This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows Vista Basic Home Edition Freezing [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear Ken:

 

Here are the FRST logs.

Thanks for your help.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:23-12-2015
Ran by [removed] (administrator) on LINDA-PC (23-12-2015 17:25:35)
Running from C:\Users\[removed]\Desktop\virus cleaners
[removed]
Platform: Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Intel Corporation) C:\WINDOWS\System32\igfxsrvc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2009-07-07] (Citrix Online, a division of Citrix Systems, Inc.)
HKU\S-1-5-18\…\Run: [GarminExpressTrayApp] => C:\Program Files\Garmin\Express Tray\ExpressTray.exe [1403304 2015-10-29] (Garmin Ltd. or its subsidiaries)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\RA Media Server\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
BootExecute: autocheck autochk /k:C * 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 8.8.4.4 [removed] 4.2.2.2
Tcpip\..\Interfaces\{C7F26639-2C1A-4FE2-AA45-8D9D300C51D8}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{E10DCCCB-A154-45DA-88BC-E56EC0A35C8A}: [DhcpNameServer] 8.8.4.4 [removed] 4.2.2.2
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
SearchScopes: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> DefaultScope {12696EE3-C065-4036-A844-31F773CCB8D3} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=DLCDF7&pc;=MDDC&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> {12696EE3-C065-4036-A844-31F773CCB8D3} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=DLCDF7&pc;=MDDC&src;=IE-SearchBox
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27] (Adobe Systems Incorporated)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-11] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-11] (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
 
FireFox:
========
FF ProfilePath: C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default
FF NewTab: about:blank
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google
FF SearchEngineOrder.3: Bing 
FF SelectedSearchEngine: Google
FF Homepage: www.google.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-17] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=10.10.2 -> C:\Windows\system32\npDeployJava1.dll [2013-01-11] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.10.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-01-11] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-17] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-07-27] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1549655542-3693215259-3179495191-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-1549655542-3693215259-3179495191-1000: CouponNetwork.com/CMDUniversalCouponPrintActivator -> C:\Users\LINDA~1.LIN\AppData\Roaming\CATALI~1\NPBCSK~1.DLL [No File]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2013-08-02] (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Linda.Linda-PC\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-12-15] (Cisco WebEx LLC)
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-02-02] [not signed]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.ebay.com/
CHR Profile: C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-15]
CHR Extension: (Google Docs) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-15]
CHR Extension: (Google Drive) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-15]
CHR Extension: (YouTube) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-15]
CHR Extension: (Google Search) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-15]
CHR Extension: (Google Sheets) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-15]
CHR Extension: (Google Docs Offline) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-15]
CHR Extension: (Gmail) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-15]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S4 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [81920 2009-03-31] (Andrea Electronics Corporation)
S4 Apache2.2; C:\Program Files\Common Files\Dell\apache\bin\httpd.exe [15872 2007-09-21] (Apache Software Foundation) [File not signed]
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-12-18] (Stardock Corporation) [File not signed]
S4 dsl-db; C:\Program Files\Common Files\Dell\MySQL\bin\mysqld.exe [5730304 2007-09-14] () [File not signed]
S4 dsl-fs-sync; C:\Program Files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe [189680 2009-04-13] (SingleClick Systems)
S4 GameConsoleService; C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe [242424 2008-11-03] (WildTangent, Inc.)
S4 Garmin Device Interaction Service; C:\Program Files\Garmin\Device Interaction Service\GarminService.exe [777744 2015-10-29] (Garmin Ltd. or its subsidiaries)
S4 GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [16680 2009-07-07] (Citrix Online, a division of Citrix Systems, Inc.)
S4 hnmsvc; c:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe [828656 2009-04-13] (Dell Inc.)
S4 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S4 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S4 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.226\McCHSvc.exe [235696 2015-10-30] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S4 SftService; C:\Program Files\Dell DataSafe Local Backup\sftservice.EXE [1692480 2011-08-18] (SoftThinks SAS)
S4 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe [254042 2009-03-31] (IDT, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
S4 wltrysvc; C:\Windows\System32\bcmwltry.exe [2809856 2008-12-21] (Dell Inc.) [File not signed]
R2 yksvc; RUNDLL32.EXE ykx32coinst,serviceStartProc [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2008-12-21] (Broadcom Corporation)
S3 DellBIOS; C:\Windows\DellBIOS.Sys [7168 2015-12-20] () [File not signed]
R3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [35776 2013-09-23] (hxxp://libusb-win32.sourceforge.net)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [170200 2015-12-23] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation)
R3 OA009Ufd; C:\Windows\System32\DRIVERS\OA009Ufd.sys [133632 2009-03-06] (Creative Technology Ltd.)
R3 OA009Vid; C:\Windows\System32\DRIVERS\OA009Vid.sys [271552 2009-03-19] (Creative Technology Ltd.)
R2 Packet; C:\Windows\System32\DRIVERS\packet.sys [22016 2008-06-17] (SingleClick Systems)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)
S3 catchme; \??\C:\Users\LINDA~1.LIN\AppData\Local\Temp\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 PCD5SRVC{3F6A8B78-EC003E00-05040104}; \??\C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-23 16:17 - 2015-12-23 16:17 - 00018543 _____ C:\ComboFix.txt
2015-12-23 16:02 - 2011-06-26 01:45 - 00256000 _____ C:\Windows\PEV.exe
2015-12-23 16:02 - 2010-11-07 12:20 - 00208896 _____ C:\Windows\MBR.exe
2015-12-23 16:02 - 2009-04-19 23:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-12-23 16:02 - 2000-08-30 19:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-12-23 16:02 - 2000-08-30 19:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-12-23 16:02 - 2000-08-30 19:00 - 00098816 _____ C:\Windows\sed.exe
2015-12-23 16:02 - 2000-08-30 19:00 - 00080412 _____ C:\Windows\grep.exe
2015-12-23 16:02 - 2000-08-30 19:00 - 00068096 _____ C:\Windows\zip.exe
2015-12-23 16:01 - 2015-12-23 16:16 - 00000000 ____D C:\Windows\erdnt
2015-12-22 22:45 - 2015-12-22 22:45 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Microsoft Corporation
2015-12-22 22:44 - 2015-12-22 22:44 - 00001998 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 Upgrade Advisor.lnk
2015-12-22 22:44 - 2015-12-22 22:44 - 00001986 _____ C:\Users\Public\Desktop\Windows 7 Upgrade Advisor.lnk
2015-12-22 22:44 - 2015-12-22 22:44 - 00000000 ____D C:\Program Files\Microsoft Windows 7 Upgrade Advisor
2015-12-22 22:39 - 2015-12-22 22:39 - 08669472 _____ (Microsoft Corporation) C:\Users\Linda.Linda-PC\Downloads\Windows7UpgradeAdvisorSetup.exe
2015-12-22 20:23 - 2015-12-22 20:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-22 05:45 - 2015-12-23 16:01 - 00000000 ____D C:\Users\Linda.Linda-PC\Desktop\virus cleaners
2015-12-22 04:25 - 2015-12-23 00:33 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-12-22 04:24 - 2015-12-22 20:23 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-12-22 04:24 - 2015-10-05 09:50 - 00094936 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-12-22 04:24 - 2015-10-05 09:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-12-22 04:24 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-12-22 04:17 - 2015-12-22 04:17 - 00002238 _____ C:\Users\Linda.Linda-PC\Desktop\JRT.txt
2015-12-21 02:31 - 2015-12-21 02:31 - 274668427 _____ C:\Windows\MEMORY.DMP
2015-12-21 02:31 - 2015-12-21 02:31 - 00143728 _____ C:\Windows\Minidump\Mini122115-01.dmp
2015-12-21 00:49 - 2015-12-23 17:25 - 00000000 ____D C:\FRST
2015-12-20 23:45 - 2015-12-23 16:41 - 00000000 ____D C:\Users\Linda.Linda-PC\Documents\troubleshooting
2015-12-20 23:06 - 2015-12-20 23:06 - 00000512 _____ C:\Users\Linda.Linda-PC\Documents\MBR.dat
2015-12-20 22:06 - 2015-12-20 22:06 - 01162486 _____ C:\Users\Linda.Linda-PC\Downloads\1545_A14 (1).EXE
2015-12-20 22:05 - 2015-12-20 22:05 - 01162486 _____ C:\Users\Linda.Linda-PC\Downloads\1545_A14.EXE
2015-12-20 22:05 - 2015-12-20 22:05 - 00007168 _____ C:\Windows\DellBIOS.Sys
2015-12-20 21:53 - 2015-12-20 21:54 - 49934552 _____ (Microsoft Corporation) C:\Users\Linda.Linda-PC\Downloads\Windows-KB890830-V5.31.exe
2015-12-20 21:18 - 2015-12-20 21:18 - 00000000 ____D C:\Users\Linda.Linda-PC\{b1967a33-da0b-4955-a208-b043aa2fbe2e}
2015-12-20 21:18 - 2015-10-28 00:20 - 00031992 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\pcdrndisprot.sys
2015-12-20 21:09 - 2015-12-20 21:09 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\LocalLow\PCDr
2015-12-20 21:09 - 2015-12-20 21:09 - 00000000 ____D C:\ProgramData\PC-Doctor for Windows
2015-12-20 21:01 - 2015-12-21 16:37 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\PCDr
2015-12-20 21:00 - 2015-12-20 21:00 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
2015-12-20 21:00 - 2015-12-20 21:00 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Deployment
2015-12-20 21:00 - 2015-12-20 21:00 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Apps\2.0
2015-12-20 20:59 - 2015-12-20 20:59 - 00417064 _____ () C:\Users\Linda.Linda-PC\Downloads\DellSystemDetectLauncher.exe
2015-12-20 20:20 - 2015-12-20 20:20 - 00247183 _____ C:\Users\Linda.Linda-PC\Documents\bookmarks_12_20_15.html
2015-12-17 08:48 - 2015-12-17 08:48 - 00000000 ____D C:\Windows\pss
2015-12-17 08:42 - 2015-12-17 08:43 - 07708304 _____ (McAfee, Inc.) C:\Users\Linda.Linda-PC\Downloads\Setup_serial_oeXOdgfIjbW_srLLuxULNQ2_key.exe
2015-12-17 08:42 - 2015-12-17 08:42 - 00001973 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-17 08:42 - 2015-12-17 08:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-17 06:19 - 2015-12-17 06:19 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-12-16 21:14 - 2015-12-16 21:14 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\McAfee File Lock
2015-12-16 21:12 - 2015-12-16 21:12 - 00000000 ____D C:\Program Files\McAfee.com
2015-12-16 21:01 - 2015-12-16 22:50 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\LogMeIn Rescue Applet
2015-12-16 20:55 - 2015-12-16 21:14 - 00000000 ____D C:\Program Files\Common Files\McAfee
2015-12-16 20:55 - 2015-12-16 20:57 - 00000000 ____D C:\Program Files\stinger
2015-12-16 19:18 - 2015-12-16 19:18 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox(88)
2015-12-15 22:47 - 2015-12-15 22:47 - 00000046 _____ C:\Users\Linda.Linda-PC\Desktop\eBay.url
2015-12-15 22:40 - 2015-12-15 22:40 - 00000000 ____D C:\ProgramData\BSD
2015-12-15 21:53 - 2015-12-15 21:53 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\McAfee
2015-12-15 21:52 - 2015-12-16 22:53 - 00000000 ____D C:\Program Files\McAfee
2015-12-13 01:15 - 2015-12-13 01:15 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox(84)
2015-12-07 13:46 - 2015-12-07 13:46 - 01958689 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(28)
2015-12-07 13:16 - 2015-12-07 13:16 - 00999116 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(27)
2015-12-04 16:36 - 2015-12-04 16:36 - 02956605 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(26)
2015-12-03 00:14 - 2015-12-03 00:14 - 00999469 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(25)
2015-12-02 16:39 - 2015-12-02 16:39 - 01959030 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(24)
2015-12-02 16:19 - 2015-12-02 16:19 - 00999491 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(23)
2015-11-24 21:04 - 2015-11-24 21:04 - 00436946 _____ C:\Users\Linda.Linda-PC\Downloads\310382351392
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-23 17:13 - 2015-06-20 15:37 - 00000936 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job
2015-12-23 17:13 - 2012-08-22 14:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-23 17:05 - 2012-08-23 22:00 - 00000946 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job
2015-12-23 17:03 - 2012-02-27 19:19 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-23 16:44 - 2012-02-27 19:19 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-23 16:44 - 2006-11-02 07:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-23 16:44 - 2006-11-02 07:45 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-23 16:44 - 2006-11-02 07:45 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-23 16:43 - 2006-11-02 07:58 - 00032588 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-12-23 16:41 - 2012-01-31 22:56 - 00000000 ____D C:\Qoobox
2015-12-23 16:17 - 2006-11-02 06:18 - 00000000 ____D C:\WINDOWS
2015-12-23 16:15 - 2006-11-02 05:23 - 00000215 _____ C:\Windows\system.ini
2015-12-23 01:08 - 2012-02-01 08:50 - 00000000 ____D C:\Program Files\Google
2015-12-23 00:57 - 2012-02-27 19:18 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Google
2015-12-23 00:57 - 2012-02-27 19:18 - 00000000 ____D C:\ProgramData\Google
2015-12-23 00:53 - 2012-05-27 15:03 - 00001945 _____ C:\Windows\epplauncher.mif
2015-12-23 00:31 - 2009-07-07 09:52 - 00000000 ____D C:\ProgramData\TEMP
2015-12-23 00:31 - 2009-07-07 09:43 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2015-12-23 00:31 - 2009-07-07 09:43 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2015-12-23 00:31 - 2009-07-07 09:34 - 00000000 ____D C:\Program Files\Dell DataSafe Local Backup
2015-12-22 23:05 - 2012-08-23 22:00 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job
2015-12-22 04:24 - 2012-01-31 22:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-12-21 22:34 - 2012-01-31 22:40 - 00000000 ____D C:\Users\Linda.Linda-PC
2015-12-21 20:39 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\inf
2015-12-21 20:39 - 2006-11-02 05:33 - 00759542 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-21 02:31 - 2014-03-01 20:13 - 00000000 ____D C:\Windows\Minidump
2015-12-21 02:12 - 2006-11-02 06:18 - 00000000 ___SD C:\Windows\Downloaded Program Files
2015-12-20 22:25 - 2009-09-24 19:45 - 00913204 _____ C:\Windows\ntbtlog.txt
2015-12-20 21:18 - 2013-10-19 13:26 - 00000000 ____D C:\Temp
2015-12-20 21:09 - 2012-01-31 22:40 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Dell
2015-12-20 21:09 - 2009-07-07 09:36 - 00000000 ____D C:\ProgramData\PCDr
2015-12-20 21:09 - 2009-07-07 09:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2015-12-20 21:08 - 2009-07-07 09:36 - 00000000 ____D C:\Program Files\Dell Support Center
2015-12-20 21:06 - 2009-07-07 09:16 - 00000000 ____D C:\Program Files\Dell
2015-12-20 21:04 - 2009-07-07 11:37 - 00000000 ____D C:\DELL
2015-12-20 21:04 - 2009-07-07 09:35 - 00000000 ____D C:\ProgramData\Dell
2015-12-17 20:13 - 2012-08-22 14:35 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-12-17 20:13 - 2012-02-27 19:18 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-12-17 08:33 - 2014-09-07 10:29 - 00000000 ___RD C:\Users\Linda.Linda-PC\Dropbox
2015-12-17 08:33 - 2014-09-07 10:25 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox
2015-12-17 06:09 - 2009-07-07 09:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Remote Access
2015-12-17 06:09 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\Msdtc
2015-12-17 06:08 - 2012-02-02 07:05 - 00000000 ____D C:\Users\RA Media Server
2015-12-17 06:08 - 2006-11-02 05:22 - 46137344 _____ C:\Windows\system32\config\software_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 43778048 _____ C:\Windows\system32\config\components_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 15466496 _____ C:\Windows\system32\config\system_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\default_previous
2015-12-17 06:07 - 2015-11-06 21:40 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-12-17 06:07 - 2012-08-22 14:35 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2015-12-17 06:07 - 2012-08-21 15:24 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-12-17 06:07 - 2012-02-28 21:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-12-17 06:07 - 2012-01-31 23:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-12-17 06:07 - 2009-07-07 09:40 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-12-17 06:07 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Dell Remote Access
2015-12-17 06:07 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Common Files\Dell
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 __RSD C:\Windows\Media
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\spool
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\rescache
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-12-17 06:06 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\registration
2015-12-17 02:02 - 2009-07-07 09:48 - 00000000 ____D C:\ProgramData\McAfee
2015-12-16 19:11 - 2013-07-15 02:01 - 00000000 ____D C:\Windows\system32\MRT
2015-12-15 21:41 - 2015-10-18 21:33 - 00000000 ____D C:\Program Files\McAfee Security Scan
2015-12-15 21:03 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Common Files\Dell(2)
2015-12-15 19:48 - 2012-02-03 06:04 - 00006080 _____ C:\Users\Linda.Linda-PC\AppData\Local\d3d9caps.dat
2015-12-10 03:45 - 2015-08-29 13:47 - 00000000 ____D C:\ProgramData\CanonIJPLM
2015-12-08 22:39 - 2012-05-27 15:14 - 00247976 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-12-03 16:08 - 2015-06-20 15:37 - 00000884 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job
2015-11-23 19:09 - 2006-11-02 05:24 - 137798368 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
 
==================== Files in the root of some directories =======
 
2013-11-04 13:41 - 2013-11-04 13:41 - 0893239 _____ () C:\Users\Linda.Linda-PC\AppData\Local\a.zip
2013-11-04 13:41 - 2013-11-04 13:41 - 2162416 _____ (Catalina Marketing Corp) C:\Users\Linda.Linda-PC\AppData\Local\BcsKtYcHW.dll
2012-02-03 06:04 - 2015-12-15 19:48 - 0006080 _____ () C:\Users\Linda.Linda-PC\AppData\Local\d3d9caps.dat
2012-01-31 22:48 - 2015-11-07 15:34 - 0018944 _____ () C:\Users\Linda.Linda-PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-29 18:33 - 2015-08-29 15:00 - 0007084 _____ () C:\ProgramData\hpzinstall.log
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-12-23 16:51
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version:23-12-2015
Ran by [removed] (2015-12-23 17:26:24)
Running from C:\Users\[removed]\Desktop\virus cleaners
Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) (2009-07-07 09:02:45)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1549655542-3693215259-3179495191-500 - Administrator - Disabled)
Guest (S-1-5-21-1549655542-3693215259-3179495191-501 - Limited - Disabled)
Linda (S-1-5-21-1549655542-3693215259-3179495191-1000 - Administrator - Enabled) => C:\Users\Linda.Linda-PC
RA Media Server (S-1-5-21-1549655542-3693215259-3179495191-1001 - Administrator - Enabled) => C:\Users\RA Media Server
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
Acrobat.com (HKLM\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated)
Acrobat.com (Version: 0.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM\…\Adobe AIR) (Version: 1.0.4990 - Adobe Systems Inc.)
Adobe Flash Player 20 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 20.0.0.228 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated)
Adobe Reader X (10.1.4) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.4 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
ANT Drivers Installer x86 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (HKLM\…\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Banctec Service Agreement (HKLM\…\{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}) (Version: 2.0.0 - Dell Inc.)
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Canon Easy-WebPrint EX (HKLM\…\Easy-WebPrint EX) (Version: 1.6.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM\…\Canon_IJ_Network_Scanner_Selector_EX) (Version: 1.5.2.3 - Canon Inc.)
Canon IJ Network Tool (HKLM\…\Canon_IJ_Network_UTILITY) (Version: 3.5.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM\…\Canon_IJ_Scan_Utility) (Version: 1.1.10.15 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\…\CANONIJPLM100) (Version: 4.2.0 - Canon Inc.)
Canon MG6600 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6600_series) (Version: 1.01 - Canon Inc.)
Canon MG6600 series On-screen Manual (HKLM\…\Canon MG6600 series On-screen Manual) (Version: 7.7.0 - Canon Inc.)
Canon MG6600 series User Registration (HKLM\…\Canon MG6600 series User Registration) (Version:  - ‭Canon Inc.)
Canon My Printer (HKLM\…\CanonMyPrinter) (Version: 3.2.1 - Canon Inc.)
Canon Quick Menu (HKLM\…\CanonQuickMenu) (Version: 2.6.0 - Canon Inc.)
Choice Guard (Version: 1.2.87.0 - Microsoft Corporation) Hidden
Cisco EAP-FAST Module (HKLM\…\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\…\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\…\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.)
Cisco WebEx Meetings (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
CutePDF Writer 3.0 (HKLM\…\CutePDF Writer Installation) (Version:  3.0 - Acro Software Inc.)
Dell DataSafe Local Backup - Support Software (HKLM\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell)
Dell DataSafe Local Backup (HKLM\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell)
Dell DataSafe Online (HKLM\…\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.1.0027 - Dell, Inc.)
Dell Dock (HKLM\…\{F6CB42B9-F033-4152-8813-FF11DA8E6A78}) (Version: 1.0.0 - Dell)
Dell Edoc Viewer (HKLM\…\{3138EAD3-700B-4A10-B617-B3F8096EE30D}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell Remote Access (HKLM\…\{F66A31D9-7831-4FBA-BA02-C411C0047CC5}) (Version: 1.2.0.0 - Dell Inc.)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.1.6664.93 - Dell)
Dell System Detect (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\58d94f3ce2c27db0) (Version: 6.12.0.1 - Dell)
Dell Touchpad (HKLM\…\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.4.115.101 - Alps Electric)
Dell Video Chat (HKLM\…\Dell Video Chat) (Version: 6.0 (6567) - SightSpeed Inc.)
Dell Webcam Central (HKLM\…\Dell Webcam Central) (Version: 1.20.10 - Creative Technology Ltd)
Dell Wireless WLAN Card Utility (HKLM\…\Broadcom 802.11 Application) (Version: 5.10.38.30 - Dell Inc.)
DELL0703 (Version: 1.0.0 - WildTangent) Hidden
Dell-eBay (HKLM\…\{B935C985-A17F-484B-8470-09E4FC27DC26}) (Version: 1.00.0000 - Dell)
Dropbox (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\Dropbox) (Version: 3.12.5 - Dropbox, Inc.)
Elevated Installer (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden
Facebook Video Calling 1.2.0.159 (HKLM\…\{7CAC6A44-C3DE-4153-ACA6-7524602C789E}) (Version: 1.2.159 - Skype Limited)
Facebook Video Calling 1.2.0.287 (HKLM\…\{B92C5909-1D37-4C51-8397-A28BB28E5DC3}) (Version: 1.2.287 - Skype Limited)
Facebook Video Calling 3.1.0.521 (HKLM\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
FastStone Photo Resizer 3.1 (HKLM\…\FastStone Photo Resizer) (Version: 3.1 - FastStone Soft.)
FredV2Step1 (HKLM\…\{D6BCD6F1-85F1-43AD-A5A8-FC7C070546DD}) (Version: 1.00.0000 - USMLE)
Garmin Express (HKLM\…\{b292f4e5-60ca-4bb8-8810-e5f908c3c1ff}) (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries)
Garmin Express (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (Version: 4.1.10.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM\…\Google Chrome) (Version: 47.0.2526.106 - Google Inc.)
Google Earth Plug-in (HKLM\…\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.29.1 - Google Inc.) Hidden
GoToAssist 8.0.0.514 (HKLM\…\GoToAssist) (Version:  - )
HP Photosmart Essential (HKLM\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
HPDiagnosticAlert (Version: 1.00.0001 - Microsoft) Hidden
Integrated Webcam Driver (1.02.01.0320)   (HKLM\…\Creative OA009) (Version: 1.02.01.0320 - Creative Technology Ltd.)
Intel(R) TV Wizard (HKLM\…\TVWiz) (Version:  - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
iTunes (HKLM\…\{86D04316-F49A-4AF2-B3F1-A1E943886CE7}) (Version: 11.3.1.2 - Apple Inc.)
Java 7 Update 10 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83217010FF}) (Version: 7.0.100 - Oracle)
Java SE Development Kit 7 Update 10 (HKLM\…\{32A3A4F4-B792-11D6-A78A-00B0D0170100}) (Version: 1.7.0.100 - Oracle)
Java(TM) 6 Update 13 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83216013FF}) (Version: 6.0.130 - Sun Microsystems, Inc.)
Live! Cam Avatar Creator (HKLM\…\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.2303.1 - Creative Technology Ltd)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM\…\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}) (Version: 8.0.58299 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\…\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\…\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 en-US) (HKLM\…\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
MSXML 4.0 SP2 (KB927978) (HKLM\…\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
P@H-Protocol (HKLM\…\{CF594DB8-CFB0-45B4-86DA-8BB4AC0941F8}) (Version: 3.0.7.0 - Valassis)
PowerDVD DX (HKLM\…\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.2.5024 - Dell Corp.)
QuickSet (HKLM\…\{C4972073-2BFE-475D-8441-564EA97DA161}) (Version: 9.2.17 - Dell Inc.)
Recipe Hub (HKLM\…\RecipeHub_2jbar Uninstall) (Version:  - Recipe Hub)
Roxio Creator DE (HKLM\…\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}) (Version: 10.1 - Roxio)
Spelling Dictionaries Support For Adobe Reader 9 (HKLM\…\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
WildTangent Games (HKLM\…\WildTangent dell Master Uninstall) (Version: 1.0.0.71 - WildTangent)
Windows 7 Upgrade Advisor (HKLM\…\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\…\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\…\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{8B9F5BF4-0407-4BB2-9FED-4C0372DABD00}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\FacebookVideoCallingProxy.exe (Skype Limited)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{AD848A76-F236-5EE2-819B-2BDE7ED40AE7}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Catalina – Print Savings\npBcsKtTcHW.dll => No File
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll => No File
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
 
==================== Restore Points =========================
 
09-12-2015 20:09:29 Scheduled Checkpoint
10-12-2015 03:01:23 Windows Update
11-12-2015 12:20:31 Scheduled Checkpoint
12-12-2015 21:04:36 Removed Dell Remote Access.
16-12-2015 18:55:01 Windows Update
17-12-2015 02:14:57 Restore Operation
17-12-2015 05:57:33 Restore Operation
20-12-2015 20:20:58 Windows Update
20-12-2015 21:18:23 Device Driver Package Install: Microsoft Network Protocol
22-12-2015 04:14:44 JRT Pre-Junkware Removal
22-12-2015 22:44:08 Installed Windows 7 Upgrade Advisor
23-12-2015 01:04:39 Joel created
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 05:23 - 2015-12-23 16:15 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {115FD057-8508-48E2-8BBD-B2D54B118451} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {18DFD9FC-082E-4E9B-8285-5F21D2B4EDAE} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {4A8BB81E-2C81-44E1-8772-404BAC47FD75} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
Task: {4CC3FF0C-9DF8-4224-A48C-C562AF4FAFB4} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-23] (Facebook Inc.)
Task: {51970B63-7D0D-41C7-9B9A-DE5C003A9F81} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {58E907C7-28E5-406F-8C86-6B8700143F78} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {66455A42-6ED6-4D87-85FC-D45E7CD41C1C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-17] (Adobe Systems Incorporated)
Task: {73B62638-31CE-4D47-BE12-F3F6FF25CAC3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-23] (Facebook Inc.)
Task: {8BEB3FB3-770A-44E9-B5BB-08D949550BD3} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
Task: {8C7A437C-8E60-4057-87B5-94145B397931} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {A30D3A2F-94EE-4F38-90F2-731BEDC54BE8} - System32\Tasks\Launch BCM WLAN Tray => C:\Windows\system32\WLTRAY.EXE [2008-12-21] (Dell Inc.)
Task: {D6471568-77D7-4D88-9A0F-642ACDA9E593} - System32\Tasks\GarminUpdaterTask => C:\Program Files\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2015-10-29] ()
Task: {F6DE8019-61B4-4B0C-9CEB-13A8EEDAFE86} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-10-29] (PC-Doctor, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-04-19 18:55 - 2013-10-23 13:23 - 00089136 _____ () C:\Windows\System32\cpwmon2k.dll
2015-07-14 17:20 - 2015-07-14 17:20 - 00756376 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:5D432CE3
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\dell.com -> dell.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\boombox_1920x1200.jpg
DNS Servers: 8.8.4.4 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AeLookupSvc => 2
MSCONFIG\Services: AESTFilters => 2
MSCONFIG\Services: Apache2.2 => 2
MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: dsl-db => 2
MSCONFIG\Services: dsl-fs-sync => 2
MSCONFIG\Services: GameConsoleService => 3
MSCONFIG\Services: Garmin Device Interaction Service => 2
MSCONFIG\Services: GoToAssist => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: gusvc => 3
MSCONFIG\Services: hnmsvc => 2
MSCONFIG\Services: IJPLMSVC => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: MBAMScheduler => 2
MSCONFIG\Services: MBAMService => 2
MSCONFIG\Services: McComponentHostService => 3
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: SftService => 2
MSCONFIG\Services: STacSV => 2
MSCONFIG\Services: wltrysvc => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dell Remote Access.lnk => C:\Windows\pss\Dell Remote Access.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Linda.Linda-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk => C:\Windows\pss\Dell Dock.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Linda.Linda-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Apoint => C:\Program Files\DellTPad\Apoint.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Broadcom Wireless Manager UI => C:\Windows\system32\WLTRAY.exe
MSCONFIG\startupreg: CanonQuickMenu => C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE /logon
MSCONFIG\startupreg: Dell DataSafe Online => "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
MSCONFIG\startupreg: Dropbox Update => "C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
MSCONFIG\startupreg: Facebook Update => "C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IAAnotif => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: IJNetworkScannerSelectorEX => C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: PDVDDXSrv => "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: QuickSet => C:\Program Files\Dell\QuickSet\QuickSet.exe
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SysTrayApp => %ProgramFiles%\IDT\WDM\sttray.exe
MSCONFIG\startupreg: WMPNSCFG => C:\Program Files\Windows Media Player\WMPNSCFG.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{1DFE9015-E882-4897-BBEE-D82C6671B9C4}C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Allow) C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe
FirewallRules: [UDP Query User{3540076B-0AAD-4D68-A9DD-8984C1DD0D20}C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Allow) C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe
FirewallRules: [{14B95006-3757-4085-B850-8BE5C39C3B21}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6B110739-15C4-44D9-9940-05EB3E13C847}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{86A47EFE-4472-49A4-A4DC-605BE72DD6AB}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{BC411B3E-88FF-40FC-A5D6-BDD9FCCADCFD}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{35C6BC21-17E5-47FB-A608-458493E67E22}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{10A0F431-68FE-4999-952E-DDE2FBA82CE0}C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{7A5BC35F-7AD3-4AAC-A407-98F7651811B3}C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{1A81DCF4-4A0D-45D1-8936-8DCC4D4DBD58}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{A17AA28B-5FB4-416F-8D8E-B03C10810F25}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{59217529-98D9-40A8-808B-2590921D055E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{CEBAE611-8EB3-47DD-AA02-1D0C51D1A23B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{7336234A-BC3B-4FC7-BCB8-568AE98795D7}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{60C14774-7DCB-480A-9CDA-40631E3B1007}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{4A10995A-73B1-41DD-BE32-8723CE20E33A}C:\program files\usmle\fredv2step1\fredv2orient.exe] => (Allow) C:\program files\usmle\fredv2step1\fredv2orient.exe
FirewallRules: [UDP Query User{60C01436-2076-4D96-96A6-56FBDF8B0248}C:\program files\usmle\fredv2step1\fredv2orient.exe] => (Allow) C:\program files\usmle\fredv2step1\fredv2orient.exe
FirewallRules: [TCP Query User{911A7A12-326A-487E-B981-F78A74CC8E0E}C:\program files\usmle\fredv2step1\ned.exe] => (Allow) C:\program files\usmle\fredv2step1\ned.exe
FirewallRules: [UDP Query User{D6058E1F-3B59-4E86-9B4B-2CCAA5B0F123}C:\program files\usmle\fredv2step1\ned.exe] => (Allow) C:\program files\usmle\fredv2step1\ned.exe
FirewallRules: [{B2FD502B-BABF-4704-B2C7-6C2825F173DC}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{4C7E78BE-279D-4DE0-9078-47579FFBB44F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{07EEE22B-A46C-472A-861F-33DBA61BBD14}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (12/23/2015 05:24:55 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (12/23/2015 04:54:39 PM) (Source: Windows Search Service) (EventID: 1006) (User: )
Description: The Windows Search Service has failed to create the SystemIndex search index. Internal error <4, 0x8004117f, Failed to add project: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects>.
 
Error: (12/23/2015 04:54:39 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: The Windows Search Service cannot open the Jet property store.
 
Details:
The content index server cannot update or access information because of a database error.  Stop and restart the search service.  If the problem persists, reset and recrawl the content index.  In some cases it may be necessary to delete and recreate the content index.   (0x8004117f)
 
Error: (12/23/2015 04:54:39 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows (2364) Windows: Error -1032 (0xfffffbf8) occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
 
Error: (12/23/2015 04:54:39 PM) (Source: ESENT) (EventID: 489) (User: )
Description: Windows (2364) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" for read only access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (12/23/2015 04:54:29 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows (2364) Windows: Error -1032 (0xfffffbf8) occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
 
Error: (12/23/2015 04:54:29 PM) (Source: ESENT) (EventID: 489) (User: )
Description: Windows (2364) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" for read only access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (12/23/2015 04:46:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (12/23/2015 04:45:41 PM) (Source: Windows Search Service) (EventID: 1006) (User: )
Description: The Windows Search Service has failed to create the SystemIndex search index. Internal error <4, 0x8004117f, Failed to add project: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects>.
 
Error: (12/23/2015 04:45:41 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: The Windows Search Service cannot open the Jet property store.
 
Details:
The content index server cannot update or access information because of a database error.  Stop and restart the search service.  If the problem persists, reset and recrawl the content index.  In some cases it may be necessary to delete and recreate the content index.   (0x8004117f)
 
 
System errors:
=============
Error: (12/23/2015 04:54:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Windows Search4
 
Error: (12/23/2015 04:54:39 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Windows Search2147749155 (0x80040D23)
 
Error: (12/23/2015 04:46:03 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Windows Search3
 
Error: (12/23/2015 04:46:03 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Windows Search2147749155 (0x80040D23)
 
Error: (12/23/2015 04:46:03 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: 1Restart the serviceWindows Search%%1056
 
Error: (12/23/2015 04:46:03 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Windows Search2300001Restart the service
 
Error: (12/23/2015 04:46:03 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Windows Search2147749155 (0x80040D23)
 
Error: (12/23/2015 04:46:03 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Windows Search1300001Restart the service
 
Error: (12/23/2015 04:46:03 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Windows Search2147749155 (0x80040D23)
 
Error: (12/23/2015 04:46:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Intel(R) PRO/1000 NDIS 6 Adapter Driver%%1058
 
 
CodeIntegrity:
===================================
  Date: 2015-12-23 17:26:14.663
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-23 17:26:14.304
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-23 17:26:13.930
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-23 17:26:13.571
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-23 17:26:13.072
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-23 17:26:12.682
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-23 17:26:12.308
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-23 17:26:11.949
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-23 17:25:56.489
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-23 17:25:56.115
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
Percentage of memory in use: 36%
Total physical RAM: 3033.63 MB
Available physical RAM: 1918.16 MB
Total Virtual: 6293.55 MB
Available Virtual: 5347.7 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:218.2 GB) (Free:94.61 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive e: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:8.45 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: 00638CBF)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=218.2 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

There ok, Qoobox is just backups or what Combofix removed.  Looks like Combofix removed those ZeroAccess entries 

 

 

 

 
Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint: 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
Toolbar: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Ken:
This is the Fixlog
 
Fix result of Farbar Recovery Scan Tool (x86) Version:23-12-2015
Ran by [removed] (2015-12-23 21:10:16) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint: 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
Toolbar: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
"HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. 
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
EmptyTemp: => 2 GB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 21:17:59 ====

YES!!  The problem appears to be resolved.  It has not frozen since the last scan.

I'll post again and confirm tomorrow.

Thanks, Happy Holidays.

You can install any AV that you like and prefer, but the key is to install only one, Microsoft says that more than one AV is overkill and can cause performance problems, just install one, keep it updated and run regular scans

 

Merry Christmas to you and your family

ken:

 

Sorry to bother  you, but there was a freezing today will on chrome.

please take a look at these logs and see if there's something.

Thanks,

Joel

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:23-12-2015
Ran by [removed] (administrator) on LINDA-PC (25-12-2015 14:40:49)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\WINDOWS\System32\mfevtps.exe
(McAfee, Inc.) C:\WINDOWS\System32\mfevtps.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\WINDOWS\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(McAfee, Inc.) C:\Program Files\McAfee\MAT\McPvTray.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssist\imstrayicon.exe
(Microsoft Corporation) C:\WINDOWS\System32\msiexec.exe
(Microsoft Corporation) C:\WINDOWS\System32\mobsync.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\System32\cmd.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McChHost.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\saUI.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [562688 2015-02-11] (McAfee, Inc.)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2009-07-07] (Citrix Online, a division of Citrix Systems, Inc.)
HKU\S-1-5-18\…\Run: [GarminExpressTrayApp] => "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\RA Media Server\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-07-07]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
BootExecute: autocheck autochk /k:C * 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{C7F26639-2C1A-4FE2-AA45-8D9D300C51D8}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{E10DCCCB-A154-45DA-88BC-E56EC0A35C8A}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
SearchScopes: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> DefaultScope {12696EE3-C065-4036-A844-31F773CCB8D3} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=DLCDF7&pc;=MDDC&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000 -> {12696EE3-C065-4036-A844-31F773CCB8D3} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=DLCDF7&pc;=MDDC&src;=IE-SearchBox
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27] (Adobe Systems Incorporated)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-12-25] (Oracle Corporation)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-11-27] (McAfee, Inc.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-12-25] (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-11-27] (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-11-27] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-11-27] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll [2015-03-03] (McAfee, Inc.)
 
FireFox:
========
FF ProfilePath: C:\Users\Linda.Linda-PC\AppData\Roaming\Mozilla\Firefox\Profiles\e53ge7if.default
FF NewTab: about:blank
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google
FF SearchEngineOrder.3: Bing 
FF SelectedSearchEngine: Google
FF Homepage: www.google.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-17] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-12-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-12-25] (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-03-03] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-17] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-07-27] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1549655542-3693215259-3179495191-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-1549655542-3693215259-3179495191-1000: CouponNetwork.com/CMDUniversalCouponPrintActivator -> C:\Users\LINDA~1.LIN\AppData\Roaming\CATALI~1\NPBCSK~1.DLL [No File]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2013-08-02] (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Linda.Linda-PC\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-12-15] (Cisco WebEx LLC)
FF Extension: McAfee WebAdvisor - C:\Program Files\McAfee\SiteAdvisor\saffplg.xpi [2015-11-23]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-02-02] [not signed]
FF HKLM\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2015-12-24] [not signed]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.ebay.com/
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type;=B211US0D19700101&p;={searchTerms}
CHR DefaultSearchKeyword: Default -> mcafee
CHR Profile: C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-15]
CHR Extension: (Google Docs) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-15]
CHR Extension: (Google Drive) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-15]
CHR Extension: (YouTube) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-15]
CHR Extension: (Google Search) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-15]
CHR Extension: (Google Sheets) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-15]
CHR Extension: (SiteAdvisor) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-12-24]
CHR Extension: (Google Docs Offline) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-15]
CHR Extension: (Gmail) - C:\Users\Linda.Linda-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-15]
CHR HKLM\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx [2015-11-27]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S4 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [81920 2009-03-31] (Andrea Electronics Corporation)
S4 Apache2.2; C:\Program Files\Common Files\Dell\apache\bin\httpd.exe [15872 2007-09-21] (Apache Software Foundation) [File not signed]
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-12-18] (Stardock Corporation) [File not signed]
S4 dsl-db; C:\Program Files\Common Files\Dell\MySQL\bin\mysqld.exe [5730304 2007-09-14] () [File not signed]
S4 dsl-fs-sync; C:\Program Files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe [189680 2009-04-13] (SingleClick Systems)
S4 GameConsoleService; C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe [242424 2008-11-03] (WildTangent, Inc.)
S4 GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [16680 2009-07-07] (Citrix Online, a division of Citrix Systems, Inc.)
S4 hnmsvc; c:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe [828656 2009-04-13] (Dell Inc.)
R2 HomeNetSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
S4 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S4 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 McAfee SiteAdvisor Service; c:\Program Files\McAfee\SiteAdvisor\McSACore.exe [132160 2015-12-02] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [690408 2015-03-03] (McAfee, Inc.)
S4 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.226\McCHSvc.exe [235696 2015-10-30] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [476680 2015-02-27] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [196600 2015-02-17] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [334576 2015-02-24] (McAfee, Inc.)
R3 mfevtp; C:\Windows\system32\mfevtps.exe [238288 2015-02-17] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [291816 2015-02-11] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S4 SftService; C:\Program Files\Dell DataSafe Local Backup\sftservice.EXE [1692480 2011-08-18] (SoftThinks SAS)
S4 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe [254042 2009-03-31] (IDT, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
S4 wltrysvc; C:\Windows\System32\bcmwltry.exe [2809856 2008-12-21] (Dell Inc.) [File not signed]
R2 yksvc; RUNDLL32.EXE ykx32coinst,serviceStartProc [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2008-12-21] (Broadcom Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [61848 2015-02-17] (McAfee, Inc.)
S3 DellBIOS; C:\Windows\DellBIOS.Sys [7168 2015-12-20] () [File not signed]
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [147912 2013-09-23] (McAfee, Inc.)
S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [35776 2013-09-23] (hxxp://libusb-win32.sourceforge.net)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [170200 2015-12-23] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation)
R2 McPvDrv; C:\Windows\system32\drivers\McPvDrv.sys [67800 2015-02-28] (McAfee, Inc.)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [304928 2015-02-17] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [260248 2015-02-17] (McAfee, Inc.)
R0 mfedisk; C:\Windows\System32\DRIVERS\mfedisk.sys [82800 2015-02-17] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [371648 2015-02-17] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [648552 2015-02-17] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [380496 2015-01-16] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [80760 2015-01-16] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [217584 2015-02-17] (McAfee, Inc.)
R3 OA009Ufd; C:\Windows\System32\DRIVERS\OA009Ufd.sys [133632 2009-03-06] (Creative Technology Ltd.)
R3 OA009Vid; C:\Windows\System32\DRIVERS\OA009Vid.sys [271552 2009-03-19] (Creative Technology Ltd.)
R2 Packet; C:\Windows\System32\DRIVERS\packet.sys [22016 2008-06-17] (SingleClick Systems)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)
S3 catchme; \??\C:\Users\LINDA~1.LIN\AppData\Local\Temp\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 PCD5SRVC{3F6A8B78-EC003E00-05040104}; \??\C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-25 14:40 - 2015-12-25 14:42 - 00020904 _____ C:\Users\Linda.Linda-PC\Desktop\FRST.txt
2015-12-25 13:30 - 2015-11-10 12:03 - 01208832 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2015-12-25 13:30 - 2015-11-10 12:03 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2015-12-25 13:30 - 2015-11-06 12:05 - 00627712 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-12-25 13:30 - 2015-11-06 11:32 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-12-25 13:30 - 2015-11-06 11:32 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-12-25 13:30 - 2015-11-06 11:32 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-12-25 13:30 - 2015-11-06 11:32 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-12-25 13:30 - 2015-11-06 10:27 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-12-25 13:30 - 2015-11-06 10:26 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-12-25 13:30 - 2015-11-06 10:24 - 02068480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-12-25 13:30 - 2015-11-06 10:20 - 01073152 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-12-25 13:30 - 2015-11-06 10:20 - 00682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-12-25 13:30 - 2015-11-06 10:19 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-12-25 13:30 - 2015-11-05 02:34 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2015-12-25 13:30 - 2015-11-02 12:04 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
2015-12-25 13:20 - 2015-12-25 13:20 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Sun
2015-12-25 13:20 - 2015-12-25 13:20 - 00000000 ____D C:\Users\Linda.Linda-PC\.oracle_jre_usage
2015-12-25 13:20 - 2015-12-25 13:20 - 00000000 ____D C:\Program Files\Common Files\Java
2015-12-25 13:18 - 2015-12-25 13:18 - 00000000 ____D C:\ProgramData\Oracle
2015-12-25 13:18 - 2015-12-25 13:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-12-24 08:18 - 2015-12-24 08:18 - 00000066 _____ C:\Users\Linda.Linda-PC\Desktop\What the Tech - Your Place for Tech Questions.url
2015-12-24 07:42 - 2015-12-24 07:42 - 00001753 _____ C:\Users\Public\Desktop\McAfee Total Protection.lnk
2015-12-24 07:41 - 2015-12-25 14:04 - 00000000 __RSD C:\Users\Linda.Linda-PC\Documents\McAfee Vaults
2015-12-24 07:41 - 2015-12-24 07:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-12-24 07:41 - 2015-02-28 01:10 - 00067800 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\McPvDrv.sys
2015-12-24 07:41 - 2013-09-23 13:48 - 00147912 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
2015-12-24 07:34 - 2015-02-17 14:50 - 00238288 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe
2015-12-24 07:33 - 2015-12-24 07:33 - 07708304 _____ (McAfee, Inc.) C:\Users\Linda.Linda-PC\Downloads\Setup_serial_tWz7VCcO2H2KH5ViRm5Q4g2_key.exe
2015-12-23 23:47 - 2015-12-23 23:47 - 00000000 ____D C:\Users\Linda.Linda-PC\Documents\Dell WebCam Central
2015-12-23 23:47 - 2015-12-23 23:47 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Creative
2015-12-23 23:47 - 2015-12-23 23:47 - 00000000 ____D C:\ProgramData\Creative
2015-12-23 23:35 - 2015-12-23 23:35 - 00016638 _____ C:\Users\Linda.Linda-PC\Downloads\Discount Mountain Software.pdf
2015-12-23 21:10 - 2015-12-23 21:17 - 00001684 _____ C:\Users\Linda.Linda-PC\Desktop\Fixlog.txt
2015-12-23 16:17 - 2015-12-23 16:17 - 00018543 _____ C:\ComboFix.txt
2015-12-23 16:02 - 2011-06-26 01:45 - 00256000 _____ C:\Windows\PEV.exe
2015-12-23 16:02 - 2010-11-07 12:20 - 00208896 _____ C:\Windows\MBR.exe
2015-12-23 16:02 - 2009-04-19 23:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-12-23 16:02 - 2000-08-30 19:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-12-23 16:02 - 2000-08-30 19:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-12-23 16:02 - 2000-08-30 19:00 - 00098816 _____ C:\Windows\sed.exe
2015-12-23 16:02 - 2000-08-30 19:00 - 00080412 _____ C:\Windows\grep.exe
2015-12-23 16:02 - 2000-08-30 19:00 - 00068096 _____ C:\Windows\zip.exe
2015-12-23 16:01 - 2015-12-23 16:16 - 00000000 ____D C:\Windows\erdnt
2015-12-23 08:32 - 2015-12-23 08:32 - 01721856 _____ (Farbar) C:\Users\Linda.Linda-PC\Desktop\FRST.exe
2015-12-22 22:45 - 2015-12-22 22:45 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Microsoft Corporation
2015-12-22 22:44 - 2015-12-22 22:44 - 00001998 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows 7 Upgrade Advisor.lnk
2015-12-22 22:44 - 2015-12-22 22:44 - 00001986 _____ C:\Users\Public\Desktop\Windows 7 Upgrade Advisor.lnk
2015-12-22 22:44 - 2015-12-22 22:44 - 00000000 ____D C:\Program Files\Microsoft Windows 7 Upgrade Advisor
2015-12-22 22:39 - 2015-12-22 22:39 - 08669472 _____ (Microsoft Corporation) C:\Users\Linda.Linda-PC\Downloads\Windows7UpgradeAdvisorSetup.exe
