Hello all,
I'm working on my Mother's computer as she has said that it is running painfully slow out of the blue, and has random redirects to dead pages.
Here is the aswMBR log:
~
Run date: 2015-11-08 12:21:12
—————————–
12:21:12.513 OS Version: Windows x64 6.2.9200
12:21:12.513 Number of processors: 2 586 0x603
12:21:12.515 ComputerName: HP-PC UserName: Hp
12:21:16.678 Initialize success
12:21:16.801 VM: initialized successfully
12:21:16.802 VM: Amd CPU BiosDisabled
12:22:50.215 AVAST engine download error: 0
12:23:26.159 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000028
12:23:26.162 Disk 0 Vendor: Hitachi_ PC3O Size: 305245MB BusType: 11
12:23:26.296 Disk 0 MBR read successfully
12:23:26.305 Disk 0 MBR scan
12:23:26.313 Disk 0 unknown MBR code
12:23:26.329 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
12:23:26.334 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 291062 MB offset 409600
12:23:26.361 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 13879 MB offset 596504576
12:23:26.381 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768
12:23:26.423 Disk 0 scanning C:\WINDOWS\system32\drivers
12:23:34.977 Service scanning
12:23:35.465 Service 3ware C:\WINDOWS\System32\drivers\3ware.sys **LOCKED** 32
12:23:37.911 Service BdfNdisf C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys **LOCKED** 5
12:23:37.972 Service bdfwfpf C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys **LOCKED** 5
12:23:38.019 Service bdfwfpf_pc C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys **LOCKED** 5
12:24:59.018 Modules scanning
12:24:59.026 Disk 0 trace - called modules:
12:24:59.033
12:24:59.039 Disk 0 statistics 136416/0/0 @ 8.85 MB/s
12:24:59.045 Scan finished successfully
12:27:02.744 Disk 0 MBR has been saved successfully to "C:\Users\Hp\Desktop\MBR.dat"
12:27:02.750 The log file has been saved successfully to "C:\Users\Hp\Desktop\aswMBR.txt"
~
Ran by [removed] (administrator) on HP-PC (08-11-2015 12:37:57)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 10 Home (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
(AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(CinemaNow, Inc.) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(PC Tools) C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsd.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
==================== Registry (Whitelisted) ===========================
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\…\Run: [RtkOSD] => C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe [995840 2010-02-05] (Realtek Semiconductor Corp.)
HKLM\…\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-01-27] (Hewlett-Packard)
HKLM\…\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-07-17] (Synaptics Incorporated)
HKLM\…\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe [1603544 2015-10-01] (Bitdefender)
HKLM-x32\…\Run: [SSDMonitor] => C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe [103896 2011-12-12] (PC Tools)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-09-22] (Google Inc.)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [SanDiskSecureAccess_Manager.exe] => C:\Users\Hp\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [27311232 2011-06-29] (Gemalto N.V.)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe [790880 2015-06-18] (Bitdefender)
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\Policies\Explorer: [NoInstrumentation] 1
BootExecute: autocheck autochk * sdnclean64.exe
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{03db8a02-2336-4c54-8b7c-da7fef957d22}: [DhcpNameServer] [removed] [removed]
==================
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPNOT/1
SearchScopes: HKLM-x32 -> {3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6} URL = hxxp://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
SearchScopes: HKLM-x32 -> {BF1D2AD1-927A-4C76-9848-9923A9B74AFB} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3538756054-3176117391-120295970-1000 -> {3D76DEC2-40CD-43D2-9A65-2689D9F2DBA6} URL = hxxp://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
SearchScopes: HKU\S-1-5-21-3538756054-3176117391-120295970-1000 -> {BF1D2AD1-927A-4C76-9848-9923A9B74AFB} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox
BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-10-09] (Bitdefender)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-23] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-10-09] (Bitdefender)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-22] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-22] (Oracle Corporation)
Toolbar: HKLM - No Name - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - No File
Toolbar: HKLM - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-10-09] (Bitdefender)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-23] (Google Inc.)
Toolbar: HKLM-x32 - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll [2015-10-09] (Bitdefender)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-23] (Google Inc.)
Toolbar: HKU\S-1-5-21-3538756054-3176117391-120295970-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-23] (Google Inc.)
DPF: HKLM-x32 {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-10-19] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-19] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2009-07-21] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-22] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-20] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-20] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2010-07-17] (Sun Microsystems, Inc.)
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-09-29] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\\antispam32\bdwteff
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender 2015\\antispam32\bdwteff [2015-10-09] [not signed]
FF HKLM\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext
FF Extension: Bitdefender Antispam Toolbar - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext [2015-07-28] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\\antispam32\bdwteff
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.80\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll => No File
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll => No File
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll => No File
CHR Plugin: (RealJukebox NS Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll => No File
CHR Plugin: (RealPlayer Version Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll => No File
CHR Profile: C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-26]
CHR Extension: (Google Drive) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-29]
CHR Extension: (YouTube) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-26]
CHR Extension: (Google Search) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-26]
CHR Extension: (Google Docs Offline) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-29]
CHR Extension: (Gmail) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-26]
CHR HKLM-x32\…\Chrome\Extension: [fabcmochhfpldjekobfaaggijgohadih] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R2 HPWMISVC; C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [19968 2010-01-12] () [File not signed]
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-02-22] (Hewlett-Packard Company) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-07-31] (Microsoft Corporation)
R2 PCToolsSSDMonitorSvc; C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe [793048 2011-12-12] (PC Tools)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [303360 2015-06-24] (Realtek Semiconductor)
R2 RtVOsdService; C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe [315392 2010-06-24] (Realtek Semiconductor Corp.) [File not signed]
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-07-17] (Synaptics Incorporated)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2015-04-22] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe [1537648 2015-10-01] (Bitdefender)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-07-31] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-07-31] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [271272 2015-05-29] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [747120 2015-05-28] (BitDefender)
U5 bdelam; C:\Windows\System32\Drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2014-12-15] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [115800 2015-05-21] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
R1 BDVEDISK; C:\Windows\system32\DRIVERS\bdvedisk.sys [79192 2013-07-30] (BitDefender)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [160032 2015-10-01] (BitDefender LLC)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2015-11-08] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-07-31] (Microsoft Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [477272 2015-10-01] (BitDefender S.R.L.)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 aswMBR; C:\Users\Hp\AppData\Local\Temp\aswMBR.sys [62728 2015-11-08] () [File not signed]
U3 aswVmm; C:\Users\Hp\AppData\Local\Temp\aswVmm.sys [224896 2015-11-08] ()
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
==================== One Month Created files and folders ========
2015-11-08 12:36 - 2015-11-08 12:38 - 00000000 ____D C:\FRST
2015-11-08 12:33 - 2015-11-08 12:35 - 02198528 _____ (Farbar) C:\Users\Hp\Desktop\FRST64.exe
2015-11-08 12:27 - 2015-11-08 12:27 - 00002032 _____ C:\Users\Hp\Desktop\aswMBR.txt
2015-11-08 12:27 - 2015-11-08 12:27 - 00000512 _____ C:\Users\Hp\Desktop\MBR.dat
2015-11-08 12:18 - 2015-11-08 12:20 - 05198336 _____ (AVAST Software) C:\Users\Hp\Desktop\aswMBR.exe
2015-11-08 11:59 - 2015-11-08 11:59 - 00016148 _____ C:\WINDOWS\system32\HP-PC_Hp_HistoryPrediction.bin
2015-11-08 06:48 - 2015-11-08 06:48 - 00002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-11-04 12:51 - 2015-11-04 12:51 - 00000000 ____D C:\Users\Hp\AppData\Local\CEF
2015-11-04 12:47 - 2015-11-04 12:47 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-11-04 12:46 - 2015-11-04 12:46 - 00002132 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-11-03 16:44 - 2015-11-03 16:45 - 00002360 _____ C:\Users\Hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-10-31 19:00 - 2015-10-31 19:00 - 00000000 ____D C:\Users\Hp\Documents\gmoney disk
2015-10-31 18:40 - 2015-10-31 18:40 - 00063488 _____ C:\Users\Hp\Documents\PAYLIST ANNA CURRENT thumb 11 2015.xls
2015-10-30 13:37 - 2015-10-30 13:37 - 00022738 _____ C:\Users\Hp\Downloads\AZ ASG 9-2015.xlsx
2015-10-30 10:30 - 2015-10-27 16:38 - 21871616 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-30 10:29 - 2015-10-27 16:16 - 18801664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-30 10:29 - 2015-10-21 05:45 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-10-30 10:29 - 2015-10-21 05:44 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-10-30 10:29 - 2015-10-21 05:43 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-30 10:29 - 2015-10-21 05:39 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-10-30 10:29 - 2015-10-21 05:00 - 24595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-30 10:29 - 2015-10-21 05:00 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-30 10:29 - 2015-10-21 04:59 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2015-10-30 10:29 - 2015-10-21 04:57 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-30 10:29 - 2015-10-21 04:52 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-30 10:29 - 2015-10-21 04:50 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-10-30 10:29 - 2015-10-21 04:48 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-30 10:29 - 2015-10-21 04:47 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-10-30 10:29 - 2015-10-21 04:46 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-30 10:29 - 2015-10-21 04:46 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-10-30 10:29 - 2015-10-21 04:44 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-10-30 10:29 - 2015-10-21 04:44 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-30 10:29 - 2015-10-21 04:43 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2015-10-30 10:29 - 2015-10-21 04:42 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-30 10:29 - 2015-10-21 04:41 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-30 10:29 - 2015-10-21 04:40 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2015-10-30 10:29 - 2015-10-21 04:38 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-10-30 10:29 - 2015-10-20 22:53 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-30 10:29 - 2015-10-20 22:49 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-10-30 10:29 - 2015-10-20 22:13 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-30 10:29 - 2015-10-20 22:11 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-30 10:29 - 2015-10-20 22:08 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-30 10:29 - 2015-10-20 22:05 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-30 10:29 - 2015-10-20 22:03 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-10-30 10:29 - 2015-10-20 22:03 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-10-30 10:29 - 2015-10-20 21:58 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2015-10-30 10:29 - 2015-10-20 21:58 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-30 10:29 - 2015-10-20 21:55 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-10-28 14:11 - 2015-10-28 14:11 - 00069632 _____ C:\Users\Hp\Downloads\PrintExportedReport.xls
2015-10-28 14:10 - 2015-10-28 14:10 - 00043520 _____ C:\Users\Hp\Downloads\crt.xls
2015-10-22 11:11 - 2015-10-15 20:10 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-22 11:11 - 2015-10-15 20:10 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-22 10:39 - 2015-10-22 10:38 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-10-19 19:00 - 2015-10-19 19:02 - 00060540 _____ C:\WINDOWS\SysWOW64\AppLog.log
2015-10-19 19:00 - 2015-10-19 19:00 - 00000000 ____D C:\WINDOWS\PCHEALTH
2015-10-19 13:53 - 2015-10-19 13:53 - 00001187 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-10-19 13:53 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-10-19 13:53 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-10-19 13:53 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-10-19 12:18 - 2015-10-10 00:12 - 00078528 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-19 12:18 - 2015-10-05 20:03 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-19 12:18 - 2015-10-05 19:46 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-19 12:18 - 2015-09-30 21:01 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-10-19 12:18 - 2015-09-30 21:01 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-10-19 12:18 - 2015-09-30 21:01 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-10-19 12:18 - 2015-09-30 21:01 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-10-19 12:18 - 2015-09-30 21:00 - 08020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-19 12:18 - 2015-09-30 20:03 - 00757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2015-10-19 12:18 - 2015-09-24 21:01 - 02573768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-10-19 12:18 - 2015-09-24 21:01 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-10-19 12:18 - 2015-09-24 20:56 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-10-19 12:18 - 2015-09-24 20:52 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-10-19 12:18 - 2015-09-24 20:33 - 01997336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-10-19 12:18 - 2015-09-24 20:26 - 20858360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-10-19 12:18 - 2015-09-24 20:11 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-19 12:18 - 2015-09-24 20:11 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-19 12:18 - 2015-09-24 20:09 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-10-19 12:18 - 2015-09-24 20:07 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-19 12:18 - 2015-09-24 20:04 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-10-19 12:18 - 2015-09-24 20:04 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-19 12:18 - 2015-09-24 20:03 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-19 12:18 - 2015-09-24 20:03 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-10-19 12:18 - 2015-09-24 20:02 - 07523840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-19 12:18 - 2015-09-24 20:02 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-10-19 12:18 - 2015-09-24 20:02 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-19 12:18 - 2015-09-24 20:01 - 04792320 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-19 12:18 - 2015-09-24 20:01 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-19 12:18 - 2015-09-24 20:00 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-19 12:18 - 2015-09-24 20:00 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-19 12:18 - 2015-09-24 20:00 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-19 12:18 - 2015-09-24 20:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-19 12:18 - 2015-09-24 19:59 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-19 12:18 - 2015-09-24 19:58 - 01871360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-10-19 12:18 - 2015-09-24 19:47 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-19 12:18 - 2015-09-24 19:47 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 03580416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-19 12:18 - 2015-09-24 19:38 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-10-19 12:18 - 2015-09-24 19:37 - 00766976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-10-19 12:18 - 2015-09-24 19:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-19 12:18 - 2015-09-24 19:37 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-19 12:18 - 2015-09-24 19:36 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-10-19 12:18 - 2015-09-24 19:36 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-19 12:18 - 2015-09-24 19:34 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-19 12:18 - 2015-09-24 19:33 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-19 12:18 - 2015-09-24 19:32 - 01594368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-10-19 12:18 - 2015-09-24 19:32 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-11-08 12:20 - 2010-09-12 15:18 - 00004140 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7D1B5BD6-72C8-4707-9A38-50B0F4CB0C8B}
2015-11-08 12:18 - 2015-07-10 05:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-08 12:13 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-11-08 11:59 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-11-08 11:55 - 2015-01-14 20:18 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-08 06:50 - 2015-09-20 14:45 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-08 06:34 - 2015-09-20 14:45 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cf52901f22c608.job
2015-11-07 14:32 - 2015-07-31 15:29 - 01018274 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-06 13:25 - 2010-03-30 05:37 - 00000000 ____D C:\ProgramData\Temp
2015-11-04 13:03 - 2015-07-31 15:31 - 00000000 ____D C:\Users\Hp
2015-11-04 12:51 - 2014-07-05 08:56 - 00000000 ____D C:\Users\Hp\AppData\Local\Adobe
2015-11-04 12:46 - 2011-09-22 15:31 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-11-04 12:46 - 2010-03-30 05:59 - 00000000 ____D C:\ProgramData\Adobe
2015-11-04 09:49 - 2015-07-10 02:05 - 00065536 ___SH C:\WINDOWS\system32\config\ELAM
2015-11-04 09:48 - 2015-07-10 05:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-04 08:42 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\rescache
2015-11-04 07:06 - 2010-03-30 05:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-04 07:04 - 2013-09-16 13:30 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-11-04 06:48 - 2010-09-12 15:30 - 143481208 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-11-03 16:45 - 2015-07-31 16:12 - 00000000 ___RD C:\Users\Hp\OneDrive
2015-10-31 20:45 - 2015-08-09 14:47 - 00000000 ____D C:\WINDOWS\Minidump
2015-10-31 17:53 - 2015-07-10 02:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-10-31 16:19 - 2015-07-10 05:20 - 00028872 _____ C:\WINDOWS\setupact.log
2015-10-31 16:14 - 2011-09-22 15:33 - 00000000 ____D C:\Users\Hp\AppData\Local\Google
2015-10-31 16:06 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-31 03:32 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-30 10:36 - 2015-07-10 03:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-29 16:03 - 2012-08-18 15:20 - 00000000 ____D C:\Users\Hp\Documents\Anna
2015-10-23 19:53 - 2013-04-26 13:26 - 00002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-10-22 10:39 - 2014-11-16 07:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-10-22 10:39 - 2013-09-16 13:55 - 00000000 ____D C:\ProgramData\Oracle
2015-10-22 10:38 - 2015-08-28 06:33 - 00000000 ____D C:\Users\Hp\.oracle_jre_usage
2015-10-22 10:37 - 2014-11-16 07:00 - 00000000 ____D C:\Program Files (x86)\Java
2015-10-21 06:33 - 2015-07-10 04:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-10-21 03:36 - 2010-09-13 09:08 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-10-21 03:34 - 2015-07-10 05:20 - 04963392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-10-21 03:33 - 2015-01-14 20:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-19 13:53 - 2015-01-14 20:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-10-09 09:15 - 2015-07-31 15:23 - 00062052 _____ C:\WINDOWS\PFRO.log
2014-08-13 01:49 - 2014-08-13 01:49 - 130565325 _____ () C:\Program Files (x86)\openoffice1.cab
2014-08-13 01:48 - 2014-08-13 01:48 - 2310144 _____ () C:\Program Files (x86)\openoffice411.msi
2014-08-13 01:48 - 2014-08-13 01:48 - 0478720 _____ () C:\Program Files (x86)\setup.exe
2014-08-13 01:48 - 2014-08-13 01:48 - 0000279 _____ () C:\Program Files (x86)\setup.ini
2012-03-08 14:18 - 2012-03-08 14:45 - 0000640 _____ () C:\Users\Hp\AppData\Roaming\.backup.dm
2010-09-16 08:23 - 2010-09-16 08:23 - 0000025 _____ () C:\Users\Hp\AppData\Roaming\bdfvconp.ini
2011-02-15 12:36 - 2011-05-17 17:51 - 0001854 _____ () C:\Users\Hp\AppData\Roaming\GhostObjGAFix.xml
2012-08-18 15:13 - 2014-01-16 08:47 - 0002035 _____ () C:\Users\Hp\AppData\Roaming\SAS7_000.DAT
2010-09-20 22:41 - 2015-08-15 15:17 - 0001584 _____ () C:\Users\Hp\AppData\Roaming\wklnhst.dat
2013-06-20 14:25 - 2013-06-20 14:25 - 0003584 _____ () C:\Users\Hp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-30 06:27 - 2015-03-12 06:47 - 0007597 _____ () C:\Users\Hp\AppData\Local\Resmon.ResmonCfg
2015-08-05 16:43 - 2015-08-05 16:43 - 0515580 _____ () C:\ProgramData\1438817797.bdinstall.bin
2011-12-01 12:46 - 2011-12-01 12:46 - 0000057 _____ () C:\ProgramData\Ament.ini
2010-09-13 09:10 - 2010-09-13 09:10 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2010-03-30 06:29 - 2010-03-30 06:29 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2010-03-30 06:21 - 2010-03-30 06:23 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2010-06-20 01:40 - 2010-06-20 01:40 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2010-06-20 01:41 - 2010-06-20 01:41 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2010-03-30 06:21 - 2010-03-30 06:21 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2010-03-30 06:23 - 2010-03-30 06:28 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2010-06-20 01:42 - 2010-06-20 01:42 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-10-31 03:46
~
Ran by [removed] (2015-11-08 12:41:05)
Running from C:\Users\[removed]\Desktop
Windows 10 Home (X64) (2015-07-31 23:04:55)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
ASPNET (S-1-5-21-3538756054-3176117391-120295970-1002 - Limited - Enabled)
BitDefenderComm (S-1-5-21-3538756054-3176117391-120295970-1005 - Limited - Enabled)
DefaultAccount (S-1-5-21-3538756054-3176117391-120295970-503 - Limited - Disabled)
Guest (S-1-5-21-3538756054-3176117391-120295970-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3538756054-3176117391-120295970-1004 - Limited - Enabled)
Hp (S-1-5-21-3538756054-3176117391-120295970-1000 - Administrator - Enabled) => C:\Users\Hp
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antispyware (Enabled - Up to date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46}
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 19.0.0.190 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.)
Adobe Flash Player 19 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Shockwave Player (HKLM-x32\…\{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}) (Version: 11.5.1.601 - Adobe Systems, Inc.)
ATI Catalyst Install Manager (HKLM\…\{C3F0426C-175D-39B7-7A14-D6B21952DE5E}) (Version: 3.0.765.0 - ATI Technologies, Inc.)
Bitdefender Total Security 2015 (HKLM\…\Bitdefender) (Version: 19.2.0.142 - Bitdefender)
Broadcom 802.11 Wireless LAN Adapter (HKLM\…\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.350.6 - Broadcom Corporation)
ccc-core-static (x32 Version: 2010.0310.1824.32984 - ATI) Hidden
CinemaNow Media Manager (HKLM-x32\…\{6C122441-1861-4CD7-B1C5-A163A6984E12}) (Version: 1.9.1.105 - CinemaNow, Inc.)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CyberLink DVD Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.2527 - CyberLink Corp.)
CyberLink MediaShow (HKLM-x32\…\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1307 - CyberLink Corp.)
CyberLink PowerDVD 9 (HKLM-x32\…\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.1.3810 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2511 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
ESU for Microsoft Windows 7 (HKLM-x32\…\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)
Gmail Notifier (HKLM-x32\…\Gmail Notifier) (Version: - )
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 46.0.2490.80 - Google Inc.)
Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6904.2028 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
HP Advisor (HKLM-x32\…\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.4.10262.3295 - Hewlett-Packard)
HP MediaSmart CinemaNow 2.0 (HKLM-x32\…\{9008D736-35CA-40DB-A2BE-5F32D954E5AA}) (Version: 2.0 - Hewlett-Packard)
HP Power Plan Utility (HKLM-x32\…\{F6B6A150-08FA-46D5-808A-EB638269551D}) (Version: 1.0.6 - Hewlett-Packard)
HP Quick Launch (HKLM\…\{6A66C1E5-4146-4CA6-A551-627CFCEACC83}) (Version: 1.0.17 - Hewlett-Packard)
HP Setup (HKLM-x32\…\{E2831862-F131-4327-B9CC-FA30F587EB6C}) (Version: 1.2.3988.3281 - Hewlett-Packard)
HP Software Framework (HKLM-x32\…\{6C872198-9ED1-4046-87B3-AFA79CDF342D}) (Version: 4.0.55.1 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP User Guides 0199 (HKLM-x32\…\{E39CFDC9-F521-4D9C-974B-17E93696FCAB}) (Version: 1.01.0000 - Hewlett-Packard)
HP Wireless Assistant (HKLM\…\{E6BC696E-5E96-4C1B-9371-379AF3A46B6B}) (Version: 4.0.4.2 - Hewlett-Packard)
Java 8 Update 65 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2515 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.2515 - CyberLink Corp.) Hidden
LAME v3.98.3 for Audacity (HKLM-x32\…\LAME for Audacity_is1) (Version: - )
LightScribe System Software (HKLM-x32\…\{6AFDE3BE-BC01-45A4-9D06-BBF5AD207313}) (Version: 1.18.12.1 - LightScribe)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 1.1 (HKLM-x32\…\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft IntelliPoint 8.2 (HKLM\…\Microsoft IntelliPoint 8.2) (Version: 8.20.468.0 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft Office XP Professional (HKLM-x32\…\{91110409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\…\{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Publisher 2010 (HKLM-x32\…\Office14.PUBLISHERR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\…\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\…\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
NOOK for PC (HKLM-x32\…\BN_DesktopReader) (Version: 2.5.6.9575 - Barnesandnoble.com)
OLYMPUS Master 2 (HKLM-x32\…\{3A1AB8E6-748E-4B95-AA2D-FE9952EB3106}) (Version: 1.0.13 - OLYMPUS IMAGING CORP.)
OneClickdigital Media Manager (HKLM-x32\…\{C259BBE2-2531-4387-B5E3-9E6845854272}) (Version: 61.0.0.0 - Recorded Books)
OpenOffice 4.1.1 (HKLM-x32\…\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
PC Tools Registry Mechanic 11.0 (HKLM-x32\…\Registry Mechanic_is1) (Version: 11.0 - PC Tools)
PhotoNow! (HKLM-x32\…\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.6904 - CyberLink Corp.)
PhotoNow! (x32 Version: 1.1.6904 - CyberLink Corp.) Hidden
Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3715 - CyberLink Corp.)
Power2Go (x32 Version: 6.1.3715 - CyberLink Corp.) Hidden
PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.2514 - CyberLink Corp.)
PowerDirector (x32 Version: 8.0.2514 - CyberLink Corp.) Hidden
Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.18.322.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30120 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 5.5.2512 - CyberLink Corp.) Hidden
RtVOsd (HKLM\…\{091A0130-A82F-4A6D-9C61-3BBBB3289030}) (Version: 1.0.6 - Realtek Semiconductor Corp.)
SanDiskSecureAccess_Manager.exe (HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\@@__UNKNOWN__@@SanDiskSecureAccess_Manager.exe) (Version: 1.1.19269 - Gemalto N.V.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-0019-0000-0000-0000000FF1CE}_Office14.PUBLISHERR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)
Skype™ 7.6 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
Sockupied Spring 2012 (HKLM-x32\…\com.interweave.sockupiedspring2012) (Version: 1.0 - Interweave)
Sockupied Spring 2012 (x32 Version: 1.0 - Interweave) Hidden
Sockupied Spring 2014 (HKLM-x32\…\com.interweave.sockupiedspring2014) (Version: 1.0.0 - F+W Media, Inc.)
Sockupied Spring 2014 (x32 Version: 1.0.0 - F+W Media, Inc.) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 19.0.12.95 - Synaptics Incorporated)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM-x32\…\Windows Media Encoder 9) (Version: - )
Zinio Reader 4 (HKLM-x32\…\ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1) (Version: 4.2.3972 - Zinio LLC)
Zinio Reader 4 (x32 Version: 4.2.3972 - Zinio LLC) Hidden
28-10-2015 07:14:18 Scheduled Checkpoint
31-10-2015 16:32:58 Windows Update
04-11-2015 06:43:24 Windows Update
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com
==================== Scheduled Tasks (Whitelisted) =============
Task: {04617C3D-0AA2-4430-818E-8CB903756659} - System32\Tasks\Bitdefender Autoscan => C:\Program Files\Bitdefender\Bitdefender 2013\mtasklaunch.exe
Task: {08F4E36D-9C0C-4CDB-BEA4-0CFDFE55029A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {097C0CAD-A452-4FCA-9EC2-8A1243120586} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {0A8B30C4-99B0-4223-896F-672BD136A109} - System32\Tasks\GoogleUpdateTaskMachineCore1cf52901f22c608 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {0BC18D7C-7A5F-4F0F-A668-DC27642550D6} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {0C267C17-A827-43D9-8CC7-FF88821A2146} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {1287B6D6-B819-48D5-AC88-63D9BF8ABF2D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {189BAE74-F6A0-4910-8D49-5729E8CDED8C} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2DFE12DF-A440-42E9-BC40-2F3F9F5DC28D} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {329EC941-3C94-4072-9691-499DD8E81B3E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {3A140220-8F1E-4E55-8832-B538A52128C1} - System32\Tasks\RMSchedule => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\RegMech.exe [2011-12-12] (PC Tools)
Task: {3D30200F-62B2-4387-8C19-A1B9F1B7D1FC} - System32\Tasks\{44A07CDE-287C-4CE7-97A6-8D22D5215342} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-06-29] (Skype Technologies S.A.)
Task: {3FA86DFB-9864-4979-8C47-3249817D201A} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {4D9F29A1-3231-42E5-B5DF-2F490B362A84} - System32\Tasks\{10BF4766-87F1-4948-AA9D-E4D3D1246EBC} => pcalua.exe -a "C:\Program Files (x86)\OpenOffice.org 3\program\sbase.exe" -d C:\Users\Hp\Documents -c -o "C:\Users\Hp\Documents\Contacts.odb"
Task: {4DDFD1B4-1BFE-4955-9128-EA1C9ED805FF} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {549707FA-A06E-4A13-906B-8BE9FC6E9612} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {5AB2BA6D-C059-4903-8AB8-746B6AA9CA3D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-11-04] (Microsoft Corporation)
Task: {5D468FCA-DFD8-492A-8DDA-533809CF4733} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-08-01] (Microsoft Corporation)
Task: {5D986A82-8659-415E-9C81-5327FB5E4AB9} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {5ED71F25-5E1C-4143-BF72-E119EFA076F9} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {605C087D-0CBA-43D2-B8BC-0DA55E7A8027} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {615F219E-46E9-493A-BE51-43EC9D653E0A} - System32\Tasks\AdobeAAMUpdater-1.0-Hp-PC-Hp => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)
Task: {63F3307B-B920-4508-875F-8DCA42BD54B7} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {6640D516-7877-4E45-BA3F-AA58C73A4FC4} - System32\Tasks\{5087E47C-F4B1-48F2-9D2B-9C7C89061E13} => Iexplore.exe hxxp://ui.skype.com/ui/0/4.1.0.179.271/en/go/help.faq.installer?LastError=1603
Task: {6DAE4147-3132-4B73-AD2A-C543E24DE489} - System32\Tasks\Hewlett-Packard\HP Assistant\HPSA Upgrade => C:\ProgramData\Hewlett-Packard\HPSAUpgrade3\HpSAUpgrade.exe [2011-08-11] (Hewlett-Packard)
Task: {7ED995AB-9353-4D10-9444-8807A11EF13C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {7F6E3D4B-5AFE-4F79-8190-66D15887BEA9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7FDAF8EC-25A4-4509-AACC-D9D27A2A0DAD} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {8C5B60D3-EC95-474B-BC98-5D0895148305} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
Task: {8CB959D3-FAC3-4FC8-8E90-3A1950FB5843} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {990FC820-7C11-4FC8-8626-1C4084ACE5E2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {9D588900-F5E1-41E3-A948-E789C8634327} - System32\Tasks\RMSmartUpdate => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\update.exe [2011-12-12] (PC Tools)
Task: {A213B09B-F624-4C98-B88F-EEBF8BCCA9C3} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {A7368EBD-48F3-4229-999C-109C8602B510} - System32\Tasks\{71C771B6-2EF4-45F3-ACC0-E269B17A5C28} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=4.2.0.187&LastError;=12002
Task: {AA9297E2-887B-4FC6-8777-20000628C6F0} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {AB4A22BA-A58C-4A61-9F99-B581C8B2946A} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {AC3188EF-AD3F-49FE-A907-01EDD4CC941C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {ADA75388-0E9A-463F-ACA4-4ADFBBD55161} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {B810FC5B-74CC-4C29-9F01-B9C0BCAE29B7} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {BE312CE1-03B9-4201-88EB-BAD1C0477C29} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-01-26] ()
Task: {BFD22CE4-E344-452D-8B78-41DC17A7E8F2} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {C55B1ADB-4F73-4F03-86F8-F25D1086E757} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {C5A51B9E-18D1-49AA-BCE3-383952A2BAB2} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
Task: {CA3E495B-2732-49BA-99C1-2B74D00C270A} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {CD385B27-CFED-4827-92F0-DC3161BB82DE} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
Task: {CDBCA0F0-B023-46EE-89AC-722E9C68D8F6} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {CE39CBD4-2EE6-429C-9DA2-C494D4CBFB94} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {D3368AB9-4EBB-47B6-B0BA-5781C8D9E410} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {DD340FA2-5315-471B-A13E-9A7C2260AFF2} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {DD7600F1-B407-4CCF-A569-B33F2CF06CFF} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {DFA008D2-2B42-4D18-9512-3A96F613B1ED} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3538756054-3176117391-120295970-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
Task: {E3860717-FB64-4F1F-B494-8CD9E507D4A3} - System32\Tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8 => C:\Program Files\Bitdefender\Bitdefender 2013\bdproductdata.exe
Task: {E8EB2E3F-133B-4A4E-878A-6983871914D5} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {EE72A342-9164-4832-BD39-615121A416F9} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {F07DB3B7-29BE-4ABA-B956-9C166A778312} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {F15293F1-93B5-4747-A456-DD3DC9D7FDA0} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {F6BA051A-6EF4-45A0-BD0B-579BFA5D11CA} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {F8DC7850-A388-4030-8294-13375FE870CE} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {FB000530-0412-49F2-84CD-6F96E45EA85F} - System32\Tasks\ScanToPCActivationApp.exe_{43A47EB1-B846-4B57-B6B4-5CE877A449A2} => C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cf52901f22c608.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\RMSchedule.job => C:\Program Files (x86)\PC Tools\PC Tools Registry Mechanic\RegMech.exe
2015-08-05 16:41 - 2015-04-22 16:55 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\txmlutil.dll
2015-08-05 16:41 - 2013-09-03 14:29 - 00101328 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdmetrics.dll
2015-08-05 16:41 - 2015-07-28 19:06 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\UI\accessl.ui
2015-08-05 16:41 - 2012-10-29 14:22 - 00152816 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdfwcore.dll
2015-09-05 14:33 - 2015-09-05 14:33 - 00875352 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttpbr.mdl
2015-09-05 14:33 - 2015-09-05 14:33 - 00741952 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttpdsp.mdl
2015-09-05 14:33 - 2015-09-05 14:33 - 02800952 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttpph.mdl
2015-09-05 14:33 - 2015-09-05 14:33 - 01413024 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_01150_005\ashttprbl.mdl
2015-08-19 09:07 - 2015-08-11 02:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2010-01-12 15:44 - 2010-01-12 15:44 - 00019968 _____ () C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
2010-01-27 14:01 - 2010-01-27 14:01 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll
2015-09-30 16:08 - 2015-09-16 23:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2010-01-27 14:01 - 2010-01-27 14:01 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll
2010-01-27 14:01 - 2010-01-27 14:01 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll
2015-09-30 16:08 - 2015-09-16 23:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-09-30 16:08 - 2015-09-16 22:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-09-30 16:09 - 2015-09-16 22:44 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-09-30 16:08 - 2015-09-16 22:42 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-09-30 16:08 - 2015-09-16 22:42 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-09-30 16:08 - 2015-09-16 22:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 04:00 - 2015-07-10 06:14 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
AlternateDataStreams: C:\ProgramData\Temp:5C321E34
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
AlternateDataStreams: C:\Users\Hp\Downloads\bitdefender_tsecurity (1).exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\GoogleEarthSetup.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\Lame_v3.98.3_for_Audacity_on_Windows.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\Microsoft_Publisher_2010_2_PC_1_User_Downloader.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\OneClickdigital Media Manager Installer.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\rminstall.exe:BDU
AlternateDataStreams: C:\Users\Hp\Downloads\spybotsd162.exe:BDU
==================== EXE Association (Whitelisted) ===============
==================== Internet Explorer trusted/restricted ===============
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\1-2005-search.com -> www.1-2005-search.com
==================== Other Areas ============================
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
MSCONFIG\startupfolder: C:^Users^Hp^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk => C:\Windows\pss\OpenOffice.org 3.2.lnkStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher =>
MSCONFIG\startupreg: HP Quick Launch => C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: HPAdvisorDock => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
MSCONFIG\startupreg: LightScribe Control Panel => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
MSCONFIG\startupreg: OM2_Monitor => "C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
MSCONFIG\startupreg: SunJavaUpdateSched =>
MSCONFIG\startupreg: TkBellExe =>
HKLM\…\StartupApproved\Run: => "IntelliPoint"
HKLM\…\StartupApproved\Run32: => "SSDMonitor"
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\StartupApproved\Run: => "SpybotPostWindows10UpgradeReInstall"
HKU\S-1-5-21-3538756054-3176117391-120295970-1000\…\StartupApproved\Run: => "SanDiskSecureAccess_Manager.exe"
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{5C670AB1-8442-4DF8-B0DF-30EE69F856DA}] => (Allow) LPort=1900
FirewallRules: [{959ADFA3-811A-4A57-BB5B-7747B726D55B}] => (Allow) LPort=2869
FirewallRules: [{1051274C-8BC4-4E18-852D-EEFE0436F0E1}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{8409542A-67FC-4DDE-8960-B5708BA132D9}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{8BAD2BB1-072F-40FC-A936-C7053AC269EE}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD9.EXE
FirewallRules: [{6BBBAE71-A4C5-4E0D-97C5-B3BA12DF8F5D}] => (Allow) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe
FirewallRules: [{3953E48E-2CAD-4ACB-91A1-9F2718A3038D}] => (Allow) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe
FirewallRules: [{112E6941-3815-4FF7-8BD9-385548D1A39A}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\MediaSmart\CinemaNow\CinemaNow.exe
FirewallRules: [{A5CCD263-2F9D-4620-A201-4A20A02604CF}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\MediaSmart\CinemaNow\CinemaNow.exe
FirewallRules: [{DA5D497C-27F9-41C0-87AA-D8D68B083CF6}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE
FirewallRules: [{D46F22B5-0E6E-44E5-AF05-D3E4237578A0}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{E80BF42B-A1DD-44CE-8476-610F88E20459}] => (Allow) svchost.exe
FirewallRules: [{A0066F71-6931-4B67-86F3-D362380B3497}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [TCP Query User{407D1FDC-0F11-4AB1-924A-CF8B47E7DA60}C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe] => (Block) C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe
FirewallRules: [UDP Query User{35B25721-3AD1-4C8D-98B6-8C1E1C24EC85}C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe] => (Block) C:\users\hp\appdata\local\temp\rarsfx0\x32\pcsftool.exe
FirewallRules: [TCP Query User{A7984981-4F39-4AF6-AB7F-21988A15F0A6}C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe] => (Allow) C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe
FirewallRules: [UDP Query User{497A74C2-93CF-4A4D-9BE5-74EEDD14C1D9}C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe] => (Allow) C:\users\hp\appdata\local\temp\rarsfx0\x64\pcsftool.exe
FirewallRules: [{4CC6C5EC-231F-4226-8D97-BC6FCF42B5AD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Event log errors: =========================
==================
Error: (11/08/2015 12:18:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.10240.16431 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147024865 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Description: Activation of app Microsoft.LockApp_cw5n1h2txyewy!WindowsDefaultLockScreen failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Description: The program LockApp.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Description: App Microsoft.LockApp_10.0.10240.16384_neutral__cw5n1h2txyewy+WindowsDefaultLockScreen did not launch within its allotted time.
Description: Product: Adobe Acrobat Reader DC - Update '{AC76BA86-7AD7-0000-2550-AC0F094E6D00}' could not be installed. Error code 1625. Additional information is available in the log file C:\Users\Hp\AppData\Local\Temp\MSI35b56.LOG.
Description: The program ShellExperienceHost.exe version 10.0.10240.16515 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Description: Package Microsoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy+App was terminated because it took too long to suspend.
Description: Faulting application name: atibtmon.exe, version: 2.0.0.0, time stamp: 0x4a04ab6c
Faulting module name: atibtmon.exe, version: 2.0.0.0, time stamp: 0x4a04ab6c
Exception code: 0x40000015
Fault offset: 0x000081c5
Faulting process id: 0x2688
Faulting application start time: 0xatibtmon.exe0
Faulting application path: atibtmon.exe1
Faulting module path: atibtmon.exe2
Report Id: atibtmon.exe3
Faulting package full name: atibtmon.exe4
Faulting package-relative application ID: atibtmon.exe5
Description: The program SearchUI.exe version 10.0.10240.16515 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
System errors:
=============
Error: (11/08/2015 11:55:23 AM) (Source: DCOM) (EventID: 10001) (User: Hp-PC)
Description: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXwmnqm0nvq2b90pwvr42qmtdjp7cj3w82.mca31App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mcaUnavailableUnavailable
Description: 4
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AdobeARMservice service.
Description: The User Data Access_Session3 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Description: The User Data Storage_Session3 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Description: The Contact Data_Session3 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Description: The Sync Host_Session3 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the BITS service.
Description: The User Data Access_Session2 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Description: The User Data Storage_Session2 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
CodeIntegrity:
===================================
Date: 2015-10-31 09:50:29.875
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.
==================== Memory info ===========================
Percentage of memory in use: 66%
Total physical RAM: 3834.9 MB
Available physical RAM: 1301.25 MB
Total Virtual: 7674.9 MB
Available Virtual: 4319.91 MB
Drive d: (RECOVERY) (Fixed) (Total:13.55 GB) (Free:1.9 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
Disk: 0 (Size: 298.1 GB) (Disk ID: 099563F6)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=284.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=13.6 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=103 MB) - (Type=0C)
Thanks for taking the time to look this over and let me know how I should proceed.
Thank you!