Here are my logs. Thanks for the download info and clarification on FRST. One problem was tha t AVG kept deleting FRST since it thought it was malware. I disabled it twice. It even deleted it after the scan so 3 times all together.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-07-2015
Ran by [removed] (administrator) on HAK-PC on 17-07-2015 03:19:24
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft® Windows Vista™ Home Basic (X86) OS Language: English (United States)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-07-2015
Ran by [removed] at 2015-07-17 03:20:49
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1992874582-3349113656-4066416677-500 - Administrator - Disabled)
Guest (S-1-5-21-1992874582-3349113656-4066416677-501 - Limited - Disabled)
Sharon (S-1-5-21-1992874582-3349113656-4066416677-1001 - Administrator - Enabled) => C:\Users\Sharon
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
7-Zip 9.20 (HKLM\…\7-Zip) (Version: - )
Adobe Flash Player 18 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 9 ActiveX (HKLM\…\ShockwaveFlash) (Version: 9 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Atheros Driver Installation Program (HKLM\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.1 - Atheros)
Audacity 2.0.3 (HKLM\…\Audacity_is1) (Version: 2.0.3 - Audacity Team)
AVG 2015 (HKLM\…\AVG) (Version: 2015.0.6081 - AVG Technologies)
AVG 2015 (Version: 15.0.4392 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.6081 - AVG Technologies) Hidden
AVG PC TuneUp 2014 (en-US) (Version: 14.0.1001.519 - AVG) Hidden
AVG PC TuneUp 2014 (HKLM\…\AVG PC TuneUp) (Version: 14.0.1001.519 - AVG)
AVG PC TuneUp 2014 (Version: 14.0.1001.519 - AVG) Hidden
BufferChm (Version: 82.0.173.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.07 - Piriform)
Citrix Online Launcher (HKLM\…\{C57F6C71-C365-4AFF-9108-397BBAD6127F}) (Version: 1.0.204 - Citrix)
Copy (Version: 82.0.188.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Destinations (Version: 82.0.173.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
DocProc (Version: 8.1.0.0 - Hewlett-Packard) Hidden
DocProcQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Elementary Education: Content Knowledge Practice Test (HKLM\…\{0AED2370-A4CD-4D5A-A6FA-32DE353DAE4C}) (Version: 2.0 - Educational Testing Service)
Emsisoft Anti-Malware (HKLM\…\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 10.0 - Emsisoft Ltd.)
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Freemake Video Converter version 4.0.1 (HKLM\…\Freemake Video Converter_is1) (Version: 4.0.1 - Ellora Assets Corporation)
Freemake Video Downloader (HKLM\…\Freemake Video Downloader_is1) (Version: 3.5.0 - Ellora Assets Corporation)
FreeScreenSharing (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\FreeScreenSharing) (Version: 0.56.21.0 - Free Conferencing Corporation)
Google Chrome (HKLM\…\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Talk Plugin (HKLM\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
GoToMeeting 7.2.3.3019 (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\GoToMeeting) (Version: 7.2.3.3019 - CitrixOnline)
HP Customer Experience Enhancements (HKLM\…\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.1.0.2264 - Hewlett-Packard)
HP Customer Participation Program 8.0 (HKLM\…\HPExtendedCapabilities) (Version: 8.0 - HP)
HP Easy Setup - Frontend (HKLM\…\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.1.0.2269 - Hewlett-Packard)
HP Imaging Device Functions 8.0 (HKLM\…\HP Imaging Device Functions) (Version: 8.0 - HP)
HP OCR Software 8.0 (HKLM\…\HPOCR) (Version: 8.0 - HP)
HP OFFICEJET 6210 Driver Utility (HKLM\…\HP OFFICEJET 6210 Driver Utility_is1) (Version: - Lavians Inc.)
HP Photosmart Essential (HKLM\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
HP Photosmart Essential 2.0 (HKLM\…\HP Photosmart Essential) (Version: 2.0 - HP)
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (HKLM\…\{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}) (Version: 8.0 - HP)
HP Solution Center 8.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 8.0 - HP)
HP Update (HKLM\…\{8C6027FD-53DC-446D-BB75-CACD7028A134}) (Version: 4.000.005.005 - Hewlett-Packard)
HPProductAssistant (Version: 82.0.173.000 - Hewlett-Packard) Hidden
HPSSupply (HKLM\…\{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}) (Version: 2.1.3.0000 - Hewlett Packard Development Company L.P.)
Image Resizer for Windows (HKLM\…\{69d72156-6582-4556-8637-06f40aa7f85b}) (Version: 3.0.4802.35565 - Brice Lambson)
Image Resizer for Windows (Version: 3.0.4802.35565 - Brice Lambson) Hidden
LightScribe 1.4.142.1 (Version: 1.4.142.1 - http://www.lightscribe.com)Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
MarketResearch (Version: 82.0.174.000 - Hewlett-Packard) Hidden
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\…\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
Mozilla Firefox 39.0 (x86 en-US) (HKLM\…\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 39.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM\…\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
muvee autoProducer 6.0 (HKLM\…\{6AF49698-949A-4C89-9B31-041D2CCB5FBD}) (Version: 6.00.050 - muvee Technologies)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: - )
OLYMPUS Master 2 (HKLM\…\{45FCADDB-0B29-457E-83A1-D245C62A716C}) (Version: 1.0.6 - OLYMPUS IMAGING CORP.)
OLYMPUS muvee theaterPack (HKLM\…\{B3282FB8-874B-4054-8356-9EB391A826F9}) (Version: 1.0.4 - OLYMPUS IMAGING CORP.)
OpenOffice.org 3.4.1 (HKLM\…\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)
Picasa 3 (HKLM\…\Picasa 3) (Version: 3.9 - Google, Inc.)
PSSWCORE (Version: 2.00.5000 - Hewlett-Packard) Hidden
Python 2.4.3 (HKLM\…\{75E71ADD-042C-4F30-BFAC-A9EC42351313}) (Version: 2.4.3150 - Martin v. Löwis)
QuickTime (HKLM\…\{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}) (Version: 7.1.3.100 - Apple Computer, Inc.)
RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\…\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5377 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Rhapsody Player Engine (HKLM\…\{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}) (Version: 1.0.604 - RealNetworks)
Roxio Creator Audio (HKLM\…\{83FFCFC7-88C6-41c6-8752-958A45325C82}) (Version: 3.4.0 - Roxio)
Roxio Creator Basic v9 (HKLM\…\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}) (Version: 3.4.0 - Roxio)
Roxio Creator Copy (HKLM\…\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio)
Roxio Creator Data (HKLM\…\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio)
Roxio Creator EasyArchive (HKLM\…\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio)
Roxio Creator Tools (HKLM\…\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio)
Roxio Express Labeler 3 (HKLM\…\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 3.2.1 - Roxio)
Roxio MyDVD Basic v9 (HKLM\…\{938B1CD7-7C60-491E-AA90-1F1888168240}) (Version: 9.0.559 - Roxio)
Skype Click to Call (HKLM\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 7.1 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Snapfish Media Detector (HKLM\…\{4EF6FDB0-3B11-4820-9860-8E08E9965195}) (Version: 1.7.0.15 - HP Snapfish)
SolutionCenter (Version: 82.0.188.000 - Hewlett-Packard) Hidden
Status (Version: 82.0.173.000 - Hewlett-Packard) Hidden
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1014 - SUPERAntiSpyware.com)
TrayApp (Version: 82.0.188.000 - Hewlett-Packard) Hidden
TrojanHunter 6.0 (HKLM\…\TrojanHunter_is1) (Version: 6.0 - Bytelayer AB)
Visual Studio 2012 x86 Redistributables (HKLM\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 1.1.9 (HKLM\…\VLC media player) (Version: 1.1.9 - VideoLAN)
WebEx Event Manager for Firefox or Chrome (HKLM\…\{06B5988F-EBA6-4802-9F7B-4FB471291321}) (Version: 28.7.0.15458 - Cisco WebEx LLC)
Windows 7 Upgrade Advisor (HKLM\…\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation)
WinPcap 4.1.2 (HKLM\…\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
Youtube Downloader HD v. 2.9.6 (HKLM\…\Youtube Downloader HD_is1) (Version: - YoutubeDownloaderHD.com)
Zoom (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\ZoomUMX) (Version: 3.5 - Zoom Video Communications, Inc.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{39125640-8D80-11DC-A2FE-C5C455D89593}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Google Talk Plugin\googletalkax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\1440\G2MOutlookAddin.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{AB9F4455-E591-4132-A386-0B91EAEDB96C}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Google Talk Plugin\o1dax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.26.9\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\psuser.dll (Google Inc.)
==================== Restore Points =========================
01-07-2015 12:42:58 Windows Update
02-07-2015 12:02:26 Scheduled Checkpoint
03-07-2015 11:44:40 Scheduled Checkpoint
04-07-2015 11:57:52 Scheduled Checkpoint
05-07-2015 00:00:05 Scheduled Checkpoint
05-07-2015 16:42:42 Scheduled Checkpoint
08-07-2015 22:24:40 Scheduled Checkpoint
13-07-2015 03:04:14 Scheduled Checkpoint
16-07-2015 03:01:38 Windows Update
16-07-2015 19:55:08 Scheduled Checkpoint
16-07-2015 20:40:45 zoek.exe restore point
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 02:23 - 2006-09-18 13:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {02B1C58A-086C-4ED9-B993-C6450A1DBC27} - System32\Tasks\Registration => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-03-05] ()
Task: {1B6DBECF-3A87-479C-9AEE-97A6A053F36F} - System32\Tasks\HP online update program => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {2406BCAB-604C-46CC-8541-B7A1BE9F6CF2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-27] (Google Inc.)
Task: {2A42CD5F-56F8-4BF2-9DCB-4539B8A920A8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-27] (Google Inc.)
Task: {5DCB035D-4B45-4509-A148-84B06314AD4B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-14] (Adobe Systems Incorporated)
Task: {63C8F07F-D02D-4EBD-8DBE-2194C65FAA96} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {76748A9F-364C-4BA3-A180-A8A9E65E30AC} - System32\Tasks\Real Player online update program => C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-10-12] (RealNetworks, Inc.)
Task: {A6977348-A03B-45E1-BB2C-CD4C13F04918} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Sharon => C:\Program Files\Windows Calendar\WinCal.exe [2007-06-26] (Microsoft Corporation)
Task: {AFF35159-F6E9-49C8-8CA7-9669E9B18DCC} - System32\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupdate.exe [2015-07-09] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {C37BA6B1-ADD5-4F04-A7B0-04BEB36E59A2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-10] (Google Inc.)
Task: {D42CA714-CB4E-4AA5-BC29-026CAF953660} - System32\Tasks\IntenetServiceOffers => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-03-05] ()
Task: {D5B4D35F-5815-451D-9D4A-CA951A9A7186} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-06-01] (Piriform Ltd)
Task: {E29A3170-0CD7-46E7-8DD5-DAC5DB3B337A} - System32\Tasks\Adobe online update program => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {EED84F28-F38A-4C31-8D42-E093B56E74A5} - System32\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupload.exe [2015-07-09] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {F9011493-B85D-4B2F-BD39-CDF7FE8536A8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-10] (Google Inc.)
Task: {FA63882F-4A5A-4C97-9855-5D7FA1F9709A} - System32\Tasks\{3092C782-E801-4022-8631-A592DFCCADB7} => pcalua.exe -a "C:\Program Files\QuickTime\QTSystem\QuickTime.cpl" -c @0,0x63737064
Task: {FA71853D-E21F-45D1-A4BB-7D16CF8065F6} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {FC86BC9D-A39B-4C5F-A3E6-D9E2CFB5D088} - \OptimusNitro_Start No Task File <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupload.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-07-14 02:26 - 2014-07-14 02:26 - 00585528 _____ () C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll
2014-07-14 02:26 - 2014-07-14 02:26 - 00357176 _____ () C:\Program Files\AVG\AVG PC TuneUp\tuavgx.dll
2014-07-14 10:07 - 2014-02-10 13:44 - 04592128 _____ () C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
2014-07-14 10:07 - 2014-02-10 13:44 - 00112128 _____ () C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll
2015-07-14 05:33 - 2015-07-13 13:55 - 16308040 _____ () C:\Program Files\Google\Chrome\Application\43.0.2357.134\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Sharon\Pictures\p.3 joy.jpg
DNS Servers: 192.168.2.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk => C:\Windows\pss\OpenOffice.org 3.4.1.lnk.Startup
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: emsisoft anti-malware => "c:\program files\emsisoft anti-malware\a2guard.exe" /d=60
MSCONFIG\startupreg: FreeScreenSharing => "C:\Users\Sharon\AppData\Local\FreeScreenSharing\FreeScreenSharing.exe"
MSCONFIG\startupreg: Google Update => "C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: OM2_Monitor => "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: THGuard => "C:\Program Files\TrojanHunter\THGuard.exe"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{C39C9369-DF78-4BA3-B71E-AAEBCCC33157}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{E6281A08-83AE-4E62-8A1A-2C189B8D1BE7}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{21C042E9-8F4D-4046-980E-4F45283AC8F2}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{61D8597E-437D-43DD-89CC-62F487F13081}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{CFE6DE30-FE46-4C60-B0B7-09C12C3214F0}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{B82921CB-E57D-4E9E-AADF-71E261A9A6FC}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{9434D6F6-9325-449C-83A6-688A78CD132F}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{5CDBFFA3-A48D-4445-88DC-6D5364623797}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{3EF2AD33-05C0-4EFB-8F08-EC2B6BBC3FE7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{C160F25F-0B64-4732-8263-97D07C2E73EB}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{0C16FA18-D5B1-4409-ACDA-1C3308C7BD9D}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{16B9DCCF-ECA7-481C-8CF0-D9E749F23A52}] => (Allow) C:\Program Files\AVG\AVG2015\avgnsx.exe
FirewallRules: [{7D687C39-533C-4B68-9896-282F2C63A60C}] => (Allow) C:\Program Files\AVG\AVG2015\avgnsx.exe
FirewallRules: [{3C94EE9E-A0CA-484C-B082-936FB1DDFC81}] => (Allow) C:\Program Files\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{43A2EA19-F75D-4B68-AFEB-BF94D6A9FD6D}] => (Allow) C:\Program Files\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{94E3137F-E0E6-4D52-A88E-624EBD131210}] => (Allow) C:\Program Files\AVG\AVG2015\avgemcx.exe
FirewallRules: [{7C10B454-7729-4ECA-B09B-5E121653AA86}] => (Allow) C:\Program Files\AVG\AVG2015\avgemcx.exe
FirewallRules: [{4839C1AC-5CD7-4C77-87DF-1A41AE07EE0D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe] => Enabled:Earthlink
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/16/2015 09:42:10 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/16/2015 09:42:10 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/16/2015 03:30:24 AM) (Source: usbperf) (EventID: 2004) (User: )
Description: Usbperf data collection failed. Collect function called with usupported Query Type.
Error: (07/16/2015 03:24:30 AM) (Source: usbperf) (EventID: 2004) (User: )
Description: Usbperf data collection failed. Collect function called with usupported Query Type.
Error: (07/16/2015 03:22:10 AM) (Source: usbperf) (EventID: 2004) (User: )
Description: Usbperf data collection failed. Collect function called with usupported Query Type.
Error: (07/16/2015 03:21:56 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4
Error: (07/16/2015 03:21:53 AM) (Source: Perflib) (EventID: 1010) (User: )
Description: EmdCacheC:\Windows\system32\emdmgmt.dll4
Error: (07/16/2015 03:21:52 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: DFSRC:\Windows\System32\DfsrPerf.dll4
Error: (07/15/2015 09:17:33 AM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
Error: (07/15/2015 07:17:35 AM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
System errors:
=============
Error: (07/16/2015 09:38:54 PM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 11, function 0.
Please contact your system vendor for technical assistance.
Error: (07/16/2015 09:38:54 PM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 9, function 0.
Please contact your system vendor for technical assistance.
Error: (07/16/2015 09:16:15 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Error: (07/16/2015 09:16:14 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Error: (07/16/2015 09:16:13 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Error: (07/16/2015 09:16:12 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Error: (07/16/2015 09:16:10 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Error: (07/16/2015 08:33:05 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt
Error: (07/16/2015 08:33:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
Error: (07/16/2015 08:31:28 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:28:06 PM on 7/16/2015 was unexpected.
Microsoft Office:
=========================
Error: (04/19/2015 10:43:02 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20499 seconds with 120 seconds of active time. This session ended with a crash.
Error: (04/17/2015 10:53:03 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2093 seconds with 0 seconds of active time. This session ended with a crash.
Error: (09/12/2014 08:49:26 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 516 seconds with 0 seconds of active time. This session ended with a crash.
Error: (09/05/2012 11:47:41 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 322286 seconds with 720 seconds of active time. This session ended with a crash.
CodeIntegrity Errors:
===================================
Date: 2015-07-17 03:20:35.548
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-17 03:20:35.505
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-17 03:20:35.462
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-17 03:20:35.420
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-17 03:20:35.176
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-17 03:20:35.131
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-17 03:20:35.087
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-17 03:20:35.014
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-17 03:20:34.401
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-17 03:20:34.356
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: AMD Athlon™ 64 X2 Dual Core Processor 3600+
Percentage of memory in use: 88%
Total physical RAM: 1917.94 MB
Available physical RAM: 217.61 MB
Total Virtual: 4073.09 MB
Available Virtual: 1029.62 MB
==================== Drives ================================
Drive c: (COMPAQ) (Fixed) (Total:140.67 GB) (Free:89.62 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Recovery) (Fixed) (Total:8.38 GB) (Free:1.01 GB) NTFS ==>[system with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 149.1 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=140.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=8.4 GB) - (Type=07 NTFS)
==================== End of log ============================
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 7/16/2015
Scan Time: 4:08:40 PM
Logfile:
Administrator: Yes
Version: 2.1.8.1057
Malware Database: v2015.07.16.05
Rootkit Database: v2015.07.16.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows Vista
CPU: x86
File System: NTFS
User: Sharon
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 309988
Time Elapsed: 21 min, 24 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)