2015-12-22 20:23 - 2015-12-22 20:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-22 05:45 - 2015-12-23 21:07 - 00000000 ____D C:\Users\Linda.Linda-PC\Desktop\virus cleaners
2015-12-22 04:25 - 2015-12-23 00:33 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-12-22 04:24 - 2015-12-22 20:23 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-12-22 04:24 - 2015-10-05 09:50 - 00094936 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-12-22 04:24 - 2015-10-05 09:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-12-22 04:24 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-12-22 04:17 - 2015-12-22 04:17 - 00002238 _____ C:\Users\Linda.Linda-PC\Desktop\JRT.txt
2015-12-21 02:31 - 2015-12-21 02:31 - 274668427 _____ C:\Windows\MEMORY.DMP
2015-12-21 02:31 - 2015-12-21 02:31 - 00143728 _____ C:\Windows\Minidump\Mini122115-01.dmp
2015-12-21 00:49 - 2015-12-25 14:40 - 00000000 ____D C:\FRST
2015-12-20 23:45 - 2015-12-23 16:41 - 00000000 ____D C:\Users\Linda.Linda-PC\Documents\troubleshooting
2015-12-20 23:06 - 2015-12-20 23:06 - 00000512 _____ C:\Users\Linda.Linda-PC\Documents\MBR.dat
2015-12-20 22:06 - 2015-12-20 22:06 - 01162486 _____ C:\Users\Linda.Linda-PC\Downloads\1545_A14 (1).EXE
2015-12-20 22:05 - 2015-12-20 22:05 - 01162486 _____ C:\Users\Linda.Linda-PC\Downloads\1545_A14.EXE
2015-12-20 22:05 - 2015-12-20 22:05 - 00007168 _____ C:\Windows\DellBIOS.Sys
2015-12-20 21:53 - 2015-12-20 21:54 - 49934552 _____ (Microsoft Corporation) C:\Users\Linda.Linda-PC\Downloads\Windows-KB890830-V5.31.exe
2015-12-20 21:18 - 2015-12-20 21:18 - 00000000 ____D C:\Users\Linda.Linda-PC\{b1967a33-da0b-4955-a208-b043aa2fbe2e}
2015-12-20 21:18 - 2015-10-28 00:20 - 00031992 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\pcdrndisprot.sys
2015-12-20 21:09 - 2015-12-20 21:09 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\LocalLow\PCDr
2015-12-20 21:09 - 2015-12-20 21:09 - 00000000 ____D C:\ProgramData\PC-Doctor for Windows
2015-12-20 21:01 - 2015-12-21 16:37 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\PCDr
2015-12-20 21:00 - 2015-12-24 08:14 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Apps\2.0
2015-12-20 21:00 - 2015-12-20 21:00 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
2015-12-20 21:00 - 2015-12-20 21:00 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Deployment
2015-12-20 20:59 - 2015-12-20 20:59 - 00417064 _____ () C:\Users\Linda.Linda-PC\Downloads\DellSystemDetectLauncher.exe
2015-12-20 20:20 - 2015-12-20 20:20 - 00247183 _____ C:\Users\Linda.Linda-PC\Documents\bookmarks_12_20_15.html
2015-12-17 08:48 - 2015-12-17 08:48 - 00000000 ____D C:\Windows\pss
2015-12-17 08:42 - 2015-12-17 08:43 - 07708304 _____ (McAfee, Inc.) C:\Users\Linda.Linda-PC\Downloads\Setup_serial_oeXOdgfIjbW_srLLuxULNQ2_key.exe
2015-12-17 08:42 - 2015-12-17 08:42 - 00001973 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-17 08:42 - 2015-12-17 08:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-17 06:19 - 2015-12-17 06:19 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-12-16 21:14 - 2015-12-16 21:14 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\McAfee File Lock
2015-12-16 21:12 - 2015-12-16 21:12 - 00000000 ____D C:\Program Files\McAfee.com
2015-12-16 21:01 - 2015-12-16 22:50 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\LogMeIn Rescue Applet
2015-12-16 20:55 - 2015-12-24 07:41 - 00000000 ____D C:\Program Files\Common Files\McAfee
2015-12-16 20:55 - 2015-12-16 20:57 - 00000000 ____D C:\Program Files\stinger
2015-12-16 19:18 - 2015-12-16 19:18 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox(88)
2015-12-15 22:47 - 2015-12-15 22:47 - 00000046 _____ C:\Users\Linda.Linda-PC\Desktop\eBay.url
2015-12-15 22:40 - 2015-12-15 22:40 - 00000000 ____D C:\ProgramData\BSD
2015-12-15 21:53 - 2015-12-15 21:53 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\McAfee
2015-12-15 21:52 - 2015-12-25 14:01 - 00000000 ____D C:\Program Files\McAfee
2015-12-13 01:15 - 2015-12-13 01:15 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox(84)
2015-12-07 13:46 - 2015-12-07 13:46 - 01958689 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(28)
2015-12-07 13:16 - 2015-12-07 13:16 - 00999116 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(27)
2015-12-04 16:36 - 2015-12-04 16:36 - 02956605 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(26)
2015-12-03 00:14 - 2015-12-03 00:14 - 00999469 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(25)
2015-12-02 16:39 - 2015-12-02 16:39 - 01959030 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(24)
2015-12-02 16:19 - 2015-12-02 16:19 - 00999491 _____ C:\Users\Linda.Linda-PC\Downloads\LabelDownloadServlet(23)
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-25 14:37 - 2015-04-30 18:14 - 00000000 ____D C:\ProgramData\Garmin
2015-12-25 14:35 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\inf
2015-12-25 14:13 - 2015-06-20 15:37 - 00000936 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job
2015-12-25 14:13 - 2012-08-22 14:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-25 14:05 - 2012-08-23 22:00 - 00000946 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job
2015-12-25 14:03 - 2012-02-27 19:19 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-25 14:01 - 2012-02-27 19:19 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-25 14:01 - 2006-11-02 07:45 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-25 14:01 - 2006-11-02 07:45 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-25 14:00 - 2006-11-02 07:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-25 14:00 - 2006-11-02 07:44 - 00258992 _____ C:\Windows\system32\FNTCACHE.DAT
2015-12-25 13:25 - 2006-11-02 07:35 - 00000000 ____D C:\Windows\system32\XPSViewer
2015-12-25 13:22 - 2012-08-21 15:24 - 00000860 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-12-25 13:22 - 2012-08-21 15:24 - 00000848 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-12-25 13:22 - 2012-08-21 15:24 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-12-25 13:21 - 2015-11-06 21:40 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-12-25 13:20 - 2012-01-31 22:40 - 00000000 ____D C:\Users\Linda.Linda-PC
2015-12-25 13:18 - 2013-01-11 00:19 - 00097888 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-12-25 13:18 - 2009-07-07 09:15 - 00000000 ____D C:\Program Files\Java
2015-12-25 12:13 - 2015-06-20 15:37 - 00000884 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job
2015-12-25 09:29 - 2012-08-23 22:00 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job
2015-12-24 13:02 - 2009-07-07 09:48 - 00000000 ____D C:\ProgramData\McAfee
2015-12-24 08:12 - 2006-11-02 07:58 - 00032588 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-12-23 23:47 - 2009-07-07 09:35 - 00000000 ____D C:\ProgramData\Dell
2015-12-23 23:47 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Common Files\Dell
2015-12-23 23:31 - 2012-02-02 21:43 - 00002627 _____ C:\Users\Linda.Linda-PC\Desktop\Microsoft Office Word 2007.lnk
2015-12-23 21:11 - 2015-06-30 22:03 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\LocalLow\Temp
2015-12-23 16:41 - 2012-01-31 22:56 - 00000000 ____D C:\Qoobox
2015-12-23 16:17 - 2006-11-02 06:18 - 00000000 ____D C:\WINDOWS
2015-12-23 16:15 - 2006-11-02 05:23 - 00000215 _____ C:\Windows\system.ini
2015-12-23 01:08 - 2012-02-01 08:50 - 00000000 ____D C:\Program Files\Google
2015-12-23 00:57 - 2012-02-27 19:18 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Local\Google
2015-12-23 00:57 - 2012-02-27 19:18 - 00000000 ____D C:\ProgramData\Google
2015-12-23 00:53 - 2012-05-27 15:03 - 00001945 _____ C:\Windows\epplauncher.mif
2015-12-23 00:31 - 2009-07-07 09:52 - 00000000 ____D C:\ProgramData\TEMP
2015-12-23 00:31 - 2009-07-07 09:43 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2015-12-23 00:31 - 2009-07-07 09:43 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2015-12-23 00:31 - 2009-07-07 09:34 - 00000000 ____D C:\Program Files\Dell DataSafe Local Backup
2015-12-22 04:24 - 2012-01-31 22:56 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-12-21 20:39 - 2006-11-02 05:33 - 00759542 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-21 02:31 - 2014-03-01 20:13 - 00000000 ____D C:\Windows\Minidump
2015-12-21 02:12 - 2006-11-02 06:18 - 00000000 ___SD C:\Windows\Downloaded Program Files
2015-12-20 22:25 - 2009-09-24 19:45 - 00913204 _____ C:\Windows\ntbtlog.txt
2015-12-20 21:18 - 2013-10-19 13:26 - 00000000 ____D C:\Temp
2015-12-20 21:09 - 2012-01-31 22:40 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Dell
2015-12-20 21:09 - 2009-07-07 09:36 - 00000000 ____D C:\ProgramData\PCDr
2015-12-20 21:09 - 2009-07-07 09:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2015-12-20 21:08 - 2009-07-07 09:36 - 00000000 ____D C:\Program Files\Dell Support Center
2015-12-20 21:06 - 2009-07-07 09:16 - 00000000 ____D C:\Program Files\Dell
2015-12-20 21:04 - 2009-07-07 11:37 - 00000000 ____D C:\DELL
2015-12-17 20:13 - 2012-08-22 14:35 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-12-17 20:13 - 2012-02-27 19:18 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-12-17 08:33 - 2014-09-07 10:29 - 00000000 ___RD C:\Users\Linda.Linda-PC\Dropbox
2015-12-17 08:33 - 2014-09-07 10:25 - 00000000 ____D C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox
2015-12-17 06:09 - 2009-07-07 09:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Remote Access
2015-12-17 06:09 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\Msdtc
2015-12-17 06:08 - 2012-02-02 07:05 - 00000000 ____D C:\Users\RA Media Server
2015-12-17 06:08 - 2006-11-02 05:22 - 46137344 _____ C:\Windows\system32\config\software_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 43778048 _____ C:\Windows\system32\config\components_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 15466496 _____ C:\Windows\system32\config\system_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2015-12-17 06:08 - 2006-11-02 05:22 - 00262144 _____ C:\Windows\system32\config\default_previous
2015-12-17 06:07 - 2012-08-22 14:35 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2015-12-17 06:07 - 2012-02-28 21:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-12-17 06:07 - 2012-01-31 23:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-12-17 06:07 - 2009-07-07 09:40 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-12-17 06:07 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Dell Remote Access
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 __RSD C:\Windows\Media
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\system32\spool
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\rescache
2015-12-17 06:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-12-17 06:06 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\registration
2015-12-16 19:11 - 2013-07-15 02:01 - 00000000 ____D C:\Windows\system32\MRT
2015-12-15 21:41 - 2015-10-18 21:33 - 00000000 ____D C:\Program Files\McAfee Security Scan
2015-12-15 21:03 - 2009-07-07 09:35 - 00000000 ____D C:\Program Files\Common Files\Dell(2)
2015-12-15 19:48 - 2012-02-03 06:04 - 00006080 _____ C:\Users\Linda.Linda-PC\AppData\Local\d3d9caps.dat
2015-12-10 03:45 - 2015-08-29 13:47 - 00000000 ____D C:\ProgramData\CanonIJPLM
2015-12-08 22:39 - 2012-05-27 15:14 - 00247976 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
 
==================== Files in the root of some directories =======
 
2013-11-04 13:41 - 2013-11-04 13:41 - 0893239 _____ () C:\Users\Linda.Linda-PC\AppData\Local\a.zip
2013-11-04 13:41 - 2013-11-04 13:41 - 2162416 _____ (Catalina Marketing Corp) C:\Users\Linda.Linda-PC\AppData\Local\BcsKtYcHW.dll
2012-02-03 06:04 - 2015-12-15 19:48 - 0006080 _____ () C:\Users\Linda.Linda-PC\AppData\Local\d3d9caps.dat
2012-01-31 22:48 - 2015-11-07 15:34 - 0018944 _____ () C:\Users\Linda.Linda-PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-29 18:33 - 2015-08-29 15:00 - 0007084 _____ () C:\ProgramData\hpzinstall.log
 
Some files in TEMP:
====================
C:\Users\Linda.Linda-PC\AppData\Local\Temp\jre-8u66-windows-au.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-12-25 14:05
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version:23-12-2015
Ran by [removed] (2015-12-25 14:43:10)
Running from C:\Users\[removed]\Desktop
Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) (2009-07-07 09:02:45)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1549655542-3693215259-3179495191-500 - Administrator - Disabled)
Guest (S-1-5-21-1549655542-3693215259-3179495191-501 - Limited - Disabled)
Linda (S-1-5-21-1549655542-3693215259-3179495191-1000 - Administrator - Enabled) => C:\Users\Linda.Linda-PC
RA Media Server (S-1-5-21-1549655542-3693215259-3179495191-1001 - Administrator - Enabled) => C:\Users\RA Media Server
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
Acrobat.com (HKLM\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated)
Acrobat.com (Version: 0.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM\…\Adobe AIR) (Version: 1.0.4990 - Adobe Systems Inc.)
Adobe Flash Player 20 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 20.0.0.228 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated)
Adobe Reader X (10.1.4) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.4 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
Apple Application Support (HKLM\…\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Banctec Service Agreement (HKLM\…\{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}) (Version: 2.0.0 - Dell Inc.)
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Canon Easy-WebPrint EX (HKLM\…\Easy-WebPrint EX) (Version: 1.6.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM\…\Canon_IJ_Network_Scanner_Selector_EX) (Version: 1.5.2.3 - Canon Inc.)
Canon IJ Network Tool (HKLM\…\Canon_IJ_Network_UTILITY) (Version: 3.5.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM\…\Canon_IJ_Scan_Utility) (Version: 1.1.10.15 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\…\CANONIJPLM100) (Version: 4.2.0 - Canon Inc.)
Canon MG6600 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6600_series) (Version: 1.01 - Canon Inc.)
Canon MG6600 series On-screen Manual (HKLM\…\Canon MG6600 series On-screen Manual) (Version: 7.7.0 - Canon Inc.)
Canon MG6600 series User Registration (HKLM\…\Canon MG6600 series User Registration) (Version:  - ‭Canon Inc.)
Canon My Printer (HKLM\…\CanonMyPrinter) (Version: 3.2.1 - Canon Inc.)
Canon Quick Menu (HKLM\…\CanonQuickMenu) (Version: 2.6.0 - Canon Inc.)
Choice Guard (Version: 1.2.87.0 - Microsoft Corporation) Hidden
Cisco EAP-FAST Module (HKLM\…\{415B2719-AD3A-4944-B404-C472DB6085B3}) (Version: 2.1.6 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\…\{83770D14-21B9-44B3-8689-F7B523F94560}) (Version: 1.0.12 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\…\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}) (Version: 1.0.13 - Cisco Systems, Inc.)
Cisco WebEx Meetings (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
CutePDF Writer 3.0 (HKLM\…\CutePDF Writer Installation) (Version:  3.0 - Acro Software Inc.)
Dell DataSafe Local Backup - Support Software (HKLM\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell)
Dell DataSafe Local Backup (HKLM\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell)
Dell DataSafe Online (HKLM\…\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.1.0027 - Dell, Inc.)
Dell Dock (HKLM\…\{F6CB42B9-F033-4152-8813-FF11DA8E6A78}) (Version: 1.0.0 - Dell)
Dell Edoc Viewer (HKLM\…\{3138EAD3-700B-4A10-B617-B3F8096EE30D}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell Remote Access (HKLM\…\{F66A31D9-7831-4FBA-BA02-C411C0047CC5}) (Version: 1.2.0.0 - Dell Inc.)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.1.6664.93 - Dell)
Dell System Detect (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\58d94f3ce2c27db0) (Version: 6.12.0.1 - Dell)
Dell Touchpad (HKLM\…\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.4.115.101 - Alps Electric)
Dell Video Chat (HKLM\…\Dell Video Chat) (Version: 6.0 (6567) - SightSpeed Inc.)
Dell Webcam Central (HKLM\…\Dell Webcam Central) (Version: 1.20.10 - Creative Technology Ltd)
Dell Wireless WLAN Card Utility (HKLM\…\Broadcom 802.11 Application) (Version: 5.10.38.30 - Dell Inc.)
DELL0703 (Version: 1.0.0 - WildTangent) Hidden
Dell-eBay (HKLM\…\{B935C985-A17F-484B-8470-09E4FC27DC26}) (Version: 1.00.0000 - Dell)
Dropbox (HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\Dropbox) (Version: 3.12.5 - Dropbox, Inc.)
Facebook Video Calling 1.2.0.159 (HKLM\…\{7CAC6A44-C3DE-4153-ACA6-7524602C789E}) (Version: 1.2.159 - Skype Limited)
Facebook Video Calling 1.2.0.287 (HKLM\…\{B92C5909-1D37-4C51-8397-A28BB28E5DC3}) (Version: 1.2.287 - Skype Limited)
Facebook Video Calling 3.1.0.521 (HKLM\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
FastStone Photo Resizer 3.1 (HKLM\…\FastStone Photo Resizer) (Version: 3.1 - FastStone Soft.)
FredV2Step1 (HKLM\…\{D6BCD6F1-85F1-43AD-A5A8-FC7C070546DD}) (Version: 1.00.0000 - USMLE)
Google Chrome (HKLM\…\Google Chrome) (Version: 47.0.2526.106 - Google Inc.)
Google Earth Plug-in (HKLM\…\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.29.1 - Google Inc.) Hidden
GoToAssist 8.0.0.514 (HKLM\…\GoToAssist) (Version:  - )
HP Photosmart Essential (HKLM\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
HPDiagnosticAlert (Version: 1.00.0001 - Microsoft) Hidden
Integrated Webcam Driver (1.02.01.0320)   (HKLM\…\Creative OA009) (Version: 1.02.01.0320 - Creative Technology Ltd.)
Intel(R) TV Wizard (HKLM\…\TVWiz) (Version:  - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
iTunes (HKLM\…\{86D04316-F49A-4AF2-B3F1-A1E943886CE7}) (Version: 11.3.1.2 - Apple Inc.)
Java 7 Update 10 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83217010FF}) (Version: 7.0.100 - Oracle)
Java 8 Update 65 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Java SE Development Kit 7 Update 10 (HKLM\…\{32A3A4F4-B792-11D6-A78A-00B0D0170100}) (Version: 1.7.0.100 - Oracle)
Java(TM) 6 Update 13 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83216013FF}) (Version: 6.0.130 - Sun Microsystems, Inc.)
Live! Cam Avatar Creator (HKLM\…\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.2303.1 - Creative Technology Ltd)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
McAfee SiteAdvisor (HKLM\…\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.7.284 - McAfee, Inc.)
McAfee Total Protection (HKLM\…\MSC) (Version: 14.0.339 - McAfee, Inc.)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM\…\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}) (Version: 8.0.58299 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\…\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\…\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 43.0.1 (x86 en-US) (HKLM\…\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 43.0.1 - Mozilla)
MSXML 4.0 SP2 (KB927978) (HKLM\…\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
P@H-Protocol (HKLM\…\{CF594DB8-CFB0-45B4-86DA-8BB4AC0941F8}) (Version: 3.0.7.0 - Valassis)
PowerDVD DX (HKLM\…\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.2.5024 - Dell Corp.)
QuickSet (HKLM\…\{C4972073-2BFE-475D-8441-564EA97DA161}) (Version: 9.2.17 - Dell Inc.)
Recipe Hub (HKLM\…\RecipeHub_2jbar Uninstall) (Version:  - Recipe Hub)
Roxio Creator DE (HKLM\…\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}) (Version: 10.1 - Roxio)
Spelling Dictionaries Support For Adobe Reader 9 (HKLM\…\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
WildTangent Games (HKLM\…\WildTangent dell Master Uninstall) (Version: 1.0.0.71 - WildTangent)
Windows 7 Upgrade Advisor (HKLM\…\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{8B9F5BF4-0407-4BB2-9FED-4C0372DABD00}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\FacebookVideoCallingProxy.exe (Skype Limited)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{AD848A76-F236-5EE2-819B-2BDE7ED40AE7}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Catalina – Print Savings\npBcsKtTcHW.dll => No File
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll => No File
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\DropboxExt.28.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.)
 
==================== Restore Points =========================
 
22-12-2015 04:14:44 JRT Pre-Junkware Removal
22-12-2015 22:44:08 Installed Windows 7 Upgrade Advisor
23-12-2015 01:04:39 Joel created
23-12-2015 21:10:20 Restore Point Created by FRST
24-12-2015 11:18:59 Scheduled Checkpoint
25-12-2015 12:07:28 Scheduled Checkpoint
25-12-2015 13:12:15 McAfee Vulnerability Scanner
25-12-2015 13:22:53 Windows Update
25-12-2015 14:34:33 Garmin Express
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 05:23 - 2015-12-23 21:10 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {115FD057-8508-48E2-8BBD-B2D54B118451} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {18DFD9FC-082E-4E9B-8285-5F21D2B4EDAE} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {4A8BB81E-2C81-44E1-8772-404BAC47FD75} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
Task: {4CC3FF0C-9DF8-4224-A48C-C562AF4FAFB4} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-23] (Facebook Inc.)
Task: {51970B63-7D0D-41C7-9B9A-DE5C003A9F81} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {58E907C7-28E5-406F-8C86-6B8700143F78} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {66455A42-6ED6-4D87-85FC-D45E7CD41C1C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-17] (Adobe Systems Incorporated)
Task: {73B62638-31CE-4D47-BE12-F3F6FF25CAC3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-23] (Facebook Inc.)
Task: {8BEB3FB3-770A-44E9-B5BB-08D949550BD3} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
Task: {8C7A437C-8E60-4057-87B5-94145B397931} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {A30D3A2F-94EE-4F38-90F2-731BEDC54BE8} - System32\Tasks\Launch BCM WLAN Tray => C:\Windows\system32\WLTRAY.EXE [2008-12-21] (Dell Inc.)
Task: {F6DE8019-61B4-4B0C-9CEB-13A8EEDAFE86} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-10-29] (PC-Doctor, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job => C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000Core.job => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1549655542-3693215259-3179495191-1000UA.job => C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-04-19 18:55 - 2013-10-23 13:23 - 00089136 _____ () C:\Windows\System32\cpwmon2k.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:5D432CE3
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\…\dell.com -> dell.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1549655542-3693215259-3179495191-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\boombox_1920x1200.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is disabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AeLookupSvc => 2
MSCONFIG\Services: AESTFilters => 2
MSCONFIG\Services: Apache2.2 => 2
MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: dsl-db => 2
MSCONFIG\Services: dsl-fs-sync => 2
MSCONFIG\Services: GameConsoleService => 3
MSCONFIG\Services: Garmin Device Interaction Service => 2
MSCONFIG\Services: GoToAssist => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: gusvc => 3
MSCONFIG\Services: hnmsvc => 2
MSCONFIG\Services: IJPLMSVC => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: MBAMScheduler => 2
MSCONFIG\Services: MBAMService => 2
MSCONFIG\Services: McComponentHostService => 3
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: SftService => 2
MSCONFIG\Services: STacSV => 2
MSCONFIG\Services: wltrysvc => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dell Remote Access.lnk => C:\Windows\pss\Dell Remote Access.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Linda.Linda-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk => C:\Windows\pss\Dell Dock.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Linda.Linda-PC^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Apoint => C:\Program Files\DellTPad\Apoint.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Broadcom Wireless Manager UI => C:\Windows\system32\WLTRAY.exe
MSCONFIG\startupreg: CanonQuickMenu => C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE /logon
MSCONFIG\startupreg: Dell DataSafe Online => "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
MSCONFIG\startupreg: Dropbox Update => "C:\Users\Linda.Linda-PC\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
MSCONFIG\startupreg: Facebook Update => "C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IAAnotif => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: IJNetworkScannerSelectorEX => C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: PDVDDXSrv => "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: QuickSet => C:\Program Files\Dell\QuickSet\QuickSet.exe
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SysTrayApp => %ProgramFiles%\IDT\WDM\sttray.exe
MSCONFIG\startupreg: WMPNSCFG => C:\Program Files\Windows Media Player\WMPNSCFG.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{1DFE9015-E882-4897-BBEE-D82C6671B9C4}C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Allow) C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe
FirewallRules: [UDP Query User{3540076B-0AAD-4D68-A9DD-8984C1DD0D20}C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Allow) C:\users\linda.linda-pc\appdata\local\facebook\video\skype\facebookvideocalling.exe
FirewallRules: [{14B95006-3757-4085-B850-8BE5C39C3B21}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6B110739-15C4-44D9-9940-05EB3E13C847}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{86A47EFE-4472-49A4-A4DC-605BE72DD6AB}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{BC411B3E-88FF-40FC-A5D6-BDD9FCCADCFD}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{35C6BC21-17E5-47FB-A608-458493E67E22}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{10A0F431-68FE-4999-952E-DDE2FBA82CE0}C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{7A5BC35F-7AD3-4AAC-A407-98F7651811B3}C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\linda.linda-pc\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{1A81DCF4-4A0D-45D1-8936-8DCC4D4DBD58}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{A17AA28B-5FB4-416F-8D8E-B03C10810F25}] => (Allow) C:\Users\Linda.Linda-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{59217529-98D9-40A8-808B-2590921D055E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{CEBAE611-8EB3-47DD-AA02-1D0C51D1A23B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{7336234A-BC3B-4FC7-BCB8-568AE98795D7}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{60C14774-7DCB-480A-9CDA-40631E3B1007}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{4A10995A-73B1-41DD-BE32-8723CE20E33A}C:\program files\usmle\fredv2step1\fredv2orient.exe] => (Allow) C:\program files\usmle\fredv2step1\fredv2orient.exe
FirewallRules: [UDP Query User{60C01436-2076-4D96-96A6-56FBDF8B0248}C:\program files\usmle\fredv2step1\fredv2orient.exe] => (Allow) C:\program files\usmle\fredv2step1\fredv2orient.exe
FirewallRules: [TCP Query User{911A7A12-326A-487E-B981-F78A74CC8E0E}C:\program files\usmle\fredv2step1\ned.exe] => (Allow) C:\program files\usmle\fredv2step1\ned.exe
FirewallRules: [UDP Query User{D6058E1F-3B59-4E86-9B4B-2CCAA5B0F123}C:\program files\usmle\fredv2step1\ned.exe] => (Allow) C:\program files\usmle\fredv2step1\ned.exe
FirewallRules: [{B2FD502B-BABF-4704-B2C7-6C2825F173DC}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{4C7E78BE-279D-4DE0-9078-47579FFBB44F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{07EEE22B-A46C-472A-861F-33DBA61BBD14}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{C667389D-1D76-426E-BD53-2B2B0AE7D651}] => (Allow) C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe
 
==================== Faulty Device Manager Devices =============
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (12/25/2015 02:39:33 PM) (Source: Windows Search Service) (EventID: 1006) (User: )
Description: The Windows Search Service has failed to create the SystemIndex search index. Internal error <4, 0x8004117f, Failed to add project: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects>.
 
Error: (12/25/2015 02:39:31 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: The Windows Search Service cannot open the Jet property store.
 
Details:
The content index server cannot update or access information because of a database error.  Stop and restart the search service.  If the problem persists, reset and recrawl the content index.  In some cases it may be necessary to delete and recreate the content index.   (0x8004117f)
 
Error: (12/25/2015 02:39:31 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows (5924) Windows: Error -1032 (0xfffffbf8) occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
 
Error: (12/25/2015 02:39:31 PM) (Source: ESENT) (EventID: 489) (User: )
Description: Windows (5924) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" for read only access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (12/25/2015 02:39:21 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows (5924) Windows: Error -1032 (0xfffffbf8) occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.
 
Error: (12/25/2015 02:39:21 PM) (Source: ESENT) (EventID: 489) (User: )
Description: Windows (5924) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" for read only access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (12/25/2015 02:26:08 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: EmdCacheC:\Windows\system32\emdmgmt.dll4
 
Error: (12/25/2015 02:26:05 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\system32\bitsperf.dll4
 
Error: (12/25/2015 02:03:23 PM) (Source: Windows Search Service) (EventID: 1006) (User: )
Description: The Windows Search Service has failed to create the SystemIndex search index. Internal error <4, 0x8004117f, Failed to add project: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects>.
 
Error: (12/25/2015 02:03:23 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: The Windows Search Service cannot open the Jet property store.
 
Details:
The content index server cannot update or access information because of a database error.  Stop and restart the search service.  If the problem persists, reset and recrawl the content index.  In some cases it may be necessary to delete and recreate the content index.   (0x8004117f)
 
 
System errors:
=============
Error: (12/25/2015 02:39:33 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Windows Search4
 
Error: (12/25/2015 02:39:33 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Windows Search2147749155 (0x80040D23)
 
Error: (12/25/2015 02:04:31 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {209500FC-6B45-4693-8871-6296C4843751}
 
Error: (12/25/2015 02:03:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Windows Search3
 
Error: (12/25/2015 02:03:23 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Windows Search2147749155 (0x80040D23)
 
Error: (12/25/2015 02:02:31 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Windows Search2300001Restart the service
 
Error: (12/25/2015 02:02:31 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Windows Search2147749155 (0x80040D23)
 
Error: (12/25/2015 02:01:58 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: 1Restart the serviceWindows Search%%1056
 
Error: (12/25/2015 02:01:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Windows Search1300001Restart the service
 
Error: (12/25/2015 02:01:17 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Windows Search2147749155 (0x80040D23)
 
 
CodeIntegrity:
===================================
  Date: 2015-12-25 14:42:25.830
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-25 14:42:25.418
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-25 14:42:24.982
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-25 14:42:24.541
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-25 14:42:23.874
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-25 14:42:23.438
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-25 14:42:23.010
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-25 14:42:22.576
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-25 14:41:26.200
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-25 14:41:24.939
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
Percentage of memory in use: 55%
Total physical RAM: 3033.63 MB
Available physical RAM: 1364.11 MB
Total Virtual: 6269.55 MB
Available Virtual: 4688 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:218.2 GB) (Free:96.45 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: () (Removable) (Total:1.86 GB) (Free:1.77 GB) FAT
Drive e: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:8.45 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: 00638CBF)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=218.2 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (Size: 1.9 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

 

Logs look ok, try this

 

  • Click the Chrome menu [external image: Clipboard01_zps2e55f676.jpg]on the browser toolbar.
  • Select Settings.
  • Scroll down to Show advanced settings…
  • Down on the bottom you will see an option for RESET BROWSER SETTINGS
  • Click on it and it will set Chome back to defaults
  • Yes, they are!

    Would like to upgrade the speed of the wireless card.

    Any ideas on what to do or if another forum post is needed?

     

    Happy New Year,

     

    Joel

    Glad things are better for you, as far as the wireless card, post here in our Networking forum, there more in tune with issues like that

     

    http://forums.whatthetech.com/index.php?showforum=128

     

     

    Double click on AdwCleaner.exe to run the tool again.
    • Click on the Uninstall button.
    • Click Yes when asked are you sure you want to uninstall.
    • Both AdwCleaner.exe, its folder and all logs will be removed.
    •  
       
      ==========================================================
       
       
      Please download DelFix and save the file to your Desktop.
       
      [external image: DelFix_zps139e2ea1.jpg]
       
      • Windows XP Double Click DelFix.exe to run the program. 
      • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
      • Checkmark " Remove Disinfection Tools"
      • Click the Run button
      •  
        This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
         
         
         
         
        So How did I get infected in the first place <– Some reading for you to keep yourself safe online
         
         
        Safe Surfn
        Ken

        Ask AI

        AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

        Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI