This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer slow [Solved]

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Satchfan,

 

I told you before AVG keeps on deleting FRST.  I disabled AVG again and downloaded FRST from your directions.  It downloaded but when I click on save for the desktop, it does not save.  I did this a few times.  Then I tried downloading it fom someplace else and it was not the same thing.  Is there another site I can download it from?

 

Thanks
GB

AVG cannot "delete" FRST.

 

I suggest that you uninstall AVG for the moment if it's interfering and follow the instructions to send a new log, otherwise I won't be able to reassure you that your computer is clean.

I have to go now.  I will do as you say.  However, I installed FRST 3 times when AVG was on.  All 3 times after I had FRST on the desktop, I got popups from AVG saying it was potential malware.  and then it disappeared all 3 times from the desktop.  yesterday, you told me to run it again.  I AVG was disabled and no popup.  I downloaded it and then clicked on to download it on the desktop.  I tried it 3 times and nothing happened.

 

I;ll finish when I return.

 

Thank

:thumbup:

 

I am travelling today, (I'm away dog-sitting at my sister's for a week) so any reply will be a bit delayed but I'll respond as soon as I can.

 

Satchfan

If you haven't yet uninstalled AVG please do so but don't use the Internet for anything other than following instructions as your computer will be unprotected.

Download the FRST 64-bit version from here, then right-click on it and choose to "Run as Administrator".
 

Satchfan,

 

I was using the 32 bit FRST before.  I was able to download and install the 64 bit version.  I got a message error when I tried to run it.  Probably because it was not for this one.  I was able to download the 32 bit version. I tried multiple times to install it but when I click, it just disappeared and did not install.  I don't think it has anything to do with AVG this time.  AVG deleted it after it was installed on the desktop. 

 

Thanks

GB

Satchfan,

 

You were right.  I deleted 

AVG and was able to scan.  Here is the log.  It's weird though .because FRST is still not on the desktop and that is where I clicked to save it.  Should I download Avira or another anti virus?

 

Thanks,

GB

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-07-2015
Ran by [removed] (administrator) on HAK-PC on 21-07-2015 00:19:06
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft® Windows Vista™ Home Basic  (X86) OS Language: English (United States)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
(Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe
(Realtek Semiconductor) C:\WINDOWS\RtHDVCpl.exe
(Google Inc.) C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
() C:\Program Files\user extensions\Client.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe
(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-01-16] (Microsoft Corporation)
HKLM\…\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2006-09-28] (Hewlett-Packard Company)
HKLM\…\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4390912 2007-03-01] (Realtek Semiconductor)
HKLM\…\Run: [SnapfishMediaDetector] => C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe [1441792 2007-03-02] ()
HKLM\…\Run: [MSConfig] => C:\Windows\system32\msconfig.exe [222208 2006-11-02] (Microsoft Corporation)
HKLM\…\RunOnce: [Launcher] => C:\Windows\SMINST\launcher.exe [44168 2007-03-07] (soft thinks)
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\Run: [Google Update] => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-05-10] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk [2007-05-10]
ShortcutTarget: Snapfish Media Detector.lnk -> C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyEnable: [S-1-5-21-1992874582-3349113656-4066416677-1001] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-1992874582-3349113656-4066416677-1001] => http=127.0.0.1:49208;https=127.0.0.1:49208;
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-18] (SuperAdBlocker.com)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{003F1CAB-9582-432A-976B-A5B40F8B2472}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{015EC064-039A-44FB-930A-94C209392E85}: [DhcpNameServer] 192.168.2.1
 
FireFox:
========
FF ProfilePath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2013-10-12] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-10-12] (RealPlayer)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Sharon\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-07-27] (Citrix Online)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/O1DPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Sharon\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2015-03-17] (Zoom Video Communications, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npatgpc.dll [2012-10-29] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF SearchPlugin: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\searchplugins\amazon-distro.xml [2012-12-13]
FF Extension: adblockvideo - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2012-09-15]
FF Extension: feedly - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2013-05-10]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2012-12-12]
FF Extension: Adblock Plus - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-15]
FF Extension: User Agent Switcher - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2013-05-06]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Video Downloader Plugin - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Youtube Download Button - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-05-20]
FF HKLM\…\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-10-12]
FF HKLM\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
 
