[removed]
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
() C:\Windows\System32\WLTRYSVC.EXE
(Dell Inc.) C:\Windows\System32\BCMWLTRY.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(IDT, Inc.) C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(AOL Inc.) C:\Program Files\Common Files\AOL\1429842640\ee\aolsoftware.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(AWS Convergence Technologies, Inc.) C:\Program Files\AWS\WeatherBug\Weather.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEstSrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.28.1\GoogleCrashHandler.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(SupportSoft, Inc.) C:\Program Files\CenturyLink\QuickCare\bin\sprtsvc.exe
(IDT, Inc.) C:\Windows\System32\stacsv.exe
(SupportSoft, Inc.) C:\Program Files\CenturyLink\QuickCare\bin\tgsrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Users\Scott\Downloads\aswMBR.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [SigmatelSysTrayApp] => C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2007-11-12] (IDT, Inc.)
HKLM\…\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5188112 2014-12-16] (AVG Technologies CZ, s.r.o.)
HKLM\…\Run: [WSHelperSetup.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020192 2014-06-25] (Wondershare)
HKLM\…\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020192 2014-06-25] (Wondershare)
HKLM\…\Run: [HostManager] => C:\Program Files\Common Files\AOL\1429842640\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.)
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2008-08-06] (Citrix Online, a division of Citrix Systems, Inc.)
HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\…\Run: [Weather] => C:\Program Files\AWS\WeatherBug\Weather.exe [1652736 2011-10-05] (AWS Convergence Technologies, Inc.)
HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\…\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [68856 2008-08-06] (Google Inc.)
HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\…\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\…\Run: [WSHelperSetup.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020192 2014-06-25] (Wondershare)
HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\…\Run: [Viber] => C:\Users\Scott\AppData\Local\Viber\Viber.exe [936656 2014-10-20] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyServer: [S-1-5-21-4285762069-3129431747-2670039461-1000] => :0
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
SearchScopes: HKLM -> DefaultScope value is missing
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2012-03-26] (Adobe Systems Incorporated)
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-03-26] (Adobe Systems Incorporated)
BHO: No Name -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> No File
BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22] (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll [2011-05-13] (Microsoft Corporation)
BHO: No Name -> {A317CB83-299C-4FC8-9ED7-2D64117D98EE} -> No File
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-23] (Google Inc.)
BHO: AcroIEToolbarHelper Class -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14] (Adobe Systems Incorporated)
BHO: Google Dictionary Compression sdch -> {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -> C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll No File
BHO: CBrowserHelperObject Object -> {CA6319C0-31B7-401E-A518-A07C3DB8F777} -> C:\Program Files\Dell\BAE\BAE.dll [2006-11-09] (Dell Inc.)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-02-28] (Microsoft Corporation.)
BHO: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll [2010-03-23] (Yahoo! Inc)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06] (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14] (Adobe Systems Incorporated)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-02-28] (Microsoft Corporation.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-4285762069-3129431747-2670039461-1000 -> Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-4285762069-3129431747-2670039461-1000 -> No Name - {A057A204-BACC-4D26-9990-79A187E2698E} - No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-11-28] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16] (Skype Technologies S.A.)
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll No File
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [152864 2010-04-08] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 172.21.118.23 172.21.118.24
Tcpip\..\Interfaces\{8FE46B69-5EBE-4C97-8567-8C339A909E76}: [DhcpNameServer] 172.21.118.23 172.21.118.24
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-28] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2010-04-28] ()
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll [2010-06-01] (Yahoo! Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-23] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-23] (Google Inc.)
FF Plugin: @viewpoint.com/VMP -> C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-03-26] (Adobe Systems Inc.)
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-15]
Chrome:
=======
CHR Profile: C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-24]
CHR Extension: (AdBlock) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-02-21]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-23]
CHR Extension: (Google Wallet) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-21]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2008-09-24] (Adobe Systems) [File not signed]
S3 AOL ACS; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [46184 2014-02-06] (AOL Inc.)
S2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3247120 2014-12-16] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-12-16] (AVG Technologies CZ, s.r.o.)
S3 GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [16680 2008-08-06] (Citrix Online, a division of Citrix Systems, Inc.)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 sprtsvc_quickcare; C:\Program Files\CenturyLink\QuickCare\bin\sprtsvc.exe [206120 2011-06-07] (SupportSoft, Inc.)
S2 SupportSoft RemoteAssist; C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe [382320 2011-06-07] (SupportSoft, Inc.)
R2 tgsrvc_quickcare; C:\Program Files\CenturyLink\QuickCare\bin\tgsrvc.exe [185640 2011-06-07] (SupportSoft, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [2506752 2008-05-19] (Dell Inc.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) [File not signed]
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-30] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [200984 2014-07-21] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [189720 2014-10-24] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-10-29] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [197400 2014-10-20] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-06-23] (AVG Technologies)
R3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-29] (America Online, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)
S3 BCM42RLY; system32\drivers\BCM42RLY.sys [X]
S3 catchme; \??\C:\Users\Scott\AppData\Local\Temp\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
U3 aswMBR; \??\C:\Users\Scott\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Scott\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-27 16:44 - 2015-07-27 16:45 - 00017925 _____ C:\Users\Scott\Downloads\FRST.txt
2015-07-27 16:42 - 2015-07-27 16:44 - 00000000 ____D C:\FRST
2015-07-27 16:42 - 2015-07-27 16:42 - 01650688 _____ (Farbar) C:\Users\Scott\Downloads\FRST.exe
2015-07-27 16:40 - 2015-07-27 16:40 - 00002286 _____ C:\Users\Scott\Desktop\aswMBR.txt
2015-07-27 16:40 - 2015-07-27 16:40 - 00000512 _____ C:\Users\Scott\Desktop\MBR.dat
2015-07-27 15:49 - 2015-07-27 15:49 - 05198336 _____ (AVAST Software) C:\Users\Scott\Downloads\aswMBR.exe
2015-07-25 08:10 - 2015-07-14 11:02 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-07-25 08:10 - 2015-07-14 09:23 - 00296960 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-07-25 08:10 - 2015-07-03 11:04 - 01316864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-07-25 08:10 - 2015-06-24 21:57 - 02066432 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-07-25 08:09 - 2015-06-17 11:50 - 02264576 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-07-25 08:09 - 2015-06-17 10:09 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-07-25 08:09 - 2015-06-12 11:01 - 00298496 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-07-25 08:09 - 2015-05-31 03:11 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-07-25 08:09 - 2015-04-24 10:54 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-07-25 08:08 - 2015-06-27 11:03 - 00783872 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-07-25 08:08 - 2015-06-27 11:02 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-07-25 08:08 - 2015-06-27 11:02 - 00218112 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-07-25 08:08 - 2015-06-27 11:01 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-07-25 08:08 - 2015-06-27 09:21 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-07-25 08:08 - 2015-06-27 09:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-07-25 08:08 - 2015-06-12 08:13 - 00440768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-07-25 08:08 - 2015-01-08 19:17 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-07-25 08:07 - 2015-05-08 18:08 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-07-23 13:48 - 2015-07-23 13:48 - 00000000 __SHD C:\found.000
2015-07-16 22:01 - 2015-07-27 15:19 - 00000000 ____D C:\Users\Scott\AppData\Roaming\ViberPC
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-27 16:45 - 2014-02-21 11:38 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-27 15:59 - 2011-01-07 20:34 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-27 15:58 - 2011-01-07 20:34 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-27 15:45 - 2014-02-21 11:38 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-27 15:45 - 2011-08-23 20:27 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-27 15:26 - 2008-08-06 05:14 - 01772199 _____ C:\Windows\WindowsUpdate.log
2015-07-27 15:25 - 2006-11-02 05:33 - 00763586 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-27 15:19 - 2015-01-11 09:50 - 00000000 ____D C:\Users\Scott\AppData\Local\Viber
2015-07-27 15:18 - 2006-11-02 08:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-27 15:18 - 2006-11-02 07:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-27 15:18 - 2006-11-02 07:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-25 08:18 - 2006-11-02 07:47 - 00381224 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-25 08:14 - 2006-11-02 08:01 - 00032644 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-07-24 08:54 - 2008-01-20 21:47 - 00553360 _____ C:\Windows\PFRO.log
2015-07-23 16:21 - 2008-08-06 10:34 - 00000000 ____D C:\ProgramData\Google
2015-07-23 13:33 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\spool
2015-07-16 22:16 - 2014-07-26 08:42 - 00000374 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2015-07-16 21:57 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\Msdtc
2015-07-16 21:56 - 2006-11-02 05:22 - 55574528 _____ C:\Windows\system32\config\software_previous
2015-07-16 21:56 - 2006-11-02 05:22 - 44040192 _____ C:\Windows\system32\config\components_previous
2015-07-16 21:56 - 2006-11-02 05:22 - 28573696 _____ C:\Windows\system32\config\system_previous
2015-07-16 21:56 - 2006-11-02 05:22 - 00524288 _____ C:\Windows\system32\config\default_previous
2015-07-16 21:56 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2015-07-16 21:56 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2015-07-16 21:55 - 2011-12-11 19:09 - 00000000 ____D C:\Users\Mcx1
2015-07-16 21:55 - 2008-09-24 12:39 - 00000000 ____D C:\Users\Scott
2015-07-16 21:54 - 2011-01-07 20:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-07-16 21:54 - 2008-08-06 10:34 - 00000000 ____D C:\Program Files\Google
2015-07-16 21:54 - 2008-08-06 10:26 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-07-16 21:54 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\rescache
2015-07-16 21:53 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\registration
2015-07-16 15:34 - 2012-07-06 15:31 - 00000000 ____D C:\Users\Scott\AppData\Local\WeatherBug
2015-06-30 21:52 - 2011-10-22 10:42 - 00000000 ____D C:\Windows\Minidump
==================== Files in the root of some directories =======
2013-12-15 18:33 - 2013-12-15 18:33 - 0000000 _____ () C:\Users\Scott\AppData\Roaming\wklnhst.dat
2008-11-09 13:31 - 2008-11-09 13:31 - 0000552 _____ () C:\Users\Scott\AppData\Local\d3d8caps.dat
2010-02-08 19:50 - 2014-02-15 08:39 - 0006648 _____ () C:\Users\Scott\AppData\Local\d3d9caps.dat
2008-11-19 16:58 - 2015-02-25 12:28 - 0097280 _____ () C:\Users\Scott\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-09-17 17:34 - 2010-09-17 17:34 - 0000079 _____ () C:\Users\Scott\AppData\Local\DVDPATH.TXT
2008-12-29 18:45 - 2008-12-29 18:45 - 0008248 _____ () C:\Users\Scott\AppData\Local\en.ini
2012-06-05 21:25 - 2012-09-14 13:16 - 0004096 ____H () C:\Users\Scott\AppData\Local\keyfile3.drm
2014-08-27 19:58 - 2014-08-27 19:58 - 0000000 _____ () C:\Users\Scott\AppData\Local\{3F3553C7-2E81-479F-8C8D-774B22E21531}
2014-06-11 17:31 - 2014-06-11 17:31 - 0000000 _____ () C:\Users\Scott\AppData\Local\{EA8F7E9C-935E-4551-976C-2CF79EA2A98C}
2010-03-03 22:14 - 2010-03-03 22:14 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2010-12-09 21:01 - 2011-01-08 23:22 - 0002859 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
C:\Users\Scott\AppData\Local\temp\AcsInstall.dll
C:\Users\Scott\AppData\Local\temp\SHFOLDER.DLL
C:\Users\Scott\AppData\Local\temp\{67ED5974-33F3-4932-BDE3-5D291D13063A}-GoogleUpdateSetup.exe
Some zero byte size files/folders:
==========================
C:\Windows\System32\FlashPlayerInstaller.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-07-27 15:23
==================== End of log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 26-07-2015
Ran by [removed] at 2015-07-27 16:45:42
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-4285762069-3129431747-2670039461-500 - Administrator - Disabled)
Guest (S-1-5-21-4285762069-3129431747-2670039461-501 - Limited - Disabled)
Mcx1 (S-1-5-21-4285762069-3129431747-2670039461-1002 - Administrator - Enabled) => C:\Users\Mcx1
Scott (S-1-5-21-4285762069-3129431747-2670039461-1000 - Administrator - Enabled) => C:\Users\Scott
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: AVG AntiVirus Free Edition 2014 (Enabled - Out of date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: AVG AntiVirus Free Edition 2014 (Enabled - Out of date) {B5F5C120-2089-702E-0001-553BB0D5A664}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
32 Bit HP CIO Components Installer (Version: 1.0.0 - Hewlett-Packard) Hidden
Adobe Bridge 1.0 (HKLM\…\{B74D4E10-6884-0000-0000-000000000103}) (Version: 001.000.004 - Adobe Systems)
Adobe Creative Suite 2 (HKLM\…\{0134A1A1-C283-4A47-91A1-92F19F960372}) (Version: - )
Adobe Flash Player 18 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader 9.5.1 (HKLM\…\{AC76BA86-7AD7-1033-7B44-A95000000001}) (Version: 9.5.1 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM\…\Advanced Audio FX Engine) (Version: - )
Advanced Video FX Engine (HKLM\…\Advanced Video FX Engine) (Version: - )
Aleks 3.8 (HKLM\…\Aleks 3.8) (Version: - )
AOL Uninstaller (Choose which Products to Remove) (HKLM\…\AOL Uninstaller) (Version: - AOL Inc.)
Apple Application Support (HKLM\…\{553255F3-78FD-40F1-A6F8-6882140265FE}) (Version: 1.2.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}) (Version: 3.0.1.3 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft PhotoImpression 6 (HKLM\…\{D03E7B00-CA85-4684-9321-1888873C34BD}) (Version: 6 - ArcSoft)
AVG 2014 (HKLM\…\AVG) (Version: 2014.0.4800 - AVG Technologies)
AVG 2014 (Version: 14.0.4257 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4800 - AVG Technologies) Hidden
Bing Bar (HKLM\…\{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}) (Version: 7.0.609.0 - Microsoft Corporation)
Bing Rewards Client Installer (Version: 16.0.345.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\…\{8A253629-0511-4854-8B4E-46E57E66005C}) (Version: 2.0.1.2 - Apple Inc.)
Browser Address Error Redirector (HKLM\…\{62230596-37E5-4618-A329-0D21F529A86F}) (Version: 1.00.0000 - Dell)
BufferChm (Version: 100.0.170.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 4.14 - Piriform)
CenturyLink Installer (HKLM\…\{C96FF998-45BD-411E-9253-B7F2660FE280}) (Version: 1.0 - CenturyLink, Inc.)
CenturyLink Personal Digital Vault™ (HKLM\…\{B97FD5DD-1226-49AD-AE6C-BF9DE1468F05}) (Version: 1.0.0004 - CenturyLink)
CenturyLink QuickCare 2.7 (HKLM\…\CenturyLinkQuickCare_is1) (Version: 2.7.1106.1010 - CenturyLink)
Cisco EAP-FAST Module (HKLM\…\{BF53252E-4AB2-4C7F-A0FD-6100755745E3}) (Version: 2.0.26 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\…\{76F9CF97-FC4B-4E20-B363-D127C888448F}) (Version: 1.0.11 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\…\{4E5386F5-C0F6-4532-A54A-374865AEAB71}) (Version: 1.0.12 - Cisco Systems, Inc.)
Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Conexant HDA D330 MDC V.92 Modem (HKLM\…\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F) (Version: - )
D1500 (Version: 100.0.206.000 - Hewlett-Packard) Hidden
D1500_Help (Version: 100.0.206.000 - Hewlett-Packard) Hidden
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Getting Started Guide (HKLM\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell Support Center (HKLM\…\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}) (Version: 2.1.08060 - Dell)
Dell Touchpad (HKLM\…\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1.103.4 - Alps Electric)
Dell Webcam Center (HKLM\…\Dell Webcam Center) (Version: - )
Dell Webcam Manager (HKLM\…\Dell Webcam Manager) (Version: - )
Dell Wireless WLAN Card (HKLM\…\Broadcom 802.11b Network Adapter) (Version: 4.170.25.12 - Dell Inc.)
Desktop QR Scanner (HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\…\c31ebb7005be8b35) (Version: 1.0.1.6 - ODOA)
Destinations (Version: 82.0.173.000 - Hewlett-Packard) Hidden
DeviceDiscovery (Version: 100.0.190.000 - Hewlett-Packard) Hidden
Digital Line Detect (HKLM\…\{E646DCF0-5A68-11D5-B229-002078017FBF}) (Version: 1.21 - BVRP Software, Inc)
DJ_SF_03_D1500_Software (Version: 100.0.206.000 - Hewlett-Packard) Hidden
DJ_SF_03_D1500_Software_Min (Version: 100.0.206.000 - Hewlett-Packard) Hidden
dj6980 (Version: 82.0.242.000 - Hewlett-Packard) Hidden
Download Updater (AOL Inc.) (HKLM\…\SoftwareUpdUtility) (Version: - AOL Inc.) <==== ATTENTION
Driver Whiz (HKLM\…\{97BBECCF-B1FD-4010-8D4B-EFC9E3CCEECF}) (Version: 8.0.1 - Driver Whiz)
EDocs (HKLM\…\{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}) (Version: - )
EPSON Attach To Email (HKLM\…\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON)
EPSON Attach To Email (Version: 1.01.0000 - SEIKO EPSON) Hidden
EPSON Copy Utility 3 (HKLM\…\{67EDD823-135A-4D59-87BD-950616D6E857}) (Version: 3.3.0.0 - )
EPSON Event Manager (HKLM\…\{48F22622-1CC2-4A83-9C1E-644DD96F832D}) (Version: 1.80.00 - )
EPSON Perfection V200 Photo Scanner Driver Update (HKLM\…\{1C278B97-9D25-48B0-9A4E-F4F2BB992043}) (Version: - )
EPSON Scan (HKLM\…\EPSON Scanner) (Version: - )
EPSON Scan Assistant (HKLM\…\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.11.00 - )
Free NaturalReader (HKLM\…\{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}) (Version: 9.0 - NaturalSoft Limited)
Google Chrome (HKLM\…\Google Chrome) (Version: 43.0.2357.81 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6710.2136 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
GoToAssist 8.0.0.514 (HKLM\…\GoToAssist) (Version: - )
GPBaseService (Version: 100.0.187.000 - Hewlett-Packard) Hidden
HP Customer Participation Program 10.0 (HKLM\…\HPExtendedCapabilities) (Version: 10.0 - HP)
HP Deskjet D1500 Printer Driver Software 10.0 Rel .3 (HKLM\…\{0CE5F45E-F6CC-4638-B0DD-BB7F6EF56713}) (Version: 10.0 - HP)
HP Deskjet Printer Driver Software. 8.0.B (HKLM\…\{0411A7A4-23D4-47ad-B109-3CBE7E8093F1}) (Version: 8.0 - HP)
HP Imaging Device Functions 10.0 (HKLM\…\HP Imaging Device Functions) (Version: 10.0 - HP)
HP Photosmart Essential (HKLM\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
HP Photosmart Essential 2.5 (HKLM\…\HP Photosmart Essential) (Version: 2.5 - HP)
HP Smart Web Printing (HKLM\…\HP Smart Web Printing) (Version: 3.5 - HP)
HP Solution Center 10.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 10.0 - HP)
HP Update (HKLM\…\{612F4E20-3661-4D44-AD79-823F1B613FB3}) (Version: 5.002.008.001 - Hewlett-Packard)
HPProductAssistant (Version: 100.0.170.000 - Hewlett-Packard) Hidden
HPSSupply (Version: 100.0.170.000 - Hewlett-Packard) Hidden
InboxAce Internet Explorer Toolbar (HKLM\…\InboxAce_1gbar Uninstall Internet Explorer) (Version: - Mindspark Interactive Network) <==== ATTENTION
Intel(R) Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - )
iTunes (HKLM\…\{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}) (Version: 9.1.1.12 - Apple Inc.)
Java(TM) 6 Update 5 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0160050}) (Version: 1.6.0.50 - Sun Microsystems, Inc.)
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Laptop Integrated Webcam Driver (1.04.01.1011) (HKLM\…\Creative OEM002) (Version: - )
Live! Cam Avatar Creator (HKLM\…\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.0817.1 - Creative Technology Ltd.)
Live! Cam Avatar v1.0 (HKLM\…\{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}) (Version: 1.0 - Creative Technology Ltd.)
LP6980_Help (Version: 82.0.242.000 - Hewlett-Packard) Hidden
LP6980Trb (Version: 82.0.242.000 - Hewlett-Packard) Hidden
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
MarketResearch (Version: 100.0.170.000 - Hewlett-Packard) Hidden
MathGV 4 (HKLM\…\{5EF2B896-B1C1-46E8-83AD-4F940B7A5982}) (Version: 4.0.0 - MathGV)
MediaDirect (HKLM\…\{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}) (Version: 3.5 - Dell)
Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
MGTEK dopisp (HKLM\…\{C25D2594-3136-4B33-9D32-8F0F5E81F349}) (Version: 5.1.2594 - MGTEK)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM\…\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM\…\{91110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Works (HKLM\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Modem Diagnostic Tool (HKLM\…\{F63A3748-B93D-4360-9AD4-B064481A5C7B}) (Version: 1.0.20.0 - Dell)
MSXML 4.0 SP2 (KB927978) (HKLM\…\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Music, Photos & Videos Launcher (HKLM\…\{D7769185-9A7C-48D4-8874-5388743A1DE2}) (Version: 1.00.0000 - Dell Inc.)
MyCenturyLink Toolbar (HKLM\…\qwesttoolbar) (Version: - CenturyLink)
NetWaiting (HKLM\…\{3F92ABBB-6BBF-11D5-B229-002078017FBF}) (Version: 2.5.44 - BVRP Software, Inc)
Office Depot PC Support Agent (HKLM\…\Office Depot PC Support Agent) (Version: 12.0.212.3 - Support.com, Inc.)
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0 - Microsoft Corporation) Hidden
OutlookAddinSetup (HKLM\…\{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}) (Version: 1.0.0 - CyberLink)
PhoneTrans Pro 3.7.3 (HKLM\…\{1FD2E976-6FCF-493C-979C-B99AAAF4081A}}_is1) (Version: 3.7.3 - iMobie Inc.)
Product Documentation Launcher (HKLM\…\{89CEAE14-DD0F-448E-9554-15781EC9DB24}) (Version: 1.00.0000 - Dell Inc.)
PSSWCORE (Version: 2.02.0000 - Hewlett-Packard) Hidden
QuickSet (HKLM\…\{4B6AD248-D3BF-426A-8D64-847288154F13}) (Version: 8.2.20 - Dell Inc.)
QuickTime (HKLM\…\{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}) (Version: 7.66.71.0 - Apple Inc.)
Respondus LockDown Browser (HKLM\…\{C0E5147E-C9F3-4360-9ED0-2E875F11766C}) (Version: 1.02.0001 - Respondus, Inc.)
Riverpoint Writer (HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\…\FF389026-F961-42C5-BACD-B4A3AA73E0F3) (Version: 1.0 - Apollo Group, Inc.)
Segoe UI (Version: 15.4.2271.0615 - Microsoft Corp) Hidden
SF_CDB_ProductContext (Version: 82.0.242.000 - Hewlett-Packard) Hidden
SF_CDB_Software (Version: 82.0.242.000 - Hewlett-Packard) Hidden
Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 10.0 - HP)
Skype Toolbars (HKLM\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.3.7555 - Skype Technologies S.A.)
Skype™ 7.0 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartWebPrintingOC (Version: 100.0.189.000 - Hewlett-Packard) Hidden
SolutionCenter (Version: 100.0.175.000 - Hewlett-Packard) Hidden
Status (Version: 100.0.175.000 - Hewlett-Packard) Hidden
Suite Specific (Version: 2.0.0 - Adobe Systems, Incorporated) Hidden
Toolbox (Version: 100.0.170.000 - Hewlett-Packard) Hidden
Toolbox (Version: 82.0.173.000 - Hewlett-Packard) Hidden
TrayApp (Version: 100.0.170.000 - Hewlett-Packard) Hidden
Tweaking.com - Registry Backup (HKLM\…\Tweaking.com - Registry Backup) (Version: 1.9.0 - Tweaking.com)
UnloadSupport (Version: 10.0.0 - Hewlett-Packard) Hidden
Viber (HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\…\Viber) (Version: 4.4.0.134678 - Viber Media Inc)
VideoToolkit01 (Version: 100.0.128.000 - Hewlett-Packard) Hidden
Viewpoint Media Player (HKLM\…\ViewpointMediaPlayer) (Version: - )
Visual Studio 2012 x86 Redistributables (HKLM\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WeatherBug (HKLM\…\{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}) (Version: 7.0.0.10 - Earth Networks, Inc.)
WebReg (Version: 100.0.170.000 - Hewlett-Packard) Hidden
Windows Live Essentials (HKLM\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Wondershare MobileTrans ( Version 5.6.0 ) (HKLM\…\{18CDCEAA-A9E4-4A4C-AC0E-C15E87C30EA5}_is1) (Version: 5.6.0 - Wondershare)
Yahoo! Messenger (HKLM\…\Yahoo! Messenger) (Version: - Yahoo! Inc.)
Yahoo! Software Update (HKLM\…\Yahoo! Software Update) (Version: - )
Yahoo! Toolbar (HKLM\…\Yahoo! Companion) (Version: - )
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-4285762069-3129431747-2670039461-1000_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-4285762069-3129431747-2670039461-1000_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-4285762069-3129431747-2670039461-1000_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
==================== Restore Points =========================
16-01-2015 04:00:22 Windows Update
17-01-2015 01:00:00 Scheduled Checkpoint
18-01-2015 01:00:01 Scheduled Checkpoint
26-02-2015 16:47:03 Scheduled Checkpoint
14-03-2015 20:05:51 Scheduled Checkpoint
19-03-2015 13:44:17 Windows Update
23-04-2015 17:34:41 Scheduled Checkpoint
23-04-2015 21:31:03 Device Driver Package Install: America Online, Inc. Network adapters
24-04-2015 03:00:22 Windows Update
25-04-2015 00:00:00 Scheduled Checkpoint
24-05-2015 17:10:40 Scheduled Checkpoint
25-05-2015 03:00:20 Windows Update
26-05-2015 13:55:41 Scheduled Checkpoint
08-06-2015 15:44:50 Scheduled Checkpoint
09-06-2015 20:21:27 Removed Live! Cam Avatar
10-06-2015 03:00:29 Windows Update
10-06-2015 23:44:34 Scheduled Checkpoint
12-06-2015 06:36:39 Scheduled Checkpoint
13-06-2015 00:00:00 Scheduled Checkpoint
14-06-2015 00:00:01 Scheduled Checkpoint
14-06-2015 13:37:16 Windows Modules Installer
16-07-2015 21:44:03 Restore Operation
23-07-2015 19:25:24 Scheduled Checkpoint
24-07-2015 12:17:09 Scheduled Checkpoint
25-07-2015 08:07:23 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 05:23 - 2014-07-26 08:24 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {3388939A-D930-4859-8896-D3C52F758AF3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {5698D810-CDAA-4265-A86A-8E94E997AC23} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-05] (Google Inc.)
Task: {94BAC943-A000-47A0-8B98-D6E9F17BBBBA} - System32\Tasks\{71747592-822A-4F68-9B3C-3DB3B6BB1AE7} => C:\Program Files\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.)
Task: {A540D80F-4C5C-4132-8707-A5B9B4C4170C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-05] (Google Inc.)
Task: {AFB40540-DE88-4AB4-8FAE-B86E39B51BB0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd)
Task: {CBD71D60-1E13-4E90-A4E0-8FBD0A6F601E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-27] (Adobe Systems Incorporated)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{00AA6145-8251-4343-ABB2-F6EEE644A49D}.job => C:\Windows\system32\msfeedssync.exe
==================== Loaded Modules (Whitelisted) ==============
2008-08-06 10:33 - 2008-05-19 01:26 - 00024064 _____ () C:\Windows\System32\WLTRYSVC.EXE
2008-08-06 10:33 - 2008-05-19 01:25 - 00054784 _____ () C:\Windows\System32\bcmwlrmt.dll
2014-08-01 22:53 - 2014-06-25 10:13 - 01457664 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2014-08-01 22:53 - 2014-05-19 17:19 - 00137728 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2014-05-02 16:36 - 2014-02-10 13:44 - 04592128 _____ () C:\Users\Scott\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
2014-05-02 16:36 - 2014-02-10 13:44 - 00112128 _____ () C:\Users\Scott\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\Scott\Desktop\SDC10132.AVI:TOC.WMV
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Office Depot PC Support Agent => ""="Office Depot PC Support Agent"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Office Depot PC Support Agent => ""="Office Depot PC Support Agent"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SupportSoft RemoteAssist => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4285762069-3129431747-2670039461-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\inspiron_NB_1280x864_03.jpg
DNS Servers: 172.21.118.23 - 172.21.118.24
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk => C:\Windows\pss\Adobe Acrobat Speed Launcher.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk => C:\Windows\pss\Adobe Gamma.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk => C:\Windows\pss\Digital Line Detect.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickSet.lnk => C:\Windows\pss\QuickSet.lnk.CommonStartup
MSCONFIG\startupreg: Acrobat Assistant 7.0 => "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: Apoint => C:\Program Files\DellTPad\Apoint.exe
MSCONFIG\startupreg: Broadcom Wireless Manager UI => C:\Windows\system32\WLTRAY.exe
MSCONFIG\startupreg: CenturyLinkTouchPointAgent => "C:\Program Files\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe" /autostart
MSCONFIG\startupreg: DELL Webcam Manager => "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
MSCONFIG\startupreg: dscactivate => "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
MSCONFIG\startupreg: ECenter => C:\Dell\E-Center\EULALauncher.exe
MSCONFIG\startupreg: EEventManager => C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
MSCONFIG\startupreg: ehTray.exe => C:\Windows\ehome\ehTray.exe
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: HP Software Update => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: IAAnotif => "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Messenger (Yahoo!) => "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
MSCONFIG\startupreg: OEM02Mon.exe => C:\Windows\OEM02Mon.exe
MSCONFIG\startupreg: PCMService => "C:\Program Files\Dell\MediaDirect\PCMService.exe"
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: QuickCare => C:\Program Files\CenturyLink\QuickCare\bin\sprtcmd.exe /P QuickCare
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SigmatelSysTrayApp => %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
MSCONFIG\startupreg: swg => "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: Weather => C:\Program Files\AWS\WeatherBug\Weather.exe 1
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide
MSCONFIG\startupreg: WMPNSCFG => C:\Program Files\Windows Media Player\WMPNSCFG.exe
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [{8E7B4B00-8331-4D3A-8233-F1D42BEB9B56}] => (Allow) C:\Program Files\Dell\MediaDirect\MediaDirect.exe
FirewallRules: [{6185BFFE-DA46-4161-B09B-4880AA7D5217}] => (Allow) C:\Program Files\Dell\MediaDirect\PCMService.exe
FirewallRules: [{691BA540-3D6B-4E72-ACF1-D74D7A87BE28}] => (Allow) C:\Program Files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe
FirewallRules: [{1A9D7E47-BF8F-4025-A667-1E914D264E59}] => (Allow) C:\Program Files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe
FirewallRules: [{B98F074C-0792-49C1-821A-8614534B82D7}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{68391ADE-9EE1-4663-98EE-356F0739A406}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{F789CA20-4065-4C65-90F1-09E82C143D05}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{838A831D-EC09-4F6C-8207-1A98C5DF3916}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{FA68FF9F-7403-4724-B0E3-A4E36F9239D3}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{0DD68AD9-357C-4113-BB86-5DC714367227}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{C22AB342-243C-400A-8B43-FAF5CCF54552}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{FBD8517E-176A-4000-ABCC-EC7A876CC6A5}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{C86FBD36-527D-482B-AF87-27D334096C11}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{2E777F9A-E42D-460C-9245-8B0B55451865}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{CDC42116-94EE-43DA-98FD-1F6F8ED1DECE}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{125E40D6-7F1E-4A3E-921A-D62A12DB3009}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{63C4C9F3-9014-43C6-B381-70D025CCAFF7}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{5DA428B0-2355-4D4C-B01E-79297C8FDA0A}] => (Allow) LPort=80
FirewallRules: [{7AC1E402-AB98-4E3B-8DC9-454B925A9B2C}] => (Allow) LPort=80
FirewallRules: [{D135638E-A585-434C-B657-5B7E814578E5}] => (Allow) LPort=80
FirewallRules: [{EE0EDA24-89AF-4D61-A543-5D1ECB64E0A8}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{A910A9F1-F8BA-4E4A-BFCC-2B9F0C26D66E}] => (Allow) LPort=2869
FirewallRules: [{CE7A1104-92D2-46D8-AC84-B76C2CD1B089}] => (Allow) LPort=1900
FirewallRules: [{C128A76F-BC3C-40EA-9380-802279A4C50C}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{FB03A01C-0691-4D7B-8291-A0A5B31534CC}] => (Allow) C:\Program Files\Windows Live\Mesh\MOE.exe
FirewallRules: [{8047C390-BA49-4305-B62A-82E504C13D08}] => (Allow) C:\Program Files\AVG\AVG10\avgmfapx.exe
FirewallRules: [{94ADA797-3A07-4153-AD25-46A4C83E300D}] => (Allow) C:\Program Files\AVG\AVG10\avgmfapx.exe
FirewallRules: [{326D28E5-7F34-42F3-91E3-C37B85E4319D}] => (Allow) C:\Program Files\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{26D410DF-56D3-44E2-86C4-B3DC67F8D366}] => (Allow) C:\Program Files\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{6A94767B-C1E4-4F05-820C-60F71CDC7B22}] => (Allow) C:\Program Files\AVG\AVG2012\avgnsx.exe
FirewallRules: [{72BBCCB1-D842-47C0-806B-8D6D8FCC5D5B}] => (Allow) C:\Program Files\AVG\AVG2012\avgnsx.exe
FirewallRules: [{3239EE78-EF64-40FD-9DFD-41D99BA74F62}] => (Allow) C:\Program Files\AVG\AVG2012\avgdiagex.exe
FirewallRules: [{55D44644-63D3-4821-A8C1-671818045DF1}] => (Allow) C:\Program Files\AVG\AVG2012\avgdiagex.exe
FirewallRules: [{CE3D4F5F-38D5-4C12-A2A3-44DB72556C30}] => (Allow) C:\Program Files\AVG\AVG2012\avgemcx.exe
FirewallRules: [{10C4A9F5-3DDA-4054-B887-8E9B5CA85021}] => (Allow) C:\Program Files\AVG\AVG2012\avgemcx.exe
FirewallRules: [{4BF019B2-83A7-4EF6-A125-77C3226D202B}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{2F9EE299-0638-43CA-856E-E8EB404E6032}] => (Allow) C:\Program Files\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{A98ED5BB-26E9-43C4-AE40-7B21D684D5FD}] => (Allow) C:\Program Files\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{6040A91D-83CB-4072-B72C-BAEA8F4F3DF5}] => (Allow) C:\Program Files\AVG\AVG2014\avgnsx.exe
FirewallRules: [{78369529-8040-4B9B-A3C4-5CB14D29FE32}] => (Allow) C:\Program Files\AVG\AVG2014\avgnsx.exe
FirewallRules: [{C02A4202-5CE1-4FD9-BB0A-E21282033854}] => (Allow) C:\Program Files\AVG\AVG2014\avgdiagex.exe
FirewallRules: [{C7A2C6C2-FE1C-469F-AE8D-AD9CBA94B3EA}] => (Allow) C:\Program Files\AVG\AVG2014\avgdiagex.exe
FirewallRules: [{13E1A35C-7C83-4AB0-92B8-4B99C564C6AB}] => (Allow) C:\Program Files\AVG\AVG2014\avgemcx.exe
FirewallRules: [{A34A7DFC-6B96-4809-AE28-4012DDCCE34F}] => (Allow) C:\Program Files\AVG\AVG2014\avgemcx.exe
FirewallRules: [{0581315C-2504-4A7E-B8C6-802496BAA0F5}] => (Allow) C:\Program Files\AVG\AVG2014\avgnsx.exe
FirewallRules: [{4C48C4C8-2D2D-4E38-9DCE-E00C36244BFA}] => (Allow) C:\Program Files\AVG\AVG2014\avgnsx.exe
FirewallRules: [{6233AF9C-CD58-4334-9ABF-FE6063A19C35}] => (Allow) C:\Program Files\AVG\AVG2014\avgdiagex.exe
FirewallRules: [{7E0F621D-3C44-4AD7-9479-0741F08FADD6}] => (Allow) C:\Program Files\AVG\AVG2014\avgdiagex.exe
FirewallRules: [{5980D6E8-5141-48F1-8CE2-88713C8E1949}] => (Allow) C:\Program Files\AVG\AVG2014\avgemcx.exe
FirewallRules: [{AE6C550D-A40A-4B3B-AB37-65914E42CE33}] => (Allow) C:\Program Files\AVG\AVG2014\avgemcx.exe
FirewallRules: [{EC1C5D97-D2B7-4CFD-B4C0-269DD1BF2594}] => (Allow) C:\Program Files\Common Files\AOL\acs\AOLDial.exe
FirewallRules: [{046D16DC-5B55-41BA-A616-B146E6BAC44B}] => (Allow) C:\Program Files\Common Files\AOL\acs\AOLDial.exe
FirewallRules: [{E5F481E7-7798-4895-AB93-74DC5860738A}] => (Allow) C:\Program Files\Common Files\AOL\acs\AOLacsd.exe
FirewallRules: [{711C9C8D-771E-4C98-8358-093BA85E0D48}] => (Allow) C:\Program Files\Common Files\AOL\acs\AOLacsd.exe
FirewallRules: [{12FD1B1D-F55F-4234-9114-8204674C0559}] => (Allow) C:\Program Files\Common Files\AOL\1429842640\ee\aolsoftware.exe
FirewallRules: [{598D0E65-0C93-41B8-A118-BCCC1F90083D}] => (Allow) C:\Program Files\Common Files\AOL\1429842640\ee\aolsoftware.exe
FirewallRules: [{6B6E0047-ADC7-4973-B912-CCBE84130E4A}] => (Allow) C:\Program Files\AOL Desktop 9.7\waol.exe
FirewallRules: [{9A925E61-9D1F-4137-A834-DBDA190041CC}] => (Allow) C:\Program Files\AOL Desktop 9.7\waol.exe
FirewallRules: [{F06704C6-8302-4109-B80F-D09B3404406A}] => (Allow) C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{F4CD2AC3-790C-4CF5-9A44-6DD33E0BA644}] => (Allow) C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{BDEC1A00-771C-48ED-AC2F-862C985F8549}] => (Allow) C:\Program Files\Common Files\AOL\Loader\aolload.exe
FirewallRules: [{18287266-E57E-4734-B7D3-CF2ADB06F0BC}] => (Allow) C:\Program Files\Common Files\AOL\Loader\aolload.exe
FirewallRules: [{259AD170-4908-4FA4-A9E9-96E993600257}] => (Allow) C:\Program Files\Common Files\AOL\System Information\sinf.exe
FirewallRules: [{36E03515-9F29-4219-9CD5-81E58E312362}] => (Allow) C:\Program Files\Common Files\AOL\System Information\sinf.exe
FirewallRules: [{0DC1FE7A-028C-4A5A-8F2E-BCB138367D61}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
Name: Microsoft ISATAP Adapter #3
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
==================== Event log errors: =========================
Application errors:
==================
Error: (07/27/2015 04:38:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:40 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:40 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:39 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
System errors:
=============
Error: (07/27/2015 03:35:33 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer JACKSON
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{8FE46B69-5EBE-4C97-8567-8C339A909E.
The master browser is stopping or an election is being forced.
Error: (07/27/2015 03:20:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: BCM42RLY%%2
Error: (07/27/2015 03:20:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: BCM42RLY%%2
Error: (07/27/2015 03:20:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: BCM42RLY%%2
Error: (07/27/2015 03:20:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: BCM42RLY%%2
Error: (07/27/2015 03:20:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: BCM42RLY%%2
Error: (07/27/2015 03:20:31 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: HP CUE DeviceDiscovery Service
Error: (07/27/2015 03:19:30 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: AVGIDSAgent3758213659 (0xE001CA1B)
Error: (07/27/2015 03:19:30 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
Error: (07/27/2015 03:18:45 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 11:30:51 AM on 7/25/2015 was unexpected.
Microsoft Office:
=========================
Error: (07/27/2015 04:38:49 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:40 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:40 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:39 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
Error: (07/27/2015 04:38:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: GetLargeResourceRecord: opt 65002 optlen 8 wrong
CodeIntegrity Error:
===================================
Date: 2015-07-27 16:44:45.214
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-27 16:44:44.797
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-27 16:44:44.312
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-27 16:44:43.897
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-27 16:44:43.292
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-27 16:44:42.873
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-27 16:44:42.402
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-07-27 16:44:41.923
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-06-30 21:55:54.132
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-06-30 21:55:53.677
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU T5750 @ 2.00GHz
Percentage of memory in use: 70%
Total physical RAM: 3061.31 MB
Available physical RAM: 916.01 MB
Total Virtual: 6332.88 MB
Available Virtual: 4110.28 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:220.58 GB) (Free:124.55 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (RECOVERY) (Fixed) (Total:9.77 GB) (Free:5.47 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: 00000080)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=9.8 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=220.6 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=2.5 GB) - (Type=OF Extended)
==================== End of log ============================