This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows Vista Basic Home Edition Freezing [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thank you for your help. 

I've been experiencing freezing while using the following browsers:  IE9, Chrome Version 47.0.2526.106 m

 

These are the scan logs

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software

Run date: 2015-12-20 23:09:13
—————————–
23:09:13.938    OS Version: Windows 6.0.6002 Service Pack 2
23:09:13.938    Number of processors: 2 586 0x170A
23:09:13.938    ComputerName: LINDA-PC  UserName: Linda
23:09:14.890    Initialize success
23:09:14.952    VM: initialized successfully
23:09:14.968    VM: Intel CPU virtualization not supported 
23:10:15.596    AVAST engine defs: 15122000
23:16:36.626    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
23:16:36.642    Disk 0 Vendor: TOSHIBA_ FG00 Size: 238475MB BusType: 3
23:16:36.860    Disk 0 MBR read successfully
23:16:36.860    Disk 0 MBR scan
23:16:36.860    Disk 0 Windows VISTA default MBR code
23:16:36.876    Disk 0 Partition 1 00     DE Dell Utility Dell 8.0       39 MB offset 63
23:16:36.907    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        15000 MB offset 81920
23:16:36.922    Disk 0 Partition 3 80 (A) 07    HPFS/NTFS NTFS       223434 MB offset 30801920
23:16:36.938    Disk 0 scanning sectors +488395120
23:16:37.203    Disk 0 scanning C:\Windows\system32\drivers
23:17:07.246    Service scanning
23:17:36.573    Service MpKslf2f09ee7 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C7139CD9-5C13-4B4E-8F1E-3F83C67C03C3}\MpKslf2f09ee7.sys **LOCKED** 32
23:18:06.932    Modules scanning
23:18:06.932    Disk 0 trace - called modules:
23:18:06.978    ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll 
23:18:06.978    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85977ac8]
23:18:06.978    3 CLASSPNP.SYS[89fa38b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x84f4b028]
23:18:08.226    AVAST engine scan C:\Windows
23:18:19.705    AVAST engine scan C:\Windows\system32
23:24:27.705    AVAST engine scan C:\Windows\system32\drivers
23:24:58.123    AVAST engine scan C:\Users\Linda.Linda-PC
00:51:02.236    AVAST engine scan C:\ProgramData
01:05:08.081    Disk 0 statistics 4357152/0/0 @ 0.43 MB/s
01:05:08.096    Scan finished successfully
01:06:10.561    Disk 0 MBR has been saved successfully to "C:\Users\Linda.Linda-PC\Documents\troubleshooting\MBR.dat"
01:06:10.639    The log file has been saved successfully to "C:\Users\Linda.Linda-PC\Documents\troubleshooting\aswMBR.txt"
01:09:05.232    Disk 0 MBR has been saved successfully to "C:\Users\Linda.Linda-PC\Documents\troubleshooting\MBR.dat"
01:09:05.435    The log file has been saved successfully to "C:\Users\Linda.Linda-PC\Documents\troubleshooting\aswMBR.txt"
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:20-12-2015
Ran by [removed] (administrator) on LINDA-PC (21-12-2015 00:50:05)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
() C:\WINDOWS\System32\WLTRYSVC.EXE
(Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
(Dell Inc.) C:\WINDOWS\System32\BCMWLTRY.EXE
(Andrea Electronics Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\WINDOWS\System32\igfxsrvc.exe
(Dell Inc.) C:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
() C:\Program Files\Canon\IJPLM\ijplmsvc.exe
(COMPANYVERS_NAME) C:\Program Files\RecipeHub_2j\bar\1.bin\2jbarsvc.exe
(SoftThinks SAS) C:\Program Files\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(SoftThinks - Dell) C:\Program Files\Dell DataSafe Local Backup\Toaster.exe
() C:\Program Files\Dell DataSafe Local Backup\Components\scheduler\STService.exe
(SoftThinks - Dell) C:\Program Files\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Users\Linda.Linda-PC\Downloads\aswMBR.exe
(Microsoft Corporation) C:\WINDOWS\System32\cleanmgr.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2009-07-07] (Citrix Online, a division of Citrix Systems, Inc.)
HKLM\…D6A79037F57F\InprocServer32: [Default-fastprox] ATTENTION! ====> ZeroAccess?
HKU\S-1-5-18\…\Run: [GarminExpressTrayApp] => C:\Program Files\Garmin\Express Tray\ExpressTray.exe [1403304 2015-10-29] (Garmin Ltd. or its subsidiaries)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\RA Media Server\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{C7F26639-2C1A-4FE2-AA45-8D9D300C51D8}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{E10DCCCB-A154-45DA-88BC-E56EC0A35C8A}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.coupons.com/
HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.coupons.com/
HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/USCON/1
URLSearchHook: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 - (No Name) - {cc8ae5b8-005b-4b1a-a27d-307eddffe5c8} - C:\Program Files\RecipeHub_2j\bar\1.bin\2jSrcAs.dll (MindSpark)
SearchScopes: HKLM -> {9230cb90-79de-4945-88a4-762244a25bc8} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=YKxdm069YYus&ptb;=FA41D754-6CE1-4984-8F9D-E59FAED37725&ind;=2012041315&ptnrS;=YKxdm069YYus&si;=google_people&n;=77ed5063&psa;=&st;=sb&searchfor;={searchTerms}
SearchScopes: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> DefaultScope {12696EE3-C065-4036-A844-31F773CCB8D3} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=DLCDF7&pc;=MDDC&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> {12696EE3-C065-4036-A844-31F773CCB8D3} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=DLCDF7&pc;=MDDC&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> {9230cb90-79de-4945-88a4-762244a25bc8} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=YKxdm069YYus&ptb;=FA41D754-6CE1-4984-8F9D-E59FAED37725&ind;=2012041315&ptnrS;=YKxdm069YYus&si;=google_people&n;=77ed5063&psa;=&st;=sb&searchfor;={searchTerms}
BHO: Toolbar BHO -> {06e3475c-5521-4de8-bb12-50720f21631c} -> C:\Program Files\RecipeHub_2j\bar\1.bin\2jbar.dll [2012-04-13] (MindSpark)
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27] (Adobe Systems Incorporated)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-11] (Oracle Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
BHO: Search Assistant BHO -> {b7acdf9c-c4f9-4d5d-998e-b147866b4d4c} -> C:\Program Files\RecipeHub_2j\bar\1.bin\2jSrcAs.dll [2012-04-13] (MindSpark)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-11] (Oracle Corporation)
BHO: TBSB07898 Class -> {FCBCCB87-9224-4B8D-B117-F56D924BEB18} -> C:\Program Files\Coupons.com CouponBar\tbcore3.dll [2013-07-15] ()
Toolbar: HKLM - Recipe Hub - {cf51de5b-eb36-4114-bb69-84df63fbadb4} - C:\Program Files\RecipeHub_2j\bar\1.bin\2jbar.dll [2012-04-13] (MindSpark)
Toolbar: HKLM - Coupons.com CouponBar - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll [2013-07-15] ()
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
Toolbar: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
DPF: {10B05D6E-5BFB-11D4-8920-00C04F57BB26} hxxps://imetlife.metlife.com/siteminderagent/forms/singlesignon/KeyMasterObj.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
 
FireFox:
========
FF ProfilePath: C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default
FF NewTab: about:blank
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google
FF SearchEngineOrder.3: Bing 
FF SelectedSearchEngine: Google
FF Homepage: www.google.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-17] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=10.10.2 -> C:\Windows\system32\npDeployJava1.dll [2013-01-11] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.10.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-01-11] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @RecipeHub_2j.com/Plugin -> C:\Program Files\RecipeHub_2j\bar\1.bin\NP2jStub.dll [2012-04-13] (MindSpark)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-17] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-07-27] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1549655542-3693215259-3179495191-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-1549655542-3693215259-3179495191-1000: CouponNetwork.com/CMDUniversalCouponPrintActivator -> C:\Users\LINDA~1.LIN\AppData\Roaming\CATALI~1\NPBCSK~1.DLL [2013-06-07] (Catalina Marketing Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2013-08-02] (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Linda.Linda-PC\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-12-15] (Cisco WebEx LLC)
FF SearchPlugin: C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\ask-web-search.xml [2014-12-26]
FF SearchPlugin: C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\bingp.xml [2013-12-16]
FF SearchPlugin: C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\web-search.xml [2013-11-04]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-02-02] [not signed]
FF HKLM\…\Firefox\Extensions: [2jffxtbr@RecipeHub_2j.com] - C:\Program Files\RecipeHub_2j\bar\1.bin
FF Extension: Recipe Hub - C:\Program Files\RecipeHub_2j\bar\1.bin [2012-04-13] [not signed]
FF HKLM\…\Firefox\Extensions: [{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}] - C:\Program Files\Coupons.com CouponBar\firefox\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}\Coupons.com.xpi
FF Extension: Coupons.com CouponBar - C:\Program Files\Coupons.com CouponBar\firefox\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}\Coupons.com.xpi [2013-07-15] [not signed]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2014-08-01]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.ebay.com/
CHR Profile: C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-15]
CHR Extension: (Google Docs) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-15]
CHR Extension: (Google Drive) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-15]
CHR Extension: (YouTube) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-15]
CHR Extension: (Google Search) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-15]
CHR Extension: (Google Sheets) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-15]
CHR Extension: (Google Docs Offline) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-15]
CHR Extension: (Gmail) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-15]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [81920 2009-03-31] (Andrea Electronics Corporation)
S2 Apache2.2; C:\Program Files\Common Files\Dell\apache\bin\httpd.exe [15872 2007-09-21] (Apache Software Foundation) [File not signed]
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-12-18] (Stardock Corporation) [File not signed]
S2 dsl-db; C:\Program Files\Common Files\Dell\MySQL\bin\mysqld.exe [5730304 2007-09-14] () [File not signed]
S2 dsl-fs-sync; C:\Program Files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe [189680 2009-04-13] (SingleClick Systems)
S3 GameConsoleService; C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe [242424 2008-11-03] (WildTangent, Inc.)
S2 Garmin Device Interaction Service; C:\Program Files\Garmin\Device Interaction Service\GarminService.exe [777744 2015-10-29] (Garmin Ltd. or its subsidiaries)
S3 GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [16680 2009-07-07] (Citrix Online, a division of Citrix Systems, Inc.)
R2 hnmsvc; c:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe [828656 2009-04-13] (Dell Inc.)
R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.226\McCHSvc.exe [235696 2015-10-30] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RecipeHub_2jService; C:\Program Files\RecipeHub_2j\bar\1.bin\2jbarsvc.exe [42504 2012-04-13] (COMPANYVERS_NAME)
R2 SftService; C:\Program Files\Dell DataSafe Local Backup\sftservice.EXE [1692480 2011-08-18] (SoftThinks SAS)
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe [254042 2009-03-31] (IDT, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [2809856 2008-12-21] (Dell Inc.) [File not signed]
R2 yksvc; RUNDLL32.EXE ykx32coinst,serviceStartProc [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2008-12-21] (Broadcom Corporation)
S3 DellBIOS; C:\Windows\DellBIOS.Sys [7168 2015-12-20] () [File not signed]
R3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [35776 2013-09-23] (hxxp://libusb-win32.sourceforge.net)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
R1 MpKslf2f09ee7; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C7139CD9-5C13-4B4E-8F1E-3F83C67C03C3}\MpKslf2f09ee7.sys [39168 2015-12-20] (Microsoft Corporation)
R3 OA009Ufd; C:\Windows\System32\DRIVERS\OA009Ufd.sys [133632 2009-03-06] (Creative Technology Ltd.)
R3 OA009Vid; C:\Windows\System32\DRIVERS\OA009Vid.sys [271552 2009-03-19] (Creative Technology Ltd.)
R2 Packet; C:\Windows\System32\DRIVERS\packet.sys [22016 2008-06-17] (SingleClick Systems)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 PCD5SRVC{3F6A8B78-EC003E00-05040104}; \??\C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [X]
U3 aswMBR; \??\C:\Users\LINDA~1.LIN\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\LINDA~1.LIN\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-21 00:50 - 2015-12-21 00:51 - 00020300 _____ C:\Users\Linda.Linda-PC\Downloads\FRST.txt
2015-12-21 00:49 - 2015-12-21 00:50 - 00000000 ____D C:\FRST
2015-12-21 00:48 - 2015-12-21 00:48 - 01721344 _____ (Farbar) C:\Users\Linda.Linda-PC\Downloads\FRST.exe
2015-12-20 23:45 - 2015-12-20 23:46 - 00000000 ____D C:\Users\Linda.Linda-PC\Documents\troubleshooting
2015-12-20 23:06 - 2015-12-20 23:06 - 00000512 _____ C:\Users\Linda.Linda-PC\Documents\MBR.dat
2015-12-20 22:38 - 2015-12-20 22:38 - 00139512 _____ C:\Windows\Minidump\Mini122015-01.dmp
2015-12-20 22:23 - 2015-12-20 22:24 - 05198336 _____ (AVAST Software) C:\Users\Linda.Linda-PC\Downloads\aswMBR.exe
2015-12-20 22:06 - 2015-12-20 22:06 - 01162486 _____ C:\Users\Linda.Linda-PC\Downloads\1545_A14 (1).EXE
2015-12-20 22:05 - 2015-12-20 22:05 - 01162486 _____ C:\Users\Linda.Linda-PC\Downloads\1545_A14.EXE
2015-12-20 22:05 - 2015-12-20 22:05 - 00007168 _____ C:\Windows\DellBIOS.Sys
2015-12-20 21:53 - 2015-12-20 21:54 - 49934552 _____ (Microsoft Corporation) C:\Users\Linda.Linda-PC\Downloads\Windows-KB890830-V5.31.exe
2015-12-20 21:18 - 2015-12-20 21:18 - 00000000 ____D C:\Users\Linda.Linda-PC\{b1967a33-da0b-4955-a208-b043aa2fbe2e}
2015-12-20 21:18 - 2015-10-28 00:20 - 00031992 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\pcdrndisprot.sys
2015-12-20 21:09 - 2015-12-20 21:09 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\LocalLow\PCDr
2015-12-20 21:09 - 2015-12-20 21:09 - 00000000 ____D C:\ProgramData\PC-Doctor for Windows
2015-12-20 21:01 - 2015-12-20 21:01 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\PCDr
2015-12-20 21:00 - 2015-12-20 21:00 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
2015-12-20 21:00 - 2015-12-20 21:00 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Deployment
2015-12-20 21:00 - 2015-12-20 21:00 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Apps\2.0
2015-12-20 20:59 - 2015-12-20 20:59 - 00417064 _____ () C:\Users\Linda.Linda-PC\Downloads\DellSystemDetectLauncher.exe
2015-12-20 20:20 - 2015-12-20 20:20 - 00247183 _____ C:\Users\Linda.Linda-PC\Documents\bookmarks_12_20_15.html
2015-12-17 22:54 - 2015-12-17 22:54 - 00143728 _____ C:\Windows\Minidump\Mini121715-01.dmp
2015-12-17 08:48 - 2015-12-17 08:48 - 00000000 ____D C:\Windows\pss
2015-12-17 08:42 - 2015-12-17 08:43 - 07708304 _____ (McAfee, Inc.) C:\Users\Linda.Linda-PC\Downloads\Setup_serial_oeXOdgfIjbW_srLLuxULNQ2_key.exe
2015-12-17 08:42 - 2015-12-17 08:42 - 00001973 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-17 08:42 - 2015-12-17 08:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-17 06:19 - 2015-12-17 06:19 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-12-17 02:07 - 2015-12-17 02:07 - 00000000 __SHD C:\found.002
2015-12-16 21:14 - 2015-12-16 21:14 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\McAfee File Lock
2015-12-16 21:12 - 2015-12-16 21:12 - 00000000 ____D C:\Program Files\McAfee.com
2015-12-16 21:01 - 2015-12-16 22:50 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\LogMeIn Rescue Applet
2015-12-16 20:55 - 2015-12-16 21:14 - 00000000 ____D C:\Program Files\Common Files\McAfee
2015-12-16 20:55 - 2015-12-16 20:57 - 00000000 ____D C:\Program Files\stinger
2015-12-16 19:18 - 2015-12-16 19:18 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox(88)
2015-12-15 22:47 - 2015-12-15 22:47 - 00000046 _____ C:\Users\Linda.Linda-PC\Desktop\eBay.url
2015-12-15 22:40 - 2015-12-15 22:40 - 00000000 ____D C:\ProgramData\BSD
2015-12-15 22:38 - 2015-12-15 22:45 - 00000000 ____D C:\Program Files\TweakBit
2015-12-15 22:38 - 2015-12-15 22:39 - 00000000 ____D C:\ProgramData\TweakBit
2015-12-15 21:53 - 2015-12-15 21:53 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\McAfee
2015-12-15 21:52 - 2015-12-16 22:53 - 00000000 ____D C:\Program Files\McAfee
2015-12-15 20:42 - 2015-12-15 20:42 - 00000000 __SHD C:\found.001
2015-12-13 13:48 - 2015-12-13 13:48 - 00000000 __SHD C:\found.000
2015-12-13 01:15 - 2015-12-13 01:15 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox(84)
2015-12-07 13:46 - 2015-12-07 13:46 - 01958689 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(28)
2015-12-07 13:16 - 2015-12-07 13:16 - 00999116 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(27)
2015-12-04 16:36 - 2015-12-04 16:36 - 02956605 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(26)
2015-12-03 00:14 - 2015-12-03 00:14 - 00999469 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(25)
2015-12-02 16:39 - 2015-12-02 16:39 - 01959030 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(24)
2015-12-02 16:19 - 2015-12-02 16:19 - 00999491 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(23)
2015-11-24 21:04 - 2015-11-24 21:04 - 00436946 _____ C:\Users\Linda.Linda-PC\Downloads\310382351392
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-21 00:49 - 2006-11-02 06:18 - 00000000 ____D C:\WINDOWS
2015-12-21 00:38 - 2006-11-02 07:45 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-21 00:38 - 2006-11-02 07:45 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-21 00:13 - 2015-06-20 15:37 - 00000936 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job
2015-12-21 00:13 - 2012-08-22 14:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-21 00:03 - 2012-02-27 19:19 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-20 23:05 - 2012-08-23 22:00 - 00000946 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job
2015-12-20 23:05 - 2012-08-23 22:00 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job
2015-12-20 22:39 - 2012-02-27 19:19 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-20 22:39 - 2009-07-07 09:52 - 00000000 ____D C:\ProgramData\TEMP
2015-12-20 22:39 - 2009-07-07 09:43 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2015-12-20 22:39 - 2009-07-07 09:43 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2015-12-20 22:39 - 2009-07-07 09:34 - 00000000 ____D C:\Program Files\Dell DataSafe Local Backup
2015-12-20 22:38 - 2014-03-01 20:13 - 180572403 _____ C:\Windows\MEMORY.DMP
2015-12-20 22:38 - 2014-03-01 20:13 - 00000000 ____D C:\Windows\Minidump
2015-12-20 22:38 - 2006-11-02 07:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-20 22:25 - 2009-09-24 19:45 - 00913204 _____ C:\Windows\ntbtlog.txt
2015-12-20 21:35 - 2006-11-02 07:58 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-12-20 21:18 - 2013-10-19 13:26 - 00000000 ____D C:\Temp
2015-12-20 21:18 - 2012-01-31 22:40 - 00000000 ____D C:\Users\Linda.Linda-PC
2015-12-20 21:18 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\inf
2015-12-20 21:09 - 2012-01-31 22:40 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Dell
2015-12-20 21:09 - 2009-07-07 09:36 - 00000000 ____D C:\ProgramData\PCDr
2015-12-20 21:09 - 2009-07-07 09:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2015-12-20 21:08 - 2009-07-07 09:36 - 00000000 ____D C:\Program Files\Dell Support Center
2015-12-20 21:06 - 2009-07-07 09:16 - 00000000 ____D C:\Program Files\Dell
2015-12-20 21:04 - 2009-07-07 11:37 - 00000000 ____D C:\DELL
2015-12-20 21:04 - 2009-07-07 09:35 - 00000000 ____D C:\ProgramData\Dell
2015-12-20 20:16 - 2006-11-02 05:33 - 00759542 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-17 20:13 - 2012-08-22 14:35 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-12-17 20:13 - 2012-02-27 19:18 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-12-17 08:33 - 2014-09-07 10:29 - 00000000 ___RD C:\Users\Linda.Linda-PC\Dropbox
2015-12-17 08:33 - 2014-09-07 10:25 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox
2015-12-17 06:09 - 2009-07-07 09:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Remote Access
2015-12-17 06:09 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\Msdtc
2015-12-17 06:08 - 2012-02-02 07:05 - 00000000 ____D C:\Users\RA Media Server
2015-12-17 06:08 - 2006-11-02 05:22 - 46137344 _____ C:\Windows\system32\config\software_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 43778048 _____ C:\Windows\system32\config\components_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 15466496 _____ C:\Windows\system32\config\system_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\default_previous
2015-12-17 06:07 - 2015-11-06 21:40 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-12-17 06:07 - 2012-08-22 14:35 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2015-12-17 06:07 - 2012-08-21 15:24 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-12-17 06:07 - 2012-02-28 21:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-12-17 06:07 - 2012-01-31 23:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-12-17 06:07 - 2012-01-31 22:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2015-12-17 06:07 - 2009-07-07 09:40 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-12-17 06:07 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Dell Remote Access
2015-12-17 06:07 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Common Files\Dell
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 __RSD C:\Windows\Media
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\spool
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\rescache
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-12-17 06:06 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\registration
2015-12-17 02:02 - 2009-07-07 09:48 - 00000000 ____D C:\ProgramData\McAfee
2015-12-16 19:11 - 2013-07-15 02:01 - 00000000 ____D C:\Windows\system32\MRT
2015-12-15 23:50 - 2012-02-27 19:18 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Google
2015-12-15 22:31 - 2012-02-01 08:50 - 00000000 ____D C:\Program Files\Google
2015-12-15 21:41 - 2015-10-18 21:33 - 00000000 ____D C:\Program Files\McAfee Security Scan
2015-12-15 21:03 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Common Files\Dell(2)
2015-12-15 19:48 - 2012-02-03 06:04 - 00006080 _____ C:\Users\Linda.Linda-PC\AppData\Local\d3d9caps.dat
2015-12-10 03:45 - 2015-08-29 13:47 - 00000000 ____D C:\ProgramData\CanonIJPLM
2015-12-08 22:39 - 2012-05-27 15:14 - 00247976 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-12-03 16:08 - 2015-06-20 15:37 - 00000884 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job
2015-11-23 19:09 - 2006-11-02 05:24 - 137798368 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
 
==================== Files in the root of some directories =======
 
2013-11-04 13:41 - 2013-11-04 13:41 - 0893239 _____ () C:\Users\Linda.Linda-PC\AppData\Local\a.zip
2013-11-04 13:41 - 2013-11-04 13:41 - 2162416 _____ (Catalina Marketing Corp) C:\Users\Linda.Linda-PC\AppData\Local\BcsKtYcHW.dll
2012-02-03 06:04 - 2015-12-15 19:48 - 0006080 _____ () C:\Users\Linda.Linda-PC\AppData\Local\d3d9caps.dat
2012-01-31 22:48 - 2015-11-07 15:34 - 0018944 _____ () C:\Users\Linda.Linda-PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-29 18:33 - 2015-08-29 15:00 - 0007084 _____ () C:\ProgramData\hpzinstall.log
 
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1549655542-3693215259-3179495191-1000\$1275ff5241a28249602b776eb539b742
 
ZeroAccess:
C:\$Recycle.Bin\S-1-5-18\$1275ff5241a28249602b776eb539b742
 
Some files in TEMP:
====================
C:\Users\Linda.Linda-PC\AppData\Local\Temp\converter.exe
C:\Users\Linda.Linda-PC\AppData\Local\Temp\Couponscom.exe
C:\Users\Linda.Linda-PC\AppData\Local\Temp\DefaultPack.exe
C:\Users\Linda.Linda-PC\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpyqxbod.dll
C:\Users\Linda.Linda-PC\AppData\Local\Temp\GoogleToolbarInstaller_en32_signed.exe
C:\Users\Linda.Linda-PC\AppData\Local\Temp\InstallFlashPlayer.exe
C:\Users\Linda.Linda-PC\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Linda.Linda-PC\AppData\Local\Temp\jre-8u66-windows-au.exe
C:\Users\Linda.Linda-PC\AppData\Local\Temp\ose00000.exe
C:\Users\Linda.Linda-PC\AppData\Local\Temp\uninstall.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-12-20 22:48
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version:20-12-2015
Ran by [removed] (2015-12-21 00:52:01)
Running from C:\Users\[removed]\Downloads
Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) (2009-07-07 09:02:45)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1549655542-3693215259-3179495191-500 - Administrator - Disabled)
Guest (S-1-5-21-1549655542-3693215259-3179495191-501 - Limited - Disabled)
Linda (S-1-5-21-1549655542-3693215259-3179495191-1000 - Administrator - Enabled) => C:\Users\Linda.Linda-PC
RA Media Server (S-1-5-21-1549655542-3693215259-3179495191-1001 - Administrator - Enabled) => C:\Users\RA Media Server
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
Acrobat.com (HKLM\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated)
Acrobat.com (Version: 0.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM\…\Adobe AIR) (Version: 1.0.4990 - Adobe Systems Inc.)
Adobe Flash Player 20 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 20.0.0.228 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated)
Adobe Reader X (10.1.4) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.4 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
ANT Drivers Installer x86 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (HKLM\…\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Banctec Service Agreement (HKLM\…\{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}) (Version: 2.0.0 - Dell Inc.)
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Canon Easy-WebPrint EX (HKLM\…\Easy-WebPrint EX) (Version: 1.6.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM\…\Canon_IJ_Network_Scanner_Selector_EX) (Version: 1.5.2.3 - Canon Inc.)
Canon IJ Network Tool (HKLM\…\Canon_IJ_Network_UTILITY) (Version: 3.5.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM\…\Canon_IJ_Scan_Utility) (Version: 1.1.10.15 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\…\CANONIJPLM100) (Version: 4.2.0 - Canon Inc.)
Canon MG6600 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6600_series) (Version: 1.01 - Canon Inc.)
Canon MG6600 series On-screen Manual (HKLM\…\Canon MG6600 series On-screen Manual) (Version: 7.7.0 - Canon Inc.)
Canon MG6600 series User Registration (HKLM\…\Canon MG6600 series User Registration) (Version:  - ‭Canon Inc.)
Canon My Printer (HKLM\…\CanonMyPrinter) (Version: 3.2.1 - Canon Inc.)
Canon Quick Menu (HKLM\…\CanonQuickMenu) (Version: 2.6.0 - Canon Inc.)
Catalina Savings Printer (HKLM\…\{37331C16-3E97-4A20-80D8-BFB43AB0E2FB}) (Version: 1.0.0 - Catalina Marketing Corp) <==== ATTENTION
Choice Guard (Version: 1.2.87.0 - Microsoft Corporation) Hidden
Cisco EAP-FAST Module (HKLM\…\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\…\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\…\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.)
Cisco WebEx Meetings (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Coupon Printer for Windows (HKLM\…\Coupon Printer for Windows5.0.0.4) (Version: 5.0.0.4 - Coupons.com Incorporated)
CouponBar (HKLM\…\CouponBar5.0.0.4) (Version: 5.0.0.4 - Coupons.com Incorporated) <==== ATTENTION
CutePDF Writer 3.0 (HKLM\…\CutePDF Writer Installation) (Version:  3.0 - Acro Software Inc.)
Dell DataSafe Local Backup - Support Software (HKLM\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell)
Dell DataSafe Local Backup (HKLM\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell)
Dell DataSafe Online (HKLM\…\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.1.0027 - Dell, Inc.)
Dell Dock (HKLM\…\{F6CB42B9-F033-4152-8813-FF11DA8E6A78}) (Version: 1.0.0 - Dell)
Dell Edoc Viewer (HKLM\…\{3138EAD3-700B-4A10-B617-B3F8096EE30D}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell Remote Access (HKLM\…\{F66A31D9-7831-4FBA-BA02-C411C0047CC5}) (Version: 1.2.0.0 - Dell Inc.)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.1.6664.93 - Dell)
Dell System Detect (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\58d94f3ce2c27db0) (Version: 6.12.0.1 - Dell)
Dell Touchpad (HKLM\…\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.4.115.101 - Alps Electric)
Dell Video Chat (HKLM\…\Dell Video Chat) (Version: 6.0 (6567) - SightSpeed Inc.)
Dell Webcam Central (HKLM\…\Dell Webcam Central) (Version: 1.20.10 - Creative Technology Ltd)
Dell Wireless WLAN Card Utility (HKLM\…\Broadcom 802.11 Application) (Version: 5.10.38.30 - Dell Inc.)
DELL0703 (Version: 1.0.0 - WildTangent) Hidden
Dell-eBay (HKLM\…\{B935C985-A17F-484B-8470-09E4FC27DC26}) (Version: 1.00.0000 - Dell)
Dropbox (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\Dropbox) (Version: 3.12.5 - Dropbox, Inc.)
Elevated Installer (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden
Facebook Video Calling 1.2.0.159 (HKLM\…\{7CAC6A44-C3DE-4153-ACA6-7524602C789E}) (Version: 1.2.159 - Skype Limited)
Facebook Video Calling 1.2.0.287 (HKLM\…\{B92C5909-1D37-4C51-8397-A28BB28E5DC3}) (Version: 1.2.287 - Skype Limited)
Facebook Video Calling 3.1.0.521 (HKLM\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
FastStone Photo Resizer 3.1 (HKLM\…\FastStone Photo Resizer) (Version: 3.1 - FastStone Soft.)
FredV2Step1 (HKLM\…\{D6BCD6F1-85F1-43AD-A5A8-FC7C070546DD}) (Version: 1.00.0000 - USMLE)
Garmin Express (HKLM\…\{b292f4e5-60ca-4bb8-8810-e5f908c3c1ff}) (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries)
Garmin Express (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM\…\Google Chrome) (Version: 47.0.2526.106 - Google Inc.)
Google Earth Plug-in (HKLM\…\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Toolbar for Internet Explorer (HKLM\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6904.2028 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.29.1 - Google Inc.) Hidden
GoToAssist 8.0.0.514 (HKLM\…\GoToAssist) (Version:  - )
HP Photosmart Essential (HKLM\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
HPDiagnosticAlert (Version: 1.00.0001 - Microsoft) Hidden
Integrated Webcam Driver (1.02.01.0320)   (HKLM\…\Creative OA009) (Version: 1.02.01.0320 - Creative Technology Ltd.)
Intel(R) TV Wizard (HKLM\…\TVWiz) (Version:  - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
iTunes (HKLM\…\{86D04316-F49A-4AF2-B3F1-A1E943886CE7}) (Version: 11.3.1.2 - Apple Inc.)
Java 7 Update 10 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83217010FF}) (Version: 7.0.100 - Oracle)
Java SE Development Kit 7 Update 10 (HKLM\…\{32A3A4F4-B792-11D6-A78A-00B0D0170100}) (Version: 1.7.0.100 - Oracle)
Java(TM) 6 Update 13 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83216013FF}) (Version: 6.0.130 - Sun Microsystems, Inc.)
Live! Cam Avatar Creator (HKLM\…\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.2303.1 - Creative Technology Ltd)
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.11.226.1 - McAfee, Inc.)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM\…\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}) (Version: 8.0.58299 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\…\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\…\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 en-US) (HKLM\…\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
MSXML 4.0 SP2 (KB927978) (HKLM\…\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
P@H-Protocol (HKLM\…\{CF594DB8-CFB0-45B4-86DA-8BB4AC0941F8}) (Version: 3.0.7.0 - Valassis)
PowerDVD DX (HKLM\…\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.2.5024 - Dell Corp.)
QuickSet (HKLM\…\{C4972073-2BFE-475D-8441-564EA97DA161}) (Version: 9.2.17 - Dell Inc.)
Recipe Hub (HKLM\…\RecipeHub_2jbar Uninstall) (Version:  - Recipe Hub)
Roxio Creator DE (HKLM\…\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}) (Version: 10.1 - Roxio)
Spelling Dictionaries Support For Adobe Reader 9 (HKLM\…\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
WildTangent Games (HKLM\…\WildTangent dell Master Uninstall) (Version: 1.0.0.71 - WildTangent)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\…\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\…\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{8B9F5BF4-0407-4BB2-9FED-4C0372DABD00}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\FacebookVideoCallingProxy.exe (Skype Limited)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{AD848A76-F236-5EE2-819B-2BDE7ED40AE7}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Catalina – Print Savings\npBcsKtTcHW.dll (Catalina Marketing Corporation)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{cc8ae5b8-005b-4b1a-a27d-307eddffe5c8}\InprocServer32 -> C:\Program Files\RecipeHub_2j\bar\1.bin\2jSrcAs.dll (MindSpark)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll => No File
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
 
==================== Restore Points =========================
 
05-12-2015 10:57:59 Scheduled Checkpoint
06-12-2015 19:47:51 Scheduled Checkpoint
07-12-2015 13:07:00 Scheduled Checkpoint
07-12-2015 19:12:45 Windows Update
09-12-2015 20:09:29 Scheduled Checkpoint
10-12-2015 03:01:23 Windows Update
11-12-2015 12:20:31 Scheduled Checkpoint
12-12-2015 21:04:36 Removed Dell Remote Access.
16-12-2015 18:55:01 Windows Update
17-12-2015 02:14:57 Restore Operation
17-12-2015 05:57:33 Restore Operation
20-12-2015 20:20:58 Windows Update
20-12-2015 21:18:23 Device Driver Package Install: Microsoft Network Protocol
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 05:23 - 2015-11-15 15:35 - 00000795 ____A C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
0.0.0.1 mssplus.mcafee.com
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {115FD057-8508-48E2-8BBD-B2D54B118451} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {18DFD9FC-082E-4E9B-8285-5F21D2B4EDAE} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {4A8BB81E-2C81-44E1-8772-404BAC47FD75} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
Task: {4CC3FF0C-9DF8-4224-A48C-C562AF4FAFB4} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-23] (Facebook Inc.)
Task: {51970B63-7D0D-41C7-9B9A-DE5C003A9F81} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {56B21282-9F53-473B-B076-C17D8AEFF9AB} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2015-10-29] (PC-Doctor, Inc.)
Task: {58E907C7-28E5-406F-8C86-6B8700143F78} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {66455A42-6ED6-4D87-85FC-D45E7CD41C1C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-17] (Adobe Systems Incorporated)
Task: {73B62638-31CE-4D47-BE12-F3F6FF25CAC3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-23] (Facebook Inc.)
Task: {8BEB3FB3-770A-44E9-B5BB-08D949550BD3} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
Task: {8C7A437C-8E60-4057-87B5-94145B397931} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {9BB64651-B047-4D3C-810B-7B2E1DD3384F} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-10-29] (PC-Doctor, Inc.)
Task: {A30D3A2F-94EE-4F38-90F2-731BEDC54BE8} - System32\Tasks\Launch BCM WLAN Tray => C:\Windows\system32\WLTRAY.EXE [2008-12-21] (Dell Inc.)
Task: {D6471568-77D7-4D88-9A0F-642ACDA9E593} - System32\Tasks\GarminUpdaterTask => C:\Program Files\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2015-10-29] ()
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2009-07-07 09:16 - 2008-12-21 13:34 - 00026112 _____ () C:\Windows\System32\WLTRYSVC.EXE
2009-07-07 09:16 - 2008-12-21 13:32 - 00054784 _____ () C:\Windows\System32\bcmwlrmt.dll
2014-04-19 18:55 - 2013-10-23 13:23 - 00089136 _____ () C:\Windows\System32\cpwmon2k.dll
2014-07-31 11:16 - 2014-07-31 11:16 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-07-31 11:16 - 2014-07-31 11:16 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-08-29 14:36 - 2013-06-28 14:28 - 00084616 _____ () C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
2009-07-07 09:34 - 2011-08-18 10:05 - 02751808 _____ () C:\Program Files\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
2011-07-27 03:53 - 2011-07-27 03:53 - 00427856 _____ () C:\Program Files\Microsoft Office\Office12\MSODCW.DLL
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:5D432CE3
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\dell.com -> dell.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\boombox_1920x1200.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dell Remote Access.lnk => C:\Windows\pss\Dell Remote Access.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Linda.Linda-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk => C:\Windows\pss\Dell Dock.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Linda.Linda-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Apoint => C:\Program Files\DellTPad\Apoint.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Broadcom Wireless Manager UI => C:\Windows\system32\WLTRAY.exe
MSCONFIG\startupreg: CanonQuickMenu => C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE /logon
MSCONFIG\startupreg: Dell DataSafe Online => "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
MSCONFIG\startupreg: dellsupportcenter => "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
MSCONFIG\startupreg: Dropbox Update => "C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
MSCONFIG\startupreg: Facebook Update => "C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IAAnotif => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: IJNetworkScannerSelectorEX => C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
MSCONFIG\startupreg: PDVDDXSrv => "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: QuickSet => C:\Program Files\Dell\QuickSet\QuickSet.exe
MSCONFIG\startupreg: Recipe Hub Search Scope Monitor => "C:\PROGRA~1\RECIPE~2\bar\1.bin\2jsrchmn.exe" /m=2 /w /h
MSCONFIG\startupreg: RecipeHub_2j Browser Plugin Loader => C:\PROGRA~1\RECIPE~2\bar\1.bin\2jbrmon.exe
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SysTrayApp => %ProgramFiles%\IDT\WDM\sttray.exe
MSCONFIG\startupreg: WMPNSCFG => C:\Program Files\Windows Media Player\WMPNSCFG.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{1DFE9015-E882-4897-BBEE-D82C6671B9C4}C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Allow) C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe
FirewallRules: [UDP Query User{3540076B-0AAD-4D68-A9DD-8984C1DD0D20}C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Allow) C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe
FirewallRules: [{14B95006-3757-4085-B850-8BE5C39C3B21}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6B110739-15C4-44D9-9940-05EB3E13C847}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{86A47EFE-4472-49A4-A4DC-605BE72DD6AB}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{BC411B3E-88FF-40FC-A5D6-BDD9FCCADCFD}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{35C6BC21-17E5-47FB-A608-458493E67E22}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{10A0F431-68FE-4999-952E-DDE2FBA82CE0}C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{7A5BC35F-7AD3-4AAC-A407-98F7651811B3}C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{1A81DCF4-4A0D-45D1-8936-8DCC4D4DBD58}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{A17AA28B-5FB4-416F-8D8E-B03C10810F25}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{59217529-98D9-40A8-808B-2590921D055E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{CEBAE611-8EB3-47DD-AA02-1D0C51D1A23B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{7336234A-BC3B-4FC7-BCB8-568AE98795D7}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{60C14774-7DCB-480A-9CDA-40631E3B1007}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{4A10995A-73B1-41DD-BE32-8723CE20E33A}C:\program files\usmle\fredv2step1\fredv2orient.exe] => (Allow) C:\program files\usmle\fredv2step1\fredv2orient.exe
FirewallRules: [UDP Query User{60C01436-2076-4D96-96A6-56FBDF8B0248}C:\program files\usmle\fredv2step1\fredv2orient.exe] => (Allow) C:\program files\usmle\fredv2step1\fredv2orient.exe
FirewallRules: [TCP Query User{911A7A12-326A-487E-B981-F78A74CC8E0E}C:\program files\usmle\fredv2step1\ned.exe] => (Allow) C:\program files\usmle\fredv2step1\ned.exe
FirewallRules: [UDP Query User{D6058E1F-3B59-4E86-9B4B-2CCAA5B0F123}C:\program files\usmle\fredv2step1\ned.exe] => (Allow) C:\program files\usmle\fredv2step1\ned.exe
FirewallRules: [{B2FD502B-BABF-4704-B2C7-6C2825F173DC}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{4C7E78BE-279D-4DE0-9078-47579FFBB44F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{07EEE22B-A46C-472A-861F-33DBA61BBD14}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (12/20/2015 10:40:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (12/20/2015 10:11:11 PM) (Source: PerfNet) (EventID: 2004) (User: )
Description: 
 
Error: (12/20/2015 10:05:11 PM) (Source: PerfNet) (EventID: 2004) (User: )
Description: 
 
Error: (12/20/2015 10:03:08 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: WmiApRplC:\Windows\system32\wbem\wmiaprpl.dll4
 
Error: (12/20/2015 10:03:08 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: SpoolerC:\Windows\system32\winspool.drv4
 
Error: (12/20/2015 10:03:08 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4
 
Error: (12/20/2015 10:03:08 PM) (Source: PerfNet) (EventID: 2004) (User: )
Description: 
 
Error: (12/20/2015 10:03:08 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: EmdCacheC:\Windows\system32\emdmgmt.dll4
 
Error: (12/20/2015 10:03:07 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\system32\bitsperf.dll4
 
Error: (12/20/2015 09:38:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (12/21/2015 12:33:33 AM) (Source: netbt) (EventID: 4321) (User: )
Description: The name "JAIMES-AIR     :0" could not be registered on the interface with IP address 192.168.1.13.
The computer with the IP address 192.168.1.15 did not allow the name to be claimed by
this computer.
 
Error: (12/21/2015 12:23:33 AM) (Source: netbt) (EventID: 4321) (User: )
Description: The name "JAIMES-AIR     :0" could not be registered on the interface with IP address 192.168.1.13.
The computer with the IP address 192.168.1.15 did not allow the name to be claimed by
this computer.
 
Error: (12/21/2015 12:12:55 AM) (Source: netbt) (EventID: 4321) (User: )
Description: The name "JAIMES-AIR     :0" could not be registered on the interface with IP address 192.168.1.13.
The computer with the IP address 192.168.1.15 did not allow the name to be claimed by
this computer.
 
Error: (12/21/2015 12:02:29 AM) (Source: netbt) (EventID: 4321) (User: )
Description: The name "JAIMES-AIR     :0" could not be registered on the interface with IP address 192.168.1.13.
The computer with the IP address 192.168.1.15 did not allow the name to be claimed by
this computer.
 
Error: (12/20/2015 11:51:51 PM) (Source: netbt) (EventID: 4321) (User: )
Description: The name "JAIMES-AIR     :0" could not be registered on the interface with IP address 192.168.1.13.
The computer with the IP address 192.168.1.15 did not allow the name to be claimed by
this computer.
 
Error: (12/20/2015 11:41:50 PM) (Source: netbt) (EventID: 4321) (User: )
Description: The name "JAIMES-AIR     :0" could not be registered on the interface with IP address 192.168.1.13.
The computer with the IP address 192.168.1.15 did not allow the name to be claimed by
this computer.
 
Error: (12/20/2015 10:40:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Remote Access DB1
 
Error: (12/20/2015 10:40:11 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Remote Access Media Server1 (0x1)
 
Error: (12/20/2015 10:40:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Garmin Device Interaction Service%%1053
 
Error: (12/20/2015 10:40:11 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000Garmin Device Interaction Service
 
 
CodeIntegrity:
===================================
  Date: 2013-11-19 03:01:10.460
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-19 03:01:10.248
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-19 03:01:10.033
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-19 03:01:09.820
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-19 03:00:43.130
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-19 03:00:42.885
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-19 03:00:42.675
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-19 03:00:42.463
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-19 03:00:42.084
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-11-19 03:00:41.869
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Microsoft Security Client\Drivers\Backup\NisDrv\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
Percentage of memory in use: 72%
Total physical RAM: 3033.63 MB
Available physical RAM: 840.14 MB
Total Virtual: 6293.55 MB
Available Virtual: 3967.81 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:218.2 GB) (Free:37.71 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive e: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:8.45 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: 00638CBF)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=218.2 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 

:welcome:

 

You have a bit going on, firstly and the most important is that you may be infected by ZeroAccess. This infection has the capabilities to steal all your passwords and credit card info for sites you frequent and log in info for banking , keep an eye on your banking and cc info for false charges.  In the meantime use a known clean computer and change all your passwords for sites that you frequent, especially ones that you use a CC for.

 

 

Lets see if TDSkiller finds and removes any of this

 

 
Please download TDSSKiller
  •  
  • Download TDSSKiller.exe to your desktop, if it is prevented from being downloaded than download the Zip version and extract it to your desktop
  • Double click TDSSKiller To start the program <– XP/Vista Users
  • Right Click TDSSKiller and select RUN AS ADMINISTRATOR <–Windows 7 and 8
  • Press Start Scan
  • Only if Malicious objects are found then ensure Cure is selected
  • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
 
 

Ken545: Thanks for your assistance.

No threats were reported by TDSSKiller…I think.

 

Here's the log

 

a20:23:08.0245 0x09ec  TDSS rootkit removing tool 3.1.0.9 Dec 11 2015 22:49:12
20:23:50.0840 0x09ec  ============================================================
20:23:50.0840 0x09ec  Current date / time: 2015/12/21 20:23:50.0840
20:23:50.0840 0x09ec  SystemInfo:
20:23:50.0841 0x09ec  
20:23:50.0841 0x09ec  OS Version: 6.0.6002 ServicePack: 2.0
20:23:50.0841 0x09ec  Product type: Workstation
20:23:50.0841 0x09ec  ComputerName: LINDA-PC
20:23:50.0841 0x09ec  UserName: Linda
20:23:50.0841 0x09ec  Windows directory: C:\Windows
20:23:50.0841 0x09ec  System windows directory: C:\Windows
20:23:50.0841 0x09ec  Processor architecture: Intel x86
20:23:50.0841 0x09ec  Number of processors: 2
20:23:50.0841 0x09ec  Page size: 0x1000
20:23:50.0841 0x09ec  Boot type: Normal boot
20:23:50.0841 0x09ec  ============================================================
20:23:51.0864 0x09ec  KLMD registered as C:\Windows\system32\drivers\60807366.sys
20:23:53.0351 0x09ec  System UUID: {C857F1AD-54F7-DB06-396F-5B887A41EF2A}
20:23:54.0459 0x09ec  Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 ( 232.89 Gb ), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
20:23:54.0461 0x09ec  ============================================================
20:23:54.0461 0x09ec  \Device\Harddisk0\DR0:
20:23:54.0462 0x09ec  MBR partitions:
20:23:54.0462 0x09ec  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x1D4C000
20:23:54.0462 0x09ec  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1D60000, BlocksNum 0x1B465170
20:23:54.0462 0x09ec  ============================================================
20:23:54.0540 0x09ec  C: <-> \Device\Harddisk0\DR0\Partition2
20:23:54.0637 0x09ec  E: <-> \Device\Harddisk0\DR0\Partition1
20:23:54.0637 0x09ec  ============================================================
20:23:54.0637 0x09ec  Initialize success
20:23:54.0637 0x09ec  ============================================================
20:24:18.0820 0x0ad0  ============================================================
20:24:18.0821 0x0ad0  Scan started
20:24:18.0821 0x0ad0  Mode: Manual; 
20:24:18.0821 0x0ad0  ============================================================
20:24:18.0821 0x0ad0  KSN ping started
20:24:32.0324 0x0ad0  KSN ping finished: true
20:24:33.0429 0x0ad0  ================ Scan system memory ========================
20:24:33.0429 0x0ad0  System memory - ok
20:24:33.0430 0x0ad0  ================ Scan services =============================
20:24:33.0840 0x0ad0  [ 82B296AE1892FE3DBEE00C9CF92F8AC7, 54B22BA63E1DA616B546992141B0C3117BA057283B8F60CB9BECE203661FEBF3 ] ACPI            C:\Windows\system32\drivers\acpi.sys
20:24:33.0847 0x0ad0  ACPI - ok
20:24:34.0114 0x0ad0  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A, F419E159D3E428A3929A1A983142E7B0783D3F104EE9587585418E51011E4B8F ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
20:24:34.0116 0x0ad0  AdobeARMservice - ok
20:24:34.0487 0x0ad0  [ F54564025D2284AE498E51D7C139F971, AAA48F38B81DB894854E8C84DB2E1F5C8447AA982D27C0BB78FF2786D9F80F83 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
20:24:34.0663 0x0ad0  AdobeFlashPlayerUpdateSvc - ok
20:24:35.0200 0x0ad0  [ 04F0FCAC69C7C71A3AC4EB97FAFC8303, FBBDD38574A1F66A5AA12B82E34FDE60B870180C4B7100C15757539DC869ED4B ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
20:24:35.0477 0x0ad0  adp94xx - ok
20:24:35.0796 0x0ad0  [ 60505E0041F7751BDBB80F88BF45C2CE, 1DE16042B8ABD7B643189E836DE273832EE743FD66AFBB641E8049C4E0CD04D8 ] adpahci         C:\Windows\system32\drivers\adpahci.sys
20:24:35.0962 0x0ad0  adpahci - ok
20:24:36.0464 0x0ad0  [ 8A42779B02AEC986EAB64ECFC98F8BD7, B89938EFF4E81FA44197D2D839EBD3340DDE01FBC79605049C088621784C1B91 ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
20:24:36.0469 0x0ad0  adpu160m - ok
20:24:36.0595 0x0ad0  [ 241C9E37F8CE45EF51C3DE27515CA4E5, 1A03E93DD8C1F3640C96124A14A3D0F4E349B06CCA2118CE40B8AE201A4030A7 ] adpu320         C:\Windows\system32\drivers\adpu320.sys
20:24:36.0651 0x0ad0  adpu320 - ok
20:24:36.0893 0x0ad0  [ 9D1FDA9E086BA64E3C93C9DE32461BCF, 200FD0BFC811EC8993AF9FC78F58823ECC717063F438B627FBCDD6BD7790CAA8 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
20:24:36.0895 0x0ad0  AeLookupSvc - ok
20:24:37.0335 0x0ad0  [ 827DBC22C96EECF6D36A13162FABAFD3, EBBC04A6AD3BC83E3791569C1120BBBB59AF70512FA2CEB6A8BA2A257F3F6C32 ] AESTFilters     C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe
20:24:37.0339 0x0ad0  AESTFilters - ok
20:24:37.0448 0x0ad0  [ 4A0978779958D8FE8F5849F452BCC812, C57002A721F3DCAFB00CF4DEC57E9E761393BDB471ACEAFFDBD1ABA9AE308598 ] AFD             C:\Windows\system32\drivers\afd.sys
20:24:37.0550 0x0ad0  AFD - ok
20:24:38.0089 0x0ad0  [ 13F9E33747E6B41A3FF305C37DB0D360, 066DD6060B1CF93F85BBAAA52848C801128CD294E8B7EACD912E0EF219DBFBC2 ] agp440          C:\Windows\system32\drivers\agp440.sys
20:24:38.0093 0x0ad0  agp440 - ok
20:24:38.0210 0x0ad0  [ AE1FDF7BF7BB6C6A70F67699D880592A, B831BF156FC49287A19FC149383D437B1034EA6F42CE9D761EB90ABD0F8D96B1 ] aic78xx         C:\Windows\system32\drivers\djsvs.sys
20:24:38.0218 0x0ad0  aic78xx - ok
20:24:38.0265 0x0ad0  [ A1545B731579895D8CC44FC0481C1192, 6B0EE833BA39C142D625A03586CCD8F6C9C3136C603CE5DF5BAC1AA3423E3E7F ] ALG             C:\Windows\System32\alg.exe
20:24:38.0584 0x0ad0  ALG - ok
20:24:38.0818 0x0ad0  [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91, 0EADB6AE21FEDAB55D41F41B638198B556CC2BE2EE57F6C8B40EB044A318319F ] aliide          C:\Windows\system32\drivers\aliide.sys
20:24:38.0820 0x0ad0  aliide - ok
20:24:39.0097 0x0ad0  [ C47344BC706E5F0B9DCE369516661578, 689C9CDAF6F38227F1C34359CAEB3C7798F318EDFD4B7FE532FBE3C8E4EE3DC8 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
20:24:39.0101 0x0ad0  amdagp - ok
20:24:39.0384 0x0ad0  [ 9B78A39A4C173FDBC1321E0DD659B34C, 2CA66EB68AD7A317D91C13B8CFD4E8CA985926A610D19595B613F5553B145C7B ] amdide          C:\Windows\system32\drivers\amdide.sys
20:24:39.0386 0x0ad0  amdide - ok
20:24:39.0532 0x0ad0  [ 18F29B49AD23ECEE3D2A826C725C8D48, 0FA08882301D218E367E63E1966B6406220EE94BAE7E7DAD6E55EB70BF6FED7F ] AmdK7           C:\Windows\system32\drivers\amdk7.sys
20:24:39.0558 0x0ad0  AmdK7 - ok
20:24:39.0682 0x0ad0  [ 93AE7F7DD54AB986A6F1A1B37BE7442D, ECE0ABA2DECEED94AC678240A4B604F04022F0740F2295CBD07D25F5917E878A ] AmdK8           C:\Windows\system32\drivers\amdk8.sys
20:24:39.0710 0x0ad0  AmdK8 - ok
20:24:40.0394 0x0ad0  [ EA504A3E708A37CDA81D214D09B8A62F, E74AA695AB2E1C5CE338CA398AD7C95499169E5ED62AAED48DA6A046172BC91E ] Apache2.2       C:\Program Files\Common Files\Dell\apache\bin\httpd.exe
20:24:40.0396 0x0ad0  Apache2.2 - ok
20:24:40.0761 0x0ad0  [ 5BFFA4DB168D2D0F99C182732535E82F, FC6D7BE2994CB143FC23AED6EDE7DDDFA057DE27413F071270BAABE6029B4981 ] ApfiltrService  C:\Windows\system32\DRIVERS\Apfiltr.sys
20:24:40.0823 0x0ad0  ApfiltrService - ok
20:24:41.0190 0x0ad0  [ 8F7D200717A58E9800D391F4C2101577, F07CF0F5636F46D8F3D5133284943E991E8739E5A644BCA5F18BB896B374620D ] Appinfo         C:\Windows\System32\appinfo.dll
20:24:41.0192 0x0ad0  Appinfo - ok
20:24:41.0472 0x0ad0  [ 6B73E94F9FE82D45781B8C8A09483082, C35EEAE7457168387A7C77A315524A3703ABDE49D9F23F59057315D9249D3473 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:24:41.0476 0x0ad0  Apple Mobile Device - ok
20:24:41.0616 0x0ad0  [ 5D2888182FB46632511ACEE92FDAD522, 2E53231ACAF9B2FB7993DBC1CD15C06D7B0CCE0D08DAFF7B0CC13A2040028A75 ] arc             C:\Windows\system32\drivers\arc.sys
20:24:41.0621 0x0ad0  arc - ok
20:24:41.0722 0x0ad0  [ 5E2A321BD7C8B3624E41FDEC3E244945, 9D47FF6C823868F2267FEFAB5851D3CD2BC3F619A2D6EFF803EA22DB0509C450 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
20:24:41.0726 0x0ad0  arcsas - ok
20:24:42.0145 0x0ad0  [ 9D768C43FEF254DD50B1DBF8AD5C4C0B, A50854EA5C08605133B8BB4DFDC6090357C5665314AA72E0BFA1E07D4E451F09 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
20:24:42.0181 0x0ad0  aspnet_state - ok
20:24:42.0365 0x0ad0  [ 53B202ABEE6455406254444303E87BE1, 4C91CA8DD345FEDD74A6AF2C07580717703F979B7DE2532B1D00B9F6896DDE70 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
20:24:42.0397 0x0ad0  AsyncMac - ok
20:24:42.0565 0x0ad0  [ 0D83C87A801A3DFCD1BF73893FE7518C, 0EEB3DFFC73B370CEBB6C5115ADC769C38B2993F0EAC0EA19E273773390DA82F ] atapi           C:\Windows\system32\drivers\atapi.sys
20:24:42.0567 0x0ad0  atapi - ok
20:24:42.0828 0x0ad0  [ 8E98A99187FF17FC1D48E6FAFFD870BE, 7C935191A0A2BA95CA9A9E450F7C8802E6184F73BC297E91908B59F34C22AB06 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
20:24:42.0841 0x0ad0  AudioEndpointBuilder - ok
20:24:42.0916 0x0ad0  [ 8E98A99187FF17FC1D48E6FAFFD870BE, 7C935191A0A2BA95CA9A9E450F7C8802E6184F73BC297E91908B59F34C22AB06 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
20:24:42.0928 0x0ad0  Audiosrv - ok
20:24:43.0036 0x0ad0  [ 423C7B87E886AC93D22936EA82665F83, 98B807D855A746E68525AEEBB6D45AF418861C2111D7F8493A8A6FB59F6C6F8E ] BCM42RLY        C:\Windows\system32\drivers\BCM42RLY.sys
20:24:43.0037 0x0ad0  BCM42RLY - ok
20:24:43.0489 0x0ad0  [ 41A70777E892C3DEA606758366566A77, 8304837FE38415EB8E4C0749E25FAC9D090E32E6526368AF6970B7721DBF3FB6 ] BCM43XX         C:\Windows\system32\DRIVERS\bcmwl6.sys
20:24:43.0536 0x0ad0  BCM43XX - ok
20:24:43.0863 0x0ad0  [ 67E506B75BD5326A3EC7B70BD014DFB6, 3B07243970CAB4E93A858BEA6E31F56AD0157C42D624F3FEB469E68EEEF65669 ] Beep            C:\Windows\system32\drivers\Beep.sys
20:24:43.0901 0x0ad0  Beep - ok
20:24:44.0011 0x0ad0  [ C789AF0F724FDA5852FB9A7D3A432381, 4B0F7A3A8F2D45E49630D24F2630B8014BCDB793B9C6E83FD2B2863A54F62BF5 ] BFE             C:\Windows\System32\bfe.dll
20:24:44.0018 0x0ad0  BFE - ok
20:24:44.0498 0x0ad0  [ 93952506C6D67330367F7E7934B6A02F, 1D9A6B10B9489C1A32F730E22CC399BFF0796E3FCB3BA52BE45ED487CAC59EBD ] BITS            C:\Windows\System32\qmgr.dll
20:24:45.0093 0x0ad0  BITS - ok
20:24:45.0186 0x0ad0  [ D4DF28447741FD3D953526E33A617397, E7239BA432090F8AC7DF453DB876507CD4419ECA964D289408A1B2B353618693 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys
20:24:45.0235 0x0ad0  blbdrive - ok
20:24:45.0448 0x0ad0  [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A, 10F21999FF6B1D410EBF280F7F27DEACA5289739CF12F4293B614B8FC6C88DCC ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
20:24:45.0465 0x0ad0  Bonjour Service - ok
20:24:45.0627 0x0ad0  [ 35F376253F687BDE63976CCB3F2108CA, C5EF6301D7BC067050038DB75D961681D1CBE418285AD60167C1334B0B54DFE9 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
20:24:45.0630 0x0ad0  bowser - ok
20:24:45.0751 0x0ad0  [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
20:24:45.0786 0x0ad0  BrFiltLo - ok
20:24:45.0838 0x0ad0  [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
20:24:45.0876 0x0ad0  BrFiltUp - ok
20:24:45.0954 0x0ad0  [ A3629A0C4226F9E9C72FAAEEBC3AD33C, FB4D2738B64AADA52B95A6CF7ED4CDBFE4DD4BEBCAF1AE9CE64317F97DB38DDF ] Browser         C:\Windows\System32\browser.dll
20:24:45.0958 0x0ad0  Browser - ok
20:24:46.0079 0x0ad0  [ B304E75CFF293029EDDF094246747113, CB6B219B186C3511A0DE3CDE7F7B8966A9E32D808A952CA8C5B42B3A3A17BFB0 ] Brserid         C:\Windows\system32\drivers\brserid.sys
20:24:46.0130 0x0ad0  Brserid - ok
20:24:46.0203 0x0ad0  [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
20:24:46.0259 0x0ad0  BrSerWdm - ok
20:24:46.0298 0x0ad0  [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
20:24:46.0333 0x0ad0  BrUsbMdm - ok
20:24:46.0348 0x0ad0  [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
20:24:46.0370 0x0ad0  BrUsbSer - ok
20:24:46.0412 0x0ad0  [ AD07C1EC6665B8B35741AB91200C6B68, DCE1305A30D6713222A01C1F1D03ED0ADABE23C742CE1E82BB142531B82A3FF7 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
20:24:46.0440 0x0ad0  BTHMODEM - ok
20:24:46.0495 0x0ad0  [ 7ADD03E75BEB9E6DD102C3081D29840A, 0CA14A77CE990B5AA32C0725C22CA190ECBC73B75064DD959CABAD79B8846F1D ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
20:24:46.0496 0x0ad0  cdfs - ok
20:24:46.0556 0x0ad0  [ 6B4BFFB9BECD728097024276430DB314, 4451EFEAD37B05C8A3CB610B6D72E73B55D3D1E1CC1B17405598C1EDAA93C2D5 ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
20:24:46.0596 0x0ad0  cdrom - ok
20:24:46.0724 0x0ad0  [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] CertPropSvc     C:\Windows\System32\certprop.dll
20:24:46.0744 0x0ad0  CertPropSvc - ok
20:24:46.0793 0x0ad0  [ E5D4133F37219DBCFE102BC61072589D, 74C7F8C53D9C71CE3C8B33BC0331948571318402B0A8E1AC4552360504092A46 ] circlass        C:\Windows\system32\drivers\circlass.sys
20:24:46.0810 0x0ad0  circlass - ok
20:24:46.0871 0x0ad0  [ 5D9311526801643000D7032A83B18B12, C5A98868A41446617B3A27C6C4AAFA4E7C093E253E8C1DD5DBFE6FAE21991209 ] CLFS            C:\Windows\system32\CLFS.sys
20:24:46.0880 0x0ad0  CLFS - ok
20:24:46.0949 0x0ad0  [ 6B6943A0CA56B47D6FB2EE476890854F, 6DA779879487F4A187DF54B0362642643D7871AA8F7E30992D781F558C50F052 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:24:46.0995 0x0ad0  clr_optimization_v2.0.50727_32 - ok
20:24:47.0034 0x0ad0  [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:24:47.0038 0x0ad0  clr_optimization_v4.0.30319_32 - ok
20:24:47.0123 0x0ad0  [ 99AFC3795B58CC478FBBBCDC658FCB56, 0D1B27C42A058C5D56A0157B5ECA9A054254F6B9C8015D0321021A7EFCE10CE2 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
20:24:47.0156 0x0ad0  CmBatt - ok
20:24:47.0193 0x0ad0  [ 0CA25E686A4928484E9FDABD168AB629, C2CB2333CAB40CDF93219870E66700F957188C86A1B1A004BC4652953091E5C5 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
20:24:47.0195 0x0ad0  cmdide - ok
20:24:47.0217 0x0ad0  [ 6AFEF0B60FA25DE07C0968983EE4F60A, E4037EF9EDE57A1039AB814EBCE9A8B12C9A084E7FAC6296212ACF2394DD37B6 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
20:24:47.0218 0x0ad0  Compbatt - ok
20:24:47.0224 0x0ad0  COMSysApp - ok
20:24:47.0235 0x0ad0  [ 741E9DFF4F42D2D8477D0FC1DC0DF871, 06EA43D771E3455F943AB624CC00C2259FE5E561164908630755E933EF44A522 ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys
20:24:47.0237 0x0ad0  crcdisk - ok
20:24:47.0308 0x0ad0  [ 1F07BECDCA750766A96CDA811BA86410, F4E36F0003184BCB36D59B23AC903421AD8C0A1FD2D6315E06375235ABC9A0AD ] Crusoe          C:\Windows\system32\drivers\crusoe.sys
20:24:47.0334 0x0ad0  Crusoe - ok
20:24:47.0412 0x0ad0  [ 684C130BBC6DB681BAD4920A4C944AA5, DDE434B206984808351C98500824A33E6740B4326C455066027F8D549D4C3B92 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
20:24:47.0418 0x0ad0  CryptSvc - ok
20:24:47.0503 0x0ad0  [ 281B2B60B5CB449BCF0474EECF73EBEC, B49D2F11426E6E28E1E5F8CA7DF213067A20A5AB6F0177F31A75162DB07CAE16 ] CtClsFlt        C:\Windows\system32\DRIVERS\CtClsFlt.sys
20:24:47.0626 0x0ad0  CtClsFlt - ok
20:24:47.0682 0x0ad0  [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] DcomLaunch      C:\Windows\system32\rpcss.dll
20:24:47.0698 0x0ad0  DcomLaunch - ok
20:24:47.0812 0x0ad0  [ 51C233297C3AA16C4222E35DED1139B6, A6C11D3BEC2A94C40933EC1D3604CFE87617BA828B14F4CDED6CFE85656DEBC0 ] DellBIOS        C:\Windows\DellBIOS.Sys
20:24:47.0841 0x0ad0  DellBIOS - ok
20:24:47.0897 0x0ad0  [ 622C41A07CA7E6DD91770F50D532CB6C, 2A9040949CB45F9970FDE930278F30D2F08E957290CB3D4DC4F2CA94F3D444D2 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
20:24:47.0931 0x0ad0  DfsC - ok
20:24:48.0166 0x0ad0  [ 2CC3DCFB533A1035B13DCAB6160AB38B, C88C91F662ADE248EEE3B568E70C2BC2D5075B7D9B7D3C63E83D011C5F7812B0 ] DFSR            C:\Windows\system32\DFSR.exe
20:24:48.0446 0x0ad0  DFSR - ok
20:24:48.0522 0x0ad0  [ 9028559C132146FB75EB7ACF384B086A, 35159D86706441ED94895B4629411B4445FCB4526AFD1F7036EE647931B7A94D ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
20:24:48.0528 0x0ad0  Dhcp - ok
20:24:48.0576 0x0ad0  [ 5D4AEFC3386920236A548271F8F1AF6A, 11B74D6800EC6F7AAEFB0B6A9F2E8376C7C3B8DB677F03AC3743CB004CA96B08 ] disk            C:\Windows\system32\drivers\disk.sys
20:24:48.0578 0x0ad0  disk - ok
20:24:48.0652 0x0ad0  [ 57D762F6F5974AF0DA2BE88A3349BAAA, D9E7DC8F9FB7837F88BBB95B52147AA80E688FB9762EEA99B8046D9C6AD48F3C ] Dnscache        C:\Windows\System32\dnsrslvr.dll
20:24:48.0677 0x0ad0  Dnscache - ok
20:24:48.0823 0x0ad0  [ 0840ABBBDF438691EE65A20040635CBE, F83597ECECFADBA45242B683A19A01ADF84203B016301B64530C7BE8234175E8 ] DockLoginService C:\Program Files\Dell\DellDock\DockLogin.exe
20:24:48.0828 0x0ad0  DockLoginService - ok
20:24:48.0859 0x0ad0  [ 324FD74686B1EF5E7C19A8AF49E748F6, DC6EB4304555B60DD17E04D20DFE4E279718E4041A9310DE29E678834BB22C5B ] dot3svc         C:\Windows\System32\dot3svc.dll
20:24:48.0918 0x0ad0  dot3svc - ok
20:24:48.0976 0x0ad0  [ 4F59C172C094E1A1D46463A8DC061CBD, CE09A4ED1F8BA6242E152C384AFF5C3C95FBB8556DAE23765272F13BF158D8F9 ] Dot4            C:\Windows\system32\DRIVERS\Dot4.sys
20:24:49.0025 0x0ad0  Dot4 - ok
20:24:49.0114 0x0ad0  [ 80BF3BA09F6F2523C8F6B7CC6DBF7BD5, 69BB5B07D03FA9F28591012F2AA4A583D3F086644C136D63A56D1A827121CC19 ] Dot4Print       C:\Windows\system32\DRIVERS\Dot4Prt.sys
20:24:49.0144 0x0ad0  Dot4Print - ok
20:24:49.0188 0x0ad0  [ C55004CA6B419B6695970DFE849B122F, 6E0C4A9E24DD09E9389E097AF63E7F5040A0658DDCEBBE963968B7118CFE9AB8 ] dot4usb         C:\Windows\system32\DRIVERS\dot4usb.sys
20:24:49.0220 0x0ad0  dot4usb - ok
20:24:49.0337 0x0ad0  [ A622E888F8AA2F6B49E9BC466F0E5DEF, 3DED7F22A29AD2F8C927DFA0FD87FDE5ED0BDCAC7260BD9F71D8EA34328C772A ] DPS             C:\Windows\system32\dps.dll
20:24:49.0341 0x0ad0  DPS - ok
20:24:49.0379 0x0ad0  [ 97FEF831AB90BEE128C9AF390E243F80, A7F4118603E2D5DDDB117EF7C058684EA5B37690EFAB2BEBA570EEF9C36281BE ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
20:24:49.0433 0x0ad0  drmkaud - ok
20:24:50.0437 0x0ad0  [ 0BB913F9F02677BD4AE96D4967CACFEE, 2AC46B01BF1E238F72701DC42F27666FFE9A3F82A401358DF43013D7B2EDAB35 ] dsl-db          C:\Program Files\Common Files\Dell\MySQL\bin\mysqld.exe
20:24:50.0731 0x0ad0  dsl-db - ok
20:24:50.0849 0x0ad0  [ E9949205D0B0DBAF153FA968ADDA9EFA, C6DD11188B47BC584420DBF80061C0E870F536AF646FF9C9B022A471697EBF93 ] dsl-fs-sync     C:\Program Files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe
20:24:50.0855 0x0ad0  dsl-fs-sync - ok
20:24:50.0935 0x0ad0  [ 5C2C209CDEFBC51D83D66E8A53B2BE89, 7AE68672A6BEEF601017BE28AA0BF3673318EFE97AA08E70F58A9391C54DF71F ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
20:24:50.0952 0x0ad0  DXGKrnl - ok
20:24:51.0036 0x0ad0  [ 908ED85B7806E8AF3AF5E9B74F7809D4, 9A763D247035578A946094D2C1CE8204E6EDFFD7237C7BF2058B5F4ECC0306E0 ] e1express       C:\Windows\system32\DRIVERS\e1e6032.sys
20:24:51.0128 0x0ad0  e1express - ok
20:24:51.0142 0x0ad0  [ 5425F74AC0C1DBD96A1E04F17D63F94C, AD133CEDCDEA75420C75A91BB4CF7152475D46ED7B7703E3BAE5F9946D610292 ] E1G60           C:\Windows\system32\DRIVERS\E1G60I32.sys
20:24:51.0201 0x0ad0  E1G60 - ok
20:24:51.0324 0x0ad0  [ C0B95E40D85CD807D614E264248A45B9, 30421DAF1722A225222268CB8BA4FE60CB76C6FD0C9157B0F53FC1368F806A4E ] EapHost         C:\Windows\System32\eapsvc.dll
20:24:51.0350 0x0ad0  EapHost - ok
20:24:51.0438 0x0ad0  [ 9BAB89DBB27891DEEF6E1F1B589A6ED4, 61BE4A6394ED5C99CB84B720F6AA6B97C7FE71A7A04D822F6EE99AB084C55606 ] Ecache          C:\Windows\system32\drivers\ecache.sys
20:24:51.0445 0x0ad0  Ecache - ok
20:24:51.0583 0x0ad0  [ 23B62471681A124889978F6295B3F4C6, A90C521F06125B86A26EA625B0E7F811AF7D328E1313165E7AD4A83596A23819 ] elxstor         C:\Windows\system32\drivers\elxstor.sys
20:24:51.0598 0x0ad0  elxstor - ok
20:24:51.0721 0x0ad0  [ E798C0BDFA4913CCF8A646D29BB34796, 7CDB2BCCDD8A8A70C6248C327A357EA3488C7ADED32D4F89B933ED72AE12B73B ] EMDMgmt         C:\Windows\system32\emdmgmt.dll
20:24:51.0798 0x0ad0  EMDMgmt - ok
20:24:51.0826 0x0ad0  [ F2A80DE2D1B7116052C09CB4D4CA1416, C21E5C078D93AE605E04D251F71B617343C908DF7EF74F96BB5B810052957572 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
20:24:51.0850 0x0ad0  ErrDev - ok
20:24:51.0933 0x0ad0  [ 67058C46504BC12D821F38CF99B7B28F, E8D19F305F78BCA1DA8425315F2C77A377CD51E3CC54323DC2FF355120EA097D ] EventSystem     C:\Windows\system32\es.dll
20:24:51.0940 0x0ad0  EventSystem - ok
20:24:52.0025 0x0ad0  [ 22B408651F9123527BCEE54B4F6C5CAE, 31AF9649333A9496A9224001266D1B68CE2A31B9FB182A755D127FC5492AA6B2 ] exfat           C:\Windows\system32\drivers\exfat.sys
20:24:52.0137 0x0ad0  exfat - ok
20:24:52.0220 0x0ad0  [ 4E404505B3F62ECFBDBCBBCF0A72DBC5, 9F446ED06A31BFE52C4F1E8ACC400B8E3F47A3CC02FFC950DB861B2B3BA4C5B9 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
20:24:52.0224 0x0ad0  fastfat - ok
20:24:52.0259 0x0ad0  [ AFE1E8B9782A0DD7FB46BBD88E43F89A, B4CBE1DC3430F2F3485F49007C71293D5B86E9C405741EA00A67B00A38BE1F8D ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
20:24:52.0285 0x0ad0  fdc - ok
20:24:52.0331 0x0ad0  [ 6629B5F0E98151F4AFDD87567EA32BA3, 8CC02D5E0639CDF74B2F85DB56D6199E1858F1A58465ED1D8B25C968E986132C ] fdPHost         C:\Windows\system32\fdPHost.dll
20:24:52.0353 0x0ad0  fdPHost - ok
20:24:52.0376 0x0ad0  [ 89ED56DCE8E47AF40892778A5BD31FD2, 924360875796C3DDDDA8097FDF53F6846B227F7413766F00AEDD981EFD691BF9 ] FDResPub        C:\Windows\system32\fdrespub.dll
20:24:52.0378 0x0ad0  FDResPub - ok
20:24:52.0424 0x0ad0  [ A8C0139A884861E3AAE9CFE73B208A9F, 3B021D148A2989AAA46AE58E5FED8A2DCA25E9212C2FA7F922880EF5A077E49B ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
20:24:52.0426 0x0ad0  FileInfo - ok
20:24:52.0451 0x0ad0  [ 0AE429A696AECBC5970E3CF2C62635AE, 1ECC315C099D17835788B68F0DE00EC98DC5AEE8F329D739E0DB90A898F22244 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
20:24:52.0482 0x0ad0  Filetrace - ok
20:24:52.0559 0x0ad0  [ 85B7CF99D532820495D68D747FDA9EBD, 682D35D219D1AFBE51CF0AB03F2D3E15C940F5AF291C1A611A19F4D279143F3C ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
20:24:52.0589 0x0ad0  flpydisk - ok
20:24:52.0633 0x0ad0  [ 01334F9EA68E6877C4EF05D3EA8ABB05, 82F8AA6AD2B5077898773D4A5814819EAF0E872FFD95894E06FEDAB6EE92CF99 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
20:24:52.0639 0x0ad0  FltMgr - ok
20:24:52.0806 0x0ad0  [ 456E786A157692A7463B3739C9ADBBF5, 9AB00B5A7CF8CCCF4332E1901286D8832508471809D8BCE45FD75CCFF9CEAD8E ] FontCache       C:\Windows\system32\FntCache.dll
20:24:52.0856 0x0ad0  FontCache - ok
20:24:52.0981 0x0ad0  [ C7FBDD1ED42F82BFA35167A5C9803EA3, 372FF71070D5ECE17342466A690737A0622E93C98DBED8172C49B0854F0012B7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
20:24:52.0983 0x0ad0  FontCache3.0.0.0 - ok
20:24:53.0029 0x0ad0  [ B972A66758577E0BFD1DE0F91AAA27B5, E934034F3F740A83D4E7ABCD2C581845AC2945B0BCCAACF65CC3F99A1DBDE455 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
20:24:53.0052 0x0ad0  Fs_Rec - ok
20:24:53.0087 0x0ad0  [ 34582A6E6573D54A07ECE5FE24A126B5, 5F45DC38F8015AD90616EAD3B57820CCD284938A96B2C4E1FF5FC7BDEE8A848D ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
20:24:53.0090 0x0ad0  gagp30kx - ok
20:24:53.0198 0x0ad0  [ 37331304E89A773B1A86FE681FCA150D, A4A43DB320A10245309EAAA47761624DB8034D74198091480DB78ED39C28F610 ] GameConsoleService C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe
20:24:53.0291 0x0ad0  GameConsoleService - ok
20:24:53.0862 0x0ad0  [ F5FEA0CD5BFB434276036C97EA3A848E, 39A005E7B88F3AB542871AB61D75924D69A660B5C18DEAC33227420E3B288731 ] Garmin Device Interaction Service C:\Program Files\Garmin\Device Interaction Service\GarminService.exe
20:24:53.0891 0x0ad0  Garmin Device Interaction Service - ok
20:24:53.0998 0x0ad0  [ 185ADA973B5020655CEE342059A86CBB, D3E352DFAF30761505480A4C557D980083F65EC5BD46E2656B2114D47B272A89 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
20:24:54.0000 0x0ad0  GEARAspiWDM - ok
20:24:54.0172 0x0ad0  [ D3316F6E3C011435F36E3D6E49B3196C, 941DF52BA26603A146ED6B65A696DB87153868ED0469EF9C2EB09AC7E63525B7 ] GoToAssist      C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
20:24:54.0263 0x0ad0  GoToAssist - ok
20:24:54.0514 0x0ad0  [ CD5D0AEEE35DFD4E986A5AA1500A6E66, DCED5126837292593F1C1B35DF18E3B631D6C0C6D0742B77C7B7742C55A7825F ] gpsvc           C:\Windows\System32\gpsvc.dll
20:24:54.0585 0x0ad0  gpsvc - ok
20:24:54.0710 0x0ad0  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate         C:\Program Files\Google\Update\GoogleUpdate.exe
20:24:54.0717 0x0ad0  gupdate - ok
20:24:54.0727 0x0ad0  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem        C:\Program Files\Google\Update\GoogleUpdate.exe
20:24:54.0733 0x0ad0  gupdatem - ok
20:24:54.0780 0x0ad0  [ 5D4BC124FAAE6730AC002CDB67BF1A1C, 00294F4DC7D17F6DD2A22B9C3299BED40146BA45C972367154D20DB502472551 ] gusvc           C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
20:24:54.0899 0x0ad0  gusvc - ok
20:24:54.0962 0x0ad0  [ 062452B7FFD68C8C042A6261FE8DFF4A, DD9873502456D3C058C6177AC223B28C71370E624FA0814C17EA3D93201F2B56 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
20:24:54.0982 0x0ad0  HDAudBus - ok
20:24:55.0027 0x0ad0  [ 1338520E78D90154ED6BE8F84DE5FCEB, 8531F1C5856983EBDA4C2B70162645ECE72FFFBA9FE7A28BCEDDF2169B7ECF9D ] HidBth          C:\Windows\system32\drivers\hidbth.sys
20:24:55.0067 0x0ad0  HidBth - ok
20:24:55.0095 0x0ad0  [ FF3160C3A2445128C5A6D9B076DA519E, DC1A70C80CD55F33B3AD5A21E86AF7C3086D8CC2DC6148C058E74A871E0BAD4A ] HidIr           C:\Windows\system32\drivers\hidir.sys
20:24:55.0135 0x0ad0  HidIr - ok
20:24:55.0217 0x0ad0  [ 84067081F3318162797385E11A8F0582, 11E32E3800CFCA37354388243F88D0239D622891BAC5483518A2BE5D1CA19015 ] hidserv         C:\Windows\system32\hidserv.dll
20:24:55.0220 0x0ad0  hidserv - ok
20:24:55.0267 0x0ad0  [ CCA4B519B17E23A00B826C55716809CC, 91AD0758A6185B0FBBE383BDB1B457FFB850477AFF8DE040DE9527A97D28EF62 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
20:24:55.0302 0x0ad0  HidUsb - ok
20:24:55.0351 0x0ad0  [ D8AD255B37DA92434C26E4876DB7D418, C901EADDD93FC90C8F29F4B6DE808F8E4F486C877FC0AA27DA4ACDE17E28899D ] hkmsvc          C:\Windows\system32\kmsvc.dll
20:24:55.0434 0x0ad0  hkmsvc - ok
20:24:55.0530 0x0ad0  [ 853BABC289F2B46F8150DF0E0CF0B537, DC719E648DB5A0083C713355EA38429E29E5A2E41E2BCF27F8BD42C307F7368D ] hnmsvc          c:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
20:24:55.0550 0x0ad0  hnmsvc - ok
20:24:55.0600 0x0ad0  [ 16EE7B23A009E00D835CDB79574A91A6, 964AFE7D2F7E48C7DE7FDAB48F57ADC4AD44A0B2A9A03071E0E8D334007E5572 ] HpCISSs         C:\Windows\system32\drivers\hpcisss.sys
20:24:55.0602 0x0ad0  HpCISSs - ok
20:24:55.0665 0x0ad0  [ 0EEECA26C8D4BDE2A4664DB058A81937, 6F88567A116B1420BE1C9C8888F34D05F51378092C805EF4E489635CF92D416B ] HTTP            C:\Windows\system32\drivers\HTTP.sys
20:24:55.0675 0x0ad0  HTTP - ok
20:24:55.0707 0x0ad0  [ C6B032D69650985468160FC9937CF5B4, 4D5A944C70037F35A9DBA4F49F174455FA80ED7EAEDAA143F0A2C0E05AE585D8 ] i2omp           C:\Windows\system32\drivers\i2omp.sys
20:24:55.0709 0x0ad0  i2omp - ok
20:24:55.0777 0x0ad0  [ 22D56C8184586B7A1F6FA60BE5F5A2BD, D96A2962848C1F59B143BFEC22EC48BD1C5A75D0EBCFD7FB965E66B85FF7D8CA ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
20:24:55.0809 0x0ad0  i8042prt - ok
20:24:55.0863 0x0ad0  [ 7B96206E4BDD2FE582F0DBC46F5F410E, D27BB43E7EE0C2905FF23C48DBF6F492873F65CAD467F13A2731EB7D3A0CE5DC ] IAANTMON        C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
20:24:55.0875 0x0ad0  IAANTMON - ok
20:24:55.0920 0x0ad0  [ 80C633722DA72E97F3F5B3B11325696D, 1255DC28801438E21AA9D3EAE6F40A9625FCEA99709A7ABCBBEA906DB34AFB6C ] iaStor          C:\Windows\system32\drivers\iastor.sys
20:24:55.0929 0x0ad0  iaStor - ok
20:24:55.0974 0x0ad0  [ 54155EA1B0DF185878E0FC9EC3AC3A14, 344A0793499261D2E4FF2FCCC70501329485F8E299EBC68953D07BA86F0D4729 ] iaStorV         C:\Windows\system32\drivers\iastorv.sys
20:24:55.0982 0x0ad0  iaStorV - ok
20:24:56.0102 0x0ad0  [ DD386C45D2B5863740166783448A2E7A, 10B912BA70306644BE73A53AF4DCDFF63880C4C5860FF6DBA92B0914EB566718 ] idsvc           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
20:24:56.0344 0x0ad0  idsvc - ok
20:24:56.0749 0x0ad0  [ 938753888EADDB29D4B3754139EC19E8, FE596D409E865C6970C0EC25DA505FCA30538647ECD7EE8B764CD36B0BA0DD90 ] igfx            C:\Windows\system32\DRIVERS\igdkmd32.sys
20:24:57.0033 0x0ad0  igfx - ok
20:24:57.0066 0x0ad0  [ 2D077BF86E843F901D8DB709C95B49A5, 78FF558A881F307858F5C7C74A748B8B2562AF3CAC7EA8639945609001D790CE ] iirsp           C:\Windows\system32\drivers\iirsp.sys
20:24:57.0068 0x0ad0  iirsp - ok
20:24:57.0192 0x0ad0  [ EB7BA65AA0EDF27EAB0109AC73F2779C, EB952C72CBB43A07E1E8AC003323CD7C5E2ED7AFC5E06973F7BDB0C702C5630D ] IJPLMSVC        C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
20:24:57.0195 0x0ad0  IJPLMSVC - ok
20:24:57.0277 0x0ad0  [ 4687EE0C0DD2CE5F7AAA9C2E33C1DC78, FA8EBED2778D9F7560ADC1B563954EEF98AAE651C0553F2803372B37B122AEB3 ] IKEEXT          C:\Windows\System32\ikeext.dll
20:24:57.0292 0x0ad0  IKEEXT - ok
20:24:57.0382 0x0ad0  [ 83AA759F3189E6370C30DE5DC5590718, 7406FE41EA8FB80052517318CB72E2641E92E579FAFAF5E8DDDFF0BF8DAE773A ] intelide        C:\Windows\system32\drivers\intelide.sys
20:24:57.0384 0x0ad0  intelide - ok
20:24:57.0402 0x0ad0  [ 224191001E78C89DFA78924C3EA595FF, E4EC9CAAEEEAEB30E13F4A8023AF687F29514667380DDFD638BBFFF1D5FC2563 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
20:24:57.0404 0x0ad0  intelppm - ok
20:24:57.0465 0x0ad0  [ 9AC218C6E6105477484C6FDBE7D409A4, FF30D09CD2A0F5BBEC309E953370F194B6F26BF4227E627B594AAA48B0F5D3C2 ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
20:24:57.0503 0x0ad0  IPBusEnum - ok
20:24:57.0527 0x0ad0  [ 62C265C38769B864CB25B4BCF62DF6C3, CAF6BCE967104233E216464E4729B0275C3BD426D812F404AB0EE83A7F2063D8 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:24:57.0565 0x0ad0  IpFilterDriver - ok
20:24:57.0619 0x0ad0  [ 1998BD97F950680BB55F55A7244679C2, A4E8BB4C6B2AF4800BD5E0BA8725FD0927F8FB6751AEBF6DD16B59C414CCB9D8 ] IpHlpSvc        C:\Windows\System32\iphlpsvc.dll
20:24:57.0627 0x0ad0  IpHlpSvc - ok
20:24:57.0632 0x0ad0  IpInIp - ok
20:24:57.0663 0x0ad0  [ B25AAF203552B7B3491139D582B39AD1, EA9C38F512F40FF12975A6719E6FE4D7EA93A4B2497103E0FDA5A4CD6033C0A6 ] IPMIDRV         C:\Windows\system32\drivers\ipmidrv.sys
20:24:57.0734 0x0ad0  IPMIDRV - ok
20:24:57.0761 0x0ad0  [ 8793643A67B42CEC66490B2A0CF92D68, 8B1ED1314E4C6623824DD6B9C15A0F7F996F4D243BF0B305421251BE40850907 ] IPNAT           C:\Windows\system32\DRIVERS\ipnat.sys
20:24:57.0849 0x0ad0  IPNAT - ok
20:24:57.0966 0x0ad0  [ 35828479CCB4EE3CFD7523AF63443D5B, CA582DB092DC049597268B8245F2EEFF5DB807CBE2CFABEA04EA00DD5ED9A2B6 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
20:24:57.0983 0x0ad0  iPod Service - ok
20:24:58.0021 0x0ad0  [ 109C0DFB82C3632FBD11949B73AEEAC9, 73B01426100256B7110DF0B74483AF1B62FC209612EEC29A7BF6DC31A7FBEFB6 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
20:24:58.0044 0x0ad0  IRENUM - ok
20:24:58.0062 0x0ad0  [ 6C70698A3E5C4376C6AB5C7C17FB0614, 10FBCBA5A74AF5D136B152FD4D3DFA2A1F2CEBC3F979D5BA6DB98B3DCB2F7A07 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
20:24:58.0065 0x0ad0  isapnp - ok
20:24:58.0114 0x0ad0  [ 232FA340531D940AAC623B121A595034, 90C93F04D8A0094EEBD118F10223605B8169DA5F24C466F503CED5C014BD17B1 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
20:24:58.0118 0x0ad0  iScsiPrt - ok
20:24:58.0176 0x0ad0  [ BCED60D16156E428F8DF8CF27B0DF150, 4934E9AB8A8A548548F0C63517F2BF4DE84B05E5C9C7C2AA6C1517B8F9C340D4 ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
20:24:58.0178 0x0ad0  iteatapi - ok
20:24:58.0212 0x0ad0  [ 06FA654504A498C30ADCA8BEC4E87E7E, 651BC35A0A3D504573BBAB40DE81929BB18C9FC0CD7944FEAE0E99CD7658EA88 ] iteraid         C:\Windows\system32\drivers\iteraid.sys
20:24:58.0219 0x0ad0  iteraid - ok
20:24:58.0240 0x0ad0  [ 37605E0A8CF00CBBA538E753E4344C6E, B9A9FFDCE45B0830E277CF322C28ACB49372C16144B0F676B283BE5DAE9A7F30 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
20:24:58.0241 0x0ad0  kbdclass - ok
20:24:58.0300 0x0ad0  [ 18247836959BA67E3511B62846B9C2E0, 9623FF990A1C11A707C358CC9FDD4306C2992A8C766A50DAFC9534A283AA011D ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
20:24:58.0329 0x0ad0  kbdhid - ok
20:24:58.0385 0x0ad0  [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] KeyIso          C:\Windows\system32\lsass.exe
20:24:58.0387 0x0ad0  KeyIso - ok
20:24:58.0511 0x0ad0  [ C89E473697B67F0E3AE9211ADBD43278, DECC1CA1E0FB0CDE384F29F5FC5D234C2C923999EB98FE1F88CDCA37859116A3 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
20:24:58.0526 0x0ad0  KSecDD - ok
20:24:58.0606 0x0ad0  [ 8078F8F8F7A79E2E6B494523A828C585, BB399993166853F0C01B7508649ECD7E7473238267BA8333D0441128FE656347 ] KtmRm           C:\Windows\system32\msdtckrm.dll
20:24:58.0623 0x0ad0  KtmRm - ok
20:24:58.0684 0x0ad0  [ 1BF5EEBFD518DD7298434D8C862F825D, F41C79410345C40B346EB5EDEA397ECD29ECB9B921AC3E19F9453E52A7B9288A ] LanmanServer    C:\Windows\system32\srvsvc.dll
20:24:58.0693 0x0ad0  LanmanServer - ok
20:24:58.0769 0x0ad0  [ 1DB69705B695B987082C8BAEC0C6B34F, D395B272F6B69D4A9FC3CDEFD812EF0DBFECF3C1B1C787C7CC1E1A1B091B8DB3 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
20:24:58.0779 0x0ad0  LanmanWorkstation - ok
20:24:58.0849 0x0ad0  [ CB5D13966F74D7F000724A907F614193, 720374DE3C3E930B3C679DEF41A7073477F0C9C3156A0400F2F23672CCFCC981 ] libusb0         C:\Windows\system32\DRIVERS\libusb0.sys
20:24:58.0887 0x0ad0  libusb0 - ok
20:24:58.0966 0x0ad0  [ D1C5883087A0C3F1344D9D55A44901F6, 608D67357AFDDD538D2C12C93EB0793ECA4EB3AF2BAB779E881C41F50E4AB911 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
20:24:58.0996 0x0ad0  lltdio - ok
20:24:59.0043 0x0ad0  [ 2D5A428872F1442631D0959A34ABFF63, E532C6ECFFB936EFF744CA57BDC6394C89E797B6B0822D04F1F3F35D9BDDD4F0 ] lltdsvc         C:\Windows\System32\lltdsvc.dll
20:24:59.0067 0x0ad0  lltdsvc - ok
20:24:59.0106 0x0ad0  [ 35D40113E4A5B961B6CE5C5857702518, 453097AEF46ED48107395D9A1696AAC259FD6CEA8A655D38C5E246FDDAB81664 ] lmhosts         C:\Windows\System32\lmhsvc.dll
20:24:59.0123 0x0ad0  lmhosts - ok
20:24:59.0174 0x0ad0  [ C7E15E82879BF3235B559563D4185365, 98C9268ADF6BAEB0522BB84BE6C98D0D6D5EB4BD27BB61412D208232164C8435 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
20:24:59.0177 0x0ad0  LSI_FC - ok
20:24:59.0215 0x0ad0  [ EE01EBAE8C9BF0FA072E0FF68718920A, 655924440E611278998226299645BC72B3627A8A057286DC8D65A162CFBBE484 ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
20:24:59.0220 0x0ad0  LSI_SAS - ok
20:24:59.0248 0x0ad0  [ 912A04696E9CA30146A62AFA1463DD5C, 1D336D47B9D1C8449F29CDB776C092235E3D70CE53D9440970533E376EB004D3 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
20:24:59.0251 0x0ad0  LSI_SCSI - ok
20:24:59.0315 0x0ad0  [ 8F5C7426567798E62A3B3614965D62CC, 659810257D942C5F4168E1247868CDA990F2324AC9ACAA9A6211F64B7AC9EC6E ] luafv           C:\Windows\system32\drivers\luafv.sys
20:24:59.0357 0x0ad0  luafv - ok
20:24:59.0582 0x0ad0  [ 8A17D59D85C479A9BD1481C7202E81F5, 717CB68E5D4B508F59726716D513547688C4983E90010B3BA2DFA2B0C89D3B7F ] McComponentHostService C:\Program Files\McAfee Security Scan\3.11.226\McCHSvc.exe
20:24:59.0671 0x0ad0  McComponentHostService - ok
20:24:59.0756 0x0ad0  [ 0001CE609D66632FA17B84705F658879, D5F9758BDC2B733307B565A74B33F5581FB425A5A9F32CCFA307DA1569EBD6CD ] megasas         C:\Windows\system32\drivers\megasas.sys
20:24:59.0758 0x0ad0  megasas - ok
20:24:59.0797 0x0ad0  [ C252F32CD9A49DBFC25ECF26EBD51A99, 47EC8F475AB62A00FAF989CD2C3ABDF2922588F75CC15C83CD99A62EF6400FB0 ] MegaSR          C:\Windows\system32\drivers\megasr.sys
20:24:59.0814 0x0ad0  MegaSR - ok
20:24:59.0853 0x0ad0  [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] MMCSS           C:\Windows\system32\mmcss.dll
20:24:59.0883 0x0ad0  MMCSS - ok
20:24:59.0931 0x0ad0  [ E13B5EA0F51BA5B1512EC671393D09BA, 5B380D1B435D809CA201FD5ED075D42F3C6BA1A4EEDBC4040F7E3329F05A334A ] Modem           C:\Windows\system32\drivers\modem.sys
20:24:59.0958 0x0ad0  Modem - ok
20:25:00.0000 0x0ad0  [ 0A9BB33B56E294F686ABB7C1E4E2D8A8, 1E8031D51E074FDFB53E98E26DABF313B901C028D01196BFD402EED5D0A89595 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
20:25:00.0001 0x0ad0  monitor - ok
20:25:00.0014 0x0ad0  [ 5BF6A1326A335C5298477754A506D263, CC7F58E5955A448F6CE28D6D8EB98C7479E11F931B5C733CFE71A29B2E95923D ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
20:25:00.0016 0x0ad0  mouclass - ok
20:25:00.0045 0x0ad0  [ 93B8D4869E12CFBE663915502900876F, 7464DE60FAAD8793D855F1F86C3C865B3A3EE41C19A3E926D1BE4426E67F5EC2 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
20:25:00.0084 0x0ad0  mouhid - ok
20:25:00.0115 0x0ad0  [ 3EAE06B0D9E32A3D45DC3E07F1FBFA97, 0C56D92C5131D60AF2FCCF071976F2932A2C544C5EC4C2A5476E99CDE17FF08C ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
20:25:00.0115 0x0ad0  MountMgr - ok
20:25:00.0201 0x0ad0  [ 0DE2474F316C515482ABAD3B697F8714, 62862AE7432F5350068E96AD466093359C6CF444EB517AE6D09134FAF78C49F5 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
20:25:00.0206 0x0ad0  MozillaMaintenance - ok
20:25:00.0286 0x0ad0  [ F112DA773EC3E9D3CDE9221ED300E033, 693C416B281DA3489C096812D0E4E0413C05798D36AF534624C3B29551CE68A4 ] MpFilter        C:\Windows\system32\DRIVERS\MpFilter.sys
20:25:00.0293 0x0ad0  MpFilter - ok
20:25:00.0325 0x0ad0  [ 511D011289755DD9F9A7579FB0B064E6, 1FD0D0D5B6E08FE06F7A5D0821BCD859B0F98A6DEA58AAB7FB6C95B64212FFC8 ] mpio            C:\Windows\system32\drivers\mpio.sys
20:25:00.0328 0x0ad0  mpio - ok
20:25:00.0608 0x0ad0  [ BB7BB66A8DAF16950F83AE7BF498AF8F, A96FC3BE055C52B98E7ECDF68D69081620F829B04B5496C73D87F271E40EA638 ] MpKslcbb96034   c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C7139CD9-5C13-4B4E-8F1E-3F83C67C03C3}\MpKslcbb96034.sys
20:25:00.0609 0x0ad0  MpKslcbb96034 - ok
20:25:00.0665 0x0ad0  [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E, 62055C0DCEB69873B8961AB17DBD002F44319A44CB05EC3A61421A0C6D4736CD ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
20:25:00.0668 0x0ad0  mpsdrv - ok
20:25:00.0769 0x0ad0  [ 5DE62C6E9108F14F6794060A9BDECAEC, 655E6645CC4A1EDBE5F51F5F80C7B504DD956851E788A6E4E4E08CDCDCE160D9 ] MpsSvc          C:\Windows\system32\mpssvc.dll
20:25:00.0786 0x0ad0  MpsSvc - ok
20:25:00.0847 0x0ad0  [ 4FBBB70D30FD20EC51F80061703B001E, 72907A0CA5CFF82F40C02A65CD8EFD51D7CFC33BE67DE572D1ACF4FD3B248F0A ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
20:25:00.0851 0x0ad0  Mraid35x - ok
20:25:00.0903 0x0ad0  [ B0584CA7DEF55929FDB5169BD28B2484, AF6A7E404FEB29F7F3428D0AF6682195E5E8ED106996A04E6947DBD575696546 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
20:25:00.0907 0x0ad0  MRxDAV - ok
20:25:00.0940 0x0ad0  [ 1B864548B2ACEC1C0BB29B615CC42978, E1DA3E6764A2C7072D99F2F093E5F40DB6DC809701B59C155C6B4EE327AB9E41 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
20:25:00.0944 0x0ad0  mrxsmb - ok
20:25:00.0996 0x0ad0  [ 3F39B02EEDC5B8A0ED896EA1CDF7245F, 41C1DCD82F964A398B7C3D44178DBF7C8AF1C2DBC5F2D944BE6B00E909FE083B ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:25:01.0005 0x0ad0  mrxsmb10 - ok
20:25:01.0050 0x0ad0  [ D0670EC8E5AD3FA5BE372BF70AC0EABF, BD2D1BA151FD5409EAA41ECCBEB863FE52FF7C2D92349961FEE736D66970748E ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:25:01.0054 0x0ad0  mrxsmb20 - ok
20:25:01.0110 0x0ad0  [ F70590424EEFBF5C27A40C67AFDB8383, 1F2AC1DA12F7E6F09D8F6622EF1366ABD4B86EBE51DD1915E803D56A568A3412 ] msahci          C:\Windows\system32\drivers\msahci.sys
20:25:01.0113 0x0ad0  msahci - ok
20:25:01.0139 0x0ad0  [ 4468B0F385A86ECDDAF8D3CA662EC0E7, EAEDC9CDD2EEC5000AF8190A4BE7729282576C3F88E64FDF57F455F5CECC81C9 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
20:25:01.0144 0x0ad0  msdsm - ok
20:25:01.0170 0x0ad0  [ FD7520CC3A80C5FC8C48852BB24C6DED, C3F3D7A07FAB9AF38A2A00BF0DF6EEE18CA8FE26277BEC9D8ADB793F2CD5EC1F ] MSDTC           C:\Windows\System32\msdtc.exe
20:25:01.0229 0x0ad0  MSDTC - ok
20:25:01.0254 0x0ad0  [ A9927F4A46B816C92F461ACB90CF8515, 753284F726F9B4D3E7322C75532244CA43714F00717C2019391FB36DEE0738C0 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
20:25:01.0303 0x0ad0  Msfs - ok
20:25:01.0355 0x0ad0  [ 0F400E306F385C56317357D6DEA56F62, C48FA8193787359902D20D869F5F602CD66D3C5D061A58DDB72F51EED433C4BC ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
20:25:01.0357 0x0ad0  msisadrv - ok
20:25:01.0452 0x0ad0  [ 85466C0757A23D9A9AECDC0755203CB2, 79141B8DF9D7470466872AF03A85C3D3976512BFDBDB8B92A22225DC8EFD70A6 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
20:25:01.0485 0x0ad0  MSiSCSI - ok
20:25:01.0492 0x0ad0  msiserver - ok
20:25:01.0561 0x0ad0  [ D8C63D34D9C9E56C059E24EC7185CC07, D0CBFB8D57E6D908679DC0488ED659CA35B92626DEA890873E165F051A1AD2AE ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
20:25:01.0595 0x0ad0  MSKSSRV - ok
20:25:01.0700 0x0ad0  [ CC09BB7FDEFC5763CCB3CF7DAE2D76CF, F8F00900EDBA2F64BF136DD0B6C83CAF07C72F24F3D49C78B7EA24757FDBC6D0 ] MsMpSvc         c:\Program Files\Microsoft Security Client\MsMpEng.exe
20:25:01.0701 0x0ad0  MsMpSvc - ok
20:25:01.0742 0x0ad0  [ 1D373C90D62DDB641D50E55B9E78D65E, 1D4897A96EA54D6FAC7916D69B4E88CAE1397C38CC8FAE08554772808476357B ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
20:25:01.0777 0x0ad0  MSPCLOCK - ok
20:25:01.0804 0x0ad0  [ B572DA05BF4E098D4BBA3A4734FB505B, B7923F204CEADD0F62C2FE4B7CF8C56DAB70F88093B15C5692D0E61490CF4BAA ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
20:25:01.0854 0x0ad0  MSPQM - ok
20:25:01.0891 0x0ad0  [ B49456D70555DE905C311BCDA6EC6ADB, 8E40586B3A1FAE9996459E0261726C9DD6A8D5F575604868C45604613385C92F ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
20:25:01.0898 0x0ad0  MsRPC - ok
20:25:01.0919 0x0ad0  [ E384487CB84BE41D09711C30CA79646C, 520391DEE14D4D6C1EA99C7D31DD95D56B44D54CA3CD8E5C9855E9C0A04F026C ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
20:25:01.0920 0x0ad0  mssmbios - ok
20:25:01.0958 0x0ad0  [ 7199C1EEC1E4993CAF96B8C0A26BD58A, DD02DF8ED7AF5BB88BD2A91F38CE4C52432CB8044BDCBC41C320CD22B10B8A3B ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
20:25:01.0979 0x0ad0  MSTEE - ok
20:25:02.0016 0x0ad0  [ 6A57B5733D4CB702C8EA4542E836B96C, 080FB0B01E949D24CDD6876125B3A72DA9F88845D8B9A1A425BCA99E7ACF6821 ] Mup             C:\Windows\system32\Drivers\mup.sys
20:25:02.0017 0x0ad0  Mup - ok
20:25:02.0058 0x0ad0  [ E4EAF0C5C1B41B5C83386CF212CA9584, 5946C3DCE65A0DB164169A1775DFCA544AF4E1895ADF6916BB1653F373F8D9AF ] napagent        C:\Windows\system32\qagentRT.dll
20:25:02.0067 0x0ad0  napagent - ok
20:25:02.0123 0x0ad0  [ 85C44FDFF9CF7E72A40DCB7EC06A4416, DC37C99C458CA69B33BFD3894187089E947F4F9C01EC2ED024FA8614989E0956 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
20:25:02.0176 0x0ad0  NativeWifiP - ok
20:25:02.0237 0x0ad0  [ DEC4B200C459FA929B0A764E79904B79, 40261D7D0BEE45E6E3F4F25D7ACAB00744BAF5D515B6D84B41A25ED22380DC13 ] NDIS            C:\Windows\system32\drivers\ndis.sys
20:25:02.0253 0x0ad0  NDIS - ok
20:25:02.0333 0x0ad0  [ 0E186E90404980569FB449BA7519AE61, DE41791D9D3074007D6DD1D3933E7A2A13E3789D0AD4F029105B58279622FC1B ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
20:25:02.0404 0x0ad0  NdisTapi - ok
20:25:02.0417 0x0ad0  [ D6973AA34C4D5D76C0430B181C3CD389, 7C303F3D6BFF8B82E39998135B444837091AB1F9EB8F28D013E5EF45DB237EFC ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
20:25:02.0445 0x0ad0  Ndisuio - ok
20:25:02.0486 0x0ad0  [ 818F648618AE34F729FDB47EC68345C3, 5FC8F9237BD7FCE3C62D5BDDD49DC104BE2BECDC2FA8CDC1DB8F1891CBAA9140 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
20:25:02.0532 0x0ad0  NdisWan - ok
20:25:02.0544 0x0ad0  [ 71DAB552B41936358F3B541AE5997FB3, 30A8B3E33CBF04FC047254E404C0321F9028F2640036AA8AC1EA0A5E64551684 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
20:25:02.0601 0x0ad0  NDProxy - ok
20:25:02.0650 0x0ad0  [ A081CB6FB9A12668F233EB5414BE3A0E, EE2A1311B51D1FEBAF79F45E568A927D8EA7704AFC8495AED2D26927566F61E3 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
20:25:02.0653 0x0ad0  Net Driver HPZ12 - ok
20:25:02.0736 0x0ad0  [ BCD093A5A6777CF626434568DC7DBA78, 2A283DD93230361204EA0897864EAF0224CB8C02E025AE2E4237B07A598B3EBD ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
20:25:02.0799 0x0ad0  NetBIOS - ok
20:25:02.0844 0x0ad0  [ ECD64230A59CBD93C85F1CD1CAB9F3F6, 83650D756C1F2768A2AAAFC7924F2A4316ABAEB1708F4B05803CDDD699B5AB6F ] netbt           C:\Windows\system32\DRIVERS\netbt.sys
20:25:02.0994 0x0ad0  netbt - ok
20:25:03.0019 0x0ad0  [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] Netlogon        C:\Windows\system32\lsass.exe
20:25:03.0021 0x0ad0  Netlogon - ok
20:25:03.0090 0x0ad0  [ C8052711DAECC48B982434C5116CA401, 417DEB86D157DD3F0B4678410FE27FDD3E8FA04AB03AF398F6C02BF207070B35 ] Netman          C:\Windows\System32\netman.dll
20:25:03.0098 0x0ad0  Netman - ok
20:25:03.0164 0x0ad0  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
20:25:03.0209 0x0ad0  NetMsmqActivator - ok
20:25:03.0220 0x0ad0  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
20:25:03.0223 0x0ad0  NetPipeActivator - ok
20:25:03.0335 0x0ad0  [ 2EF3BBE22E5A5ACD1428EE387A0D0172, 55DB91EDD0339D2434C06445F8A716A48EA90925B0FF7EBF45BB79D4B54B80BF ] netprofm        C:\Windows\System32\netprofm.dll
20:25:03.0341 0x0ad0  netprofm - ok
20:25:03.0408 0x0ad0  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
20:25:03.0412 0x0ad0  NetTcpActivator - ok
20:25:03.0420 0x0ad0  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
20:25:03.0423 0x0ad0  NetTcpPortSharing - ok
20:25:03.0464 0x0ad0  [ 2E7FB731D4790A1BC6270ACCEFACB36E, EE9A00B694E8A3A5842CDC56C7BA1364317AC8134E046A0059661D057094B1A3 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
20:25:03.0466 0x0ad0  nfrd960 - ok
20:25:03.0523 0x0ad0  [ 780FF28BCD8470C5FDDEEF69982AA295, 1ED386E87E0AA733F23D554D2BF4EF4168DB9A419B7BA0BA8FBA20F118BE21DF ] NisDrv          C:\Windows\system32\DRIVERS\NisDrvWFP.sys
20:25:03.0526 0x0ad0  NisDrv - ok
20:25:03.0613 0x0ad0  [ 3FF257F54649D4F19E39263C5D581CD1, 1F201EEE770A452AA30C6270AAA456A77F9F3A102F473E12C22D3B8809932C1B ] NisSrv          c:\Program Files\Microsoft Security Client\NisSrv.exe
20:25:03.0623 0x0ad0  NisSrv - ok
20:25:03.0672 0x0ad0  [ C96411DD46AABC0D6F3CF06D0E0E7E14, 0D36F322AF1B923D96735BFFCAC3FDB0B282E59220BADAB8B49AC178A6765380 ] NlaSvc          C:\Windows\System32\nlasvc.dll
20:25:03.0679 0x0ad0  NlaSvc - ok
20:25:03.0717 0x0ad0  [ D36F239D7CCE1931598E8FB90A0DBC26, DF9397411D0CE5A87E3346D4E6E25BEC537A21BCE196CC55FD999CD08FC4A637 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
20:25:03.0766 0x0ad0  Npfs - ok
20:25:03.0793 0x0ad0  [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD, 15CA178518EB3D457AA4C109D97A8490821590842AE4E9841703B5A55870C8F6 ] nsi             C:\Windows\system32\nsisvc.dll
20:25:03.0821 0x0ad0  nsi - ok
20:25:03.0865 0x0ad0  [ 609773E344A97410CE4EBF74A8914FCF, 90B9CBD2B62854DD503DE4A910CB987D402368EB99882FE20FFB6DEACD70F2BD ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
20:25:03.0925 0x0ad0  nsiproxy - ok
20:25:04.0045 0x0ad0  [ 2C1121F2B87E9A6B12485DF53CD848C7, E580428F3BA7B201C6C7CFADF1F44A6ECA4F589EDB034DA14260136236195936 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
20:25:04.0089 0x0ad0  Ntfs - ok
20:25:04.0122 0x0ad0  [ E875C093AEC0C978A90F30C9E0DFBB72, D3A480CD7EF374EFBC1BB831B33B81534774DDDBB0FB338BEE1D444949FD8DE7 ] ntrigdigi       C:\Windows\system32\drivers\ntrigdigi.sys
20:25:04.0150 0x0ad0  ntrigdigi - ok
20:25:04.0163 0x0ad0  [ C5DBBCDA07D780BDA9B685DF333BB41E, 3652893DFF05469A273C3073D8D0A9D6D6BBDEC7855FEA8EAB768F95BA674108 ] Null            C:\Windows\system32\drivers\Null.sys
20:25:04.0186 0x0ad0  Null - ok
20:25:04.0219 0x0ad0  [ 2EDF9E7751554B42CBB60116DE727101, 37A0AA78E83DBB5A788F7F067EB71DDF6CCC72A66BB41B209E1A5E2F68F8AF9B ] nvraid          C:\Windows\system32\drivers\nvraid.sys
20:25:04.0222 0x0ad0  nvraid - ok
20:25:04.0262 0x0ad0  [ ABED0C09758D1D97DB0042DBB2688177, 84B9BF886EF9181915E8AB6D971446BC681E6DE4485DBECD62838EAFA10E7F46 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
20:25:04.0264 0x0ad0  nvstor - ok
20:25:04.0330 0x0ad0  [ 18BBDF913916B71BD54575BDB6EEAC0B, 5FBA165149AB09E869DCE35622E91CFC964BDD22B31A5E76CF12F1565402B207 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
20:25:04.0334 0x0ad0  nv_agp - ok
20:25:04.0339 0x0ad0  NwlnkFlt - ok
20:25:04.0347 0x0ad0  NwlnkFwd - ok
20:25:04.0419 0x0ad0  [ 2CF21D5F8F1B74BB1922135AC2B12DDB, A6D6296A5477CB2AF7252CB1A0C4B5C384D0BFAE9F4860CAB466209BDC72C747 ] OA009Ufd        C:\Windows\system32\DRIVERS\OA009Ufd.sys
20:25:04.0481 0x0ad0  OA009Ufd - ok
20:25:04.0543 0x0ad0  [ 636C6EE8BB6EC473B8FE221EFF77E0CC, 5996BE7E14645ACDE3F7D91C8854C930D75173F5B579EC5D0705253EF1A226AC ] OA009Vid        C:\Windows\system32\DRIVERS\OA009Vid.sys
20:25:04.0604 0x0ad0  OA009Vid - ok
20:25:04.0782 0x0ad0  [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv          C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
20:25:04.0875 0x0ad0  odserv - ok
20:25:04.0951 0x0ad0  [ BE32DA025A0BE1878F0EE8D6D9386CD5, B9D6CB4626FC67D108D713467C9ED8D0E2A071D98621B5531AD9D0C172FE7B89 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
20:25:04.0980 0x0ad0  ohci1394 - ok
20:25:05.0041 0x0ad0  [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose             C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:25:05.0139 0x0ad0  ose - ok
20:25:05.0189 0x0ad0  [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2pimsvc        C:\Windows\system32\p2psvc.dll
20:25:05.0273 0x0ad0  p2pimsvc - ok
20:25:05.0295 0x0ad0  [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2psvc          C:\Windows\system32\p2psvc.dll
20:25:05.0311 0x0ad0  p2psvc - ok
20:25:05.0352 0x0ad0  [ 9D80E0BE979C3EDAF2863F23B88F4DE6, F257ED0D25E3F60ADEEF6F8BDFB46BA30779F066F20B69ACA3D2C79E8AEABB70 ] Packet          C:\Windows\system32\DRIVERS\packet.sys
20:25:05.0353 0x0ad0  Packet - ok
20:25:05.0403 0x0ad0  [ 0FA9B5055484649D63C303FE404E5F4D, ABF357001A5E7B21621560E74FA538E2D899C5111A6AAC784B5B12D9D819C6CD ] Parport         C:\Windows\system32\drivers\parport.sys
20:25:05.0405 0x0ad0  Parport - ok
20:25:05.0476 0x0ad0  [ B9C2B89F08670E159F7181891E449CD9, BD48CE95CF4B75D1FD5FD379B2A8727BC000F2B6748B77636C6BDB0B37B0344A ] partmgr         C:\Windows\system32\drivers\partmgr.sys
20:25:05.0478 0x0ad0  partmgr - ok
20:25:05.0511 0x0ad0  [ 4F9A6A8A31413180D0FCB279AD5D8112, DCE48BC6E3447403521BB9FBF727E629DEE45B69B8AE8CFEE1A67FECAE3CB9D3 ] Parvdm          C:\Windows\system32\drivers\parvdm.sys
20:25:05.0533 0x0ad0  Parvdm - ok
20:25:05.0562 0x0ad0  [ C6276AD11F4BB49B58AA1ED88537F14A, 409E956AF994640DF8D062E5E41F87A6EE7EEE0335C191B582722A49322357CE ] PcaSvc          C:\Windows\System32\pcasvc.dll
20:25:05.0565 0x0ad0  PcaSvc - ok
20:25:05.0606 0x0ad0  PCD5SRVC{3F6A8B78-EC003E00-05040104} - ok
20:25:05.0682 0x0ad0  [ 941DC1D19E7E8620F40BBC206981EFDB, 156142A8B587131D2D47074CBFD0A31F69B3C27A8C74C8C4F29DFE7B53BBA802 ] pci             C:\Windows\system32\drivers\pci.sys
20:25:05.0687 0x0ad0  pci - ok
20:25:05.0720 0x0ad0  [ FC175F5DDAB666D7F4D17449A547626F, 7D6108213D1AD3F97A3B83E491BCCC7D6F5BC72C32A182BDDE8736851A26C8D2 ] pciide          C:\Windows\system32\drivers\pciide.sys
20:25:05.0721 0x0ad0  pciide - ok
20:25:05.0750 0x0ad0  [ E6F3FB1B86AA519E7698AD05E58B04E5, 2C4B45DDD3B980C9DAA6F039CAEFCD6E84A4D5BB43AFBA73C0C42B5556C1303C ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
20:25:05.0757 0x0ad0  pcmcia - ok
20:25:05.0820 0x0ad0  [ 6349F6ED9C623B44B52EA3C63C831A92, 9EAA3ABD396870123107D6E1B758F56FDA378BD28B28DB8415AA470D24294F92 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
20:25:05.0844 0x0ad0  PEAUTH - ok
20:25:06.0070 0x0ad0  [ B1689DF169143F57053F795390C99DB3, 887B8C76B34CABC68067C0F27CC4EEF02457A53634C96FE5B0FE9B99453BDBEF ] pla             C:\Windows\system32\pla.dll
20:25:06.0269 0x0ad0  pla - ok
20:25:06.0380 0x0ad0  [ C5E7F8A996EC0A82D508FD9064A5569E, 416A93816CDF12DD42DEA796D37E6E2000D3172AAAB20D3EAD3B715DACD4B61F ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
20:25:07.0426 0x0ad0  PlugPlay - ok
20:25:07.0471 0x0ad0  [ 65BC271F337637731D3C71455AE1F476, DAD32B61FE0147F8D2DA4C8F016920CD6BB2098F16E3CC2768009763E71DEFBC ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
20:25:07.0473 0x0ad0  Pml Driver HPZ12 - ok
20:25:07.0567 0x0ad0  [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPAutoReg     C:\Windows\system32\p2psvc.dll
20:25:07.0583 0x0ad0  PNRPAutoReg - ok
20:25:07.0630 0x0ad0  [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPsvc         C:\Windows\system32\p2psvc.dll
20:25:07.0649 0x0ad0  PNRPsvc - ok
20:25:07.0703 0x0ad0  [ D0494460421A03CD5225CCA0059AA146, FC30E90522C63F2A66D89381705712D2CDF07B2E029DF40C2DEBB2353E763E90 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
20:25:07.0714 0x0ad0  PolicyAgent - ok
20:25:07.0786 0x0ad0  [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1, 6E4B188A4BFDBBCA51347BCCE2873F2D0F858398851B9B5129CB9F36A02E4354 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
20:25:07.0827 0x0ad0  PptpMiniport - ok
20:25:07.0850 0x0ad0  [ 2027293619DD0F047C584CF2E7DF4FFD, B7C172CCD08D8A30483D27536355ED1E5009B33629355B426470AFBA8542B394 ] Processor       C:\Windows\system32\drivers\processr.sys
20:25:07.0872 0x0ad0  Processor - ok
20:25:07.0916 0x0ad0  [ 0D5DAD610D7EA1627581ED06FB2BAA9A, 6E27CF3A1624AE10EECB8B5F38E03D76A6AABE4E75DD66DEDD67E0773935A396 ] ProfSvc         C:\Windows\system32\profsvc.dll
20:25:07.0922 0x0ad0  ProfSvc - ok
20:25:07.0974 0x0ad0  [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] ProtectedStorage C:\Windows\system32\lsass.exe
20:25:07.0976 0x0ad0  ProtectedStorage - ok
20:25:08.0071 0x0ad0  [ 99514FAA8DF93D34B5589187DB3AA0BA, 4DDE5EC0C721B22E1D7D55ED3514B60EA07435C232A3A931BB49C7F486B52C18 ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
20:25:08.0107 0x0ad0  PSched - ok
20:25:08.0155 0x0ad0  [ 03E0FE281823BA64B3782F5B38950E73, D47E5536AD28D02B7D784846CFB2F4FD96187BFD64FC07BACDE9DC7B75D1D2E2 ] PxHelp20        C:\Windows\system32\Drivers\PxHelp20.sys
20:25:08.0157 0x0ad0  PxHelp20 - ok
20:25:08.0277 0x0ad0  [ 0A6DB55AFB7820C99AA1F3A1D270F4F6, 8B7D44A7698B95FE34CBBE4FAB2F01EC1F5BA86C2B19672F99767E650E99BF1C ] ql2300          C:\Windows\system32\drivers\ql2300.sys
20:25:08.0310 0x0ad0  ql2300 - ok
20:25:08.0363 0x0ad0  [ 81A7E5C076E59995D54BC1ED3A16E60B, A2988F065F93C41B3B389BFF3BB3FD69F768C2AF249C2356F315CC92E5C9E128 ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
20:25:08.0367 0x0ad0  ql40xx - ok
20:25:08.0419 0x0ad0  [ E9ECAE663F47E6CB43962D18AB18890F, F1A05320CAED9E745AA36A6DA9B64C48AAEDE888B42B249840CEB31448F7F432 ] QWAVE           C:\Windows\system32\qwave.dll
20:25:08.0476 0x0ad0  QWAVE - ok
20:25:08.0506 0x0ad0  [ 9F5E0E1926014D17486901C88ECA2DB7, 67CDFB99AB546DCEEF20507EAC07DD52FFB51BFDFE9416ABEDDC1201B60D720E ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
20:25:08.0537 0x0ad0  QWAVEdrv - ok
20:25:08.0648 0x0ad0  [ E642B131FB74CAF4BB8A014F31113142, 18A81B27FB2DA556AC51DBA8956203A6E821D75B2B09F11049250E732318F573 ] R300            C:\Windows\system32\DRIVERS\atikmdag.sys
20:25:08.0974 0x0ad0  R300 - ok
20:25:09.0003 0x0ad0  [ 147D7F9C556D259924351FEB0DE606C3, E41EBA5F3098C6CF2BE4C0060A5F4BF161C3677D983B7A0D70ACC12FC3CFEFD7 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
20:25:09.0004 0x0ad0  RasAcd - ok
20:25:09.0059 0x0ad0  [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F, 6A410ABCCD2211EFF511CDBF22E4152B57D2996336EBE711DFF71904AF232DB2 ] RasAuto         C:\Windows\System32\rasauto.dll
20:25:09.0081 0x0ad0  RasAuto - ok
20:25:09.0108 0x0ad0  [ A214ADBAF4CB47DD2728859EF31F26B0, A24F37F55E2C018B1B4FA2C568A01AAAAEA1220833ED24A93378386174A70A32 ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
20:25:09.0143 0x0ad0  Rasl2tp - ok
20:25:09.0209 0x0ad0  [ 75D47445D70CA6F9F894B032FBC64FCF, 9112EA5D25F867136858524C7965ACCEDC02675D1E2985B950598D89CCF25E14 ] RasMan          C:\Windows\System32\rasmans.dll
20:25:09.0223 0x0ad0  RasMan - ok
20:25:09.0300 0x0ad0  [ 509A98DD18AF4375E1FC40BC175F1DEF, CC7C278CA298CE102D871E34C176E73F903D6687D1E8B5AFAB8772C7DE1A60B1 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
20:25:09.0359 0x0ad0  RasPppoe - ok
20:25:09.0469 0x0ad0  [ 2005F4A1E05FA09389AC85840F0A9E4D, D8A664073FDE82F9AB324347024CDB7043635C84EB11C24C59AB384C52F0FD94 ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
20:25:09.0524 0x0ad0  RasSstp - ok
20:25:09.0559 0x0ad0  [ B14C9D5B9ADD2F84F70570BBBFAA7935, 3D533767A50554B86C769DF4D8841B3EA680B3807E85EA3533BDA9B649548269 ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
20:25:09.0722 0x0ad0  rdbss - ok
20:25:09.0753 0x0ad0  [ 89E59BE9A564262A3FB6C4F4F1CD9899, 6F948FB0E73495CA60B7B19E758268495EC8A084C475EC59AD7940AA619570BB ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
20:25:09.0773 0x0ad0  RDPCDD - ok
20:25:09.0806 0x0ad0  [ FBC0BACD9C3D7F6956853F64A66E252D, 7672B10C7039295B152C02C96903E869FF2C0A88A2C3FA89BAE9F1D593B43569 ] rdpdr           C:\Windows\system32\drivers\rdpdr.sys
20:25:09.0814 0x0ad0  rdpdr - ok
20:25:09.0836 0x0ad0  [ 9D91FE5286F748862ECFFA05F8A0710C, 33F37F1B207151A5564BF051BBF16F35D8C5A0F426CCA078A51F125BF09E487B ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
20:25:09.0858 0x0ad0  RDPENCDD - ok
20:25:09.0907 0x0ad0  [ C127EBD5AFAB31524662C48DFCEB773A, 40A6B88FEAFF02D1B5C0CA32F290CF3D9B48B85D248C7532F30CC5C09BAA4D89 ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
20:25:09.0965 0x0ad0  RDPWD - ok
20:25:10.0059 0x0ad0  [ 622FCF264119F7DF127BE353F796B319, 6689D8F62F860178685496EF45520967AFAEFF94CFBCC64CF77074F21577E0A2 ] RecipeHub_2jService C:\PROGRA~1\RECIPE~2\bar\1.bin\2jbarsvc.exe
20:25:10.0060 0x0ad0  RecipeHub_2jService - ok
20:25:10.0098 0x0ad0  [ BCDD6B4804D06B1F7EBF29E53A57ECE9, 8A961CCD0A0265E03D9952C733B593B02B5CF64E308D6B420276D2D6B20F86FC ] RemoteAccess    C:\Windows\System32\mprdim.dll
20:25:10.0198 0x0ad0  RemoteAccess - ok
20:25:10.0260 0x0ad0  [ 9E6894EA18DAFF37B63E1005F83AE4AB, 5D6DF994D297C875D547C7B111A571AA90D582DAECADE18A53F65AD988819E67 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
20:25:10.0286 0x0ad0  RemoteRegistry - ok
20:25:10.0373 0x0ad0  [ 5123F83CBC4349D065534EEB6BBDC42B, 92A3F38EA924D83D601BB93E3750F9DBC2DD963FB7ACF2A0E776297E21815225 ] RpcLocator      C:\Windows\system32\locator.exe
20:25:10.0403 0x0ad0  RpcLocator - ok
20:25:10.0457 0x0ad0  [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] RpcSs           C:\Windows\system32\rpcss.dll
20:25:10.0480 0x0ad0  RpcSs - ok
20:25:10.0519 0x0ad0  [ 9C508F4074A39E8B4B31D27198146FAD, 84913471E5A6C297B1EDABE45EF3FE7D2C4410EF04370F615109FD9E2690FFDB ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
20:25:10.0569 0x0ad0  rspndr - ok
20:25:10.0610 0x0ad0  [ D97D8259293B7A82CB891F37F997DF3F, 8C52C259368233A40F4C8F1CC2D9EC6478CFA670CD1393A7DB176C9123A93AD6 ] RTSTOR          C:\Windows\system32\drivers\RTSTOR.SYS
20:25:10.0655 0x0ad0  RTSTOR - ok
20:25:10.0675 0x0ad0  [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] SamSs           C:\Windows\system32\lsass.exe
20:25:10.0676 0x0ad0  SamSs - ok
20:25:10.0712 0x0ad0  [ 3CE8F073A557E172B330109436984E30, CEC281C6076FAA1E34372CF419C6308E73811316606B8D0D9055B7D8952BDC88 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
20:25:10.0751 0x0ad0  sbp2port - ok
20:25:10.0781 0x0ad0  [ 77B7A11A0C3D78D3386398FBBEA1B632, A3D290AB793BDC2F84C7B963300DFCE81CFE082A0FFF7489E8E5B14714892C00 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
20:25:10.0802 0x0ad0  SCardSvr - ok
20:25:10.0949 0x0ad0  [ F79CC0F814748E15538BF4D808030739, 396E94A309AFB163791095A25950CB7D85EEC43B416E1E7F056F430E1B719F4D ] Schedule        C:\Windows\system32\schedsvc.dll
20:25:10.0965 0x0ad0  Schedule - ok
20:25:11.0003 0x0ad0  [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] SCPolicySvc     C:\Windows\System32\certprop.dll
20:25:11.0004 0x0ad0  SCPolicySvc - ok
20:25:11.0102 0x0ad0  [ 716313D9F6B0529D03F726D5AAF6F191, 44FE994A11631C1D99C73026340BACE39973C65A1281D87A61B481C9B5FAB251 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
20:25:11.0141 0x0ad0  SDRSVC - ok
20:25:11.0162 0x0ad0  [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
20:25:11.0199 0x0ad0  secdrv - ok
20:25:11.0227 0x0ad0  [ FD5199D4D8A521005E4B5EE7FE00FA9B, 0FB7A1D300C72B1ADC423CC57343C17853E5F8ACFE3EA2C42FAC2FF72E502FBE ] seclogon        C:\Windows\system32\seclogon.dll
20:25:11.0229 0x0ad0  seclogon - ok
20:25:11.0318 0x0ad0  [ A9BBAB5759771E523F55563D6CBE140F, 415BF6F6A1E4C5F98DABF9C2EEAF8CA49730693046E5F94C7655683717EDAD75 ] SENS            C:\Windows\System32\sens.dll
20:25:11.0321 0x0ad0  SENS - ok
20:25:11.0353 0x0ad0  [ 68E44E331D46F0FB38F0863A84CD1A31, 0778D85B6869CE2610820DC9724360538BFE832426E898AEBC34E53D2AB4322B ] Serenum         C:\Windows\system32\drivers\serenum.sys
20:25:11.0420 0x0ad0  Serenum - ok
20:25:11.0452 0x0ad0  [ C70D69A918B178D3C3B06339B40C2E1B, 40BEEECA4C797A3355F4B01C57C2763C33028F27826315062320789A496D0810 ] Serial          C:\Windows\system32\drivers\serial.sys
20:25:11.0457 0x0ad0  Serial - ok
20:25:11.0494 0x0ad0  [ 8AF3D28A879BF75DB53A0EE7A4289624, C870BEBB969DCD9170E64584D1CD329A193D9FC812A45EF3574891110CA68B45 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
20:25:11.0532 0x0ad0  sermouse - ok
20:25:11.0585 0x0ad0  [ D2193326F729B163125610DBF3E17D57, 82C894E24E2C139C884246A693AD37BBF0A4E9375B7F7A288EF1DB22F89434B9 ] SessionEnv      C:\Windows\system32\sessenv.dll
20:25:11.0591 0x0ad0  SessionEnv - ok
20:25:11.0657 0x0ad0  [ 3EFA810BDCA87F6ECC24F9832243FE86, E50FEA94DB9851A46A8A71A8C061AC953A9D5B14585382B3F0FFC84931A0A68F ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
20:25:11.0692 0x0ad0  sffdisk - ok
20:25:11.0717 0x0ad0  [ E95D451F7EA3E583AEC75F3B3EE42DC5, B014BE4F9B0C79ECCE2537D1CF4AAD48ACB4C5AD3DACAC4444F0F465B9689921 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
20:25:11.0736 0x0ad0  sffp_mmc - ok
20:25:11.0764 0x0ad0  [ 3D0EA348784B7AC9EA9BD9F317980979, 2500CE188C9B71C50E966FA575303AEFE50934E376C530AECEC7C7533C15EF08 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
20:25:11.0806 0x0ad0  sffp_sd - ok
20:25:11.0835 0x0ad0  [ 46ED8E91793B2E6F848015445A0AC188, 34A97304F23EA153422848F6F1CAF8ADF0944EA781E12F027B6DEAF751A04B5D ] sfloppy         C:\Windows\system32\drivers\sfloppy.sys
20:25:11.0859 0x0ad0  sfloppy - ok
20:25:12.0098 0x0ad0  [ 74EC60E20516AAA573BE74F31175270F, 35A68231368DEE46FEF2A4E30BFAAC38F093FC5A362A7491ED38BDE11F0FC356 ] SftService      C:\Program Files\Dell DataSafe Local Backup\sftservice.EXE
20:25:12.0181 0x0ad0  SftService - ok
20:25:12.0250 0x0ad0  [ E1499BD0FF76B1B2FBBF1AF339D91165, 9A8F0403467E75880D3070C4D862489A75134383BAF8E7C45F8C5E7DFB0605A5 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
20:25:12.0297 0x0ad0  SharedAccess - ok
20:25:12.0358 0x0ad0  [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
20:25:12.0395 0x0ad0  ShellHWDetection - ok
20:25:12.0433 0x0ad0  [ 1D76624A09A054F682D746B924E2DBC3, DC903DD466AB8899883253F09477B02E4E93A31C8B279F9F02BD555F1AA083B7 ] sisagp          C:\Windows\system32\drivers\sisagp.sys
20:25:12.0478 0x0ad0  sisagp - ok
20:25:12.0504 0x0ad0  [ 43CB7AA756C7DB280D01DA9B676CFDE2, 08484CAEA0518C0A4CCCD292D8C803B27FEC453537EE1E4CEE74A7208356A474 ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
20:25:12.0545 0x0ad0  SiSRaid2 - ok
20:25:12.0626 0x0ad0  [ A99C6C8B0BAA970D8AA59DDC50B57F94, 97AC9DD6DC4F58AC60E819B999BB157663EE7C1739521D16768AA9AC00DAD012 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
20:25:12.0684 0x0ad0  SiSRaid4 - ok
20:25:13.0031 0x0ad0  [ 862BB4CBC05D80C5B45BE430E5EF872F, F4961B22C93E472C8C862421AA231CDDA9E40D3958741A1D666357F22CC3143D ] slsvc           C:\Windows\system32\SLsvc.exe
20:25:13.0251 0x0ad0  slsvc - ok
20:25:13.0356 0x0ad0  [ 6EDC422215CD78AA8A9CDE6B30ABBD35, D8342BC3152859F4F7512E85ABEC61147DBCAB515458644728874E42F639D6CA ] SLUINotify      C:\Windows\system32\SLUINotify.dll
20:25:13.0403 0x0ad0  SLUINotify - ok
20:25:13.0430 0x0ad0  [ 7B75299A4D201D6A6533603D6914AB04, 172BE3951F06B1991EF70B71EB91786D1EFC4E381C22BCA3A5F622CD59F3227E ] Smb             C:\Windows\system32\DRIVERS\smb.sys
20:25:13.0479 0x0ad0  Smb - ok
20:25:13.0511 0x0ad0  [ 2A146A055B4401C16EE62D18B8E2A032, D0930FFA53951C92F56E1ECB41374F4C0AA01ECBF99F474513A21EAD579CFE47 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
20:25:13.0540 0x0ad0  SNMPTRAP - ok
20:25:13.0576 0x0ad0  [ 7AEBDEEF071FE28B0EEF2CDD69102BFF, E03BEE733F4C2A5F39946D4955679A290E22758DFCE4222EE69ABF64FC54EDF7 ] spldr           C:\Windows\system32\drivers\spldr.sys
20:25:13.0577 0x0ad0  spldr - ok
20:25:13.0687 0x0ad0  [ 8554097E5136C3BF9F69FE578A1B35F4, 2578545CFD647FB18F217B33C8CB4F0184A35F548659494056E455020CC15FB0 ] Spooler         C:\Windows\System32\spoolsv.exe
20:25:13.0693 0x0ad0  Spooler - ok
20:25:13.0793 0x0ad0  [ DC7E6FCD8C51AEF8FF3F2E23C786014A, 02852FC293359BA89155367FA7D3A69922EC2574E5B85C842517272768BE8808 ] srv             C:\Windows\system32\DRIVERS\srv.sys
20:25:13.0805 0x0ad0  srv - ok
20:25:13.0871 0x0ad0  [ FF33AFF99564B1AA534F58868CBE41EF, EFBB005DA19E5B320009CBF93E686D8BFA6A50A23B5A5001C7C84C7D85EF7D49 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
20:25:13.0877 0x0ad0  srv2 - ok
20:25:13.0967 0x0ad0  [ 8AE0783E3EDCED90D4B2961887056A2B, D24168259988576B13EB2A4B2C11622A736174DDF11F6718D9A0DC9837F50EA5 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
20:25:13.0970 0x0ad0  srvnet - ok
20:25:14.0025 0x0ad0  [ 03D50B37234967433A5EA5BA72BC0B62, 7B61D6A4BF5D446A9473D058BC207FB6DA7C2FEFB8083F3B66CAC8907DBD8327 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
20:25:14.0030 0x0ad0  SSDPSRV - ok
20:25:14.0064 0x0ad0  [ 6F1A32E7B7B30F004D9A20AFADB14944, AA9D874A14CA4779E76701D2B02F4CCA92CD5917435FB4CACA149FCB2D1D4C4C ] SstpSvc         C:\Windows\system32\sstpsvc.dll
20:25:14.0069 0x0ad0  SstpSvc - ok
20:25:14.0227 0x0ad0  [ DDEB942850278D67EDC108D57F774BF8, 8212F3FC56587FC26ECFDD1E1AF6919F86671395B7614BFCDF698B5252F0BA55 ] STacSV          C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe
20:25:14.0367 0x0ad0  STacSV - ok
20:25:14.0465 0x0ad0  [ C4BE9C3AF8AF6F2E4CDD22FCABF77A1B, F65FB294790DF77D2E8C98CF6352025C7F02A3E8B54E55755418F1F3447631CA ] STHDA           C:\Windows\system32\DRIVERS\stwrt.sys
20:25:14.0547 0x0ad0  STHDA - ok
20:25:14.0581 0x0ad0  [ 5DE7D67E49B88F5F07F3E53C4B92A352, 6930A598C35646646ED0E91633797EFE139AE6CDD0012335BD1340754A22F997 ] stisvc          C:\Windows\System32\wiaservc.dll
20:25:14.0595 0x0ad0  stisvc - ok
20:25:14.0657 0x0ad0  [ 1D0063597C3666404FCF97698ABEB019, 352A63C97F930499BC598C2A398663377D7CCD4A42770E35635C90EDC4DA530A ] stllssvr        C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
20:25:14.0714 0x0ad0  stllssvr - ok
20:25:14.0756 0x0ad0  [ 7BA58ECF0C0A9A69D44B3DCA62BECF56, 23CC47FA2D6E183D69DB0D3D3F3081A830D94A58FBC0A9A295B3A56C51E9486A ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
20:25:14.0815 0x0ad0  swenum - ok
20:25:14.0878 0x0ad0  [ F21FD248040681CCA1FB6C9A03AAA93D, 32FE765841A183A1F2C1ACACBBF8CDB11E7D4D4396F9C9F6CFF1B51C9B620ED3 ] swprv           C:\Windows\System32\swprv.dll
20:25:14.0920 0x0ad0  swprv - ok
20:25:14.0936 0x0ad0  [ 192AA3AC01DF071B541094F251DEED10, 5C6EB56D1C39F3717EB754A1B37C8A618BA4F2107F64048E985D71FA04D1AD05 ] Symc8xx         C:\Windows\system32\drivers\symc8xx.sys
20:25:14.0974 0x0ad0  Symc8xx - ok
20:25:15.0020 0x0ad0  [ 8C8EB8C76736EBAF3B13B633B2E64125, A6C4845DDED81CCF4947612A4D6E42035136025BCD80812D2FF396927CAADEC5 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
20:25:15.0051 0x0ad0  Sym_hi - ok
20:25:15.0081 0x0ad0  [ 8072AF52B5FD103BBBA387A1E49F62CB, D336A7D008D145619E79043EBF5D0D455086BA1FEF89612BC2EA11CC363D82B0 ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
20:25:15.0112 0x0ad0  Sym_u3 - ok
20:25:15.0164 0x0ad0  [ 9A51B04E9886AA4EE90093586B0BA88D, 1666C29FBFA34174B506678C920636519051D03456A6DDCCD6FF708CAE5D9962 ] SysMain         C:\Windows\system32\sysmain.dll
20:25:15.0180 0x0ad0  SysMain - ok
20:25:15.0245 0x0ad0  [ 2DCA225EAE15F42C0933E998EE0231C3, 67C7913E41854DFA3043426B7D59AA1FBBB9DE01A6E6904E40A696A7C61A5F98 ] TabletInputService C:\Windows\System32\TabSvc.dll
20:25:15.0266 0x0ad0  TabletInputService - ok
20:25:15.0325 0x0ad0  [ D7673E4B38CE21EE54C59EEEB65E2483, 330D0AD13F5008D8569CE8E5EA0BBD69F54F59FEB54FD903FA18D2849CEC6AF0 ] TapiSrv         C:\Windows\System32\tapisrv.dll
20:25:15.0333 0x0ad0  TapiSrv - ok
20:25:15.0391 0x0ad0  [ CB05822CD9CC6C688168E113C603DBE7, 9DB8945BDC702BB13E9DE477F2D3CCA4CE0E9E8CE9B54CE1A25375F2A2C93F0E ] TBS             C:\Windows\System32\tbssvc.dll
20:25:15.0394 0x0ad0  TBS - ok
20:25:15.0568 0x0ad0  [ A4196D394207369E1431E8681B373312, BEF96BAB70FDF94F8CB2942BDEA9B4D934443E5305E3FD737809C3F7524B1E8E ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
20:25:15.0703 0x0ad0  Tcpip - ok
20:25:15.0824 0x0ad0  [ A4196D394207369E1431E8681B373312, BEF96BAB70FDF94F8CB2942BDEA9B4D934443E5305E3FD737809C3F7524B1E8E ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
20:25:15.0855 0x0ad0  Tcpip6 - ok
20:25:15.0958 0x0ad0  [ 95389980F70FC4990A4395A0B8BBE1D6, FB5CBC85733A4EC4FB9F210A5D4E5989F6A3F2995D895F5B41163CDFC04DB82C ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
20:25:15.0960 0x0ad0  tcpipreg - ok
20:25:16.0011 0x0ad0  [ 5DCF5E267BE67A1AE926F2DF77FBCC56, E00C0A03AEE579B51B39930A72F39F4EFFE7CDA37187B0AE90F4E001AD15473B ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
20:25:16.0047 0x0ad0  TDPIPE - ok
20:25:16.0079 0x0ad0  [ 389C63E32B3CEFED425B61ED92D3F021, E4718E290678F00995E754AE66F1027D227BFAB9E1A1D2AC8E4EAD27DC50CB17 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
20:25:16.0119 0x0ad0  TDTCP - ok
20:25:16.0171 0x0ad0  [ EC565DFA3D9C45D8083B72DEC5B33710, BC4F41795AF98FD87F8CC92F946E6896BAC1925A35C3E5E159E8BF4E6A34A35D ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
20:25:16.0234 0x0ad0  tdx - ok
20:25:16.0266 0x0ad0  [ 3CAD38910468EAB9A6479E2F01DB43C7, 9D18C71EDF39743A0A592BC0873909D2B75B5B177B2672A865D1EEC0BFD2F61C ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
20:25:16.0374 0x0ad0  TermDD - ok
20:25:16.0441 0x0ad0  [ DBD84E59D631569EC3E756EF144E8431, 9E58629EC762584A2D294A619593620626F7CBE467045AD0F920B6CF1D4B4724 ] TermService     C:\Windows\System32\termsrv.dll
20:25:16.0455 0x0ad0  TermService - ok
20:25:16.0490 0x0ad0  [ C7230FBEE14437716701C15BE02C27B8, 8221DE73D77CF71C2857D78829E807D015D9CB8BDEE4BAFD6950BF0C718CC774 ] Themes          C:\Windows\system32\shsvcs.dll
20:25:16.0497 0x0ad0  Themes - ok
20:25:16.0541 0x0ad0  [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] THREADORDER     C:\Windows\system32\mmcss.dll
20:25:16.0543 0x0ad0  THREADORDER - ok
20:25:16.0596 0x0ad0  [ EC74E77D0EB004BD3A809B5F8FB8C2CE, 1E4BBC58D0E35D79C764CF1BA73602C5E29A5A2393D40332801D533E445C6667 ] TrkWks          C:\Windows\System32\trkwks.dll
20:25:16.0600 0x0ad0  TrkWks - ok
20:25:16.0654 0x0ad0  [ 97D9D6A04E3AD9B6C626B9931DB78DBA, 8E42133ED5EE5EEC414A8B11C1035385C6141E445EA9677F947D20768F25A877 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
20:25:16.0686 0x0ad0  TrustedInstaller - ok
20:25:16.0729 0x0ad0  [ F4EAA7ECBCB25DE901C9B7F2CDCDA0B3, 1CBB5106A32362ABDEE73BF170E205FE64DDBF826C5F6DFFCCD229F220B9C85E ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
20:25:16.0759 0x0ad0  tssecsrv - ok
20:25:16.0786 0x0ad0  [ CAECC0120AC49E3D2F758B9169872D38, 80DB15ADF5F4FF78D0C7D5081B6C0E8F1E5125872B60D23C19DA8E62C9DAC9A8 ] tunmp           C:\Windows\system32\DRIVERS\tunmp.sys
20:25:16.0809 0x0ad0  tunmp - ok
20:25:16.0880 0x0ad0  [ 300DB877AC094FEAB0BE7688C3454A9C, 3B36AA191FBE25B1A61150EAA2BDF8BA286DC4C052F6E98B0ED8202135553D8C ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
20:25:16.0913 0x0ad0  tunnel - ok
20:25:16.0954 0x0ad0  [ 7D33C4DB2CE363C8518D2DFCF533941F, C6A539AD31B0BD9F895E0A537783AA75D5760C8590D83BA832D59A9B090CA0E9 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
20:25:17.0000 0x0ad0  uagp35 - ok
20:25:17.0043 0x0ad0  [ D9728AF68C4C7693CB100B8441CBDEC6, A2CEE1EE4EF17106349F4E6967F504354801934179FBB3F10B9A4E3C30BC28CE ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
20:25:17.0114 0x0ad0  udfs - ok
20:25:17.0163 0x0ad0  [ ECEF404F62863755951E09C802C94AD5, 5D92062B3E371F196774EBFE840C78501E55A244DB2A49703C7AC0141C7DABF1 ] UI0Detect       C:\Windows\system32\UI0Detect.exe
20:25:17.0189 0x0ad0  UI0Detect - ok
20:25:17.0221 0x0ad0  [ B0ACFDC9E4AF279E9116C03E014B2B27, 455D30859E381361FF6EE8B01EDC22A2E66CD5EC22CA9F314E88009DB77A8BAF ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
20:25:17.0260 0x0ad0  uliagpkx - ok
20:25:17.0299 0x0ad0  [ 9224BB254F591DE4CA8D572A5F0D635C, C5E7B24587AC5A28ECA63300307AD95B8A846833340126AE378840A40E53C056 ] uliahci         C:\Windows\system32\drivers\uliahci.sys
20:25:17.0349 0x0ad0  uliahci - ok
20:25:17.0468 0x0ad0  [ 8514D0E5CD0534467C5FC61BE94A569F, A6EFB967044F88335469DB3351587E31CEC659BB6A7D8ED45C68329232C31BB9 ] UlSata          C:\Windows\system32\drivers\ulsata.sys
20:25:17.0510 0x0ad0  UlSata - ok
20:25:17.0563 0x0ad0  [ 38C3C6E62B157A6BC46594FADA45C62B, 44F87DC955CB4E35E0EB4C8B4E931472B33D97FE000C22370A06AD5EDCEFD0BA ] ulsata2         C:\Windows\system32\drivers\ulsata2.sys
20:25:17.0616 0x0ad0  ulsata2 - ok
20:25:17.0656 0x0ad0  [ 32CFF9F809AE9AED85464492BF3E32D2, 91AAA47AEF17F373276B01AC8FA823592A0C854541A7A9A3B78F2350DB964EBC ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
20:25:17.0676 0x0ad0  umbus - ok
20:25:17.0729 0x0ad0  [ 68308183F4AE0BE7BF8ECD07CB297999, 4444233CA3C42BEE50ED47553D4AE5A7C12D8F288D2FA4B2DAE1D9B9FEC1A72D ] upnphost        C:\Windows\System32\upnphost.dll
20:25:17.0739 0x0ad0  upnphost - ok
20:25:17.0788 0x0ad0  [ 6E421CCC57059B0186C6259CA3B6DFC9, E348BF23CCD6C14FD10C1689BBDC77E125245331F97BFE60D4C8FD9A8711CB59 ] USBAAPL         C:\Windows\system32\Drivers\usbaapl.sys
20:25:17.0827 0x0ad0  USBAAPL - ok
20:25:17.0859 0x0ad0  [ AAB0B5F72D2D726FBFDC895A2902DE1D, 7824AF6E2ADEA23F208526F3A62AD1BACDBBDB23E58EB5806890B0761529C50F ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
20:25:17.0904 0x0ad0  usbccgp - ok
20:25:17.0932 0x0ad0  [ E9476E6C486E76BC4898074768FB7131, D14B8F69A511DC1F990A9C123C18689AFE59659BA8130D248D8D03E9BD2143B6 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
20:25:17.0952 0x0ad0  usbcir - ok
20:25:18.0013 0x0ad0  [ 153E8515CB86F8BB5D1A8B478EBF4BB2, 0F1F79BA7C32ACAAE69184A56E67D6E18E2E2F07E0BE23F266401431169DAE14 ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
20:25:18.0071 0x0ad0  usbehci - ok
20:25:18.0109 0x0ad0  [ 2AE6BCEBD85D31317E433733DAF25888, 7B2C0E8703D0275A620160E479166EB7AA31B0F146507603535CEBF0BA4684A4 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
20:25:18.0169 0x0ad0  usbhub - ok
20:25:18.0251 0x0ad0  [ 38DBC7DD6CC5A72011F187425384388B, 456CFCD190035C3033709C8DC0F6DC4352BBF751D57C0C52DD04F8C301FEBACD ] usbohci         C:\Windows\system32\drivers\usbohci.sys
20:25:18.0275 0x0ad0  usbohci - ok
20:25:18.0352 0x0ad0  [ E75C4B5269091D15A2E7DC0B6D35F2F5, B0A4141B69B66276890836DE98EB8BC790D35CE59FA503060593E8CC12AA106B ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
20:25:18.0386 0x0ad0  usbprint - ok
20:25:18.0435 0x0ad0  [ 1D714B8497CD68307806D5D3F60A5169, 1914D92ECE39995168E3C8F5A7694B7A94954DB299410A2781D1321C8E60C3D9 ] usbscan         C:\Windows\system32\DRIVERS\usbscan.sys
20:25:18.0469 0x0ad0  usbscan - ok
20:25:18.0505 0x0ad0  [ BE3DA31C191BC222D9AD503C5224F2AD, 201FB0FDBF423342202686DC0D8A3221B7798AE04C04A649D3441C257C733CE8 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:25:18.0544 0x0ad0  USBSTOR - ok
20:25:18.0578 0x0ad0  [ 44056325428A8E4C755830426E29878F, 95F182047746D352B7DC2B22298D5E58738E1B787C110D1DE841C026FB8A67EB ] usbuhci         C:\Windows\system32\DRIVERS\usbuhci.sys
20:25:18.0606 0x0ad0  usbuhci - ok
20:25:18.0684 0x0ad0  [ E67998E8F14CB0627A769F6530BCB352, 60982F168E9BF13954328C728F55F4D3ADDC572CACB65289B0E895A63DAA08C1 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
20:25:18.0776 0x0ad0  usbvideo - ok
20:25:18.0804 0x0ad0  [ 1509E705F3AC1D474C92454A5C2DD81F, 7F525921A3513224F8B093A16E19B4235B300349A14B0B86EE11B7473BA53337 ] UxSms           C:\Windows\System32\uxsms.dll
20:25:18.0827 0x0ad0  UxSms - ok
20:25:18.0965 0x0ad0  [ CD88D1B7776DC17A119049742EC07EB4, 6B68B9EDB8C6BCB2644F1F004D5743E928509D12107D996F390A24A72E0AA528 ] vds             C:\Windows\System32\vds.exe
20:25:19.0004 0x0ad0  vds - ok
20:25:19.0040 0x0ad0  [ 87B06E1F30B749A114F74622D013F8D4, 06C06EF87F7DC668D23B50AA5F419F62474ACF90E325E167491BF290286D6594 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
20:25:19.0066 0x0ad0  vga - ok
20:25:19.0084 0x0ad0  [ 2E93AC0A1D8C79D019DB6C51F036636C, 8B6F3B4EE90691A22788915AD0F99D8EE617750430A34E7CEB9AB4FB4E581755 ] VgaSave         C:\Windows\System32\drivers\vga.sys
20:25:19.0113 0x0ad0  VgaSave - ok
20:25:19.0138 0x0ad0  [ 5D7159DEF58A800D5781BA3A879627BC, 499A8E51FDE61AE0D7C1812D1E5B331211A36BD095A4992C629B93DE6D80F4E6 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
20:25:19.0176 0x0ad0  viaagp - ok
20:25:19.0232 0x0ad0  [ C4F3A691B5BAD343E6249BD8C2D45DEE, 19DE07AD6CD51036FA8A6B8EE82F34D7F5264FF3A12CBE6E52BD036D0303E319 ] ViaC7           C:\Windows\system32\drivers\viac7.sys
20:25:19.0251 0x0ad0  ViaC7 - ok
20:25:19.0326 0x0ad0  [ AADF5587A4063F52C2C3FED7887426FC, 0A74791A236FDAFCD045CFB79A159245B94F7C2033E0CD830C1B76F0F994E06D ] viaide          C:\Windows\system32\drivers\viaide.sys
20:25:19.0397 0x0ad0  viaide - ok
20:25:19.0431 0x0ad0  [ 69503668AC66C77C6CD7AF86FBDF8C43, 2CE407674A58313737073F02B9A617460BBA84B36C3A16D98AE5ED45279F5006 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
20:25:19.0433 0x0ad0  volmgr - ok
20:25:19.0538 0x0ad0  [ 23E41B834759917BFD6B9A0D625D0C28, 9F60992805262F936E8DA33610FDF60A191ECAFC08BBF657C8F9A21833C8EFC5 ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
20:25:19.0547 0x0ad0  volmgrx - ok
20:25:19.0586 0x0ad0  [ 786DB5771F05EF300390399F626BF30A, 4A07BE5AEDBA4C15C2F9A91250F0488A0B0305C67BB7A037508D5CBF86D4E1B7 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
20:25:19.0593 0x0ad0  volsnap - ok
20:25:19.0640 0x0ad0  [ 587253E09325E6BF226B299774B728A9, C9F46197819C2A095456393C518A9B00B59ECDC54F464D038AA7F8DCCDB93CCF ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
20:25:19.0733 0x0ad0  vsmraid - ok
20:25:19.0974 0x0ad0  [ DB3D19F850C6EB32BDCB9BC0836ACDDB, D81FF1CDA87A2FE83EFD5B3FE01EFF940952F8BAEE70BEA3B2F6EF30E2121704 ] VSS             C:\Windows\system32\vssvc.exe
20:25:20.0108 0x0ad0  VSS - ok
20:25:20.0205 0x0ad0  [ 96EA68B9EB310A69C25EBB0282B2B9DE, C76D3427F8A2953CB4D96BBA1523679CBE1BBF7FA821A35D2FBEB3E67AC6A10B ] W32Time         C:\Windows\system32\w32time.dll
20:25:20.0214 0x0ad0  W32Time - ok
20:25:20.0249 0x0ad0  [ 48DFEE8F1AF7C8235D4E626F0C4FE031, A41D05BC0DA3C476C32E0A4DAF015DF7BADF28A03CE236D5596885FF1772F148 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
20:25:20.0275 0x0ad0  WacomPen - ok
20:25:20.0343 0x0ad0  [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
20:25:20.0383 0x0ad0  Wanarp - ok
20:25:20.0388 0x0ad0  [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
20:25:20.0390 0x0ad0  Wanarpv6 - ok
20:25:20.0445 0x0ad0  [ A3CD60FD826381B49F03832590E069AF, 213C5DB5E5D828264286FD7548527566D6160CCA780BC6853B7B28CECF329674 ] wcncsvc         C:\Windows\System32\wcncsvc.dll
20:25:20.0505 0x0ad0  wcncsvc - ok
20:25:20.0545 0x0ad0  [ 11BCB7AFCDD7AADACB5746F544D3A9C7, 0370E20FD12ED713F94E5CD76F068F7A7A5E7F42416DD2A8A41249020DA7DA31 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
20:25:20.0565 0x0ad0  WcsPlugInService - ok
20:25:20.0603 0x0ad0  [ 78FE9542363F297B18C027B2D7E7C07F, 6BC3ED2A48EF41E1EE597FD58271DB12256EC013518663331CD0FBCB3FC415EE ] Wd              C:\Windows\system32\drivers\wd.sys
20:25:20.0633 0x0ad0  Wd - ok
20:25:20.0805 0x0ad0  [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
20:25:20.0820 0x0ad0  Wdf01000 - ok
20:25:20.0851 0x0ad0  [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiServiceHost  C:\Windows\system32\wdi.dll
20:25:20.0855 0x0ad0  WdiServiceHost - ok
20:25:20.0860 0x0ad0  [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiSystemHost   C:\Windows\system32\wdi.dll
20:25:20.0864 0x0ad0  WdiSystemHost - ok
20:25:21.0003 0x0ad0  [ BB77BAA3E7FD8F1A5D092A96D37B5A2D, 880C37347091224DFB7C442252FE4A29FD7002DA6A8BA994B8CEAABC5E535593 ] WebClient       C:\Windows\System32\webclnt.dll
20:25:21.0011 0x0ad0  WebClient - ok
20:25:21.0073 0x0ad0  [ AE3736E7E8892241C23E4EBBB7453B60, 0F998116CC07CD719CB237EAE53BB16B2EDD6973828B9C1055EB981AEA0453D1 ] Wecsvc          C:\Windows\system32\wecsvc.dll
20:25:21.0102 0x0ad0  Wecsvc - ok
20:25:21.0145 0x0ad0  [ 670FF720071ED741206D69BD995EA453, 4B96F5E3545F69AE9EBC75DC4AB27B87306D656EE526AE39E7EC7E2B6F83F7FD ] wercplsupport   C:\Windows\System32\wercplsupport.dll
20:25:21.0170 0x0ad0  wercplsupport - ok
20:25:21.0199 0x0ad0  [ 32B88481D3B326DA6DEB07B1D03481E7, 821FBAF147E525ED15EB9391B16A96C6D5464841258B11F277EFB57A3BD50E37 ] WerSvc          C:\Windows\System32\WerSvc.dll
20:25:21.0205 0x0ad0  WerSvc - ok
20:25:21.0314 0x0ad0  [ 4575AA12561C5648483403541D0D7F2B, 2DBB7904285F16E879E1662C4CC4DFAA420D5EB24DDFC4BAC0B7616F5F44649A ] WinDefend       C:\Program Files\Windows Defender\mpsvc.dll
20:25:21.0323 0x0ad0  WinDefend - ok
20:25:21.0332 0x0ad0  WinHttpAutoProxySvc - ok
20:25:21.0550 0x0ad0  [ 6B2A1D0E80110E3D04E6863C6E62FD8A, EE8BC7C378993EFE90273764C83119EBF331768CD7B24DE949233C74A51306C2 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
20:25:21.0555 0x0ad0  Winmgmt - ok
20:25:21.0901 0x0ad0  [ 7CFE68BDC065E55AA5E8421607037511, C2CE76D52AD4E31FC4216E94457DC16ABF65A5F3E883F0BD97AD387FB7574533 ] WinRM           C:\Windows\system32\WsmSvc.dll
20:25:22.0003 0x0ad0  WinRM - ok
20:25:22.0156 0x0ad0  [ C008405E4FEEB069E30DA1D823910234, C392A7B5FEACB7D11A3A231C1AD65D533984E6E7429ECD3BFBF90A27E8DEB157 ] Wlansvc         C:\Windows\System32\wlansvc.dll
20:25:22.0174 0x0ad0  Wlansvc - ok
20:25:22.0181 0x0ad0  wltrysvc - ok
20:25:22.0241 0x0ad0  [ 2E7255D172DF0B8283CDFB7B433B864E, 60C786CF0EA4A29B309B9457F0496D5A0AF1F093FC2C5D88078865814B7DBBA3 ] WmiAcpi         C:\Windows\system32\DRIVERS\wmiacpi.sys
20:25:22.0243 0x0ad0  WmiAcpi - ok
20:25:22.0340 0x0ad0  [ 43BE3875207DCB62A85C8C49970B66CC, 27169F2E8A30807794407DA8F80611E4287F940AAE2A1F00F547901872FB9703 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
20:25:22.0428 0x0ad0  wmiApSrv - ok
20:25:22.0647 0x0ad0  [ 3978704576A121A9204F8CC49A301A9B, 936CC13B90A183613BDA4081556C96D48CA415B5F65D61E18CB5F2E51EEBE59F ] WMPNetworkSvc   C:\Program Files\Windows Media Player\wmpnetwk.exe
20:25:22.0710 0x0ad0  WMPNetworkSvc - ok
20:25:22.0863 0x0ad0  [ CFC5A04558F5070CEE3E3A7809F3FF52, 45899E04000E21C4E009BE8B6149F199A5B2E0512C657A525770BF9DBFED7D2B ] WPCSvc          C:\Windows\System32\wpcsvc.dll
20:25:22.0956 0x0ad0  WPCSvc - ok
20:25:23.0014 0x0ad0  [ 801FBDB89D472B3C467EB112A0FC9246, C24053FA12732089384D3AF06C676FF201D282FC5AD56A42B6EE8BAED4379CB2 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
20:25:23.0021 0x0ad0  WPDBusEnum - ok
20:25:23.0061 0x0ad0  [ DE9D36F91A4DF3D911626643DEBF11EA, 8029ECE76E29276BFB6ED3387AC560A9A779AAF683A4416E96334FAF7BDBADA0 ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
20:25:23.0089 0x0ad0  WpdUsb - ok
20:25:23.0343 0x0ad0  [ F8D3544ACBCE9110362119F7C10D848E, 31C49201A931751A36286874AC0B929D886F490D7CE48CCC9283850A56AD9FD9 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
20:25:23.0365 0x0ad0  WPFFontCache_v0400 - ok
20:25:23.0410 0x0ad0  [ E3A3CB253C0EC2494D4A61F5E43A389C, 10BA8B102E31B961819E524FCA5FA817B588EC77FB26B4E176D0A5CFF11EDF79 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
20:25:23.0438 0x0ad0  ws2ifsl - ok
20:25:23.0483 0x0ad0  [ 1CA6C40261DDC0425987980D0CD2AAAB, 727C1E3A170316641F832A8D197EDA6D6EE1206E4ED7B741E5A4017B7F2F7B88 ] wscsvc          C:\Windows\System32\wscsvc.dll
20:25:23.0488 0x0ad0  wscsvc - ok
20:25:23.0698 0x0ad0  [ 4422AC5ED8D4C2F0DB63E71D4C069DD7, B010DCC7B802C26A701A7DE1CA1B21D6B43D99FE88524D015C9228376B0BDA6E ] WSDPrintDevice  C:\Windows\system32\DRIVERS\WSDPrint.sys
20:25:23.0728 0x0ad0  WSDPrintDevice - ok
20:25:23.0780 0x0ad0  [ 65D1FF8AAFF4A7D8F787A290E5087816, 9681C1B3B683E7F9531CD223C4C09877C829EFF3C707DD826752A815C1CF8982 ] WSDScan         C:\Windows\system32\DRIVERS\WSDScan.sys
20:25:23.0824 0x0ad0  WSDScan - ok
20:25:23.0834 0x0ad0  WSearch - ok
20:25:24.0192 0x0ad0  [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv        C:\Windows\system32\wuaueng.dll
20:25:24.0337 0x0ad0  wuauserv - ok
20:25:24.0484 0x0ad0  [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
20:25:24.0515 0x0ad0  WudfPf - ok
20:25:24.0582 0x0ad0  [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
20:25:24.0629 0x0ad0  WUDFRd - ok
20:25:24.0691 0x0ad0  [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
20:25:24.0738 0x0ad0  wudfsvc - ok
20:25:24.0748 0x0ad0  yksvc - ok
20:25:24.0804 0x0ad0  [ 1A51DF1A5C658D534ED980D18F7982DE, ACC33646033D43B8FBCAA1C03CC8307B89FEE40ACFE4630D2A226CFB56B9D992 ] yukonwlh        C:\Windows\system32\DRIVERS\yk60x86.sys
20:25:24.0815 0x0ad0  yukonwlh - ok
20:25:24.0824 0x0ad0  ================ Scan global ===============================
20:25:24.0891 0x0ad0  [ 2F2DFC846D75D680B9018823A8B5EF07, DBC823CF0C659B6D7482CB080CD042EC6BBAEDB6297DB712CADA1BCEAA8A95C8 ] C:\Windows\system32\basesrv.dll
20:25:24.0977 0x0ad0  [ A508314231C49AEE86987CEA3EAECAD1, D29BCFA967C23C7264592576D62D95FA8C687E8662D19DCCC73653A9EFB6340D ] C:\Windows\system32\winsrv.dll
20:25:25.0067 0x0ad0  [ A508314231C49AEE86987CEA3EAECAD1, D29BCFA967C23C7264592576D62D95FA8C687E8662D19DCCC73653A9EFB6340D ] C:\Windows\system32\winsrv.dll
20:25:25.0138 0x0ad0  [ 4F0A7910FC7D8A66433FA9961EEF8BB5, 2086EDEE8CF9CC9BDBDC03018F7C28BB56172F941CB4D6F3D857BCF82B32FB6B ] C:\Windows\system32\services.exe
20:25:25.0154 0x0ad0  [ Global ] - ok
20:25:25.0154 0x0ad0  ================ Scan MBR ==================================
20:25:25.0182 0x0ad0  [ CDB4DE4BBD714F152979DA2DCBEF57EB ] \Device\Harddisk0\DR0
20:25:25.0961 0x0ad0  \Device\Harddisk0\DR0 - ok
20:25:25.0962 0x0ad0  ================ Scan VBR ==================================
20:25:26.0060 0x0ad0  [ AA4E06478E79009610F297B7B978B815 ] \Device\Harddisk0\DR0\Partition1
20:25:26.0136 0x0ad0  \Device\Harddisk0\DR0\Partition1 - ok
20:25:26.0159 0x0ad0  [ 2F5CA4A860936E3BD9D462C071BE5DC6 ] \Device\Harddisk0\DR0\Partition2
20:25:26.0194 0x0ad0  \Device\Harddisk0\DR0\Partition2 - ok
20:25:26.0194 0x0ad0  ================ Scan generic autorun ======================
20:25:26.0367 0x0ad0  [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\Sidebar.exe
20:25:26.0527 0x0ad0  Sidebar - ok
20:25:26.0534 0x0ad0  WindowsWelcomeCenter - ok
20:25:26.0840 0x0ad0  [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\Sidebar.exe
20:25:26.0866 0x0ad0  Sidebar - ok
20:25:26.0871 0x0ad0  WindowsWelcomeCenter - ok
20:25:27.0155 0x0ad0  [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\Sidebar.exe
20:25:27.0187 0x0ad0  Sidebar - ok
20:25:27.0190 0x0ad0  Waiting for KSN requests completion. In queue: 57
20:25:28.0190 0x0ad0  Waiting for KSN requests completion. In queue: 57
20:25:29.0190 0x0ad0  Waiting for KSN requests completion. In queue: 57
20:25:30.0211 0x0ad0  AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.8.204.0 ), 0x61000 ( enabled : updated )
20:25:30.0220 0x0ad0  Win FW state via NFP2: enabled ( trusted )
20:25:45.0595 0x0ad0  ============================================================
20:25:45.0595 0x0ad0  Scan finished
20:25:45.0595 0x0ad0  ============================================================
20:25:45.0608 0x051c  Detected object count: 0
20:25:45.0608 0x051c  Actual detected object count: 0
 

Great  :thumbup:

 

 

Just want to let you know that Vista was most likely the worst Operating System that ever came out. If your still running Vista your computer is most likely pretty old, you may want to think about upgrading to a new one with Windows 10 that is so much more secure.

 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
Do not click on any links in the top Advertisment.
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
     
    [external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
    • Download the one from Bleeping Computer
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
      •  
        [external image: 0841859c-1a35-4dbd-b41a-e720629e3e22_zps]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • Ken, thanks for your continued support.

          I posted all the logs you requested.

          ADWCleaner has 5 logs and i posted them all.

           

          ADWCleaner(S1)

          # AdwCleaner v5.026 - Logfile created 22/12/2015 at 03:52:46
          # Updated 21/12/2015 by Xplode
          # Database : 2015-12-21.3 [Server]
          # Operating system : Windows Vista (TM) Home Basic Service Pack 2 (x86)
          # Username : Linda - LINDA-PC
          # Running from : C:\Users\Linda.Linda-PC\Desktop\AdwCleaner.exe
          # Option : Scan
          # Support : http://toolslib.net/forum
           
          ADWCleaner(S2)
          # AdwCleaner v5.026 - Logfile created 22/12/2015 at 03:57:15
          # Updated 21/12/2015 by Xplode
          # Database : 2015-12-21.3 [Server]
          # Operating system : Windows Vista (TM) Home Basic Service Pack 2 (x86)
          # Username : Linda - LINDA-PC
          # Running from : C:\Users\Linda.Linda-PC\Desktop\AdwCleaner.exe
          # Option : Scan
          # Support : http://toolslib.net/forum
           
          ***** [ Services ] *****
           
          Service Found : RecipeHub_2jService
           
          ***** [ Folders ] *****
           
          Folder Found : C:\Program Files\Viewpoint
          Folder Found : C:\Program Files\Coupons.com CouponBar
          Folder Found : C:\Program Files\Coupons
          Folder Found : C:\Program Files\TweakBit
          Folder Found : C:\Program Files\RecipeHub_2j
          Folder Found : C:\Program Files\RecipeHub_2jEI
          Folder Found : C:\ProgramData\TweakBit
          Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
          Folder Found : C:\Users\Linda.Linda-PC\AppData\LocalLow\Toolbar4
          Folder Found : C:\Users\Linda.Linda-PC\AppData\LocalLow\RecipeHub_2j
          Folder Found : C:\Users\Linda.Linda-PC\AppData\LocalLow\RecipeHub_2jEI
          Folder Found : C:\Users\Linda.Linda-PC\AppData\Roaming\catalina – print savings
          Folder Found : C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\catalina – print savings
           
          ***** [ Files ] *****
           
          File Found : C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\ask-web-search.xml
          File Found : C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\bingp.xml
          File Found : C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\web-search.xml
          File Found : C:\Users\Public\Desktop\eBay.lnk
           
          ***** [ DLL ] *****
           
           
          ***** [ Shortcuts ] *****
           
           
          ***** [ Scheduled tasks ] *****
           
           
          ***** [ Registry ] *****
           
          Key Found : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
          Key Found : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
          Key Found : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler
          Key Found : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1
          Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
          Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
          Key Found : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
          Key Found : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbTask
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1
          Key Found : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook
          Key Found : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook.1
          Key Found : HKLM\SOFTWARE\MozillaPlugins\@RecipeHub_2j.com/Plugin
          Key Found : HKLM\SOFTWARE\MozillaPlugins\@RecipeHub_2j.com/Plugin
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.DynamicBarButton
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.DynamicBarButton.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.FeedManager
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.FeedManager.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.HTMLMenu
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.HTMLMenu.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.HTMLPanel
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.HTMLPanel.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.MultipleButton
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.MultipleButton.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.PseudoTransparentPlugin
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.PseudoTransparentPlugin.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.Radio
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.Radio.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.RadioSettings
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.RadioSettings.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.ScriptButton
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.ScriptButton.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.SettingsPlugin
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.SettingsPlugin.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.ThirdPartyInstaller
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.ThirdPartyInstaller.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.ToolbarPlugin
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.ToolbarPlugin.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.UrlAlertButton
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.UrlAlertButton.1
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.XMLSessionPlugin
          Key Found : HKLM\SOFTWARE\Classes\RecipeHub_2j.XMLSessionPlugin.1
          Key Found : HKLM\SOFTWARE\Classes\TBSB07898.IEToolbar
          Key Found : HKLM\SOFTWARE\Classes\TBSB07898.IEToolbar.1
          Key Found : HKLM\SOFTWARE\Classes\TBSB07898.TBSB07898
          Key Found : HKLM\SOFTWARE\Classes\TBSB07898.TBSB07898.3
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.TBSB07898
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.TBSB07898.1
          Key Found : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
          Key Found : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
          Key Found : HKCU\Software\Classes\CLSID\{cc8ae5b8-005b-4b1a-a27d-307eddffe5c8}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{D433A9D0-8267-40CB-8AD5-24F22FA5373F}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{06e3475c-5521-4de8-bb12-50720f21631c}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{26abd3e0-6a39-48d9-bf04-2bb873d80348}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{2bd71ade-f254-477e-add5-b2423a83b355}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{31917ad2-f351-44c9-997e-6099011074df}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{325174ef-2148-410e-ad4c-31156ec79a67}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{3a8ab5b2-2afb-47b0-817e-583e35765b07}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{4271790f-c050-4034-85de-3d8ca2bdac6c}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{4e002b61-e524-4b3f-b0b5-8e0318284d21}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{51653395-fe70-4b72-ba08-3c64b44f5d43}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{5841fe52-af7d-4cb5-be33-1ab40c3edd25}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{6809c391-babc-426d-83e3-81e096a6b9ad}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{7f14cca5-74e6-492e-bf0f-58a7b4b2881c}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{ab61ca60-662a-437c-8815-4ce53990ed02}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{b7acdf9c-c4f9-4d5d-998e-b147866b4d4c}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{c6de2e64-0666-46c8-97f2-d0c411692dfd}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{CB4B8622-CB4A-4C03-8CC1-2B4052F08553}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{cc43333b-9017-452b-bfc6-e41b5a8555af}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{cf51de5b-eb36-4114-bb69-84df63fbadb4}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{daab1633-ec52-49ae-ba45-74b3e319c6c6}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{dc6051b9-dd61-44cb-8ee6-fa28eae44bf9}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{e1eace5b-5208-4b5c-a060-4691cc04389f}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{f1f85700-aaec-4b9c-aa04-cc7cf9fdc5fd}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{c6de2e64-0666-46c8-97f2-d0c411692dfd}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{10730512-1D08-4B6E-9272-3DB1EF325A57}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{206FB111-F5AE-40A1-84D1-9F730D56077A}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{20F22058-994B-4C59-A8F4-149650E39323}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{26CB74E8-A80A-49BD-B680-7CD5EDB2A62C}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{2D9E9F86-DBD3-41E4-94E0-16142BC63F0E}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{30C04BB3-2216-424A-B101-608DFF1D54C5}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{35400B56-968C-4135-8623-7EF58BB79745}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{36E778E5-F988-4689-A78C-03E38601EDE7}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{38F163B3-A02C-473F-BB97-449A4E4BE0E6}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{3C406CFD-4BAD-4C6A-A40E-109AFA4A7032}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{422B2601-6455-4D7E-AA66-85CBCDF93248}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{46666EC1-F22B-465B-B1D3-A56976459C69}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{4768BCA3-6919-4AF9-BA11-14F9883FF453}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{546B91E6-7CC3-4A67-B081-AE4FDE071BBD}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{586A3C61-F969-4B60-8788-0435E902CC33}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{6F512A90-8617-4C8B-92A4-2697BCC50EB3}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{7DB225B9-A986-4DF8-BD9E-0D452DF30B4E}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{931A4276-9972-4AC1-BB18-32A5997AAF08}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{945C482E-9508-4AC7-BF43-07CC9B5E2D45}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{99EE7955-E10B-4100-9923-8BCCCE33F98F}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{A142B533-344A-426D-83CF-C9F6034DE0A8}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{C9B21032-EACD-486B-A80B-3718585B876C}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{D7AE6EC0-D616-438E-8CA7-CC322D481F44}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{DE67D450-2D67-4AE5-8D7A-43642382855B}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{F12FADBF-18EC-414F-8D93-A6E86E556909}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{F1C72F35-B4B0-403C-8118-2B06F678FEB5}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{F614ED5D-AD54-46DA-8516-D28F15327FE7}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{FA88083E-CB43-4AFE-BDD5-6A9A43B897B7}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{36e778e5-f988-4689-a78c-03e38601ede7}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{a142b533-344a-426d-83cf-c9f6034de0a8}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{143B3E67-3D6E-4F36-8E62-063D43B29BB0}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{1695AEEE-5B43-4FBB-B1BC-9E5E6C30C495}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2F08F2FA-BC7D-47DC-B75C-6D4B9AFB792C}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{32F1AAFC-6DAB-4B99-8AC2-4B721B1E06D1}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4DAA8599-9CC2-4C34-A606-3B0A8E9B3C4A}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{5D67DB82-A94B-4D44-BE81-5FB62671B982}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{795C5E1E-BFDB-468F-8B8A-309C24219676}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8DFA0267-C525-420A-B69B-9408E9843DC7}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{CE493EA1-30FC-4CBE-9DE9-6A57DBC0AF69}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DFF81829-A59F-44DB-8010-2EEDADC2465F}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E7FC6003-06E8-4C2D-8756-A30FE9C95C73}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06e3475c-5521-4de8-bb12-50720f21631c}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b7acdf9c-c4f9-4d5d-998e-b147866b4d4c}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{06e3475c-5521-4de8-bb12-50720f21631c}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{b7acdf9c-c4f9-4d5d-998e-b147866b4d4c}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{cf51de5b-eb36-4114-bb69-84df63fbadb4}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{dc6051b9-dd61-44cb-8ee6-fa28eae44bf9}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{06e3475c-5521-4de8-bb12-50720f21631c}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{b7acdf9c-c4f9-4d5d-998e-b147866b4d4c}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{cf51de5b-eb36-4114-bb69-84df63fbadb4}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{325174ef-2148-410e-ad4c-31156ec79a67}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6809c391-babc-426d-83e3-81e096a6b9ad}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ab61ca60-662a-437c-8815-4ce53990ed02}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CB4B8622-CB4A-4C03-8CC1-2B4052F08553}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{daab1633-ec52-49ae-ba45-74b3e319c6c6}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{dc6051b9-dd61-44cb-8ee6-fa28eae44bf9}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c6de2e64-0666-46c8-97f2-d0c411692dfd}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{36E778E5-F988-4689-A78C-03E38601EDE7}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A142B533-344A-426D-83CF-C9F6034DE0A8}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{36e778e5-f988-4689-a78c-03e38601ede7}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4acf5837-1634-4afc-a583-53405f15ee0b}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a142b533-344a-426d-83cf-c9f6034de0a8}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c6de2e64-0666-46c8-97f2-d0c411692dfd}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{db082b40-5dde-4df1-8ee1-76a3e98966d1}
          Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{cf51de5b-eb36-4114-bb69-84df63fbadb4}]
          Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
          Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{cc8ae5b8-005b-4b1a-a27d-307eddffe5c8}]
          Key Found : HKCU\Software\AppDataLow\Software\RecipeHub_2j
          Key Found : HKCU\Software\AppDataLow\Software\RecipeHub_2jEI
          Key Found : HKLM\SOFTWARE\RecipeHub_2j
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37331C16-3E97-4A20-80D8-BFB43AB0E2FB}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RecipeHub_2jbar Uninstall
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{37331C16-3E97-4A20-80D8-BFB43AB0E2FB}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\RecipeHub_2jbar Uninstall
          Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9230cb90-79de-4945-88a4-762244a25bc8}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9230cb90-79de-4945-88a4-762244a25bc8}
           
          ***** [ Web browsers ] *****
           
          [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Found : user_pref("browser.search.hiddenOneOffs", "Ask Web Search,Yahoo,Amazon.com,eBay,Twitter,Wikipedia (en),Web Search,Bing ,DuckDuckGo");
          [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._39Members_.lastActivePing", "1420155355920");
          [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
          [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "");
          [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark.lastInstalled", "[removed]");
          [C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
          [C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
           
          ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [19687 bytes] ##########
           
          ADWCleaner(S3)
          # AdwCleaner v5.026 - Logfile created 22/12/2015 at 04:02:39
          # Updated 21/12/2015 by Xplode
          # Database : 2015-12-21.3 [Server]
          # Operating system : Windows Vista (TM) Home Basic Service Pack 2 (x86)
          # Username : Linda - LINDA-PC
          # Running from : C:\Users\Linda.Linda-PC\Desktop\AdwCleaner.exe
          # Option : Scan
          # Support : http://toolslib.net/forum
           
          ***** [ Services ] *****
           
           
          ***** [ Folders ] *****
           
          Folder Found : C:\Users\Linda.Linda-PC\AppData\LocalLow\Toolbar4
          Folder Found : C:\Users\Linda.Linda-PC\AppData\Roaming\catalina – print savings
          Folder Found : C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\catalina – print savings
           
          ***** [ Files ] *****
           
          File Found : C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\ask-web-search.xml
          File Found : C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\bingp.xml
          File Found : C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\web-search.xml
          File Found : C:\Users\Public\Desktop\eBay.lnk
           
          ***** [ DLL ] *****
           
           
          ***** [ Shortcuts ] *****
           
           
          ***** [ Scheduled tasks ] *****
           
           
          ***** [ Registry ] *****
           
          Key Found : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
          Key Found : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
          Key Found : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler
          Key Found : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1
          Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
          Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
          Key Found : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
          Key Found : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbTask
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
          Key Found : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1
          Key Found : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook
          Key Found : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook.1
          Key Found : HKLM\SOFTWARE\MozillaPlugins\@RecipeHub_2j.com/Plugin
          Key Found : HKLM\SOFTWARE\Classes\TBSB07898.IEToolbar
          Key Found : HKLM\SOFTWARE\Classes\TBSB07898.IEToolbar.1
          Key Found : HKLM\SOFTWARE\Classes\TBSB07898.TBSB07898
          Key Found : HKLM\SOFTWARE\Classes\TBSB07898.TBSB07898.3
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.TBSB07898
          Key Found : HKLM\SOFTWARE\Classes\Toolbar3.TBSB07898.1
          Key Found : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
          Key Found : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{D433A9D0-8267-40CB-8AD5-24F22FA5373F}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{c6de2e64-0666-46c8-97f2-d0c411692dfd}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{10730512-1D08-4B6E-9272-3DB1EF325A57}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{206FB111-F5AE-40A1-84D1-9F730D56077A}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{20F22058-994B-4C59-A8F4-149650E39323}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{26CB74E8-A80A-49BD-B680-7CD5EDB2A62C}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{2D9E9F86-DBD3-41E4-94E0-16142BC63F0E}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{30C04BB3-2216-424A-B101-608DFF1D54C5}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{35400B56-968C-4135-8623-7EF58BB79745}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{36E778E5-F988-4689-A78C-03E38601EDE7}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{38F163B3-A02C-473F-BB97-449A4E4BE0E6}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{3C406CFD-4BAD-4C6A-A40E-109AFA4A7032}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{422B2601-6455-4D7E-AA66-85CBCDF93248}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{46666EC1-F22B-465B-B1D3-A56976459C69}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{4768BCA3-6919-4AF9-BA11-14F9883FF453}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{546B91E6-7CC3-4A67-B081-AE4FDE071BBD}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{586A3C61-F969-4B60-8788-0435E902CC33}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{6F512A90-8617-4C8B-92A4-2697BCC50EB3}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{7DB225B9-A986-4DF8-BD9E-0D452DF30B4E}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{931A4276-9972-4AC1-BB18-32A5997AAF08}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{945C482E-9508-4AC7-BF43-07CC9B5E2D45}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{99EE7955-E10B-4100-9923-8BCCCE33F98F}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{A142B533-344A-426D-83CF-C9F6034DE0A8}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{C9B21032-EACD-486B-A80B-3718585B876C}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{D7AE6EC0-D616-438E-8CA7-CC322D481F44}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{DE67D450-2D67-4AE5-8D7A-43642382855B}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{F12FADBF-18EC-414F-8D93-A6E86E556909}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{F1C72F35-B4B0-403C-8118-2B06F678FEB5}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{F614ED5D-AD54-46DA-8516-D28F15327FE7}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{FA88083E-CB43-4AFE-BDD5-6A9A43B897B7}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{36e778e5-f988-4689-a78c-03e38601ede7}
          Key Found : HKLM\SOFTWARE\Classes\Interface\{a142b533-344a-426d-83cf-c9f6034de0a8}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{143B3E67-3D6E-4F36-8E62-063D43B29BB0}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{1695AEEE-5B43-4FBB-B1BC-9E5E6C30C495}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2F08F2FA-BC7D-47DC-B75C-6D4B9AFB792C}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{32F1AAFC-6DAB-4B99-8AC2-4B721B1E06D1}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4DAA8599-9CC2-4C34-A606-3B0A8E9B3C4A}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{5D67DB82-A94B-4D44-BE81-5FB62671B982}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{795C5E1E-BFDB-468F-8B8A-309C24219676}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{8DFA0267-C525-420A-B69B-9408E9843DC7}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{CE493EA1-30FC-4CBE-9DE9-6A57DBC0AF69}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{DFF81829-A59F-44DB-8010-2EEDADC2465F}
          Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E7FC6003-06E8-4C2D-8756-A30FE9C95C73}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{36E778E5-F988-4689-A78C-03E38601EDE7}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A142B533-344A-426D-83CF-C9F6034DE0A8}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{36e778e5-f988-4689-a78c-03e38601ede7}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4acf5837-1634-4afc-a583-53405f15ee0b}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a142b533-344a-426d-83cf-c9f6034de0a8}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c6de2e64-0666-46c8-97f2-d0c411692dfd}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{db082b40-5dde-4df1-8ee1-76a3e98966d1}
          Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37331C16-3E97-4A20-80D8-BFB43AB0E2FB}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{37331C16-3E97-4A20-80D8-BFB43AB0E2FB}
          Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9230cb90-79de-4945-88a4-762244a25bc8}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9230cb90-79de-4945-88a4-762244a25bc8}
           
          ***** [ Web browsers ] *****
           
          [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Found : user_pref("browser.search.hiddenOneOffs", "Ask Web Search,Yahoo,Amazon.com,eBay,Twitter,Wikipedia (en),Web Search,Bing ,DuckDuckGo");
          [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark._39Members_.lastActivePing", "1420155355920");
          [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
          [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "");
          [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Found : user_pref("extensions.toolbar.mindspark.lastInstalled", "[removed]");
          [C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
          [C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
           
          ########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [13003 bytes] ##########
           
          ADWCleaner(C1)
          # AdwCleaner v5.026 - Logfile created 22/12/2015 at 03:59:59
          # Updated 21/12/2015 by Xplode
          # Database : 2015-12-21.3 [Server]
          # Operating system : Windows Vista (TM) Home Basic Service Pack 2 (x86)
          # Username : Linda - LINDA-PC
          # Running from : C:\Users\Linda.Linda-PC\Desktop\AdwCleaner.exe
          # Option : Cleaning
          # Support : http://toolslib.net/forum
           
          ***** [ Services ] *****
           
          [-] Service Deleted : RecipeHub_2jService
           
          ***** [ Folders ] *****
           
          [-] Folder Deleted : C:\Program Files\Viewpoint
          [-] Folder Deleted : C:\Program Files\Coupons.com CouponBar
          [-] Folder Deleted : C:\Program Files\Coupons
          [-] Folder Deleted : C:\Program Files\TweakBit
          [-] Folder Deleted : C:\Program Files\RecipeHub_2j
          [-] Folder Deleted : C:\Program Files\RecipeHub_2jEI
          [-] Folder Deleted : C:\ProgramData\TweakBit
          [-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
           
          ADWCleaner(C2)
          # AdwCleaner v5.026 - Logfile created 22/12/2015 at 04:03:51
          # Updated 21/12/2015 by Xplode
          # Database : 2015-12-21.3 [Server]
          # Operating system : Windows Vista (TM) Home Basic Service Pack 2 (x86)
          # Username : Linda - LINDA-PC
          # Running from : C:\Users\Linda.Linda-PC\Desktop\AdwCleaner.exe
          # Option : Cleaning
          # Support : http://toolslib.net/forum
           
          ***** [ Services ] *****
           
           
          ***** [ Folders ] *****
           
          [-] Folder Deleted : C:\Users\Linda.Linda-PC\AppData\LocalLow\Toolbar4
          [-] Folder Deleted : C:\Users\Linda.Linda-PC\AppData\Roaming\catalina – print savings
          [-] Folder Deleted : C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\catalina – print savings
           
          ***** [ Files ] *****
           
          [-] File Deleted : C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\ask-web-search.xml
          [-] File Deleted : C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\bingp.xml
          [-] File Deleted : C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\searchplugins\web-search.xml
          [-] File Deleted : C:\Users\Public\Desktop\eBay.lnk
           
          ***** [ DLLs ] *****
           
           
          ***** [ Shortcuts ] *****
           
           
          ***** [ Scheduled tasks ] *****
           
           
          ***** [ Registry ] *****
           
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
          [-] Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler
          [-] Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
          [-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook
          [-] Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook.1
          [-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@RecipeHub_2j.com/Plugin
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.IEToolbar
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.IEToolbar.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.TBSB07898
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.TBSB07898.3
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.TBSB07898
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.TBSB07898.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D433A9D0-8267-40CB-8AD5-24F22FA5373F}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{c6de2e64-0666-46c8-97f2-d0c411692dfd}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10730512-1D08-4B6E-9272-3DB1EF325A57}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{206FB111-F5AE-40A1-84D1-9F730D56077A}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{20F22058-994B-4C59-A8F4-149650E39323}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{26CB74E8-A80A-49BD-B680-7CD5EDB2A62C}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D9E9F86-DBD3-41E4-94E0-16142BC63F0E}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{30C04BB3-2216-424A-B101-608DFF1D54C5}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{35400B56-968C-4135-8623-7EF58BB79745}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{36E778E5-F988-4689-A78C-03E38601EDE7}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{38F163B3-A02C-473F-BB97-449A4E4BE0E6}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3C406CFD-4BAD-4C6A-A40E-109AFA4A7032}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{422B2601-6455-4D7E-AA66-85CBCDF93248}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{46666EC1-F22B-465B-B1D3-A56976459C69}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4768BCA3-6919-4AF9-BA11-14F9883FF453}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{546B91E6-7CC3-4A67-B081-AE4FDE071BBD}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{586A3C61-F969-4B60-8788-0435E902CC33}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6F512A90-8617-4C8B-92A4-2697BCC50EB3}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7DB225B9-A986-4DF8-BD9E-0D452DF30B4E}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{931A4276-9972-4AC1-BB18-32A5997AAF08}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{945C482E-9508-4AC7-BF43-07CC9B5E2D45}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{99EE7955-E10B-4100-9923-8BCCCE33F98F}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A142B533-344A-426D-83CF-C9F6034DE0A8}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C9B21032-EACD-486B-A80B-3718585B876C}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D7AE6EC0-D616-438E-8CA7-CC322D481F44}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DE67D450-2D67-4AE5-8D7A-43642382855B}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F12FADBF-18EC-414F-8D93-A6E86E556909}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F1C72F35-B4B0-403C-8118-2B06F678FEB5}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F614ED5D-AD54-46DA-8516-D28F15327FE7}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FA88083E-CB43-4AFE-BDD5-6A9A43B897B7}
          [!] Key Not Deleted : HKLM\SOFTWARE\Classes\Interface\{36e778e5-f988-4689-a78c-03e38601ede7}
          [!] Key Not Deleted : HKLM\SOFTWARE\Classes\Interface\{a142b533-344a-426d-83cf-c9f6034de0a8}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{143B3E67-3D6E-4F36-8E62-063D43B29BB0}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1695AEEE-5B43-4FBB-B1BC-9E5E6C30C495}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2F08F2FA-BC7D-47DC-B75C-6D4B9AFB792C}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{32F1AAFC-6DAB-4B99-8AC2-4B721B1E06D1}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4DAA8599-9CC2-4C34-A606-3B0A8E9B3C4A}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{5D67DB82-A94B-4D44-BE81-5FB62671B982}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{795C5E1E-BFDB-468F-8B8A-309C24219676}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8DFA0267-C525-420A-B69B-9408E9843DC7}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CE493EA1-30FC-4CBE-9DE9-6A57DBC0AF69}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DFF81829-A59F-44DB-8010-2EEDADC2465F}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E7FC6003-06E8-4C2D-8756-A30FE9C95C73}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{36E778E5-F988-4689-A78C-03E38601EDE7}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A142B533-344A-426D-83CF-C9F6034DE0A8}
          [!] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{36e778e5-f988-4689-a78c-03e38601ede7}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4acf5837-1634-4afc-a583-53405f15ee0b}
          [!] Key Not Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a142b533-344a-426d-83cf-c9f6034de0a8}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c6de2e64-0666-46c8-97f2-d0c411692dfd}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{db082b40-5dde-4df1-8ee1-76a3e98966d1}
          [-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37331C16-3E97-4A20-80D8-BFB43AB0E2FB}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{37331C16-3E97-4A20-80D8-BFB43AB0E2FB}
          [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9230cb90-79de-4945-88a4-762244a25bc8}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9230cb90-79de-4945-88a4-762244a25bc8}
           
          ***** [ Web browsers ] *****
           
          [-] [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Deleted : user_pref("browser.search.hiddenOneOffs", "Ask Web Search,Yahoo,Amazon.com,eBay,Twitter,Wikipedia (en),Web Search,Bing ,DuckDuckGo");
          [-] [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._39Members_.lastActivePing", "1420155355920");
          [-] [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
          [-] [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "");
          [-] [C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "[removed]");
          [-] [C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
          [-] [C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
           
          *************************
           
          :: "Tracing" keys removed
          :: Winsock settings cleared
           
          ########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [13963 bytes] ##########
           
           

           

           

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Malwarebytes
          Version: 8.0.1 (11.24.2015)
          Operating System: Windows Vista (TM) Home Basic x86 
          Ran by [removed] (Administrator) on Tue 12/22/2015 at  4:14:44.48
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           
           
           
           
          File System: 6 
           
          Successfully deleted: C:\Program Files\mozilla firefox\defaults\pref\itms.js (File) 
          Successfully deleted: C:\Users\Linda.Linda-PC\Appdata\LocalLow\recipehub_2j (Folder) 
          Successfully deleted: C:\Users\Linda.Linda-PC\Appdata\LocalLow\recipehub_2jei (Folder) 
          Successfully deleted: C:\Windows\couponprinter.ocx (File) 
          Successfully deleted: C:\Windows\System32\Tasks\PCDEventLauncherTask (Task)
          Successfully deleted: C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask (Task)
           
          Deleted the following from C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\prefs.js
          user_pref(extensions.xpiState, {\app-global\:{\{972ce4c6-7e08-4474-a285-3208198ce6fd}\:{\d\:\C:\\\\Program Files\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972c
           
           
           
          Registry: 7 
           
          Successfully deleted: HKLM\Software\Mozilla\Firefox\Extensions\\{1c43baf1-00c2-40a8-a09e-f84cfd79546d} (Registry Value) 
          Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page (Registry Value) 
          Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06e3475c-5521-4de8-bb12-50720f21631c} (Registry Key)
          Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b7acdf9c-c4f9-4d5d-998e-b147866b4d4c} (Registry Key)
          Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Main\\Start Page (Registry Value) 
          Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{8660E5B3-6C41-44DE-8503-98D99BBECD41} (Registry Value) 
          Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{cf51de5b-eb36-4114-bb69-84df63fbadb4} (Registry Value) 
           
           
           
           
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Tue 12/22/2015 at  4:17:15.61
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           

           

          Malwarebytes Anti-Malware
          www.malwarebytes.org
           
          Scan Date: 12/22/2015
          Scan Time: 4:26:42 AM
          Logfile: 
          Administrator: Yes
           
          Version: 2.2.0.1024
          Malware Database: v2015.12.22.02
          Rootkit Database: v2015.12.18.01
          License: Free
          Malware Protection: Disabled
          Malicious Website Protection: Disabled
          Self-protection: Disabled
           
          OS: Windows Vista Service Pack 2
          CPU: x86
          File System: NTFS
          User: Linda
           
          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 388471
          Time Elapsed: 36 min, 38 sec
           
          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Disabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled
           
          Processes: 0
          (No malicious items detected)
           
          Modules: 0
          (No malicious items detected)
           
          Registry Keys: 16
          PUP.Optional.MindSpark, HKLM\SOFTWARE\CLASSES\CLSID\{06e3475c-5521-4de8-bb12-50720f21631c}, , [0119c3e5e8a3cc6acbc04d0f1de5d42c], 
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{06E3475C-5521-4DE8-BB12-50720F21631C}, , [0119c3e5e8a3cc6acbc04d0f1de5d42c], 
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{06E3475C-5521-4DE8-BB12-50720F21631C}, , [0119c3e5e8a3cc6acbc04d0f1de5d42c], 
          PUP.Optional.CouponBar, HKLM\SOFTWARE\CLASSES\CLSID\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, , [4fcb2e7a7318c5714b2b8ad06b979b65], 
          PUP.Optional.CouponBar, HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, , [4fcb2e7a7318c5714b2b8ad06b979b65], 
          PUP.Optional.MindSpark, HKLM\SOFTWARE\CLASSES\CLSID\{b7acdf9c-c4f9-4d5d-998e-b147866b4d4c}, , [ba602583a1eadc5a11cfb4a9d62c28d8], 
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{B7ACDF9C-C4F9-4D5D-998E-B147866B4D4C}, , [ba602583a1eadc5a11cfb4a9d62c28d8], 
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B7ACDF9C-C4F9-4D5D-998E-B147866B4D4C}, , [ba602583a1eadc5a11cfb4a9d62c28d8], 
          PUP.Optional.MindSpark, HKLM\SOFTWARE\CLASSES\CLSID\{cf51de5b-eb36-4114-bb69-84df63fbadb4}, , [be5c42660289d46258ae1c421ae83ac6], 
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CF51DE5B-EB36-4114-BB69-84DF63FBADB4}, , [be5c42660289d46258ae1c421ae83ac6], 
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CF51DE5B-EB36-4114-BB69-84DF63FBADB4}, , [be5c42660289d46258ae1c421ae83ac6], 
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{cc8ae5b8-005b-4b1a-a27d-307eddffe5c8}, , [d64406a223682d0985803e20788a718f], 
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1001_Classes\CLSID\{CC8AE5B8-005B-4B1A-A27D-307EDDFFE5C8}, , [d64406a223682d0985803e20788a718f], 
          PUP.Optional.MindSpark, HKLM\SOFTWARE\RecipeHub_2j, , [de3cbaee0685f73f95ad466719ea27d9], 
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\APPDATALOW\SOFTWARE\RecipeHub_2j, , [3edc0f99602b0e28732c0ba059aa56aa], 
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1001\SOFTWARE\APPDATALOW\SOFTWARE\RecipeHub_2j, , [0a1090180982c274d9c69d0edd26ea16], 
           
          Registry Values: 3
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{CC8AE5B8-005B-4B1A-A27D-307EDDFFE5C8}, , [d64406a223682d0985803e20788a718f], 
          PUP.Optional.MindSpark, HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{cc8ae5b8-005b-4b1a-a27d-307eddffe5c8}, , [c5554464c8c365d1887dcf8f44befc04], 
          PUP.Optional.MindSpark, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|2jffxtbr@RecipeHub_2j.com, C:\Program Files\RecipeHub_2j\bar\1.bin, , [f426bceca5e642f4ad6197160df653ad]
           
          Registry Data: 0
          (No malicious items detected)
           
          Folders: 1
          PUP.Optional.MindSpark, C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\MapsGalaxy_39, , [20fa62466f1cdb5b0383abff19eac33d], 
           
          Files: 1
          PUP.Optional.MindSpark, C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\MapsGalaxy_39\10C7879C-A85A-4DDD-84DB-F2A4BEB38338.sqlite, , [20fa62466f1cdb5b0383abff19eac33d], 
           
          Physical Sectors: 0
          (No malicious items detected)
           
           
          (end)

          Good Morning

           

          When you ran Malwarebytes did you have it quarantine all those entries, there bad and need to go. On the Malwarebytes log is should show those entries as quarantined but it does not, you may have to run the program again and remove them

           

          Dont panic , this is from another users Malwarebytes log , I just wanted to show you how it looks when entries are quarantined

           
          PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B0660298-91AA-421F-BF0D-BFF6BB8BF3AE}, Quarantined, [d8771a9c444610265bd9f3af73904ab6],
          PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}, Quarantined, [d8771a9c444610265bd9f3af73904ab6],
           
           

           
          Run the program again
           
          •  
          • You can highlight one of the detections by left clicking on it.
          • Then, right click on the highlighted detection, and select 'Check All Items'.
          • Next, click 'Remove Selected'. That should remove them all
           

           

          Ken:

          Thanks for your continued support.

          I see what you mean.

          I believe after the scan I did quarantine the threats because I clicked a "remove" button and a quarantine folder was created.

          But I'll run it again and send you the log file.

           

          FYI, I'm still having the freezing problem which is happening while on the desktop with no programs open.

           

          Can I upgrade to a Windows version better than Vista that will be supported by the system components we currently have?

          I'm certain that Windows 10 requirements exceed our computer's capabilities.

          Is there an online method to determine a Windows version that can be supported by this laptop?

           

          Thanks,

           

          Joel

          This is the most recent log file from malwarebytes which i upgraded to the trial version that gave me the quarantine threat option.

          But the scan found 0 threats and no quarantined items.

           

          Thanks,

           

          Joel

           

          Malwarebytes Anti-Malware
          www.malwarebytes.org
           
          Scan Date: 12/22/2015
          Scan Time: 9:53:13 PM
          Logfile: 
          Administrator: Yes
           
          Version: 2.2.0.1024
          Malware Database: v2015.12.22.07
          Rootkit Database: v2015.12.18.01
          License: Trial
          Malware Protection: Enabled
          Malicious Website Protection: Enabled
          Self-protection: Disabled
           
          OS: Windows Vista Service Pack 2
          CPU: x86
          File System: NTFS
          User: Linda
           
          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 388662
          Time Elapsed: 38 min, 53 sec
           
          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Disabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled
           
          Processes: 0
          (No malicious items detected)
           
          Modules: 0
          (No malicious items detected)
           
          Registry Keys: 0
          (No malicious items detected)
           
          Registry Values: 0
          (No malicious items detected)
           
          Registry Data: 0
          (No malicious items detected)
           
          Folders: 0
          (No malicious items detected)
           
          Files: 0
          (No malicious items detected)
           
          Physical Sectors: 0
          (No malicious items detected)
           
           
          (end)

          Good,

           

          Open up FRST, make sure to checkmark Additions, run a new scan and post both the new FRST and Additions logs and also tell me if you think your computer has improved

          Dear ken:

           

          I appreciate all your help.

          Vista is still unreliable and freezes, even when no programs are opened by me.

          I've disabled all programs on the startup menu too.

          Are there any more antivirus routines I should run?

           

          Also, I'd like to upgrade to Windows 7 and my hardware is compatible.

          Do you think this will solve the issues I'm having?

          Or will the problems and viruses migrate too?

           

          Thanks,

           

          Joel

           

          Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:23-12-2015
          Ran by [removed] (administrator) on LINDA-PC (23-12-2015 08:34:12)
          Running from C:\Users\[removed]\Desktop\virus cleaners
          [removed]
          Platform: Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) Language: English (United States)
          Internet Explorer Version 9 (Default browser: Chrome)
          Boot Mode: Normal
          Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
           
          ==================== Processes (Whitelisted) =================
           
          (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
           
          (Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
          (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
          (Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
          (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
          (Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
          (Intel Corporation) C:\WINDOWS\System32\igfxsrvc.exe
          (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
          (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
           
           
          ==================== Registry (Whitelisted) ===========================
           
          (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
           
          Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2009-07-07] (Citrix Online, a division of Citrix Systems, Inc.)
          HKLM\…D6A79037F57F\InprocServer32: [Default-fastprox] ATTENTION! ====> ZeroAccess?
          HKU\S-1-5-18\…\Run: [GarminExpressTrayApp] => C:\Program Files\Garmin\Express Tray\ExpressTray.exe [1403304 2015-10-29] (Garmin Ltd. or its subsidiaries)
          ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
          Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
          ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
          Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
          ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
          Startup: C:\Users\RA Media Server\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
          ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
          BootExecute: autocheck autochk /k:C * 
           
          ==================== Internet (Whitelisted) ====================
           
          (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
           
          Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
          Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
          Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
          Tcpip\..\Interfaces\{C7F26639-2C1A-4FE2-AA45-8D9D300C51D8}: [DhcpNameServer] 192.168.1.1
          Tcpip\..\Interfaces\{E10DCCCB-A154-45DA-88BC-E56EC0A35C8A}: [DhcpNameServer] 192.168.1.1
           
          Internet Explorer:
          ==================
          HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = 
          HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/USCON/1
          SearchScopes: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> DefaultScope {12696EE3-C065-4036-A844-31F773CCB8D3} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=DLCDF7&pc;=MDDC&src;=IE-SearchBox
          SearchScopes: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> {12696EE3-C065-4036-A844-31F773CCB8D3} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=DLCDF7&pc;=MDDC&src;=IE-SearchBox
          BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27] (Adobe Systems Incorporated)
          BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
          BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-11] (Oracle Corporation)
          BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-11] (Oracle Corporation)
          Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
          Toolbar: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
           
          FireFox:
          ========
          FF ProfilePath: C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default
          FF NewTab: about:blank
          FF DefaultSearchEngine: Google
          FF DefaultSearchEngine.US: Google
          FF SearchEngineOrder.3: Bing 
          FF SelectedSearchEngine: Google
          FF Homepage: www.google.com
          FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-17] ()
          FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
          FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
          FF Plugin: @java.com/DTPlugin,version=10.10.2 -> C:\Windows\system32\npDeployJava1.dll [2013-01-11] (Oracle Corporation)
          FF Plugin: @java.com/JavaPlugin,version=10.10.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-01-11] (Oracle Corporation)
          FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
          FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
          FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-17] (Google Inc.)
          FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-17] (Google Inc.)
          FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-07-27] (Adobe Systems Inc.)
          FF Plugin HKU\S-1-5-21-1549655542-3693215259-3179495191-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
          FF Plugin HKU\S-1-5-21-1549655542-3693215259-3179495191-1000: CouponNetwork.com/CMDUniversalCouponPrintActivator -> C:\Users\LINDA~1.LIN\AppData\Roaming\CATALI~1\NPBCSK~1.DLL [No File]
          FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2013-08-02] (Coupons, Inc.)
          FF Plugin ProgramFiles/Appdata: C:\Users\Linda.Linda-PC\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-12-15] (Cisco WebEx LLC)
          FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
          FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-02-02] [not signed]
           
          Chrome: 
          =======
          CHR HomePage: Default -> hxxp://www.ebay.com/
          CHR Profile: C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default
          CHR Extension: (Google Slides) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-15]
          CHR Extension: (Google Docs) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-15]
          CHR Extension: (Google Drive) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-15]
          CHR Extension: (YouTube) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-15]
          CHR Extension: (Google Search) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-15]
          CHR Extension: (Google Sheets) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-15]
          CHR Extension: (Google Docs Offline) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-15]
          CHR Extension: (Chrome Web Store Payments) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-15]
          CHR Extension: (Gmail) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-15]
           
          ==================== Services (Whitelisted) ========================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          S4 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [81920 2009-03-31] (Andrea Electronics Corporation)
          S4 Apache2.2; C:\Program Files\Common Files\Dell\apache\bin\httpd.exe [15872 2007-09-21] (Apache Software Foundation) [File not signed]
          R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-12-18] (Stardock Corporation) [File not signed]
          S4 dsl-db; C:\Program Files\Common Files\Dell\MySQL\bin\mysqld.exe [5730304 2007-09-14] () [File not signed]
          S4 dsl-fs-sync; C:\Program Files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe [189680 2009-04-13] (SingleClick Systems)
          S4 GameConsoleService; C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe [242424 2008-11-03] (WildTangent, Inc.)
          S4 Garmin Device Interaction Service; C:\Program Files\Garmin\Device Interaction Service\GarminService.exe [777744 2015-10-29] (Garmin Ltd. or its subsidiaries)
          S4 GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [16680 2009-07-07] (Citrix Online, a division of Citrix Systems, Inc.)
          S4 hnmsvc; c:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe [828656 2009-04-13] (Dell Inc.)
          S4 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
          S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
          S4 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
          S4 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.226\McCHSvc.exe [235696 2015-10-30] (McAfee, Inc.)
          R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
          R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
          S4 SftService; C:\Program Files\Dell DataSafe Local Backup\sftservice.EXE [1692480 2011-08-18] (SoftThinks SAS)
          S4 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe [254042 2009-03-31] (IDT, Inc.)
          R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
          S4 wltrysvc; C:\Windows\System32\bcmwltry.exe [2809856 2008-12-21] (Dell Inc.) [File not signed]
          R2 yksvc; RUNDLL32.EXE ykx32coinst,serviceStartProc [X]
           
          ===================== Drivers (Whitelisted) ==========================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          S3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2008-12-21] (Broadcom Corporation)
          S3 DellBIOS; C:\Windows\DellBIOS.Sys [7168 2015-12-20] () [File not signed]
          R3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [35776 2013-09-23] (hxxp://libusb-win32.sourceforge.net)
          S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
          S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [170200 2015-12-23] (Malwarebytes)
          S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation)
          R3 OA009Ufd; C:\Windows\System32\DRIVERS\OA009Ufd.sys [133632 2009-03-06] (Creative Technology Ltd.)
          R3 OA009Vid; C:\Windows\System32\DRIVERS\OA009Vid.sys [271552 2009-03-19] (Creative Technology Ltd.)
          R2 Packet; C:\Windows\System32\DRIVERS\packet.sys [22016 2008-06-17] (SingleClick Systems)
          S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
          S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
          S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
          S3 PCD5SRVC{3F6A8B78-EC003E00-05040104}; \??\C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [X]
           
          ==================== NetSvcs (Whitelisted) ===================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
           
          ==================== One Month Created files and folders ========
           
          (If an entry is included in the fixlist, the file/folder will be moved.)
           
          2015-12-22 22:45 - 2015-12-22 22:45 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Microsoft Corporation
          2015-12-22 22:44 - 2015-12-22 22:44 - 00001998 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 Upgrade Advisor.lnk
          2015-12-22 22:44 - 2015-12-22 22:44 - 00001986 _____ C:\Users\Public\Desktop\Windows 7 Upgrade Advisor.lnk
          2015-12-22 22:44 - 2015-12-22 22:44 - 00000000 ____D C:\Program Files\Microsoft Windows 7 Upgrade Advisor
          2015-12-22 22:39 - 2015-12-22 22:39 - 08669472 _____ (Microsoft Corporation) C:\Users\Linda.Linda-PC\Downloads\Windows7UpgradeAdvisorSetup.exe
          2015-12-22 20:23 - 2015-12-22 20:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
          2015-12-22 05:45 - 2015-12-23 08:34 - 00000000 ____D C:\Users\Linda.Linda-PC\Desktop\virus cleaners
          2015-12-22 04:25 - 2015-12-23 00:33 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
          2015-12-22 04:24 - 2015-12-22 20:23 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
          2015-12-22 04:24 - 2015-10-05 09:50 - 00094936 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
          2015-12-22 04:24 - 2015-10-05 09:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
          2015-12-22 04:24 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
          2015-12-22 04:17 - 2015-12-22 04:17 - 00002238 _____ C:\Users\Linda.Linda-PC\Desktop\JRT.txt
          2015-12-21 02:31 - 2015-12-21 02:31 - 274668427 _____ C:\Windows\MEMORY.DMP
          2015-12-21 02:31 - 2015-12-21 02:31 - 00143728 _____ C:\Windows\Minidump\Mini122115-01.dmp
          2015-12-21 00:49 - 2015-12-23 08:34 - 00000000 ____D C:\FRST
          2015-12-20 23:45 - 2015-12-22 22:33 - 00000000 ____D C:\Users\Linda.Linda-PC\Documents\troubleshooting
          2015-12-20 23:06 - 2015-12-20 23:06 - 00000512 _____ C:\Users\Linda.Linda-PC\Documents\MBR.dat
          2015-12-20 22:06 - 2015-12-20 22:06 - 01162486 _____ C:\Users\Linda.Linda-PC\Downloads\1545_A14 (1).EXE
          2015-12-20 22:05 - 2015-12-20 22:05 - 01162486 _____ C:\Users\Linda.Linda-PC\Downloads\1545_A14.EXE
          2015-12-20 22:05 - 2015-12-20 22:05 - 00007168 _____ C:\Windows\DellBIOS.Sys
          2015-12-20 21:53 - 2015-12-20 21:54 - 49934552 _____ (Microsoft Corporation) C:\Users\Linda.Linda-PC\Downloads\Windows-KB890830-V5.31.exe
          2015-12-20 21:18 - 2015-12-20 21:18 - 00000000 ____D C:\Users\Linda.Linda-PC\{b1967a33-da0b-4955-a208-b043aa2fbe2e}
          2015-12-20 21:18 - 2015-10-28 00:20 - 00031992 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\pcdrndisprot.sys
          2015-12-20 21:09 - 2015-12-20 21:09 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\LocalLow\PCDr
          2015-12-20 21:09 - 2015-12-20 21:09 - 00000000 ____D C:\ProgramData\PC-Doctor for Windows
          2015-12-20 21:01 - 2015-12-21 16:37 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\PCDr
          2015-12-20 21:00 - 2015-12-20 21:00 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
          2015-12-20 21:00 - 2015-12-20 21:00 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Deployment
          2015-12-20 21:00 - 2015-12-20 21:00 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Apps\2.0
          2015-12-20 20:59 - 2015-12-20 20:59 - 00417064 _____ () C:\Users\Linda.Linda-PC\Downloads\DellSystemDetectLauncher.exe
          2015-12-20 20:20 - 2015-12-20 20:20 - 00247183 _____ C:\Users\Linda.Linda-PC\Documents\bookmarks_12_20_15.html
          2015-12-17 08:48 - 2015-12-17 08:48 - 00000000 ____D C:\Windows\pss
          2015-12-17 08:42 - 2015-12-17 08:43 - 07708304 _____ (McAfee, Inc.) C:\Users\Linda.Linda-PC\Downloads\Setup_serial_oeXOdgfIjbW_srLLuxULNQ2_key.exe
          2015-12-17 08:42 - 2015-12-17 08:42 - 00001973 _____ C:\Users\Public\Desktop\Google Chrome.lnk
          2015-12-17 08:42 - 2015-12-17 08:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
          2015-12-17 06:19 - 2015-12-17 06:19 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
          2015-12-16 21:14 - 2015-12-16 21:14 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\McAfee File Lock
          2015-12-16 21:12 - 2015-12-16 21:12 - 00000000 ____D C:\Program Files\McAfee.com
          2015-12-16 21:01 - 2015-12-16 22:50 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\LogMeIn Rescue Applet
          2015-12-16 20:55 - 2015-12-16 21:14 - 00000000 ____D C:\Program Files\Common Files\McAfee
          2015-12-16 20:55 - 2015-12-16 20:57 - 00000000 ____D C:\Program Files\stinger
          2015-12-16 19:18 - 2015-12-16 19:18 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox(88)
          2015-12-15 22:47 - 2015-12-15 22:47 - 00000046 _____ C:\Users\Linda.Linda-PC\Desktop\eBay.url
          2015-12-15 22:40 - 2015-12-15 22:40 - 00000000 ____D C:\ProgramData\BSD
          2015-12-15 21:53 - 2015-12-15 21:53 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\McAfee
          2015-12-15 21:52 - 2015-12-16 22:53 - 00000000 ____D C:\Program Files\McAfee
          2015-12-13 01:15 - 2015-12-13 01:15 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox(84)
          2015-12-07 13:46 - 2015-12-07 13:46 - 01958689 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(28)
          2015-12-07 13:16 - 2015-12-07 13:16 - 00999116 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(27)
          2015-12-04 16:36 - 2015-12-04 16:36 - 02956605 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(26)
          2015-12-03 00:14 - 2015-12-03 00:14 - 00999469 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(25)
          2015-12-02 16:39 - 2015-12-02 16:39 - 01959030 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(24)
          2015-12-02 16:19 - 2015-12-02 16:19 - 00999491 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(23)
          2015-11-24 21:04 - 2015-11-24 21:04 - 00436946 _____ C:\Users\Linda.Linda-PC\Downloads\310382351392
           
          ==================== One Month Modified files and folders ========
           
          (If an entry is included in the fixlist, the file/folder will be moved.)
           
          2015-12-23 08:22 - 2012-02-27 19:19 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
          2015-12-23 08:22 - 2006-11-02 07:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
          2015-12-23 08:22 - 2006-11-02 07:45 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
          2015-12-23 08:22 - 2006-11-02 07:45 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
          2015-12-23 01:13 - 2015-06-20 15:37 - 00000936 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job
          2015-12-23 01:13 - 2012-08-22 14:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
          2015-12-23 01:08 - 2012-02-27 19:19 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
          2015-12-23 01:08 - 2012-02-01 08:50 - 00000000 ____D C:\Program Files\Google
          2015-12-23 01:07 - 2006-11-02 07:58 - 00032588 _____ C:\Windows\Tasks\SCHEDLGU.TXT
          2015-12-23 00:57 - 2012-02-27 19:18 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Google
          2015-12-23 00:57 - 2012-02-27 19:18 - 00000000 ____D C:\ProgramData\Google
          2015-12-23 00:53 - 2012-05-27 15:03 - 00001945 _____ C:\Windows\epplauncher.mif
          2015-12-23 00:31 - 2009-07-07 09:52 - 00000000 ____D C:\ProgramData\TEMP
          2015-12-23 00:31 - 2009-07-07 09:43 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
          2015-12-23 00:31 - 2009-07-07 09:43 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
          2015-12-23 00:31 - 2009-07-07 09:34 - 00000000 ____D C:\Program Files\Dell DataSafe Local Backup
          2015-12-22 23:05 - 2012-08-23 22:00 - 00000946 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job
          2015-12-22 23:05 - 2012-08-23 22:00 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job
          2015-12-22 04:24 - 2012-01-31 22:56 - 00000000 ____D C:\ProgramData\Malwarebytes
          2015-12-22 04:15 - 2006-11-02 06:18 - 00000000 ____D C:\WINDOWS
          2015-12-21 22:34 - 2012-01-31 22:40 - 00000000 ____D C:\Users\Linda.Linda-PC
          2015-12-21 20:39 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\inf
          2015-12-21 20:39 - 2006-11-02 05:33 - 00759542 _____ C:\Windows\system32\PerfStringBackup.INI
          2015-12-21 02:31 - 2014-03-01 20:13 - 00000000 ____D C:\Windows\Minidump
          2015-12-21 02:12 - 2006-11-02 06:18 - 00000000 ___SD C:\Windows\Downloaded Program Files
          2015-12-20 22:25 - 2009-09-24 19:45 - 00913204 _____ C:\Windows\ntbtlog.txt
          2015-12-20 21:18 - 2013-10-19 13:26 - 00000000 ____D C:\Temp
          2015-12-20 21:09 - 2012-01-31 22:40 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Dell
          2015-12-20 21:09 - 2009-07-07 09:36 - 00000000 ____D C:\ProgramData\PCDr
          2015-12-20 21:09 - 2009-07-07 09:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
          2015-12-20 21:08 - 2009-07-07 09:36 - 00000000 ____D C:\Program Files\Dell Support Center
          2015-12-20 21:06 - 2009-07-07 09:16 - 00000000 ____D C:\Program Files\Dell
          2015-12-20 21:04 - 2009-07-07 11:37 - 00000000 ____D C:\DELL
          2015-12-20 21:04 - 2009-07-07 09:35 - 00000000 ____D C:\ProgramData\Dell
          2015-12-17 20:13 - 2012-08-22 14:35 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
          2015-12-17 20:13 - 2012-02-27 19:18 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
          2015-12-17 08:33 - 2014-09-07 10:29 - 00000000 ___RD C:\Users\Linda.Linda-PC\Dropbox
          2015-12-17 08:33 - 2014-09-07 10:25 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox
          2015-12-17 06:09 - 2009-07-07 09:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Remote Access
          2015-12-17 06:09 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\Msdtc
          2015-12-17 06:08 - 2012-02-02 07:05 - 00000000 ____D C:\Users\RA Media Server
          2015-12-17 06:08 - 2006-11-02 05:22 - 46137344 _____ C:\Windows\system32\config\software_previous
          2015-12-17 06:08 - 2006-11-02 05:22 - 43778048 _____ C:\Windows\system32\config\components_previous
          2015-12-17 06:08 - 2006-11-02 05:22 - 15466496 _____ C:\Windows\system32\config\system_previous
          2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\security_previous
          2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
          2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\default_previous
          2015-12-17 06:07 - 2015-11-06 21:40 - 00000000 ____D C:\Program Files\Mozilla Firefox
          2015-12-17 06:07 - 2012-08-22 14:35 - 00000000 ____D C:\ProgramData\McAfee Security Scan
          2015-12-17 06:07 - 2012-08-21 15:24 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
          2015-12-17 06:07 - 2012-02-28 21:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
          2015-12-17 06:07 - 2012-01-31 23:23 - 00000000 ____D C:\ProgramData\Microsoft Help
          2015-12-17 06:07 - 2009-07-07 09:40 - 00000000 ____D C:\Program Files\Microsoft Silverlight
          2015-12-17 06:07 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Dell Remote Access
          2015-12-17 06:07 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Common Files\Dell
          2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 __RSD C:\Windows\Media
          2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\spool
          2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\rescache
          2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\PolicyDefinitions
          2015-12-17 06:06 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\registration
          2015-12-17 02:02 - 2009-07-07 09:48 - 00000000 ____D C:\ProgramData\McAfee
          2015-12-16 19:11 - 2013-07-15 02:01 - 00000000 ____D C:\Windows\system32\MRT
          2015-12-15 21:41 - 2015-10-18 21:33 - 00000000 ____D C:\Program Files\McAfee Security Scan
          2015-12-15 21:03 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Common Files\Dell(2)
          2015-12-15 19:48 - 2012-02-03 06:04 - 00006080 _____ C:\Users\Linda.Linda-PC\AppData\Local\d3d9caps.dat
          2015-12-10 03:45 - 2015-08-29 13:47 - 00000000 ____D C:\ProgramData\CanonIJPLM
          2015-12-08 22:39 - 2012-05-27 15:14 - 00247976 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
          2015-12-03 16:08 - 2015-06-20 15:37 - 00000884 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job
          2015-11-23 19:09 - 2006-11-02 05:24 - 137798368 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
           
          ==================== Files in the root of some directories =======
           
          2013-11-04 13:41 - 2013-11-04 13:41 - 0893239 _____ () C:\Users\Linda.Linda-PC\AppData\Local\a.zip
          2013-11-04 13:41 - 2013-11-04 13:41 - 2162416 _____ (Catalina Marketing Corp) C:\Users\Linda.Linda-PC\AppData\Local\BcsKtYcHW.dll
          2012-02-03 06:04 - 2015-12-15 19:48 - 0006080 _____ () C:\Users\Linda.Linda-PC\AppData\Local\d3d9caps.dat
          2012-01-31 22:48 - 2015-11-07 15:34 - 0018944 _____ () C:\Users\Linda.Linda-PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
          2012-04-29 18:33 - 2015-08-29 15:00 - 0007084 _____ () C:\ProgramData\hpzinstall.log
           
          ZeroAccess:
          C:\$Recycle.Bin\S-1-5-21-1549655542-3693215259-3179495191-1000\$1275ff5241a28249602b776eb539b742
           
          ZeroAccess:
          C:\$Recycle.Bin\S-1-5-18\$1275ff5241a28249602b776eb539b742
           
          Some files in TEMP:
          ====================
          C:\Users\Linda.Linda-PC\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpyqxbod.dll
          C:\Users\Linda.Linda-PC\AppData\Local\Temp\InstallFlashPlayer.exe
          C:\Users\Linda.Linda-PC\AppData\Local\Temp\ose00000.exe
           
           
          ==================== Bamital & volsnap =================
           
          (There is no automatic fix for files that do not pass verification.)
           
          C:\Windows\explorer.exe => File is digitally signed
          C:\Windows\system32\winlogon.exe => File is digitally signed
          C:\Windows\system32\wininit.exe => File is digitally signed
          C:\Windows\system32\svchost.exe => File is digitally signed
          C:\Windows\system32\services.exe => File is digitally signed
          C:\Windows\system32\User32.dll => File is digitally signed
          C:\Windows\system32\userinit.exe => File is digitally signed
          C:\Windows\system32\rpcss.dll => File is digitally signed
          C:\Windows\system32\dnsapi.dll => File is digitally signed
          C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
           
           
          LastRegBack: 2015-12-23 08:29
           
          ==================== End of FRST.txt ============================
           
           
          Additional scan result of Farbar Recovery Scan Tool (x86) Version:23-12-2015
          Ran by [removed] (2015-12-23 08:34:47)
          Running from C:\Users\[removed]\Desktop\virus cleaners
          Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) (2009-07-07 09:02:45)
          Boot Mode: Normal
          ==========================================================
           
           
          ==================== Accounts: =============================
           
          Administrator (S-1-5-21-1549655542-3693215259-3179495191-500 - Administrator - Disabled)
          Guest (S-1-5-21-1549655542-3693215259-3179495191-501 - Limited - Disabled)
          Linda (S-1-5-21-1549655542-3693215259-3179495191-1000 - Administrator - Enabled) => C:\Users\Linda.Linda-PC
          RA Media Server (S-1-5-21-1549655542-3693215259-3179495191-1001 - Administrator - Enabled) => C:\Users\RA Media Server
           
          ==================== Security Center ========================
           
          (If an entry is included in the fixlist, it will be removed.)
           
          AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
           
          ==================== Installed Programs ======================
           
          (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
           
          32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
          Acrobat.com (HKLM\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated)
          Acrobat.com (Version: 0.0.0 - Adobe Systems Incorporated) Hidden
          Adobe AIR (HKLM\…\Adobe AIR) (Version: 1.0.4990 - Adobe Systems Inc.)
          Adobe Flash Player 20 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 20.0.0.228 - Adobe Systems Incorporated)
          Adobe Flash Player 20 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated)
          Adobe Reader X (10.1.4) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.4 - Adobe Systems Incorporated)
          Advanced Audio FX Engine (HKLM\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
          ANT Drivers Installer x86 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
          Apple Application Support (HKLM\…\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
          Apple Mobile Device Support (HKLM\…\{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}) (Version: 7.1.2.6 - Apple Inc.)
          Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
          Banctec Service Agreement (HKLM\…\{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}) (Version: 2.0.0 - Dell Inc.)
          Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
          Canon Easy-WebPrint EX (HKLM\…\Easy-WebPrint EX) (Version: 1.6.0.0 - Canon Inc.)
          Canon IJ Network Scanner Selector EX (HKLM\…\Canon_IJ_Network_Scanner_Selector_EX) (Version: 1.5.2.3 - Canon Inc.)
          Canon IJ Network Tool (HKLM\…\Canon_IJ_Network_UTILITY) (Version: 3.5.0 - Canon Inc.)
          Canon IJ Scan Utility (HKLM\…\Canon_IJ_Scan_Utility) (Version: 1.1.10.15 - Canon Inc.)
          Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\…\CANONIJPLM100) (Version: 4.2.0 - Canon Inc.)
          Canon MG6600 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6600_series) (Version: 1.01 - Canon Inc.)
          Canon MG6600 series On-screen Manual (HKLM\…\Canon MG6600 series On-screen Manual) (Version: 7.7.0 - Canon Inc.)
          Canon MG6600 series User Registration (HKLM\…\Canon MG6600 series User Registration) (Version:  - ‭Canon Inc.)
          Canon My Printer (HKLM\…\CanonMyPrinter) (Version: 3.2.1 - Canon Inc.)
          Canon Quick Menu (HKLM\…\CanonQuickMenu) (Version: 2.6.0 - Canon Inc.)
          Choice Guard (Version: 1.2.87.0 - Microsoft Corporation) Hidden
          Cisco EAP-FAST Module (HKLM\…\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.)
          Cisco LEAP Module (HKLM\…\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.)
          Cisco PEAP Module (HKLM\…\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.)
          Cisco WebEx Meetings (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
          Coupon Printer for Windows (HKLM\…\Coupon Printer for Windows5.0.0.4) (Version: 5.0.0.4 - Coupons.com Incorporated)
          CouponBar (HKLM\…\CouponBar5.0.0.4) (Version: 5.0.0.4 - Coupons.com Incorporated) <==== ATTENTION
          CutePDF Writer 3.0 (HKLM\…\CutePDF Writer Installation) (Version:  3.0 - Acro Software Inc.)
          Dell DataSafe Local Backup - Support Software (HKLM\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell)
          Dell DataSafe Local Backup (HKLM\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell)
          Dell DataSafe Online (HKLM\…\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.1.0027 - Dell, Inc.)
          Dell Dock (HKLM\…\{F6CB42B9-F033-4152-8813-FF11DA8E6A78}) (Version: 1.0.0 - Dell)
          Dell Edoc Viewer (HKLM\…\{3138EAD3-700B-4A10-B617-B3F8096EE30D}) (Version: 1.0.0 - Dell Inc)
          Dell Getting Started Guide (HKLM\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
          Dell Remote Access (HKLM\…\{F66A31D9-7831-4FBA-BA02-C411C0047CC5}) (Version: 1.2.0.0 - Dell Inc.)
          Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.1.6664.93 - Dell)
          Dell System Detect (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\58d94f3ce2c27db0) (Version: 6.12.0.1 - Dell)
          Dell Touchpad (HKLM\…\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.4.115.101 - Alps Electric)
          Dell Video Chat (HKLM\…\Dell Video Chat) (Version: 6.0 (6567) - SightSpeed Inc.)
          Dell Webcam Central (HKLM\…\Dell Webcam Central) (Version: 1.20.10 - Creative Technology Ltd)
          Dell Wireless WLAN Card Utility (HKLM\…\Broadcom 802.11 Application) (Version: 5.10.38.30 - Dell Inc.)
          DELL0703 (Version: 1.0.0 - WildTangent) Hidden
          Dell-eBay (HKLM\…\{B935C985-A17F-484B-8470-09E4FC27DC26}) (Version: 1.00.0000 - Dell)
          Dropbox (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\Dropbox) (Version: 3.12.5 - Dropbox, Inc.)
          Elevated Installer (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden
          Facebook Video Calling 1.2.0.159 (HKLM\…\{7CAC6A44-C3DE-4153-ACA6-7524602C789E}) (Version: 1.2.159 - Skype Limited)
          Facebook Video Calling 1.2.0.287 (HKLM\…\{B92C5909-1D37-4C51-8397-A28BB28E5DC3}) (Version: 1.2.287 - Skype Limited)
          Facebook Video Calling 3.1.0.521 (HKLM\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
          FastStone Photo Resizer 3.1 (HKLM\…\FastStone Photo Resizer) (Version: 3.1 - FastStone Soft.)
          FredV2Step1 (HKLM\…\{D6BCD6F1-85F1-43AD-A5A8-FC7C070546DD}) (Version: 1.00.0000 - USMLE)
          Garmin Express (HKLM\…\{b292f4e5-60ca-4bb8-8810-e5f908c3c1ff}) (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries)
          Garmin Express (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden
          Garmin Express Tray (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden
          Google Chrome (HKLM\…\Google Chrome) (Version: 47.0.2526.106 - Google Inc.)
          Google Earth Plug-in (HKLM\…\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
          Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
          Google Update Helper (Version: 1.3.29.1 - Google Inc.) Hidden
          GoToAssist 8.0.0.514 (HKLM\…\GoToAssist) (Version:  - )
          HP Photosmart Essential (HKLM\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
          HPDiagnosticAlert (Version: 1.00.0001 - Microsoft) Hidden
          Integrated Webcam Driver (1.02.01.0320)   (HKLM\…\Creative OA009) (Version: 1.02.01.0320 - Creative Technology Ltd.)
          Intel(R) TV Wizard (HKLM\…\TVWiz) (Version:  - Intel Corporation)
          Intel® Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
          iTunes (HKLM\…\{86D04316-F49A-4AF2-B3F1-A1E943886CE7}) (Version: 11.3.1.2 - Apple Inc.)
          Java 7 Update 10 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83217010FF}) (Version: 7.0.100 - Oracle)
          Java SE Development Kit 7 Update 10 (HKLM\…\{32A3A4F4-B792-11D6-A78A-00B0D0170100}) (Version: 1.7.0.100 - Oracle)
          Java(TM) 6 Update 13 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83216013FF}) (Version: 6.0.130 - Sun Microsystems, Inc.)
          Live! Cam Avatar Creator (HKLM\…\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.2303.1 - Creative Technology Ltd)
          Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
          Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
          Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
          Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
          Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
          Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
          Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM\…\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM\…\{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}) (Version: 8.0.58299 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\…\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\…\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
          Mozilla Firefox 42.0 (x86 en-US) (HKLM\…\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
          Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
          MSXML 4.0 SP2 (KB927978) (HKLM\…\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
          MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
          MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
          P@H-Protocol (HKLM\…\{CF594DB8-CFB0-45B4-86DA-8BB4AC0941F8}) (Version: 3.0.7.0 - Valassis)
          PowerDVD DX (HKLM\…\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.2.5024 - Dell Corp.)
          QuickSet (HKLM\…\{C4972073-2BFE-475D-8441-564EA97DA161}) (Version: 9.2.17 - Dell Inc.)
          Recipe Hub (HKLM\…\RecipeHub_2jbar Uninstall) (Version:  - Recipe Hub)
          Roxio Creator DE (HKLM\…\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}) (Version: 10.1 - Roxio)
          Spelling Dictionaries Support For Adobe Reader 9 (HKLM\…\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
          Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
          WildTangent Games (HKLM\…\WildTangent dell Master Uninstall) (Version: 1.0.0.71 - WildTangent)
          Windows 7 Upgrade Advisor (HKLM\…\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation)
          Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\…\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
          Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\…\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
           
          ==================== Custom CLSID (Whitelisted): ==========================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{8B9F5BF4-0407-4BB2-9FED-4C0372DABD00}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\FacebookVideoCallingProxy.exe (Skype Limited)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{AD848A76-F236-5EE2-819B-2BDE7ED40AE7}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Catalina – Print Savings\npBcsKtTcHW.dll => No File
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll => No File
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
          CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
           
          ==================== Restore Points =========================
           
          09-12-2015 20:09:29 Scheduled Checkpoint
          10-12-2015 03:01:23 Windows Update
          11-12-2015 12:20:31 Scheduled Checkpoint
          12-12-2015 21:04:36 Removed Dell Remote Access.
          16-12-2015 18:55:01 Windows Update
          17-12-2015 02:14:57 Restore Operation
          17-12-2015 05:57:33 Restore Operation
          20-12-2015 20:20:58 Windows Update
          20-12-2015 21:18:23 Device Driver Package Install: Microsoft Network Protocol
          22-12-2015 04:14:44 JRT Pre-Junkware Removal
          22-12-2015 22:44:08 Installed Windows 7 Upgrade Advisor
          23-12-2015 01:04:39 Joel created
           
          ==================== Hosts content: ==========================
           
          (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
           
          2006-11-02 05:23 - 2015-11-15 15:35 - 00000795 ____A C:\Windows\system32\Drivers\etc\hosts
           
          127.0.0.1       localhost
          0.0.0.1 mssplus.mcafee.com
           
          ==================== Scheduled Tasks (Whitelisted) =============
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          Task: {115FD057-8508-48E2-8BBD-B2D54B118451} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
          Task: {18DFD9FC-082E-4E9B-8285-5F21D2B4EDAE} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
          Task: {4A8BB81E-2C81-44E1-8772-404BAC47FD75} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
          Task: {4CC3FF0C-9DF8-4224-A48C-C562AF4FAFB4} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-23] (Facebook Inc.)
          Task: {51970B63-7D0D-41C7-9B9A-DE5C003A9F81} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
          Task: {58E907C7-28E5-406F-8C86-6B8700143F78} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
          Task: {66455A42-6ED6-4D87-85FC-D45E7CD41C1C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-17] (Adobe Systems Incorporated)
          Task: {73B62638-31CE-4D47-BE12-F3F6FF25CAC3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-23] (Facebook Inc.)
          Task: {8BEB3FB3-770A-44E9-B5BB-08D949550BD3} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
          Task: {8C7A437C-8E60-4057-87B5-94145B397931} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
          Task: {A30D3A2F-94EE-4F38-90F2-731BEDC54BE8} - System32\Tasks\Launch BCM WLAN Tray => C:\Windows\system32\WLTRAY.EXE [2008-12-21] (Dell Inc.)
          Task: {D6471568-77D7-4D88-9A0F-642ACDA9E593} - System32\Tasks\GarminUpdaterTask => C:\Program Files\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2015-10-29] ()
          Task: {F6DE8019-61B4-4B0C-9CEB-13A8EEDAFE86} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-10-29] (PC-Doctor, Inc.)
           
          (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
           
          Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
          Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe
          Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe
          Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
          Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
           
          ==================== Shortcuts =============================
           
          (The entries could be listed to be restored or removed.)
           
          ==================== Loaded Modules (Whitelisted) ==============
           
          2014-04-19 18:55 - 2013-10-23 13:23 - 00089136 _____ () C:\Windows\System32\cpwmon2k.dll
          2015-12-17 08:42 - 2015-12-10 22:54 - 16573256 _____ () C:\Program Files\Google\Chrome\Application\47.0.2526.106\PepperFlash\pepflashplayer.dll
           
          ==================== Alternate Data Streams (Whitelisted) =========
           
          (If an entry is included in the fixlist, only the ADS will be removed.)
           
          AlternateDataStreams: C:\ProgramData\TEMP:5D432CE3
           
          ==================== Safe Mode (Whitelisted) ===================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
           
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
           
          ==================== EXE Association (Whitelisted) ===============
           
          (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
           
           
          ==================== Internet Explorer trusted/restricted ===============
           
          (If an entry is included in the fixlist, it will be removed from the registry.)
           
          IE trusted site: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\dell.com -> dell.com
           
          ==================== Other Areas ============================
           
          (Currently there is no automatic fix for this section.)
           
          HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\boombox_1920x1200.jpg
          DNS Servers: 192.168.1.1
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
          Windows Firewall is enabled.
           
          ==================== MSCONFIG/TASK MANAGER disabled items ==
           
          (Currently there is no automatic fix for this section.)
           
          MSCONFIG\Services: AdobeARMservice => 2
          MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
          MSCONFIG\Services: AeLookupSvc => 2
          MSCONFIG\Services: AESTFilters => 2
          MSCONFIG\Services: Apache2.2 => 2
          MSCONFIG\Services: Apple Mobile Device => 2
          MSCONFIG\Services: Bonjour Service => 2
          MSCONFIG\Services: dsl-db => 2
          MSCONFIG\Services: dsl-fs-sync => 2
          MSCONFIG\Services: GameConsoleService => 3
          MSCONFIG\Services: Garmin Device Interaction Service => 2
          MSCONFIG\Services: GoToAssist => 3
          MSCONFIG\Services: gupdate => 2
          MSCONFIG\Services: gupdatem => 3
          MSCONFIG\Services: gusvc => 3
          MSCONFIG\Services: hnmsvc => 2
          MSCONFIG\Services: IJPLMSVC => 2
          MSCONFIG\Services: iPod Service => 3
          MSCONFIG\Services: MBAMScheduler => 2
          MSCONFIG\Services: MBAMService => 2
          MSCONFIG\Services: McComponentHostService => 3
          MSCONFIG\Services: MozillaMaintenance => 3
          MSCONFIG\Services: SftService => 2
          MSCONFIG\Services: STacSV => 2
          MSCONFIG\Services: wltrysvc => 2
          MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dell Remote Access.lnk => C:\Windows\pss\Dell Remote Access.lnk.CommonStartup
          MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
          MSCONFIG\startupfolder: C:^Users^Linda.Linda-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk => C:\Windows\pss\Dell Dock.lnk.Startup
          MSCONFIG\startupfolder: C:^Users^Linda.Linda-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
          MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
          MSCONFIG\startupreg: Apoint => C:\Program Files\DellTPad\Apoint.exe
          MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
          MSCONFIG\startupreg: Broadcom Wireless Manager UI => C:\Windows\system32\WLTRAY.exe
          MSCONFIG\startupreg: CanonQuickMenu => C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE /logon
          MSCONFIG\startupreg: Dell DataSafe Online => "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
          MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
          MSCONFIG\startupreg: dellsupportcenter => "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
          MSCONFIG\startupreg: Dropbox Update => "C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
          MSCONFIG\startupreg: Facebook Update => "C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
          MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
          MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
          MSCONFIG\startupreg: IAAnotif => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
          MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
          MSCONFIG\startupreg: IJNetworkScannerSelectorEX => C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
          MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
          MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
          MSCONFIG\startupreg: PDVDDXSrv => "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
          MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
          MSCONFIG\startupreg: QuickSet => C:\Program Files\Dell\QuickSet\QuickSet.exe
          MSCONFIG\startupreg: Recipe Hub Search Scope Monitor => "C:\PROGRA~1\RECIPE~2\bar\1.bin\2jsrchmn.exe" /m=2 /w /h
          MSCONFIG\startupreg: RecipeHub_2j Browser Plugin Loader => C:\PROGRA~1\RECIPE~2\bar\1.bin\2jbrmon.exe
          MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
          MSCONFIG\startupreg: SysTrayApp => %ProgramFiles%\IDT\WDM\sttray.exe
          MSCONFIG\startupreg: WMPNSCFG => C:\Program Files\Windows Media Player\WMPNSCFG.exe
           
          ==================== FirewallRules (Whitelisted) ===============
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          FirewallRules: [TCP Query User{1DFE9015-E882-4897-BBEE-D82C6671B9C4}C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Allow) C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe
          FirewallRules: [UDP Query User{3540076B-0AAD-4D68-A9DD-8984C1DD0D20}C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Allow) C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe
          FirewallRules: [{14B95006-3757-4085-B850-8BE5C39C3B21}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{6B110739-15C4-44D9-9940-05EB3E13C847}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{86A47EFE-4472-49A4-A4DC-605BE72DD6AB}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
          FirewallRules: [{BC411B3E-88FF-40FC-A5D6-BDD9FCCADCFD}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
          FirewallRules: [{35C6BC21-17E5-47FB-A608-458493E67E22}] => (Allow) C:\Program Files\iTunes\iTunes.exe
          FirewallRules: [TCP Query User{10A0F431-68FE-4999-952E-DDE2FBA82CE0}C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe
          FirewallRules: [UDP Query User{7A5BC35F-7AD3-4AAC-A407-98F7651811B3}C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe
          FirewallRules: [{1A81DCF4-4A0D-45D1-8936-8DCC4D4DBD58}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe
          FirewallRules: [{A17AA28B-5FB4-416F-8D8E-B03C10810F25}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe
          FirewallRules: [{59217529-98D9-40A8-808B-2590921D055E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
          FirewallRules: [{CEBAE611-8EB3-47DD-AA02-1D0C51D1A23B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
          FirewallRules: [TCP Query User{7336234A-BC3B-4FC7-BCB8-568AE98795D7}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
          FirewallRules: [UDP Query User{60C14774-7DCB-480A-9CDA-40631E3B1007}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
          FirewallRules: [TCP Query User{4A10995A-73B1-41DD-BE32-8723CE20E33A}C:\program files\usmle\fredv2step1\fredv2orient.exe] => (Allow) C:\program files\usmle\fredv2step1\fredv2orient.exe
          FirewallRules: [UDP Query User{60C01436-2076-4D96-96A6-56FBDF8B0248}C:\program files\usmle\fredv2step1\fredv2orient.exe] => (Allow) C:\program files\usmle\fredv2step1\fredv2orient.exe
          FirewallRules: [TCP Query User{911A7A12-326A-487E-B981-F78A74CC8E0E}C:\program files\usmle\fredv2step1\ned.exe] => (Allow) C:\program files\usmle\fredv2step1\ned.exe
          FirewallRules: [UDP Query User{D6058E1F-3B59-4E86-9B4B-2CCAA5B0F123}C:\program files\usmle\fredv2step1\ned.exe] => (Allow) C:\program files\usmle\fredv2step1\ned.exe
          FirewallRules: [{B2FD502B-BABF-4704-B2C7-6C2825F173DC}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
          FirewallRules: [{4C7E78BE-279D-4DE0-9078-47579FFBB44F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
          FirewallRules: [{07EEE22B-A46C-472A-861F-33DBA61BBD14}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
           
          ==================== Faulty Device Manager Devices =============
           
           
          ==================== Event log errors: =========================
           
          Application errors:
          ==================
          Error: (12/23/2015 08:33:10 AM) (Source: Windows Search Service) (EventID: 1006) (User: )
          Description: The Windows Search Service has failed to create the SystemIndex search index. Internal error <4, 0x8004117f, Failed to add project: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects>.
           
          Error: (12/23/2015 08:33:10 AM) (Source: Windows Search Service) (EventID: 9000) (User: )
          Description: The Windows Search Service cannot open the Jet property store.
           
          Details:
          The content index server cannot update or access information because of a database error.  Stop and restart the search service.  If the problem persists, reset and recrawl the content index.  In some cases it may be necessary to delete and recreate the content index.   (0x8004117f)
           
          Error: (12/23/2015 08:33:10 AM) (Source: ESENT) (EventID: 455) (User: )
          Description: Windows (3732) Windows: Error -1032 (0xfffffbf8) occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
           
          Error: (12/23/2015 08:33:10 AM) (Source: ESENT) (EventID: 489) (User: )
          Description: Windows (3732) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" for read only access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
           
          Error: (12/23/2015 08:33:00 AM) (Source: ESENT) (EventID: 455) (User: )
          Description: Windows (3732) Windows: Error -1032 (0xfffffbf8) occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
           
          Error: (12/23/2015 08:33:00 AM) (Source: ESENT) (EventID: 489) (User: )
          Description: Windows (3732) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" for read only access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
           
          Error: (12/23/2015 08:32:23 AM) (Source: Windows Search Service) (EventID: 1006) (User: )
          Description: The Windows Search Service has failed to create the SystemIndex search index. Internal error <4, 0x8004117f, Failed to add project: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects>.
           
          Error: (12/23/2015 08:32:23 AM) (Source: Windows Search Service) (EventID: 9000) (User: )
          Description: The Windows Search Service cannot open the Jet property store.
           
          Details:
          The content index server cannot update or access information because of a database error.  Stop and restart the search service.  If the problem persists, reset and recrawl the content index.  In some cases it may be necessary to delete and recreate the content index.   (0x8004117f)
           
          Error: (12/23/2015 08:32:23 AM) (Source: ESENT) (EventID: 455) (User: )
          Description: Windows (3320) Windows: Error -1032 (0xfffffbf8) occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
           
          Error: (12/23/2015 08:32:23 AM) (Source: ESENT) (EventID: 489) (User: )
          Description: Windows (3320) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" for read only access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
           
           
          System errors:
          =============
          Error: (12/23/2015 08:33:10 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
          Description: Windows Search7
           
          Error: (12/23/2015 08:33:10 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
          Description: Windows Search2147749155 (0x80040D23)
           
          Error: (12/23/2015 08:32:23 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
          Description: Windows Search6
           
          Error: (12/23/2015 08:32:23 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
          Description: Windows Search2147749155 (0x80040D23)
           
          Error: (12/23/2015 08:30:33 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
          Description: Windows Search5
           
          Error: (12/23/2015 08:30:33 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
          Description: Windows Search2147749155 (0x80040D23)
           
          Error: (12/23/2015 08:24:18 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
          Description: Windows Search4
           
          Error: (12/23/2015 08:24:18 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
          Description: Windows Search2147749155 (0x80040D23)
           
          Error: (12/23/2015 08:23:59 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
          Description: Windows Search3
           
          Error: (12/23/2015 08:23:59 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
          Description: Windows Search2147749155 (0x80040D23)
           
           
          CodeIntegrity:
          ===================================
            Date: 2015-12-23 08:34:37.378
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
           
            Date: 2015-12-23 08:34:36.972
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
           
            Date: 2015-12-23 08:34:36.644
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
           
            Date: 2015-12-23 08:34:36.300
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
           
            Date: 2015-12-23 08:34:35.800
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
           
            Date: 2015-12-23 08:34:35.472
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
           
            Date: 2015-12-23 08:34:35.113
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
           
            Date: 2015-12-23 08:34:34.769
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
           
            Date: 2015-12-23 08:34:20.020
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
           
            Date: 2015-12-23 08:34:19.676
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
           
           
          ==================== Memory info =========================== 
           
          Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
          Percentage of memory in use: 38%
          Total physical RAM: 3033.63 MB
          Available physical RAM: 1880.55 MB
          Total Virtual: 6287.55 MB
          Available Virtual: 5300.36 MB
           
          ==================== Drives ================================
           
          Drive c: (OS) (Fixed) (Total:218.2 GB) (Free:92.73 GB) NTFS ==>[drive with boot components (obtained from BCD)]
          Drive e: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:8.45 GB) NTFS
           
          ==================== MBR & Partition Table ==================
           
          ========================================================
          Disk: 0 (Size: 232.9 GB) (Disk ID: 00638CBF)
          Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
          Partition 2: (Not Active) - (Size=14.6 GB) - (Type=07 NTFS)
          Partition 3: (Active) - (Size=218.2 GB) - (Type=07 NTFS)
           
          ==================== End of Addition.txt ============================

          First if you purchase a windows 7 disk and do a complete format and reinstall anything bad on your system will be gone. You should be able to find one pretty easy on sites like Amazon or eBay. Its quite a chore, if you wanted to do this yourself our windows people can guide you through it, maybe taking it to a reliable computer shop in your area maybe easier. They can back up all your documents and photos, format the drive, reinstall windows and then put your files back, something to think about.

           

           

          Your log is still show signs of Zero Access which is a rootkit type of infection, lets run Combofix and see if it removes it

           

           

           
          Download ComboFix from one of these locations:
           
          Link 1
          Link 2
           
           
          * IMPORTANT !!! Save ComboFix.exe to your Desktop
           
           
          • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
          • See this Link  for programs that need to be disabled and instruction on how to disable them.
          • Remember to re-enable them when we're done.
           
           
          • Double click on ComboFix.exe & follow the prompts.
           
          For Windows XP Users
           
          • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. 
           
           
          • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
          •  
           
          **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
           
           

          [external image: RC1.png]

           
           
          Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

          [external image: RC2-1.png]

           
          Click on Yes, to continue scanning for malware.
           
          When finished, it shall produce a log for you.  Please include the C:\ComboFix.txt in your next reply.
           
          *If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
          Dear Ken;
          here is the combofix log
          does it also remove viruses?
           
          Thanks,
           
          Joel
           
          ComboFix 15-12-23.01 - Linda 12/23/2015  16:07:39.1.2 - x86
          Running from: c:\users\[removed]\Desktop\virus cleaners\ComboFix.exe
          .
          .
          (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          c:\programdata\PCDr\6664\AddOnDownloaded\0124e21d-018c-4ce0-92a3-b9e205a76bc0.dll
          c:\programdata\PCDr\6664\AddOnDownloaded\06054fba-5619-4a86-a861-ffb0464bef5d.dll
          c:\programdata\PCDr\6664\AddOnDownloaded\06fda46e-43c1-481a-9eb2-9799f42e7f99.dll
          c:\programdata\PCDr\6664\AddOnDownloaded\073fb38f-0e69-479d-bca1-4f81ec9dcbf6.dll
          c:\programdata\PCDr\6664\AddOnDownloaded\0bc194f9-b102-4833-85bd-603e216a9274.dll
          c:\programdata\PCDr\6664\AddOnDownloaded\0d461521-7dbf-4cec-a29e-936c88cdf8c9.dll
          c:\programdata\PCDr\6664\AddOnDownloaded\100c3865-0c76-461b-b2fd-042d6d5fa7f6.dll
          c:\programdata\PCDr\6664\AddOnDownloaded\14d73fac-0439-4f06-9763-0341fab0d44f.dll
          c:\programdata\PCDr\6664\AddOnDownloaded\173c4dd2-e93c-4725-b006-db1d8f465192.dll
          c:\windows\system32\SET5C05.tmp
          E:\autorun.inf
          .
          .
          (((((((((((((((((((((((((   Files Created from 2015-11-23 to 2015-12-23  )))))))))))))))))))))))))))))))
          .
          .
          2015-12-23 21:15 . 2015-12-23 21:15 ——– d—–w- c:\users\RA Media Server\AppData\Local\temp
          2015-12-23 21:15 . 2015-12-23 21:15 ——– d—–w- c:\users\Linda\AppData\Local\temp
          2015-12-23 21:15 . 2015-12-23 21:15 ——– d—–w- c:\users\Default\AppData\Local\temp
          2015-12-23 03:45 . 2015-12-23 03:45 ——– d—–w- c:\users\Linda.Linda-PC\AppData\Local\Microsoft Corporation
          2015-12-23 03:44 . 2015-12-23 03:44 ——– d—–w- c:\program files\Microsoft Windows 7 Upgrade Advisor
          2015-12-22 09:25 . 2015-12-23 05:33 170200 —-a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
          2015-12-22 09:24 . 2015-10-05 14:50 94936 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
          2015-12-22 09:24 . 2015-12-23 01:23 ——– d—–w- c:\program files\Malwarebytes Anti-Malware
          2015-12-22 09:24 . 2015-10-05 14:50 51928 —-a-w- c:\windows\system32\drivers\mwac.sys
          2015-12-22 09:24 . 2015-10-05 14:50 23256 —-a-w- c:\windows\system32\drivers\mbam.sys
          2015-12-21 05:49 . 2015-12-23 13:36 ——– d—–w- C:\FRST
          2015-12-21 03:05 . 2015-12-21 03:05 7168 —-a-w- c:\windows\DellBIOS.Sys
          2015-12-21 02:18 . 2015-12-21 02:18 ——– d—–w- c:\users\Linda.Linda-PC\{b1967a33-da0b-4955-a208-b043aa2fbe2e}
          2015-12-21 02:18 . 2015-10-28 05:20 31992 —-a-w- c:\windows\system32\drivers\pcdrndisprot.sys
          2015-12-21 02:09 . 2015-12-21 02:09 ——– d—–w- c:\programdata\PC-Doctor for Windows
          2015-12-21 02:01 . 2015-12-21 21:37 ——– d—–w- c:\users\Linda.Linda-PC\AppData\Roaming\PCDr
          2015-12-21 02:00 . 2015-12-21 02:00 ——– d—–w- c:\users\Linda.Linda-PC\AppData\Local\Deployment
          2015-12-21 02:00 . 2015-12-21 02:00 ——– d—–w- c:\users\Linda.Linda-PC\AppData\Local\Apps
          2015-12-17 02:14 . 2015-12-17 02:14 ——– d—–w- c:\users\Linda.Linda-PC\AppData\Local\McAfee File Lock
          2015-12-17 02:01 . 2015-12-17 03:50 ——– d—–w- c:\users\Linda.Linda-PC\AppData\Local\LogMeIn Rescue Applet
          2015-12-17 01:55 . 2015-12-17 01:57 ——– d—–w- c:\program files\stinger
          2015-12-17 01:55 . 2015-12-17 02:14 ——– d—–w- c:\program files\Common Files\McAfee
          2015-12-16 03:40 . 2015-12-16 03:40 ——– d—–w- c:\programdata\BSD
          2015-12-16 02:53 . 2015-12-16 02:53 ——– d—–w- c:\users\Linda.Linda-PC\AppData\Roaming\McAfee
          2015-12-16 02:52 . 2015-12-17 03:53 ——– d—–w- c:\program files\McAfee
          .
          .
          .
          ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2015-12-18 01:13 . 2012-08-22 19:35 796864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
          2015-12-18 01:13 . 2012-02-28 00:18 142528 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
          2015-12-09 03:39 . 2012-05-27 20:14 247976 ——w- c:\windows\system32\MpSigStub.exe
          2015-10-31 18:38 . 2015-11-11 00:35 367616 —-a-w- c:\windows\system32\html.iec
          2015-10-31 18:37 . 2015-11-11 00:35 1830912 —-a-w- c:\windows\system32\jscript9.dll
          2015-10-31 18:36 . 2015-11-11 00:35 1436160 —-a-w- c:\windows\system32\inetcpl.cpl
          2015-10-31 18:36 . 2015-11-11 00:35 1088512 —-a-w- c:\windows\system32\wininet.dll
          2015-10-31 18:36 . 2015-11-11 00:35 142848 —-a-w- c:\windows\system32\ieUnatt.exe
          2015-10-31 18:36 . 2015-11-11 00:35 412672 —-a-w- c:\windows\system32\vbscript.dll
          2015-10-31 18:36 . 2015-11-11 00:36 11776 —-a-w- c:\windows\system32\mshta.exe
          2015-10-31 18:36 . 2015-11-11 00:36 2382848 —-a-w- c:\windows\system32\mshtml.tlb
          2015-10-17 16:01 . 2015-11-11 08:11 501248 —-a-w- c:\windows\system32\kerberos.dll
          2015-10-17 14:24 . 2015-11-11 08:16 2068480 —-a-w- c:\windows\system32\win32k.sys
          2015-10-14 20:22 . 2015-11-11 08:10 1206192 —-a-w- c:\windows\system32\ntdll.dll
          2015-10-14 16:01 . 2015-11-11 08:10 3606464 —-a-w- c:\windows\system32\ntkrnlpa.exe
          2015-10-14 16:01 . 2015-11-11 08:10 3554752 —-a-w- c:\windows\system32\ntoskrnl.exe
          2015-10-13 14:31 . 2015-11-11 08:12 273408 —-a-w- c:\windows\system32\drivers\afd.sys
          2015-10-13 14:31 . 2015-11-11 08:12 72192 —-a-w- c:\windows\system32\drivers\tdx.sys
          2015-10-13 06:29 . 2015-10-13 06:29 875720 —-a-w- c:\windows\system32\msvcr120_clr0400.dll
          2015-10-10 16:02 . 2015-11-11 08:06 526272 —-a-w- c:\windows\system32\drivers\ndis.sys
          2015-09-26 16:05 . 2015-11-11 08:02 281600 —-a-w- c:\windows\system32\schannel.dll
          2015-09-26 16:04 . 2015-11-11 08:02 206336 —-a-w- c:\windows\system32\ncrypt.dll
          2015-09-26 13:21 . 2015-11-11 08:02 274432 —-a-w- c:\windows\system32\bcrypt.dll
          .
          .
          (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* empty entries & legit default entries are not shown 
          REGEDIT4
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
          @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
          [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
          2015-12-08 21:33 199488 —-a-w- c:\users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
          @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
          [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
          2015-12-08 21:33 199488 —-a-w- c:\users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
          @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
          [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
          2015-12-08 21:33 199488 —-a-w- c:\users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
          @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
          [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
          2015-12-08 21:33 199488 —-a-w- c:\users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
          @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
          [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
          2015-12-08 21:33 199488 —-a-w- c:\users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
          @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
          [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
          2015-12-08 21:33 199488 —-a-w- c:\users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
          @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
          [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
          2015-12-08 21:33 199488 —-a-w- c:\users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
          @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
          [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
          2015-12-08 21:33 199488 —-a-w- c:\users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll
          .
          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "GarminExpressTrayApp"="c:\program files\Garmin\Express Tray\ExpressTray.exe" [2015-10-29 1403304]
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
          "EnableUIADesktopToggle"= 0 (0x0)
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
          2009-07-07 14:25 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
          .
          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
          BootExecute REG_MULTI_SZ   autocheck autochk /k:C *
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
          @="Driver"
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
          @="Driver"
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
          @="Driver"
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
          @="Service"
          .
          [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dell Remote Access.lnk]
          path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Dell Remote Access.lnk
          backup=c:\windows\pss\Dell Remote Access.lnk.CommonStartup
          backupExtension=.CommonStartup
          .
          [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
          path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
          backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
          backupExtension=.CommonStartup
          .
          [HKLM\~\startupfolder\C:^Users^Linda.Linda-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk]
          path=c:\users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
          backup=c:\windows\pss\Dell Dock.lnk.Startup
          backupExtension=.Startup
          .
          [HKLM\~\startupfolder\C:^Users^Linda.Linda-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
          path=c:\users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
          backup=c:\windows\pss\Dropbox.lnk.Startup
          backupExtension=.Startup
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
          2012-07-27 20:51 919008 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
          2009-03-31 14:18 217088 —-a-w- c:\program files\DellTPad\Apoint.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
          2014-07-31 16:15 43816 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
          2008-12-21 18:34 3810304 —-a-w- c:\windows\System32\WLTRAY.EXE
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonQuickMenu]
          2014-11-08 19:14 1298504 —-a-w- c:\program files\Canon\Quick Menu\CNQMMAIN.EXE
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell DataSafe Online]
          2009-04-09 21:29 1762032 —-a-w- c:\program files\Dell DataSafe Online\DataSafeOnline.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Webcam Central]
          2009-01-09 18:49 405639 —-a-w- c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dropbox Update]
          2015-06-20 20:37 134512 —-atw- c:\users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
          2012-08-24 03:00 138096 —-atw- c:\users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarminExpressTrayApp]
          2015-10-29 13:31 1403304 —-a-w- c:\program files\Garmin\Express Tray\ExpressTray.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
          2009-03-31 16:55 173592 —-a-w- c:\windows\System32\hkcmd.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
          2008-05-07 22:41 178712 —-a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
          2009-03-31 16:55 141848 —-a-w- c:\windows\System32\igfxtray.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScannerSelectorEX]
          2014-01-15 19:13 438888 —-a-w- c:\program files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
          2014-08-01 20:18 152392 —-a-w- c:\program files\iTunes\iTunesHelper.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
          2009-02-05 02:26 128232 —-a-w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
          2009-03-31 16:55 150552 —-a-w- c:\windows\System32\igfxpers.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickSet]
          2009-01-09 17:06 1735760 —-a-w- c:\program files\Dell\QuickSet\quickset.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
          2009-04-11 06:28 1233920 —-a-w- c:\program files\Windows Sidebar\sidebar.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
          2012-07-03 14:04 252848 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
          2009-03-31 15:00 483428 —-a-w- c:\program files\IDT\WDM\sttray.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
          2008-01-21 02:35 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe
          .
          R4 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [2009-03-31 81920]
          .
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          LocalServiceNoNetwork REG_MULTI_SZ   PLA DPS BFE mpssvc
          LocalServiceAndNoImpersonation REG_MULTI_SZ   FontCache
          HPZ12 REG_MULTI_SZ   Pml Driver HPZ12 Net Driver HPZ12
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
          2015-12-17 13:41 1000264 —-a-w- c:\program files\Google\Chrome\Application\47.0.2526.106\Installer\chrmstp.exe
          .
          Contents of the 'Scheduled Tasks' folder
          .
          2015-12-23 c:\windows\Tasks\Adobe Flash Player Updater.job
          - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-22 01:13]
          .
          2015-12-03 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job
          - c:\users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20 20:37]
          .
          2015-12-23 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job
          - c:\users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20 20:37]
          .
          2015-12-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job
          - c:\users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-24 03:00]
          .
          2015-12-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job
          - c:\users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-24 03:00]
          .
          2015-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2012-02-28 00:43]
          .
          2015-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2012-02-28 00:43]
          .
          .
          ——- Supplementary Scan ——-
          .
          uInternet Settings,ProxyOverride = *.local
          IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
          Trusted Zone: dell.com
          TCP: DhcpNameServer = 8.8.4.4 [removed] 4.2.2.2
          FF - ProfilePath - c:\users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default\
          FF - prefs.js: browser.search.selectedEngine - Google
          FF - prefs.js: browser.startup.homepage - www.google.com
          .
          - - - - ORPHANS REMOVED - - - -
          .
          MSConfigStartUp-dellsupportcenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
          MSConfigStartUp-MSC - c:\program files\Microsoft Security Client\msseces.exe
          MSConfigStartUp-Recipe Hub Search Scope Monitor - c:\progra~1\RECIPE~2\bar\1.bin\2jsrchmn.exe
          MSConfigStartUp-RecipeHub_2j Browser Plugin Loader - c:\progra~1\RECIPE~2\bar\1.bin\2jbrmon.exe
          AddRemove-Coupon Printer for Windows5.0.0.4 - c:\program files\Coupons\uninstall.exe
          AddRemove-CouponBar5.0.0.4 - c:\program files\Coupons.com CouponBar\uninstall.exe
          .
          .
          .
          **************************************************************************
          .
          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2015-12-23 16:15
          Windows 6.0.6002 Service Pack 2 NTFS
          .
          scanning hidden processes …  
          .
          scanning hidden autostart entries … 
          .
          scanning hidden files …  
          .
          .
          c:\users\LINDA~1.LIN\AppData\Local\Temp\catchme.dll 53248 bytes executable
          .
          scan completed successfully
          hidden files: 1
          .
          **************************************************************************
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
          "ImagePath"="\??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
          .
          Completion time: 2015-12-23  16:17:56
          ComboFix-quarantined-files.txt  2015-12-23 21:17
          ComboFix2.txt  2010-12-21 04:21
          .
          Pre-Run: 99,323,637,760 bytes free
          Post-Run: 101,845,770,240 bytes free
          .
          - - End Of File - - D5E99F5378266945586EE496087BEB66
          CDB4DE4BBD714F152979DA2DCBEF57EB

          Dear Ken:

           

          I noticed something unusual in the "tree" structure of Windows Explorer and I was wondering if you could help.

          It may or may not be related to the work we've been doing.

          I wanted to paste a screenshot of my explorer but it wouldn't past into this reply area.

          So, I'll describe it

           

          Within a folder I created to hold the virus downloads and log files there is now a subfolder called "C" which contains a Program folder, a ProgramData folder and a Users folder.  The Users folder concerns me because it is a duplicate of the Users folder on the C: drive and the duplicate folder contains duplicates of the user names listed in the C: drive's Users folder.

           

          Also a new folder has been created called Qoobox which contains subfolders, files and programs I'm not familiar with, but one subfolder is labeled "Quarantine" and another is labeled "Windows"

           

          Thanks again,

           

          Joel

          Ask AI

          AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

          Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI