This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HP Notebook running painfully slow w random redirects [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello all,

 

I'm working on my Mother's computer as she has said that it is running painfully slow out of the blue, and has random redirects to dead pages.

Here is the aswMBR log:
~

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-11-08 12:21:12
—————————–
12:21:12.513    OS Version: Windows x64 6.2.9200
12:21:12.513    Number of processors: 2 586 0x603
12:21:12.515    ComputerName: HP-PC  UserName: Hp
12:21:16.678    Initialize success
12:21:16.801    VM: initialized successfully
12:21:16.802    VM: Amd CPU BiosDisabled
12:22:50.215    AVAST engine download error: 0
12:23:26.159    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000028
12:23:26.162    Disk 0 Vendor: Hitachi_ PC3O Size: 305245MB BusType: 11
12:23:26.296    Disk 0 MBR read successfully
12:23:26.305    Disk 0 MBR scan
12:23:26.313    Disk 0 unknown MBR code
12:23:26.329    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          199 MB offset 2048
12:23:26.334    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       291062 MB offset 409600
12:23:26.361    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS        13879 MB offset 596504576
12:23:26.381    Disk 0 Partition 4 00     0C    FAT32 LBA MSDOS5.0      103 MB offset 624928768
12:23:26.423    Disk 0 scanning C:\WINDOWS\system32\drivers
12:23:34.977    Service scanning
12:23:35.465    Service 3ware C:\WINDOWS\System32\drivers\3ware.sys **LOCKED** 32
12:23:37.911    Service BdfNdisf C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys **LOCKED** 5
12:23:37.972    Service bdfwfpf C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys **LOCKED** 5
12:23:38.019    Service bdfwfpf_pc C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys **LOCKED** 5
12:24:59.018    Modules scanning
12:24:59.026    Disk 0 trace - called modules:
12:24:59.033   
12:24:59.039    Disk 0 statistics 136416/0/0 @ 8.85 MB/s
12:24:59.045    Scan finished successfully
12:27:02.744    Disk 0 MBR has been saved successfully to "C:\Users\Hp\Desktop\MBR.dat"
12:27:02.750    The log file has been saved successfully to "C:\Users\Hp\Desktop\aswMBR.txt"
 
 
 
 
 
And the FRST:
~
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
Ran by [removed] (administrator) on HP-PC (08-11-2015 12:37:57)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 10 Home (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(CinemaNow, Inc.) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsd.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
 

==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\…\Run: [RtkOSD] => C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe [995840 2010-02-05] (Realtek Semiconductor Corp.)
HKLM\…\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-01-27] (Hewlett-Packard)
HKLM\…\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-07-17] (Synaptics Incorporated)
HKLM\…\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe [1603544 2015-10-01] (Bitdefender)
HKLM-x32\…\Run: [SSDMonitor] => C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2011-12-12] (PC Tools)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-09-22] (Google Inc.)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [SanDiskSecureAccess_Manager.exe] => C:\Users\Hp\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [27311232 2011-06-29] (Gemalto N.V.)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe [790880 2015-06-18] (Bitdefender)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Policies\Explorer: [NoInstrumentation] 1
BootExecute: autocheck autochk * sdnclean64.exe
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{03db8a02-2336-4c54-8b7c-da7fef957d22}: [DhcpNameServer] [removed] [removed]
 
Internet Explorer:
==================
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPNOT/1
SearchScopes: HKLM-x32 -> {3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6} URL = hxxp://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
SearchScopes: HKLM-x32 -> {BF1D2AD1-927A-4C76-9848-9923A9B74AFB} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3538756054-3176117391-120295970-1000 -> {3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6} URL = hxxp://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
SearchScopes: HKU\S-1-5-21-3538756054-3176117391-120295970-1000 -> {BF1D2AD1-927A-4C76-9848-9923A9B74AFB} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox
BHO: Bitdefender Wallet  -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-10-09] (Bitdefender)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-23] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-10-09] (Bitdefender)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-22] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-22] (Oracle Corporation)
Toolbar: HKLM - No Name - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} -  No File
Toolbar: HKLM - Bitdefender Wallet  - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-10-09] (Bitdefender)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-23] (Google Inc.)
Toolbar: HKLM-x32 - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-10-09] (Bitdefender)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-3538756054-3176117391-120295970-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-23] (Google Inc.)
DPF: HKLM-x32 {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-10-19] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-19] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2009-07-21] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-22] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-20] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-20] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2010-07-17] (Sun Microsystems, Inc.)
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-09-29] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\\antispam32\bdwteff
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender 2015\\antispam32\bdwteff [2015-10-09] [not signed]
FF HKLM\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext
FF Extension: Bitdefender Antispam Toolbar - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext [2015-07-28] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\\antispam32\bdwteff
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext
 
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll => No File
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll => No File
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll => No File
CHR Plugin: (RealJukebox NS Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll => No File
CHR Plugin: (RealPlayer Version Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll => No File
CHR Profile: C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-26]
CHR Extension: (Google Drive) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-29]
CHR Extension: (YouTube) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-26]
CHR Extension: (Google Search) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-26]
CHR Extension: (Google Docs Offline) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-29]
CHR Extension: (Gmail) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-26]
CHR HKLM-x32\…\Chrome\Extension: [fabcmochhfpldjekobfaaggijgohadih] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2015\bdparentalservice.exe [78144 2015-07-24] (Bitdefender)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R2 HPWMISVC; C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [19968 2010-01-12] () [File not signed]
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-02-22] (Hewlett-Packard Company) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-07-31] (Microsoft Corporation)
R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2011-12-12] (PC Tools)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [303360 2015-06-24] (Realtek Semiconductor)
R2 RtVOsdService; C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe [315392 2010-06-24] (Realtek Semiconductor Corp.) [File not signed]
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-07-17] (Synaptics Incorporated)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2015-04-22] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe [1537648 2015-10-01] (Bitdefender)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-07-31] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-07-31] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1369288 2015-05-28] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [271272 2015-05-29] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [747120 2015-05-28] (BitDefender)
U5 bdelam; C:\Windows\System32\Drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2014-12-15] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [115800 2015-05-21] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
R1 BDVEDISK; C:\Windows\system32\DRIVERS\bdvedisk.sys [79192 2013-07-30] (BitDefender)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [160032 2015-10-01] (BitDefender LLC)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2015-11-08] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-07-31] (Microsoft Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek                                            )
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [477272 2015-10-01] (BitDefender S.R.L.)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 aswMBR; C:\Users\Hp\AppData\Local\Temp\aswMBR.sys [62728 2015-11-08] () [File not signed]
U3 aswVmm; C:\Users\Hp\AppData\Local\Temp\aswVmm.sys [224896 2015-11-08] ()
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 

==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-11-08 12:37 - 2015-11-08 12:38 - 00023802 _____ C:\Users\Hp\Desktop\FRST.txt
2015-11-08 12:36 - 2015-11-08 12:38 - 00000000 ____D C:\FRST
2015-11-08 12:33 - 2015-11-08 12:35 - 02198528 _____ (Farbar) C:\Users\Hp\Desktop\FRST64.exe
2015-11-08 12:27 - 2015-11-08 12:27 - 00002032 _____ C:\Users\Hp\Desktop\aswMBR.txt
2015-11-08 12:27 - 2015-11-08 12:27 - 00000512 _____ C:\Users\Hp\Desktop\MBR.dat
2015-11-08 12:18 - 2015-11-08 12:20 - 05198336 _____ (AVAST Software) C:\Users\Hp\Desktop\aswMBR.exe
2015-11-08 11:59 - 2015-11-08 11:59 - 00016148 _____ C:\WINDOWS\system32\HP-PC_Hp_HistoryPrediction.bin
2015-11-08 06:48 - 2015-11-08 06:48 - 00002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-11-04 12:51 - 2015-11-04 12:51 - 00000000 ____D C:\Users\Hp\AppData\Local\CEF
2015-11-04 12:47 - 2015-11-04 12:47 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-11-04 12:46 - 2015-11-04 12:46 - 00002132 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-11-03 16:44 - 2015-11-03 16:45 - 00002360 _____ C:\Users\Hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-10-31 19:00 - 2015-10-31 19:00 - 00000000 ____D C:\Users\Hp\Documents\gmoney disk
2015-10-31 18:40 - 2015-10-31 18:40 - 00063488 _____ C:\Users\Hp\Documents\PAYLIST ANNA CURRENT thumb 11 2015.xls
2015-10-30 13:37 - 2015-10-30 13:37 - 00022738 _____ C:\Users\Hp\Downloads\AZ ASG 9-2015.xlsx
2015-10-30 10:30 - 2015-10-27 16:38 - 21871616 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-30 10:29 - 2015-10-27 16:16 - 18801664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-30 10:29 - 2015-10-21 05:45 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-10-30 10:29 - 2015-10-21 05:44 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-10-30 10:29 - 2015-10-21 05:43 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-30 10:29 - 2015-10-21 05:39 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-10-30 10:29 - 2015-10-21 05:00 - 24595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-30 10:29 - 2015-10-21 05:00 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-30 10:29 - 2015-10-21 04:59 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2015-10-30 10:29 - 2015-10-21 04:57 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-30 10:29 - 2015-10-21 04:52 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-30 10:29 - 2015-10-21 04:50 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-10-30 10:29 - 2015-10-21 04:48 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-30 10:29 - 2015-10-21 04:47 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-10-30 10:29 - 2015-10-21 04:46 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-30 10:29 - 2015-10-21 04:46 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-10-30 10:29 - 2015-10-21 04:44 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-10-30 10:29 - 2015-10-21 04:44 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-30 10:29 - 2015-10-21 04:43 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2015-10-30 10:29 - 2015-10-21 04:42 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-30 10:29 - 2015-10-21 04:41 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-30 10:29 - 2015-10-21 04:40 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2015-10-30 10:29 - 2015-10-21 04:38 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-10-30 10:29 - 2015-10-20 22:53 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-30 10:29 - 2015-10-20 22:49 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-10-30 10:29 - 2015-10-20 22:13 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-30 10:29 - 2015-10-20 22:11 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-30 10:29 - 2015-10-20 22:08 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-30 10:29 - 2015-10-20 22:05 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-30 10:29 - 2015-10-20 22:03 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-10-30 10:29 - 2015-10-20 22:03 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-10-30 10:29 - 2015-10-20 21:58 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2015-10-30 10:29 - 2015-10-20 21:58 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-30 10:29 - 2015-10-20 21:55 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-10-28 14:11 - 2015-10-28 14:11 - 00069632 _____ C:\Users\Hp\Downloads\PrintExportedReport.xls
2015-10-28 14:10 - 2015-10-28 14:10 - 00043520 _____ C:\Users\Hp\Downloads\crt.xls
2015-10-22 11:11 - 2015-10-15 20:10 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-22 11:11 - 2015-10-15 20:10 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-22 10:39 - 2015-10-22 10:38 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-10-19 19:00 - 2015-10-19 19:02 - 00060540 _____ C:\WINDOWS\SysWOW64\AppLog.log
2015-10-19 19:00 - 2015-10-19 19:00 - 00000000 ____D C:\WINDOWS\PCHEALTH
2015-10-19 13:53 - 2015-10-19 13:53 - 00001187 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-10-19 13:53 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-10-19 13:53 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-10-19 13:53 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-10-19 12:18 - 2015-10-10 00:12 - 00078528 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-19 12:18 - 2015-10-05 20:03 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-19 12:18 - 2015-10-05 19:46 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-19 12:18 - 2015-09-30 21:01 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-10-19 12:18 - 2015-09-30 21:01 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-10-19 12:18 - 2015-09-30 21:01 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-10-19 12:18 - 2015-09-30 21:01 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-10-19 12:18 - 2015-09-30 21:00 - 08020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-19 12:18 - 2015-09-30 20:03 - 00757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2015-10-19 12:18 - 2015-09-24 21:01 - 02573768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-10-19 12:18 - 2015-09-24 21:01 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-10-19 12:18 - 2015-09-24 20:56 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-10-19 12:18 - 2015-09-24 20:52 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-10-19 12:18 - 2015-09-24 20:33 - 01997336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-10-19 12:18 - 2015-09-24 20:26 - 20858360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-10-19 12:18 - 2015-09-24 20:11 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-19 12:18 - 2015-09-24 20:11 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-19 12:18 - 2015-09-24 20:09 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-10-19 12:18 - 2015-09-24 20:07 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-19 12:18 - 2015-09-24 20:04 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-10-19 12:18 - 2015-09-24 20:04 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-19 12:18 - 2015-09-24 20:03 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-19 12:18 - 2015-09-24 20:03 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-10-19 12:18 - 2015-09-24 20:02 - 07523840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-19 12:18 - 2015-09-24 20:02 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-10-19 12:18 - 2015-09-24 20:02 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-19 12:18 - 2015-09-24 20:01 - 04792320 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-19 12:18 - 2015-09-24 20:01 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-19 12:18 - 2015-09-24 20:00 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-19 12:18 - 2015-09-24 20:00 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-19 12:18 - 2015-09-24 20:00 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-19 12:18 - 2015-09-24 20:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-19 12:18 - 2015-09-24 19:58 - 01871360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-10-19 12:18 - 2015-09-24 19:47 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-19 12:18 - 2015-09-24 19:47 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 03580416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-10-19 12:18 - 2015-09-24 19:37 - 00766976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-10-19 12:18 - 2015-09-24 19:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-19 12:18 - 2015-09-24 19:37 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-19 12:18 - 2015-09-24 19:36 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-10-19 12:18 - 2015-09-24 19:36 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-19 12:18 - 2015-09-24 19:33 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-19 12:18 - 2015-09-24 19:32 - 01594368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-10-19 12:18 - 2015-09-24 19:32 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-11-08 12:29 - 2013-04-26 13:25 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-11-08 12:20 - 2010-09-12 15:18 - 00004140 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7D1B5BD6-72C8-4707-9A38-50B0F4CB0C8B}
2015-11-08 12:18 - 2015-07-10 05:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-08 12:13 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-11-08 11:59 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-11-08 11:55 - 2015-01-14 20:18 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-08 06:50 - 2015-09-20 14:45 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-08 06:34 - 2015-09-20 14:45 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cf52901f22c608.job
2015-11-07 14:32 - 2015-07-31 15:29 - 01018274 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-06 13:25 - 2010-03-30 05:37 - 00000000 ____D C:\ProgramData\Temp
2015-11-04 13:03 - 2015-07-31 15:31 - 00000000 ____D C:\Users\Hp
2015-11-04 12:51 - 2014-07-05 08:56 - 00000000 ____D C:\Users\Hp\AppData\Local\Adobe
2015-11-04 12:46 - 2011-09-22 15:31 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-11-04 12:46 - 2010-03-30 05:59 - 00000000 ____D C:\ProgramData\Adobe
2015-11-04 09:49 - 2015-07-10 02:05 - 00065536 ___SH C:\WINDOWS\system32\config\ELAM
2015-11-04 09:48 - 2015-07-10 05:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-04 08:42 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\rescache
2015-11-04 07:06 - 2010-03-30 05:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-04 07:04 - 2013-09-16 13:30 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-11-04 06:48 - 2010-09-12 15:30 - 143481208 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-11-03 16:45 - 2015-07-31 16:12 - 00000000 ___RD C:\Users\Hp\OneDrive
2015-10-31 20:45 - 2015-08-09 14:47 - 00000000 ____D C:\WINDOWS\Minidump
2015-10-31 17:53 - 2015-07-10 02:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-10-31 16:19 - 2015-07-10 05:20 - 00028872 _____ C:\WINDOWS\setupact.log
2015-10-31 16:14 - 2011-09-22 15:33 - 00000000 ____D C:\Users\Hp\AppData\Local\Google
2015-10-31 16:06 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-31 03:32 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-30 10:36 - 2015-07-10 03:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-29 16:03 - 2012-08-18 15:20 - 00000000 ____D C:\Users\Hp\Documents\Anna
2015-10-23 19:53 - 2013-04-26 13:26 - 00002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-10-22 10:39 - 2014-11-16 07:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-10-22 10:39 - 2013-09-16 13:55 - 00000000 ____D C:\ProgramData\Oracle
2015-10-22 10:38 - 2015-08-28 06:33 - 00000000 ____D C:\Users\Hp\.oracle_jre_usage
2015-10-22 10:37 - 2014-11-16 07:00 - 00000000 ____D C:\Program Files (x86)\Java
2015-10-21 06:33 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-10-21 03:36 - 2010-09-13 09:08 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-10-21 03:34 - 2015-07-10 05:20 - 04963392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-10-21 03:33 - 2015-01-14 20:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-19 13:53 - 2015-01-14 20:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-10-09 09:15 - 2015-07-31 15:23 - 00062052 _____ C:\WINDOWS\PFRO.log
 
==================== Files in the root of some directories =======
 
2013-02-19 00:02 - 2013-02-19 00:02 - 4126720 _____ () C:\Program Files (x86)\GUT40AE.tmp
2014-08-13 01:49 - 2014-08-13 01:49 - 130565325 _____ () C:\Program Files (x86)\openoffice1.cab
2014-08-13 01:48 - 2014-08-13 01:48 - 2310144 _____ () C:\Program Files (x86)\openoffice411.msi
2014-08-13 01:48 - 2014-08-13 01:48 - 0478720 _____ () C:\Program Files (x86)\setup.exe
2014-08-13 01:48 - 2014-08-13 01:48 - 0000279 _____ () C:\Program Files (x86)\setup.ini
2012-03-08 14:18 - 2012-03-08 14:45 - 0000640 _____ () C:\Users\Hp\AppData\Roaming\.backup.dm
2010-09-16 08:23 - 2010-09-16 08:23 - 0000025 _____ () C:\Users\Hp\AppData\Roaming\bdfvconp.ini
2011-02-15 12:36 - 2011-05-17 17:51 - 0001854 _____ () C:\Users\Hp\AppData\Roaming\GhostObjGAFix.xml
2012-08-18 15:13 - 2014-01-16 08:47 - 0002035 _____ () C:\Users\Hp\AppData\Roaming\SAS7_000.DAT
2010-09-20 22:41 - 2015-08-15 15:17 - 0001584 _____ () C:\Users\Hp\AppData\Roaming\wklnhst.dat
2013-06-20 14:25 - 2013-06-20 14:25 - 0003584 _____ () C:\Users\Hp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-30 06:27 - 2015-03-12 06:47 - 0007597 _____ () C:\Users\Hp\AppData\Local\Resmon.ResmonCfg
2015-08-05 16:43 - 2015-08-05 16:43 - 0515580 _____ () C:\ProgramData\1438817797.bdinstall.bin
2011-12-01 12:46 - 2011-12-01 12:46 - 0000057 _____ () C:\ProgramData\Ament.ini
2010-09-13 09:10 - 2010-09-13 09:10 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2010-03-30 06:29 - 2010-03-30 06:29 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2010-03-30 06:21 - 2010-03-30 06:23 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2010-06-20 01:40 - 2010-06-20 01:40 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2010-03-30 06:21 - 2010-03-30 06:21 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2010-03-30 06:23 - 2010-03-30 06:28 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2010-06-20 01:42 - 2010-06-20 01:42 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 

LastRegBack: 2015-10-31 03:46
 
==================== End of FRST.txt ============================
​
 
 
 
And Addition:
~
Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by [removed] (2015-11-08 12:41:05)
Running from C:\Users\[removed]\Desktop
Windows 10 Home (X64) (2015-07-31 23:04:55)
Boot Mode: Normal
==========================================================
 

==================== Accounts: =============================
 
Administrator (S-1-5-21-3538756054-3176117391-120295970-500 - Administrator - Disabled)
ASPNET (S-1-5-21-3538756054-3176117391-120295970-1002 - Limited - Enabled)
BitDefenderComm (S-1-5-21-3538756054-3176117391-120295970-1005 - Limited - Enabled)
DefaultAccount (S-1-5-21-3538756054-3176117391-120295970-503 - Limited - Disabled)
Guest (S-1-5-21-3538756054-3176117391-120295970-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3538756054-3176117391-120295970-1004 - Limited - Enabled)
Hp (S-1-5-21-3538756054-3176117391-120295970-1000 - Administrator - Enabled) => C:\Users\Hp
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Bitdefender Antivirus (Enabled - Up to date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antispyware (Enabled - Up to date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20077 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 19.0.0.190 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.)
Adobe Flash Player 19 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Shockwave Player (HKLM-x32\…\{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}) (Version: 11.5.1.601 - Adobe Systems, Inc.)
ATI Catalyst Install Manager (HKLM\…\{C3F0426C-175D-39B7-7A14-D6B21952DE5E}) (Version: 3.0.765.0 - ATI Technologies, Inc.)
Bitdefender Total Security 2015 (HKLM\…\Bitdefender) (Version: 19.2.0.142 - Bitdefender)
Broadcom 802.11 Wireless LAN Adapter (HKLM\…\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.350.6 - Broadcom Corporation)
ccc-core-static (x32 Version: 2010.0310.1824.32984 - ATI) Hidden
CinemaNow Media Manager (HKLM-x32\…\{6C122441-1861-4CD7-B1C5-A163A6984E12}) (Version: 1.9.1.105 - CinemaNow, Inc.)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CyberLink DVD Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.2527 - CyberLink Corp.)
CyberLink MediaShow (HKLM-x32\…\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1307 - CyberLink Corp.)
CyberLink PowerDVD 9 (HKLM-x32\…\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.1.3810 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2511 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
ESU for Microsoft Windows 7 (HKLM-x32\…\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)
Gmail Notifier (HKLM-x32\…\Gmail Notifier) (Version:  - )
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 46.0.2490.80 - Google Inc.)
Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6904.2028 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
HP Advisor (HKLM-x32\…\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.4.10262.3295 - Hewlett-Packard)
HP MediaSmart CinemaNow 2.0 (HKLM-x32\…\{9008D736-35CA-40DB-A2BE-5F32D954E5AA}) (Version: 2.0 - Hewlett-Packard)
HP Power Plan Utility (HKLM-x32\…\{F6B6A150-08FA-46D5-808A-EB638269551D}) (Version: 1.0.6 - Hewlett-Packard)
HP Quick Launch (HKLM\…\{6A66C1E5-4146-4CA6-A551-627CFCEACC83}) (Version: 1.0.17 - Hewlett-Packard)
HP Setup (HKLM-x32\…\{E2831862-F131-4327-B9CC-FA30F587EB6C}) (Version: 1.2.3988.3281 - Hewlett-Packard)
HP Software Framework (HKLM-x32\…\{6C872198-9ED1-4046-87B3-AFA79CDF342D}) (Version: 4.0.55.1 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP User Guides 0199 (HKLM-x32\…\{E39CFDC9-F521-4D9C-974B-17E93696FCAB}) (Version: 1.01.0000 - Hewlett-Packard)
HP Wireless Assistant (HKLM\…\{E6BC696E-5E96-4C1B-9371-379AF3A46B6B}) (Version: 4.0.4.2 - Hewlett-Packard)
Java 8 Update 65 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2515 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.2515 - CyberLink Corp.) Hidden
LAME v3.98.3 for Audacity (HKLM-x32\…\LAME for Audacity_is1) (Version:  - )
LightScribe System Software (HKLM-x32\…\{6AFDE3BE-BC01-45A4-9D06-BBF5AD207313}) (Version: 1.18.12.1 - LightScribe)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 1.1 (HKLM-x32\…\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft IntelliPoint 8.2 (HKLM\…\Microsoft IntelliPoint 8.2) (Version: 8.20.468.0 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft Office XP Professional (HKLM-x32\…\{91110409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\…\{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Publisher 2010 (HKLM-x32\…\Office14.PUBLISHERR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\…\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\…\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
NOOK for PC (HKLM-x32\…\BN_DesktopReader) (Version: 2.5.6.9575 - Barnesandnoble.com)
OLYMPUS Master 2 (HKLM-x32\…\{3A1AB8E6-748E-4B95-AA2D-FE9952EB3106}) (Version: 1.0.13 - OLYMPUS IMAGING CORP.)
OneClickdigital Media Manager (HKLM-x32\…\{C259BBE2-2531-4387-B5E3-9E6845854272}) (Version: 61.0.0.0 - Recorded Books)
OpenOffice 4.1.1 (HKLM-x32\…\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
PC Tools Registry Mechanic 11.0 (HKLM-x32\…\Registry Mechanic_is1) (Version: 11.0 - PC Tools)
PhotoNow! (HKLM-x32\…\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.6904 - CyberLink Corp.)
PhotoNow! (x32 Version: 1.1.6904 - CyberLink Corp.) Hidden
Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3715 - CyberLink Corp.)
Power2Go (x32 Version: 6.1.3715 - CyberLink Corp.) Hidden
PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.2514 - CyberLink Corp.)
PowerDirector (x32 Version: 8.0.2514 - CyberLink Corp.) Hidden
Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.18.322.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30120 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 5.5.2512 - CyberLink Corp.) Hidden
RtVOsd (HKLM\…\{091A0130-A82F-4A6D-9C61-3BBBB3289030}) (Version: 1.0.6 - Realtek Semiconductor Corp.)
SanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19269 - Gemalto N.V.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-0019-0000-0000-0000000FF1CE}_Office14.PUBLISHERR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)
Skype™ 7.6 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
Sockupied Spring 2012 (HKLM-x32\…\com.interweave.sockupiedspring2012) (Version: 1.0 - Interweave)
Sockupied Spring 2012 (x32 Version: 1.0 - Interweave) Hidden
Sockupied Spring 2014 (HKLM-x32\…\com.interweave.sockupiedspring2014) (Version: 1.0.0 - F+W Media, Inc.)
Sockupied Spring 2014 (x32 Version: 1.0.0 - F+W Media, Inc.) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 19.0.12.95 - Synaptics Incorporated)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM-x32\…\Windows Media Encoder 9) (Version:  - )
Zinio Reader 4 (HKLM-x32\…\ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1) (Version: 4.2.3972 - Zinio LLC)
Zinio Reader 4 (x32 Version: 4.2.3972 - Zinio LLC) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3538756054-3176117391-120295970-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Hp\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation)
 
==================== Restore Points =========================
 
19-10-2015 14:41:29 Scheduled Checkpoint
28-10-2015 07:14:18 Scheduled Checkpoint
31-10-2015 16:32:58 Windows Update
04-11-2015 06:43:24 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-08-05 12:24 - 2015-08-05 12:24 - 00450771 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com
 
There are 15463 more lines.
 

==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {00D37CBD-1363-420A-A9A9-F81EAD3D5369} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-19] (Adobe Systems Incorporated)
Task: {04617C3D-0AA2-4430-818E-8CB903756659} - System32\Tasks\Bitdefender Autoscan => C:\Program Files\Bitdefender\Bitdefender 2013\mtasklaunch.exe
Task: {08F4E36D-9C0C-4CDB-BEA4-0CFDFE55029A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {097C0CAD-A452-4FCA-9EC2-8A1243120586} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {0A8B30C4-99B0-4223-896F-672BD136A109} - System32\Tasks\GoogleUpdateTaskMachineCore1cf52901f22c608 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {0BC18D7C-7A5F-4F0F-A668-DC27642550D6} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {0C267C17-A827-43D9-8CC7-FF88821A2146} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {1287B6D6-B819-48D5-AC88-63D9BF8ABF2D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {189BAE74-F6A0-4910-8D49-5729E8CDED8C} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2DFE12DF-A440-42E9-BC40-2F3F9F5DC28D} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {329EC941-3C94-4072-9691-499DD8E81B3E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {3A140220-8F1E-4E55-8832-B538A52128C1} - System32\Tasks\RMSchedule => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\RegMech.exe [2011-12-12] (PC Tools)
Task: {3D30200F-62B2-4387-8C19-A1B9F1B7D1FC} - System32\Tasks\{44A07CDE-287C-4CE7-97A6-8D22D5215342} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-06-29] (Skype Technologies S.A.)
Task: {3FA86DFB-9864-4979-8C47-3249817D201A} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {4D9F29A1-3231-42E5-B5DF-2F490B362A84} - System32\Tasks\{10BF4766-87F1-4948-AA9D-E4D3D1246EBC} => pcalua.exe -a "C:\Program Files (x86)\OpenOffice.org 3\program\sbase.exe" -d C:\Users\Hp\Documents -c -o "C:\Users\Hp\Documents\Contacts.odb"
Task: {4DDFD1B4-1BFE-4955-9128-EA1C9ED805FF} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {549707FA-A06E-4A13-906B-8BE9FC6E9612} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {5AB2BA6D-C059-4903-8AB8-746B6AA9CA3D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-11-04] (Microsoft Corporation)
Task: {5D468FCA-DFD8-492A-8DDA-533809CF4733} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-08-01] (Microsoft Corporation)
Task: {5D986A82-8659-415E-9C81-5327FB5E4AB9} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {5ED71F25-5E1C-4143-BF72-E119EFA076F9} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {605C087D-0CBA-43D2-B8BC-0DA55E7A8027} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {615F219E-46E9-493A-BE51-43EC9D653E0A} - System32\Tasks\AdobeAAMUpdater-1.0-Hp-PC-Hp => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)
Task: {63F3307B-B920-4508-875F-8DCA42BD54B7} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {6640D516-7877-4E45-BA3F-AA58C73A4FC4} - System32\Tasks\{5087E47C-F4B1-48F2-9D2B-9C7C89061E13} => Iexplore.exe hxxp://ui.skype.com/ui/0/4.1.0.179.271/en/go/help.faq.installer?LastError=1603
Task: {6DAE4147-3132-4B73-AD2A-C543E24DE489} - System32\Tasks\Hewlett-Packard\HP Assistant\HPSA Upgrade => C:\ProgramData\Hewlett-Packard\HPSAUpgrade3\HpSAUpgrade.exe [2011-08-11] (Hewlett-Packard)
Task: {7ED995AB-9353-4D10-9444-8807A11EF13C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {7F6E3D4B-5AFE-4F79-8190-66D15887BEA9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7FDAF8EC-25A4-4509-AACC-D9D27A2A0DAD} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {8C5B60D3-EC95-474B-BC98-5D0895148305} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
Task: {8CB959D3-FAC3-4FC8-8E90-3A1950FB5843} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {990FC820-7C11-4FC8-8626-1C4084ACE5E2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {9D588900-F5E1-41E3-A948-E789C8634327} - System32\Tasks\RMSmartUpdate => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\update.exe [2011-12-12] (PC Tools)
Task: {A213B09B-F624-4C98-B88F-EEBF8BCCA9C3} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {A7368EBD-48F3-4229-999C-109C8602B510} - System32\Tasks\{71C771B6-2EF4-45F3-ACC0-E269B17A5C28} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=4.2.0.187&LastError;=12002
Task: {AA9297E2-887B-4FC6-8777-20000628C6F0} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {AB4A22BA-A58C-4A61-9F99-B581C8B2946A} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {AC3188EF-AD3F-49FE-A907-01EDD4CC941C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {ADA75388-0E9A-463F-ACA4-4ADFBBD55161} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {B810FC5B-74CC-4C29-9F01-B9C0BCAE29B7} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {BE312CE1-03B9-4201-88EB-BAD1C0477C29} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-01-26] ()
Task: {BFD22CE4-E344-452D-8B78-41DC17A7E8F2} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {C55B1ADB-4F73-4F03-86F8-F25D1086E757} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {C5A51B9E-18D1-49AA-BCE3-383952A2BAB2} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
Task: {CA3E495B-2732-49BA-99C1-2B74D00C270A} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {CD385B27-CFED-4827-92F0-DC3161BB82DE} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
Task: {CDBCA0F0-B023-46EE-89AC-722E9C68D8F6} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {CE39CBD4-2EE6-429C-9DA2-C494D4CBFB94} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {D3368AB9-4EBB-47B6-B0BA-5781C8D9E410} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {DD340FA2-5315-471B-A13E-9A7C2260AFF2} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DD7600F1-B407-4CCF-A569-B33F2CF06CFF} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {DFA008D2-2B42-4D18-9512-3A96F613B1ED} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {E3860717-FB64-4F1F-B494-8CD9E507D4A3} - System32\Tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8 => C:\Program Files\Bitdefender\Bitdefender 2013\bdproductdata.exe
Task: {E8EB2E3F-133B-4A4E-878A-6983871914D5} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {EE72A342-9164-4832-BD39-615121A416F9} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {F07DB3B7-29BE-4ABA-B956-9C166A778312} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {F15293F1-93B5-4747-A456-DD3DC9D7FDA0} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {F6BA051A-6EF4-45A0-BD0B-579BFA5D11CA} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {F8DC7850-A388-4030-8294-13375FE870CE} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {FB000530-0412-49F2-84CD-6F96E45EA85F} - System32\Tasks\ScanToPCActivationApp.exe_{43A47EB1-B846-4B57-B6B4-5CE877A449A2} => C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cf52901f22c608.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\RMSchedule.job => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\RegMech.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-07-31 16:14 - 2015-07-31 16:14 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-08-05 16:41 - 2015-04-22 16:55 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\txmlutil.dll
2015-08-05 16:41 - 2013-09-03 14:29 - 00101328 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdmetrics.dll
2015-08-05 16:41 - 2015-07-28 19:06 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\UI\accessl.ui
2015-08-05 16:41 - 2012-10-29 14:22 - 00152816 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdfwcore.dll
2015-09-05 14:33 - 2015-09-05 14:33 - 00875352 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttpbr.mdl
2015-09-05 14:33 - 2015-09-05 14:33 - 00741952 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttpdsp.mdl
2015-09-05 14:33 - 2015-09-05 14:33 - 02800952 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttpph.mdl
2015-09-05 14:33 - 2015-09-05 14:33 - 01413024 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttprbl.mdl
2015-08-19 09:07 - 2015-08-11 02:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2010-01-12 15:44 - 2010-01-12 15:44 - 00019968 _____ () C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
2010-01-27 14:01 - 2010-01-27 14:01 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll
2015-09-30 16:08 - 2015-09-16 23:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2010-01-27 14:01 - 2010-01-27 14:01 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll
2010-01-27 14:01 - 2010-01-27 14:01 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll
2015-09-30 16:08 - 2015-09-16 23:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-09-30 16:08 - 2015-09-16 22:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-09-30 16:09 - 2015-09-16 22:44 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-09-30 16:08 - 2015-09-16 22:42 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-09-30 16:08 - 2015-09-16 22:42 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-09-30 16:08 - 2015-09-16 22:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 04:00 - 2015-07-10 06:14 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\Temp:0FF263E8
AlternateDataStreams: C:\ProgramData\Temp:5C321E34
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
AlternateDataStreams: C:\Users\Hp\Downloads\bitdefender_tsecurity (1).exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\GoogleEarthSetup.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\Lame_v3.98.3_for_Audacity_on_Windows.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\Microsoft_Publisher_2010_2_PC_1_User_Downloader.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\OneClickdigital Media Manager Installer.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\rminstall.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\spybotsd162.exe:BDU
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 

==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 

==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\1-2005-search.com -> www.1-2005-search.com
 
There are 12683 more sites.
 

==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Hp\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnkCommon Startup
MSCONFIG\startupfolder: C:^Users^Hp^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk => C:\Windows\pss\OpenOffice.org 3.2.lnkStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher =>
MSCONFIG\startupreg: HP Quick Launch => C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: HPAdvisorDock => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
MSCONFIG\startupreg: LightScribe Control Panel => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
MSCONFIG\startupreg: OM2_Monitor => "C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
MSCONFIG\startupreg: SunJavaUpdateSched =>
MSCONFIG\startupreg: TkBellExe =>
HKLM\…\StartupApproved\Run: => "IntelliPoint"
HKLM\…\StartupApproved\Run32: => "SSDMonitor"
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\StartupApproved\Run: => "SpybotPostWindows10UpgradeReInstall"
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\StartupApproved\Run: => "SanDiskSecureAccess_Manager.exe"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{5C670AB1-8442-4DF8-B0DF-30EE69F856DA}] => (Allow) LPort=1900
FirewallRules: [{959ADFA3-811A-4A57-BB5B-7747B726D55B}] => (Allow) LPort=2869
FirewallRules: [{1051274C-8BC4-4E18-852D-EEFE0436F0E1}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{8409542A-67FC-4DDE-8960-B5708BA132D9}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{8BAD2BB1-072F-40FC-A936-C7053AC269EE}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD9.EXE
FirewallRules: [{6BBBAE71-A4C5-4E0D-97C5-B3BA12DF8F5D}] => (Allow) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe
FirewallRules: [{3953E48E-2CAD-4ACB-91A1-9F2718A3038D}] => (Allow) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe
FirewallRules: [{112E6941-3815-4FF7-8BD9-385548D1A39A}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\MediaSmart\CinemaNow\CinemaNow.exe
FirewallRules: [{A5CCD263-2F9D-4620-A201-4A20A02604CF}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\MediaSmart\CinemaNow\CinemaNow.exe
FirewallRules: [{DA5D497C-27F9-41C0-87AA-D8D68B083CF6}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE
FirewallRules: [{D46F22B5-0E6E-44E5-AF05-D3E4237578A0}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{E80BF42B-A1DD-44CE-8476-610F88E20459}] => (Allow) svchost.exe
FirewallRules: [{A0066F71-6931-4B67-86F3-D362380B3497}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [TCP Query User{407D1FDC-0F11-4AB1-924A-CF8B47E7DA60}C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe] => (Block) C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe
FirewallRules: [UDP Query User{35B25721-3AD1-4C8D-98B6-8C1E1C24EC85}C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe] => (Block) C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe
FirewallRules: [TCP Query User{A7984981-4F39-4AF6-AB7F-21988A15F0A6}C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe] => (Allow) C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe
FirewallRules: [UDP Query User{497A74C2-93CF-4A4D-9BE5-74EEDD14C1D9}C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe] => (Allow) C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe
FirewallRules: [{4CC6C5EC-231F-4226-8D97-BC6FCF42B5AD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 

==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/08/2015 12:18:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.10240.16431 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 3320
 
Start Time: 01d11a2a23a7f3ff
 
Termination Time: 0
 
Application Path: C:\Windows\explorer.exe
 
Report Id: 67e6b561-864d-11e5-9bdc-c80aa9cb513a
 
Faulting package full name:
 
Faulting package-relative application ID:
 
Error: (11/08/2015 11:55:23 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Hp-PC)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147024865 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (11/08/2015 07:31:51 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Hp-PC)
Description: Activation of app Microsoft.LockApp_cw5n1h2txyewy!WindowsDefaultLockScreen failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (11/08/2015 07:31:51 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LockApp.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 3b74
 
Start Time: 01d11a32234036e1
 
Termination Time: 4294967295
 
Application Path: C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
 
Report Id: 71e5092c-8625-11e5-9bdc-c80aa9cb513a
 
Faulting package full name: Microsoft.LockApp_10.0.10240.16384_neutral__cw5n1h2txyewy
 
Faulting package-relative application ID: WindowsDefaultLockScreen
 
Error: (11/08/2015 07:31:37 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: Hp-PC)
Description: App Microsoft.LockApp_10.0.10240.16384_neutral__cw5n1h2txyewy+WindowsDefaultLockScreen did not launch within its allotted time.
 
Error: (11/08/2015 06:47:00 AM) (Source: MsiInstaller) (EventID: 1023) (User: Hp-PC)
Description: Product: Adobe Acrobat Reader DC - Update '{AC76BA86-7AD7-0000-2550-AC0F094E6D00}' could not be installed. Error code 1625. Additional information is available in the log file C:\Users\Hp\AppData\Local\Temp\MSI35b56.LOG.
 
Error: (11/08/2015 06:39:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program ShellExperienceHost.exe version 10.0.10240.16515 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 3b8c
 
Start Time: 01d11a2a2b405196
 
Termination Time: 4294967295
 
Application Path: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
 
Report Id: 2d33a0c3-861e-11e5-9bdc-c80aa9cb513a
 
Faulting package full name: Microsoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy
 
Faulting package-relative application ID: App
 
Error: (11/08/2015 06:39:37 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Hp-PC)
Description: Package Microsoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy+App was terminated because it took too long to suspend.
 
Error: (11/08/2015 06:34:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: atibtmon.exe, version: 2.0.0.0, time stamp: 0x4a04ab6c
Faulting module name: atibtmon.exe, version: 2.0.0.0, time stamp: 0x4a04ab6c
Exception code: 0x40000015
Fault offset: 0x000081c5
Faulting process id: 0x2688
Faulting application start time: 0xatibtmon.exe0
Faulting application path: atibtmon.exe1
Faulting module path: atibtmon.exe2
Report Id: atibtmon.exe3
Faulting package full name: atibtmon.exe4
Faulting package-relative application ID: atibtmon.exe5
 
Error: (11/07/2015 03:01:12 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SearchUI.exe version 10.0.10240.16515 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 305c
 
Start Time: 01d119a7785007db
 
Termination Time: 4294967295
 
Application Path: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
 
Report Id: 0a6b29ec-859b-11e5-9bdc-c80aa9cb513a
 
Faulting package full name: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy
 
Faulting package-relative application ID: CortanaUI
 

System errors:
=============
Error: (11/08/2015 11:55:23 AM) (Source: DCOM) (EventID: 10001) (User: Hp-PC)
Description: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXwmnqm0nvq2b90pwvr42qmtdjp7cj3w82.mca31App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mcaUnavailableUnavailable
 
Error: (11/08/2015 07:36:11 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
 
Error: (11/08/2015 06:47:31 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AdobeARMservice service.
 
Error: (11/07/2015 03:45:53 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_Session3 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (11/07/2015 03:45:53 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_Session3 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (11/07/2015 03:45:53 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_Session3 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (11/07/2015 03:45:53 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_Session3 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (11/07/2015 02:31:00 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the BITS service.
 
Error: (11/06/2015 01:52:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_Session2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (11/06/2015 01:52:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_Session2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 

CodeIntegrity:
===================================
  Date: 2015-10-31 09:50:29.875
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-31 09:50:29.733
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-31 09:50:29.634
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-31 09:50:29.430
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-31 09:50:29.361
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-31 09:50:29.282
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-31 09:50:26.581
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-31 09:50:25.871
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-31 06:54:07.355
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2015-10-31 06:54:07.176
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
 

==================== Memory info ===========================
 
Processor: AMD Turion™ II P520 Dual-Core Processor
Percentage of memory in use: 66%
Total physical RAM: 3834.9 MB
Available physical RAM: 1301.25 MB
Total Virtual: 7674.9 MB
Available Virtual: 4319.91 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:284.24 GB) (Free:219.5 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (RECOVERY) (Fixed) (Total:13.55 GB) (Free:1.9 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: 099563F6)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=284.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=13.6 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=103 MB) - (Type=0C)
 
==================== End of Addition.txt ============================
​
 

​Thanks for taking the time to look this over and let me know how I should proceed.

Thank you!​

Hello MacFhearguis and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!


IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your logs now and will reply with instructions shortly.
 

Hello again MacFhearguis.

There isn't too much wrong but some things that could be contributing to the slowness and we can run some scans to see about the redirects.


Note: Please follow the instructions in the order given.

===================================================

Registry cleaners

I see you are using a “Registry Cleaner”, Registry Mechanic from PC Tools. It's not a good idea to use registry cleaners/boosters.

This may have been installed unintentionally as it come bundled with Adobe Shockwave Player.

However, the usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid and erroneous entries does not affect system performance but it can result in "unpredictable results". Unless you have a particular problem that requires a registry edit to correct it, (and you are expert in the registry), I would suggest you leave the registry alone.

I strongly advise you to uninstall PC Tools Registry Mechanic 11.0 and any other cleaner/optimizer/booster/tuneup/tweak type utilities that you have on this or any other  computer.

One of the malware experts, miekiemoes, has an excellent write-up here

Another from quietman7 here

================================================

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

HKLM-x32\…\Run: [] => [X]
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM-x32 -> {3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6} URL = hxxp://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKLM-x32 -> {BF1D2AD1-927A-4C76-9848-9923A9B74AFB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3538756054-3176117391-120295970-1000 -> {3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6} URL = hxxp://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKU\S-1-5-21-3538756054-3176117391-120295970-1000 -> {BF1D2AD1-927A-4C76-9848-9923A9B74AFB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
Toolbar: HKLM - No Name - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} -  No File
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll => No File
CHR Plugin: (Java™ Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll => No File
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll => No File
CHR Plugin: (RealJukebox NS Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll => No File
CHR Plugin: (RealPlayer Version Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll => No File
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2010-03-30 06:29 - 2010-03-30 06:29 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2010-03-30 06:21 - 2010-03-30 06:23 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2010-06-20 01:40 - 2010-06-20 01:40 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2010-03-30 06:21 - 2010-03-30 06:21 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2010-03-30 06:23 - 2010-03-30 06:28 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2010-06-20 01:42 - 2010-06-20 01:42 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
Task: {08F4E36D-9C0C-4CDB-BEA4-0CFDFE55029A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {097C0CAD-A452-4FCA-9EC2-8A1243120586} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {0BC18D7C-7A5F-4F0F-A668-DC27642550D6} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {189BAE74-F6A0-4910-8D49-5729E8CDED8C} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {329EC941-3C94-4072-9691-499DD8E81B3E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {3A140220-8F1E-4E55-8832-B538A52128C1} - System32\Tasks\RMSchedule => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\RegMech.exe [2011-12-12] (PC Tools)
Task: {63F3307B-B920-4508-875F-8DCA42BD54B7} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {7ED995AB-9353-4D10-9444-8807A11EF13C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {7F6E3D4B-5AFE-4F79-8190-66D15887BEA9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {9D588900-F5E1-41E3-A948-E789C8634327} - System32\Tasks\RMSmartUpdate => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\update.exe [2011-12-12] (PC Tools)
Task: {AC3188EF-AD3F-49FE-A907-01EDD4CC941C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {CE39CBD4-2EE6-429C-9DA2-C494D4CBFB94} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {F8DC7850-A388-4030-8294-13375FE870CE} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\RMSchedule.job => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\RegMech.exe
AlternateDataStreams: C:\ProgramData\Temp:0FF263E8
AlternateDataStreams: C:\ProgramData\Temp:5C321E34
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Run Farbar Recovery Scan Tool

Please run FRST again and make sure there is a checkmark next to "addition.txt" before you hit “Scan”.

Logs to include with next post:

Fixlog.txt
AdwCleaner log

New Frst.txt
New Addition.txt

Thanks

Satchfan

Fix Log:

Fix result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by [removed] (2015-11-09 10:00:40) Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================

 

fixlist content:
*****************
HKLM-x32\…\Run: [] => [X]
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM-x32 -> {3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6} URL = hxxp://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
SearchScopes: HKLM-x32 -> {BF1D2AD1-927A-4C76-9848-9923A9B74AFB} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3538756054-3176117391-120295970-1000 -> {3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6} URL = hxxp://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
SearchScopes: HKU\S-1-5-21-3538756054-3176117391-120295970-1000 -> {BF1D2AD1-927A-4C76-9848-9923A9B74AFB} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox
Toolbar: HKLM - No Name - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} -  No File
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll => No File
CHR Plugin: (Java™ Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll => No File
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll => No File
CHR Plugin: (RealJukebox NS Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll => No File
CHR Plugin: (RealPlayer Version Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll => No File
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2010-03-30 06:29 - 2010-03-30 06:29 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2010-03-30 06:21 - 2010-03-30 06:23 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2010-06-20 01:40 - 2010-06-20 01:40 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2010-03-30 06:21 - 2010-03-30 06:21 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2010-03-30 06:23 - 2010-03-30 06:28 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2010-06-20 01:42 - 2010-06-20 01:42 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
Task: {08F4E36D-9C0C-4CDB-BEA4-0CFDFE55029A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {097C0CAD-A452-4FCA-9EC2-8A1243120586} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {0BC18D7C-7A5F-4F0F-A668-DC27642550D6} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {189BAE74-F6A0-4910-8D49-5729E8CDED8C} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {329EC941-3C94-4072-9691-499DD8E81B3E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {3A140220-8F1E-4E55-8832-B538A52128C1} - System32\Tasks\RMSchedule => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\RegMech.exe [2011-12-12] (PC Tools)
Task: {63F3307B-B920-4508-875F-8DCA42BD54B7} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {7ED995AB-9353-4D10-9444-8807A11EF13C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {7F6E3D4B-5AFE-4F79-8190-66D15887BEA9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {9D588900-F5E1-41E3-A948-E789C8634327} - System32\Tasks\RMSmartUpdate => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\update.exe [2011-12-12] (PC Tools)
Task: {AC3188EF-AD3F-49FE-A907-01EDD4CC941C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {CE39CBD4-2EE6-429C-9DA2-C494D4CBFB94} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {F8DC7850-A388-4030-8294-13375FE870CE} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\RMSchedule.job => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\RegMech.exe
AlternateDataStreams: C:\ProgramData\Temp:0FF263E8
AlternateDataStreams: C:\ProgramData\Temp:5C321E34
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
EmptyTemp:
*****************

 

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6}" => key removed successfully
HKCR\Wow6432Node\CLSID\{3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BF1D2AD1-927A-4C76-9848-9923A9B74AFB}" => key removed successfully
HKCR\Wow6432Node\CLSID\{BF1D2AD1-927A-4C76-9848-9923A9B74AFB} => key not found.
"HKU\S-1-5-21-3538756054-3176117391-120295970-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6}" => key removed successfully
HKCR\CLSID\{3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6} => key not found.
"HKU\S-1-5-21-3538756054-3176117391-120295970-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BF1D2AD1-927A-4C76-9848-9923A9B74AFB}" => key removed successfully
HKCR\CLSID\{BF1D2AD1-927A-4C76-9848-9923A9B74AFB} => key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{381FFDE8-2394-4f90-B10D-FC6124A40F8C} => value removed successfully
HKCR\CLSID\{381FFDE8-2394-4f90-B10D-FC6124A40F8C} => key not found.
C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\ppGoogleNaClPluginChrome.dll => not found.
C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\pdf.dll => not found.
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => not found.
C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL => not found.
C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL => not found.
C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll => not found.
C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => not found.
C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll => not found.
C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll => not found.
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll => not found.
C:\Windows\SysWOW64\npDeployJava1.dll => not found.
c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => not found.
c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll => not found.
c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll => not found.
c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll => not found.
idsvc => service removed successfully
wfpcapture => service removed successfully
wpcsvc => service removed successfully
C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log => moved successfully
C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log => moved successfully
C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log => moved successfully
C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log => moved successfully
C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log => moved successfully
C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log => moved successfully
C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log => moved successfully
C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log => moved successfully
C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{08F4E36D-9C0C-4CDB-BEA4-0CFDFE55029A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{08F4E36D-9C0C-4CDB-BEA4-0CFDFE55029A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{097C0CAD-A452-4FCA-9EC2-8A1243120586}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{097C0CAD-A452-4FCA-9EC2-8A1243120586}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0BC18D7C-7A5F-4F0F-A668-DC27642550D6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BC18D7C-7A5F-4F0F-A668-DC27642550D6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{189BAE74-F6A0-4910-8D49-5729E8CDED8C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{189BAE74-F6A0-4910-8D49-5729E8CDED8C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{329EC941-3C94-4072-9691-499DD8E81B3E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{329EC941-3C94-4072-9691-499DD8E81B3E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3A140220-8F1E-4E55-8832-B538A52128C1} => key not found.
C:\WINDOWS\System32\Tasks\RMSchedule => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RMSchedule => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{63F3307B-B920-4508-875F-8DCA42BD54B7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{63F3307B-B920-4508-875F-8DCA42BD54B7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7ED995AB-9353-4D10-9444-8807A11EF13C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7ED995AB-9353-4D10-9444-8807A11EF13C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7F6E3D4B-5AFE-4F79-8190-66D15887BEA9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7F6E3D4B-5AFE-4F79-8190-66D15887BEA9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9D588900-F5E1-41E3-A948-E789C8634327} => key not found.
C:\WINDOWS\System32\Tasks\RMSmartUpdate => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RMSmartUpdate => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC3188EF-AD3F-49FE-A907-01EDD4CC941C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC3188EF-AD3F-49FE-A907-01EDD4CC941C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CE39CBD4-2EE6-429C-9DA2-C494D4CBFB94}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE39CBD4-2EE6-429C-9DA2-C494D4CBFB94}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F8DC7850-A388-4030-8294-13375FE870CE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8DC7850-A388-4030-8294-13375FE870CE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
C:\WINDOWS\Tasks\RMSchedule.job => not found.
C:\ProgramData\Temp => ":0FF263E8" ADS removed successfully.
C:\ProgramData\Temp => ":5C321E34" ADS removed successfully.
C:\ProgramData\Temp => ":D1B5B4F1" ADS removed successfully.
EmptyTemp: => 5 GB temporary data Removed.

 

 

The system needed a reboot.

 

==== End of Fixlog 10:12:49 ====

​

 

 

 

ADWCleaner Log:
~

# AdwCleaner v5.019 - Logfile created 09/11/2015 at 10:30:52
# Updated 08/11/2015 by Xplode
# Database : 2015-11-09.1 [Server]
# Operating system : Windows 10 Home  (x64)
# Username : Hp - HP-PC
# Running from : C:\Users\Hp\Desktop\adwcleaner_5.019.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

 

***** [ Services ] *****

 

 

***** [ Folders ] *****

 

[-] Folder Deleted : C:\Users\Hp\AppData\Roaming\registry mechanic

 

***** [ Files ] *****

 

 

***** [ DLLs ] *****

 

 

***** [ Shortcuts ] *****

 

 

***** [ Scheduled tasks ] *****

 

 

***** [ Registry ] *****

 

[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
[-] Key Deleted : HKCU\Software\YahooPartnerToolbar

 

***** [ Web browsers ] *****

 

[-] [C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com

 

*************************

 

:: "Tracing" keys removed
:: Winsock settings cleared

 

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1129 bytes] ##########

​

 

 

 

FRST:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
Ran by [removed] (administrator) on HP-PC (09-11-2015 10:36:14)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 10 Home (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(CinemaNow, Inc.) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
() C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe
() C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\ActionUriServer.exe

 

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\…\Run: [RtkOSD] => C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe [995840 2010-02-05] (Realtek Semiconductor Corp.)
HKLM\…\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-01-27] (Hewlett-Packard)
HKLM\…\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-07-17] (Synaptics Incorporated)
HKLM\…\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe [1603544 2015-10-01] (Bitdefender)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-09-22] (Google Inc.)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [SanDiskSecureAccess_Manager.exe] => C:\Users\Hp\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [27311232 2011-06-29] (Gemalto N.V.)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe [790880 2015-06-18] (Bitdefender)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Policies\Explorer: [NoInstrumentation] 1
BootExecute: autocheck autochk * sdnclean64.exe

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{03db8a02-2336-4c54-8b7c-da7fef957d22}: [DhcpNameServer] [removed] [removed]

 

Internet Explorer:
==================
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPNOT/1
BHO: Bitdefender Wallet  -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-10-09] (Bitdefender)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-23] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-10-09] (Bitdefender)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-22] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-22] (Oracle Corporation)
Toolbar: HKLM - Bitdefender Wallet  - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-10-09] (Bitdefender)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-23] (Google Inc.)
Toolbar: HKLM-x32 - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-10-09] (Bitdefender)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-3538756054-3176117391-120295970-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-23] (Google Inc.)
DPF: HKLM-x32 {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)

 

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-10-19] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-19] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2009-07-21] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-22] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-20] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-20] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2010-07-17] (Sun Microsystems, Inc.)
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-09-29] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\\antispam32\bdwteff
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender 2015\\antispam32\bdwteff [2015-10-09] [not signed]
FF HKLM\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext
FF Extension: Bitdefender Antispam Toolbar - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext [2015-07-28] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\\antispam32\bdwteff
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext

 

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll => No File
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll => No File
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll => No File
CHR Plugin: (RealJukebox NS Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll => No File
CHR Plugin: (RealPlayer Version Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll => No File
CHR Profile: C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-26]
CHR Extension: (Google Drive) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-29]
CHR Extension: (YouTube) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-26]
CHR Extension: (Google Search) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-26]
CHR Extension: (Google Docs Offline) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-29]
CHR Extension: (Gmail) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-26]
CHR HKLM-x32\…\Chrome\Extension: [fabcmochhfpldjekobfaaggijgohadih] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]

 

==================== Services (Whitelisted) ========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

S3 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2015\bdparentalservice.exe [78144 2015-07-24] (Bitdefender)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R2 HPWMISVC; C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [19968 2010-01-12] () [File not signed]
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-02-22] (Hewlett-Packard Company) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-07-31] (Microsoft Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [303360 2015-06-24] (Realtek Semiconductor)
R2 RtVOsdService; C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe [315392 2010-06-24] (Realtek Semiconductor Corp.) [File not signed]
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-07-17] (Synaptics Incorporated)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2015-04-22] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe [1537648 2015-10-01] (Bitdefender)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-07-31] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-07-31] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

 

===================== Drivers (Whitelisted) ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1369288 2015-05-28] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [271272 2015-05-29] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [747120 2015-05-28] (BitDefender)
U5 bdelam; C:\Windows\System32\Drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2014-12-15] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [115800 2015-05-21] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
R1 BDVEDISK; C:\Windows\system32\DRIVERS\bdvedisk.sys [79192 2013-07-30] (BitDefender)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [160032 2015-10-01] (BitDefender LLC)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2015-11-09] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-07-31] (Microsoft Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek                                            )
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [477272 2015-10-01] (BitDefender S.R.L.)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2015-11-09 10:33 - 2015-11-09 10:33 - 00016148 _____ C:\WINDOWS\system32\HP-PC_Hp_HistoryPrediction.bin
2015-11-09 10:28 - 2015-11-09 10:30 - 00000000 ____D C:\AdwCleaner
2015-11-09 10:27 - 2015-11-09 10:28 - 01712128 _____ C:\Users\Hp\Desktop\adwcleaner_5.019.exe
2015-11-09 10:24 - 2015-11-09 10:24 - 01712128 _____ C:\Users\Hp\Downloads\CJXo08DbMj9LO1NPxduzjzYDQPEnWiGT
2015-11-09 10:19 - 2015-11-09 10:19 - 01712128 _____ C:\Users\Hp\Downloads\VcQM72qS9GCTtsCzEcHBDtZbtqB523Wu
2015-11-08 14:02 - 2015-11-08 14:02 - 00282696 _____ C:\WINDOWS\Minidump\110815-25156-01.dmp
2015-11-08 12:41 - 2015-11-08 12:47 - 00049505 _____ C:\Users\Hp\Desktop\Addition.txt
2015-11-08 12:37 - 2015-11-09 10:36 - 00022191 _____ C:\Users\Hp\Desktop\FRST.txt
2015-11-08 12:36 - 2015-11-09 10:36 - 00000000 ____D C:\FRST
2015-11-08 12:33 - 2015-11-08 12:35 - 02198528 _____ (Farbar) C:\Users\Hp\Desktop\FRST64.exe
2015-11-08 12:27 - 2015-11-08 12:27 - 00002032 _____ C:\Users\Hp\Desktop\aswMBR.txt
2015-11-08 12:27 - 2015-11-08 12:27 - 00000512 _____ C:\Users\Hp\Desktop\MBR.dat
2015-11-08 12:18 - 2015-11-08 12:20 - 05198336 _____ (AVAST Software) C:\Users\Hp\Desktop\aswMBR.exe
2015-11-08 06:48 - 2015-11-08 06:48 - 00002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-11-04 12:51 - 2015-11-04 12:51 - 00000000 ____D C:\Users\Hp\AppData\Local\CEF
2015-11-04 12:47 - 2015-11-04 12:47 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-11-04 12:46 - 2015-11-04 12:46 - 00002132 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-11-03 16:44 - 2015-11-03 16:45 - 00002360 _____ C:\Users\Hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-10-31 19:00 - 2015-10-31 19:00 - 00000000 ____D C:\Users\Hp\Documents\gmoney disk
2015-10-31 18:40 - 2015-10-31 18:40 - 00063488 _____ C:\Users\Hp\Documents\PAYLIST ANNA CURRENT thumb 11 2015.xls
2015-10-30 13:37 - 2015-10-30 13:37 - 00022738 _____ C:\Users\Hp\Downloads\AZ ASG 9-2015.xlsx
2015-10-30 10:30 - 2015-10-27 16:38 - 21871616 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-30 10:29 - 2015-10-27 16:16 - 18801664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-30 10:29 - 2015-10-21 05:45 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-10-30 10:29 - 2015-10-21 05:44 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-10-30 10:29 - 2015-10-21 05:43 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-30 10:29 - 2015-10-21 05:39 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-10-30 10:29 - 2015-10-21 05:00 - 24595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-30 10:29 - 2015-10-21 05:00 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-30 10:29 - 2015-10-21 04:59 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2015-10-30 10:29 - 2015-10-21 04:57 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-30 10:29 - 2015-10-21 04:52 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-30 10:29 - 2015-10-21 04:50 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-10-30 10:29 - 2015-10-21 04:48 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-30 10:29 - 2015-10-21 04:47 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-10-30 10:29 - 2015-10-21 04:46 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-30 10:29 - 2015-10-21 04:46 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-10-30 10:29 - 2015-10-21 04:44 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-10-30 10:29 - 2015-10-21 04:44 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-30 10:29 - 2015-10-21 04:43 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2015-10-30 10:29 - 2015-10-21 04:42 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-30 10:29 - 2015-10-21 04:41 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-30 10:29 - 2015-10-21 04:40 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2015-10-30 10:29 - 2015-10-21 04:38 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-10-30 10:29 - 2015-10-20 22:53 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-30 10:29 - 2015-10-20 22:49 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-10-30 10:29 - 2015-10-20 22:13 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-30 10:29 - 2015-10-20 22:11 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-30 10:29 - 2015-10-20 22:08 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-30 10:29 - 2015-10-20 22:05 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-30 10:29 - 2015-10-20 22:03 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-10-30 10:29 - 2015-10-20 22:03 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-10-30 10:29 - 2015-10-20 21:58 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2015-10-30 10:29 - 2015-10-20 21:58 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-30 10:29 - 2015-10-20 21:55 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-10-28 14:11 - 2015-10-28 14:11 - 00069632 _____ C:\Users\Hp\Downloads\PrintExportedReport.xls
2015-10-28 14:10 - 2015-10-28 14:10 - 00043520 _____ C:\Users\Hp\Downloads\crt.xls
2015-10-22 11:11 - 2015-10-15 20:10 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-22 11:11 - 2015-10-15 20:10 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-22 10:39 - 2015-10-22 10:38 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-10-19 19:00 - 2015-10-19 19:02 - 00060540 _____ C:\WINDOWS\SysWOW64\AppLog.log
2015-10-19 19:00 - 2015-10-19 19:00 - 00000000 ____D C:\WINDOWS\PCHEALTH
2015-10-19 13:53 - 2015-10-19 13:53 - 00001187 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-10-19 13:53 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-10-19 13:53 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-10-19 13:53 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-10-19 12:18 - 2015-10-10 00:12 - 00078528 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-19 12:18 - 2015-10-05 20:03 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-19 12:18 - 2015-10-05 19:46 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-19 12:18 - 2015-09-30 21:01 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-10-19 12:18 - 2015-09-30 21:01 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-10-19 12:18 - 2015-09-30 21:01 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-10-19 12:18 - 2015-09-30 21:01 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-10-19 12:18 - 2015-09-30 21:00 - 08020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-19 12:18 - 2015-09-30 20:03 - 00757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2015-10-19 12:18 - 2015-09-24 21:01 - 02573768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-10-19 12:18 - 2015-09-24 21:01 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-10-19 12:18 - 2015-09-24 20:56 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-10-19 12:18 - 2015-09-24 20:52 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-10-19 12:18 - 2015-09-24 20:33 - 01997336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-10-19 12:18 - 2015-09-24 20:26 - 20858360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-10-19 12:18 - 2015-09-24 20:11 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-19 12:18 - 2015-09-24 20:11 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-19 12:18 - 2015-09-24 20:09 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-10-19 12:18 - 2015-09-24 20:07 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-19 12:18 - 2015-09-24 20:04 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-10-19 12:18 - 2015-09-24 20:04 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-19 12:18 - 2015-09-24 20:03 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-19 12:18 - 2015-09-24 20:03 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-10-19 12:18 - 2015-09-24 20:02 - 07523840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-19 12:18 - 2015-09-24 20:02 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-10-19 12:18 - 2015-09-24 20:02 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-19 12:18 - 2015-09-24 20:01 - 04792320 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-19 12:18 - 2015-09-24 20:01 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-19 12:18 - 2015-09-24 20:00 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-19 12:18 - 2015-09-24 20:00 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-19 12:18 - 2015-09-24 20:00 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-19 12:18 - 2015-09-24 20:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-19 12:18 - 2015-09-24 19:58 - 01871360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-10-19 12:18 - 2015-09-24 19:47 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-19 12:18 - 2015-09-24 19:47 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 03580416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-10-19 12:18 - 2015-09-24 19:37 - 00766976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-10-19 12:18 - 2015-09-24 19:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-19 12:18 - 2015-09-24 19:37 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-19 12:18 - 2015-09-24 19:36 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-10-19 12:18 - 2015-09-24 19:36 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-19 12:18 - 2015-09-24 19:33 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-19 12:18 - 2015-09-24 19:32 - 01594368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-10-19 12:18 - 2015-09-24 19:32 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2015-11-09 10:34 - 2015-07-10 05:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-09 10:34 - 2015-01-14 20:18 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-09 10:33 - 2015-09-20 14:45 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cf52901f22c608.job
2015-11-09 10:32 - 2015-07-10 05:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-09 10:31 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-11-09 10:31 - 2015-07-10 02:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-11-09 10:29 - 2013-04-26 13:25 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-11-09 10:23 - 2010-09-12 15:18 - 00004140 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7D1B5BD6-72C8-4707-9A38-50B0F4CB0C8B}
2015-11-09 10:19 - 2015-07-31 15:29 - 01018274 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-09 10:14 - 2015-07-31 15:23 - 00064096 _____ C:\WINDOWS\PFRO.log
2015-11-09 10:14 - 2011-12-27 09:40 - 00000000 ____D C:\Program Files (x86)\PC Tools
2015-11-09 10:13 - 2015-07-31 15:31 - 00000000 ____D C:\Users\Hp
2015-11-09 10:02 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-11-09 10:00 - 2015-09-12 17:42 - 00000000 ____D C:\Users\Hp\AppData\LocalLow\Temp
2015-11-09 09:57 - 2010-03-30 05:37 - 00000000 ____D C:\ProgramData\Temp
2015-11-09 09:51 - 2015-09-20 14:45 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-08 14:02 - 2015-08-09 14:47 - 00000000 ____D C:\WINDOWS\Minidump
2015-11-08 14:02 - 2015-08-09 14:46 - 593931394 _____ C:\WINDOWS\MEMORY.DMP
2015-11-04 12:51 - 2014-07-05 08:56 - 00000000 ____D C:\Users\Hp\AppData\Local\Adobe
2015-11-04 12:46 - 2011-09-22 15:31 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-11-04 12:46 - 2010-03-30 05:59 - 00000000 ____D C:\ProgramData\Adobe
2015-11-04 09:49 - 2015-07-10 02:05 - 00065536 ___SH C:\WINDOWS\system32\config\ELAM
2015-11-04 08:42 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\rescache
2015-11-04 07:06 - 2010-03-30 05:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-04 07:04 - 2013-09-16 13:30 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-11-04 06:48 - 2010-09-12 15:30 - 143481208 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-11-03 16:45 - 2015-07-31 16:12 - 00000000 ___RD C:\Users\Hp\OneDrive
2015-10-31 16:19 - 2015-07-10 05:20 - 00028872 _____ C:\WINDOWS\setupact.log
2015-10-31 16:14 - 2011-09-22 15:33 - 00000000 ____D C:\Users\Hp\AppData\Local\Google
2015-10-31 16:06 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-31 03:32 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-30 10:36 - 2015-07-10 03:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-29 16:03 - 2012-08-18 15:20 - 00000000 ____D C:\Users\Hp\Documents\Anna
2015-10-23 19:53 - 2013-04-26 13:26 - 00002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-10-22 10:39 - 2014-11-16 07:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-10-22 10:39 - 2013-09-16 13:55 - 00000000 ____D C:\ProgramData\Oracle
2015-10-22 10:38 - 2015-08-28 06:33 - 00000000 ____D C:\Users\Hp\.oracle_jre_usage
2015-10-22 10:37 - 2014-11-16 07:00 - 00000000 ____D C:\Program Files (x86)\Java
2015-10-21 06:33 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-10-21 03:36 - 2010-09-13 09:08 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-10-21 03:34 - 2015-07-10 05:20 - 04963392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-10-21 03:33 - 2015-01-14 20:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-19 13:53 - 2015-01-14 20:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware

 

==================== Files in the root of some directories =======

 

2013-02-19 00:02 - 2013-02-19 00:02 - 4126720 _____ () C:\Program Files (x86)\GUT40AE.tmp
2014-08-13 01:49 - 2014-08-13 01:49 - 130565325 _____ () C:\Program Files (x86)\openoffice1.cab
2014-08-13 01:48 - 2014-08-13 01:48 - 2310144 _____ () C:\Program Files (x86)\openoffice411.msi
2014-08-13 01:48 - 2014-08-13 01:48 - 0478720 _____ () C:\Program Files (x86)\setup.exe
2014-08-13 01:48 - 2014-08-13 01:48 - 0000279 _____ () C:\Program Files (x86)\setup.ini
2012-03-08 14:18 - 2012-03-08 14:45 - 0000640 _____ () C:\Users\Hp\AppData\Roaming\.backup.dm
2010-09-16 08:23 - 2010-09-16 08:23 - 0000025 _____ () C:\Users\Hp\AppData\Roaming\bdfvconp.ini
2011-02-15 12:36 - 2011-05-17 17:51 - 0001854 _____ () C:\Users\Hp\AppData\Roaming\GhostObjGAFix.xml
2012-08-18 15:13 - 2014-01-16 08:47 - 0002035 _____ () C:\Users\Hp\AppData\Roaming\SAS7_000.DAT
2010-09-20 22:41 - 2015-08-15 15:17 - 0001584 _____ () C:\Users\Hp\AppData\Roaming\wklnhst.dat
2013-06-20 14:25 - 2013-06-20 14:25 - 0003584 _____ () C:\Users\Hp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-30 06:27 - 2015-03-12 06:47 - 0007597 _____ () C:\Users\Hp\AppData\Local\Resmon.ResmonCfg
2015-08-05 16:43 - 2015-08-05 16:43 - 0515580 _____ () C:\ProgramData\1438817797.bdinstall.bin
2011-12-01 12:46 - 2011-12-01 12:46 - 0000057 _____ () C:\ProgramData\Ament.ini
2010-09-13 09:10 - 2010-09-13 09:10 - 0000056 ____H () C:\ProgramData\ezsidmv.dat

 

Some files in TEMP:
====================
C:\Users\Hp\AppData\Local\Temp\sqlite3.dll

 

 

==================== Bamital & volsnap =================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

 

 

LastRegBack: 2015-10-31 03:46

 

==================== End of FRST.txt ============================

​

 

 

 

Addition:
~

Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-11-2015
Ran by [removed] (2015-11-09 10:38:02)
Running from C:\Users\[removed]\Desktop
Windows 10 Home (X64) (2015-07-31 23:04:55)
Boot Mode: Normal
==========================================================

 

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-3538756054-3176117391-120295970-500 - Administrator - Disabled)
ASPNET (S-1-5-21-3538756054-3176117391-120295970-1002 - Limited - Enabled)
BitDefenderComm (S-1-5-21-3538756054-3176117391-120295970-1005 - Limited - Enabled)
DefaultAccount (S-1-5-21-3538756054-3176117391-120295970-503 - Limited - Disabled)
Guest (S-1-5-21-3538756054-3176117391-120295970-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3538756054-3176117391-120295970-1004 - Limited - Enabled)
Hp (S-1-5-21-3538756054-3176117391-120295970-1000 - Administrator - Enabled) => C:\Users\Hp

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: Bitdefender Antivirus (Enabled - Up to date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antispyware (Enabled - Up to date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46}

 

==================== Installed Programs ======================

 

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20077 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 19.0.0.190 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.)
Adobe Flash Player 19 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Shockwave Player (HKLM-x32\…\{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}) (Version: 11.5.1.601 - Adobe Systems, Inc.)
ATI Catalyst Install Manager (HKLM\…\{C3F0426C-175D-39B7-7A14-D6B21952DE5E}) (Version: 3.0.765.0 - ATI Technologies, Inc.)
Bitdefender Total Security 2015 (HKLM\…\Bitdefender) (Version: 19.2.0.142 - Bitdefender)
Broadcom 802.11 Wireless LAN Adapter (HKLM\…\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.350.6 - Broadcom Corporation)
ccc-core-static (x32 Version: 2010.0310.1824.32984 - ATI) Hidden
CinemaNow Media Manager (HKLM-x32\…\{6C122441-1861-4CD7-B1C5-A163A6984E12}) (Version: 1.9.1.105 - CinemaNow, Inc.)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CyberLink DVD Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.2527 - CyberLink Corp.)
CyberLink MediaShow (HKLM-x32\…\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1307 - CyberLink Corp.)
CyberLink PowerDVD 9 (HKLM-x32\…\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.1.3810 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2511 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
ESU for Microsoft Windows 7 (HKLM-x32\…\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)
Gmail Notifier (HKLM-x32\…\Gmail Notifier) (Version:  - )
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 46.0.2490.80 - Google Inc.)
Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6904.2028 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
HP Advisor (HKLM-x32\…\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.4.10262.3295 - Hewlett-Packard)
HP MediaSmart CinemaNow 2.0 (HKLM-x32\…\{9008D736-35CA-40DB-A2BE-5F32D954E5AA}) (Version: 2.0 - Hewlett-Packard)
HP Power Plan Utility (HKLM-x32\…\{F6B6A150-08FA-46D5-808A-EB638269551D}) (Version: 1.0.6 - Hewlett-Packard)
HP Quick Launch (HKLM\…\{6A66C1E5-4146-4CA6-A551-627CFCEACC83}) (Version: 1.0.17 - Hewlett-Packard)
HP Setup (HKLM-x32\…\{E2831862-F131-4327-B9CC-FA30F587EB6C}) (Version: 1.2.3988.3281 - Hewlett-Packard)
HP Software Framework (HKLM-x32\…\{6C872198-9ED1-4046-87B3-AFA79CDF342D}) (Version: 4.0.55.1 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP User Guides 0199 (HKLM-x32\…\{E39CFDC9-F521-4D9C-974B-17E93696FCAB}) (Version: 1.01.0000 - Hewlett-Packard)
HP Wireless Assistant (HKLM\…\{E6BC696E-5E96-4C1B-9371-379AF3A46B6B}) (Version: 4.0.4.2 - Hewlett-Packard)
Java 8 Update 65 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2515 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.2515 - CyberLink Corp.) Hidden
LAME v3.98.3 for Audacity (HKLM-x32\…\LAME for Audacity_is1) (Version:  - )
LightScribe System Software (HKLM-x32\…\{6AFDE3BE-BC01-45A4-9D06-BBF5AD207313}) (Version: 1.18.12.1 - LightScribe)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 1.1 (HKLM-x32\…\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft IntelliPoint 8.2 (HKLM\…\Microsoft IntelliPoint 8.2) (Version: 8.20.468.0 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft Office XP Professional (HKLM-x32\…\{91110409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\…\{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Publisher 2010 (HKLM-x32\…\Office14.PUBLISHERR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\…\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\…\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
NOOK for PC (HKLM-x32\…\BN_DesktopReader) (Version: 2.5.6.9575 - Barnesandnoble.com)
OLYMPUS Master 2 (HKLM-x32\…\{3A1AB8E6-748E-4B95-AA2D-FE9952EB3106}) (Version: 1.0.13 - OLYMPUS IMAGING CORP.)
OneClickdigital Media Manager (HKLM-x32\…\{C259BBE2-2531-4387-B5E3-9E6845854272}) (Version: 61.0.0.0 - Recorded Books)
OpenOffice 4.1.1 (HKLM-x32\…\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
PhotoNow! (HKLM-x32\…\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.6904 - CyberLink Corp.)
PhotoNow! (x32 Version: 1.1.6904 - CyberLink Corp.) Hidden
Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3715 - CyberLink Corp.)
Power2Go (x32 Version: 6.1.3715 - CyberLink Corp.) Hidden
PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.2514 - CyberLink Corp.)
PowerDirector (x32 Version: 8.0.2514 - CyberLink Corp.) Hidden
Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.18.322.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30120 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 5.5.2512 - CyberLink Corp.) Hidden
RtVOsd (HKLM\…\{091A0130-A82F-4A6D-9C61-3BBBB3289030}) (Version: 1.0.6 - Realtek Semiconductor Corp.)
SanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19269 - Gemalto N.V.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-0019-0000-0000-0000000FF1CE}_Office14.PUBLISHERR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)
Skype™ 7.6 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
Sockupied Spring 2012 (HKLM-x32\…\com.interweave.sockupiedspring2012) (Version: 1.0 - Interweave)
Sockupied Spring 2012 (x32 Version: 1.0 - Interweave) Hidden
Sockupied Spring 2014 (HKLM-x32\…\com.interweave.sockupiedspring2014) (Version: 1.0.0 - F+W Media, Inc.)
Sockupied Spring 2014 (x32 Version: 1.0.0 - F+W Media, Inc.) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 19.0.12.95 - Synaptics Incorporated)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM-x32\…\Windows Media Encoder 9) (Version:  - )
Zinio Reader 4 (HKLM-x32\…\ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1) (Version: 4.2.3972 - Zinio LLC)
Zinio Reader 4 (x32 Version: 4.2.3972 - Zinio LLC) Hidden

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

CustomCLSID: HKU\S-1-5-21-3538756054-3176117391-120295970-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Hp\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation)

 

==================== Restore Points =========================

 

19-10-2015 14:41:29 Scheduled Checkpoint
28-10-2015 07:14:18 Scheduled Checkpoint
31-10-2015 16:32:58 Windows Update
04-11-2015 06:43:24 Windows Update

 

==================== Hosts content: ==========================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2015-08-05 12:24 - 2015-08-05 12:24 - 00450771 ____A C:\WINDOWS\system32\Drivers\etc\hosts

 

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com

 

There are 15463 more lines.

 

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {00D37CBD-1363-420A-A9A9-F81EAD3D5369} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-19] (Adobe Systems Incorporated)
Task: {04617C3D-0AA2-4430-818E-8CB903756659} - System32\Tasks\Bitdefender Autoscan => C:\Program Files\Bitdefender\Bitdefender 2013\mtasklaunch.exe
Task: {0A8B30C4-99B0-4223-896F-672BD136A109} - System32\Tasks\GoogleUpdateTaskMachineCore1cf52901f22c608 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {0C267C17-A827-43D9-8CC7-FF88821A2146} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {1287B6D6-B819-48D5-AC88-63D9BF8ABF2D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {1413E7D6-F5F1-4702-B0C8-8DCD71C5B041} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-11-04] (Microsoft Corporation)
Task: {2DFE12DF-A440-42E9-BC40-2F3F9F5DC28D} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {3D30200F-62B2-4387-8C19-A1B9F1B7D1FC} - System32\Tasks\{44A07CDE-287C-4CE7-97A6-8D22D5215342} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-06-29] (Skype Technologies S.A.)
Task: {3FA86DFB-9864-4979-8C47-3249817D201A} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {4D9F29A1-3231-42E5-B5DF-2F490B362A84} - System32\Tasks\{10BF4766-87F1-4948-AA9D-E4D3D1246EBC} => pcalua.exe -a "C:\Program Files (x86)\OpenOffice.org 3\program\sbase.exe" -d C:\Users\Hp\Documents -c -o "C:\Users\Hp\Documents\Contacts.odb"
Task: {4DDFD1B4-1BFE-4955-9128-EA1C9ED805FF} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {549707FA-A06E-4A13-906B-8BE9FC6E9612} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {5D468FCA-DFD8-492A-8DDA-533809CF4733} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-08-01] (Microsoft Corporation)
Task: {5D986A82-8659-415E-9C81-5327FB5E4AB9} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {5ED71F25-5E1C-4143-BF72-E119EFA076F9} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {605C087D-0CBA-43D2-B8BC-0DA55E7A8027} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {615F219E-46E9-493A-BE51-43EC9D653E0A} - System32\Tasks\AdobeAAMUpdater-1.0-Hp-PC-Hp => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)
Task: {6640D516-7877-4E45-BA3F-AA58C73A4FC4} - System32\Tasks\{5087E47C-F4B1-48F2-9D2B-9C7C89061E13} => Iexplore.exe hxxp://ui.skype.com/ui/0/4.1.0.179.271/en/go/help.faq.installer?LastError=1603
Task: {6DAE4147-3132-4B73-AD2A-C543E24DE489} - System32\Tasks\Hewlett-Packard\HP Assistant\HPSA Upgrade => C:\ProgramData\Hewlett-Packard\HPSAUpgrade3\HpSAUpgrade.exe [2011-08-11] (Hewlett-Packard)
Task: {7FDAF8EC-25A4-4509-AACC-D9D27A2A0DAD} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {8C5B60D3-EC95-474B-BC98-5D0895148305} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
Task: {8CB959D3-FAC3-4FC8-8E90-3A1950FB5843} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {990FC820-7C11-4FC8-8626-1C4084ACE5E2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {A213B09B-F624-4C98-B88F-EEBF8BCCA9C3} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {A7368EBD-48F3-4229-999C-109C8602B510} - System32\Tasks\{71C771B6-2EF4-45F3-ACC0-E269B17A5C28} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=4.2.0.187&LastError;=12002
Task: {AA9297E2-887B-4FC6-8777-20000628C6F0} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {AB4A22BA-A58C-4A61-9F99-B581C8B2946A} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {ADA75388-0E9A-463F-ACA4-4ADFBBD55161} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {B810FC5B-74CC-4C29-9F01-B9C0BCAE29B7} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {BE312CE1-03B9-4201-88EB-BAD1C0477C29} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-01-26] ()
Task: {BFD22CE4-E344-452D-8B78-41DC17A7E8F2} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {C55B1ADB-4F73-4F03-86F8-F25D1086E757} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {C5A51B9E-18D1-49AA-BCE3-383952A2BAB2} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
Task: {CA3E495B-2732-49BA-99C1-2B74D00C270A} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {CD385B27-CFED-4827-92F0-DC3161BB82DE} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
Task: {CDBCA0F0-B023-46EE-89AC-722E9C68D8F6} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {D3368AB9-4EBB-47B6-B0BA-5781C8D9E410} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {DD340FA2-5315-471B-A13E-9A7C2260AFF2} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DD7600F1-B407-4CCF-A569-B33F2CF06CFF} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {DFA008D2-2B42-4D18-9512-3A96F613B1ED} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {E3860717-FB64-4F1F-B494-8CD9E507D4A3} - System32\Tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8 => C:\Program Files\Bitdefender\Bitdefender 2013\bdproductdata.exe
Task: {E8EB2E3F-133B-4A4E-878A-6983871914D5} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {EE72A342-9164-4832-BD39-615121A416F9} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {F07DB3B7-29BE-4ABA-B956-9C166A778312} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {F15293F1-93B5-4747-A456-DD3DC9D7FDA0} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {F6BA051A-6EF4-45A0-BD0B-579BFA5D11CA} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {FB000530-0412-49F2-84CD-6F96E45EA85F} - System32\Tasks\ScanToPCActivationApp.exe_{43A47EB1-B846-4B57-B6B4-5CE877A449A2} => C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cf52901f22c608.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

 

==================== Loaded Modules (Whitelisted) ==============

 

2015-07-31 16:14 - 2015-07-31 16:14 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-08-05 16:41 - 2015-04-22 16:55 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\txmlutil.dll
2015-08-05 16:41 - 2013-09-03 14:29 - 00101328 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdmetrics.dll
2015-08-05 16:41 - 2015-07-28 19:06 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\UI\accessl.ui
2015-08-05 16:41 - 2012-10-29 14:22 - 00152816 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdfwcore.dll
2015-09-05 14:33 - 2015-09-05 14:33 - 00875352 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttpbr.mdl
2015-09-05 14:33 - 2015-09-05 14:33 - 00741952 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttpdsp.mdl
2015-09-05 14:33 - 2015-09-05 14:33 - 02800952 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttpph.mdl
2015-09-05 14:33 - 2015-09-05 14:33 - 01413024 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttprbl.mdl
2015-08-19 09:07 - 2015-08-11 02:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2010-01-12 15:44 - 2010-01-12 15:44 - 00019968 _____ () C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
2015-09-30 16:08 - 2015-09-16 23:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-09-30 16:08 - 2015-09-16 23:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-09-30 16:08 - 2015-09-16 22:43 - 02028544 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RulesService.dll
2015-09-30 16:08 - 2015-09-16 22:42 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-09-30 16:08 - 2015-09-16 22:42 - 00619008 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SignalsManager.dll
2015-09-30 16:08 - 2015-09-16 22:43 - 00928768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RulesBackgroundTasks.dll
2015-09-30 16:08 - 2015-09-16 22:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-09-30 16:09 - 2015-09-16 22:44 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-09-30 16:08 - 2015-09-16 22:42 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-09-30 16:08 - 2015-09-16 22:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2010-01-27 14:00 - 2010-01-27 14:00 - 00008192 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe
2010-01-27 14:01 - 2010-01-27 14:01 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

AlternateDataStreams: C:\Users\Hp\Desktop\adwcleaner_5.019.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\bitdefender_tsecurity (1).exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\GoogleEarthSetup.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\Lame_v3.98.3_for_Audacity_on_Windows.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\Microsoft_Publisher_2010_2_PC_1_User_Downloader.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\OneClickdigital Media Manager Installer.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\rminstall.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\spybotsd162.exe:BDU

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

 

 

==================== EXE Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\1-2005-search.com -> www.1-2005-search.com

 

There are 12683 more sites.

 

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-21-3538756054-3176117391-120295970-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Hp\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

(Currently there is no automatic fix for this section.)

 

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnkCommon Startup
MSCONFIG\startupfolder: C:^Users^Hp^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk => C:\Windows\pss\OpenOffice.org 3.2.lnkStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher =>
MSCONFIG\startupreg: HP Quick Launch => C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: HPAdvisorDock => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
MSCONFIG\startupreg: LightScribe Control Panel => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
MSCONFIG\startupreg: OM2_Monitor => "C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
MSCONFIG\startupreg: SunJavaUpdateSched =>
MSCONFIG\startupreg: TkBellExe =>
HKLM\…\StartupApproved\Run: => "IntelliPoint"
HKLM\…\StartupApproved\Run32: => "SSDMonitor"
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\StartupApproved\Run: => "SpybotPostWindows10UpgradeReInstall"
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\StartupApproved\Run: => "SanDiskSecureAccess_Manager.exe"

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{5C670AB1-8442-4DF8-B0DF-30EE69F856DA}] => (Allow) LPort=1900
FirewallRules: [{959ADFA3-811A-4A57-BB5B-7747B726D55B}] => (Allow) LPort=2869
FirewallRules: [{1051274C-8BC4-4E18-852D-EEFE0436F0E1}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{8409542A-67FC-4DDE-8960-B5708BA132D9}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{8BAD2BB1-072F-40FC-A936-C7053AC269EE}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD9.EXE
FirewallRules: [{6BBBAE71-A4C5-4E0D-97C5-B3BA12DF8F5D}] => (Allow) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe
FirewallRules: [{3953E48E-2CAD-4ACB-91A1-9F2718A3038D}] => (Allow) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe
FirewallRules: [{112E6941-3815-4FF7-8BD9-385548D1A39A}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\MediaSmart\CinemaNow\CinemaNow.exe
FirewallRules: [{A5CCD263-2F9D-4620-A201-4A20A02604CF}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\MediaSmart\CinemaNow\CinemaNow.exe
FirewallRules: [{DA5D497C-27F9-41C0-87AA-D8D68B083CF6}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE
FirewallRules: [{D46F22B5-0E6E-44E5-AF05-D3E4237578A0}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{E80BF42B-A1DD-44CE-8476-610F88E20459}] => (Allow) svchost.exe
FirewallRules: [{A0066F71-6931-4B67-86F3-D362380B3497}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [TCP Query User{407D1FDC-0F11-4AB1-924A-CF8B47E7DA60}C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe] => (Block) C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe
FirewallRules: [UDP Query User{35B25721-3AD1-4C8D-98B6-8C1E1C24EC85}C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe] => (Block) C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe
FirewallRules: [TCP Query User{A7984981-4F39-4AF6-AB7F-21988A15F0A6}C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe] => (Allow) C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe
FirewallRules: [UDP Query User{497A74C2-93CF-4A4D-9BE5-74EEDD14C1D9}C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe] => (Allow) C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe
FirewallRules: [{4CC6C5EC-231F-4226-8D97-BC6FCF42B5AD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

 

==================== Faulty Device Manager Devices =============

 

 

==================== Event log errors: =========================

 

Application errors:
==================
Error: (11/09/2015 09:35:47 AM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location I:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).

 

Error: (11/08/2015 01:42:59 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 11.0.10240.16412 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

 

Process ID: 3678

 

Start Time: 01d11a65c3b8ee3a

 

Termination Time: 41

 

Application Path: C:\Program Files (x86)\Internet Explorer\iexplore.exe

 

Report Id: 492d49d4-8659-11e5-9bdc-c80aa9cb513a

 

Faulting package full name:

 

Faulting package-relative application ID:

 

Error: (11/08/2015 01:40:40 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Hp-PC)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147024865 See the Microsoft-Windows-TWinUI/Operational log for additional information.

 

Error: (11/08/2015 12:18:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.10240.16431 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

 

Process ID: 3320

 

Start Time: 01d11a2a23a7f3ff

 

Termination Time: 0

 

Application Path: C:\Windows\explorer.exe

 

Report Id: 67e6b561-864d-11e5-9bdc-c80aa9cb513a

 

Faulting package full name:

 

Faulting package-relative application ID:

 

Error: (11/08/2015 11:55:23 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Hp-PC)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147024865 See the Microsoft-Windows-TWinUI/Operational log for additional information.

 

Error: (11/08/2015 07:31:51 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Hp-PC)
Description: Activation of app Microsoft.LockApp_cw5n1h2txyewy!WindowsDefaultLockScreen failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.

 

Error: (11/08/2015 07:31:51 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LockApp.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

 

Process ID: 3b74

 

Start Time: 01d11a32234036e1

 

Termination Time: 4294967295

 

Application Path: C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe

 

Report Id: 71e5092c-8625-11e5-9bdc-c80aa9cb513a

 

Faulting package full name: Microsoft.LockApp_10.0.10240.16384_neutral__cw5n1h2txyewy

 

Faulting package-relative application ID: WindowsDefaultLockScreen

 

Error: (11/08/2015 07:31:37 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: Hp-PC)
Description: App Microsoft.LockApp_10.0.10240.16384_neutral__cw5n1h2txyewy+WindowsDefaultLockScreen did not launch within its allotted time.

 

Error: (11/08/2015 06:47:00 AM) (Source: MsiInstaller) (EventID: 1023) (User: Hp-PC)
Description: Product: Adobe Acrobat Reader DC - Update '{AC76BA86-7AD7-0000-2550-AC0F094E6D00}' could not be installed. Error code 1625. Additional information is available in the log file C:\Users\Hp\AppData\Local\Temp\MSI35b56.LOG.

 

Error: (11/08/2015 06:39:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program ShellExperienceHost.exe version 10.0.10240.16515 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

 

Process ID: 3b8c

 

Start Time: 01d11a2a2b405196

 

Termination Time: 4294967295

 

Application Path: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe

 

Report Id: 2d33a0c3-861e-11e5-9bdc-c80aa9cb513a

 

Faulting package full name: Microsoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy

 

Faulting package-relative application ID: App

 

 

System errors:
=============
Error: (11/09/2015 10:32:52 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error:
%%1058

 

Error: (11/09/2015 10:31:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RtVOsdService Installer service failed to start due to the following error:
%%3

 

Error: (11/09/2015 10:31:43 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

 

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll

 

Error: (11/09/2015 10:31:43 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

 

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll

 

Error: (11/09/2015 10:31:41 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the VSSERV service.

 

Error: (11/09/2015 10:31:21 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
%%1056

 

Error: (11/09/2015 10:31:11 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

 

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll

 

Error: (11/09/2015 10:31:09 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_Session1 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.

 

Error: (11/09/2015 10:31:09 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_Session1 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.

 

Error: (11/09/2015 10:31:09 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_Session1 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.

 

 

CodeIntegrity:
===================================
  Date: 2015-10-31 09:50:29.875
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-10-31 09:50:29.733
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-10-31 09:50:29.634
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-10-31 09:50:29.430
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-10-31 09:50:29.361
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-10-31 09:50:29.282
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-10-31 09:50:26.581
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-10-31 09:50:25.871
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-10-31 06:54:07.355
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

 

  Date: 2015-10-31 06:54:07.176
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

 

 

==================== Memory info ===========================

 

Processor: AMD Turion™ II P520 Dual-Core Processor
Percentage of memory in use: 55%
Total physical RAM: 3834.9 MB
Available physical RAM: 1707.34 MB
Total Virtual: 7674.9 MB
Available Virtual: 5377.25 MB

 

==================== Drives ================================

 

Drive c: () (Fixed) (Total:284.24 GB) (Free:224.3 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (RECOVERY) (Fixed) (Total:13.55 GB) (Free:1.9 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32

 

==================== MBR & Partition Table ==================

 

========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: 099563F6)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=284.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=13.6 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=103 MB) - (Type=0C)

 

==================== End of Addition.txt ============================

​

Just trying to post these logs was almost impossible due to how slow the browser was.
 

This computer has Edge and IE and Chrome installed. I could not post the logs in Edge, and had to use IE to post them.

My main concern is that there is a virus or malware on the comp. If that is not the case, and the slowness is just due to old age and such, I'm fine with that and can look at newer computers for my mother.

 

SatchFan, the help and guidance is appreciated.




 

My main concern is that there is a virus or malware on the comp.

 

I see no evidence of that.

 

If that is not the case, and the slowness is just due to old age

 

The computer specs seem to be perfectly adequate to cope with Windows 10 but I think there may be some compatibility issues which I'm not an expert in.

 

I'd suggest starting a topic in our Windows forum where you will be able to get some more technical help with that rather than malware, (which, having seen the logs, I'm pretty sure is not the case).

 

Please let me know if you choose that route or if you'd like us to look further here.

 

Satchfan

Satchfan,

I appreciate you taking a look at the logs and am glad to know that there doesn't appear to be any malware.

The redirects that I was experiencing while using the comp had to do with some sort of anti-virus or anti-malware, but I'm not seeing them anymore. Honestly, it has me a bit confused, but I certainly trust the you folks here on the topic, rather I do my own recollection.

I'll defer to you for the next step on the MW or Virus stuff, and if things are appear clear, I can address the compatibility issues.

Hello MacFhearguis.

Let’s have a look at your security.

Run Security Check

Download Security Check by screen317 from here or here.

  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE: If you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED!, try rebooting the system and then run SecurityCheck again.

Satchfan

 

 

 Results of screen317's Security Check version 1.009 
   x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Disabled! 
Bitdefender Antivirus  
Windows Defender       
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
 MVPS Hosts File 
 Java 8 Update 65 
 Java version 32-bit out of Date!
 Adobe Flash Player  19.0.0.245 
````````Process Check: objlist.exe by Laurent```````` 
 Malwarebytes Anti-Malware mbamservice.exe 
 Malwarebytes Anti-Malware mbam.exe 
 Malwarebytes Anti-Malware mbamscheduler.exe  
 Bitdefender Bitdefender 2015 vsserv.exe 
 Bitdefender Bitdefender 2015 updatesrv.exe 
 Bitdefender Bitdefender 2015 bdagent.exe 
 Bitdefender Bitdefender 2015 bdwtxag.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````
 

I apologise for the delay in replying but I had a minor family issue that I needed to deal with.


According to the SystemLook log, Windows firewall is disabled and Windows Defender enabled but BitDefender's firewall isn't listed.

These could be misleading as your previous logs showed BD’s firewall enabled and Defender disabled!

You need to check that BitDefender's firewall is enabled and that Windows Defender is disabled as 2 antiviruses running would cause a conflict.

===================================================

Registry cleaners

I see you are using a “Registry Cleaner”, PC Tools Registry Mechanic. It's not a good idea to use registry cleaners/boosters.

This may have been installed unintentionally as it come bundled with Adobe Shockwave Player.

However, the usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid and erroneous entries does not affect system performance but it can result in "unpredictable results". Unless you have a particular problem that requires a registry edit to correct it, (and you are expert in the registry), I would suggest you leave the registry alone.

I strongly advise you to get rid of PC Tools Registry Mechanic and any other cleaner/optimizer/booster/tuneup/tweak type utilities that you have on this or any other  computer.

One of the malware experts, miekiemoes, has an excellent write-up here
Another from quietman7 here


Can you tell me what current problems you are noticing.

Satchfan

 

Hi MacFhearguis

 

It has again been several days since my last post. Please let me know if you have any remaining questions.

 

If I do not hear from you within 24 hours I'll assume that all is now OK and close this topic.

 

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI