WS2IFSL; No ImagePath

S2 zumbus; system32\DRIVERS\zumbus.sys [X]

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2015-07-25 11:43 - 2015-07-25 11:44 - 00016438 _____ C:\Documents and Settings\Dad\Desktop\FRST.txt

2015-07-25 11:42 - 2015-07-25 11:42 - 01650688 _____ (Farbar) C:\Documents and Settings\Dad\Desktop\FRST.exe

2015-07-25 11:36 - 2015-07-25 11:41 - 00126821 _____ C:\WINDOWS\system32\DB284806105

2015-07-24 16:20 - 2015-07-24 16:20 - 00000724 _____ C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

2015-07-24 15:56 - 2015-07-24 15:56 - 00000917 _____ C:\Documents and Settings\Dad\Desktop\Revo Uninstaller.lnk

2015-07-24 15:55 - 2015-07-24 15:55 - 02623656 _____ (VS Revo Group Ltd.) C:\Documents and Settings\Dad\Desktop\revosetup.exe

2015-07-24 14:12 - 2015-07-24 15:12 - 18524336 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe

2015-07-24 14:00 - 2015-07-24 14:00 - 00000000 ____D C:\Documents and Settings\Dad\Start Menu\Programs\Dropbox

2015-07-24 13:58 - 2015-07-24 13:58 - 00000000 ____D C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox

2015-07-24 13:57 - 2015-07-24 14:16 - 00000000 ____D C:\Documents and Settings\Dad\Desktop\Misc Desktop Files

2015-07-24 13:51 - 2015-07-24 16:20 - 00000000 ____D C:\Program Files\Mozilla Firefox

2015-07-24 13:47 - 2015-07-24 13:48 - 00000000 ____D C:\Documents and Settings\Dad\Start Menu\Programs\Dell

2015-07-24 13:46 - 2015-07-24 16:03 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware

2015-07-24 13:46 - 2015-07-24 13:49 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware

2015-07-24 13:41 - 2015-07-24 15:56 - 00000000 ____D C:\Program Files\VS Revo Group

2015-07-24 13:40 - 2015-07-24 13:40 - 00000000 ____D C:\Documents and Settings\Dad\Application Data\DriverFinder

2015-07-24 13:40 - 2015-07-24 13:40 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Coupons

2015-07-24 13:40 - 2015-07-24 13:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\EmailNotifier

2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ___HD C:\WINDOWS\msdownld.tmp

2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ___HD C:\WINDOWS\$MSI31Uninstall_KB893803v2$

2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ____D C:\WINDOWS\XSxS

2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy

2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware

2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ____D C:\Documents and Settings\Dad\WINDOWS

2015-07-24 13:37 - 2015-07-24 13:37 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TEMP

2015-07-23 10:58 - 2015-07-23 21:25 - 00022538 _____ C:\WINDOWS\bitssetup.log

2015-07-23 10:57 - 2015-07-23 21:17 - 00001670 _____ C:\WINDOWS\Windows Update.log

2015-07-23 10:45 - 2015-07-23 10:45 - 00000000 ____D C:\RegBackup

2015-07-23 10:45 - 2015-07-23 10:45 - 00000000 ____D C:\Program Files\Tweaking.com

2015-07-22 11:15 - 2015-07-24 13:36 - 00000000 ____D C:\Documents and Settings\Dad\Start Menu\Programs\Dropbox(3)

2015-07-22 11:13 - 2015-07-25 11:08 - 00000980 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1844237615-515967899-725345543-1005UA.job

2015-07-22 11:13 - 2015-07-24 14:08 - 00000928 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1844237615-515967899-725345543-1005Core.job

2015-07-21 14:05 - 2015-07-24 13:37 - 00000000 __SHD C:\RECYCLER(2)

2015-07-21 13:58 - 2015-07-24 13:37 - 00000000 ____D C:\ComboFix(2)

2015-07-19 10:17 - 2015-07-25 11:44 - 00000000 ____D C:\Documents and Settings\Dad\Local Settings\temp

2015-07-19 10:17 - 2015-07-19 22:00 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\temp

2015-07-19 10:17 - 2015-07-19 10:17 - 00017636 _____ C:\ComboFix.txt

2015-07-19 10:17 - 2015-07-19 10:17 - 00000000 ____D C:\Documents and Settings\postgres.PETE-05F6D62355\Local Settings\temp

2015-07-19 10:17 - 2015-07-19 10:17 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\temp

2015-07-19 10:17 - 2015-07-19 10:17 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\temp

2015-07-19 10:17 - 2015-07-19 10:17 - 00000000 ____D C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\temp

2015-07-19 10:17 - 2015-07-19 10:17 - 00000000 ____D C:\Documents and Settings\Administrator.PETE-05F6D62355\Local Settings\temp

2015-07-18 19:18 - 2015-07-18 19:18 - 00008192 ____H C:\WINDOWS\system32\config\security.tmp.LOG

2015-07-18 19:18 - 2015-07-18 19:18 - 00000000 ____H C:\WINDOWS\system32\config\system.tmp.LOG

2015-07-18 19:18 - 2015-07-18 19:18 - 00000000 ____H C:\WINDOWS\system32\config\software.tmp.LOG

2015-07-18 19:18 - 2015-07-18 19:18 - 00000000 ____H C:\WINDOWS\system32\config\sam.tmp.LOG

2015-07-18 19:18 - 2015-07-18 19:18 - 00000000 ____H C:\WINDOWS\system32\config\default.tmp.LOG

2015-07-18 18:49 - 2015-07-24 13:37 - 00000000 ____D C:\cmdcons

2015-07-18 18:49 - 2014-10-14 16:37 - 00000245 _____ C:\Boot.bak

2015-07-18 18:49 - 2004-08-03 23:00 - 00260272 __RSH C:\cmldr

2015-07-17 18:46 - 2015-07-24 13:37 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy

2015-07-17 14:04 - 2015-07-24 13:37 - 00000000 ____D C:\WINDOWS\erdnt

2015-07-17 14:04 - 2015-07-24 13:37 - 00000000 ____D C:\Qoobox

2015-07-16 21:36 - 2015-07-16 21:36 - 00065536 _____ C:\WINDOWS\Minidump\Mini071615-01.dmp

2015-07-16 15:33 - 2015-07-16 15:33 - 00000000 ____D C:\Program Files\VS Revo Group(2)

2015-07-15 05:35 - 2015-07-24 13:40 - 00000000 ____D C:\Documents and Settings\Dad\Desktop\New Folder

2015-07-14 20:51 - 2015-07-21 18:03 - 00000384 _____ C:\runcheck.txt

2015-07-11 22:26 - 2015-07-11 22:26 - 00065536 _____ C:\WINDOWS\Minidump\Mini071115-01.dmp

2015-07-10 12:40 - 2015-07-10 12:40 - 00000000 ____D C:\Program Files\360

2015-07-09 22:28 - 2015-07-24 13:42 - 00000000 ____D C:\Program Files\Mozilla Firefox(2).bak

2015-07-09 20:58 - 2015-07-24 13:46 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\tor

2015-07-08 15:48 - 2015-07-25 01:02 - 00049556 _____ C:\WINDOWS\system32\CFG284806105

2015-07-08 14:27 - 2015-07-24 13:46 - 00000000 ___HD C:\Documents and Settings\All Users\Application Data\{F87DCEF6-04DD-4A4E-8B0F-729ABCA4B397}

2015-07-07 13:45 - 2015-07-24 16:22 - 00000664 _____ C:\Documents and Settings\Dad\Local Settings\Application Data\d3d9caps.dat

2015-06-28 15:38 - 2015-07-24 13:47 - 00000000 ____D C:\Program Files\Dell Support Center

2015-06-28 15:38 - 2015-06-28 15:38 - 00000000 ____D C:\Program Files\Dell

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2015-07-25 11:43 - 2014-10-15 13:33 - 00000000 ____D C:\FRST

2015-07-25 11:43 - 2011-10-16 10:17 - 00000426 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{DFAC5F52-F896-4C64-B364-5AA672E62C68}.job

2015-07-25 11:36 - 2011-03-21 10:38 - 00000000 ____D C:\TEMP

2015-07-25 11:12 - 2012-08-05 07:08 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job

2015-07-25 10:15 - 2011-03-20 19:11 - 01090154 _____ C:\WINDOWS\WindowsUpdate.log

2015-07-25 01:04 - 2011-03-21 10:34 - 00000418 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{C1600535-C1FD-474A-9F2E-A1BAED631CC7}.job

2015-07-25 01:04 - 2011-03-20 19:16 - 00032592 _____ C:\WINDOWS\SchedLgU.Txt

2015-07-25 01:02 - 2013-11-24 18:20 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat

2015-07-25 01:01 - 2014-04-30 13:15 - 00000000 ___RD C:\Documents and Settings\Dad\My Documents\Dropbox

2015-07-25 01:01 - 2014-04-30 13:09 - 00000000 ____D C:\Documents and Settings\Dad\Application Data\Dropbox

2015-07-25 01:01 - 2014-02-21 22:41 - 00000000 ____D C:\Documents and Settings\Dad\Application Data\Skype

2015-07-25 01:00 - 2014-10-16 07:40 - 00000274 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job

2015-07-25 01:00 - 2014-03-27 06:57 - 00000218 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job

2015-07-25 01:00 - 2013-07-27 09:46 - 00000282 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1004.job

2015-07-25 01:00 - 2013-04-27 08:59 - 00000296 _____ C:\WINDOWS\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job

2015-07-25 01:00 - 2013-04-26 09:13 - 00000282 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job

2015-07-25 01:00 - 2011-11-24 15:56 - 00000274 _____ C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job

2015-07-25 01:00 - 2011-06-03 13:00 - 00000282 _____ C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1004.job

2015-07-25 01:00 - 2011-03-20 08:20 - 01415385 _____ C:\WINDOWS\setupapi.log

2015-07-25 00:58 - 2014-06-22 10:21 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service

2015-07-25 00:58 - 2011-03-20 19:16 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT

2015-07-25 00:58 - 2011-03-19 15:30 - 00000159 _____ C:\WINDOWS\wiadebug.log

2015-07-25 00:58 - 2011-03-19 15:30 - 00000049 _____ C:\WINDOWS\wiaservc.log

2015-07-24 17:15 - 2011-03-20 19:35 - 00000178 ___SH C:\Documents and Settings\Dad\ntuser.ini

2015-07-24 16:20 - 2014-06-22 10:21 - 00000730 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk

2015-07-24 16:00 - 2011-03-21 10:37 - 00000000 ____D C:\Program Files\Google

2015-07-24 15:12 - 2012-08-05 07:08 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe

2015-07-24 15:12 - 2011-08-14 07:58 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl

2015-07-24 14:40 - 2011-03-21 13:17 - 00031512 ____C C:\Documents and Settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2015-07-24 14:21 - 2013-08-15 03:16 - 00000000 ____D C:\WINDOWS\system32\MRT

2015-07-24 14:21 - 2004-08-04 06:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl

2015-07-24 14:10 - 2011-03-21 14:00 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Microsoft Help

2015-07-24 14:00 - 2013-07-27 09:46 - 00000290 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1004.job

2015-07-24 13:55 - 2011-03-19 15:17 - 00159544 _____ C:\WINDOWS\system32\FNTCACHE.DAT

2015-07-24 13:54 - 2011-09-19 16:38 - 00000000 ____D C:\Documents and Settings\Administrator.PETE-05F6D62355

2015-07-24 13:54 - 2011-03-22 17:42 - 00000000 ____D C:\Documents and Settings\Caitlin.PETE-05F6D62355

2015-07-24 13:54 - 2011-03-21 13:43 - 00000000 ____D C:\Documents and Settings\postgres.PETE-05F6D62355

2015-07-24 13:54 - 2011-03-20 19:35 - 00000000 ____D C:\Documents and Settings\Dad

2015-07-24 13:54 - 2011-03-20 19:16 - 00000000 __SHD C:\Documents and Settings\LocalService

2015-07-24 13:54 - 2011-03-20 19:15 - 00000000 __SHD C:\Documents and Settings\NetworkService

2015-07-24 13:54 - 2011-03-20 19:08 - 00000000 ____D C:\WINDOWS\Registration

2015-07-24 13:52 - 2014-02-22 00:59 - 00000000 ___RD C:\Program Files\Skype

2015-07-24 13:50 - 2014-07-08 21:46 - 00000000 ____D C:\Documents and Settings\Dad\Local Settings\Application Data\Adobe

2015-07-24 13:50 - 2013-10-13 19:24 - 00000000 ____D C:\Program Files\Juicy Stakes 2.0

2015-07-24 13:50 - 2013-02-28 08:10 - 00000000 ____D C:\Documents and Settings\Dad\Start Menu\Programs\Juicy Stakes 2.0

2015-07-24 13:50 - 2011-04-15 19:57 - 00000000 ____D C:\Program Files\Cake Poker 2.0

2015-07-24 13:48 - 2015-06-17 22:39 - 00000000 ____D C:\Documents and Settings\Dad\Start Menu\Programs\Dropbox(2)

2015-07-24 13:47 - 2014-02-22 14:02 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Dell

2015-07-24 13:47 - 2014-02-22 14:02 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\PCDr

2015-07-24 13:47 - 2014-02-22 13:56 - 00000000 ____D C:\Documents and Settings\Dad\Application Data\PCDr

2015-07-24 13:43 - 2011-06-24 20:13 - 00000000 ____D C:\Documents and Settings\Caitlin.PETE-05F6D62355\Local Settings\Application Data\Coupons.com

2015-07-24 13:42 - 2011-03-20 19:37 - 00000000 ____D C:\Documents and Settings\Dad\Desktop\Wealth Beyond Reason

2015-07-24 13:40 - 2011-04-12 12:15 - 00000000 ____D C:\Documents and Settings\Dad\Application Data\Ahead

2015-07-24 13:39 - 2011-03-21 10:38 - 00000000 ____D C:\Documents and Settings\Dad\Local Settings\Application Data\Google

2015-07-24 10:31 - 2013-04-27 08:59 - 00000304 _____ C:\WINDOWS\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job

2015-07-24 08:23 - 2011-03-22 17:40 - 00000282 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job

2015-07-23 21:28 - 2014-11-12 13:59 - 00005778 _____ C:\WINDOWS\COM+.log

2015-07-23 18:09 - 2014-01-30 18:48 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

2015-07-23 11:46 - 2004-08-04 06:00 - 00000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_21

2015-07-23 11:07 - 2004-08-04 06:00 - 00000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_860

2015-07-21 14:19 - 2013-06-03 17:15 - 00000000 ____D C:\Documents and Settings\Dad\My Documents\Holly Scans

2015-07-21 14:19 - 2011-03-20 19:37 - 00000000 ____D C:\Documents and Settings\Dad\My Documents\1968 Fender Precision

2015-07-21 14:16 - 2011-03-19 15:21 - 02323960 _____ C:\WINDOWS\FaxSetup.log

2015-07-21 14:16 - 2011-03-19 15:21 - 01159178 _____ C:\WINDOWS\ocgen.log

2015-07-21 14:16 - 2011-03-19 15:21 - 01088957 _____ C:\WINDOWS\tsoc.log

2015-07-21 14:16 - 2011-03-19 15:21 - 00755889 _____ C:\WINDOWS\iis6.log

2015-07-21 14:16 - 2011-03-19 15:21 - 00736088 _____ C:\WINDOWS\msmqinst.log

2015-07-21 14:16 - 2011-03-19 15:21 - 00666573 _____ C:\WINDOWS\comsetup.log

2015-07-21 14:16 - 2011-03-19 15:21 - 00411892 _____ C:\WINDOWS\netfxocm.log

2015-07-21 14:16 - 2011-03-19 15:21 - 00410430 _____ C:\WINDOWS\ntdtcsetup.log

2015-07-21 14:16 - 2011-03-19 15:21 - 00163691 _____ C:\WINDOWS\MedCtrOC.log

2015-07-21 14:16 - 2011-03-19 15:21 - 00120188 _____ C:\WINDOWS\tabletoc.log

2015-07-21 14:16 - 2011-03-19 15:21 - 00118105 _____ C:\WINDOWS\msgsocm.log

2015-07-21 14:16 - 2011-03-19 15:21 - 00109201 _____ C:\WINDOWS\ocmsn.log

2015-07-21 14:16 - 2011-03-19 15:21 - 00001917 _____ C:\WINDOWS\imsins.log

2015-07-20 16:19 - 2013-04-27 08:59 - 00000322 _____ C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job

2015-07-20 15:45 - 2011-06-03 13:00 - 00000290 _____ C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1004.job

2015-07-19 21:43 - 2014-10-14 20:08 - 00000000 ____D C:\AdwCleaner

2015-07-19 10:15 - 2004-08-04 06:00 - 00000227 _____ C:\WINDOWS\system.ini

2015-07-18 19:20 - 2004-08-04 06:00 - 00000027 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_259

2015-07-18 19:19 - 2011-03-19 15:17 - 00073728 _____ C:\WINDOWS\system32\config\security.bak

2015-07-18 19:19 - 2011-03-19 15:17 - 00028672 _____ C:\WINDOWS\system32\config\sam.bak

2015-07-18 19:19 - 2011-03-19 15:16 - 38535168 _____ C:\WINDOWS\system32\config\software.bak

2015-07-18 19:19 - 2011-03-19 15:16 - 11272192 _____ C:\WINDOWS\system32\config\system.bak

2015-07-18 19:19 - 2011-03-19 15:16 - 00524288 _____ C:\WINDOWS\system32\config\default.bak

2015-07-17 13:47 - 2011-03-20 19:08 - 00048276 _____ C:\WINDOWS\wmsetup.log

2015-07-17 13:47 - 2004-08-04 06:00 - 00000726 _____ C:\WINDOWS\win.ini

2015-07-16 21:36 - 2011-03-20 03:10 - 2145386496 _____ C:\WINDOWS\MEMORY.DMP

2015-07-16 21:36 - 2011-03-19 15:19 - 00000000 ____D C:\WINDOWS\Minidump

2015-07-03 08:49 - 2011-03-21 10:25 - 127070192 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

2015-06-30 07:39 - 2013-11-13 04:23 - 01197296 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

2015-06-28 16:32 - 2014-02-22 09:09 - 00000000 ____D C:\Documents and Settings\Dad\Local Settings\Application Data\Deployment

 

==================== Files in the root of some directories =======

 

2011-03-21 13:44 - 2011-03-21 13:44 - 0068381 ____C () C:\Program Files\hminstalllog.txt

2015-07-07 13:45 - 2015-07-24 16:22 - 0000664 _____ () C:\Documents and Settings\Dad\Local Settings\Application Data\d3d9caps.dat

2011-03-23 16:29 - 2014-10-05 09:30 - 0029696 ____C () C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

2013-04-24 18:03 - 2013-04-24 18:03 - 0002243 ____C () C:\Documents and Settings\Dad\Local Settings\Application Data\recently-used.xbel

2007-01-16 20:36 - 2007-01-16 20:36 - 1468195 ____C () C:\Documents and Settings\All Users\P1160014.JPG

 

Some files in TEMP:

====================

C:\Documents and Settings\Dad\Local Settings\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp9l73kt.dll

 

 

==================== Bamital & volsnap Check =================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\WINDOWS\explorer.exe => File is digitally signed

C:\WINDOWS\system32\winlogon.exe => File is digitally signed

C:\WINDOWS\system32\svchost.exe => File is digitally signed

C:\WINDOWS\system32\services.exe => File is digitally signed

C:\WINDOWS\system32\User32.dll => File is digitally signed

C:\WINDOWS\system32\userinit.exe => File is digitally signed

C:\WINDOWS\system32\rpcss.dll => File is digitally signed

C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

 

==================== End of log ============================

 

 

Now The Addition Txt.

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 25-07-2015

Ran by [removed] at 2015-07-25 11:45:41

Running from C:\Documents and Settings\[removed]\Desktop

Boot Mode: Normal

==========================================================

 

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-1844237615-515967899-725345543-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator.PETE-05F6D62355

Caitlin (S-1-5-21-1844237615-515967899-725345543-1004 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Caitlin.PETE-05F6D62355

Dad (S-1-5-21-1844237615-515967899-725345543-1005 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Dad

Guest (S-1-5-21-1844237615-515967899-725345543-501 - Limited - Disabled)

HelpAssistant (S-1-5-21-1844237615-515967899-725345543-1000 - Limited - Disabled)

postgres (S-1-5-21-1844237615-515967899-725345543-1006 - Limited - Enabled) => %SystemDrive%\Documents and Settings\postgres.PETE-05F6D62355

SUPPORT_388945a0 (S-1-5-21-1844237615-515967899-725345543-1002 - Limited - Disabled)

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: Microsoft Security Essentials (Disabled - Up to date) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

 

==================== Installed Programs ======================

 

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

3ivx MPEG-4 5.0.3 (remove only) (HKLM\…\3ivx MPEG-4 5.0.3) (Version: 5.0.3 - 3ivx Technologies, Pty. Ltd.)

AAC/MP4 Plugin (Free/GPL) 1.1 (HKLM\…\AAC/MP4 Plugin (Free/GPL), install for Mind Stereo_is1) (Version:  - Transparent Corporation)

Adobe Acrobat 4.0 (HKLM\…\Adobe Acrobat 4.0) (Version: 4.0 - Adobe Systems, Inc.)

Adobe AIR (HKLM\…\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)

Adobe Download Assistant (HKLM\…\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.5 - Adobe Systems Incorporated)

Adobe Flash Player 18 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)

Adobe Flash Player 18 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)

Adobe PhotoDeluxe Home Edition 4.0 (HKLM\…\Adobe PhotoDeluxe Home Edition 4.0) (Version: 4.0 - Adobe Systems, Inc.)

Adobe Reader XI (11.0.08) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)

Adobe Shockwave Player 12.1 (HKLM\…\Adobe Shockwave Player) (Version: 12.1.7.157 - Adobe Systems, Inc.)

Amazon Kindle (HKLM\…\Amazon Kindle) (Version:  - Amazon)

Apple Application Support (32-bit) (HKLM\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)

Apple Mobile Device Support (HKLM\…\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)

Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)

Atmosphere Lite v5.0 (HKLM\…\Atmosphere Lite (Boundless Living Edition)_is1) (Version:  - Vectormedia Software)

Atmosphere Lite v7.0 (HKLM\…\Atmosphere Lite_is1) (Version:  - Vectormedia Software.)

Audacity 1.3.12 (Unicode) (HKLM\…\Audacity 1.3 Beta (Unicode)_is1) (Version:  - Audacity Team)

Audacity 2.0 (HKLM\…\Audacity_is1) (Version:  - Audacity Team)

Audible Download Manager (HKLM\…\AudibleDownloadManager) (Version: 6.6.0.15 - Audible, Inc.)

Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)

Canon MP250 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series) (Version:  - )

CutePDF Writer 3.0 (HKLM\…\CutePDF Writer Installation) (Version:  3.0 - CutePDF.com)

Dell ResourceCD (HKLM\…\{D78653C3-A8FF-415F-92E6-D774E634FF2D}) (Version:  - )

Dell System Detect (HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\73f463568823ebbe) (Version: 5.12.0.3 - Dell)

Drivers (HKLM\…\{6ABA1658-6429-4D01-875C-0EA6EE851AD1}) (Version:  - )

Dropbox (HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\Dropbox) (Version: 3.6.9 - Dropbox, Inc.)

Extended Asian Language font pack for Adobe Reader XI (HKLM\…\{AC76BA86-7AD7-2530-0000-A00000000004}) (Version: 11.0.0 - Adobe Systems Incorporated)

FlipShare (HKLM\…\{0D3F9802-689F-9B6D-8E44-B55971F0CCBB}) (Version: 4.5.0.39816 - Flip Video)

Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden

GPL Ghostscript (HKLM\…\GPL Ghostscript 9.06) (Version: 9.06 - Artifex Software Inc.)

High Definition Audio Driver Package - KB888111 (HKLM\…\KB888111WXPSP2) (Version: 20040219.000000 - Microsoft Corporation)

Holdem Manager (HKLM\…\HoldemManager) (Version:  - )

iSEEK AnswerWorks English Runtime (HKLM\…\{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}) (Version: [removed] - Vantage Linguistics)

iTunes (HKLM\…\{CE1F04C7-79BC-4219-BE6A-BA490224D4B5}) (Version: 12.1.2.27 - Apple Inc.)

J2SE Runtime Environment 5.0 Update 16 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0150160}) (Version: 1.5.0.160 - Sun Microsystems, Inc.)

Juicy Stakes 2.0 (HKLM\…\Juicy Stakes 2.0) (Version: 2.0.1.8336 - Juicy Stakes)

LAME v3.99.3 (for Windows) (HKLM\…\LAME_is1) (Version:  - )

Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)

Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)

Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)

Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)

Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\…\MSCompPackV1) (Version: 1 - Microsoft Corporation)

Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)

Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)

Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)

Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)

Microsoft User-Mode Driver Framework Feature Pack 1.9 (HKLM\…\Wudf01009) (Version:  - Microsoft Corporation)

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\…\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft WinUsb 1.0 (HKLM\…\winusb0100) (Version:  - Microsoft Corporation)

Mind Stereo 1.1.3 (HKLM\…\Mind Stereo_is1) (Version:  - Transparent Corporation)

Mozilla Firefox 39.0 (x86 en-US) (HKLM\…\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla)

Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 39.0 - Mozilla)

MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)

MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)

MSXML 6 Service Pack 2 (KB973686) (HKLM\…\{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}) (Version: 6.20.2003.0 - Microsoft Corporation)

Nero Suite (HKLM\…\NeroMultiInstaller!UninstallKey) (Version:  - )

NETGEAR WNDA3100v2 wireless USB 2.0 adapter (HKLM\…\{3C7839E7-21F4-49E0-B4D5-AC8ED818CCB0}) (Version: 2.2.0.3 - NETGEAR)

PDF to JPG Converter 1.3 (HKLM\…\PDF to JPG Converter) (Version: 1.3 - )

Poker Calculator Pro (HKLM\…\Poker Calculator Pro) (Version:  - Poker Pro Labs)

PokerStars.net (HKLM\…\PokerStars.net) (Version:  - PokerStars.net)

PostgreSQL 8.4 (HKLM\…\PostgreSQL 8.4) (Version: 8.4 - PostgreSQL Global Development Group)

Quicken 2011 (HKLM\…\{5FE545A1-D215-4216-9189-E7B39C9D1CC1}) (Version: 20.1.8.6 - Intuit)

QuickShare (HKLM\…\{11D4FAA0-A577-4FA8-B24E-D24283D861D1}) (Version: 11.24.60.15709 - Linkury Inc.) <==== ATTENTION

QuickTime (HKLM\…\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)

RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden

RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden

RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden

RealPlayer (HKLM\…\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)

Realtek AC'97 Audio (HKLM\…\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version: 5.36 - Realtek Semiconductor Corp.)

Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.7083 - Realtek Semiconductor Corp.)

RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden

Revo Uninstaller 1.95 (HKLM\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)

Skype™ 7.0 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)

SoundMAX (HKLM\…\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 5.10.01.4541 - Analog Devices)

swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden

TomTom HOME (HKLM\…\{99072AB4-D795-44D5-9D65-E3C9F8322C97}) (Version: 2.9.7 - TomTom)

TomTom HOME Visual Studio Merge Modules (HKLM\…\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)

Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)

Virtual Sound Canvas 3.2 (HKLM\…\VSC32) (Version:  - )

VoiceOver Kit (HKLM\…\{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}) (Version: 1.42.128.0 - Apple Inc.)

WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden

Windows Imaging Component (HKLM\…\WIC) (Version: 3.0.0.0 - Microsoft Corporation)

Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)

Windows Media Format 11 runtime (HKLM\…\Windows Media Format Runtime) (Version:  - )

Windows Media Player 11 (HKLM\…\Windows Media Player) (Version:  - )

Windows PowerShell(TM) 1.0 (HKLM\…\KB926139-v2) (Version: 2 - Microsoft Corporation)

Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)

WinZip 17.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DC}) (Version: 17.5.10562 - WinZip Computing, S.L. )

Wireless Client Manager (HKLM\…\{27678F85-7234-4CEB-B84D-2C44E9C4B18E}) (Version:  - )

Yahoo! Detect (HKLM\…\YTdetect) (Version:  - )

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.29\psuser.dll No (the data entry has 5 more characters).

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{E69341A3-E6D2-4175-B60C-C9D3D6FA40F6}\localserver32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\Dad\Application Data\Dropbox\bin\DropboxExt.26.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-1844237615-515967899-725345543-1005_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)

 

==================== Restore Points =========================

 

26-04-2015 21:15:19 System Checkpoint

27-04-2015 21:49:07 System Checkpoint

28-04-2015 21:50:54 System Checkpoint

29-04-2015 22:39:56 System Checkpoint

30-04-2015 22:43:50 System Checkpoint

01-05-2015 22:51:17 System Checkpoint

02-05-2015 23:31:49 System Checkpoint

04-05-2015 00:33:19 System Checkpoint

05-05-2015 01:21:45 System Checkpoint

06-05-2015 01:45:07 System Checkpoint

07-05-2015 02:32:32 System Checkpoint

08-05-2015 06:38:48 System Checkpoint

09-05-2015 12:47:59 System Checkpoint

10-05-2015 12:58:35 System Checkpoint

11-05-2015 13:13:11 System Checkpoint

12-05-2015 14:08:31 System Checkpoint

13-05-2015 07:25:40 Software Distribution Service 3.0

14-05-2015 15:08:11 System Checkpoint

15-05-2015 16:12:00 System Checkpoint

16-05-2015 17:20:04 System Checkpoint

17-05-2015 18:16:07 System Checkpoint

18-05-2015 18:40:08 System Checkpoint

19-05-2015 19:29:44 System Checkpoint

20-05-2015 20:00:53 System Checkpoint

21-05-2015 20:33:01 System Checkpoint

23-05-2015 00:24:14 System Checkpoint

24-05-2015 00:53:03 System Checkpoint

25-05-2015 01:45:56 System Checkpoint

26-05-2015 02:37:25 System Checkpoint

27-05-2015 07:54:46 System Checkpoint

28-05-2015 08:03:47 System Checkpoint

29-05-2015 11:02:55 System Checkpoint

30-05-2015 11:53:37 System Checkpoint

31-05-2015 18:53:38 System Checkpoint

01-06-2015 19:05:02 System Checkpoint

02-06-2015 19:25:57 System Checkpoint

03-06-2015 20:07:02 System Checkpoint

04-06-2015 20:16:26 System Checkpoint

05-06-2015 23:49:04 System Checkpoint

07-06-2015 00:05:46 System Checkpoint

08-06-2015 01:12:47 System Checkpoint

09-06-2015 02:05:59 System Checkpoint

10-06-2015 02:58:42 System Checkpoint

10-06-2015 09:00:16 Software Distribution Service 3.0

11-06-2015 13:18:59 System Checkpoint

12-06-2015 13:35:26 System Checkpoint

13-06-2015 23:07:12 System Checkpoint

14-06-2015 23:42:34 System Checkpoint

15-06-2015 23:48:26 System Checkpoint

16-06-2015 23:58:20 System Checkpoint

18-06-2015 00:39:41 System Checkpoint

19-06-2015 01:30:34 System Checkpoint

20-06-2015 02:22:23 System Checkpoint

21-06-2015 07:54:02 System Checkpoint

22-06-2015 15:02:49 System Checkpoint

23-06-2015 15:18:30 System Checkpoint

24-06-2015 15:21:50 System Checkpoint

25-06-2015 16:04:10 System Checkpoint

26-06-2015 16:58:03 System Checkpoint

27-06-2015 17:09:57 System Checkpoint

28-06-2015 17:10:16 System Checkpoint

29-06-2015 17:19:00 System Checkpoint

30-06-2015 17:49:46 System Checkpoint

01-07-2015 18:08:15 System Checkpoint

02-07-2015 18:08:58 System Checkpoint

03-07-2015 18:43:09 System Checkpoint

04-07-2015 19:31:49 System Checkpoint

05-07-2015 19:41:23 System Checkpoint

06-07-2015 20:09:32 System Checkpoint

07-07-2015 20:47:54 System Checkpoint

08-07-2015 15:43:20 Restore Operation

09-07-2015 06:46:06 Restore Operation

09-07-2015 21:18:52 Restore Operation

09-07-2015 22:03:42 Software Distribution Service 3.0

09-07-2015 22:30:41 Restore Operation

10-07-2015 22:46:19 System Checkpoint

11-07-2015 22:47:54 Restore Operation

12-07-2015 23:18:08 System Checkpoint

14-07-2015 00:16:29 System Checkpoint

15-07-2015 00:39:38 System Checkpoint

15-07-2015 09:00:40 Software Distribution Service 3.0

16-07-2015 06:09:07 Removed Google Earth.

16-07-2015 06:12:26 Removed Fuze Meeting

16-07-2015 15:34:15 Revo Uninstaller's restore point - HijackThis Packages

16-07-2015 17:07:03 Revo Uninstaller's restore point - Google Chrome

16-07-2015 17:11:32 Revo Uninstaller's restore point - Chromium

16-07-2015 17:48:56 Revo Uninstaller's restore point - Google Chrome

16-07-2015 17:59:56 Revo Uninstaller's restore point - Google Chrome

16-07-2015 18:01:07 Revo Uninstaller's restore point - Google Chrome

18-07-2015 18:46:59 ComboFix created restore point

19-07-2015 22:26:19 System Checkpoint

20-07-2015 06:05:03 Revo Uninstaller's restore point - Malwarebytes Anti-Malware version 2.0.4.1028

21-07-2015 06:15:10 System Checkpoint

22-07-2015 06:48:27 System Checkpoint

22-07-2015 11:28:27 Revo Uninstaller's restore point - Google Chrome

23-07-2015 12:23:42 System Checkpoint

24-07-2015 12:32:46 System Checkpoint

24-07-2015 13:34:48 Restore Operation

24-07-2015 14:03:34 Software Distribution Service 3.0

24-07-2015 14:31:31 Removed Fuze Meeting

24-07-2015 15:56:54 Revo Uninstaller's restore point - Mozilla Firefox 37.0.2 (x86 en-US)

24-07-2015 15:59:29 Revo Uninstaller's restore point - Mozilla Firefox 37.0.2 (x86 en-US)

24-07-2015 16:00:24 Revo Uninstaller's restore point - Google Earth

24-07-2015 16:00:37 Removed Google Earth.

24-07-2015 16:02:17 Revo Uninstaller's restore point - Malwarebytes Anti-Malware version 2.0.4.1028

 

==================== Hosts content: ==========================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2004-08-04 06:00 - 2015-07-23 21:24 - 00000855 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1       localhost

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe

Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1844237615-515967899-725345543-1005Core.job => C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\DropboxUpdate.exe

Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1844237615-515967899-725345543-1005UA.job => C:\Documents and Settings\Dad\Local Settings\Application Data\Dropbox\Update\DropboxUpdate.exe

Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe

Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe

Task: C:\WINDOWS\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe

Task: C:\WINDOWS\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe

Task: C:\WINDOWS\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe

Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe

Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe

Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe

Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe

Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe

Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe

Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1004.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe

Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-515967899-725345543-1005.job => C:\Program Files\Real\RealUpgrade\realupgrade.exe

Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{C1600535-C1FD-474A-9F2E-A1BAED631CC7}.job => C:\WINDOWS\system32\msfeedssync.exe

Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{DFAC5F52-F896-4C64-B364-5AA672E62C68}.job => C:\WINDOWS\system32\msfeedssync.exe

 

==================== Loaded Modules (Whitelisted) ==============

 

2013-03-09 14:25 - 2012-10-04 19:50 - 00088688 _____ () C:\WINDOWS\system32\cpwmon2k.dll

2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll

2015-01-20 23:35 - 2015-01-20 23:35 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll

2009-06-04 17:41 - 2009-06-04 17:41 - 00451904 _____ () C:\Program Files\Flip Video\FlipShare\FlipShareService.exe

2009-06-04 17:37 - 2009-06-04 17:37 - 01581056 _____ () C:\Program Files\Flip Video\FlipShare\QtCore4.dll

2011-03-21 13:41 - 2009-09-08 03:48 - 00172032 _____ () C:\Program Files\PostgreSQL\8.4\bin\LIBPQ.dll

2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe

2011-03-21 13:41 - 2009-02-12 15:01 - 00976384 _____ () C:\Program Files\PostgreSQL\8.4\bin\libxml2.dll

2011-03-21 13:41 - 2005-07-20 06:48 - 00059904 _____ () C:\Program Files\PostgreSQL\8.4\bin\zlib1.dll

2014-11-15 13:26 - 2013-11-11 16:10 - 00307928 _____ () C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe

2014-11-15 13:26 - 2013-12-05 15:06 - 00319488 _____ () C:\Program Files\NETGEAR\WNDA3100v2\WifiLib.dll

2014-11-15 13:26 - 2013-12-09 18:01 - 08385240 _____ () C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe

2014-11-15 13:26 - 2013-11-01 18:31 - 00278528 _____ () C:\Program Files\NETGEAR\WNDA3100v2\WifiSvcLib.dll

2015-07-25 01:00 - 2015-07-25 01:00 - 00043008 _____ () c:\Documents and Settings\Dad\Local Settings\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp9l73kt.dll

2015-03-04 17:45 - 2015-03-19 03:15 - 00750080 _____ () C:\Documents and Settings\Dad\Application Data\Dropbox\bin\libGLESv2.dll

2015-03-04 17:45 - 2015-03-19 03:15 - 00047616 _____ () C:\Documents and Settings\Dad\Application Data\Dropbox\bin\libEGL.dll

2015-03-04 17:45 - 2015-03-19 03:15 - 00865280 _____ () C:\Documents and Settings\Dad\Application Data\Dropbox\bin\plugins\platforms\qwindows.dll

2015-03-04 17:45 - 2015-03-19 03:15 - 00200704 _____ () C:\Documents and Settings\Dad\Application Data\Dropbox\bin\plugins\imageformats\qjpeg.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

AlternateDataStreams: C:\Documents and Settings\Dad\My Documents\My Ideal Day.docx:com.dropbox.attributes

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

 

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

 

==================== EXE Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

IE trusted site: HKU\S-1-5-21-1844237615-515967899-725345543-1005\…\dell.com -> dell.com

 

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-21-1844237615-515967899-725345543-1005\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Dad\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

HKU\S-1-5-21-1844237615-515967899-725345543-1006\Control Panel\Desktop\\Wallpaper -> (None)

DNS Servers: [removed] - [removed]

Windows Firewall is enabled.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

(Currently there is no automatic fix for this section.)

 

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE] => Enabled:Microsoft Office OneNote

StandardProfile\AuthorizedApplications: [C:\Program Files\PPN Poker\PokerClient.exe] => Enabled:PPN Poker

StandardProfile\AuthorizedApplications: [C:\Program Files\PPN Poker\PokerUpdate.exe] => Disabled:PokerUpdate

StandardProfile\AuthorizedApplications: [C:\Program Files\Cake Poker 2.0\PokerClient.exe] => Enabled:Cake Poker 2.0

StandardProfile\AuthorizedApplications: [C:\Program Files\FrostWire 5\FrostWire.exe] => Enabled:FrostWire

StandardProfile\AuthorizedApplications: [C:\Program Files\Java\jre6\bin\javaw.exe] => Enabled:Java(TM) Platform SE binary

StandardProfile\AuthorizedApplications: [C:\Program Files\Pure Poker 2.0\PokerClient.exe] => Enabled:Pure Poker 2.0

StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service

StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Dad\Local Settings\Application Data\Fuze Box\Fuze Meeting\Fuze_Meeting.exe] => Enabled:Fuze Meeting

StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Dad\Application Data\Dropbox\bin\Dropbox.exe] => Enabled:Dropbox

StandardProfile\AuthorizedApplications: [C:\Documents and Settings\All Users\Application Data\EmailNotifier\EmailNotifier.exe] => Enabled:Email Notifier

StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Google Talk\googletalk.exe] => Enabled:Google Talk

StandardProfile\AuthorizedApplications: [C:\Program Files\Skype\Phone\Skype.exe] => Enabled:Skype

StandardProfile\AuthorizedApplications: [C:\Program Files\Juicy Stakes 2.0\PokerClient.exe] => Enabled:Juicy Stakes 2.0

StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes

StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)

StandardProfile\GloballyOpenPorts: [5432:TCP] => Enabled:postgres

 

==================== Faulty Device Manager Devices =============

 

Name: Video Controller (VGA Compatible)

Description: Video Controller (VGA Compatible)

Class Guid: {4D36E97E-E325-11CE-BFC1-08002BE10318}

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

 

Name: SM Bus Controller

Description: SM Bus Controller

Class Guid: {4D36E97E-E325-11CE-BFC1-08002BE10318}

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

 

Name: PCI Simple Communications Controller

Description: PCI Simple Communications Controller

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

 

Name: Ethernet Controller

Description: Ethernet Controller

Class Guid:

Manufacturer:

Service:

Problem: : This device is not configured correctly. (Code1)

Resolution: You may be prompted to provide the path of the driver. Windows may have the driver built-in, or may still have the driver files installed from the last time that you set up the device. If you are asked for the driver and you do not have it, you can try to download the latest driver from the hardware vendor�s Web site.

In the device properties dialog box, click the "Driver" tab, and then click "Update Driver" to start the "Hardware Update Wizard". Follow the instructions to update the driver. If updating the driver does not work, see your hardware documentation for more information.

 

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (07/25/2015 12:58:51 AM) (Source: PostgreSQL) (EventID: 0) (User: )

Description: 2015-07-25 00:58:51 EDTFATAL:  the database system is starting up

 

Error: (07/24/2015 04:07:51 PM) (Source: PostgreSQL) (EventID: 0) (User: )

Description: 2015-07-24 16:07:51 EDTFATAL:  the database system is starting up

 

Error: (07/24/2015 03:48:34 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module unknown, version 0.0.0.0, fault address 0x00013e58.

Processing media-specific event for [iexplore.exe!ws!]

 

Error: (07/24/2015 03:41:52 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module unknown, version 0.0.0.0, fault address 0x00013e58.

Processing media-specific event for [iexplore.exe!ws!]

 

Error: (07/24/2015 03:40:30 PM) (Source: Application Hang) (EventID: 1002) (User: )

Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error: (07/24/2015 03:36:27 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application chrome.exe, version 42.0.2311.90, faulting module chrome.dll, version 42.0.2311.90, fault address 0x0051f9eb.

Processing media-specific event for [chrome.exe!ws!]

 

Error: (07/24/2015 02:41:10 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application chrome.exe, version 42.0.2311.90, faulting module chrome.dll, version 42.0.2311.90, fault address 0x0051f9eb.

Processing media-specific event for [chrome.exe!ws!]

 

Error: (07/24/2015 02:40:57 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application chrome.exe, version 42.0.2311.90, faulting module chrome.dll, version 42.0.2311.90, fault address 0x0051f9eb.

Processing media-specific event for [chrome.exe!ws!]

 

Error: (07/24/2015 02:40:47 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application chrome.exe, version 42.0.2311.90, faulting module chrome.dll, version 42.0.2311.90, fault address 0x0051f9eb.

Processing media-specific event for [chrome.exe!ws!]

 

Error: (07/24/2015 02:36:16 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module unknown, version 0.0.0.0, fault address 0x00013e58.

Processing media-specific event for [iexplore.exe!ws!]

 

 

System errors:

=============

Error: (07/25/2015 12:58:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The MBAMService service failed to start due to the following error:

%%1053

 

Error: (07/25/2015 12:58:51 AM) (Source: Service Control Manager) (EventID: 7009) (User: )

Description: Timeout (30000 milliseconds) waiting for the MBAMService service to connect.

 

Error: (07/25/2015 12:58:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The MBAMScheduler service failed to start due to the following error:

%%1053

 

Error: (07/25/2015 12:58:51 AM) (Source: Service Control Manager) (EventID: 7009) (User: )

Description: Timeout (30000 milliseconds) waiting for the MBAMScheduler service to connect.

 

Error: (07/25/2015 12:58:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The Zune Bus Enumerator Driver service failed to start due to the following error:

%%2

 

Error: (07/24/2015 04:07:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The MBAMService service failed to start due to the following error:

%%1053

 

Error: (07/24/2015 04:07:51 PM) (Source: Service Control Manager) (EventID: 7009) (User: )

Description: Timeout (30000 milliseconds) waiting for the MBAMService service to connect.

 

Error: (07/24/2015 04:07:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The MBAMScheduler service failed to start due to the following error:

%%1053

 

Error: (07/24/2015 04:07:51 PM) (Source: Service Control Manager) (EventID: 7009) (User: )

Description: Timeout (30000 milliseconds) waiting for the MBAMScheduler service to connect.

 

Error: (07/24/2015 04:07:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The Zune Bus Enumerator Driver service failed to start due to the following error:

%%2

 

 

Microsoft Office:

=========================

 

==================== Memory info ===========================

 

Processor:  Intel(R) Celeron(R) CPU 3.06GHz

Percentage of memory in use: 22%

Total physical RAM: 3037.93 MB

Available physical RAM: 2357.88 MB

Total Virtual: 4924.02 MB

Available Virtual: 4438.65 MB

 

==================== Drives ================================

 

Drive c: () (Fixed) (Total:931.5 GB) (Free:845.72 GB) NTFS ==>[drive with boot components (Windows XP)]

Drive d: (My Disc) (CDROM) (Total:0.04 GB) (Free:0 GB) CDFS

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: D04FD04F)

Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)

 

==================== End of log ============================

Thir log requested:

 

Results of screen317's Security Check version 1.005 

   x86  

``````````````Antivirus/Firewall Check:``````````````

 Windows Security Center service is not running! This report may not be accurate!

 WMI entry may not exist for antivirus; attempting automatic update.

`````````Anti-malware/Other Utilities Check:`````````

 Adobe Flash Player        18.0.0.209 

 Mozilla Firefox (39.0)

````````Process Check: objlist.exe by Laurent```````` 

`````````````````System Health check`````````````````

 Total Fragmentation on Drive C:: 9%

````````````````````End of Log``````````````````````

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI