Hey,
My friend has dropped off his laptop to me to have it fixed but I have hit a dead end. Basically, I am unable to open many applications such as Office and other .exe files. I get an error saying that "application" has stopped working. When I click view details, I get an error APPCRASH.
Also, there are a few google redirects which I am unable to completely fix but I cannot run MBAM or ADW Cleaner or other cleaning tools. I am unable to update Google Chrome. The only browser working on this computer is Internet Explorer with no add-ons.
I got an error while running aswMBR. As soon as I started the scan, it said scan error and it didn't seem like it was going further. I stopped it once and started it again but to no avail. I am going to show you the logs as it is.
I am posting the logs. Please help.
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-02-21 07:30:57
—————————–
07:30:57.766 OS Version: Windows 6.1.7601 Service Pack 1
07:30:57.766 Number of processors: 4 586 0x2505
07:30:57.766 ComputerName: TOSHIBA-PC UserName: toshiba
07:30:58.468 Initialze error C000010E - driver not loaded
07:33:18.994 AVAST engine defs: 16022002
07:33:23.081 Scan error: Incorrect function.
07:33:32.691 Scan stopped
07:33:36.170 Scan error: Incorrect function.
07:37:31.434 The log file has been saved successfully to "C:\Users\toshiba\Desktop\aswMBR.txt"
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:20-02-2016
Ran by [removed] (administrator) on TOSHIBA-PC (21-02-2016 07:38:30)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE.EXE
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Windows\System32\runouce.exe
() C:\Windows\System32\runouce.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_20_0_0_306_ActiveX.exe
(AVAST Software) C:\Users\toshiba\Desktop\aswMBR.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [98172 2010-01-22] (Microsoft Corporation)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [11753028 2013-02-19] (Realtek Semiconductor)
HKLM\…\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [102708 2013-05-30] (Hewlett-Packard)
HKLM\…\Run: [] => [X]
HKLM\…\Run: [Runonce] => C:\Windows\system32\runouce.exe [10748 2016-02-19] ()
HKLM\…\Disallowed\Certificates: 181E2AE5727DE60F52EF26D90BC6919481601793 (Avast Antivirus) <==== ATTENTION
HKLM\…\Disallowed\Certificates: 2FA3FB2570A7A859026C59A1C723E7EF9F9AF13D (Trend Micro) <==== ATTENTION
HKLM\…\Disallowed\Certificates: 4B953F30F1DE4DFEF894B136DAA155CEAFC243A0 (Baidu Online Network Technology) <==== ATTENTION
HKLM\…\Disallowed\Certificates: 65AFAA515036C38C9EC28248C453FB0F6B1E7094 (ESET) <==== ATTENTION
HKLM\…\Disallowed\Certificates: 8138B44330354E413DC52AF1DBFCA8BA1C0F6C0A (ThreatTrack Security) <==== ATTENTION
HKLM\…\Disallowed\Certificates: 82F19360B15655A94E875A5B5F7844E2932FC2A6 (Bitdefender SRL) <==== ATTENTION
HKLM\…\Disallowed\Certificates: 883224FAB9D5BC431563A00AF10A79AA78087584 (Panda Security S.L) <==== ATTENTION
HKLM\…\Disallowed\Certificates: 89B89723B7106A1926036B1469D2497B85841849 (Lavasoft Limited) <==== ATTENTION
HKLM\…\Disallowed\Certificates: AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947 (AVG Technologies CZ) <==== ATTENTION
HKLM\…\Disallowed\Certificates: B1E5407220D2E41A2045A5B183AE83F54E3C9643 (Avira Operations GmbH & Co. KG) <==== ATTENTION
HKLM\…\Disallowed\Certificates: BD22822F42C0B3F61AA0F30360EFB2A15068893B (ESS Distribution) <==== ATTENTION
HKLM\…\Disallowed\Certificates: D37F61D57CB0481F3D77EDAC7DE72196C4314E2C (McAfee) <==== ATTENTION
HKU\S-1-5-21-750069077-2733385025-3247444180-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6285076 2015-04-23] (Piriform Ltd)
HKU\S-1-5-21-750069077-2733385025-3247444180-1000\…\RunOnce: [Application Restart #0] => C:\Program Files\Google\Chrome\Application\chrome.exe –extensions-on-chrome-urls –test-type –load-extension="c:\Program Files\Google\Chrome\Application\Extensions\chrome\app\37.1329.9.18" –flag-s (the data entry has 105 more characters).
HKLM\…\AppCertDlls: [windows_service_for_control_application_23139093481232] -> C:\Users\toshiba\AppData\Local\Wixer\advapi.dll
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2016-01-15] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2016-01-15] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2016-01-15] (Google)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{15D61722-8660-4C3D-B412-E8C5A8BF2E6C}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2013-06-08] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AdobeARMservice; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [88780 2015-12-13] (Adobe Systems Incorporated) [File not signed]
S2 gupdate; C:\Program Files\Google\Update\GoogleUpdate.exe [150852 2016-01-04] (Google Inc.) [File not signed]
S3 gupdatem; C:\Program Files\Google\Update\GoogleUpdate.exe [150852 2016-01-04] (Google Inc.) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1086772 2015-04-14] (Malwarebytes Corporation) [File not signed]
S3 Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [30970228 2010-01-22] (Microsoft Corporation) [File not signed]
S3 ose; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [156004 2010-01-10] (Microsoft Corporation) [File not signed]
S3 osppsvc; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [4646652 2010-01-10] (Microsoft Corporation) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [142408 2013-01-18] (Realtek Semiconductor)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 bpusb; C:\Windows\System32\Drivers\bpusb.sys [71168 2012-07-03] (Intel Corporation)
R0 iaStorA; C:\Windows\System32\DRIVERS\iaStorA.sys [527344 2013-02-04] (Intel Corporation)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [26096 2013-02-04] (Intel Corporation)
R0 iusb3hcs; C:\Windows\System32\DRIVERS\iusb3hcs.sys [16440 2012-12-04] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2016-02-19] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R3 NETwNs32; C:\Windows\System32\DRIVERS\Netwsn00.sys [10378992 2013-02-27] (Intel Corporation)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
U3 aswMBR; \??\C:\Users\toshiba\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\toshiba\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-21 07:38 - 2016-02-21 07:38 - 00009065 _____ C:\Users\toshiba\Desktop\FRST.txt
2016-02-21 07:37 - 2016-02-21 07:38 - 00000000 ____D C:\FRST
2016-02-21 07:37 - 2016-02-21 07:37 - 00000633 _____ C:\Users\toshiba\Desktop\aswMBR.txt
2016-02-21 07:29 - 2016-02-21 07:29 - 01722368 _____ (Farbar) C:\Users\toshiba\Desktop\FRST.exe
2016-02-21 07:28 - 2016-02-21 07:28 - 05198336 _____ (AVAST Software) C:\Users\toshiba\Desktop\aswMBR.exe
2016-02-21 07:24 - 2016-02-21 07:25 - 00193456 _____ C:\TDSSKiller.3.1.0.9_21.02.2016_07.24.58_log.txt
2016-02-20 20:33 - 2016-02-20 20:33 - 00986624 _____ C:\Users\toshiba\Downloads\MicrosoftFixit50850_msi.exe
2016-02-20 16:59 - 2016-02-20 16:59 - 01511424 _____ C:\Users\toshiba\Downloads\AdwCleaner_exe
2016-02-19 04:59 - 2016-02-19 04:59 - 00004592 _____ C:\Users\toshiba\Desktop\JRT.txt
2016-02-19 04:52 - 2016-02-19 04:53 - 00000000 ____D C:\Program Files\GUMAD6E.tmp
2016-02-19 04:52 - 2016-02-19 04:52 - 00994380 _____ (Google Inc.) C:\Users\toshiba\Downloads\ChromeSetup.exe
2016-02-19 04:47 - 2016-02-19 04:48 - 00000000 ____D C:\Program Files\GUM14A8.tmp
2016-02-19 04:45 - 2016-02-21 07:20 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-02-19 04:40 - 2016-02-19 04:40 - 01518076 _____ C:\Users\toshiba\Downloads\AdwCleaner.exe
2016-02-19 04:30 - 2016-02-19 04:31 - 00193454 _____ C:\TDSSKiller.3.1.0.9_19.02.2016_04.30.04_log.txt
2016-02-19 04:22 - 2016-02-19 04:37 - 00000000 ____D C:\Users\toshiba\AppData\Local\VS Revo Group
2016-02-19 04:22 - 2016-02-19 04:22 - 00001230 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2016-02-19 04:22 - 2016-02-19 04:22 - 00000000 ____D C:\ProgramData\VS Revo Group
2016-02-19 04:22 - 2016-02-19 04:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2016-02-19 04:22 - 2016-02-19 04:22 - 00000000 ____D C:\Program Files\VS Revo Group
2016-02-19 04:22 - 2009-12-30 10:21 - 00027192 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2016-02-19 04:05 - 2016-02-19 04:06 - 00010748 __RSH C:\Windows\system32\runouce.exe
2016-02-19 03:57 - 2016-02-19 03:58 - 00014888 _____ C:\Users\Public\Desktop\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:58 - 00014888 _____ C:\Users\Default\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:58 - 00014888 _____ C:\Users\Default\Downloads\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:58 - 00014888 _____ C:\Users\Default\Documents\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:58 - 00014888 _____ C:\Users\Default\Desktop\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:58 - 00014888 _____ C:\Users\Default User\Downloads\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:58 - 00014888 _____ C:\Users\Default User\Documents\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:58 - 00014888 _____ C:\Users\Default User\Desktop\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:58 - 00014888 _____ C:\ProgramData\Microsoft\Windows\Start Menu\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:57 - 00014888 _____ C:\Users\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:57 - 00014888 _____ C:\Users\toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:57 - 00014888 _____ C:\Users\Default\AppData\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:57 - 00014888 _____ C:\Users\Default\AppData\Roaming\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:57 - 00014888 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:57 - 00014888 _____ C:\Users\Default\AppData\Local\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:57 - 00014888 _____ C:\Users\Default User\AppData\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:57 - 00014888 _____ C:\Users\Default User\AppData\Roaming\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:57 - 00014888 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:57 - 00014888 _____ C:\Users\Default User\AppData\Local\TOSHIBA-PC.eml
2016-02-19 03:57 - 2016-02-19 03:57 - 00014888 _____ C:\ProgramData\TOSHIBA-PC.eml
2016-02-19 03:54 - 2016-02-19 04:04 - 00001054 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-02-19 03:50 - 2016-02-19 03:50 - 00019952 _____ C:\Users\toshiba\Documents\cc_20160219_035042.reg
2016-02-16 02:49 - 2016-02-19 03:57 - 00000000 ____D C:\Users\toshiba\AppData\Local\ElevatedDiagnostics
2016-02-15 00:48 - 2016-02-15 00:48 - 00116359 _____ C:\Users\toshiba\Downloads\Bill print Email A5.pdf
2016-02-10 22:21 - 2016-01-16 22:36 - 01413632 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-02-10 22:20 - 2016-01-23 00:10 - 00341200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-02-10 22:20 - 2016-01-22 10:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-02-10 22:20 - 2016-01-22 10:02 - 00496640 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-02-10 22:20 - 2016-01-22 10:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-02-10 22:20 - 2016-01-22 10:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-02-10 22:20 - 2016-01-22 10:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-02-10 22:20 - 2016-01-22 10:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-02-10 22:20 - 2016-01-22 09:55 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-02-10 22:20 - 2016-01-22 09:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-02-10 22:20 - 2016-01-22 09:52 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-02-10 22:20 - 2016-01-22 09:51 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-02-10 22:20 - 2016-01-22 09:51 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-02-10 22:20 - 2016-01-22 09:51 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-02-10 22:20 - 2016-01-22 09:46 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-02-10 22:20 - 2016-01-22 09:43 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-02-10 22:20 - 2016-01-22 09:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-02-10 22:20 - 2016-01-22 09:38 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-02-10 22:20 - 2016-01-22 09:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-02-10 22:20 - 2016-01-22 09:35 - 04611072 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-02-10 22:20 - 2016-01-22 09:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-02-10 22:20 - 2016-01-22 09:34 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-02-10 22:20 - 2016-01-22 09:33 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-02-10 22:20 - 2016-01-22 09:27 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-02-10 22:20 - 2016-01-22 09:25 - 00687104 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-02-10 22:20 - 2016-01-22 09:25 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-02-10 22:20 - 2016-01-22 09:24 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-02-10 22:20 - 2016-01-22 09:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-02-10 22:20 - 2016-01-22 09:07 - 02120704 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-02-10 22:20 - 2016-01-22 09:02 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-02-10 22:18 - 2016-01-22 10:13 - 03993536 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2016-02-10 22:18 - 2016-01-22 10:13 - 03938752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-02-10 22:18 - 2016-01-22 10:13 - 00138176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-02-10 22:18 - 2016-01-22 10:13 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-02-10 22:18 - 2016-01-22 10:09 - 01310232 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-02-10 22:18 - 2016-01-22 10:06 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-02-10 22:18 - 2016-01-22 10:06 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-02-10 22:18 - 2016-01-22 10:06 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-02-10 22:18 - 2016-01-22 10:06 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-02-10 22:18 - 2016-01-22 10:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-02-10 22:18 - 2016-01-22 10:06 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-02-10 22:18 - 2016-01-22 10:05 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-02-10 22:18 - 2016-01-22 10:05 - 00251392 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-02-10 22:18 - 2016-01-22 10:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-02-10 22:18 - 2016-01-22 10:04 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2016-02-10 22:18 - 2016-01-22 10:04 - 00535040 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2016-02-10 22:18 - 2016-01-22 10:02 - 01060864 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-02-10 22:18 - 2016-01-22 10:02 - 00872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-02-10 22:18 - 2016-01-22 10:02 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-02-10 22:18 - 2016-01-22 10:02 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-02-10 22:18 - 2016-01-22 10:02 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-02-10 22:18 - 2016-01-22 10:02 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-02-10 22:18 - 2016-01-22 10:02 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\msorcl32.dll
2016-02-10 22:18 - 2016-01-22 10:02 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-02-10 22:18 - 2016-01-22 10:02 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-02-10 22:18 - 2016-01-22 10:02 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00642560 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 09:07 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-02-10 22:18 - 2016-01-22 09:01 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-02-10 22:18 - 2016-01-22 09:00 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-02-10 22:18 - 2016-01-22 08:53 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-02-10 22:18 - 2016-01-22 08:53 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-02-10 22:18 - 2016-01-22 08:53 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-02-10 22:18 - 2016-01-22 08:51 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-02-10 22:18 - 2016-01-22 08:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-02-10 22:18 - 2016-01-22 08:51 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-02-10 22:18 - 2016-01-22 08:51 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-02-10 22:18 - 2016-01-22 08:51 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 08:51 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 08:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-02-10 22:18 - 2016-01-22 08:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-02-10 22:18 - 2016-01-07 21:47 - 02386944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-02-10 22:18 - 2016-01-07 21:35 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-02-10 22:18 - 2016-01-06 22:41 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2016-02-10 22:18 - 2016-01-06 21:56 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2016-02-10 22:17 - 2016-02-06 14:01 - 20366848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-02-10 22:17 - 2016-02-06 13:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-02-10 22:17 - 2016-02-06 13:43 - 02280448 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-02-10 22:17 - 2016-02-06 13:38 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-02-10 22:17 - 2016-02-06 13:16 - 12857856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-02-10 22:17 - 2016-02-06 12:54 - 01312256 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-01-30 13:50 - 2016-02-19 03:57 - 00000000 ____D C:\Users\toshiba\AppData\Local\CEF
2016-01-30 13:47 - 2016-01-30 13:47 - 00509813 _____ C:\Users\toshiba\Downloads\anilppmndv1.pdf
2016-01-30 01:13 - 2016-01-30 01:13 - 02953158 _____ C:\Users\toshiba\Downloads\YOUR WINNING DETAILS.bmp
2016-01-26 15:50 - 2016-01-30 01:11 - 00000000 ____D C:\Windows\Minidump
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-21 07:29 - 2014-12-09 00:39 - 00014888 _____ C:\Users\toshiba\Downloads\TOSHIBA-PC.eml
2016-02-21 07:29 - 2014-12-09 00:39 - 00014888 _____ C:\Users\Public\Downloads\TOSHIBA-PC.eml
2016-02-21 07:28 - 2014-12-09 00:39 - 00014888 _____ C:\Users\toshiba\TOSHIBA-PC.eml
2016-02-21 07:28 - 2014-12-09 00:39 - 00014888 _____ C:\Users\toshiba\Documents\TOSHIBA-PC.eml
2016-02-21 07:28 - 2014-12-09 00:39 - 00014888 _____ C:\Users\toshiba\Desktop\TOSHIBA-PC.eml
2016-02-21 07:28 - 2014-12-09 00:39 - 00014888 _____ C:\Users\toshiba\AppData\TOSHIBA-PC.eml
2016-02-21 07:28 - 2014-12-09 00:39 - 00014888 _____ C:\Users\toshiba\AppData\Roaming\TOSHIBA-PC.eml
2016-02-21 07:28 - 2014-12-09 00:39 - 00014888 _____ C:\Users\toshiba\AppData\LocalLow\TOSHIBA-PC.eml
2016-02-21 07:28 - 2014-12-09 00:39 - 00014888 _____ C:\Users\toshiba\AppData\Local\TOSHIBA-PC.eml
2016-02-21 07:28 - 2014-12-09 00:39 - 00014888 _____ C:\Users\Public\TOSHIBA-PC.eml
2016-02-21 07:28 - 2014-12-09 00:39 - 00014888 _____ C:\Users\Public\Documents\TOSHIBA-PC.eml
2016-02-21 07:26 - 2009-07-14 08:34 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-21 07:26 - 2009-07-14 08:34 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-21 07:20 - 2016-01-04 03:18 - 00000888 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-20 20:54 - 2016-01-04 03:18 - 00000884 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-20 20:39 - 2009-07-14 08:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-19 05:53 - 2009-07-14 06:37 - 00000000 ____D C:\Windows\rescache
2016-02-19 04:45 - 2014-11-12 18:26 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-02-19 04:45 - 2014-11-12 18:26 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-02-19 04:41 - 2015-05-03 01:33 - 00000000 ____D C:\AdwCleaner
2016-02-19 04:15 - 2014-11-12 18:26 - 00000000 ____D C:\Users\toshiba\AppData\Local\Google
2016-02-19 04:15 - 2014-11-12 18:26 - 00000000 ____D C:\Program Files\Google
2016-02-19 04:07 - 2015-05-03 03:02 - 00000000 ____D C:\Windows\system32\MRT
2016-02-19 04:05 - 2015-07-30 02:32 - 00000000 ____D C:\Users\toshiba\AppData\Local\Wixer
2016-02-19 04:05 - 2009-07-14 08:53 - 00032618 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-02-19 04:05 - 2009-07-14 08:34 - 00000000 ____D C:\Windows\ServiceProfiles
2016-02-19 04:04 - 2016-01-04 02:45 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-02-19 04:04 - 2016-01-04 02:45 - 00002011 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2016-02-19 04:04 - 2015-11-17 01:44 - 00002164 _____ C:\Users\Public\Desktop\HP Deskjet 1510 series.lnk
2016-02-19 04:04 - 2015-11-17 01:44 - 00001153 _____ C:\Users\Public\Desktop\Shop for Supplies - HP Deskjet 1510 series.lnk
2016-02-19 04:04 - 2014-12-08 22:58 - 00001943 _____ C:\Users\Public\Desktop\HP Photo Creations.lnk
2016-02-19 04:04 - 2014-11-12 18:27 - 00001018 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-02-19 04:04 - 2014-11-12 18:27 - 00001014 _____ C:\Users\Public\Desktop\Google Drive.lnk
2016-02-19 04:04 - 2014-11-12 18:26 - 00002146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-19 04:04 - 2014-11-12 18:26 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
2016-02-19 04:04 - 2014-11-12 18:26 - 00001114 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
2016-02-19 04:04 - 2014-11-12 18:02 - 00001389 _____ C:\Users\toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-02-19 04:04 - 2014-11-12 17:57 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-02-19 04:04 - 2014-11-12 17:57 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-02-19 04:04 - 2009-07-14 08:46 - 00001479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-02-19 04:04 - 2009-07-14 08:46 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-02-19 04:04 - 2009-07-14 08:42 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-02-19 04:04 - 2009-07-14 08:42 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-02-19 04:04 - 2009-07-14 08:42 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-02-19 04:04 - 2009-07-14 08:37 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-02-19 03:57 - 2016-01-06 17:00 - 00000000 ____D C:\Users\toshiba\AppData\Local\Ofi Labs
2016-02-19 03:57 - 2016-01-06 16:55 - 00000000 ____D C:\Users\toshiba\AppData\Roaming\Twr
2016-02-19 03:57 - 2015-07-30 02:32 - 00000000 ____D C:\ProgramData\npp
2016-02-19 03:57 - 2015-05-06 22:38 - 00000000 ____D C:\ProgramData\Package Cache
2016-02-19 03:57 - 2015-05-03 11:10 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-02-19 03:57 - 2014-12-08 22:58 - 00000000 ____D C:\ProgramData\Visan
2016-02-19 03:57 - 2014-12-08 22:58 - 00000000 ____D C:\ProgramData\HP Photo Creations
2016-02-19 03:57 - 2014-12-08 22:57 - 00000000 ____D C:\ProgramData\HP
2016-02-19 03:57 - 2014-11-15 15:48 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2016-02-19 03:57 - 2014-11-15 15:48 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2016-02-19 03:57 - 2014-11-12 18:28 - 00000000 ____D C:\ProgramData\MFAData
2016-02-19 03:57 - 2014-11-12 18:27 - 00000000 ____D C:\ProgramData\Skype
2016-02-19 03:57 - 2014-11-12 18:27 - 00000000 ____D C:\ProgramData\Adobe
2016-02-19 03:57 - 2014-11-12 18:25 - 00000000 ____D C:\ProgramData\Mozilla
2016-02-19 03:57 - 2011-04-12 06:24 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2016-02-19 03:57 - 2011-04-12 06:24 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs
2016-02-19 03:54 - 2015-05-03 11:10 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-02-19 03:54 - 2015-05-03 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-02-19 03:54 - 2015-05-03 11:10 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-02-19 03:54 - 2014-11-12 18:20 - 00000000 ____D C:\Program Files\WinRAR
2016-02-17 22:54 - 2015-09-08 22:54 - 00000000 ____D C:\Users\toshiba\AppData\Roaming\npp
2016-02-17 22:54 - 2015-07-30 02:30 - 00594428 _____ (Igor Pavlov) C:\Users\toshiba\AppData\Local\7za.exe
2016-02-17 22:54 - 2015-04-28 11:00 - 00004540 __RSH C:\ProgramData\ntuser.pol
2016-02-17 22:00 - 2009-07-14 06:37 - 00000000 ____D C:\Windows\inf
2016-02-16 02:50 - 2009-07-14 06:37 - 00000000 ____D C:\Windows\system32\NDF
2016-02-16 02:47 - 2015-05-03 03:02 - 144254680 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-02-11 16:06 - 2010-11-21 01:01 - 00713888 _____ C:\Windows\system32\PerfStringBackup.INI
2016-02-11 16:01 - 2009-07-14 08:33 - 00407360 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-11 15:59 - 2011-04-12 06:24 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-10 17:31 - 2014-11-12 18:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-01-30 13:50 - 2014-11-13 20:55 - 00000000 ____D C:\Users\toshiba\AppData\Local\Adobe
2016-01-30 13:48 - 2015-05-24 05:43 - 00000000 ____D C:\Users\toshiba\Documents\Outlook Files
2016-01-30 01:11 - 2014-11-12 17:53 - 00000000 ____D C:\Windows\Panther
==================== Files in the root of some directories =======
2015-09-08 22:54 - 2015-09-08 22:54 - 0000066 _____ () C:\Users\toshiba\AppData\Roaming\sn.txt
2014-12-09 00:39 - 2016-02-21 07:28 - 0014888 _____ () C:\Users\toshiba\AppData\Roaming\TOSHIBA-PC.eml
2014-12-09 00:39 - 2016-02-21 07:28 - 0014888 _____ () C:\Users\toshiba\AppData\Roaming\Microsoft\TOSHIBA-PC.eml
2015-07-30 02:30 - 2016-02-17 22:54 - 0594428 _____ (Igor Pavlov) C:\Users\toshiba\AppData\Local\7za.exe
2015-07-30 02:31 - 2015-07-30 02:32 - 3531374 _____ () C:\Users\toshiba\AppData\Local\curl.zip
2015-09-08 22:54 - 2015-09-08 22:54 - 0000188 _____ () C:\Users\toshiba\AppData\Local\j3HaNIn.vbs
2015-05-03 11:25 - 2015-05-03 11:27 - 0000698 _____ () C:\Users\toshiba\AppData\Local\Temp-log.txt
2014-12-09 00:39 - 2016-02-21 07:28 - 0014888 _____ () C:\Users\toshiba\AppData\Local\TOSHIBA-PC.eml
2014-12-08 22:56 - 2014-12-08 22:56 - 0000057 _____ () C:\ProgramData\Ament.ini
2016-02-19 03:57 - 2016-02-19 03:57 - 0014888 _____ () C:\ProgramData\TOSHIBA-PC.eml
Some files in TEMP:
====================
C:\Users\toshiba\AppData\Local\Temp\sqlite3.dll
C:\Users\toshiba\AppData\Local\Temp\Xwu.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-02-19 05:46
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version:20-02-2016
Ran by [removed] (2016-02-21 07:38:58)
Running from C:\Users\[removed]\Desktop
Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2014-11-12 14:01:34)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-750069077-2733385025-3247444180-500 - Administrator - Disabled)
Guest (S-1-5-21-750069077-2733385025-3247444180-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-750069077-2733385025-3247444180-1002 - Limited - Enabled)
toshiba (S-1-5-21-750069077-2733385025-3247444180-1000 - Administrator - Enabled) => C:\Users\toshiba
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (HKLM\…\7-Zip) (Version: - )
Adobe Acrobat Reader DC (HKLM\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.010.20056 - Adobe Systems Incorporated)
Adobe Flash Player 20 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 20.0.0.306 - Adobe Systems Incorporated)
CCleaner (HKLM\…\CCleaner) (Version: 5.05 - Piriform)
Google Chrome (HKLM\…\{38764777-9FDB-35BC-A8DB-FA324E5EAC4A}) (Version: 48.0.2564.109 - Google, Inc.)
Google Drive (HKLM\…\{EF61675D-9BBC-4EC7-B906-F13BE8D3BD20}) (Version: 1.27.1227.2094 - Google, Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.29.5 - Google Inc.) Hidden
HP Deskjet 1510 series Basic Device Software (HKLM\…\{61268BF7-3EC8-4CDC-922B-C8F718A0D46F}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Deskjet 1510 series Help (HKLM\…\{2E25FCEB-EFCB-4696-AA01-D3CBAC721831}) (Version: 30.0.0 - Hewlett Packard)
HP Photo Creations (HKLM\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Kodi (HKU\S-1-5-21-750069077-2733385025-3247444180-1000\…\Kodi) (Version: - XBMC-Foundation)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft Office Professional Plus 2010 (HKLM\…\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\…\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Product Improvement Study for HP Deskjet 1510 series (HKLM\…\{0D3AAA98-358E-44FE-98FA-F27146FF52CA}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6844 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.5 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.5 - VS Revo Group, Ltd.)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 16.2.12.3 - Synaptics Incorporated)
TeamViewer 8 (HKLM\…\TeamViewer 8) (Version: 8.0.19617 - TeamViewer)
VLC media player 2.0.7 (HKLM\…\VLC media player) (Version: 2.0.7 - VideoLAN)
WinRAR 4.20 (32-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {08C36A85-EEED-4B81-8B41-3E828A40928C} - \Newsfeed -> No File <==== ATTENTION
Task: {25374AF8-C7DD-460B-B875-7285D7B2B2E8} - System32\Tasks\iBackup => C:\Users\toshiba\AppData\Local\RemoveTool.exe
Task: {2A1B91D2-EC1C-4A0F-B40D-E3CB4F48BA14} - \Drv Update -> No File <==== ATTENTION
Task: {2A76DA74-589F-4D68-B70F-E0A3F58BF20A} - System32\Tasks\{EFC68383-6529-457B-BB61-8CA91D73294C} => Chrome.exe hxxp://ui.skype.com/ui/0/7.4.0.102/en/abandoninstall?source=lightinstaller&page;=tsInstall
Task: {330B5DDD-9B01-4B94-82EB-4A88502D53B1} - System32\Tasks\nod => C:\Users\toshiba\AppData\Roaming\Twr\Isto\noodrun.exe [2015-10-27] ()
Task: {368A9D11-FC3B-4ADA-93E9-D64ABB72A660} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated)
Task: {380267E6-287D-4C63-A90E-E73B04ED6159} - System32\Tasks\nod01 => C:\Users\toshiba\AppData\Roaming\Twr\Isto\noodrun.exe [2015-10-27] ()
Task: {3B90CDE2-4A00-41A9-9CAC-000FB249D3AA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-01-04] (Google Inc.)
Task: {490E0732-72E8-4FA6-85E4-A9B94F894630} - System32\Tasks\{D03F28FE-E28B-4EB9-96C1-EDBE9BA7F427} => pcalua.exe -a "C:\Users\toshiba\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.25.0\dsrsetup.exe" -c /uninstl
Task: {5271EE7C-A269-48A1-B4F8-37567B6F9958} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-01-04] (Google Inc.)
Task: {533FC41C-3EE5-45F2-87E5-8EAD544E73BD} - System32\Tasks\Scheduled Update => C:\Users\toshiba\AppData\Roaming\npp\GUP.exe [2015-12-22] (Don HO [removed])
Task: {5820DBC5-E15C-424A-9D74-9342D9947194} - System32\Tasks\{15AD9EDD-4D2D-4778-8744-456FAEB4AC29} => c:\program files\opera\launcher.exe
Task: {58FDB578-AC2D-4537-95F3-C5D38AA52191} - System32\Tasks\Synaptics TouchPad Enhancements => Program Files\Synaptics\SynTP\SynTPEnh.exe
Task: {7AB987B4-9EB2-4E84-BFF4-90E174A8CF4C} - System32\Tasks\{BCEF73AF-267D-4EEC-903A-596D79D3E7E0} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=7.4.0.102&LastError;=404
Task: {84360622-2692-4F8E-B3C0-DDC54B70C248} - \Mistl -> No File <==== ATTENTION
Task: {85DE9749-8713-41A4-8933-300B96740674} - \9A5A8340-6B15 -> No File <==== ATTENTION
Task: {966897E8-E8F4-4793-982E-160615085E6A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-19] (Adobe Systems Incorporated)
Task: {9F5C5378-C11A-473D-82BE-AF3C8768F1AB} - System32\Tasks\SystemTask => C:\ProgramData\npp\npp.exe [2015-12-22] (Don HO [removed]) <==== ATTENTION
Task: {AB883FA2-C4A5-4445-9242-9677B4A830AD} - System32\Tasks\{A3C83F2E-339E-46DB-AFA5-D3F0DB836E21} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=7.4.0.102&LastError;=404
Task: {B7DCEFDF-4CFD-4318-98F8-932B0A032F6C} - System32\Tasks\JVL => C:\ProgramData\npp\npp.exe [2015-12-22] (Don HO [removed]) <==== ATTENTION
Task: {C6957ACA-538E-46CA-AB55-2E0DD4D02EEE} - System32\Tasks\Noodle => C:\Users\toshiba\AppData\Roaming\Twr\noodle.exe [2015-10-26] ()
Task: {CC44CC1E-B87C-4E83-B61E-6D2C95869497} - System32\Tasks\HPCustParticipation HP Deskjet 1510 series => C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)
Task: {E7327D20-719C-4556-B8A9-D69DC816BF6A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-23] (Piriform Ltd)
Task: {FF9726DA-3399-4DA3-82ED-475C4692B330} - \Virt-Device -> No File <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2010-01-10 08:18 - 2010-01-10 08:18 - 04254560 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-01-21 13:34 - 2010-01-21 13:34 - 08793952 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2012-01-10 21:12 - 2012-01-10 21:12 - 00094208 _____ () C:\Windows\System32\IccLibDll.dll
2016-02-19 04:05 - 2016-02-19 04:06 - 00010748 __RSH () C:\Windows\system32\runouce.exe
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 06:04 - 2009-06-11 01:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-750069077-2733385025-3247444180-1000\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{9B7B5EAE-50A0-4163-B8F6-ED1A74E60758}] => (Allow) C:\Program Files\TeamViewer\Version8\TeamViewer.exe
FirewallRules: [{6FFCBEF1-CB15-4603-989C-7E2F18C45B97}] => (Allow) C:\Program Files\TeamViewer\Version8\TeamViewer.exe
FirewallRules: [{617BF2CC-3DE2-4E3E-BC54-507F15BE83EE}] => (Allow) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
FirewallRules: [{206BFC55-8C96-46C0-B679-04650D6BB6D6}] => (Allow) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
FirewallRules: [TCP Query User{C825BD21-9A31-4EE0-BF51-446064CDD48A}F:\skype\phone\skype.exe] => (Allow) F:\skype\phone\skype.exe
FirewallRules: [UDP Query User{FA537035-46EE-498A-8F90-04403F1D08B7}F:\skype\phone\skype.exe] => (Allow) F:\skype\phone\skype.exe
FirewallRules: [{57C8FA6A-9CBF-464F-89CB-A8B18EB9683E}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\USBSetup.exe
FirewallRules: [{E0113E24-B7D0-408A-A8D3-2EA12D551C4C}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{FCBC953F-C9A7-45EA-ADC7-0607A95EA704}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Windows\system32\winlogon.exe] => enabled:@shell32.dll,-1
==================== Restore Points =========================
10-01-2016 02:40:08 Windows Update
19-01-2016 17:55:42 Windows Update
25-01-2016 17:59:02 Windows Update
10-02-2016 23:21:34 Scheduled Checkpoint
11-02-2016 15:39:49 Windows Update
16-02-2016 02:47:06 Windows Update
19-02-2016 03:56:22 Removed Google Chrome
19-02-2016 03:57:00 Removed Google Chrome
19-02-2016 04:09:41 Removed Google Chrome
19-02-2016 04:16:51 Removed Google Chrome
19-02-2016 04:17:19 Removed Google Chrome
19-02-2016 04:22:54 Revo Uninstaller Pro's restore point - Google Chrome
19-02-2016 04:23:06 Removed Google Chrome
19-02-2016 04:23:59 Revo Uninstaller Pro's restore point - Google Chrome
19-02-2016 04:24:08 Removed Google Chrome
19-02-2016 04:25:16 Revo Uninstaller Pro's restore point - Google Chrome
19-02-2016 04:25:26 Removed Google Chrome
19-02-2016 04:58:46 JRT Pre-Junkware Removal
19-02-2016 05:11:50 Removed Google Chrome
==================== Faulty Device Manager Devices =============
Name: WiMAX Bus Eumerator
Description: WiMAX Bus Eumerator
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/21/2016 07:27:05 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program AdwCleaner because of this error.
Program: AdwCleaner
File:
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
Additional Data
Error value: 00000000
Disk type: 0
Error: (02/21/2016 07:27:05 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AdwCleaner.exe, version: 5.0.3.5, time stamp: 0x56c609fc
Faulting module name: AdwCleaner.exe, version: 5.0.3.5, time stamp: 0x56c609fc
Exception code: 0xc0000096
Fault offset: 0x002b2b63
Faulting process id: 0x9f4
Faulting application start time: 0xAdwCleaner.exe0
Faulting application path: AdwCleaner.exe1
Faulting module path: AdwCleaner.exe2
Report Id: AdwCleaner.exe3
Error: (02/21/2016 07:20:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Faulting module name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Exception code: 0x80000003
Fault offset: 0x000288a7
Faulting process id: 0xf0c
Faulting application start time: 0xGoogleUpdate.exe0
Faulting application path: GoogleUpdate.exe1
Faulting module path: GoogleUpdate.exe2
Report Id: GoogleUpdate.exe3
Error: (02/21/2016 03:03:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AdobeARM.exe, version: 1.824.16.6751, time stamp: 0x566e71fd
Faulting module name: AdobeARM.exe, version: 1.824.16.6751, time stamp: 0x566e71fd
Exception code: 0x80000003
Fault offset: 0x0010fc37
Faulting process id: 0x51c
Faulting application start time: 0xAdobeARM.exe0
Faulting application path: AdobeARM.exe1
Faulting module path: AdobeARM.exe2
Report Id: AdobeARM.exe3
Error: (02/21/2016 03:03:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Faulting module name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Exception code: 0x80000003
Fault offset: 0x000288a7
Faulting process id: 0x970
Faulting application start time: 0xGoogleUpdate.exe0
Faulting application path: GoogleUpdate.exe1
Faulting module path: GoogleUpdate.exe2
Report Id: GoogleUpdate.exe3
Error: (02/20/2016 08:54:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Faulting module name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Exception code: 0x80000003
Fault offset: 0x000288a7
Faulting process id: 0x694
Faulting application start time: 0xGoogleUpdate.exe0
Faulting application path: GoogleUpdate.exe1
Faulting module path: GoogleUpdate.exe2
Report Id: GoogleUpdate.exe3
Error: (02/20/2016 08:54:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Faulting module name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Exception code: 0x80000003
Fault offset: 0x000288a7
Faulting process id: 0xc50
Faulting application start time: 0xGoogleUpdate.exe0
Faulting application path: GoogleUpdate.exe1
Faulting module path: GoogleUpdate.exe2
Report Id: GoogleUpdate.exe3
Error: (02/20/2016 08:51:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AdobeARM.exe, version: 1.824.16.6751, time stamp: 0x566e71fd
Faulting module name: AdobeARM.exe, version: 1.824.16.6751, time stamp: 0x566e71fd
Exception code: 0x80000003
Fault offset: 0x0010fc37
Faulting process id: 0x76c
Faulting application start time: 0xAdobeARM.exe0
Faulting application path: AdobeARM.exe1
Faulting module path: AdobeARM.exe2
Report Id: AdobeARM.exe3
Error: (02/20/2016 08:49:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Faulting module name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Exception code: 0x80000003
Fault offset: 0x000288a7
Faulting process id: 0xeb0
Faulting application start time: 0xGoogleUpdate.exe0
Faulting application path: GoogleUpdate.exe1
Faulting module path: GoogleUpdate.exe2
Report Id: GoogleUpdate.exe3
Error: (02/20/2016 08:49:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Faulting module name: GoogleUpdate.exe, version: 1.3.29.1, time stamp: 0x564f508c
Exception code: 0x80000003
Fault offset: 0x000288a7
Faulting process id: 0xbd8
Faulting application start time: 0xGoogleUpdate.exe0
Faulting application path: GoogleUpdate.exe1
Faulting module path: GoogleUpdate.exe2
Report Id: GoogleUpdate.exe3
System errors:
=============
Error: (02/20/2016 08:42:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Google Update Service (gupdate) service failed to start due to the following error:
%%1053
Error: (02/20/2016 08:42:21 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.
Error: (02/20/2016 08:40:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The MBAMService service failed to start due to the following error:
%%1053
Error: (02/20/2016 08:40:14 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the MBAMService service to connect.
Error: (02/20/2016 08:39:59 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Adobe Acrobat Update Service service to connect.
Error: (02/19/2016 04:46:10 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Google Update Service (gupdate) service failed to start due to the following error:
%%1053
Error: (02/19/2016 04:46:10 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.
Error: (02/19/2016 04:44:02 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The MBAMService service failed to start due to the following error:
%%1053
Error: (02/19/2016 04:44:02 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the MBAMService service to connect.
Error: (02/19/2016 04:43:47 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Adobe Acrobat Update Service service to connect.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5 CPU M 480 @ 2.67GHz
Percentage of memory in use: 34%
Total physical RAM: 2994.67 MB
Available physical RAM: 1951.43 MB
Total Virtual: 5987.66 MB
Available Virtual: 4816.21 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:195.21 GB) (Free:162.65 GB) NTFS
Drive d: () (Fixed) (Total:270.45 GB) (Free:248.94 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 030FB4CD)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=195.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=270.4 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
Regards,
galaxy