Chrome: 
=======
CHR Profile: C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (RealDownloader) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-04-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-21]
CHR Extension: (Skype Click to Call) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-09-01]
CHR Extension: (Google Wallet) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-13]
CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-29] (SUPERAntiSpyware.com)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [5509384 2015-07-08] (Emsisoft Ltd)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-04-25] (Freemake) [File not signed]
S3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-13] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 LightScribeService; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [1858360 2014-07-14] (AVG)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [35640 2014-07-14] (AVG)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [265912 2007-01-16] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 eapihdrv; C:\Users\Sharon\AppData\Local\Temp\ehdrv.sys [135760 2015-07-18] (ESET)
R1 epp32; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp32.sys [112408 2015-07-08] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2014-02-10] (TuneUp Software)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-21 00:16 - 2015-07-21 00:16 - 01638912 _____ (Farbar) C:\Users\Sharon\Desktop\FRST.exe
2015-07-19 04:15 - 2015-07-19 04:15 - 00000955 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-07-19 04:12 - 2015-07-20 21:21 - 00001360 _____ C:\blitzblank.log
2015-07-18 13:15 - 2015-07-18 13:15 - 00000000 ____D C:\Program Files\VS Revo Group
2015-07-18 10:36 - 2015-07-18 10:36 - 00000000 ____D C:\Users\Sharon\AppData\Roaming\One System Care
2015-07-18 10:32 - 2015-07-20 11:00 - 00000266 _____ C:\Windows\Tasks\One System CarePeriod.job
2015-07-18 10:32 - 2015-07-19 04:17 - 00000000 ____D C:\Program Files\gmsd_us_021010034
2015-07-18 10:32 - 2015-07-18 10:33 - 00000000 ____D C:\Users\Sharon\AppData\Local\gmsd_us_021010034
2015-07-18 10:32 - 2014-08-18 11:51 - 00660792 _____ (VoiceFive, Inc.) C:\Windows\system32\pmls.dll
2015-07-18 10:31 - 2015-07-19 04:17 - 00000000 ____D C:\Program Files\OneSystemCare
2015-07-18 10:31 - 2015-07-18 10:32 - 00000000 ____D C:\Program Files\PremierOpinion
2015-07-18 10:31 - 2015-07-18 10:31 - 00000064 _____ C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
2015-07-18 10:31 - 2015-07-18 10:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care
2015-07-18 10:30 - 2015-07-20 16:33 - 00000000 ____D C:\Program Files\user extensions
2015-07-18 05:03 - 2015-07-18 05:03 - 00001812 _____ C:\Users\Sharon\Desktop\ESETScan..txt
2015-07-18 02:43 - 2015-07-18 02:43 - 00000000 ____D C:\Program Files\ESET
2015-07-18 02:41 - 2015-07-18 02:41 - 02870984 _____ (ESET) C:\Users\Sharon\Desktop\esetsmartinstaller_enu.exe
2015-07-17 03:20 - 2015-07-17 03:22 - 00035307 _____ C:\Users\Sharon\Desktop\Addition.txt
2015-07-17 03:19 - 2015-07-21 00:19 - 00018332 _____ C:\Users\Sharon\Desktop\FRST.txt
2015-07-17 03:00 - 2015-07-17 03:00 - 01636864 _____ (Farbar) C:\Users\Sharon\Downloads\FRST.exe
2015-07-17 02:55 - 2015-07-17 02:55 - 00000377 _____ C:\Users\Sharon\Desktop\fixlist.txt
2015-07-16 21:26 - 2015-07-16 20:37 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-16 20:40 - 2015-07-16 21:40 - 00021621 _____ C:\zoek-results.log
2015-07-16 20:36 - 2015-07-16 20:36 - 01308672 _____ C:\Users\Sharon\Desktop\zoek.exe
2015-07-16 20:31 - 2015-07-20 21:22 - 00002644 _____ C:\Windows\PFRO.log
2015-07-16 20:26 - 2015-07-16 20:26 - 01308672 _____ C:\Users\Sharon\Downloads\zoek (1).exe
2015-07-16 20:25 - 2015-07-16 21:20 - 00000000 ____D C:\zoek_backup
2015-07-16 20:24 - 2015-07-16 20:24 - 01308672 _____ C:\Users\Sharon\Desktop\zoek (1).exe
2015-07-16 20:08 - 2015-07-16 20:09 - 01308672 _____ C:\Users\Sharon\Downloads\zoek.exe
2015-07-16 14:38 - 2015-07-16 14:39 - 00000000 ____D C:\Users\Sharon\Desktop\New Folder
2015-07-14 05:39 - 2015-07-14 05:41 - 00034963 _____ C:\Users\Sharon\Downloads\Addition.txt
2015-07-14 05:35 - 2015-07-21 00:19 - 00000000 ____D C:\FRST
2015-07-13 10:24 - 2015-07-13 10:24 - 00000296 _____ C:\Windows\system32\spsys.log
2015-07-13 02:35 - 2015-07-13 02:35 - 00003121 _____ C:\Users\Sharon\Desktop\JRT.txt
2015-07-13 02:22 - 2015-07-13 02:22 - 00000207 _____ C:\Windows\tweaking.com-regbackup-HAK-PC-Windows-Vista-(TM)-Home-Basic-(32-bit).dat
2015-07-13 02:21 - 2015-07-13 02:21 - 00000000 ____D C:\RegBackup
2015-07-13 02:19 - 2015-07-13 02:19 - 00009208 _____ C:\Users\Sharon\Desktop\AdwCleaner[S0].txt
2015-07-13 02:16 - 2015-07-13 02:17 - 03034492 _____ (Malwarebytes Corporation) C:\Users\Sharon\Downloads\JRT.exe
2015-07-13 02:14 - 2015-07-13 02:14 - 00000000 ____D C:\Windows\pss
2015-07-13 02:00 - 2015-07-13 02:05 - 00000000 ____D C:\AdwCleaner
2015-07-13 01:58 - 2015-07-13 01:59 - 02248704 _____ C:\Users\Sharon\Downloads\adwcleaner_4.208.exe
2015-07-12 11:15 - 2015-07-12 11:15 - 00010182 _____ C:\Users\Sharon\Downloads\hijackthis.log
2015-07-12 11:14 - 2015-07-12 11:14 - 00388608 _____ (Trend Micro Inc.) C:\Users\Sharon\Downloads\HiJackThis.exe
