I cleared the browser cache. Did not reset the browser settings because of password etc. loss until I know I must do this.
After I posted my first board message, I used the tools provided by WTT to obtain the logs for your review. This instantly eliminated the fbstatic-a.akamaihd.net visible scrolling bar from the bottom left corner of the Facebook log in page. I was able to log into Facebook with no further issue and my system has been running much faster since.
Here are log results. I am so thankful to have your help with this issue. Please help me rid my system from anything you deem threatening.
Additional scan result of Farbar Recovery Scan Tool (x86) Version:02-08-2015 01
Ran by [removed] (2015-08-05 00:01:36)
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1766275910-2450894708-632072239-500 - Administrator - Disabled)
Guest (S-1-5-21-1766275910-2450894708-632072239-501 - Limited - Disabled)
Janelle (S-1-5-21-1766275910-2450894708-632072239-1000 - Administrator - Enabled) => C:\Users\Janelle
Mary (S-1-5-21-1766275910-2450894708-632072239-1002 - Administrator - Enabled) => C:\Users\Mary
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Activation Assistant for the 2007 Microsoft Office suites (HKLM\…\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
ActiveCheck component for HP Active Support Library (Version: 3.0.0.2 - Hewlett-Packard) Hidden
Adobe Flash Player 18 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader 8 (HKLM\…\{AC76BA86-7AD7-1033-7B44-A80000000002}) (Version: 8.0.0 - Adobe Systems Incorporated)
AppCore (Version: 1 - Symantec Corporation) Hidden
AV (Version: 1 - Symantec Corporation) Hidden
ccCommon (Version: 106.2.0.21 - Symantec) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.01 - Piriform)
Cisco Connect (HKLM\…\Cisco Connect) (Version: 1.2.10104.2 - Cisco Consumer Products LLC)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
ESU for Microsoft Vista (HKLM\…\{88A548E6-4B09-43E7-AD55-3C7D1B37706D}) (Version: 2.0.2.1 - Hewlett-Packard)
Google Chrome (HKLM\…\Google Chrome) (Version: 44.0.2403.130 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\…\CNXT_MODEM_HDA_HSF) (Version: - )
HP Active Support Library (HKLM\…\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}) (Version: 3.1.9.1 - Hewlett-Packard)
HP Customer Experience Enhancements (HKLM\…\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.1.0.2278 - Hewlett-Packard)
HP Easy Setup - Frontend (HKLM\…\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.1.0.2279 - Hewlett-Packard)
HP Help and Support (HKLM\…\{9061CEF2-51F5-42C9-8A70-9ED351C6597A}) (Version: 1.1.0 - Hewlett-Packard)
HP Pavilion Webcam Driver for Vista v061.001.00005 (HKLM\…\{5CA81D12-9EC2-4082-972B-43ECA63F41F2}) (Version: 061.001.00005 - Chicony)
HP Photosmart Essential 2.0 (HKLM\…\HP Photosmart Essential) (Version: 2.0 - HP)
HP Quick Launch Buttons 6.20 B1 (HKLM\…\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.20 B1 - Hewlett-Packard)
HP QuickPlay 3.2 (HKLM\…\{45D707E9-F3C4-11D9-A373-0050BAE317E1}) (Version: - )
HP Total Care Advisor (HKLM\…\{F6B29003-A078-4491-AFBE-62EFB6CFFE19}) (Version: 1.1.19 - Hewlett-Packard)
HP Update (HKLM\…\{612F4E20-3661-4D44-AD79-823F1B613FB3}) (Version: 5.002.008.001 - Hewlett-Packard)
HP User Guides 0041 (HKLM\…\{AF0B98A9-F7E2-4FF5-88C7-7960EB91752B}) (Version: 1.03.0002 - Hewlett-Packard)
HP Wireless Assistant (HKLM\…\{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}) (Version: 3.00 H3 - Hewlett-Packard)
HPAsset component for HP Active Support Library (Version: 3.0.2.2 - Hewlett-Packard) Hidden
HPNetworkAssistant (HKLM\…\{228C6B46-64E2-404E-898A-EF0830603EF4}) (Version: 1.1.70 - Hewlett-Packard.)
Internet Explorer (Enable DEP) (HKLM\…\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb) (Version: - )
IrfanView (remove only) (HKLM\…\IrfanView) (Version: - )
Java 8 Update 31 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Java(TM) SE Runtime Environment 6 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0160000}) (Version: 1.6.0.0 - Sun Microsystems, Inc.)
LightScribe 1.4.136.1 (Version: 1.4.136.1 - http://www.lightscribe.com)Hidden
LiveUpdate 3.2 (Symantec Corporation) (HKLM\…\LiveUpdate) (Version: 3.2.0.41 - Symantec Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Fix it Center (HKLM\…\{B7588D45-AFDC-4C93-9E2E-A100F3554B64}) (Version: 1.0.0100 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\…\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
Move Media Player (HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Move Media Player) (Version: - Move Networks)
MSCU for Microsoft Vista (HKLM\…\{3FFB3B34-D639-4384-9AE9-DDE58430D86F}) (Version: 1.0.1.1 - Hewlett-Packard)
MSRedist (Version: 1.0.0.0 - Symantec Corporation) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM\…\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM\…\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
muvee autoProducer 6.0 (HKLM\…\{0BFC200F-C45D-4271-AF34-4CA969225DEB}) (Version: 6.00.050 - muvee Technologies)
My HP Games (HKLM\…\WildTangent hplaptop Master Uninstall) (Version: HPLAP0503 - WildTangent)
Norton AntiVirus (Version: 14.2.0.29 - Symantec Corporation) Hidden
Norton Confidential Browser Component (Version: 1.5.0.29 - Symantec Corporation) Hidden
Norton Confidential Web Protection Component (Version: 1.5.0.29 - Symantec Corporation) Hidden
Norton Internet Security (Symantec Corporation) (HKLM\…\SymSetup.{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}) (Version: 10.2.0.30 - Symantec Corporation)
Norton Internet Security (Version: 10.1.0 - Symantec Corp.) Hidden
Norton Internet Security (Version: 10.2.0.30 - Symantec Corporation) Hidden
Norton Protection Center (Version: 2007.2.0.22 - Symantec Corporation) Hidden
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: 1.4 - NVIDIA Corporation)
PMB (HKLM\…\{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}) (Version: 5.5.00.11260 - Sony Corporation)
PSSWCORE (Version: 2.00.5000 - Hewlett-Packard) Hidden
QuickTime 7 (HKLM\…\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Rhapsody (HKLM\…\Rhapsody) (Version: - )
Rhapsody Player Engine (HKLM\…\{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}) (Version: 1.0.604 - RealNetworks)
Roxio Creator Audio (HKLM\…\{83FFCFC7-88C6-41c6-8752-958A45325C82}) (Version: 3.4.0 - Roxio)
Roxio Creator Basic v9 (HKLM\…\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}) (Version: 3.4.0 - Roxio)
Roxio Creator Copy (HKLM\…\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio)
Roxio Creator Data (HKLM\…\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio)
Roxio Creator EasyArchive (HKLM\…\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio)
Roxio Creator Tools (HKLM\…\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio)
Roxio Express Labeler 3 (HKLM\…\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 3.2.1 - Roxio)
Roxio MyDVD Basic v9 (HKLM\…\{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}) (Version: 9.0.551 - Roxio)
SPBBC 32bit (Version: 3.2.0.21 - Symantec Corporation) Hidden
Symantec Real Time Storage Protection Component (Version: 10.1.4.2 - Symantec Corporation) Hidden
SymNet (Version: 7.2.0.15 - Symantec Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 11.0.7.0 - Synaptics)
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{e3e02f12-2adb-478c-8742-5f0819f9f0f4}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{e473a65c-8087-49a3-affd-c5bc4a10669b}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{f4c28532-b9d0-4950-a2df-e83f9929242b}\InprocServer32 -> C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll (MindSpark)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{fc345d4c-b8f4-4674-bff7-3c37d2e535ee}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{fd6484ed-ebe3-4c3d-938a-8238003b41b7}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
==================== Restore Points =========================
11-07-2015 11:54:01 Scheduled Checkpoint
12-07-2015 16:17:46 Windows Update
15-07-2015 18:26:33 Scheduled Checkpoint
15-07-2015 18:56:37 Windows Update
17-07-2015 09:47:57 Scheduled Checkpoint
18-07-2015 19:57:33 Windows Update
23-07-2015 19:19:33 Windows Update
28-07-2015 19:12:02 Windows Update
31-07-2015 23:01:09 Windows Update
31-07-2015 23:32:16 Restore Operation
01-08-2015 10:28:49 Restore Operation
01-08-2015 12:40:01 Windows Update
04-08-2015 18:59:22 AA11
04-08-2015 20:10:52 Restore Operation
04-08-2015 20:33:03 Restore Operation
04-08-2015 21:23:12 Restore Operation
04-08-2015 23:05:07 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 03:23 - 2006-09-18 14:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0D584032-436C-4E12-90F9-BC136FA4EE56} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd)
Task: {1F014C22-11EA-4585-9D8F-C4363BB38751} - System32\Tasks\PC Unleashed => C:\Program Files\PC Unleashed Online\PC Unleashed\pcu.exe [2012-07-19] (PC Unleashed Online, Inc.)
Task: {3062B010-09B0-4171-9967-935DF58F28BA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-04] (Adobe Systems Incorporated)
Task: {608DCA47-66AA-45F7-B64A-47E8B04B3DBB} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\OSUpgrade => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunHandleOSUpgrade
Task: {610C123E-E75B-4FFB-A9EB-14B2E4251660} - System32\Tasks\{44E094D7-1DC5-4FCC-A3DC-A2E4FF5F4D76} => C:\Program Files\Skype\Phone\Skype.exe
Task: {6ABC175F-3949-40B0-B045-58BD6ACEE499} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-27] (Google Inc.)
Task: {6C7BCA72-D959-4C1C-9D2F-9CB4935D55D5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-27] (Google Inc.)
Task: {A388C444-1D6E-4259-AE16-83E1E1C54246} - System32\Tasks\{C6E2C9FA-2FB6-4B9A-9086-ABE7FF602C1F} => pcalua.exe -a C:\PROGRA~1\Zynga\UNWISE.EXE -c /U C:\PROGRA~1\Zynga\INSTALL.LOG
Task: {AAA9C09D-8453-41C7-BA18-93DBFCF28B09} - System32\Tasks\HPCeeScheduleForJanelle => C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-03-23] (Hewlett-Packard)
Task: {C5C00E62-28DE-4166-B95D-11151B0A6BA7} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\ConfigExec => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunCollectConfigurationInfo
Task: {C81D473C-C0C4-4127-8516-1365D7FCF574} - System32\Tasks\HP Health Check => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09] (Hewlett-Packard)
Task: {D395CBD8-97A9-43F0-BC9E-B61BF670F395} - System32\Tasks\{DEC880E0-57F8-492C-A84D-6F4DD5CD60AE} => pcalua.exe -a C:\Windows\system32\javacpl.cpl -c Java
Task: {F9C398E4-49F1-4C82-98C5-324659342CFB} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForJanelle.job => C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe
Task: C:\Windows\Tasks\PC Unleashed.job => C:\Program Files\PC Unleashed Online\PC Unleashed\pcu.exe
==================== Loaded Modules (Whitelisted) ==============
2007-05-31 02:21 - 2007-03-28 17:45 - 00270431 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
2007-05-31 02:21 - 2007-03-28 17:45 - 00233573 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapEngine.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00032768 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00114783 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLSchMgr.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00339968 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLTinyDB.dll
2007-05-31 02:20 - 2007-03-28 17:44 - 00061440 _____ () C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll
2007-05-16 11:43 - 2007-05-16 11:43 - 00677432 ____R () C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\Web\Wallpaper\img34.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{964F56F1-41AD-446F-B77E-82B071B28749}] => (Allow) C:\Program Files\HP\QuickPlay\QP.exe
FirewallRules: [{95E87BAB-D6F1-493C-AF4A-24B8CD4E995B}] => (Allow) C:\Program Files\HP\QuickPlay\QPService.exe
FirewallRules: [{748AB940-A937-49CF-B0BE-DDE3197C8C3F}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{B33D8B4B-4DF8-4E93-9CF8-80A110094D07}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{C6FFCC69-5FEF-42B6-8093-109073549692}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{51134F5C-05F7-485C-A9F7-8C3A7AF53B8B}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{825DD0AB-F15C-4AE4-879F-02D0098A5DBA}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{2F81CA3D-A256-4BCF-8C72-A9B4ECE9CD72}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [TCP Query User{81F7F573-2E0E-4F6E-9AF2-4D32BC5E6737}C:\program files\hp games\wheel of fortune\wheel of fortune.exe] => (Block) C:\program files\hp games\wheel of fortune\wheel of fortune.exe
FirewallRules: [UDP Query User{0FF5FE79-1718-4D5F-843D-934158FDF2B9}C:\program files\hp games\wheel of fortune\wheel of fortune.exe] => (Block) C:\program files\hp games\wheel of fortune\wheel of fortune.exe
FirewallRules: [{6970BDF2-9C56-4A2C-AF78-474954847B5C}] => (Allow) LPort=80
FirewallRules: [{A0F5CD9E-13EC-4D38-B369-0A5C2513BB22}] => (Allow) LPort=80
FirewallRules: [{4677590A-FFC7-4A3C-B305-9EC8888C3FCE}] => (Allow) LPort=80
FirewallRules: [{5DD5967B-6554-4E2D-8D6E-AEB6A5693BE0}] => (Allow) C:\Program Files\Microsoft Silverlight\5.1.20513.0\Silverlight.Configuration.exe
FirewallRules: [{82381A18-4994-4A86-9AC4-0D553E263286}] => (Allow) C:\Program Files\Microsoft Silverlight\5.1.20513.0\Silverlight.Configuration.exe
FirewallRules: [{0440192A-FA1C-429F-8FC8-8C216DA976F0}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{6A6FEB30-CF72-4331-BF5A-93AED3262624}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe] => Enabled:Earthlink
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
System errors:
=============
Error: (08/04/2015 10:17:31 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: KtmRm for Distributed Transaction Coordinator
Error: (08/04/2015 10:14:25 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: 30000ShellHWDetection
Error: (08/04/2015 10:11:00 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: CyberLink Task Scheduler (CTS)CyberLink Background Capture Service (CBCS)%%1070
Error: (08/04/2015 10:10:59 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: CyberLink Background Capture Service (CBCS)
Error: (08/04/2015 10:09:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: MyFunCardsService%%3
Error: (08/04/2015 10:09:05 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 10:08:04 PM on 8/4/2015 was unexpected.
Error: (08/04/2015 10:08:54 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: The default transaction resource manager on volume D: encountered a non-retryable error and could not start. The data contains the error code.
Error: (08/04/2015 09:39:12 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: KtmRm for Distributed Transaction Coordinator
Error: (08/04/2015 09:31:13 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: CyberLink Task Scheduler (CTS)CyberLink Background Capture Service (CBCS)%%1070
Error: (08/04/2015 09:31:13 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: CyberLink Background Capture Service (CBCS)
Microsoft Office:
=========================
CodeIntegrity:
===================================
Date: 2014-01-01 19:46:34.373
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:46:33.921
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:46:33.546
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:46:33.125
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:45:55.890
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:45:55.311
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:45:54.857
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:45:54.406
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2013-12-03 17:49:39.111
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2013-12-03 17:49:38.730
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: AMD Turion™ 64 X2 Mobile Technology TL-60
Percentage of memory in use: 56%
Total physical RAM: 1981.87 MB
Available physical RAM: 860.04 MB
Total Virtual: 4214.26 MB
Available Virtual: 2784.87 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:140.85 GB) (Free:47.61 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (HP_RECOVERY) (Fixed) (Total:8.2 GB) (Free:0 GB) NTFS ==>[system with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 149.1 GB) (Disk ID: C6450749)
Partition 1: (Active) - (Size=140.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=8.2 GB) - (Type=07 NTFS)
==================== End of log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version:02-08-2015 01
Ran by [removed] (2015-08-05 00:01:36)
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1766275910-2450894708-632072239-500 - Administrator - Disabled)
Guest (S-1-5-21-1766275910-2450894708-632072239-501 - Limited - Disabled)
Janelle (S-1-5-21-1766275910-2450894708-632072239-1000 - Administrator - Enabled) => C:\Users\Janelle
Mary (S-1-5-21-1766275910-2450894708-632072239-1002 - Administrator - Enabled) => C:\Users\Mary
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Activation Assistant for the 2007 Microsoft Office suites (HKLM\…\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
ActiveCheck component for HP Active Support Library (Version: 3.0.0.2 - Hewlett-Packard) Hidden
Adobe Flash Player 18 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader 8 (HKLM\…\{AC76BA86-7AD7-1033-7B44-A80000000002}) (Version: 8.0.0 - Adobe Systems Incorporated)
AppCore (Version: 1 - Symantec Corporation) Hidden
AV (Version: 1 - Symantec Corporation) Hidden
ccCommon (Version: 106.2.0.21 - Symantec) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.01 - Piriform)
Cisco Connect (HKLM\…\Cisco Connect) (Version: 1.2.10104.2 - Cisco Consumer Products LLC)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
ESU for Microsoft Vista (HKLM\…\{88A548E6-4B09-43E7-AD55-3C7D1B37706D}) (Version: 2.0.2.1 - Hewlett-Packard)
Google Chrome (HKLM\…\Google Chrome) (Version: 44.0.2403.130 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\…\CNXT_MODEM_HDA_HSF) (Version: - )
HP Active Support Library (HKLM\…\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}) (Version: 3.1.9.1 - Hewlett-Packard)
HP Customer Experience Enhancements (HKLM\…\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.1.0.2278 - Hewlett-Packard)
HP Easy Setup - Frontend (HKLM\…\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.1.0.2279 - Hewlett-Packard)
HP Help and Support (HKLM\…\{9061CEF2-51F5-42C9-8A70-9ED351C6597A}) (Version: 1.1.0 - Hewlett-Packard)
HP Pavilion Webcam Driver for Vista v061.001.00005 (HKLM\…\{5CA81D12-9EC2-4082-972B-43ECA63F41F2}) (Version: 061.001.00005 - Chicony)
HP Photosmart Essential 2.0 (HKLM\…\HP Photosmart Essential) (Version: 2.0 - HP)
HP Quick Launch Buttons 6.20 B1 (HKLM\…\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.20 B1 - Hewlett-Packard)
HP QuickPlay 3.2 (HKLM\…\{45D707E9-F3C4-11D9-A373-0050BAE317E1}) (Version: - )
HP Total Care Advisor (HKLM\…\{F6B29003-A078-4491-AFBE-62EFB6CFFE19}) (Version: 1.1.19 - Hewlett-Packard)
HP Update (HKLM\…\{612F4E20-3661-4D44-AD79-823F1B613FB3}) (Version: 5.002.008.001 - Hewlett-Packard)
HP User Guides 0041 (HKLM\…\{AF0B98A9-F7E2-4FF5-88C7-7960EB91752B}) (Version: 1.03.0002 - Hewlett-Packard)
HP Wireless Assistant (HKLM\…\{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}) (Version: 3.00 H3 - Hewlett-Packard)
HPAsset component for HP Active Support Library (Version: 3.0.2.2 - Hewlett-Packard) Hidden
HPNetworkAssistant (HKLM\…\{228C6B46-64E2-404E-898A-EF0830603EF4}) (Version: 1.1.70 - Hewlett-Packard.)
Internet Explorer (Enable DEP) (HKLM\…\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb) (Version: - )
IrfanView (remove only) (HKLM\…\IrfanView) (Version: - )
Java 8 Update 31 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Java(TM) SE Runtime Environment 6 (HKLM\…\{3248F0A8-6813-11D6-A77B-00B0D0160000}) (Version: 1.6.0.0 - Sun Microsystems, Inc.)
LightScribe 1.4.136.1 (Version: 1.4.136.1 - http://www.lightscribe.com)Hidden
LiveUpdate 3.2 (Symantec Corporation) (HKLM\…\LiveUpdate) (Version: 3.2.0.41 - Symantec Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Fix it Center (HKLM\…\{B7588D45-AFDC-4C93-9E2E-A100F3554B64}) (Version: 1.0.0100 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\…\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
Move Media Player (HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Move Media Player) (Version: - Move Networks)
MSCU for Microsoft Vista (HKLM\…\{3FFB3B34-D639-4384-9AE9-DDE58430D86F}) (Version: 1.0.1.1 - Hewlett-Packard)
MSRedist (Version: 1.0.0.0 - Symantec Corporation) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM\…\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM\…\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
muvee autoProducer 6.0 (HKLM\…\{0BFC200F-C45D-4271-AF34-4CA969225DEB}) (Version: 6.00.050 - muvee Technologies)
My HP Games (HKLM\…\WildTangent hplaptop Master Uninstall) (Version: HPLAP0503 - WildTangent)
Norton AntiVirus (Version: 14.2.0.29 - Symantec Corporation) Hidden
Norton Confidential Browser Component (Version: 1.5.0.29 - Symantec Corporation) Hidden
Norton Confidential Web Protection Component (Version: 1.5.0.29 - Symantec Corporation) Hidden
Norton Internet Security (Symantec Corporation) (HKLM\…\SymSetup.{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}) (Version: 10.2.0.30 - Symantec Corporation)
Norton Internet Security (Version: 10.1.0 - Symantec Corp.) Hidden
Norton Internet Security (Version: 10.2.0.30 - Symantec Corporation) Hidden
Norton Protection Center (Version: 2007.2.0.22 - Symantec Corporation) Hidden
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: 1.4 - NVIDIA Corporation)
PMB (HKLM\…\{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}) (Version: 5.5.00.11260 - Sony Corporation)
PSSWCORE (Version: 2.00.5000 - Hewlett-Packard) Hidden
QuickTime 7 (HKLM\…\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Rhapsody (HKLM\…\Rhapsody) (Version: - )
Rhapsody Player Engine (HKLM\…\{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}) (Version: 1.0.604 - RealNetworks)
Roxio Creator Audio (HKLM\…\{83FFCFC7-88C6-41c6-8752-958A45325C82}) (Version: 3.4.0 - Roxio)
Roxio Creator Basic v9 (HKLM\…\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}) (Version: 3.4.0 - Roxio)
Roxio Creator Copy (HKLM\…\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio)
Roxio Creator Data (HKLM\…\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio)
Roxio Creator EasyArchive (HKLM\…\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio)
Roxio Creator Tools (HKLM\…\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio)
Roxio Express Labeler 3 (HKLM\…\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 3.2.1 - Roxio)
Roxio MyDVD Basic v9 (HKLM\…\{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}) (Version: 9.0.551 - Roxio)
SPBBC 32bit (Version: 3.2.0.21 - Symantec Corporation) Hidden
Symantec Real Time Storage Protection Component (Version: 10.1.4.2 - Symantec Corporation) Hidden
SymNet (Version: 7.2.0.15 - Symantec Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 11.0.7.0 - Synaptics)
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{e3e02f12-2adb-478c-8742-5f0819f9f0f4}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{e473a65c-8087-49a3-affd-c5bc4a10669b}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{f4c28532-b9d0-4950-a2df-e83f9929242b}\InprocServer32 -> C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll (MindSpark)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{fc345d4c-b8f4-4674-bff7-3c37d2e535ee}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1766275910-2450894708-632072239-1000_Classes\CLSID\{fd6484ed-ebe3-4c3d-938a-8238003b41b7}\InprocServer32 -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
==================== Restore Points =========================
11-07-2015 11:54:01 Scheduled Checkpoint
12-07-2015 16:17:46 Windows Update
15-07-2015 18:26:33 Scheduled Checkpoint
15-07-2015 18:56:37 Windows Update
17-07-2015 09:47:57 Scheduled Checkpoint
18-07-2015 19:57:33 Windows Update
23-07-2015 19:19:33 Windows Update
28-07-2015 19:12:02 Windows Update
31-07-2015 23:01:09 Windows Update
31-07-2015 23:32:16 Restore Operation
01-08-2015 10:28:49 Restore Operation
01-08-2015 12:40:01 Windows Update
04-08-2015 18:59:22 AA11
04-08-2015 20:10:52 Restore Operation
04-08-2015 20:33:03 Restore Operation
04-08-2015 21:23:12 Restore Operation
04-08-2015 23:05:07 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 03:23 - 2006-09-18 14:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0D584032-436C-4E12-90F9-BC136FA4EE56} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd)
Task: {1F014C22-11EA-4585-9D8F-C4363BB38751} - System32\Tasks\PC Unleashed => C:\Program Files\PC Unleashed Online\PC Unleashed\pcu.exe [2012-07-19] (PC Unleashed Online, Inc.)
Task: {3062B010-09B0-4171-9967-935DF58F28BA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-04] (Adobe Systems Incorporated)
Task: {608DCA47-66AA-45F7-B64A-47E8B04B3DBB} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\OSUpgrade => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunHandleOSUpgrade
Task: {610C123E-E75B-4FFB-A9EB-14B2E4251660} - System32\Tasks\{44E094D7-1DC5-4FCC-A3DC-A2E4FF5F4D76} => C:\Program Files\Skype\Phone\Skype.exe
Task: {6ABC175F-3949-40B0-B045-58BD6ACEE499} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-27] (Google Inc.)
Task: {6C7BCA72-D959-4C1C-9D2F-9CB4935D55D5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-27] (Google Inc.)
Task: {A388C444-1D6E-4259-AE16-83E1E1C54246} - System32\Tasks\{C6E2C9FA-2FB6-4B9A-9086-ABE7FF602C1F} => pcalua.exe -a C:\PROGRA~1\Zynga\UNWISE.EXE -c /U C:\PROGRA~1\Zynga\INSTALL.LOG
Task: {AAA9C09D-8453-41C7-BA18-93DBFCF28B09} - System32\Tasks\HPCeeScheduleForJanelle => C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-03-23] (Hewlett-Packard)
Task: {C5C00E62-28DE-4166-B95D-11151B0A6BA7} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\ConfigExec => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunCollectConfigurationInfo
Task: {C81D473C-C0C4-4127-8516-1365D7FCF574} - System32\Tasks\HP Health Check => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09] (Hewlett-Packard)
Task: {D395CBD8-97A9-43F0-BC9E-B61BF670F395} - System32\Tasks\{DEC880E0-57F8-492C-A84D-6F4DD5CD60AE} => pcalua.exe -a C:\Windows\system32\javacpl.cpl -c Java
Task: {F9C398E4-49F1-4C82-98C5-324659342CFB} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForJanelle.job => C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe
Task: C:\Windows\Tasks\PC Unleashed.job => C:\Program Files\PC Unleashed Online\PC Unleashed\pcu.exe
==================== Loaded Modules (Whitelisted) ==============
2007-05-31 02:21 - 2007-03-28 17:45 - 00270431 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
2007-05-31 02:21 - 2007-03-28 17:45 - 00233573 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapEngine.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00032768 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00114783 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLSchMgr.dll
2007-05-31 02:21 - 2007-03-28 17:45 - 00339968 _____ () C:\Program Files\HP\QuickPlay\Kernel\TV\CLTinyDB.dll
2007-05-31 02:20 - 2007-03-28 17:44 - 00061440 _____ () C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll
2007-05-16 11:43 - 2007-05-16 11:43 - 00677432 ____R () C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\Web\Wallpaper\img34.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{964F56F1-41AD-446F-B77E-82B071B28749}] => (Allow) C:\Program Files\HP\QuickPlay\QP.exe
FirewallRules: [{95E87BAB-D6F1-493C-AF4A-24B8CD4E995B}] => (Allow) C:\Program Files\HP\QuickPlay\QPService.exe
FirewallRules: [{748AB940-A937-49CF-B0BE-DDE3197C8C3F}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{B33D8B4B-4DF8-4E93-9CF8-80A110094D07}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{C6FFCC69-5FEF-42B6-8093-109073549692}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{51134F5C-05F7-485C-A9F7-8C3A7AF53B8B}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{825DD0AB-F15C-4AE4-879F-02D0098A5DBA}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{2F81CA3D-A256-4BCF-8C72-A9B4ECE9CD72}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [TCP Query User{81F7F573-2E0E-4F6E-9AF2-4D32BC5E6737}C:\program files\hp games\wheel of fortune\wheel of fortune.exe] => (Block) C:\program files\hp games\wheel of fortune\wheel of fortune.exe
FirewallRules: [UDP Query User{0FF5FE79-1718-4D5F-843D-934158FDF2B9}C:\program files\hp games\wheel of fortune\wheel of fortune.exe] => (Block) C:\program files\hp games\wheel of fortune\wheel of fortune.exe
FirewallRules: [{6970BDF2-9C56-4A2C-AF78-474954847B5C}] => (Allow) LPort=80
FirewallRules: [{A0F5CD9E-13EC-4D38-B369-0A5C2513BB22}] => (Allow) LPort=80
FirewallRules: [{4677590A-FFC7-4A3C-B305-9EC8888C3FCE}] => (Allow) LPort=80
FirewallRules: [{5DD5967B-6554-4E2D-8D6E-AEB6A5693BE0}] => (Allow) C:\Program Files\Microsoft Silverlight\5.1.20513.0\Silverlight.Configuration.exe
FirewallRules: [{82381A18-4994-4A86-9AC4-0D553E263286}] => (Allow) C:\Program Files\Microsoft Silverlight\5.1.20513.0\Silverlight.Configuration.exe
FirewallRules: [{0440192A-FA1C-429F-8FC8-8C216DA976F0}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{6A6FEB30-CF72-4331-BF5A-93AED3262624}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe] => Enabled:Earthlink
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (08/04/2015 11:58:14 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
System errors:
=============
Error: (08/04/2015 10:17:31 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: KtmRm for Distributed Transaction Coordinator
Error: (08/04/2015 10:14:25 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: 30000ShellHWDetection
Error: (08/04/2015 10:11:00 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: CyberLink Task Scheduler (CTS)CyberLink Background Capture Service (CBCS)%%1070
Error: (08/04/2015 10:10:59 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: CyberLink Background Capture Service (CBCS)
Error: (08/04/2015 10:09:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: MyFunCardsService%%3
Error: (08/04/2015 10:09:05 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 10:08:04 PM on 8/4/2015 was unexpected.
Error: (08/04/2015 10:08:54 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: The default transaction resource manager on volume D: encountered a non-retryable error and could not start. The data contains the error code.
Error: (08/04/2015 09:39:12 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: KtmRm for Distributed Transaction Coordinator
Error: (08/04/2015 09:31:13 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: CyberLink Task Scheduler (CTS)CyberLink Background Capture Service (CBCS)%%1070
Error: (08/04/2015 09:31:13 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: CyberLink Background Capture Service (CBCS)
Microsoft Office:
=========================
CodeIntegrity:
===================================
Date: 2014-01-01 19:46:34.373
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:46:33.921
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:46:33.546
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:46:33.125
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:45:55.890
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:45:55.311
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:45:54.857
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-01-01 19:45:54.406
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2013-12-03 17:49:39.111
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
Date: 2013-12-03 17:49:38.730
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Ad-Aware Antivirus\Drivers\i386\wlh\sbhips.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: AMD Turion™ 64 X2 Mobile Technology TL-60
Percentage of memory in use: 56%
Total physical RAM: 1981.87 MB
Available physical RAM: 860.04 MB
Total Virtual: 4214.26 MB
Available Virtual: 2784.87 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:140.85 GB) (Free:47.61 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (HP_RECOVERY) (Fixed) (Total:8.2 GB) (Free:0 GB) NTFS ==>[system with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 149.1 GB) (Disk ID: C6450749)
Partition 1: (Active) - (Size=140.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=8.2 GB) - (Type=07 NTFS)
==================== End of log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-08-2015 01
Ran by [removed] (administrator) on JANELLE-PC (05-08-2015 00:00:45)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
(Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
(Symantec Corporation) C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
() C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
(CyberLink Corp.) C:\Program Files\Hp\QuickPlay\QPService.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehmsas.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\System32\mobsync.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1045800 2008-03-28] (Synaptics, Inc.)
HKLM\…\Run: [QPService] => C:\Program Files\HP\QuickPlay\QPService.exe [176128 2007-03-28] (CyberLink Corp.)
HKLM\…\Run: [QlbCtrl] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [159744 2007-02-13] ( Hewlett-Packard Development Company, L.P.)
HKLM\…\Run: [HP Health Check Scheduler] => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-10-09] (Hewlett-Packard)
HKLM\…\Run: [PMBVolumeWatcher] => C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [hpWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [480560 2007-10-03] (Hewlett-Packard Development Company, L.P.)
HKLM\…\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-02-18] (Hewlett-Packard)
HKLM\…\Run: [Search Protection] => C:\ProgramData\Search Protection\SearchProtection.exe
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd)
HKU\S-1-5-18\…\RunOnce: [adaware] => reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f
HKU\S-1-5-18\…\RunOnce: [adaware_XP] => reg.exe delete "HKCU\Software\adaware" /f
AppInit_DLLs: C:\PROGRA~1\Amazon\AMAZON~1\\AMAZON~1.DLL => C:\PROGRA~1\Amazon\AMAZON~1\\AMAZON~1.DLL File not found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [2007-05-31]
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk [2007-05-31]
ShortcutTarget: Adobe Reader Synchronizer.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page =
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
URLSearchHook: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 - (No Name) - {f4c28532-b9d0-4950-a2df-e83f9929242b} - C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll (MindSpark)
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {A9A5A44B-65D6-4CE2-BD35-55F5467AAD17} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {d48efd2d-1c0c-4d68-bbc3-2f219c756723} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {E22D2942-636A-4FAB-AE76-63F24DDBECC1} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {F3F92588-AF51-4B46-9EA9-CCD5DE246D63} URL =
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22] (Adobe Systems Incorporated)
BHO: No Name -> {1E8A6170-7264-4D0F-BEAE-D42A53123C75} -> c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-01-12] (Symantec Corporation)
BHO: No Name -> {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} -> No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-22] (Oracle Corporation)
BHO: Search Assistant BHO -> {c4b22c87-45ef-4f43-89f2-40db2078864e} -> C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll [2012-10-19] (MindSpark)
BHO: No Name -> {da71fd14-5f7b-46ae-b8b1-44074a38f331} -> No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-22] (Oracle Corporation)
Toolbar: HKLM - Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll [2007-01-12] (Symantec Corporation)
Toolbar: HKLM - MyFunCards - {210f1b36-3b7f-41a4-b5da-3eb87f5a56c2} - C:\Program Files\MyFunCards_5m\bar\1.bin\5mbar.dll [2012-10-19] (MindSpark)
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} - No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed] 192.168.1.1
Tcpip\..\Interfaces\{28F058A5-ABB1-48F7-A91F-A3143EF6CC6C}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{9BBF898D-8D4D-4C50-87CB-98891C247373}: [DhcpNameServer] [removed] [removed] 192.168.1.1
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-22] (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @MyFunCards_5m.com/Plugin -> C:\Program Files\MyFunCards_5m\bar\1.bin\NP5mStub.dll [2012-10-19] (MindSpark)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-27] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-27] (Google Inc.)
FF Plugin HKU\S-1-5-21-1766275910-2450894708-632072239-1000: @movenetworks.com/Quantum Media Player -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll [2010-04-23] (Move Networks)
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-04-11]
FF HKLM\…\Firefox\Extensions: [5mffxtbr@MyFunCards_5m.com] - C:\Program Files\MyFunCards_5m\bar\1.bin
FF Extension: No Name - C:\Program Files\MyFunCards_5m\bar\1.bin [2012-10-19]
FF HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Janelle\AppData\Roaming\Move Networks
FF Extension: Move Media Player - C:\Users\Janelle\AppData\Roaming\Move Networks [2010-04-23]
FF HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Firefox\Extensions: [{07433EEA-AEA0-461F-AB9F-35D67476BA7E}] - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E}
FF Extension: XULRunner - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E} [2011-03-12]
Chrome:
=======
CHR Profile: C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-22]
CHR Extension: (Google Drive) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-22]
CHR Extension: (YouTube) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-22]
CHR Extension: (Google Search) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-22]
CHR Extension: (MSN Homepage) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkcgfbgohboipdhliafmacjnhjbhmim [2015-02-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-22]
CHR Extension: (Gmail) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-22]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [554616 2007-01-05] (Symantec Corporation)
R2 ccEvtMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
R2 ccSetMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
R2 CLCapSvc; C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe [270431 2007-03-28] () [File not signed]
S2 CLSched; C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe [118877 2007-03-28] () [File not signed]
R2 CLTNetCnService; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
S3 Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [110592 2007-01-09] (Hewlett-Packard Development Company, L.P.) [File not signed]
S3 comHost; c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [49248 2007-01-13] (Symantec Corporation)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [File not signed]
R2 hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [135168 2006-05-02] (Hewlett-Packard Development Company, L.P.) [File not signed]
S3 IDriverT; C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S3 ISPwdSvc; c:\Program Files\Norton Internet Security\isPwdSvc.exe [80504 2007-01-14] (Symantec Corporation)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2006-12-14] (Hewlett-Packard Company) [File not signed]
S3 LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE [2918008 2007-01-05] (Symantec Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
S3 RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [880640 2007-02-12] (Sonic Solutions) [File not signed]
S3 Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [1174664 2007-05-31] (Symantec Corporation)
R2 SymAppCore; c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe [47712 2007-01-05] (Symantec Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
S2 MyFunCards_5mService; C:\PROGRA~1\MYFUNC~2\bar\1.bin\5mbarsvc.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 eabfiltr; C:\Windows\System32\DRIVERS\eabfiltr.sys [8192 2006-11-30] (Hewlett-Packard Development Company, L.P.)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [387384 2007-01-10] (Symantec Corporation)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-10-06] (GFI Software)
S3 IDSvix86; C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20070108.003\IDSvix86.sys [212280 2006-12-28] (Symantec Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R3 NAVENG; C:\ProgramData\Symantec\Definitions\VirusDefs\20070110.052\NAVENG.SYS [80408 2007-01-10] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Symantec\Definitions\VirusDefs\20070110.052\NAVEX15.SYS [833048 2007-01-10] (Symantec Corporation)
R1 SBRE; C:\Windows\system32\drivers\SBREDrv.sys [101720 2011-06-30] (Sunbelt Software)
S3 SPBBCDrv; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [417592 2007-01-03] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [247608 2007-01-12] (Symantec Corporation)
S3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [276792 2007-01-12] (Symantec Corporation)
R1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [25400 2007-01-12] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [115000 2007-05-31] (Symantec Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U5 SYMTDI; C:\Windows\System32\Drivers\SYMTDI.sys [191544 2007-01-09] (Symantec Corporation)
U3 aswMBR; \??\C:\Users\Janelle\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Janelle\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-05 00:00 - 2015-08-05 00:01 - 00021538 _____ C:\Users\Janelle\Downloads\FRST.txt
2015-08-04 23:59 - 2015-08-05 00:00 - 00000000 ____D C:\FRST
2015-08-04 23:57 - 2015-08-04 23:58 - 01673728 _____ (Farbar) C:\Users\Janelle\Downloads\FRST.exe
2015-08-04 23:53 - 2015-08-04 23:53 - 00004149 _____ C:\Users\Janelle\Documents\Documents\Documents\aswMBR.txt
2015-08-04 23:53 - 2015-08-04 23:53 - 00000512 _____ C:\Users\Janelle\Documents\Documents\Documents\MBR.dat
2015-08-04 23:06 - 2015-08-04 23:07 - 05198336 _____ (AVAST Software) C:\Users\Janelle\Downloads\aswMBR.exe
2015-08-04 20:24 - 2015-08-04 21:29 - 00000000 ____D C:\Program Files\GUM81CC.tmp
2015-08-04 20:09 - 2015-08-04 20:10 - 05831179 _____ (Piriform Ltd) C:\Users\Janelle\Downloads\9AA6.tmp
2015-07-31 17:27 - 2015-08-01 10:36 - 00000000 ____D C:\Program Files\Skype
2015-07-31 17:27 - 2015-07-31 17:27 - 00000000 ____D C:\Users\Janelle\AppData\Local\Skype
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-04 23:51 - 2013-09-06 17:08 - 01992870 _____ C:\Windows\WindowsUpdate.log
2015-08-04 23:46 - 2006-11-02 05:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-04 23:46 - 2006-11-02 05:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-04 23:14 - 2014-10-01 21:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-04 23:10 - 2015-05-27 17:57 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-04 22:33 - 2014-10-01 21:35 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-08-04 22:33 - 2014-10-01 21:35 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-08-04 22:10 - 2010-04-13 20:25 - 00047962 _____ C:\ProgramData\nvModes.001
2015-08-04 22:09 - 2015-05-27 17:57 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-04 22:09 - 2006-11-02 06:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-04 21:51 - 2015-05-27 18:00 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-04 21:29 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\system32\Msdtc
2015-08-04 21:28 - 2013-05-10 23:29 - 00000000 ____D C:\Users\Mary
2015-08-04 21:28 - 2010-03-24 21:33 - 00000000 ____D C:\Users\Janelle
2015-08-04 21:28 - 2006-11-02 03:22 - 51380224 _____ C:\Windows\system32\config\software_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 40632320 _____ C:\Windows\system32\config\components_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 25427968 _____ C:\Windows\system32\config\system_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00524288 _____ C:\Windows\system32\config\default_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2015-08-04 21:27 - 2015-05-27 18:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-04 21:27 - 2010-03-24 21:42 - 00000000 ____D C:\Users\Janelle\AppData\Local\QuickPlay
2015-08-04 21:27 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\system32\spool
2015-08-04 21:27 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\registration
2015-08-04 21:23 - 2011-03-24 14:04 - 00000000 ____D C:\Users\Janelle\AppData\Roaming\HpUpdate
2015-08-04 20:09 - 2010-06-16 22:20 - 00000000 ____D C:\Users\Janelle\AppData\Roaming\Skype
2015-08-04 19:08 - 2010-04-13 20:25 - 00047962 _____ C:\ProgramData\nvModes.dat
2015-08-01 10:36 - 2010-06-16 22:19 - 00000000 ____D C:\ProgramData\Skype
2015-07-31 18:23 - 2010-09-26 20:58 - 00000052 _____ C:\Windows\system32\DOErrors.log
==================== Files in the root of some directories =======
2013-05-27 15:35 - 2013-05-18 19:03 - 0186768 _____ () C:\Program Files\20res.dll
2013-05-27 15:35 - 2013-05-18 19:03 - 0708168 _____ (MindSpark) C:\Program Files\20Uninstall YourLocalLotto Toolbar.dll
2011-10-10 09:48 - 2011-10-10 09:48 - 0000272 _____ () C:\Users\Janelle\AppData\Roaming\.backup.dm
2012-09-21 17:01 - 2012-09-23 14:29 - 0000048 _____ () C:\Users\Janelle\AppData\Roaming\0F478F.dat
2014-02-02 17:41 - 2014-02-02 17:41 - 0002086 _____ () C:\Users\Janelle\AppData\Roaming\data.sec
2012-09-21 17:01 - 2012-09-21 17:01 - 0000028 _____ () C:\Users\Janelle\AppData\Roaming\Filesop.txt.block
2010-03-24 23:01 - 2010-04-13 19:51 - 0013119 _____ () C:\Users\Janelle\AppData\Roaming\nvModes.001
2010-03-24 23:01 - 2010-04-13 15:55 - 0013119 _____ () C:\Users\Janelle\AppData\Roaming\nvModes.dat
2012-09-21 18:14 - 2012-09-21 18:14 - 0000030 _____ () C:\Users\Janelle\AppData\Roaming\ok.txt.block
2012-09-23 14:38 - 2012-09-23 14:38 - 0000041 _____ () C:\Users\Janelle\AppData\Roaming\smss.exe.tmp
2012-09-21 18:14 - 2012-09-21 18:14 - 0002176 _____ () C:\Users\Janelle\AppData\Roaming\WARNING.txt
2012-03-02 11:18 - 2015-03-06 21:24 - 0000384 _____ () C:\Users\Janelle\AppData\Roaming\wklnhst.dat
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\AtStart.txt
2012-09-21 17:01 - 2012-09-23 15:24 - 0006529 _____ () C:\Users\Janelle\AppData\Local\chromeupdate.crx
2010-06-03 17:04 - 2015-03-05 23:04 - 0007620 _____ () C:\Users\Janelle\AppData\Local\d3d9caps.dat
2010-04-08 16:58 - 2015-06-26 18:10 - 0004608 _____ () C:\Users\Janelle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\DSwitch.txt
2011-03-12 05:10 - 2011-05-10 01:08 - 0001034 _____ () C:\Users\Janelle\AppData\Local\Mdebukijaduxoxu.dat
2011-03-12 05:10 - 2011-05-10 01:08 - 0000000 _____ () C:\Users\Janelle\AppData\Local\Mwuda.bin
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\QSwitch.txt
2012-09-22 14:32 - 2012-09-22 14:32 - 0000000 _____ () C:\ProgramData\50pWN8.dat
2012-09-22 14:31 - 2012-09-22 14:31 - 0000001 _____ () C:\ProgramData\5U0eRTH0.exe.b
2012-09-22 14:31 - 2012-09-22 14:31 - 0000001 _____ () C:\ProgramData\5U0eRTH0.exe_.b
2010-06-16 22:22 - 2010-06-16 22:22 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2007-05-31 02:34 - 2012-06-23 14:09 - 0000675 _____ () C:\ProgramData\hpzinstall.log
2010-04-13 20:25 - 2015-08-04 22:10 - 0047962 _____ () C:\ProgramData\nvModes.001
2010-04-13 20:25 - 2015-08-04 19:08 - 0047962 _____ () C:\ProgramData\nvModes.dat
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1766275910-2450894708-632072239-1000\$ef8a5bbf5833eadd22ca66c158232ebe
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$ef8a5bbf5833eadd22ca66c158232ebe
ZeroAccess:
C:\Users\Janelle\AppData\Local\{ef8a5bbf-5833-eadd-22ca-66c158232ebe}
ZeroAccess:
C:\Users\Janelle\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files\Google\Desktop\Install
Some files in TEMP:
====================
C:\Users\Mary\AppData\Local\Temp\symlcsv1.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
LastRegBack: 2015-08-04 22:37
==================== End of log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-08-2015 01
Ran by [removed] (administrator) on JANELLE-PC (05-08-2015 00:00:45)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
(Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
(Symantec Corporation) C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
() C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Symantec Corporation) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
(CyberLink Corp.) C:\Program Files\Hp\QuickPlay\QPService.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehmsas.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\System32\mobsync.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1045800 2008-03-28] (Synaptics, Inc.)
HKLM\…\Run: [QPService] => C:\Program Files\HP\QuickPlay\QPService.exe [176128 2007-03-28] (CyberLink Corp.)
HKLM\…\Run: [QlbCtrl] => C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [159744 2007-02-13] ( Hewlett-Packard Development Company, L.P.)
HKLM\…\Run: [HP Health Check Scheduler] => c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-10-09] (Hewlett-Packard)
HKLM\…\Run: [PMBVolumeWatcher] => C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [hpWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [480560 2007-10-03] (Hewlett-Packard Development Company, L.P.)
HKLM\…\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-02-18] (Hewlett-Packard)
HKLM\…\Run: [Search Protection] => C:\ProgramData\Search Protection\SearchProtection.exe
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd)
HKU\S-1-5-18\…\RunOnce: [adaware] => reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f
HKU\S-1-5-18\…\RunOnce: [adaware_XP] => reg.exe delete "HKCU\Software\adaware" /f
AppInit_DLLs: C:\PROGRA~1\Amazon\AMAZON~1\\AMAZON~1.DLL => C:\PROGRA~1\Amazon\AMAZON~1\\AMAZON~1.DLL File not found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [2007-05-31]
ShortcutTarget: Adobe Reader Speed Launch.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk [2007-05-31]
ShortcutTarget: Adobe Reader Synchronizer.lnk -> C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page =
HKU\S-1-5-21-1766275910-2450894708-632072239-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
URLSearchHook: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 - (No Name) - {f4c28532-b9d0-4950-a2df-e83f9929242b} - C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll (MindSpark)
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {A9A5A44B-65D6-4CE2-BD35-55F5467AAD17} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {d48efd2d-1c0c-4d68-bbc3-2f219c756723} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {E22D2942-636A-4FAB-AE76-63F24DDBECC1} URL =
SearchScopes: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> {F3F92588-AF51-4B46-9EA9-CCD5DE246D63} URL =
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22] (Adobe Systems Incorporated)
BHO: No Name -> {1E8A6170-7264-4D0F-BEAE-D42A53123C75} -> c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-01-12] (Symantec Corporation)
BHO: No Name -> {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} -> No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-22] (Oracle Corporation)
BHO: Search Assistant BHO -> {c4b22c87-45ef-4f43-89f2-40db2078864e} -> C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll [2012-10-19] (MindSpark)
BHO: No Name -> {da71fd14-5f7b-46ae-b8b1-44074a38f331} -> No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-22] (Oracle Corporation)
Toolbar: HKLM - Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll [2007-01-12] (Symantec Corporation)
Toolbar: HKLM - MyFunCards - {210f1b36-3b7f-41a4-b5da-3eb87f5a56c2} - C:\Program Files\MyFunCards_5m\bar\1.bin\5mbar.dll [2012-10-19] (MindSpark)
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} - No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - No File
Toolbar: HKU\S-1-5-21-1766275910-2450894708-632072239-1000 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed] 192.168.1.1
Tcpip\..\Interfaces\{28F058A5-ABB1-48F7-A91F-A3143EF6CC6C}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{9BBF898D-8D4D-4C50-87CB-98891C247373}: [DhcpNameServer] [removed] [removed] 192.168.1.1
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-22] (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @MyFunCards_5m.com/Plugin -> C:\Program Files\MyFunCards_5m\bar\1.bin\NP5mStub.dll [2012-10-19] (MindSpark)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-27] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-27] (Google Inc.)
FF Plugin HKU\S-1-5-21-1766275910-2450894708-632072239-1000: @movenetworks.com/Quantum Media Player -> C:\Users\Janelle\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll [2010-04-23] (Move Networks)
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-04-11]
FF HKLM\…\Firefox\Extensions: [5mffxtbr@MyFunCards_5m.com] - C:\Program Files\MyFunCards_5m\bar\1.bin
FF Extension: No Name - C:\Program Files\MyFunCards_5m\bar\1.bin [2012-10-19]
FF HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Firefox\Extensions: [[removed]] - C:\Users\Janelle\AppData\Roaming\Move Networks
FF Extension: Move Media Player - C:\Users\Janelle\AppData\Roaming\Move Networks [2010-04-23]
FF HKU\S-1-5-21-1766275910-2450894708-632072239-1000\…\Firefox\Extensions: [{07433EEA-AEA0-461F-AB9F-35D67476BA7E}] - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E}
FF Extension: XULRunner - C:\Users\Janelle\AppData\Local\{07433EEA-AEA0-461F-AB9F-35D67476BA7E} [2011-03-12]
Chrome:
=======
CHR Profile: C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-22]
CHR Extension: (Google Drive) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-22]
CHR Extension: (YouTube) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-22]
CHR Extension: (Google Search) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-22]
CHR Extension: (MSN Homepage) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkcgfbgohboipdhliafmacjnhjbhmim [2015-02-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-22]
CHR Extension: (Gmail) - C:\Users\Janelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-22]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [554616 2007-01-05] (Symantec Corporation)
R2 ccEvtMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
R2 ccSetMgr; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
R2 CLCapSvc; C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe [270431 2007-03-28] () [File not signed]
S2 CLSched; C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe [118877 2007-03-28] () [File not signed]
R2 CLTNetCnService; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108648 2007-01-10] (Symantec Corporation)
S3 Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [110592 2007-01-09] (Hewlett-Packard Development Company, L.P.) [File not signed]
S3 comHost; c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [49248 2007-01-13] (Symantec Corporation)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [File not signed]
R2 hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [135168 2006-05-02] (Hewlett-Packard Development Company, L.P.) [File not signed]
S3 IDriverT; C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S3 ISPwdSvc; c:\Program Files\Norton Internet Security\isPwdSvc.exe [80504 2007-01-14] (Symantec Corporation)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2006-12-14] (Hewlett-Packard Company) [File not signed]
S3 LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE [2918008 2007-01-05] (Symantec Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
S3 RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [880640 2007-02-12] (Sonic Solutions) [File not signed]
S3 Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [1174664 2007-05-31] (Symantec Corporation)
R2 SymAppCore; c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe [47712 2007-01-05] (Symantec Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
S2 MyFunCards_5mService; C:\PROGRA~1\MYFUNC~2\bar\1.bin\5mbarsvc.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 eabfiltr; C:\Windows\System32\DRIVERS\eabfiltr.sys [8192 2006-11-30] (Hewlett-Packard Development Company, L.P.)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [387384 2007-01-10] (Symantec Corporation)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-10-06] (GFI Software)
S3 IDSvix86; C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20070108.003\IDSvix86.sys [212280 2006-12-28] (Symantec Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R3 NAVENG; C:\ProgramData\Symantec\Definitions\VirusDefs\20070110.052\NAVENG.SYS [80408 2007-01-10] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Symantec\Definitions\VirusDefs\20070110.052\NAVEX15.SYS [833048 2007-01-10] (Symantec Corporation)
R1 SBRE; C:\Windows\system32\drivers\SBREDrv.sys [101720 2011-06-30] (Sunbelt Software)
S3 SPBBCDrv; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [417592 2007-01-03] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [247608 2007-01-12] (Symantec Corporation)
S3 SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [276792 2007-01-12] (Symantec Corporation)
R1 SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [25400 2007-01-12] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [115000 2007-05-31] (Symantec Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U5 SYMTDI; C:\Windows\System32\Drivers\SYMTDI.sys [191544 2007-01-09] (Symantec Corporation)
U3 aswMBR; \??\C:\Users\Janelle\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Janelle\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-05 00:00 - 2015-08-05 00:01 - 00021538 _____ C:\Users\Janelle\Downloads\FRST.txt
2015-08-04 23:59 - 2015-08-05 00:00 - 00000000 ____D C:\FRST
2015-08-04 23:57 - 2015-08-04 23:58 - 01673728 _____ (Farbar) C:\Users\Janelle\Downloads\FRST.exe
2015-08-04 23:53 - 2015-08-04 23:53 - 00004149 _____ C:\Users\Janelle\Documents\Documents\Documents\aswMBR.txt
2015-08-04 23:53 - 2015-08-04 23:53 - 00000512 _____ C:\Users\Janelle\Documents\Documents\Documents\MBR.dat
2015-08-04 23:06 - 2015-08-04 23:07 - 05198336 _____ (AVAST Software) C:\Users\Janelle\Downloads\aswMBR.exe
2015-08-04 20:24 - 2015-08-04 21:29 - 00000000 ____D C:\Program Files\GUM81CC.tmp
2015-08-04 20:09 - 2015-08-04 20:10 - 05831179 _____ (Piriform Ltd) C:\Users\Janelle\Downloads\9AA6.tmp
2015-07-31 17:27 - 2015-08-01 10:36 - 00000000 ____D C:\Program Files\Skype
2015-07-31 17:27 - 2015-07-31 17:27 - 00000000 ____D C:\Users\Janelle\AppData\Local\Skype
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-04 23:51 - 2013-09-06 17:08 - 01992870 _____ C:\Windows\WindowsUpdate.log
2015-08-04 23:46 - 2006-11-02 05:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-04 23:46 - 2006-11-02 05:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-04 23:14 - 2014-10-01 21:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-04 23:10 - 2015-05-27 17:57 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-04 22:33 - 2014-10-01 21:35 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-08-04 22:33 - 2014-10-01 21:35 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-08-04 22:10 - 2010-04-13 20:25 - 00047962 _____ C:\ProgramData\nvModes.001
2015-08-04 22:09 - 2015-05-27 17:57 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-04 22:09 - 2006-11-02 06:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-04 21:51 - 2015-05-27 18:00 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-04 21:29 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\system32\Msdtc
2015-08-04 21:28 - 2013-05-10 23:29 - 00000000 ____D C:\Users\Mary
2015-08-04 21:28 - 2010-03-24 21:33 - 00000000 ____D C:\Users\Janelle
2015-08-04 21:28 - 2006-11-02 03:22 - 51380224 _____ C:\Windows\system32\config\software_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 40632320 _____ C:\Windows\system32\config\components_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 25427968 _____ C:\Windows\system32\config\system_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00524288 _____ C:\Windows\system32\config\default_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2015-08-04 21:28 - 2006-11-02 03:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2015-08-04 21:27 - 2015-05-27 18:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-04 21:27 - 2010-03-24 21:42 - 00000000 ____D C:\Users\Janelle\AppData\Local\QuickPlay
2015-08-04 21:27 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\system32\spool
2015-08-04 21:27 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\registration
2015-08-04 21:23 - 2011-03-24 14:04 - 00000000 ____D C:\Users\Janelle\AppData\Roaming\HpUpdate
2015-08-04 20:09 - 2010-06-16 22:20 - 00000000 ____D C:\Users\Janelle\AppData\Roaming\Skype
2015-08-04 19:08 - 2010-04-13 20:25 - 00047962 _____ C:\ProgramData\nvModes.dat
2015-08-01 10:36 - 2010-06-16 22:19 - 00000000 ____D C:\ProgramData\Skype
2015-07-31 18:23 - 2010-09-26 20:58 - 00000052 _____ C:\Windows\system32\DOErrors.log
==================== Files in the root of some directories =======
2013-05-27 15:35 - 2013-05-18 19:03 - 0186768 _____ () C:\Program Files\20res.dll
2013-05-27 15:35 - 2013-05-18 19:03 - 0708168 _____ (MindSpark) C:\Program Files\20Uninstall YourLocalLotto Toolbar.dll
2011-10-10 09:48 - 2011-10-10 09:48 - 0000272 _____ () C:\Users\Janelle\AppData\Roaming\.backup.dm
2012-09-21 17:01 - 2012-09-23 14:29 - 0000048 _____ () C:\Users\Janelle\AppData\Roaming\0F478F.dat
2014-02-02 17:41 - 2014-02-02 17:41 - 0002086 _____ () C:\Users\Janelle\AppData\Roaming\data.sec
2012-09-21 17:01 - 2012-09-21 17:01 - 0000028 _____ () C:\Users\Janelle\AppData\Roaming\Filesop.txt.block
2010-03-24 23:01 - 2010-04-13 19:51 - 0013119 _____ () C:\Users\Janelle\AppData\Roaming\nvModes.001
2010-03-24 23:01 - 2010-04-13 15:55 - 0013119 _____ () C:\Users\Janelle\AppData\Roaming\nvModes.dat
2012-09-21 18:14 - 2012-09-21 18:14 - 0000030 _____ () C:\Users\Janelle\AppData\Roaming\ok.txt.block
2012-09-23 14:38 - 2012-09-23 14:38 - 0000041 _____ () C:\Users\Janelle\AppData\Roaming\smss.exe.tmp
2012-09-21 18:14 - 2012-09-21 18:14 - 0002176 _____ () C:\Users\Janelle\AppData\Roaming\WARNING.txt
2012-03-02 11:18 - 2015-03-06 21:24 - 0000384 _____ () C:\Users\Janelle\AppData\Roaming\wklnhst.dat
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\AtStart.txt
2012-09-21 17:01 - 2012-09-23 15:24 - 0006529 _____ () C:\Users\Janelle\AppData\Local\chromeupdate.crx
2010-06-03 17:04 - 2015-03-05 23:04 - 0007620 _____ () C:\Users\Janelle\AppData\Local\d3d9caps.dat
2010-04-08 16:58 - 2015-06-26 18:10 - 0004608 _____ () C:\Users\Janelle\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\DSwitch.txt
2011-03-12 05:10 - 2011-05-10 01:08 - 0001034 _____ () C:\Users\Janelle\AppData\Local\Mdebukijaduxoxu.dat
2011-03-12 05:10 - 2011-05-10 01:08 - 0000000 _____ () C:\Users\Janelle\AppData\Local\Mwuda.bin
2010-03-24 21:42 - 2010-03-24 21:42 - 0000000 _____ () C:\Users\Janelle\AppData\Local\QSwitch.txt
2012-09-22 14:32 - 2012-09-22 14:32 - 0000000 _____ () C:\ProgramData\50pWN8.dat
2012-09-22 14:31 - 2012-09-22 14:31 - 0000001 _____ () C:\ProgramData\5U0eRTH0.exe.b
2012-09-22 14:31 - 2012-09-22 14:31 - 0000001 _____ () C:\ProgramData\5U0eRTH0.exe_.b
2010-06-16 22:22 - 2010-06-16 22:22 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2007-05-31 02:34 - 2012-06-23 14:09 - 0000675 _____ () C:\ProgramData\hpzinstall.log
2010-04-13 20:25 - 2015-08-04 22:10 - 0047962 _____ () C:\ProgramData\nvModes.001
2010-04-13 20:25 - 2015-08-04 19:08 - 0047962 _____ () C:\ProgramData\nvModes.dat
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1766275910-2450894708-632072239-1000\$ef8a5bbf5833eadd22ca66c158232ebe
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$ef8a5bbf5833eadd22ca66c158232ebe
ZeroAccess:
C:\Users\Janelle\AppData\Local\{ef8a5bbf-5833-eadd-22ca-66c158232ebe}
ZeroAccess:
C:\Users\Janelle\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files\Google\Desktop\Install
Some files in TEMP:
====================
C:\Users\Mary\AppData\Local\Temp\symlcsv1.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
LastRegBack: 2015-08-04 22:37
==================== End of log ============================