My wives laptop, Samsung NP300E5C, runs extremely slow. I have used CCleaner to clean out cashe and junk files, I dont know what else to do to make sure its not infected. Have Kaspersky antivirus actively ruuning.
Her birthday is this month and I told her I would see what I can do to make it run faster.
So I need your help
below are the text files from ASWMBR and FRST64
FRST TEXT FILE:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:09-08-2015
Ran by [removed] (administrator) on CARLASPC (10-08-2015 12:23:22)
Running from C:\Users\[removed]\Desktop\KevinStuff
[removed]
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe
(Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\SAMSUNG\SW Update Service\SWMAgent.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avpui.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.7\waol.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Carbonite, Inc.) C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191312 2012-08-06] (Realtek Semiconductor)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2862448 2012-08-05] (ELAN Microelectronics Corp.)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [765056 2012-09-29] (Qualcomm Atheros)
HKLM-x32\…\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\…\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-07] (CyberLink)
HKLM-x32\…\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.)
HKLM-x32\…\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1064144 2015-03-06] (Carbonite, Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4204859643-4009438992-3315869148-1001\…\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2014-10-28] (Microsoft Corporation)
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7930136 2015-07-30] (SUPERAntiSpyware)
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\Run: [AOL Fast Start] => C:\Program Files (x86)\AOL Desktop 9.7\AOL.EXE [72312 2012-10-15] (AOL Inc.)
AppInit_DLLs: C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File not found
AppInit_DLLs: C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll File not found
Startup: C:\Users\carla35758\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-09-29]
ShortcutTarget: Dropbox.lnk -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.facebook.com/
SearchScopes: HKLM -> {CC865B26-C31D-4D23-B17B-96548EEF03F6} URL =
SearchScopes: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002 -> {660B7A65-A56F-4D71-BFCF-0005860DBC96} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=UTF-8&fr;=w3i&type;=W3i_DS,136,0_0,Search,20140518,19890,0,25,0
SearchScopes: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002 -> {7B6EFEF5-D5E7-4702-9B31-BBD18869E868} URL =
BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{66468EF5-92A1-437E-B0FF-288E107324DF}: [DhcpNameServer] [removed] [removed]
FireFox:
========
FF ProfilePath: C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980
FF DefaultSearchEngine.US: Ask Web Search
FF Homepage: https://www.facebook.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-14] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19] ()
FF Plugin-x32: @kaspersky.com/online_banking_08806E753BE44495B44E90AA2513BDC5 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-27] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @viewpoint.com/VMP -> C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4204859643-4009438992-3315869148-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\carla35758\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS)
FF user.js: detected! => C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980\user.js [2015-05-20]
FF SearchPlugin: C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980\searchplugins\ask-web-search.xml [2015-05-17]
FF Extension: MapsGalaxy - C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980\Extensions\[removed] [2015-06-05]
FF Extension: ShopAtHome.com Toolbar - C:\Users\carla35758\AppData\Roaming\Mozilla\Firefox\Profiles\c634hs6v.default-1411133199980\Extensions\[removed] [2014-10-14]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed]
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\[removed] [2015-05-19]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2013-07-03] <==== ATTENTION
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\carla35758\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (cosstminn) - C:\Users\carla35758\AppData\Local\Google\Chrome\User Data\Default\Extensions\daghmolfjadhlegnbflapihpbaibodig [2014-08-19]
CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-08-12] (SUPERAntiSpyware.com)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [220288 2012-09-29] (Qualcomm Atheros Commnucations) [File not signed]
R2 AVP15.0.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe [194000 2015-06-24] (Kaspersky Lab ZAO)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593976 2012-08-26] (Samsung Electronics CO., LTD.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2014-10-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-09-29] (Atheros) [File not signed]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-09-24] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-24] (CyberLink)
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [247016 2015-06-24] (Kaspersky Lab UK Ltd)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-24] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [64368 2015-06-24] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [159960 2015-06-24] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [226480 2015-07-03] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [831664 2015-06-24] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [39792 2015-06-24] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [40304 2015-06-24] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [39792 2015-06-24] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [24944 2015-06-24] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [77680 2015-06-24] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [85360 2015-06-24] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [190648 2015-06-24] (Kaspersky Lab ZAO)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
S3 BTATH_LWFLT; \SystemRoot\system32\DRIVERS\btath_lwflt.sys [X]
U3 aswMBR; \??\C:\Users\CARLA3~1\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\CARLA3~1\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-10 09:11 - 2015-08-10 09:11 - 00036776 _____ C:\Users\carla35758\Downloads\w4sgeen9(2).exe
2015-08-10 08:58 - 2015-08-10 08:59 - 00036776 _____ C:\Users\carla35758\Downloads\w4sgeen9(1).exe
2015-08-10 08:36 - 2015-08-10 12:23 - 00000000 ____D C:\FRST
2015-08-10 08:35 - 2015-08-10 12:23 - 00000000 ____D C:\Users\carla35758\Desktop\KevinStuff
2015-07-28 16:43 - 2015-07-28 16:43 - 00000748 _____ C:\Users\Public\Desktop\Skoolbo Common Core.lnk
2015-07-28 16:39 - 2015-07-28 16:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skoolbo Common Core
2015-07-28 16:39 - 2015-07-28 16:39 - 00000000 ____D C:\Skoolbo Common Core
2015-07-28 15:55 - 2015-07-28 16:24 - 368329728 _____ C:\Users\carla35758\Downloads\SkoolboUS.msi
2015-07-28 15:38 - 2015-07-28 15:45 - 83888551 _____ C:\Users\carla35758\Downloads\SkoolboAussie.msi.part
2015-07-28 09:18 - 2015-07-25 08:34 - 01084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-07-26 22:20 - 2015-07-26 22:29 - 00000000 ____D C:\Users\carla35758\Desktop\CourageousChurchPoolParty
2015-07-26 22:19 - 2015-07-26 22:28 - 00000000 ____D C:\Users\carla35758\Desktop\30yearHighSchoolReunion
2015-07-21 20:32 - 2015-08-01 09:15 - 00000154 _____ C:\WINDOWS\setupact.log
2015-07-21 20:32 - 2015-07-21 20:32 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-07-20 18:38 - 2015-07-14 09:14 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-07-20 18:38 - 2015-07-14 09:14 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-07-20 18:38 - 2015-07-14 09:14 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-07-20 18:38 - 2015-07-14 09:13 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-07-18 02:00 - 2015-08-10 12:17 - 01188105 _____ C:\WINDOWS\WindowsUpdate.log
2015-07-14 18:06 - 2015-06-24 21:31 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-07-14 18:06 - 2015-04-29 18:22 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-14 18:04 - 2015-06-28 00:07 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2015-07-14 18:04 - 2015-06-28 00:07 - 00178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-07-14 18:04 - 2015-06-28 00:06 - 01311960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-07-14 18:04 - 2015-06-28 00:06 - 00332120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2015-07-14 18:04 - 2015-06-27 11:42 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-07-14 18:04 - 2015-06-26 22:13 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2015-07-14 18:04 - 2015-06-26 22:12 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2015-07-14 18:04 - 2015-06-26 22:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2015-07-14 18:04 - 2015-06-26 21:05 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-07-14 18:04 - 2015-06-26 21:00 - 00989184 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-07-14 18:04 - 2015-06-26 20:26 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-07-14 18:03 - 2015-06-26 21:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-07-14 18:03 - 2015-06-26 20:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-07-14 17:55 - 2015-07-09 11:03 - 03701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-07-14 17:54 - 2015-07-09 10:54 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-07-14 17:54 - 2015-07-09 10:34 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-07-14 17:54 - 2015-06-26 21:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-07-14 17:53 - 2015-07-09 14:51 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-07-14 17:53 - 2015-07-09 13:40 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-07-14 17:53 - 2015-07-09 10:50 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-07-14 17:53 - 2015-07-09 10:48 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-07-14 17:53 - 2015-07-09 10:46 - 02229248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-07-14 17:53 - 2015-07-09 10:38 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-07-14 17:53 - 2015-07-09 10:35 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-07-14 17:52 - 2015-07-09 10:53 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-07-14 17:52 - 2015-07-09 10:50 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-14 17:52 - 2015-07-09 10:37 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-07-14 17:52 - 2015-06-26 22:08 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-07-14 17:51 - 2015-06-26 22:08 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-07-14 17:35 - 2015-06-29 10:07 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-07-14 17:35 - 2015-06-26 18:21 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-07-14 17:34 - 2015-06-29 17:43 - 00026288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-14 17:34 - 2015-06-29 10:07 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-07-14 17:34 - 2015-06-29 10:07 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-07-14 17:33 - 2015-06-29 10:07 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-07-14 17:33 - 2015-06-26 18:21 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-07-14 17:30 - 2014-11-04 14:25 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys
2015-07-14 17:30 - 2014-11-04 14:25 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys
2015-07-14 17:30 - 2014-11-04 01:55 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys
2015-07-14 17:30 - 2014-11-04 01:54 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys
2015-07-14 17:30 - 2014-11-04 01:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2015-07-14 17:30 - 2014-11-04 01:54 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
2015-07-14 17:29 - 2015-05-02 19:39 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-07-14 17:26 - 2015-05-07 10:21 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-14 17:26 - 2015-05-07 10:05 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll
2015-07-14 17:22 - 2015-05-07 12:50 - 22292672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-07-14 17:20 - 2015-05-07 11:53 - 19734960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-07-14 17:16 - 2015-05-07 12:00 - 03109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-14 17:16 - 2015-05-07 11:12 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-07-14 17:13 - 2015-05-11 13:17 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2015-07-14 17:11 - 2015-04-24 21:25 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys
2015-07-14 17:07 - 2015-05-03 09:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-07-14 17:07 - 2015-05-03 09:49 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2015-07-14 17:06 - 2015-05-03 10:09 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-14 17:06 - 2015-05-03 09:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-14 16:49 - 2015-06-15 17:41 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-07-14 16:49 - 2015-06-15 17:24 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-07-14 16:49 - 2015-06-15 16:16 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-07-14 16:49 - 2015-06-15 16:09 - 03607552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-07-14 16:49 - 2015-06-15 15:50 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-07-14 16:49 - 2015-06-15 14:57 - 02460160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-07-14 16:48 - 2015-05-30 16:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-14 16:48 - 2015-05-30 14:36 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-14 16:48 - 2015-05-30 14:35 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-07-14 16:46 - 2015-07-01 17:08 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-07-14 16:46 - 2015-07-01 16:14 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-07-14 16:44 - 2015-07-02 16:21 - 19877376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-07-14 16:44 - 2015-07-02 15:49 - 25193984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-07-14 16:43 - 2015-07-02 15:23 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-07-14 16:43 - 2015-07-02 15:19 - 12855296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-07-14 16:43 - 2015-07-02 14:20 - 14453248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-07-14 16:43 - 2015-07-02 13:59 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-07-14 16:42 - 2015-07-02 15:50 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-07-14 16:42 - 2015-07-02 14:55 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-07-14 16:41 - 2015-06-15 17:39 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-07-14 16:41 - 2015-06-15 17:38 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-07-14 16:41 - 2015-06-15 17:26 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-07-14 16:41 - 2015-06-15 17:24 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-07-14 16:41 - 2015-06-15 17:02 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2015-07-14 16:41 - 2015-06-15 16:58 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2015-07-14 16:41 - 2015-06-15 16:57 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-07-14 16:41 - 2015-06-15 16:56 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-07-14 16:41 - 2015-06-15 16:55 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-07-14 16:41 - 2015-06-15 16:49 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-07-14 16:41 - 2015-06-15 16:41 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-07-14 16:41 - 2015-06-15 16:38 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-07-14 16:41 - 2015-06-15 16:36 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-07-14 16:41 - 2015-06-15 16:17 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-07-14 16:41 - 2015-06-15 16:16 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-07-14 16:41 - 2015-06-15 16:15 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-07-14 16:41 - 2015-06-15 16:13 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-07-14 16:41 - 2015-06-15 16:04 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-07-14 16:41 - 2015-06-15 16:03 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-07-14 16:41 - 2015-06-15 15:52 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-07-14 16:41 - 2015-06-15 15:47 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2015-07-14 16:41 - 2015-06-15 15:44 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2015-07-14 16:41 - 2015-06-15 15:43 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-07-14 16:41 - 2015-06-15 15:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-07-14 16:41 - 2015-06-15 15:41 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-07-14 16:41 - 2015-06-15 15:37 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-07-14 16:41 - 2015-06-15 15:32 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-07-14 16:41 - 2015-06-15 15:31 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-07-14 16:41 - 2015-06-15 15:30 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-07-14 16:41 - 2015-06-15 15:30 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-07-14 16:41 - 2015-06-15 15:17 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-07-14 16:41 - 2015-06-15 15:07 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-07-14 16:41 - 2015-06-15 15:02 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-07-14 16:40 - 2015-06-10 22:49 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-07-14 16:40 - 2015-06-10 11:13 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-07-14 16:40 - 2015-05-11 11:34 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
2015-07-14 16:39 - 2015-06-16 00:36 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2015-07-14 16:39 - 2015-06-16 00:36 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2015-07-14 16:39 - 2015-05-12 08:19 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-14 16:39 - 2015-05-07 11:47 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2015-07-14 16:39 - 2015-05-03 10:07 - 07784448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-14 16:39 - 2015-05-03 09:57 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2015-07-14 16:39 - 2015-05-01 18:33 - 00410739 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-07-14 16:39 - 2015-04-28 08:13 - 00513480 _____ C:\WINDOWS\SysWOW64\locale.nls
2015-07-14 16:39 - 2015-04-28 08:13 - 00513480 _____ C:\WINDOWS\system32\locale.nls
2015-07-14 16:39 - 2015-04-23 10:47 - 03084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-07-14 16:39 - 2015-04-23 10:16 - 02471424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-07-12 23:35 - 2015-07-12 23:37 - 00000000 ____D C:\Users\carla35758\Desktop\mawmaw-papaw-7-12-15
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-10 12:16 - 2013-11-09 13:31 - 00000392 _____ C:\WINDOWS\Tasks\WpsUpdateTask_carla35758.job
2015-08-10 12:00 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-08-10 11:35 - 2015-06-14 16:48 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-08-10 11:05 - 2015-05-19 14:05 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-08-10 09:55 - 2014-11-06 12:33 - 00000538 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 0053b9ac-3feb-4519-8a4d-147b3b99a4bb.job
2015-08-10 09:41 - 2013-05-31 18:36 - 00000966 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002UA.job
2015-08-10 08:55 - 2015-02-14 09:34 - 00003946 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B265354F-4343-4044-9BBC-6323DD2FBBF9}
2015-08-10 08:37 - 2014-09-24 02:15 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-10 01:00 - 2014-11-06 12:33 - 00000538 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task da4e332b-f72c-488e-bc21-ac7a7a869ad2.job
2015-08-09 22:47 - 2012-08-22 23:11 - 00000000 ____D C:\ProgramData\Temp
2015-08-09 18:41 - 2013-05-31 18:36 - 00000944 _____ C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002Core.job
2015-08-09 14:13 - 2014-06-16 14:12 - 00000392 _____ C:\WINDOWS\Tasks\PassShow_wd.job
2015-08-07 17:02 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-08-07 16:57 - 2012-12-29 14:35 - 00000000 ____D C:\Users\carla35758\AppData\Local\Packages
2015-08-07 06:19 - 2012-12-29 15:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-07 06:19 - 2012-12-29 15:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-01 09:21 - 2012-12-29 14:44 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4204859643-4009438992-3315869148-1002
2015-08-01 09:15 - 2013-08-22 09:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-01 09:14 - 2013-08-17 09:54 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-30 09:37 - 2012-07-26 02:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-07-25 18:52 - 2015-04-03 22:13 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-07-21 20:32 - 2013-08-22 09:44 - 00481176 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-07-17 17:00 - 2013-11-24 16:13 - 00073728 ___SH C:\Users\carla35758\Desktop\Thumbs.db
2015-07-17 16:38 - 2015-04-03 22:13 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2015-07-17 16:38 - 2014-12-10 22:30 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-07-17 16:38 - 2014-09-24 04:50 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-07-17 16:38 - 2013-08-22 10:36 - 00000000 ___RD C:\WINDOWS\ToastData
2015-07-17 16:38 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\WinStore
2015-07-16 17:37 - 2013-04-11 15:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-07-16 17:19 - 2013-08-16 13:15 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-07-16 10:34 - 2014-10-23 21:30 - 00000000 ____D C:\Users\carla35758
2015-07-16 10:34 - 2013-08-22 08:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-07-16 10:33 - 2014-09-18 06:55 - 00000000 ____D C:\Users\carla35758\AppData\Roaming\v9
2015-07-14 23:35 - 2015-06-14 16:48 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-07-13 16:10 - 2015-06-11 09:03 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-07-13 16:10 - 2015-06-11 09:03 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-12 23:34 - 2015-04-24 22:58 - 00000000 ____D C:\Users\carla35758\Desktop\harrisChapelSpringfest
==================== Files in the root of some directories =======
2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\carla35758\AppData\Roaming\JOQA
2014-09-01 03:18 - 2014-09-01 03:18 - 0002086 _____ () C:\Users\carla35758\AppData\Roaming\NKO
2014-08-21 06:50 - 2014-08-21 06:50 - 0000045 _____ () C:\Users\carla35758\AppData\Roaming\WB.CFG
2013-05-22 16:45 - 2013-02-21 16:59 - 2063240 _____ (Samsung Electronics) C:\ProgramData\MakeMarkerFile.exe
2013-05-22 16:45 - 2013-01-12 23:51 - 0003004 _____ () C:\ProgramData\MakeMarkerFile.xml
Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-11 09:15
==================== End of log ============================
ADDITION TEXT FILE:
Additional scan result of Farbar Recovery Scan Tool (x64) Version:09-08-2015
Ran by [removed] (2015-08-10 12:26:47)
Running from C:\Users\[removed]\Desktop\KevinStuff
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-4204859643-4009438992-3315869148-500 - Administrator - Disabled)
carla35758 (S-1-5-21-4204859643-4009438992-3315869148-1002 - Administrator - Enabled) => C:\Users\carla35758
Guest (S-1-5-21-4204859643-4009438992-3315869148-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4204859643-4009438992-3315869148-1006 - Limited - Enabled)
UpdatusUser (S-1-5-21-4204859643-4009438992-3315869148-1001 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
12 Labours of Hercules (HKLM-x32\…\BFG-12 Labours of Hercules) (Version: - )
12 Labours of Hercules II: The Cretan Bull (HKLM-x32\…\BFG-12 Labours of Hercules II - The Cretan Bull) (Version: - )
12 Labours of Hercules III: Girl Power (HKLM-x32\…\BFG-12 Labours of Hercules III - Girl Power) (Version: - )
4 Elements (HKLM-x32\…\BFG-4 Elements) (Version: - )
4 Elements II (HKLM-x32\…\BFG-4 Elements II) (Version: - )
Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.03) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
Allshare Play Link (HKLM-x32\…\{91786428-D4AA-476D-8AF9-A63FFAC2901F}) (Version: 1.0.0 - Samsung)
AOL Uninstaller (Choose which Products to Remove) (HKLM-x32\…\AOL Uninstaller) (Version: - AOL Inc.)
Big Fish: Game Manager (HKLM-x32\…\BFGC) (Version: 3.3.0.2 - )
Carbonite (HKLM-x32\…\Carbonite Backup) (Version: 5.7.4 build 4814 (Mar-06-2015) - Carbonite)
CCleaner (HKLM\…\CCleaner) (Version: 4.03 - Piriform)
Cradle of Egypt (HKLM-x32\…\BFG-Cradle of Egypt) (Version: - )
CyberLink Power2Go 8 (HKLM-x32\…\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.1912 - CyberLink Corp.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4415.02 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dropbox (HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\Dropbox) (Version: 2.10.30 - Dropbox, Inc.)
Easy File Share (HKLM-x32\…\{A7C37D4B-F37A-42E8-9B6A-B28C18AD4C12}) (Version: 1.3.4 - Samsung Electronics CO.,LTD.)
E-POP (HKLM-x32\…\{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}) (Version: 1.0.1 - Samsung Electronics CO., LTD.)
ETDWare PS/2-X64 11.7.2.1_WHQL (HKLM\…\Elantech) (Version: 11.7.2.1 - ELAN Microelectronic Corp.)
Galería de fotos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Help Desk (HKLM\…\{C85A891D-7AB4-46AE-84F0-B0C3FAC82280}) (Version: 1.0.4 - Samsung Electronics CO., LTD.)
Intel AppUp(SM) center (HKLM-x32\…\Intel AppUp(SM) center 33070) (Version: 3.6.1.33070.11 - Intel)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\…\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36702 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.2.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Internet Explorer Toolbar 4.9 by SweetPacks (HKLM-x32\…\{F4E33CE5-A7AB-4F68-A7E7-F0AA84EF2D9E}) (Version: 4.9.0000 - SweetIM Technologies Ltd.) <==== ATTENTION
Island Tribe 2 (HKLM-x32\…\BFG-Island Tribe 2) (Version: - )
Island Tribe 3 (HKLM-x32\…\BFG-Island Tribe 3) (Version: - )
Island Tribe 4 (HKLM-x32\…\BFG-Island Tribe 4) (Version: - )
Island Tribe 5 (HKLM-x32\…\BFG-Island Tribe 5) (Version: - )
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
Jewel Legends: Atlantis (HKLM-x32\…\BFG-Jewel Legends - Atlantis) (Version: - )
Kaspersky Internet Security (HKLM-x32\…\InstallWIX_{02FECEE0-16B2-43DB-BC3B-C844477FC142}) (Version: 15.0.2.361 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 15.0.2.361 - Kaspersky Lab) Hidden
Kingdom Chronicles (HKLM-x32\…\BFG-Kingdom Chronicles) (Version: - )
Kingsoft Office 2013 (9.1.0.4246) (HKLM-x32\…\Kingsoft Office) (Version: 9.1.0.4246 - Kingsoft Corp.)
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM-x32\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version: - Microsoft)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUSR) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Mozilla Firefox 39.0.3 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 39.0.3 (x86 en-US)) (Version: 39.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
My Kingdom for the Princess III (HKLM-x32\…\BFG-My Kingdom for the Princess III) (Version: - )
Northern Tale 3 (HKLM-x32\…\BFG-Northern Tale 3) (Version: - )
NVIDIA Graphics Driver 305.46 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 305.46 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0613 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0613 - NVIDIA Corporation)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.210 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Quick Starter (HKLM\…\{EC36E2BC-86F7-44C9-84B2-93930F0FBDBF}) (Version: 1.0.0 - Samsung Electronics CO., LTD.)
QuickShare (HKLM-x32\…\{04DB50FA-EA80-4256-85F9-540C582E280D}) (Version: 1.39.60.10936 - Linkury Inc.) <==== ATTENTION
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6699 - Realtek Semiconductor Corp.)
Recovery (HKLM-x32\…\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.0.4.0 - Samsung Electronics CO., LTD.)
Rescue Team 3 (HKLM-x32\…\BFG-Rescue Team 3) (Version: - )
Rescue Team 4 (HKLM-x32\…\BFG-Rescue Team 4) (Version: - )
Rolling Idols (HKLM-x32\…\BFG-Rolling Idols) (Version: - )
S Agent (Version: 1.1.47 - Samsung Electronics CO., LTD.) Hidden
Settings (HKLM-x32\…\{52E5DE60-C96B-42CC-9A37-FE04725940AE}) (Version: 2.0.0 - Samsung Electronics CO., LTD.)
Skoolbo Common Core (HKLM-x32\…\{5A4A6854-80F9-486E-994D-CB7DE54446D5}) (Version: 1.9 - Skoolbo)
Slingo Quest Egypt (HKLM-x32\…\BFG-Slingo Quest Egypt) (Version: - )
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1032 - SUPERAntiSpyware.com)
Support Center (HKLM\…\{332518C0-0D31-4FFA-9D15-24C9C3D70B08}) (Version: 2.0.7 - Samsung Electronics CO., LTD.)
Support Center FAQ (x32 Version: 1.0.0 - Samsung Electronics CO., LTD.) Hidden
SW Update (HKLM-x32\…\{4F1936F8-82B4-437E-BC47-FAB9136A04B2}) (Version: 2.2.2 - Samsung Electronics CO., LTD.)
Unity Web Player (HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\UnityWebPlayer) (Version: 5.0.3f2 - Unity Technologies ApS)
User Guide (HKLM-x32\…\{039EA659-E421-45C6-8913-BED5D69B5536}) (Version: 1.1.00 - Samsung Electronics CO., LTD.)
Viewpoint Media Player (HKLM-x32\…\ViewpointMediaPlayer) (Version: - )
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Driver Package - Samsung Electronics Co. Ltd. (RadioHIDMini) HIDClass (07/27/2012 20.57.1.735) (HKLM\…\9F04C462DAB591BDCCE784F77E4D4F1736010B92) (Version: 07/27/2012 20.57.1.735 - Samsung Electronics Co. Ltd.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation)
World Mosaics (HKLM-x32\…\BFG-World Mosaics) (Version: - )
World Mosaics 2 (HKLM-x32\…\BFG-World Mosaics 2) (Version: - )
World Mosaics 3 - Fairy Tales (HKLM-x32\…\BFG-World Mosaics 3 - Fairy Tales) (Version: - )
World Mosaics 4 (HKLM-x32\…\BFG-World Mosaics 4) (Version: - )
World Mosaics 5 (HKLM-x32\…\BFG-World Mosaics 5) (Version: - )
World Mosaics 6 (HKLM-x32\…\BFG-World Mosaics 6) (Version: - )
World Mosaics 7 (HKLM-x32\…\BFG-World Mosaics 7) (Version: - )
Xerox PhotoCafe (HKLM-x32\…\Xerox PhotoCafe) (Version: 1.0.0.6162 - Xerox)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4204859643-4009438992-3315869148-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\carla35758\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
==================== Restore Points =========================
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {070C494E-CD08-4707-8FED-069101CD900F} - \UNELEVATE_5431 -> No File <==== ATTENTION
Task: {096E8B75-6174-41DA-8FDF-D304073A5F4C} - System32\Tasks\{C466F0B1-0338-4A75-8344-AD12604D66EE} => pcalua.exe -a C:\Users\carla35758\AppData\Roaming\v9\UninstallManager.exe -c -ptid=brd
Task: {18752ADC-B660-4C6F-BA15-61D22C5DD0E3} - \SPDriver -> No File <==== ATTENTION
Task: {293AD38A-4B55-4804-8242-E6284210F818} - System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} => C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe [2015-08-10] (Carbonite, Inc.)
Task: {32FCAA4B-128E-4C12-A714-0D7672270DEB} - System32\Tasks\SUPERAntiSpyware Scheduled Task da4e332b-f72c-488e-bc21-ac7a7a869ad2 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2015-06-02] (SUPERAdBlocker.com)
Task: {3B4A0561-468B-4EB0-818E-CEB4F289165A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002Core => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {3B91F900-5B7B-448F-BF2E-336E82217199} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-03-19] (Samsung Electronics CO., LTD.)
Task: {44CC3745-D2A0-4BDE-B7C4-923572E8564A} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-13] (Intel Corporation)
Task: {568F5729-80E6-4D41-9F5F-5CB1B4A7A649} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-14] (Adobe Systems Incorporated)
Task: {5ED2BD9A-B701-4A2C-A3C9-66E09507CA5D} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {63841FB8-2F7E-4FA8-9A61-F50F9A81A1E4} - System32\Tasks\Xerox PhotoCafe Communicator => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe [2011-10-26] ()
Task: {66772626-F494-4B3A-959A-3880CFFD2C07} - System32\Tasks\SMupdate1 => Rundll32.exe C:\Program Files\Common Files\System\SysMenu.dll ,Command701 update1 <==== ATTENTION
Task: {6FCA7E11-801E-47AB-A1C0-08463E6AB6FB} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\Program Files\Common Files\System\SysMenu.dll ,Command701 update2 <==== ATTENTION
Task: {73ECE52C-D3EC-4FD5-AB08-D163F22467BB} - \PassShow_wd -> No File <==== ATTENTION
Task: {77D6C834-DDD7-4093-8ED6-45A83845E4AF} - System32\Tasks\SUPERAntiSpyware Scheduled Task 0053b9ac-3feb-4519-8a4d-147b3b99a4bb => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2015-06-02] (SUPERAdBlocker.com)
Task: {7D1EC64A-AC38-4232-851D-480DA778B967} - \ShopperPro -> No File <==== ATTENTION
Task: {88046CAC-C778-49A7-ACA5-42400985CC23} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2012-08-26] (Samsung Electronics CO., LTD.)
Task: {8A86E6C1-367E-430D-82BC-116B4AB573A0} - \SMW_UpdateTask_Time_3337383035303739342d7837235a576c4a3241345041 -> No File <==== ATTENTION
Task: {90087B42-1C8E-4F64-8849-86829F63DA92} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\Program Files\Common Files\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
Task: {91890BDF-A52C-4594-9172-238D8B3CC894} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe
Task: {92D51808-34E0-4B7D-AE64-27CE43674E94} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002UA => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {A5E5FE4D-0FA4-42CB-9D42-A0761D729516} - System32\Tasks\JOQA => C:\Users\carla35758\AppData\Roaming\JOQA.exe <==== ATTENTION
Task: {A7F7D002-44F7-46AE-917F-5E05883EED9F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-07-03] (Microsoft Corporation)
Task: {AA8101C7-DE8C-46B5-A0B6-24902A843EBA} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2012-08-15] (SEC)
Task: {B323EEB2-9A31-479D-873C-30B54580EF93} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {BE6E1AFB-7517-43EB-88C9-F3499C6EF59D} - \SPBIW_UpdateTask_Time_3337383035303739342d7837235a576c4a3241345041 -> No File <==== ATTENTION
Task: {CCB32432-49F8-4C5C-BE80-19E08C6E842E} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-06-13] (Intel Corporation)
Task: {CD32C726-BF85-4C1D-A1CC-0E299F9DE022} - System32\Tasks\NKO => C:\Users\carla35758\AppData\Roaming\NKO.exe <==== ATTENTION
Task: {D001A4BC-EFBA-40A3-8EE0-BA67163C32E5} - \PassShow Update -> No File <==== ATTENTION
Task: {D1D33321-9002-4DAD-BB26-A3A2223F13D4} - System32\Tasks\WpsUpdateTask_carla35758 => C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsupdate.exe [2014-08-06] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {F0D408F1-3B65-4649-BA92-EE988E83FD2A} - System32\Tasks\{C6959241-77B1-456F-BA17-1EF70857F486} => pcalua.exe -a "C:\Program Files (x86)\Groovorio\\uninstall.exe"
Task: {F4B6C860-9974-47A1-AE15-70B38327297B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002Core.job => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-4204859643-4009438992-3315869148-1002UA.job => C:\Users\carla35758\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\JOQA.job => C:\Users\carla35758\AppData\Roaming\JOQA.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\NKO.job => C:\Users\carla35758\AppData\Roaming\NKO.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\PassShow_wd.job => C:\Program Files (x86)\PassShowS\PassShowl.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 0053b9ac-3feb-4519-8a4d-147b3b99a4bb.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task da4e332b-f72c-488e-bc21-ac7a7a869ad2.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\WINDOWS\Tasks\WpsUpdateTask_carla35758.job => C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsupdate.exe
Task: C:\WINDOWS\Tasks\Xerox PhotoCafe Communicator.job => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe
==================== Loaded Modules (Whitelisted) ==============
2014-01-29 23:02 - 2015-06-01 21:00 - 00102912 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-12-23 16:54 - 2014-12-23 16:54 - 01272616 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\kpcengine.2.3.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00026232 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00110712 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00029816 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll
2012-08-26 04:48 - 2012-08-26 04:48 - 00091768 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll
2012-10-15 11:45 - 2012-10-15 11:45 - 00048640 _____ () C:\Program Files (x86)\AOL Desktop 9.7\zlib.dll
2012-08-22 22:54 - 2012-06-25 13:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:0ACF1AF5
AlternateDataStreams: C:\ProgramData\Temp:0AF6266B
AlternateDataStreams: C:\ProgramData\Temp:0D01FEF7
AlternateDataStreams: C:\ProgramData\Temp:134FBDE2
AlternateDataStreams: C:\ProgramData\Temp:1409277B
AlternateDataStreams: C:\ProgramData\Temp:15E76ABF
AlternateDataStreams: C:\ProgramData\Temp:165AF2C6
AlternateDataStreams: C:\ProgramData\Temp:1968990D
AlternateDataStreams: C:\ProgramData\Temp:1A5207FA
AlternateDataStreams: C:\ProgramData\Temp:1A5CC80A
AlternateDataStreams: C:\ProgramData\Temp:2487D1DA
AlternateDataStreams: C:\ProgramData\Temp:2CB9631F
AlternateDataStreams: C:\ProgramData\Temp:2CED8825
AlternateDataStreams: C:\ProgramData\Temp:3AF262FC
AlternateDataStreams: C:\ProgramData\Temp:3DA71AE7
AlternateDataStreams: C:\ProgramData\Temp:45C55624
AlternateDataStreams: C:\ProgramData\Temp:46CBC45C
AlternateDataStreams: C:\ProgramData\Temp:52329B88
AlternateDataStreams: C:\ProgramData\Temp:5C4A588B
AlternateDataStreams: C:\ProgramData\Temp:5D40B34A
AlternateDataStreams: C:\ProgramData\Temp:61C6B926
AlternateDataStreams: C:\ProgramData\Temp:639BB5E9
AlternateDataStreams: C:\ProgramData\Temp:6641B59F
AlternateDataStreams: C:\ProgramData\Temp:67396145
AlternateDataStreams: C:\ProgramData\Temp:6DDFD746
AlternateDataStreams: C:\ProgramData\Temp:77E239B1
AlternateDataStreams: C:\ProgramData\Temp:7E4E56EA
AlternateDataStreams: C:\ProgramData\Temp:84FA02E7
AlternateDataStreams: C:\ProgramData\Temp:85376176
AlternateDataStreams: C:\ProgramData\Temp:87CA9EF8
AlternateDataStreams: C:\ProgramData\Temp:884C7316
AlternateDataStreams: C:\ProgramData\Temp:89A5891E
AlternateDataStreams: C:\ProgramData\Temp:8B3C3098
AlternateDataStreams: C:\ProgramData\Temp:8C12CFCD
AlternateDataStreams: C:\ProgramData\Temp:97CA3B9E
AlternateDataStreams: C:\ProgramData\Temp:99AC3203
AlternateDataStreams: C:\ProgramData\Temp:9D91E651
AlternateDataStreams: C:\ProgramData\Temp:9DA44E6B
AlternateDataStreams: C:\ProgramData\Temp:A31FAD21
AlternateDataStreams: C:\ProgramData\Temp:A3E34FEB
AlternateDataStreams: C:\ProgramData\Temp:A6A65B80
AlternateDataStreams: C:\ProgramData\Temp:AC83EA04
AlternateDataStreams: C:\ProgramData\Temp:B059B88E
AlternateDataStreams: C:\ProgramData\Temp:B9F8237A
AlternateDataStreams: C:\ProgramData\Temp:C36F1B98
AlternateDataStreams: C:\ProgramData\Temp:C69BA1D0
AlternateDataStreams: C:\ProgramData\Temp:CA400C1B
AlternateDataStreams: C:\ProgramData\Temp:CB959782
AlternateDataStreams: C:\ProgramData\Temp:CC386FD2
AlternateDataStreams: C:\ProgramData\Temp:D01ACC06
AlternateDataStreams: C:\ProgramData\Temp:D1713795
AlternateDataStreams: C:\ProgramData\Temp:D3A82449
AlternateDataStreams: C:\ProgramData\Temp:D5CCCBAA
AlternateDataStreams: C:\ProgramData\Temp:D92485C9
AlternateDataStreams: C:\ProgramData\Temp:DCA79AB3
AlternateDataStreams: C:\ProgramData\Temp:E153075C
AlternateDataStreams: C:\ProgramData\Temp:E2295807
AlternateDataStreams: C:\ProgramData\Temp:E5BA9ADD
AlternateDataStreams: C:\ProgramData\Temp:E6537A16
AlternateDataStreams: C:\ProgramData\Temp:ED6B6C83
AlternateDataStreams: C:\ProgramData\Temp:F72306CC
AlternateDataStreams: C:\ProgramData\Temp:F7581CE6
AlternateDataStreams: C:\ProgramData\Temp:F7B0AE93
AlternateDataStreams: C:\ProgramData\Temp:FBFC061F
AlternateDataStreams: C:\ProgramData\Temp:FC2E567F
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4204859643-4009438992-3315869148-1001\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\Samsung\Samsung_wallpaper.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: HostManager => C:\Program Files (x86)\Common Files\AOL\1356813129\ee\AOLSoftware.exe
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
HKLM\…\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\…\StartupApproved\Run: => "BtTray"
HKLM\…\StartupApproved\Run: => "RtHDVCpl"
HKLM\…\StartupApproved\Run: => "ETDCtrl"
HKLM\…\StartupApproved\Run32: => "Adobe ARM"
HKLM\…\StartupApproved\Run32: => "Adobe Reader Speed Launcher"
HKLM\…\StartupApproved\Run32: => "BCSSync"
HKLM\…\StartupApproved\Run32: => "RemoteControl10"
HKLM\…\StartupApproved\Run32: => "Intel AppUp(SM) center"
HKLM\…\StartupApproved\Run32: => "HostManager"
HKLM\…\StartupApproved\Run32: => "CLMLServer_For_P2G8"
HKLM\…\StartupApproved\Run32: => "CLVirtualDrive"
HKLM\…\StartupApproved\Run32: => "ETDCtrl"
HKLM\…\StartupApproved\Run32: => "fst_us_210"
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-4204859643-4009438992-3315869148-1002\…\StartupApproved\Run: => "Browser Infrastructure Helper"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{1C944511-C752-4493-B77A-157665E1C1C1}C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{CA550F8B-40AF-4A39-8732-ED60339734C9}C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\carla35758\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{2BE51C0E-67C3-4554-A77B-A9910CF7D8A0}] => (Allow) C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{C912F999-8FBD-48DF-856C-9194469551B3}] => (Allow) C:\Users\carla35758\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{C584D5A0-0A75-4296-BC02-98DD649035FA}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe
FirewallRules: [{3A46C0B8-F73A-41E3-A45C-78A1A66D8AC4}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe
FirewallRules: [{2177685B-3B42-4E3D-B6EB-BE9BFDF89B32}] => (Allow) C:\Program Files (x86)\Common Files\AOL\System Information\sinf.exe
FirewallRules: [{ED1A5EF6-F1D7-45AE-98FC-BB52831D4916}] => (Allow) C:\Program Files (x86)\Common Files\AOL\System Information\sinf.exe
FirewallRules: [{57969852-6B9E-422E-B61D-96414191AF03}] => (Allow) C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe
FirewallRules: [{30915F87-7117-4739-853A-DEC7D0E7E21E}] => (Allow) C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe
FirewallRules: [{35D40D3A-430E-4702-89F4-6F7AA94E5226}] => (Allow) C:\Program Files (x86)\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{D771DC33-51D7-4A46-98D8-9A519549C5B2}] => (Allow) C:\Program Files (x86)\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{7835419C-0960-418B-8D70-2B0D44F8E1F3}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\waol.exe
FirewallRules: [{5813D3CA-B66F-44BF-AC77-A1264147028C}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\waol.exe
FirewallRules: [{EFEF65F3-EDFE-41D7-BD10-07C7B515BE57}] => (Allow) C:\Program Files (x86)\Common Files\AOL\1356813129\ee\aolsoftware.exe
FirewallRules: [{E3B67B5A-981A-4050-9981-40EAF70EFB0B}] => (Allow) C:\Program Files (x86)\Common Files\AOL\1356813129\ee\aolsoftware.exe
FirewallRules: [{76CBB1F3-68DA-4EEE-9312-BCD48395B1A1}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
FirewallRules: [{8B6C5983-23C6-4F9A-B86B-315874CCF55E}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
FirewallRules: [{CAF94027-B948-40D0-B2DA-9911DF3B57C6}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLDial.exe
FirewallRules: [{067EF64B-B79E-4E0A-85E3-913525CF530C}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLDial.exe
FirewallRules: [{C9BE8101-F480-4219-8D33-18631D9DAC83}] => (Allow) LPort=1900
FirewallRules: [{AC9085FB-C7DC-475E-83BD-2C4D8042D93C}] => (Allow) LPort=2869
FirewallRules: [{8B2EFA22-CB98-4A8F-868A-7808AC8BC521}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{B8732F72-F9D9-4596-8C03-073046CB1499}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{E13E5F9C-E7EB-48DB-BD40-A0E0C9890A29}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{ADC11769-653B-4AC1-8A43-CF7D98CE434B}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{4DABB302-3070-48FA-A239-8D9FB5755AA8}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{8DF1A401-119B-4D12-B731-D8C994E05C25}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{AEA6A349-7612-4EAC-961D-669F5BE63A11}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{439983AA-B322-47B5-A703-CE00E2685F24}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{6A8764C7-0C43-4328-B3D5-1CE6F11F2F67}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/10/2015 10:53:33 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wwahost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: c58
Start Time: 01d0d383f980ccda
Termination Time: 4294967295
Application Path: C:\WINDOWS\syswow64\wwahost.exe
Report Id: ee86ca77-3f77-11e5-bf7c-50b7c33d372b
Faulting package full name: Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c
Faulting package-relative application ID: App
Error: (08/10/2015 10:12:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: EasySettingsCmdServer.exe, version: 0.0.0.0, time stamp: 0x50376629
Faulting module name: MSVCR100.dll, version: 10.0.30319.460, time stamp: 0x4db13576
Exception code: 0x40000015
Fault offset: 0x0008cb95
Faulting process id: 0xe7c
Faulting application start time: 0xEasySettingsCmdServer.exe0
Faulting application path: EasySettingsCmdServer.exe1
Faulting module path: EasySettingsCmdServer.exe2
Report Id: EasySettingsCmdServer.exe3
Faulting package full name: EasySettingsCmdServer.exe4
Faulting package-relative application ID: EasySettingsCmdServer.exe5
Error: (08/09/2015 10:10:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wwahost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 1c54
Start Time: 01d0d319544d5020
Termination Time: 4294967295
Application Path: C:\WINDOWS\syswow64\wwahost.exe
Report Id: 49c8b5c4-3f0d-11e5-bf7c-50b7c33d372b
Faulting package full name: Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c
Faulting package-relative application ID: App
Error: (08/07/2015 09:40:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GWXUX.exe, version: 6.3.9600.17924, time stamp: 0x55959290
Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f4336
Exception code: 0xc0000005
Fault offset: 0x000000000003d85e
Faulting process id: 0x118
Faulting application start time: 0xGWXUX.exe0
Faulting application path: GWXUX.exe1
Faulting module path: GWXUX.exe2
Report Id: GWXUX.exe3
Faulting package full name: GWXUX.exe4
Faulting package-relative application ID: GWXUX.exe5
Error: (08/05/2015 09:39:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f42c2
Exception code: 0xc0000005
Fault offset: 0x00040fb2
Faulting process id: 0x1674
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5
Error: (08/05/2015 09:39:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Exception code: 0xc0000005
Fault offset: 0x001f804f
Faulting process id: 0xa50
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5
Error: (08/05/2015 09:39:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f42c2
Exception code: 0xc0000005
Fault offset: 0x00040fb2
Faulting process id: 0x4f8
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5
Error: (08/05/2015 09:39:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Exception code: 0xc0000005
Fault offset: 0x001f804f
Faulting process id: 0xaf0
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5
Error: (08/05/2015 09:39:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f42c2
Exception code: 0xc0000005
Fault offset: 0x00040fb2
Faulting process id: 0x1550
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5
Error: (08/05/2015 09:38:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Faulting module name: bfgclient.exe, version: 3.3.0.2, time stamp: 0x53179a91
Exception code: 0xc0000005
Fault offset: 0x001f804f
Faulting process id: 0x100
Faulting application start time: 0xbfgclient.exe0
Faulting application path: bfgclient.exe1
Faulting module path: bfgclient.exe2
Report Id: bfgclient.exe3
Faulting package full name: bfgclient.exe4
Faulting package-relative application ID: bfgclient.exe5
System errors:
=============
Error: (08/10/2015 10:23:17 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (08/10/2015 10:02:00 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (08/10/2015 09:25:33 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (08/07/2015 06:33:07 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (08/07/2015 01:48:30 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (08/07/2015 01:10:19 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (08/07/2015 12:19:59 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (08/07/2015 11:01:51 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (08/06/2015 02:53:43 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (08/05/2015 10:21:04 AM) (Source: DCOM) (EventID: 10010) (User: CarlasPC)
Description: App.AppX54xz6wnkhmw763c2y8tb018n7d71dtx7.wwa
Microsoft Office:
=========================
Error: (08/10/2015 10:53:33 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.3.9600.17415c5801d0d383f980ccda4294967295C:\WINDOWS\syswow64\wwahost.exeee86ca77-3f77-11e5-bf7c-50b7c33d372bMicrosoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5cApp
Error: (08/10/2015 10:12:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: EasySettingsCmdServer.exe0.0.0.050376629MSVCR100.dll10.0.30319.4604db13576400000150008cb95e7c01d0cc649553f140C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exeC:\Program Files (x86)\Samsung\Settings\CmdServer\MSVCR100.dll3de8a61b-3f72-11e5-bf7c-50b7c33d372b
Error: (08/09/2015 10:10:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.3.9600.174151c5401d0d319544d50204294967295C:\WINDOWS\syswow64\wwahost.exe49c8b5c4-3f0d-11e5-bf7c-50b7c33d372bMicrosoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5cApp
Error: (08/07/2015 09:40:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: GWXUX.exe6.3.9600.1792455959290ntdll.dll6.3.9600.17736550f4336c0000005000000000003d85e11801d0d1839907d523C:\WINDOWS\System32\GWX\GWXUX.exeC:\WINDOWS\SYSTEM32\ntdll.dlle50049d4-3d76-11e5-bf7c-50b7c33d372b
Error: (08/05/2015 09:39:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91ntdll.dll6.3.9600.17736550f42c2c000000500040fb2167401d0cff11bc4b598C:\Program Files (x86)\bfgclient\bfgclient.exeC:\WINDOWS\SYSTEM32\ntdll.dll5de4d618-3be4-11e5-bf7c-50b7c33d372b
Error: (08/05/2015 09:39:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91bfgclient.exe3.3.0.253179a91c0000005001f804fa5001d0cff11b08b16fC:\Program Files (x86)\bfgclient\bfgclient.exeC:\Program Files (x86)\bfgclient\bfgclient.exe5acf4758-3be4-11e5-bf7c-50b7c33d372b
Error: (08/05/2015 09:39:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91ntdll.dll6.3.9600.17736550f42c2c000000500040fb24f801d0cff11565a917C:\Program Files (x86)\bfgclient\bfgclient.exeC:\WINDOWS\SYSTEM32\ntdll.dll56e43df4-3be4-11e5-bf7c-50b7c33d372b
Error: (08/05/2015 09:39:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91bfgclient.exe3.3.0.253179a91c0000005001f804faf001d0cff11525b30aC:\Program Files (x86)\bfgclient\bfgclient.exeC:\Program Files (x86)\bfgclient\bfgclient.exe534f0929-3be4-11e5-bf7c-50b7c33d372b
Error: (08/05/2015 09:39:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91ntdll.dll6.3.9600.17736550f42c2c000000500040fb2155001d0cff1082a4bfeC:\Program Files (x86)\bfgclient\bfgclient.exeC:\WINDOWS\SYSTEM32\ntdll.dll4eab7873-3be4-11e5-bf7c-50b7c33d372b
Error: (08/05/2015 09:38:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: bfgclient.exe3.3.0.253179a91bfgclient.exe3.3.0.253179a91c0000005001f804f10001d0cff0f98a4e9eC:\Program Files (x86)\bfgclient\bfgclient.exeC:\Program Files (x86)\bfgclient\bfgclient.exe470e6374-3be4-11e5-bf7c-50b7c33d372b
CodeIntegrity:
===================================
Date: 2015-05-12 12:25:00.726
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-12 12:24:59.904
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-12 12:24:56.339
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-09 19:00:37.871
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-09 19:00:36.384
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-05-09 19:00:34.739
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-04-22 22:00:33.049
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-04-22 22:00:32.407
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-04-22 22:00:31.725
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-04-22 22:00:29.965
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) CPU B950 @ 2.10GHz
Percentage of memory in use: 51%
Total physical RAM: 3795.54 MB
Available physical RAM: 1843.25 MB
Total Virtual: 4499.54 MB
Available Virtual: 2198.5 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:439.91 GB) (Free:310.34 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: B0418F27)
Partition: GPT.
==================== End of log ============================
ASWMRB Text file:
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-08-10 09:13:27
—————————–
09:13:27.305 OS Version: Windows x64 6.2.9200
09:13:27.305 Number of processors: 2 586 0x2A07
09:13:27.305 ComputerName: CARLASPC UserName:
09:13:28.493 Initialize success
09:13:28.681 VM: initialized successfully
09:13:28.681 VM: Intel CPU virtualization not supported
09:15:17.909 AVAST engine defs: 15080901
09:26:17.327 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000030
09:26:17.327 Disk 0 Vendor: ST500LM012_HN-M500MBB 2AR10002 Size: 476940MB BusType: 11
09:26:17.897 Disk 0 MBR read successfully
09:26:17.897 Disk 0 MBR scan
09:26:17.913 Disk 0 unknown MBR code
09:26:17.944 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
09:26:18.773 Disk 0 scanning C:\WINDOWS\system32\drivers
09:27:05.119 Service scanning
09:27:50.496 Modules scanning
09:27:50.512 Disk 0 trace - called modules:
09:27:50.543 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll iaStorA.sys
09:27:50.559 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe000679b9370]
09:27:50.574 3 CLASSPNP.SYS[fffff800fb911170] -> nt!IofCallDriver -> \Device\00000030[0xffffe00067205060]
09:27:52.324 AVAST engine scan C:\WINDOWS
09:28:24.685 AVAST engine scan C:\WINDOWS\system32
09:33:52.452 AVAST engine scan C:\WINDOWS\system32\drivers
09:34:33.923 AVAST engine scan C:\Users\carla35758
10:43:52.672 AVAST engine scan C:\ProgramData
11:10:32.752 Disk 0 statistics 4287184/0/0 @ 0.46 MB/s
11:10:32.799 Scan finished successfully
12:22:51.572 Disk 0 MBR has been saved successfully to "C:\Users\carla35758\Desktop\KevinStuff\MBR.dat"
12:22:51.603 The log file has been saved successfully to "C:\Users\carla35758\Desktop\KevinStuff\aswMBR.txt"