2015-07-10 03:41 - 2015-07-10 03:41 - 00027329 _____ C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!.html
2015-07-10 03:41 - 2015-07-10 03:41 - 00000000 ____D C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!_files
2015-07-08 16:22 - 2015-07-12 11:21 - 00001356 _____ C:\Users\Sharon\AppData\Local\d3d9caps.dat
2015-07-08 14:46 - 2015-07-20 22:57 - 00458613 _____ C:\Windows\WindowsUpdate.log
2015-07-07 10:56 - 2015-07-07 10:56 - 00000810 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\Program Files\CCleaner
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507.exe
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507 (1).exe
2015-07-07 01:38 - 2015-07-07 01:44 - 00000000 ____D C:\ProgramData\Emsisoft
2015-07-07 01:10 - 2015-07-07 01:11 - 00000000 ____D C:\Program Files\TrojanHunter
2015-07-07 01:10 - 2015-07-07 01:10 - 00000858 _____ C:\Users\Sharon\Desktop\TrojanHunter.lnk
2015-07-07 01:10 - 2015-07-07 01:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
2015-07-07 01:09 - 2015-07-07 01:09 - 04069672 _____ (Bytelayer AB ) C:\Users\Sharon\Downloads\TrojanHunterSetup.exe
2015-07-06 17:15 - 2015-07-06 17:15 - 00000894 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2015-07-06 17:15 - 2015-07-06 17:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2015-07-06 17:14 - 2015-03-24 00:17 - 00111368 _____ (Emsisoft GmbH) C:\Windows\system32\Drivers\epp32.sys
2015-07-06 17:13 - 2015-07-21 00:11 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2015-07-06 16:13 - 2015-07-06 16:30 - 167273960 _____ (Emsisoft Ltd. ) C:\Users\Sharon\Downloads\EmsisoftAntiMalwareSetup.exe
2015-07-05 12:46 - 2015-07-05 12:46 - 00242712 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 39.0.exe
2015-07-05 10:22 - 2015-07-05 10:26 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Sharon\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-07-03 14:20 - 2015-07-03 14:20 - 01125056 _____ (Adobe Systems Incorporated) C:\Users\Sharon\Downloads\flashplayer18_ha_install.exe
2015-07-02 13:55 - 2015-07-02 13:55 - 00243408 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 38.0.5.exe
2015-06-30 12:25 - 2015-07-05 14:17 - 00000000 ____D C:\Program Files\Mozilla Firefox
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-21 00:18 - 2012-10-18 13:49 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-21 00:16 - 2015-05-10 16:53 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job
2015-07-21 00:07 - 2007-05-10 11:27 - 00000000 ____D C:\Windows\SMINST
2015-07-21 00:06 - 2013-04-27 03:03 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-21 00:06 - 2006-11-02 04:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-21 00:06 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-21 00:06 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-20 22:58 - 2006-11-02 04:58 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-07-20 22:31 - 2014-07-27 15:41 - 00000568 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-20 22:29 - 2013-04-27 03:03 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-20 21:53 - 2015-05-30 13:19 - 00000664 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-20 21:22 - 2014-11-04 14:23 - 00000000 ____D C:\ProgramData\AVG2015
2015-07-20 21:22 - 2012-07-09 10:09 - 00000000 ____D C:\Program Files\AVG
2015-07-20 21:22 - 2012-07-09 10:00 - 00000000 ____D C:\ProgramData\MFAData
2015-07-20 19:31 - 2012-07-09 10:10 - 00000000 ___HD C:\$AVG
2015-07-20 12:16 - 2015-05-10 16:53 - 00000860 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job
2015-07-19 04:14 - 2012-06-06 18:34 - 00000950 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-07-19 04:14 - 2012-06-06 18:34 - 00000921 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2015-07-17 03:28 - 2014-04-11 17:05 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-16 21:40 - 2013-02-18 13:09 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-07-16 21:16 - 2006-11-02 03:18 - 00000000 ___RD C:\Users\Public
2015-07-16 21:16 - 2006-11-02 03:18 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-07-16 03:22 - 2013-07-14 19:21 - 00000000 ____D C:\Windows\system32\MRT
2015-07-14 23:47 - 2012-07-08 00:30 - 00000000 ____D C:\Users\Sharon\AppData\Roaming\Skype
2015-07-14 21:20 - 2012-07-08 00:19 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-14 21:20 - 2012-07-08 00:19 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-08 15:04 - 2013-05-06 08:20 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-07 11:00 - 2012-07-17 15:02 - 00000000 ____D C:\Windows\Minidump
2015-07-07 11:00 - 2007-05-10 11:06 - 00000000 ____D C:\Windows\Panther
2015-07-07 01:25 - 2012-06-06 18:33 - 00000000 ____D C:\Users\Sharon\AppData\Local\VirtualStore
2015-07-05 14:17 - 2013-03-09 15:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-07-05 14:16 - 2006-11-02 04:35 - 00000000 ____D C:\Windows\DigitalLocker
2015-07-05 12:50 - 2013-03-09 15:52 - 00000864 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-05 12:50 - 2013-03-09 15:52 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-05 10:30 - 2014-04-11 17:02 - 00000905 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-07-03 08:49 - 2006-11-02 02:24 - 127070192 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-07-01 12:53 - 2014-04-14 12:13 - 00000000 ____D C:\Users\Sharon\AppData\Local\AVG
 
==================== Files in the root of some directories =======
 
2013-05-21 03:10 - 2014-01-30 13:39 - 0003736 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
2015-07-18 10:31 - 2015-07-18 10:31 - 0000064 _____ () C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
2015-07-08 16:22 - 2015-07-12 11:21 - 0001356 _____ () C:\Users\Sharon\AppData\Local\d3d9caps.dat
2012-07-08 02:19 - 2015-05-06 19:35 - 0025088 _____ () C:\Users\Sharon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2007-05-10 10:43 - 2013-03-21 07:29 - 0002738 _____ () C:\ProgramData\hpzinstall.log
 
Some files in TEMP:
====================
C:\Users\Sharon\AppData\Local\Temp\farbar-recovery-scan-tool.exe
C:\Users\Sharon\AppData\Local\Temp\farbar-recovery-scan-tool.exe-1437244056672.exe
C:\Users\Sharon\AppData\Local\Temp\farbar-recovery-scan-tool.exe-1437244307874.exe
C:\Users\Sharon\AppData\Local\Temp\farbar-recovery-scan-tool.exe-1437244547564.exe
C:\Users\Sharon\AppData\Local\Temp\gb-update.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-21 00:13
 
==================== End of log ============================

Run AVG removal tool

There are still some remnants of AVG on your computer even after the uninstall so please download and run AVG Removal Tool from here.

===================================================

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

() C:\Program Files\user extensions\Client.exe
SearchScopes: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.co…q={searchTerms}
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
2015-07-18 10:36 - 2015-07-18 10:36 - 00000000 ____D C:\Users\Sharon\AppData\Roaming\One System Care
2015-07-18 10:32 - 2015-07-20 11:00 - 00000266 _____ C:\Windows\Tasks\One System CarePeriod.job
2015-07-18 10:32 - 2015-07-19 04:17 - 00000000 ____D C:\Program Files\gmsd_us_021010034
2015-07-18 10:32 - 2015-07-18 10:33 - 00000000 ____D C:\Users\Sharon\AppData\Local\gmsd_us_021010034
2015-07-18 10:32 - 2014-08-18 11:51 - 00660792 _____ (VoiceFive, Inc.) C:\Windows\system32\pmls.dll
2015-07-18 10:31 - 2015-07-19 04:17 - 00000000 ____D C:\Program Files\OneSystemCare
2015-07-18 10:31 - 2015-07-18 10:32 - 00000000 ____D C:\Program Files\PremierOpinion
2015-07-18 10:31 - 2015-07-18 10:31 - 00000064 _____ C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
2015-07-18 10:31 - 2015-07-18 10:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care
C:\Users\Sharon\AppData\Roaming\One System Care
C:\Windows\Tasks\One System CarePeriod.job
C:\Program Files\gmsd_us_021010034
C:\Users\Sharon\AppData\Local\gmsd_us_021010034
C:\Windows\system32\pmls.dll
C:\Program Files\OneSystemCare
C:\Program Files\PremierOpinion
C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care
C:\Program Files\user extensions\Client.exe
RemoveProxy:
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

Please also run FRST again, make sure “Addition.txt” is also checkmarked before you hit “Scan” and send the new log.

Can you also answer my previous question about One System Care and tell me what problems remain.

Thanks

Satchfan

 

Satchfan,

 

I could not download FRST a few days ago.  I went to another website that I thought was reputable and downloaded what I thought was FRST.  It was loaded with crapware and One System Care was one.  Sorry.  I uninstalled it but evidently some  remain. The computer seems to be much faster.

 

Thanks,

 

GB

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 20-07-2015
Ran by [removed] at 2015-07-21 03:45:23 Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
 
() C:\Program Files\user extensions\Client.exe
SearchScopes: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.co…q={searchTerms}
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
2015-07-18 10:36 - 2015-07-18 10:36 - 00000000 ____D C:\Users\Sharon\AppData\Roaming\One System Care
2015-07-18 10:32 - 2015-07-20 11:00 - 00000266 _____ C:\Windows\Tasks\One System CarePeriod.job
2015-07-18 10:32 - 2015-07-19 04:17 - 00000000 ____D C:\Program Files\gmsd_us_021010034
2015-07-18 10:32 - 2015-07-18 10:33 - 00000000 ____D C:\Users\Sharon\AppData\Local\gmsd_us_021010034
2015-07-18 10:32 - 2014-08-18 11:51 - 00660792 _____ (VoiceFive, Inc.) C:\Windows\system32\pmls.dll
2015-07-18 10:31 - 2015-07-19 04:17 - 00000000 ____D C:\Program Files\OneSystemCare
2015-07-18 10:31 - 2015-07-18 10:32 - 00000000 ____D C:\Program Files\PremierOpinion
2015-07-18 10:31 - 2015-07-18 10:31 - 00000064 _____ C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
2015-07-18 10:31 - 2015-07-18 10:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care
C:\Users\Sharon\AppData\Roaming\One System Care
C:\Windows\Tasks\One System CarePeriod.job
C:\Program Files\gmsd_us_021010034
C:\Users\Sharon\AppData\Local\gmsd_us_021010034
C:\Windows\system32\pmls.dll
C:\Program Files\OneSystemCare
C:\Program Files\PremierOpinion
C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care
C:\Program Files\user extensions\Client.exe
RemoveProxy:
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
EmptyTemp:
*****************
 
C:\Program Files\user extensions\Client.exe
[3936] C:\Program Files\user extensions\Client.exe => process closed successfully.
"HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully.
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found. 
"HKCR\PROTOCOLS\Handler\linkscanner" => key removed successfully.
HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => key not found. 
blbdrive => Service removed successfully.
IpInIp => Service removed successfully.
NwlnkFlt => Service removed successfully.
NwlnkFwd => Service removed successfully.
taphss6 => Service removed successfully.
C:\Users\Sharon\AppData\Roaming\One System Care => moved successfully.
C:\Windows\Tasks\One System CarePeriod.job => moved successfully.
C:\Program Files\gmsd_us_021010034 => moved successfully.
C:\Users\Sharon\AppData\Local\gmsd_us_021010034 => moved successfully.
C:\Windows\system32\pmls.dll => moved successfully.
C:\Program Files\OneSystemCare => moved successfully.
C:\Program Files\PremierOpinion => moved successfully.
C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47 => moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care => moved successfully.
"C:\Users\Sharon\AppData\Roaming\One System Care" => File/Folder not found.
"C:\Windows\Tasks\One System CarePeriod.job" => File/Folder not found.
"C:\Program Files\gmsd_us_021010034" => File/Folder not found.
"C:\Users\Sharon\AppData\Local\gmsd_us_021010034" => File/Folder not found.
"C:\Windows\system32\pmls.dll" => File/Folder not found.
"C:\Program Files\OneSystemCare" => File/Folder not found.
"C:\Program Files\PremierOpinion" => File/Folder not found.
"C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47" => File/Folder not found.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care" => File/Folder not found.
C:\Program Files\user extensions\Client.exe => moved successfully.
 
========= RemoveProxy: =========
 
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully.
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully.
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully.
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully.
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully.
 
 
========= End of RemoveProxy: =========
 
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.0.6000 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.
 
Unable to cancel {4052307A-21EF-413B-99B8-20FB701DBE51}.
{542BF183-F808-4ACA-A712-8004FF3CE4EE} canceled.
1 out of 2 jobs canceled.
 
========= End of CMD: =========
 
EmptyTemp: => 1008.2 MB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 03:46:53 ====
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-07-2015
Ran by [removed] at 2015-07-21 04:03:24
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1992874582-3349113656-4066416677-500 - Administrator - Disabled)
Guest (S-1-5-21-1992874582-3349113656-4066416677-501 - Limited - Disabled)
Sharon (S-1-5-21-1992874582-3349113656-4066416677-1001 - Administrator - Enabled) => C:\Users\Sharon
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
7-Zip 9.20 (HKLM\…\7-Zip) (Version:  - )
Adobe Flash Player 18 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 9 ActiveX (HKLM\…\ShockwaveFlash) (Version: 9 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Atheros Driver Installation Program (HKLM\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.1 - Atheros)
Audacity 2.0.3 (HKLM\…\Audacity_is1) (Version: 2.0.3 - Audacity Team)
AVG PC TuneUp 2014 (en-US) (Version: 14.0.1001.519 - AVG) Hidden
AVG PC TuneUp 2014 (HKLM\…\AVG PC TuneUp) (Version: 14.0.1001.519 - AVG)
AVG PC TuneUp 2014 (Version: 14.0.1001.519 - AVG) Hidden
BufferChm (Version: 82.0.173.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.07 - Piriform)
Citrix Online Launcher (HKLM\…\{C57F6C71-C365-4AFF-9108-397BBAD6127F}) (Version: 1.0.204 - Citrix)
Copy (Version: 82.0.188.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Destinations (Version: 82.0.173.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
DocProc (Version: 8.1.0.0 - Hewlett-Packard) Hidden
DocProcQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Elementary Education: Content Knowledge Practice Test (HKLM\…\{0AED2370-A4CD-4D5A-A6FA-32DE353DAE4C}) (Version: 2.0 - Educational Testing Service)
Emsisoft Anti-Malware (HKLM\…\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 10.0 - Emsisoft Ltd.)
ESET Online Scanner v3 (HKLM\…\ESET Online Scanner) (Version:  - )
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Freemake Video Converter version 4.0.1 (HKLM\…\Freemake Video Converter_is1) (Version: 4.0.1 - Ellora Assets Corporation)
Freemake Video Downloader (HKLM\…\Freemake Video Downloader_is1) (Version: 3.5.0 - Ellora Assets Corporation)
FreeScreenSharing (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\FreeScreenSharing) (Version: 0.56.21.0 - Free Conferencing Corporation)
GamesDesktop 025.021010034 (HKLM\…\gmsd_us_021010034_is1) (Version:  - GAMESDESKTOP) <==== ATTENTION
GeniusBox 2.0 (HKLM\…\GeniusBox) (Version: 2.0 - GeniusBox 2.0)
Google Chrome (HKLM\…\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Talk Plugin (HKLM\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
GoToMeeting 7.2.3.3019 (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\GoToMeeting) (Version: 7.2.3.3019 - CitrixOnline)
HP Customer Experience Enhancements (HKLM\…\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.1.0.2264 - Hewlett-Packard)
HP Customer Participation Program 8.0 (HKLM\…\HPExtendedCapabilities) (Version: 8.0 - HP)
HP Easy Setup - Frontend (HKLM\…\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.1.0.2269 - Hewlett-Packard)
HP Imaging Device Functions 8.0 (HKLM\…\HP Imaging Device Functions) (Version: 8.0 - HP)
HP OCR Software 8.0 (HKLM\…\HPOCR) (Version: 8.0 - HP)
HP OFFICEJET 6210 Driver Utility (HKLM\…\HP OFFICEJET 6210 Driver Utility_is1) (Version:  - Lavians Inc.)
HP Photosmart Essential (HKLM\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
HP Photosmart Essential 2.0 (HKLM\…\HP Photosmart Essential) (Version: 2.0 - HP)
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (HKLM\…\{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}) (Version: 8.0 - HP)
HP Solution Center 8.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 8.0 - HP)
HP Update (HKLM\…\{8C6027FD-53DC-446D-BB75-CACD7028A134}) (Version: 4.000.005.005 - Hewlett-Packard)
HPProductAssistant (Version: 82.0.173.000 - Hewlett-Packard) Hidden
HPSSupply (HKLM\…\{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}) (Version: 2.1.3.0000 - Hewlett Packard Development Company L.P.)
Image Resizer for Windows (HKLM\…\{69d72156-6582-4556-8637-06f40aa7f85b}) (Version: 3.0.4802.35565 - Brice Lambson)
Image Resizer for Windows (Version: 3.0.4802.35565 - Brice Lambson) Hidden
Itibiti RTC (Version: 0.0.1 - Itibiti Inc) Hidden
LightScribe  1.4.142.1 (Version: 1.4.142.1 - http://www.lightscribe.com)Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
MarketResearch (Version: 82.0.174.000 - Hewlett-Packard) Hidden
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\…\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
Mozilla Firefox 39.0 (x86 en-US) (HKLM\…\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 39.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM\…\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
muvee autoProducer 6.0 (HKLM\…\{6AF49698-949A-4C89-9B31-041D2CCB5FBD}) (Version: 6.00.050 - muvee Technologies)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version:  - )
OLYMPUS Master 2 (HKLM\…\{45FCADDB-0B29-457E-83A1-D245C62A716C}) (Version: 1.0.6 - OLYMPUS IMAGING CORP.)
OLYMPUS muvee theaterPack (HKLM\…\{B3282FB8-874B-4054-8356-9EB391A826F9}) (Version: 1.0.4 - OLYMPUS IMAGING CORP.)
OpenOffice.org 3.4.1 (HKLM\…\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)
Picasa 3 (HKLM\…\Picasa 3) (Version: 3.9 - Google, Inc.)
PSSWCORE (Version: 2.00.5000 - Hewlett-Packard) Hidden
Python 2.4.3 (HKLM\…\{75E71ADD-042C-4F30-BFAC-A9EC42351313}) (Version: 2.4.3150 - Martin v. Löwis)
QuickTime (HKLM\…\{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}) (Version: 7.1.3.100 - Apple Computer, Inc.)
RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\…\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5377 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Rhapsody Player Engine (HKLM\…\{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}) (Version: 1.0.604 - RealNetworks)
Roxio Creator Audio (HKLM\…\{83FFCFC7-88C6-41c6-8752-958A45325C82}) (Version: 3.4.0 - Roxio)
Roxio Creator Basic v9 (HKLM\…\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}) (Version: 3.4.0 - Roxio)
Roxio Creator Copy (HKLM\…\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio)
Roxio Creator Data (HKLM\…\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio)
Roxio Creator EasyArchive (HKLM\…\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio)
Roxio Creator Tools (HKLM\…\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio)
Roxio Express Labeler 3 (HKLM\…\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 3.2.1 - Roxio)
Roxio MyDVD Basic v9 (HKLM\…\{938B1CD7-7C60-491E-AA90-1F1888168240}) (Version: 9.0.559 - Roxio)
Skype Click to Call (HKLM\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 7.1 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Snapfish Media Detector (HKLM\…\{4EF6FDB0-3B11-4820-9860-8E08E9965195}) (Version: 1.7.0.15 - HP Snapfish)
SolutionCenter (Version: 82.0.188.000 - Hewlett-Packard) Hidden
Status (Version: 82.0.173.000 - Hewlett-Packard) Hidden
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1014 - SUPERAntiSpyware.com)
TrayApp (Version: 82.0.188.000 - Hewlett-Packard) Hidden
TrojanHunter 6.0 (HKLM\…\TrojanHunter_is1) (Version: 6.0 - Bytelayer AB)
Visual Studio 2012 x86 Redistributables (HKLM\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 1.1.9 (HKLM\…\VLC media player) (Version: 1.1.9 - VideoLAN)
WebEx Event Manager for Firefox or Chrome (HKLM\…\{06B5988F-EBA6-4802-9F7B-4FB471291321}) (Version: 28.7.0.15458 - Cisco WebEx LLC)
Windows 7 Upgrade Advisor (HKLM\…\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation)
WinPcap 4.1.2 (HKLM\…\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
Youtube Downloader HD v. 2.9.6 (HKLM\…\Youtube Downloader HD_is1) (Version:  - YoutubeDownloaderHD.com)
Zoom (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\ZoomUMX) (Version: 3.5 - Zoom Video Communications, Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{39125640-8D80-11DC-A2FE-C5C455D89593}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Google Talk Plugin\googletalkax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\1440\G2MOutlookAddin.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{AB9F4455-E591-4132-A386-0B91EAEDB96C}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Google Talk Plugin\o1dax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.26.9\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\psuser.dll (Google Inc.)
 
==================== Restore Points =========================
 
05-07-2015 16:42:42 Scheduled Checkpoint
08-07-2015 22:24:40 Scheduled Checkpoint
13-07-2015 03:04:14 Scheduled Checkpoint
16-07-2015 03:01:38 Windows Update
16-07-2015 19:55:08 Scheduled Checkpoint
16-07-2015 20:40:45 zoek.exe restore point
18-07-2015 07:26:24 Scheduled Checkpoint
18-07-2015 13:17:38 Revo Uninstaller's restore point - Knctr
19-07-2015 19:14:19 Scheduled Checkpoint
20-07-2015 19:24:57 Removed AVG 2015
20-07-2015 19:32:23 Removed AVG 2015
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 02:23 - 2006-09-18 13:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {02B1C58A-086C-4ED9-B993-C6450A1DBC27} - System32\Tasks\Registration => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-03-05] ()
Task: {09F713C9-DD9B-446B-A2F3-0C4F27A5D403} - System32\Tasks\Validate Installation => C:\Program Files\user extensions\updater.exe [2015-07-21] () <==== ATTENTION
Task: {1B6DBECF-3A87-479C-9AEE-97A6A053F36F} - System32\Tasks\HP online update program => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {2406BCAB-604C-46CC-8541-B7A1BE9F6CF2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-27] (Google Inc.)
Task: {2A42CD5F-56F8-4BF2-9DCB-4539B8A920A8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-27] (Google Inc.)
Task: {5DCB035D-4B45-4509-A148-84B06314AD4B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-14] (Adobe Systems Incorporated)
Task: {63C8F07F-D02D-4EBD-8DBE-2194C65FAA96} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {70150072-3745-4970-92F2-319F581F5B89} - System32\Tasks\One System Care Monitor => C:\Program Files\OneSystemCare\CleanupConsole.exe
Task: {76748A9F-364C-4BA3-A180-A8A9E65E30AC} - System32\Tasks\Real Player online update program => C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-10-12] (RealNetworks, Inc.)
Task: {9047B2F4-831E-4E7F-8006-E9C122A2D247} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Sharon => C:\Program Files\Windows Calendar\WinCal.exe [2007-06-26] (Microsoft Corporation)
Task: {AFF35159-F6E9-49C8-8CA7-9669E9B18DCC} - System32\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupdate.exe [2015-07-09] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {C37BA6B1-ADD5-4F04-A7B0-04BEB36E59A2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-10] (Google Inc.)
Task: {D19CEAE8-8D50-43AA-BE02-9BD931893253} - System32\Tasks\One System CarePeriod => C:\Program Files\OneSystemCare\OneSystemCare.exe
Task: {D42CA714-CB4E-4AA5-BC29-026CAF953660} - System32\Tasks\IntenetServiceOffers => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-03-05] ()
Task: {D5B4D35F-5815-451D-9D4A-CA951A9A7186} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-06-01] (Piriform Ltd)
Task: {DFF5F404-E5D1-4C9B-A6DF-AD7A86B8B840} - System32\Tasks\GeniusBox => cmd.exe /C start "" "C:\Program Files\user extensions\client.exe" <==== ATTENTION
Task: {E29A3170-0CD7-46E7-8DD5-DAC5DB3B337A} - System32\Tasks\Adobe online update program => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {E37A6FDD-D5C9-4E94-B251-B372F6A2DCFE} - System32\Tasks\One System Care Run Delay => C:\Program Files\OneSystemCare\OneSystemCare.exe
Task: {EED84F28-F38A-4C31-8D42-E093B56E74A5} - System32\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupload.exe [2015-07-09] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {F49EF02D-3499-4122-A306-8768A7A6322E} - System32\Tasks\Check Updates => C:\Program Files\user extensions\updater.exe [2015-07-21] () <==== ATTENTION
Task: {F9011493-B85D-4B2F-BD39-CDF7FE8536A8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-10] (Google Inc.)
Task: {FA63882F-4A5A-4C97-9855-5D7FA1F9709A} - System32\Tasks\{3092C782-E801-4022-8631-A592DFCCADB7} => pcalua.exe -a "C:\Program Files\QuickTime\QTSystem\QuickTime.cpl" -c @0,0x63737064
Task: {FA71853D-E21F-45D1-A4BB-7D16CF8065F6} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {FC86BC9D-A39B-4C5F-A3E6-D9E2CFB5D088} - \OptimusNitro_Start No Task File <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupload.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-07-14 02:26 - 2014-07-14 02:26 - 00585528 _____ () C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll
2014-07-14 02:26 - 2014-07-14 02:26 - 00357176 _____ () C:\Program Files\AVG\AVG PC TuneUp\tuavgx.dll
2015-07-21 03:54 - 2015-07-21 03:54 - 00076800 _____ () C:\Program Files\user extensions\Client.exe
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Sharon\Pictures\p.3 joy.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk => C:\Windows\pss\OpenOffice.org 3.4.1.lnk.Startup
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: emsisoft anti-malware => "c:\program files\emsisoft anti-malware\a2guard.exe" /d=60
MSCONFIG\startupreg: FreeScreenSharing => "C:\Users\Sharon\AppData\Local\FreeScreenSharing\FreeScreenSharing.exe"
MSCONFIG\startupreg: Google Update => "C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: OM2_Monitor => "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: THGuard => "C:\Program Files\TrojanHunter\THGuard.exe"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{C39C9369-DF78-4BA3-B71E-AAEBCCC33157}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{E6281A08-83AE-4E62-8A1A-2C189B8D1BE7}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{21C042E9-8F4D-4046-980E-4F45283AC8F2}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{61D8597E-437D-43DD-89CC-62F487F13081}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{CFE6DE30-FE46-4C60-B0B7-09C12C3214F0}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{B82921CB-E57D-4E9E-AADF-71E261A9A6FC}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{9434D6F6-9325-449C-83A6-688A78CD132F}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{5CDBFFA3-A48D-4445-88DC-6D5364623797}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{3EF2AD33-05C0-4EFB-8F08-EC2B6BBC3FE7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{C160F25F-0B64-4732-8263-97D07C2E73EB}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{0C16FA18-D5B1-4409-ACDA-1C3308C7BD9D}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{4839C1AC-5CD7-4C77-87DF-1A41AE07EE0D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{4F4D0146-ADF9-4BA9-B769-B9BE6A194012}] => (Allow) C:\Program Files\PremierOpinion\pmropn.exe
FirewallRules: [{976E81F9-33D6-45A9-905C-63E8E6B78923}] => (Allow) C:\Program Files\PremierOpinion\pmropn.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe] => Enabled:Earthlink
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/21/2015 03:52:12 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (07/21/2015 03:52:12 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (07/19/2015 04:15:47 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (07/19/2015 04:15:47 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (07/19/2015 04:14:34 AM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail (2592) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.
 
Error: (07/18/2015 01:17:37 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {b3eb9576-9865-4ecc-9a52-be690a9893e7}
 
Error: (07/18/2015 10:32:43 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3"1".
Dependent Assembly Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (07/18/2015 10:32:22 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3"1".
Dependent Assembly Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (07/18/2015 10:32:21 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3"1".
Dependent Assembly Microsoft.Windows.Networking.RtcDll,language="*",processorArchitecture="X86",publicKeyToken="6595b64144ccf1df",type="win32",version="5.2.1002.3" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (07/18/2015 09:28:59 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
 
System errors:
=============
Error: (07/21/2015 12:06:00 AM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 11, function 0.
Please contact your system vendor for technical assistance.
 
Error: (07/21/2015 12:06:00 AM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 9, function 0.
Please contact your system vendor for technical assistance.
 
Error: (07/20/2015 10:58:09 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Group Policy Client
 
Error: (07/20/2015 09:23:35 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt
 
Error: (07/20/2015 09:23:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
 
Error: (07/20/2015 09:21:32 PM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 11, function 0.
Please contact your system vendor for technical assistance.
 
Error: (07/20/2015 09:21:32 PM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 9, function 0.
Please contact your system vendor for technical assistance.
 
Error: (07/20/2015 09:17:25 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {022105BD-948A-40C9-AB42-A3300DDF097F}
 
Error: (07/19/2015 04:12:53 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 4:10:36 AM on 7/19/2015 was unexpected.
 
Error: (07/18/2015 09:27:58 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt
 
 
Microsoft Office:
=========================
Error: (04/19/2015 10:43:02 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20499 seconds with 120 seconds of active time.  This session ended with a crash.
 
Error: (04/17/2015 10:53:03 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2093 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (09/12/2014 08:49:26 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 516 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (09/05/2012 11:47:41 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 322286 seconds with 720 seconds of active time.  This session ended with a crash.
 
 
CodeIntegrity Errors:
===================================
  Date: 2015-07-20 19:27:23.967
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-20 19:27:23.920
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-20 19:27:23.889
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-20 19:27:23.842
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-20 19:27:19.653
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-20 19:27:19.575
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-20 19:27:19.528
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-20 19:27:19.482
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-20 19:27:19.079
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgmfx86.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-20 19:27:19.017
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\AVG\AVG2015\Drivers\avgmfx86.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ 64 X2 Dual Core Processor 3600+
Percentage of memory in use: 54%
Total physical RAM: 1917.94 MB
Available physical RAM: 865.2 MB
Total Virtual: 4053.84 MB
Available Virtual: 2503.35 MB
 
==================== Drives ================================
 
Drive c: (COMPAQ) (Fixed) (Total:140.67 GB) (Free:91.6 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Recovery) (Fixed) (Total:8.38 GB) (Free:1.01 GB) NTFS ==>[system with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 149.1 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=140.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=8.4 GB) - (Type=07 NTFS)
 
==================== End of log ============================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI