This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Legit copy of windows now displays as unverified. [Solved]

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I was silly and fell for a dumb download.  I ran malware byte's and it removed some infections but my windows 7 is displaying as an unverified version when it has been a legal version as long as I've owned this laptop.  I haven't done anything besides run maleware byte's.  Here are my logs:

 

Avast:

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-04-18 18:56:31
—————————–
18:56:31.679    OS Version: Windows x64 6.1.7601 Service Pack 1
18:56:31.679    Number of processors: 2 586 0x603
18:56:31.679    ComputerName: OWNER-VAIO  UserName: Owner
18:56:34.519    Initialize success
18:56:34.597    VM: initialized successfully
18:56:34.597    VM: Amd CPU BiosDisabled 
18:59:01.897    AVAST engine defs: 16033102
19:01:22.155    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000056
19:01:22.170    Disk 0 Vendor: WDC_WD50 03.0 Size: 476940MB BusType: 11
19:01:22.358    Disk 0 MBR read successfully
19:01:22.358    Disk 0 MBR scan
19:01:22.373    Disk 0 Windows 7 default MBR code
19:01:22.373    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS         9777 MB offset 2048
19:01:22.482    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 20025344
19:01:22.498    Disk 0 default boot code
19:01:22.607    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       467061 MB offset 20230144
19:01:22.872    Disk 0 scanning C:\Windows\system32\drivers
19:01:56.768    Service scanning
19:03:13.687    Modules scanning
19:03:13.702    Disk 0 trace - called modules:
19:03:13.749    ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys ACPI.sys storport.sys hal.dll amd_sata.sys 
19:03:13.765    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800431d060]
19:03:13.765    3 CLASSPNP.SYS[fffff8800191943f] -> nt!IofCallDriver -> [0xfffffa80042d3040]
19:03:13.780    5 amd_xata.sys[fffff88000df57a8] -> nt!IofCallDriver -> [0xfffffa80042d1d30]
19:03:13.780    7 ACPI.sys[fffff88000f067a1] -> nt!IofCallDriver -> \Device\00000056[0xfffffa80042cb140]
19:03:17.883    AVAST engine scan C:\Windows
19:03:28.569    AVAST engine scan C:\Windows\system32
19:17:09.855    AVAST engine scan C:\Windows\system32\drivers
19:17:39.993    AVAST engine scan C:\Users\Owner
19:41:22.933    AVAST engine scan C:\ProgramData
19:48:04.294    Disk 0 statistics 4435263/0/0 @ 1.88 MB/s
19:48:04.309    Scan finished successfully
19:48:37.658    Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat"
19:48:37.798    The log file has been saved successfully to "C:\Users\Owner\Desktop\AvastScan1.txt"
FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016
Ran by [removed] (administrator) on OWNER-VAIO (18-04-2016 19:53:31)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Wacom Technology, Corp.) C:\Windows\System32\Wacom_Tablet.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Sony Corporation) C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Wacom Technology, Corp.) C:\Windows\System32\WTablet\Wacom_TabletUser.exe
(Wacom Technology, Corp.) C:\Windows\System32\Wacom_Tablet.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\Lexmark S510 Series\LMADHmon.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Spotify Ltd) C:\Users\Owner\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1436736 2011-06-15] (Microsoft Corporation)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-17] (Apple Inc.)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-12-17] (Apple Inc.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-14] (Adobe Systems Incorporated)
HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\…\Run: [LMab1err] => C:\Program Files (x86)\Lexmark\ErrorApp\LMab1err.exe [643752 2011-04-12] ()
HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\…\Run: [LMADHmon] => C:\Program Files (x86)\Lexmark S510 Series\LMADHmon.exe [946856 2011-07-28] ()
HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\…\Run: [Spotify Web Helper] => C:\Users\Owner\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2541160 2016-04-03] (Spotify Ltd)
HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\…\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-03-15] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-03-15] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-03-15] (Microsoft Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{3F67DA4C-0592-4B3A-8B23-AE4FF83F9F18}: [DhcpNameServer] 8.8.8.8 8.8.4.4
ManualProxies: 
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://sony.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=SNYVDF&pc;=MASA&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=SNYVDF&pc;=MASA&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=SNYVDF&pc;=MASA&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=SNYVDF&pc;=MASA&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2212292319-1339573239-2403685339-1005 -> DefaultScope {2ECA6D94-9F41-40F1-B34C-02AC0E3D18FE} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2212292319-1339573239-2403685339-1005 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2212292319-1339573239-2403685339-1005 -> {2ECA6D94-9F41-40F1-B34C-02AC0E3D18FE} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-03-15] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-09-12] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-03-15] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-03-15] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-12] (Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-03-15] (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10] (Microsoft Corporation)
BHO-x32: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-19] (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-03-15] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-03-15] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-09-03] (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-19] (Skype Technologies S.A.)
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-12] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-12] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-12] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-12] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-03] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-09-03] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-02-27] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR Session Restore: Default -> is enabled.
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => No File
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (kamkam94 
 Quizlet) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkjlaafnpegnpjabdnmokmdolpcmomai [2015-11-21]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-03]
CHR Extension: (I-Learn: Student Dashboard) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjncaleihooaeodglgpamppchpbgfbco [2015-11-21]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2828016 2016-02-09] (Microsoft Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [12784 2011-04-27] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [288272 2011-04-27] (Microsoft Corporation)
R2 TabletServiceWacom; C:\Windows\system32\Wacom_Tablet.exe [1908520 2007-09-07] (Wacom Technology, Corp.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2010-04-08] (Sony Corporation) [File not signed]
R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [852336 2010-03-18] (Sony Corporation)
R3 VUAgent; C:\Program Files\Sony\VAIO Update 5\VUAgent.exe [1203568 2010-01-22] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S2 Oasis2Service; "C:\Program Files (x86)\DDNi\Oasis2Service\Oasis2Service.exe" [X]
S2 PMBDeviceInfoProvider; "c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe" [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S1 bwsojnng; C:\Windows\system32\drivers\bwsojnng.sys [55168 2016-04-18] (Microsoft Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S1 kuzmlcql; C:\Windows\system32\drivers\kuzmlcql.sys [55168 2016-04-18] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [189440 2011-04-18] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [84864 2011-04-27] (Microsoft Corporation)
U2 IAStorDataMgrSvc; no ImagePath
U2 MSSQL$DDNI; no ImagePath
U3 aswMBR; \??\C:\Users\Owner\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Owner\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-04-18 19:53 - 2016-04-18 19:54 - 00018641 _____ C:\Users\Owner\Desktop\FRST.txt
2016-04-18 19:52 - 2016-04-18 19:53 - 00000000 ____D C:\FRST
2016-04-18 19:52 - 2016-04-18 19:51 - 02375680 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
2016-04-18 19:51 - 2016-04-18 19:51 - 02375680 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe
2016-04-18 19:49 - 2016-04-18 19:49 - 01726464 _____ (Farbar) C:\Users\Owner\Downloads\FRST.exe
2016-04-18 19:49 - 2016-04-18 19:49 - 01726464 _____ (Farbar) C:\Users\Owner\Desktop\FRST.exe
2016-04-18 19:48 - 2016-04-18 19:48 - 00002298 _____ C:\Users\Owner\Desktop\AvastScan1.txt
2016-04-18 19:48 - 2016-04-18 19:48 - 00000512 _____ C:\Users\Owner\Desktop\MBR.dat
2016-04-18 18:55 - 2016-04-18 18:55 - 05198336 _____ (AVAST Software) C:\Users\Owner\Downloads\aswMBR.exe
2016-04-18 10:06 - 2016-04-18 10:06 - 00357888 ____N (Microsoft Corporation) C:\Windows\system32\dnsapi.dllCB3FCF87
2016-04-18 10:06 - 2016-04-18 10:06 - 00055168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kuzmlcql.sys
2016-04-18 09:40 - 2016-04-18 09:40 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dllCE3D7CDA
2016-04-18 09:40 - 2016-04-18 09:40 - 00055168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bwsojnng.sys
2016-04-18 08:30 - 2016-04-18 08:33 - 00131072 _____ C:\Windows\ocsetup_uninstall_OEMHelpCustomization.etl
2016-04-18 08:30 - 2016-04-18 08:33 - 00028576 _____ C:\Windows\ocsetup_cbs_uninstall_OEMHelpCustomization.txt
2016-04-16 12:06 - 2016-04-16 12:06 - 00000000 ____D C:\Windows\system32\bhvo
2016-04-16 11:04 - 2016-04-16 11:04 - 00000000 ____D C:\ProgramData\28341ff220e0446c9fff27c4493d622e
2016-04-16 11:01 - 2016-04-16 12:07 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Jeicc
2016-04-16 11:01 - 2016-04-16 12:07 - 00000000 ____D C:\Users\Owner\AppData\LocalLow\Company
2016-04-16 11:01 - 2016-04-16 11:01 - 00003330 _____ C:\Windows\System32\Tasks\Telni
2016-04-16 11:01 - 2016-04-16 11:01 - 00000000 ____D C:\Users\Owner\AppData\Local\Tempfolder
2016-04-16 11:01 - 2016-04-16 11:01 - 00000000 ____D C:\uninst
2016-04-15 21:05 - 2016-04-15 21:05 - 00027840 _____ C:\Windows\system32\s000000.dat
2016-04-15 21:05 - 2016-04-15 21:05 - 00000040 _____ C:\Windows\system32\sstate_prev.sdt
2016-04-15 21:05 - 2016-04-15 21:05 - 00000000 _____ C:\Windows\system32\sstates.sdt
2016-04-13 07:48 - 2016-03-17 17:04 - 05551336 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-04-13 07:48 - 2016-03-17 17:04 - 00706280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-04-13 07:48 - 2016-03-17 17:04 - 00154344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-04-13 07:48 - 2016-03-17 17:04 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-04-13 07:48 - 2016-03-17 17:01 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-04-13 07:48 - 2016-03-17 17:01 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-04-13 07:48 - 2016-03-17 16:56 - 02084864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-04-13 07:48 - 2016-03-17 16:53 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-04-13 07:48 - 2016-03-17 16:36 - 03998952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-04-13 07:48 - 2016-03-17 16:36 - 03943144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-04-13 07:48 - 2016-03-17 16:33 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-04-13 07:48 - 2016-03-17 16:28 - 01414144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-04-13 07:48 - 2016-03-16 12:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-04-13 07:48 - 2016-03-16 12:28 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-04-13 07:48 - 2016-03-16 12:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-04-13 07:48 - 2016-03-06 12:53 - 01885696 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2016-04-13 07:48 - 2016-03-06 12:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2016-04-13 07:48 - 2016-03-06 12:38 - 01240576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2016-04-13 07:48 - 2016-03-06 12:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2016-04-13 07:48 - 2016-02-02 12:57 - 00511488 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2016-04-13 07:47 - 2016-04-04 12:14 - 00038120 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-04-13 07:47 - 2016-04-04 12:02 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-04-13 07:47 - 2016-04-02 07:08 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-04-13 07:47 - 2016-03-29 11:53 - 03216896 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-04-13 07:47 - 2016-03-23 08:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-04-13 07:47 - 2016-03-17 16:58 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-04-13 07:47 - 2016-03-17 16:58 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-04-13 07:47 - 2016-03-17 16:58 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-04-13 07:47 - 2016-03-17 16:58 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-04-13 07:47 - 2016-03-17 16:58 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-04-13 07:47 - 2016-03-17 16:58 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-04-13 07:47 - 2016-03-17 16:58 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-04-13 07:47 - 2016-03-17 16:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-04-13 07:47 - 2016-03-17 16:58 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-04-13 07:47 - 2016-03-17 16:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-04-13 07:47 - 2016-03-17 16:57 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-04-13 07:47 - 2016-03-17 16:57 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-04-13 07:47 - 2016-03-17 16:57 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-04-13 07:47 - 2016-03-17 16:57 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-04-13 07:47 - 2016-03-17 16:57 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-04-13 07:47 - 2016-03-17 16:56 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-04-13 07:47 - 2016-03-17 16:54 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-04-13 07:47 - 2016-03-17 16:54 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-04-13 07:47 - 2016-03-17 16:54 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-04-13 07:47 - 2016-03-17 16:54 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-04-13 07:47 - 2016-03-17 16:53 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-04-13 07:47 - 2016-03-17 16:53 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-04-13 07:47 - 2016-03-17 16:53 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:31 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-04-13 07:47 - 2016-03-17 16:31 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-04-13 07:47 - 2016-03-17 16:31 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-04-13 07:47 - 2016-03-17 16:31 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-04-13 07:47 - 2016-03-17 16:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-04-13 07:47 - 2016-03-17 16:30 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-04-13 07:47 - 2016-03-17 16:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-04-13 07:47 - 2016-03-17 16:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-04-13 07:47 - 2016-03-17 16:29 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-04-13 07:47 - 2016-03-17 16:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-04-13 07:47 - 2016-03-17 16:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-04-13 07:47 - 2016-03-17 16:27 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-04-13 07:47 - 2016-03-17 16:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-04-13 07:47 - 2016-03-17 16:27 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-04-13 07:47 - 2016-03-17 16:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-04-13 07:47 - 2016-03-17 16:26 - 00553984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-04-13 07:47 - 2016-03-17 16:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 16:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 15:53 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-04-13 07:47 - 2016-03-17 15:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-04-13 07:47 - 2016-03-17 15:52 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-04-13 07:47 - 2016-03-17 15:51 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-04-13 07:47 - 2016-03-17 15:44 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-04-13 07:47 - 2016-03-17 15:43 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-04-13 07:47 - 2016-03-17 15:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-04-13 07:47 - 2016-03-17 15:38 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-04-13 07:47 - 2016-03-17 15:37 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-04-13 07:47 - 2016-03-17 15:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-04-13 07:47 - 2016-03-17 15:35 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-04-13 07:47 - 2016-03-17 15:35 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-04-13 07:47 - 2016-03-17 15:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-04-13 07:47 - 2016-03-17 15:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-04-13 07:47 - 2016-03-17 15:30 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-04-13 07:47 - 2016-03-17 15:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-04-13 07:47 - 2016-03-17 15:29 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-04-13 07:47 - 2016-03-17 15:29 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 15:29 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 15:29 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 15:29 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-04-13 07:47 - 2016-03-17 12:04 - 00698368 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-04-13 07:47 - 2016-03-17 12:04 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-04-13 07:47 - 2016-03-17 12:04 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-04-13 07:47 - 2016-03-17 12:04 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-04-13 07:47 - 2016-03-15 18:16 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2016-04-13 07:47 - 2016-03-15 18:16 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2016-04-13 07:47 - 2016-03-15 17:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2016-04-13 07:47 - 2016-02-05 12:56 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll
2016-04-13 07:47 - 2016-02-05 12:54 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2016-04-13 07:47 - 2016-02-05 11:33 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbs.dll
2016-04-13 07:47 - 2016-01-20 18:51 - 00073664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2016-04-13 07:47 - 2015-06-03 14:21 - 00451080 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2016-04-13 07:46 - 2016-03-31 13:25 - 00394952 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-04-13 07:46 - 2016-03-31 12:41 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-04-13 07:46 - 2016-03-30 18:54 - 25817600 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-04-13 07:46 - 2016-03-30 18:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-04-13 07:46 - 2016-03-30 18:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-04-13 07:46 - 2016-03-30 18:31 - 02892800 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-04-13 07:46 - 2016-03-30 18:28 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-04-13 07:46 - 2016-03-30 18:28 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-04-13 07:46 - 2016-03-30 18:27 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-04-13 07:46 - 2016-03-30 18:27 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-04-13 07:46 - 2016-03-30 18:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-04-13 07:46 - 2016-03-30 18:25 - 06052352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-04-13 07:46 - 2016-03-30 18:22 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-04-13 07:46 - 2016-03-30 18:21 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-04-13 07:46 - 2016-03-30 18:19 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-04-13 07:46 - 2016-03-30 18:17 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-04-13 07:46 - 2016-03-30 18:17 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-04-13 07:46 - 2016-03-30 18:17 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-04-13 07:46 - 2016-03-30 18:17 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-04-13 07:46 - 2016-03-30 18:11 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-04-13 07:46 - 2016-03-30 18:08 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-04-13 07:46 - 2016-03-30 18:03 - 20352512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-04-13 07:46 - 2016-03-30 18:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-04-13 07:46 - 2016-03-30 18:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-04-13 07:46 - 2016-03-30 17:59 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-04-13 07:46 - 2016-03-30 17:57 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-04-13 07:46 - 2016-03-30 17:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-04-13 07:46 - 2016-03-30 17:55 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-04-13 07:46 - 2016-03-30 17:53 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-04-13 07:46 - 2016-03-30 17:53 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-04-13 07:46 - 2016-03-30 17:52 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-04-13 07:46 - 2016-03-30 17:52 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-04-13 07:46 - 2016-03-30 17:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-04-13 07:46 - 2016-03-30 17:52 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-04-13 07:46 - 2016-03-30 17:51 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-04-13 07:46 - 2016-03-30 17:48 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-04-13 07:46 - 2016-03-30 17:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-04-13 07:46 - 2016-03-30 17:46 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-04-13 07:46 - 2016-03-30 17:45 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-04-13 07:46 - 2016-03-30 17:45 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-04-13 07:46 - 2016-03-30 17:45 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-04-13 07:46 - 2016-03-30 17:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-04-13 07:46 - 2016-03-30 17:43 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-04-13 07:46 - 2016-03-30 17:43 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-04-13 07:46 - 2016-03-30 17:42 - 02131968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-04-13 07:46 - 2016-03-30 17:42 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-04-13 07:46 - 2016-03-30 17:39 - 15415808 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-04-13 07:46 - 2016-03-30 17:38 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-04-13 07:46 - 2016-03-30 17:34 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-04-13 07:46 - 2016-03-30 17:33 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-04-13 07:46 - 2016-03-30 17:31 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-04-13 07:46 - 2016-03-30 17:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-04-13 07:46 - 2016-03-30 17:30 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-04-13 07:46 - 2016-03-30 17:30 - 02596864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-04-13 07:46 - 2016-03-30 17:30 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-04-13 07:46 - 2016-03-30 17:29 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-04-13 07:46 - 2016-03-30 17:24 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-04-13 07:46 - 2016-03-30 17:23 - 02056192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-04-13 07:46 - 2016-03-30 17:23 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-04-13 07:46 - 2016-03-30 17:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-04-13 07:46 - 2016-03-30 17:21 - 13811712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-04-13 07:46 - 2016-03-30 17:18 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-04-13 07:46 - 2016-03-30 17:06 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-04-13 07:46 - 2016-03-30 17:05 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-04-13 07:46 - 2016-03-30 17:02 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-04-13 07:46 - 2016-03-30 17:00 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-04-13 07:46 - 2016-03-11 12:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-04-13 07:46 - 2016-03-11 12:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-04-07 15:26 - 2016-04-07 15:26 - 00345680 _____ C:\Users\Owner\Downloads\M102 Reading and Listening Schedule W16 (2).xlsx
2016-04-07 15:20 - 2016-04-07 15:20 - 00002363 _____ C:\Users\Owner\Desktop\Excel 2013.lnk
2016-04-07 15:19 - 2016-04-07 15:19 - 00002401 _____ C:\Users\Owner\Desktop\Word 2013.lnk
2016-04-07 15:19 - 2016-04-07 15:19 - 00000000 ____D C:\Users\Owner\Documents\Old Documents
2016-04-06 12:03 - 2016-04-06 12:03 - 00006090 _____ C:\Users\Owner\Downloads\Kamstra_Brandy_GradPlan.pdf
2016-04-06 11:32 - 2016-04-06 11:32 - 00571923 _____ C:\Users\Owner\Downloads\Music.pdf
2016-04-06 11:21 - 2016-04-06 11:22 - 00350936 _____ (Spotify Ltd) C:\Users\Owner\Downloads\SpotifySetup.exe
2016-04-06 08:51 - 2016-04-06 08:51 - 00592889 _____ C:\Users\Owner\Downloads\Fear Not Little Flock (2).pdf
2016-04-06 08:27 - 2016-04-06 08:27 - 00588892 _____ C:\Users\Owner\Downloads\Fear Not Little Flock (1).pdf
2016-04-06 08:15 - 2016-04-06 08:15 - 00587527 _____ C:\Users\Owner\Downloads\Fear Not Little Flock.pdf
2016-04-04 20:44 - 2016-04-04 20:44 - 00078161 _____ C:\Users\Owner\Downloads\mus_173_exam_4_beethoven_example.m4a
2016-04-03 17:10 - 2016-04-03 17:10 - 00000000 ____D C:\Users\Owner\AppData\Local\CEF
2016-04-01 11:48 - 2016-04-01 11:48 - 09530368 _____ C:\Users\Owner\Downloads\Gospel Values and Arts M102.ppt
2016-03-23 20:15 - 2016-03-23 20:15 - 00038679 _____ C:\Users\Owner\Downloads\Project 8 Answer Key.pdf
2016-03-23 20:13 - 2016-03-23 20:13 - 00037693 _____ C:\Users\Owner\Downloads\Project 8 Student Wksht.pdf
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-04-18 19:48 - 2009-07-13 22:45 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-18 19:48 - 2009-07-13 22:45 - 00010096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-18 19:47 - 2013-03-08 18:05 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-18 19:03 - 2012-12-28 10:54 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-18 18:47 - 2013-03-08 18:05 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-18 11:42 - 2015-12-29 15:07 - 00000000 ____D C:\Users\Owner\Desktop\School Work
2016-04-18 09:51 - 2012-12-27 13:34 - 00003934 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{21D48B08-33AB-4564-9FD6-B6A34429C08F}
2016-04-18 09:37 - 2009-07-13 23:13 - 00786836 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-18 09:37 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\inf
2016-04-18 09:32 - 2013-01-28 22:04 - 00000000 ____D C:\Users\Owner\AppData\Local\CrashDumps
2016-04-18 09:21 - 2013-01-05 15:12 - 00000000 ____D C:\Users\Owner\AppData\Roaming\WTablet
2016-04-18 09:14 - 2009-07-13 23:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-18 09:10 - 2015-06-10 22:23 - 00000258 __RSH C:\ProgramData\ntuser.pol
2016-04-18 09:00 - 2012-12-27 12:24 - 00000000 ____D C:\Program Files\Sony
2016-04-18 08:58 - 2015-11-29 17:49 - 00000000 ____D C:\Users\Owner\AppData\Local\TERA
2016-04-18 08:30 - 2012-12-27 12:36 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-04-18 08:30 - 2012-12-27 12:32 - 00000000 ____D C:\ProgramData\DDNi
2016-04-18 08:30 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\Help
2016-04-18 08:28 - 2015-06-07 14:16 - 00325908 _____ C:\Windows\ntbtlog.txt
2016-04-18 08:27 - 2015-07-02 20:13 - 00000000 ____D C:\Users\Owner\AppData\Roaming\uTorrent
2016-04-16 12:06 - 2012-12-27 15:34 - 00357888 ____N (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2016-04-16 12:06 - 2012-12-27 15:34 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2016-04-16 12:04 - 2009-07-13 20:34 - 00000505 _____ C:\Windows\win.ini
2016-04-16 11:12 - 2015-06-07 14:24 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-04-16 10:59 - 2013-03-08 18:06 - 00002357 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-16 10:59 - 2013-03-08 18:06 - 00002345 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-16 10:59 - 2013-01-03 14:31 - 00001597 _____ C:\Users\Owner\Desktop\Internet Explorer (64-bit).lnk
2016-04-16 10:59 - 2012-12-27 13:33 - 00001631 _____ C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-04-15 19:58 - 2009-07-13 22:45 - 00468520 _____ C:\Windows\system32\FNTCACHE.DAT
2016-04-15 19:55 - 2015-05-27 05:01 - 00000000 ____D C:\Windows\system32\appraiser
2016-04-15 17:17 - 2013-08-30 13:07 - 00000000 ____D C:\Windows\system32\MRT
2016-04-15 17:05 - 2012-12-27 15:55 - 135176864 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-04-13 17:45 - 2012-12-28 11:14 - 00453280 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-04-08 09:03 - 2012-12-28 10:54 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-04-08 09:03 - 2012-12-28 10:54 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-04-08 09:03 - 2012-12-28 10:54 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-04-07 08:03 - 2013-01-19 13:58 - 00000000 ____D C:\ProgramData\LexmarkUpdate
2016-04-06 11:22 - 2013-01-05 15:20 - 00000000 ____D C:\Users\Owner\AppData\Local\Spotify
2016-04-06 11:22 - 2013-01-05 15:19 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Spotify
2016-04-05 09:59 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\rescache
2016-04-03 18:24 - 2013-06-04 15:15 - 00000023 _____ C:\test.xml
2016-04-03 17:10 - 2015-09-03 21:51 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-04-03 17:01 - 2015-09-03 21:44 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-03-26 03:02 - 2015-05-31 10:18 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2016-03-26 03:02 - 2015-05-31 10:18 - 00000000 ___SD C:\Windows\system32\GWX
 
==================== Files in the root of some directories =======
 
2013-03-17 08:24 - 2013-03-17 08:24 - 0003584 _____ () C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-02-28 19:33 - 2013-05-27 10:05 - 0003102 _____ () C:\ProgramData\LMADHscan.log
 
Files to move or delete:
====================
C:\Users\Owner\jobq.dat
 
 
Some files in TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\EAD1C17.exe
C:\Users\Owner\AppData\Local\Temp\EAD254B.exe
C:\Users\Owner\AppData\Local\Temp\EAD2838.exe
C:\Users\Owner\AppData\Local\Temp\EAD369.exe
C:\Users\Owner\AppData\Local\Temp\EAD3F31.exe
C:\Users\Owner\AppData\Local\Temp\EAD6FB3.exe
C:\Users\Owner\AppData\Local\Temp\EAD8E5.exe
C:\Users\Owner\AppData\Local\Temp\EADF9A9.exe
C:\Users\Owner\AppData\Local\Temp\i4jdel0.exe
C:\Users\Owner\AppData\Local\Temp\i7FbB4Tr1u.exe
C:\Users\Owner\AppData\Local\Temp\JNL0dxjqko.exe
C:\Users\Owner\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u51-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u73-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\MSN3B1E.exe
C:\Users\Owner\AppData\Local\Temp\nb8knocy.dll
C:\Users\Owner\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Owner\AppData\Local\Temp\xzhOtGfLMo.exe
C:\Users\Owner\AppData\Local\Temp\Y2CbLGIyip.exe
C:\Users\Owner\AppData\Local\Temp\yu5iEn8UzC.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll
[2012-12-27 15:34] - [2016-04-16 12:06] - 0357888 ____N (Microsoft Corporation) 6F424DCA6501DF61C1DE50BBE253116C
 
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-04-18 11:37
 
==================== End of FRST.txt ============================
Addition:
Additional scan result of Farbar Recovery Scan Tool (x64) Version:18-04-2016
Ran by [removed] (2016-04-18 19:56:39)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-12-27 19:28:07)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2212292319-1339573239-2403685339-500 - Administrator - Disabled)
boinc_master (S-1-5-21-2212292319-1339573239-2403685339-1000 - Limited - Enabled) => C:\Users\boinc_master
boinc_project (S-1-5-21-2212292319-1339573239-2403685339-1001 - Limited - Enabled)
Guest (S-1-5-21-2212292319-1339573239-2403685339-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2212292319-1339573239-2403685339-1007 - Limited - Enabled)
Owner (S-1-5-21-2212292319-1339573239-2403685339-1005 - Administrator - Enabled) => C:\Users\Owner
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {108DAC43-C256-20B7-BB05-914135DA5160}
AS: Microsoft Security Essentials (Enabled - Up to date) {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 21 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.15) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.15 - Adobe Systems Incorporated)
Alps Pointing-device for VAIO (HKLM\…\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version:  - ALPS ELECTRIC CO., LTD.)
AMD USB Filter Driver (HKLM-x32\…\{987B04C4-B5AC-4AD6-A7E9-8D681085B850}) (Version: 1.0.15.94 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\…\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Application Manager for VAIO (HKLM-x32\…\Application Manager for VAIO) (Version:  - )
ArcSoft WebCam Companion 3 (HKLM-x32\…\{DE8AAC73-6D8D-483E-96EA-CAEDDADB9079}) (Version: 3.0.21.368 - ArcSoft)
ATI Catalyst Install Manager (HKLM\…\{475672E2-253A-4B55-2E0E-1456A2BFD3E7}) (Version: 3.0.765.0 - ATI Technologies, Inc.)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Buzzdock (HKLM\…\{ac225167-00fc-452d-94c5-bb93600e7d9a}) (Version:  - Alactro LLC) <==== ATTENTION
ccc-core-static (x32 Version: 2010.0713.642.10121 - ATI) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Decrap my Computer (HKLM-x32\…\Decrap my Computer) (Version:  - Macecraft Software)
FamilySearch Indexing 3.26.0 (HKLM-x32\…\0591-8077-9297-0833) (Version: 3.26.0 - FamilySearch)
Free Audio Converter version 5.0.60.713 (HKLM-x32\…\Free Audio Converter_is1) (Version: 5.0.60.713 - DVDVideoSoft Ltd.)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.165 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
iTunes (HKLM\…\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.)
Java 8 Update 60 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86418060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Java 8 Update 60 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Lexmark S510 Series Uninstaller (HKLM\…\Lexmark S510 Series) (Version:  - Lexmark International, Inc.)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Media Gallery (x32 Version: 1.2.0.23220 - Sony Corporation) Hidden
Media Gallery MergeModules x64 (Version: 1.0.14250 - Sony Corporation) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 - en-us (HKLM\…\ProPlusRetail - en-us) (Version: 15.0.4805.1003 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\…\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 2.1.1116.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\…\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
MSI_SPF_x64 (Version: 1.0.0 - Sony Corporation) Hidden
MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\…\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
NCSOFT Game Launcher (HKLM-x32\…\NCLauncher_NCWest) (Version:  - NCSOFT)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4805.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4805.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4805.1003 - Microsoft Corporation) Hidden
Origin (HKLM-x32\…\Origin) (Version: 8.4.1.210 - Electronic Arts, Inc.)
PaintTool SAI Ver.1 (HKLM-x32\…\PaintToolSAI) (Version:  - )
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
PMB VAIO Edition Plug-in (Version: 1.4.02.11300 - Sony Corporation) Hidden
PMB VAIO Edition Plug-in (x32 Version: 1.4.00.09190 - Sony Corporation) Hidden
QuickTime (HKLM-x32\…\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
Realtek HDMI Audio Driver for ATI (HKLM-x32\…\{5449FB4F-1802-4D5B-A6D8-087DB1142147}) (Version: 6.0.1.6034 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6069 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30116 - Realtek Semiconductor Corp.)
Setting Utility Series (x32 Version: 5.2.0.15250 - Sony Corporation) Hidden
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartWi Connection Utility (HKLM-x32\…\{9B5F85CA-90D4-4AFC-BB37-32477FD0D2B9}) (Version: 4.11.4.20100722.2739 - Sony Corporation)
Sony Home Network Library (x32 Version: 2.1.0.14240 - Sony Corporation) Hidden
Spotify (HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\…\Spotify) (Version: 1.0.15.133.gf21970bd - Spotify AB)
Tansee iPod Transfer 5.8.0.0 (HKLM-x32\…\Tansee iPod Transfer_is1) (Version: 5.8.0.0 - Tansee, Inc.)
VAIO Care (x32 Version: 6.2.2.07150 - Sony Corporation) Hidden
VAIO Content Monitoring Settings (x32 Version: 2.5.0.13220 - Sony Corporation) Hidden
VAIO Data Restore Tool (x32 Version: 1.3.0.13150 - Sony Corporation) Hidden
VAIO Entertainment Platform (x32 Version: 3.7.0.16080 - Sony Corporation) Hidden
VAIO Event Service (x32 Version: 5.2.0.15020 - Sony Corporation) Hidden
VAIO Gate (x32 Version: 2.2.0.06080 - Sony Corporation) Hidden
VAIO Gate Default (x32 Version: 2.2.0.07020 - Sony Corporation) Hidden
VAIO Hardware Diagnostics (x32 Version: 3.9.1 - Sony Corporation) Hidden
VAIO Manual (x32 Version: 1.0.0.03290 - Sony Corporation) Hidden
VAIO Media plus (x32 Version: 2.1.0.15040 - Sony Corporation) Hidden
VAIO Media plus Opening Movie (x32 Version: 2.1.0.14080 - Sony Corporation) Hidden
VAIO Original Function Settings (x32 Version: 2.1.0.13120 - Sony Corporation) Hidden
VAIO Power Management (x32 Version: 5.1.0.15250 - Sony Corporation) Hidden
VAIO Sample Contents (x32 Version: 1.2.0.16080 - Sony Corporation) Hidden
VAIO Survey (x32 Version: 6.00.1028 - Sony Corporation) Hidden
VAIO Transfer Support (x32 Version: 1.1.1.13070 - Sony Corporation) Hidden
VAIO Update 5 (x32 Version: 5.1.0.13220 - Sony Corporation) Hidden
VAIO Wallpaper Contents (x32 Version: 2.1.0.14090 - Sony Corporation) Hidden
VMp MergeModule x64 (Version: 1.0.0 - Default Company Name) Hidden
Wacom Tablet (HKLM-x32\…\Wacom Tablet Driver) (Version:  - Wacom Technology Corp.)
WIDCOMM Bluetooth Software (HKLM\…\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.500 - Broadcom Corporation)
Windows Driver Package - Broadcom Bluetooth  (09/09/2009 6.2.0.9405) (HKLM\…\930E4792BDAEAFB62A9514EE7578775658A5D07C) (Version: 09/09/2009 6.2.0.9405 - Broadcom)
Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800) (HKLM\…\3BA80AB4C7E9F8497C115C844953A3D4BEB84D21) (Version: 07/28/2009 6.2.0.9800 - Broadcom)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {05EA6B03-C37D-4AD1-BA96-EFC4A4CDDA70} - \StartPoint -> No File <==== ATTENTION
Task: {091DBA71-8FC1-4A1D-823B-53D071F96903} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-29] (Microsoft Corporation)
Task: {0A7FB4BB-C12C-42FB-8AEC-E98A65E0BFD3} - System32\Tasks\SONY\VAIO Update\VAIO Update 5 => C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe [2010-01-22] (Sony Corporation)
Task: {4200920B-8BF8-4604-A197-E63FB82F02FB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
Task: {4B573C1F-302B-431D-8E55-0A5898FBB159} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated)
Task: {4CF4FDD5-3D4E-419A-8CDB-8968906621D2} - System32\Tasks\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe
Task: {4E7E5A7C-C174-43A0-8052-7245972BE631} - \StartPoint Updater -> No File <==== ATTENTION
Task: {5677F8AD-5483-454F-81A7-6DF3DCF8393F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {6793E9E6-8DF4-4A84-822A-81D067580815} - System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2010-06-08] (Sony Corporation)
Task: {680C4893-485F-4B2F-A230-A38C0CB73865} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)
Task: {6E6C9CDD-F171-4020-A19F-6B422BBB8A7A} - System32\Tasks\LexmarkPUDCTask => C:\Program Files\Lexmark\ProductUpdate\LMprodupdate.exe [2011-06-03] ()
Task: {7337D2C6-A80F-4D7C-BE3B-D1136175FD97} - System32\Tasks\Telni => C:\PROGRA~1\Faxci\Saesu.bat <==== ATTENTION
Task: {7C43DDE9-760E-457D-A429-C8DFE34A1160} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {7E2C3D80-D5F5-444B-BAAD-66A495BE9C0A} - System32\Tasks\VAIO® Messenger (Owner) => C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe
Task: {85DFCC61-0098-48FF-A179-FD3D0A0ED060} - System32\Tasks\VAIO Care Support => C:\Program Files\Sony\VAIO Care\VCSpt.exe
Task: {969053BA-FD24-4B73-AF6A-759540C83DC8} - System32\Tasks\Sony\VAIO Survey => C:\Program Files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe [2009-10-26] ()
Task: {A499EDEC-3363-49E0-829A-D1BE5792DC33} - System32\Tasks\Microsoft\Microsoft Antimalware\MP Scheduled Scan => c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27] (Microsoft Corporation)
Task: {B48D1192-35E3-4E05-9393-7AC4C793AFA6} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2010-06-08] (Sony Corporation)
Task: {C0404FF8-9933-4F63-8786-28F6E9760863} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-29] (Microsoft Corporation)
Task: {C4B5ADFE-9850-4092-ADF7-5800843660BE} - System32\Tasks\Sony\Java Update => C:\Program Files\Java\jre6\bin\jusched.exe
Task: {E2F8DE42-9C6D-4FEE-9D8D-5767C521B67D} - System32\Tasks\DDNi Startup => C:\Program Files (x86)\DDNi\Oasis\DDNiStartup.exe
Task: {EBE49205-7E09-4E33-9108-D93FB06D6554} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-03] (Google Inc.)
Task: {F3FED85E-EABB-4147-8F22-2B63768406A9} - \{7D0D7F47-090E-7D04-0C11-797E087A1109} -> No File <==== ATTENTION
Task: {F58BA5ED-57E8-45B2-AB15-5283961BD862} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-03] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Owner\Desktop\Internet Explorer (64-bit).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1460825999&a;=1003203&src;=sh&uuid;=45c74ead-4253-4aba-ab56-0680942c4607"
ShortcutWithArgument: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1460825999&a;=1003203&src;=sh&uuid;=45c74ead-4253-4aba-ab56-0680942c4607"
ShortcutWithArgument: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\I-Learn_ Student Dashboard.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://trustedsurf.com/?ssid=1460825999&a;=1003203&src;=sh&uuid;=45c74ead-4253-4aba-ab56-0680942c4607"
ShortcutWithArgument: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\kamkam94 _ Quizlet.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://trustedsurf.com/?ssid=1460825999&a;=1003203&src;=sh&uuid;=45c74ead-4253-4aba-ab56-0680942c4607"
ShortcutWithArgument: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1460825999&a;=1003203&src;=sh&uuid;=45c74ead-4253-4aba-ab56-0680942c4607"
ShortcutWithArgument: C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://trustedsurf.com/?ssid=1460825999&a;=1003203&src;=sh&uuid;=45c74ead-4253-4aba-ab56-0680942c4607"
ShortcutWithArgument: C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1460825999&a;=1003203&src;=sh&uuid;=45c74ead-4253-4aba-ab56-0680942c4607"
ShortcutWithArgument: C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://trustedsurf.com/?ssid=1460825999&a;=1003203&src;=sh&uuid;=45c74ead-4253-4aba-ab56-0680942c4607"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://trustedsurf.com/?ssid=1460825999&a;=1003203&src;=sh&uuid;=45c74ead-4253-4aba-ab56-0680942c4607"
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> "hxxp://trustedsurf.com/?ssid=1460825999&a;=1003203&src;=sh&uuid;=45c74ead-4253-4aba-ab56-0680942c4607"
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-03-20 18:12 - 2015-03-20 18:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-12-17 19:38 - 2015-12-17 19:38 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-09-03 21:44 - 2015-10-13 04:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-10-29 10:13 - 2015-09-01 10:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2013-01-19 14:03 - 2011-07-28 07:34 - 00946856 _____ () C:\Program Files (x86)\Lexmark S510 Series\LMADHmon.exe
2012-12-27 13:46 - 2010-01-22 15:03 - 00055808 _____ () C:\Program Files\Sony\VAIO Update 5\VUAgentPS64.dll
2012-12-27 13:37 - 2010-03-02 18:22 - 00013824 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll
2012-12-27 13:37 - 2010-03-02 18:22 - 00013312 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSubPS.dll
2013-01-19 14:03 - 2011-06-24 07:02 - 01454080 _____ () C:\Program Files (x86)\Lexmark S510 Series\lmabdrs.dll
2015-10-29 10:12 - 2015-09-01 06:25 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
2016-04-11 13:49 - 2016-04-06 04:04 - 01675928 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\libglesv2.dll
2016-04-11 13:49 - 2016-04-06 04:04 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\libegl.dll
2016-04-08 22:31 - 2016-04-08 13:53 - 17532096 _____ () C:\Users\Owner\AppData\Local\Google\Chrome\User Data\PepperFlash\21.0.0.216\pepflashplayer.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Windows\system32\Drivers\bwsojnng.sys:changelist [1282]
AlternateDataStreams: C:\Windows\system32\Drivers\kuzmlcql.sys:changelist [1282]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 20:34 - 2016-04-16 12:06 - 00001444 ____A C:\Windows\system32\Drivers\etc\hosts
 
107.178.255.88 www.google-analytics.com
107.178.255.88 www.statcounter.com
107.178.255.88 statcounter.com
107.178.255.88 ssl.google-analytics.com
107.178.255.88 partner.googleadservices.com
107.178.255.88 google-analytics.com
107.178.248.130 static.doubleclick.net
107.178.247.130 connect.facebook.net
107.178.255.88 www.google-analytics.com
107.178.255.88 www.statcounter.com
107.178.255.88 statcounter.com
107.178.255.88 ssl.google-analytics.com
107.178.255.88 partner.googleadservices.com
107.178.255.88 google-analytics.com
107.178.248.130 static.doubleclick.net
107.178.247.130 connect.facebook.net
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Apoint => %ProgramFiles%\Apoint\Apoint.exe
MSCONFIG\startupreg: PMBVolumeWatcher => c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SmartWiHelper => "C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe" /WindowsStartup
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{530B3CA7-8C17-48CC-B1D1-70B5FD535520}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{6FE985BA-9D77-4F3A-AC20-1283ABE7B27E}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{71837D63-D6E4-44D2-BDA9-CF81B85A2B5E}] => (Allow) LPort=2869
FirewallRules: [{7CE3F815-1617-46F8-A188-4344415DAEFB}] => (Allow) LPort=1900
FirewallRules: [{3EFF1687-7EA7-4FBD-B5D8-A2821FC2132B}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{0039F9C0-4418-45AA-B94D-E8C4690B6B73}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{F3E1645D-F09F-40F5-81F1-4F1D3E7FDAC1}] => (Allow) C:\Users\Owner\AppData\Local\Temp\7zSCF73.tmp\SymNRT.exe
FirewallRules: [{FDD58F95-7E7F-42BE-B8EC-15C9C9957ADD}] => (Allow) C:\Users\Owner\AppData\Local\Temp\7zSCF73.tmp\SymNRT.exe
FirewallRules: [TCP Query User{807FB3F8-4511-4179-BDCE-B1EC4D84F11D}C:\users\owner\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\owner\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{CA856AAF-AE85-431A-8E38-2244115C8BAB}C:\users\owner\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\owner\appdata\roaming\spotify\spotify.exe
FirewallRules: [{9791354F-92C6-4258-9F58-5CF68C973FF6}] => (Allow) C:\Program Files (x86)\Lexmark\Status Center\lmsmc.exe
FirewallRules: [{B0BA5C5A-809E-4EEF-AF3F-C6686F185AFE}] => (Allow) C:\Program Files (x86)\Lexmark\Status Center\lmsmc.exe
FirewallRules: [{30897BA0-2D2F-44E5-8661-387942FC2454}] => (Allow) C:\Program Files (x86)\Lexmark\PSU\lmpsu.exe
FirewallRules: [{FE3DC3A7-76E8-43CD-9B00-89F97ABC2FCA}] => (Allow) C:\Program Files (x86)\Lexmark\PSU\lmpsu.exe
FirewallRules: [{34F07FFC-5EFB-4C44-B25D-24F9661CAD9B}] => (Allow) C:\Program Files (x86)\Lexmark\WirelessSetup\LMwpss.exe
FirewallRules: [{75576720-1703-44C4-B8F8-EDFCB7BA1A4C}] => (Allow) C:\Program Files (x86)\Lexmark\WirelessSetup\LMwpss.exe
FirewallRules: [{04508E43-B252-4108-925D-70D229A94253}] => (Allow) C:\Program Files (x86)\Lexmark S510 Series\LMADHmon.exe
FirewallRules: [{9F3453BE-C085-46B3-8773-DDEA2AA7F17D}] => (Allow) C:\Program Files (x86)\Lexmark S510 Series\LMADHmon.exe
FirewallRules: [{247E9401-993F-48D6-B434-367DFD5C2513}] => (Allow) C:\Program Files (x86)\Lexmark S510 Series\LMADHlscn.exe
FirewallRules: [{C3E8E9D3-C2DC-489E-8396-419700B9A1B9}] => (Allow) C:\Program Files (x86)\Lexmark S510 Series\LMADHlscn.exe
FirewallRules: [{A699E37D-40E0-4907-A4FA-29AE6F582103}] => (Allow) C:\Program Files (x86)\Lexmark S510 Series\LMabscw.dll
FirewallRules: [{2B6438D3-9464-4393-8BA3-A838DFA24FF0}] => (Allow) C:\Program Files (x86)\Lexmark S510 Series\LMabscw.dll
FirewallRules: [{7393FBC4-6C07-4446-A1E1-E737CB82CA69}] => (Allow) C:\Program Files (x86)\Lexmark\NetworkTwain\LMZZZ_32__bc.dll
FirewallRules: [{D65227D2-2F6A-4111-AFAC-274BD82FE9AB}] => (Allow) C:\Program Files (x86)\Lexmark\NetworkTwain\LMZZZ_32__bc.dll
FirewallRules: [{63702C73-0667-446B-A9B8-6FBCBF414F0C}] => (Allow) C:\Program Files (x86)\Lexmark\NetworkTwain\LMzzz_32serv.dll
FirewallRules: [{612117C9-6BF6-4CDC-800B-ABA100754B3B}] => (Allow) C:\Program Files (x86)\Lexmark\NetworkTwain\LMzzz_32serv.dll
FirewallRules: [{24D4AA90-7B61-47C3-A8D6-7DAE37B3378D}] => (Allow) C:\Program Files (x86)\Lexmark\NetworkTwain\lextwprotocol.dll
FirewallRules: [{F820CBA7-4EA8-48A7-A370-D6D580AA3C57}] => (Allow) C:\Program Files (x86)\Lexmark\NetworkTwain\lextwprotocol.dll
FirewallRules: [{80172BEA-7843-4FFE-B60B-3C7E6185943B}] => (Allow) C:\Windows\twain_32\Lexmark\NetworkTwain\lexnetworkds.ds
FirewallRules: [{24ECA241-4676-4CD9-B6E0-5683D9990BE1}] => (Allow) C:\Windows\twain_32\Lexmark\NetworkTwain\lexnetworkds.ds
FirewallRules: [TCP Query User{37920E60-7194-42F4-91A2-DA3F8A4BFE94}C:\program files (x86)\lexmark s510 series\lmadhmon.exe] => (Block) C:\program files (x86)\lexmark s510 series\lmadhmon.exe
FirewallRules: [UDP Query User{449C8548-F146-48FE-83E5-9008CA647764}C:\program files (x86)\lexmark s510 series\lmadhmon.exe] => (Block) C:\program files (x86)\lexmark s510 series\lmadhmon.exe
FirewallRules: [TCP Query User{D7FA072F-8042-4A73-8465-E72C081BEA03}C:\users\owner\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\owner\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{E879C056-F84B-4FD5-B7B4-451F7B9E5A8F}C:\users\owner\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\owner\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{98DAAE94-DBB2-4CF0-9ACA-6EEC4CCD0E4C}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe
FirewallRules: [UDP Query User{85CA6375-7CD7-4109-86A8-66F299AEBE10}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe
FirewallRules: [TCP Query User{E60728E1-49E1-4A90-A4C8-63C68982D3CC}C:\program files (x86)\electronic arts\eadm\core.exe] => (Block) C:\program files (x86)\electronic arts\eadm\core.exe
FirewallRules: [UDP Query User{59D7F2AE-4FEE-4081-B07D-2E39644F5C37}C:\program files (x86)\electronic arts\eadm\core.exe] => (Block) C:\program files (x86)\electronic arts\eadm\core.exe
FirewallRules: [{F7EF8DEE-AF3A-4D13-BD45-C2AAFFBA7C48}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5753BE0E-82DC-4DD6-8983-325B162EC127}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{FEC51B15-AD5D-4563-9053-55E3F68A454A}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{63F58DC7-5849-47AF-BC83-497FDF36BC2B}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{CB42CEF5-DB6A-467F-8995-E3A935820014}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{87352A60-E8C3-4E24-81F9-CB833869CBCD}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5B82E452-A19E-481E-923C-C1587FA7F442}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{7E1A515B-F71D-4E68-94E1-E5017D311A15}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{1DABDD7E-5C07-4C2C-A443-493313F0C90F}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{90054C83-EB0D-4904-9E2C-83D7D26839F0}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{D2A42FAA-1E77-4FB9-A8A0-D7E93688F70E}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{CF13E7BF-D662-4E59-8E24-C5669978121E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C06E88AC-ACE8-409F-9C61-87F538371C00}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D30BD46F-AF68-4CEB-B38D-DAA0EDE4AE86}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{3F967478-7E58-4D06-8569-A1CA13271AA3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{68C06107-F749-4A38-84D1-7CDD5540A874}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{5B7CA687-1EC5-4D52-A428-CC1876DADDE3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{B2B2E4A1-9B67-41D3-ABD5-5994E6A51961}] => (Allow) C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
FirewallRules: [{B7F2BFE1-81D6-4555-9D9F-9904913F8635}] => (Allow) C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
FirewallRules: [{879AC841-3BFA-462D-AC63-273580238EBB}] => (Allow) C:\Program Files (x86)\SrpnFiles\downloader.exe
FirewallRules: [{52B67663-FEA8-4050-85DB-9452D511695E}] => (Allow) C:\Program Files (x86)\SrpnFiles\downloader.exe
 
==================== Restore Points =========================
 
18-03-2016 00:42:15 Windows Update
21-03-2016 04:21:33 Windows Update
25-03-2016 01:35:44 Windows Update
26-03-2016 03:00:26 Windows Update
29-03-2016 18:03:39 Windows Update
01-04-2016 21:25:11 Windows Update
05-04-2016 03:11:40 Windows Update
08-04-2016 08:30:56 Windows Update
11-04-2016 17:11:47 Windows Update
14-04-2016 21:09:06 Windows Update
15-04-2016 16:59:05 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/18/2016 09:32:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: jucheck.exe, version: 2.8.60.27, time stamp: 0x55c116b1
Faulting module name: jucheck.exe, version: 2.8.60.27, time stamp: 0x55c116b1
Exception code: 0x40000015
Fault offset: 0x00052d24
Faulting process id: 0x12d8
Faulting application start time: 0xjucheck.exe0
Faulting application path: jucheck.exe1
Faulting module path: jucheck.exe2
Report Id: jucheck.exe3
 
Error: (04/18/2016 09:10:02 AM) (Source: Software Protection Platform Service) (EventID: 1017) (User: )
Description: Installation of the Proof of Purchase failed. 0x80070005
Partial Pkey=CGKHQ
ACID=?
Detailed Error[?]
 
Error: (04/18/2016 09:09:49 AM) (Source: TabletServiceWacom) (EventID: 0) (User: )
Description: Could not init tablet driver
 
Error: (04/18/2016 08:59:54 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Users\Owner\AppData\Local\Temp\{163D0DE3-1426-499B-B7C4-EE58F311E569}\setup.exe -runfromtemp -l0x0409  -removeonly -media_path:"C:\Program Files (x86)\InstallShield Installation Information\{B9291CA2-6FA5-44EA-8EE0-923EB32ADAAB}\" -tempdisk1folder:"C:\Users\Owner\AppData\Local\Temp\{163D0DE3-1426-499B-B7C4-EE58F311E569}\"; Description = Removed Aion; Error = 0x8007043c).
 
Error: (04/18/2016 08:58:56 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Users\Owner\AppData\Local\Temp\{26E67DDF-9B4D-4A58-B48D-9BB732A5AD9E}\setup.exe -runfromtemp -l0x0409  -removeonly -media_path:"C:\Users\Owner\AppData\Local\TERA\" -tempdisk1folder:"C:\Users\Owner\AppData\Local\Temp\{26E67DDF-9B4D-4A58-B48D-9BB732A5AD9E}\"; Description = Removed TERA; Error = 0x8007043c).
 
Error: (04/18/2016 08:32:48 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\servicing\TrustedInstaller.exe; Description = Windows Modules Installer; Error = 0x8007043c).
 
Error: (04/18/2016 08:30:41 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Users\Owner\AppData\Local\Temp\setC966.tmp -deleter -l0x9 -removeonly -your_launchersetup.exe -clone_of"C:\Program Files (x86)\InstallShield Installation Information\{AD3E7141-A22E-40F1-A7A4-55E898AE35E3}\"; Description = Removed VAIO Help and Support; Error = 0x8007043c).
 
Error: (04/18/2016 08:29:48 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Users\Owner\AppData\Local\Temp\{167EA7B3-C942-4111-A8B1-6849EF649110}\setup.exe -removeonly -media_path:"C:\Program Files (x86)\InstallShield Installation Information\{36C5BBF0-E5BF-4DE1-B684-7E90B0C93FB5}\" -tempdisk1folder:"C:\Users\Owner\AppData\Local\Temp\{167EA7B3-C942-4111-A8B1-6849EF649110}\"; Description = Removed VAIO Care; Error = 0x8007043c).
 
Error: (04/16/2016 11:03:00 AM) (Source: MsiInstaller) (EventID: 11316) (User: Owner-VAIO)
Description: Product: Consumer Input Update Helper – Error 1316. The specified account already exists.
 
Error: (04/15/2016 09:05:54 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15553
 
 
System errors:
=============
Error: (04/18/2016 09:34:14 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error: 
%%5
 
Error: (04/18/2016 09:34:14 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The DHCP Client service terminated with the following error: 
%%5
 
Error: (04/18/2016 09:32:58 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error: 
%%1062
 
Error: (04/18/2016 09:32:58 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error: 
%%5
 
Error: (04/18/2016 09:32:58 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The DHCP Client service terminated with the following error: 
%%5
 
Error: (04/18/2016 09:32:42 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error: 
%%5
 
Error: (04/18/2016 09:32:42 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The DHCP Client service terminated with the following error: 
%%5
 
Error: (04/18/2016 09:23:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error: 
%%5
 
Error: (04/18/2016 09:23:16 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The DHCP Client service terminated with the following error: 
%%5
 
Error: (04/18/2016 09:23:15 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error: 
%%5
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ II P360 Dual-Core Processor
Percentage of memory in use: 56%
Total physical RAM: 3834.9 MB
Available physical RAM: 1667.21 MB
Total Virtual: 7667.98 MB
Available Virtual: 5408.54 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:456.11 GB) (Free:296.85 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 409AC7FB)
Partition 1: (Not Active) - (Size=9.5 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=456.1 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
Thank you so much for your time and help!
 
 
Hello and    :welcome:
 
My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret.  Please be patient while I review your logs. 
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you.  Topics with no reply in 4 days are closed!
 
While I review the logs you've posted, please do the following:
 
MGA Diagnostics
 
  • Please download and save the following tool to your desktop Link
  • Right-click on MGADiag.exe and select Run as Administrator.
  • Select Continue.  The diagnosis will now begin.
  • When the process is over, click Copy.
  • Open Notepad and paste the contents.
  • Save this file as MGADiag.txt.
  • Post the content on MGADiag.txt in your next reply.

Thank you so much for your help!  I haven't noticed any other infections, but I am kinda worried that something might be lurking, ya know?

Here is the log you requested:

Diagnostic Report (1.9.0027.0):
—————————————–
Windows Validation Data–>
 
Validation Code: 50
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-VGV87-C7XPK-CGKHQ
Windows Product Key Hash: sdEjrEJjW0FuXAhegYxl8GAkBYg=
Windows Product ID: 00359-OEM-8992687-00016
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: {68C82D3D-118F-4950-99CB-9A8F3B120195}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_ldr.160317-0600
TTS Error: 
Validation Diagnostic: 
Resolution Status: N/A
 
Vista WgaER Data–>
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
 
Windows XP Notifications Data–>
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
 
OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
 
OGA Data–>
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
 
Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Download signed ActiveX controls: Disabled
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
 
File Scan Data–>
 
Other data–>
Office Details: {68C82D3D-118F-4950-99CB-9A8F3B120195}1.9.0027.06.1.7601.2.00010300.1.0.003x64*****-*****-*****-*****-CGKHQ00359-OEM-8992687-000162S-1-5-21-2212292319-1339573239-2403685339Sony CorporationVPCEE41FXInsyde Corp.R0200Z520101209000000.000000+00082493507018400F404090409Mountain Standard Time(GMT-07:00)03SonyVAIO109  
 
Spsys.log Content: 0x80070002
 
Licensing Data–>
On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0xC004F012' to display the error text.
Error: 0xC004F012 
 
Windows Activation Technologies–>
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 2:15:2016 14:50
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
 
 
HWID Data–>
HWID Hash Current: NAAAAAEAAwABAAEAAAACAAAAAwABAAEA6GFy7O5niC0+thAz/EvAO5gvmg/8LOKKrBEYeQ==
 
OEM Activation 1.0 Data–>
N/A
 
OEM Activation 2.0 Data–>
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information: 
  ACPI Table Name OEMID Value OEMTableID Value
  APIC Sony VAIO
  FACP Sony VAIO
  HPET Sony VAIO
  BOOT Sony VAIO
  MCFG Sony VAIO
  SLIC Sony VAIO
  SSDT Sony VAIO
 
 

Also, microsoft security essentials keeps popping up saying there is a trojan on the pc, but I haven't touched anything.  I figured its best to wait on you.

Before we address any possible remaining malware issues, let's address your Windows Validation first. 
 
If you haven't already done so, please locate the Windows Product Key for your machine. Normally this product key is on a sticker on your computer or located with the manual or on the disc sleeve that came with Windows 7. 
 
  • Click the Start button > right-click Computer > click Properties
  • Scroll down to the bottom of the window that appears, and then, under Windows activation, click Change product key
  • If you're prompted for permission to continue the process, click Continue
  • Follow the instructions to enter your product key and activate your copy of Windows 7
 
If you are able to successfully activate using your Product Key, please reboot (for good measure) and rerun another MGA Diagnostic report posting the fresh results in your reply.
 
If you are not able to successfully activate using your product key, or you no longer have access to your product key, please let me know.
 

So I have my product key.  Its on the bottom of my laptop.  Unfortunately I can't enter it into the section.  I uploaded a picture of the screen to imgur: http://imgur.com/3tqvUVV

 

Clicking on the button takes me to a useless website about what genuine windows actually is and stuff.

Here you go. Although nothing has been done between the last one I posted and now.  

 

MGAdiag2:

Diagnostic Report (1.9.0027.0):
—————————————–
Windows Validation Data–>
 
Validation Code: 50
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-VGV87-C7XPK-CGKHQ
Windows Product Key Hash: sdEjrEJjW0FuXAhegYxl8GAkBYg=
Windows Product ID: 00359-OEM-8992687-00016
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: {68C82D3D-118F-4950-99CB-9A8F3B120195}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_ldr.160317-0600
TTS Error: 
Validation Diagnostic: 
Resolution Status: N/A
 
Vista WgaER Data–>
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
 
Windows XP Notifications Data–>
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
 
OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
 
OGA Data–>
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-
 
80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
 
Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Download signed ActiveX controls: Disabled
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
 
File Scan Data–>
 
Other data–>
Office Details: {68C82D3D-118F-4950-99CB-9A8F3B120195}
 
1.9.0027.06.1.7601.2.00010300.1.0.003x64
 
e>*****-*****-*****-*****-CGKHQ00359-OEM-8992687-
 
000162S-1-5-21-2212292319-1339573239-
 
2403685339Sony 
 
CorporationVPCEE41FXInsyde 
 
Corp.R0200Z5
 
minor="6"/>20101209000000.000000+00082493507018400F40409
 
erLCID>0409Mountain Standard Time(GMT-07:00)
 
03
 
>SonyVAIO
 
>109  
 
Spsys.log Content: 0x80070002
 
Licensing Data–>
On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0xC004F012' to display the 
 
error text.
Error: 0xC004F012 
 
Windows Activation Technologies–>
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 2:15:2016 14:50
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
 
 
HWID Data–>
HWID Hash Current: NAAAAAEAAwABAAEAAAACAAAAAwABAAEA6GFy7O5niC0+thAz/EvAO5gvmg/8LOKKrBEYeQ==
 
OEM Activation 1.0 Data–>
N/A
 
OEM Activation 2.0 Data–>
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information: 
  ACPI Table Name OEMID Value OEMTableID Value
  APIC Sony VAIO
  FACP Sony VAIO
  HPET Sony VAIO
  BOOT Sony VAIO
  MCFG Sony VAIO
  SLIC Sony VAIO
  SSDT Sony VAIO
 
I should add that the key listed on the properties page is nothing like the one on my laptop.

It's fine that the keys don't match. The one shown in your image is the OEM key that gets installed at the factory (and is used on many machines). These keys can stop being detected automatically for any number of reasons (from system upgrades to malware). The other 25 digit key you have located on your machine (and you SHOULD NOT post that key publicly) is your Certificate of Authenticity (COA) key. It can only be used a certain number of times for activation and is specific to your machine. You'll want to safeguard that key.

(Note: For security, the diagnostic log does not display your full COA key, and I will not ask you for the full key at any time.)

 

The OEM key matches your Sony Vaio. In theory, we should be able to change the code to the COA key for activation. However, there is a line in your report that concerns me, knowing that you recently removed malware immediately prior to this issue starting. I do need to do a little more research to ensure we don't need to do some registry fixes as well.

 

We do need to make sure we get Windows to properly recognize activation so you can get all your Windows Updates. After that, we can remove the remnants of what needs to be cleaned up. Please be patient while to do some further research and I'll be back with what we need to do next.

Awesome!  You are amazing!  Thank you so much for all the work you are putting in for me!  I will be here refreshing like a maniac till then, haha.  Thank you for sticking with such a silly issue.  Again, thanks.  You rock so much.

 

And for clarity's sake, the issue with the invalid key happened with the malware, and I'm still getting consistent popups about malware still on the laptop.  So I know that issue is present as well, but I'm sure you know the best route to take.  Keep on rocking!

First, let's check your Active X settings in Internet Explorer. Some of these appear to be disabled and it could possibly interfere with proper Windows Validation.

 

  1. Open Internet Explorer.

  2. Click the Tools menu, and then click Internet Options.

  3. On the Security tab, click the Custom level button.

  4. Scroll down the Security Settings list until you see ActiveX controls and plug-ins.

  5. For Automatic prompting for ActiveX controls, click Enable.

  6. Scroll down to Download signed ActiveX controls and click Enable or Prompt.

  7. Scroll down to Run ActiveX controls and plug-ins and click Enable or Prompt.

  8. Scroll down to Script ActiveX controls marked safe for scripting and click Enable or Prompt.

  9. Click OK, and then click OK again.

 

I know this may get a little repetitive, but the error code your report shows can be caused by a few different issues. I'd like to try the least invasive solutions first.

 

Please post a fresh MGA Diagnostic report after completing these steps.

Ok!  Here is the log from the latest run.

Diagnostic Report (1.9.0027.0):
—————————————–
Windows Validation Data–>
 
Validation Code: 50
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-VGV87-C7XPK-CGKHQ
Windows Product Key Hash: sdEjrEJjW0FuXAhegYxl8GAkBYg=
Windows Product ID: 00359-OEM-8992687-00016
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: {68C82D3D-118F-4950-99CB-9A8F3B120195}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_ldr.160317-0600
TTS Error: 
Validation Diagnostic: 
Resolution Status: N/A
 
Vista WgaER Data–>
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
 
Windows XP Notifications Data–>
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
 
OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
 
OGA Data–>
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
 
Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Download signed ActiveX controls: Disabled
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
 
File Scan Data–>
 
Other data–>
Office Details: {68C82D3D-118F-4950-99CB-9A8F3B120195}1.9.0027.06.1.7601.2.00010300.1.0.003x64*****-*****-*****-*****-CGKHQ00359-OEM-8992687-000162S-1-5-21-2212292319-1339573239-2403685339Sony CorporationVPCEE41FXInsyde Corp.R0200Z520101209000000.000000+00082493507018400F404090409Mountain Standard Time(GMT-07:00)03SonyVAIO109  
 
Spsys.log Content: 0x80070002
 
Licensing Data–>
On a computer running Microsoft Windows non-core edition, run 'slui.exe 0x2a 0xC004F012' to display the error text.
Error: 0xC004F012 
 
Windows Activation Technologies–>
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 2:15:2016 14:50
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
 
 
HWID Data–>
HWID Hash Current: NAAAAAEAAwABAAEAAAACAAAAAwABAAEA6GFy7O5niC0+thAz/EvAO5gvmg/8LOKKrBEYeQ==
 
OEM Activation 1.0 Data–>
N/A
 
OEM Activation 2.0 Data–>
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information: 
  ACPI Table Name OEMID Value OEMTableID Value
  APIC Sony VAIO
  FACP Sony VAIO
  HPET Sony VAIO
  BOOT Sony VAIO
  MCFG Sony VAIO
  SLIC Sony VAIO
  SSDT Sony VAIO
 
 
The only option that needed to be changed was the first one, the rest were already set.  Thanks again for your help!

We're going to rebuild the Licensing Store:

  1. Start an elevated command prompt. To do this, follow these steps:
    1. Click Start, and then type cmd in the search box.
    2. Right-click cmd, and then click Run as Administrator.
  2. Type the following commands (listed in bold) in the order in which they are presented.
    Press Enter after each command.
    net stop sppsvc <—If it asks if you're sure, select yes
    Note: the Software Protection Service may not be running, this is ok.

     
  3. cd %windir%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform 

    ren tokens.dat tokens.bar 

    net start sppsvc 

    cscript.exe %windir%\system32\slmgr.vbs /rilc
     
  4. Restart the computer.

Right-click Computer > Properties > Change product key

Note: Your COA key may require activation by phone (this is not unusual when you are changing the key from OEM to COA. If activation via the above steps is unsuccessful, AND you are presented with a screen for other options on activation, please look for one to activate via automated phone system. You'll be asked for your location and then given a call center phone number.

​
Please reboot and then post a fresh MGA Diagnostic log. If for any reason you are unable to complete these steps successfully please let me know.

 

So, I couldn't attempt to activate windows because it was already activated upon reboot.  So yay!  That is resolved.  Here is the log you requested:

 

MGADiag3:

Diagnostic Report (1.9.0027.0):
—————————————–
Windows Validation Data–>
 
Validation Code: 0
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-VGV87-C7XPK-CGKHQ
Windows Product Key Hash: sdEjrEJjW0FuXAhegYxl8GAkBYg=
Windows Product ID: 00359-OEM-8992687-00016
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: {68C82D3D-118F-4950-99CB-9A8F3B120195}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_ldr.160317-0600
TTS Error: 
Validation Diagnostic: 
Resolution Status: N/A
 
Vista WgaER Data–>
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
 
Windows XP Notifications Data–>
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
 
OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
 
OGA Data–>
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
 
Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Download signed ActiveX controls: Disabled
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
 
File Scan Data–>
 
Other data–>
Office Details: {68C82D3D-118F-4950-99CB-9A8F3B120195}1.9.0027.06.1.7601.2.00010300.1.0.003x64*****-*****-*****-*****-CGKHQ00359-OEM-8992687-000162S-1-5-21-2212292319-1339573239-2403685339Sony CorporationVPCEE41FXInsyde Corp.R0200Z520101209000000.000000+00082493507018400F404090409Mountain Standard Time(GMT-07:00)03SonyVAIO109  
 
Spsys.log Content: 0x80070002
 
Licensing Data–>
Software licensing service version: 6.1.7601.17514
 
Name: Windows(R) 7, HomePremium edition
Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
Activation ID: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00359-00178-926-800016-02-1033-7601.0000-1112016
Installation ID: 004063151224770930327525408454798315863761015551270815
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: CGKHQ
License Status: Licensed
Remaining Windows rearm count: 4
Trusted time: 4/20/2016 6:04:58 PM
 
Windows Activation Technologies–>
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 2:15:2016 14:50
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
 
 
HWID Data–>
HWID Hash Current: NAAAAAEAAwABAAEAAAACAAAAAwABAAEA6GFy7O5niC0+thAz/EvAO5gvmg/8LOKKrBEYeQ==
 
OEM Activation 1.0 Data–>
N/A
 
OEM Activation 2.0 Data–>
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information: 
  ACPI Table Name OEMID Value OEMTableID Value
  APIC Sony VAIO
  FACP Sony VAIO
  HPET Sony VAIO
  BOOT Sony VAIO
  MCFG Sony VAIO
  SLIC Sony VAIO
  SSDT Sony VAIO
 
Did you happen to notice any infections?  I was getting pop ups about a trojan earlier.  Should I run another virus scan?

I'm glad we were able to get your product back to licensed status! There are a few things that need to be addressed now:

 

 

Fix with FRST (normal mode)
  • Open notepad (Start =>All Programs => Accessories => Notepad).
  • Please copy the entire contents of the code box below.
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
  • Save it to the same directory as frst.exe (or frst64.exe) as fixlist.txt.Open notepad. e this into the open notepad. 
 
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
 
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
 
U2 IAStorDataMgrSvc; no ImagePath
U2 MSSQL$DDNI; no ImagePath
 
C:\Users\Owner\AppData\Local\Temp\EAD1C17.exe
C:\Users\Owner\AppData\Local\Temp\EAD254B.exe
C:\Users\Owner\AppData\Local\Temp\EAD2838.exe
C:\Users\Owner\AppData\Local\Temp\EAD369.exe
C:\Users\Owner\AppData\Local\Temp\EAD3F31.exe
C:\Users\Owner\AppData\Local\Temp\EAD6FB3.exe
C:\Users\Owner\AppData\Local\Temp\EAD8E5.exe
C:\Users\Owner\AppData\Local\Temp\EADF9A9.exe
C:\Users\Owner\AppData\Local\Temp\i4jdel0.exe
C:\Users\Owner\AppData\Local\Temp\i7FbB4Tr1u.exe
C:\Users\Owner\AppData\Local\Temp\JNL0dxjqko.exe
C:\Users\Owner\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u51-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u73-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\MSN3B1E.exe
C:\Users\Owner\AppData\Local\Temp\nb8knocy.dll
C:\Users\Owner\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Owner\AppData\Local\Temp\xzhOtGfLMo.exe
C:\Users\Owner\AppData\Local\Temp\Y2CbLGIyip.exe
C:\Users\Owner\AppData\Local\Temp\yu5iEn8UzC.exe
 
Task: {05EA6B03-C37D-4AD1-BA96-EFC4A4CDDA70} - \StartPoint -> No File <==== ATTENTION
Task: {4E7E5A7C-C174-43A0-8052-7245972BE631} - \StartPoint Updater -> No File <==== ATTENTION
Task: {7337D2C6-A80F-4D7C-BE3B-D1136175FD97} - System32\Tasks\Telni => C:\PROGRA~1\Faxci\Saesu.bat <==== ATTENTION
 
AlternateDataStreams: C:\Windows\system32\Drivers\bwsojnng.sys:changelist [1282]
AlternateDataStreams: C:\Windows\system32\Drivers\kuzmlcql.sys:changelist [1282]
 
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 
Run frst.exe (on 64bit, run frst64.exe) and press the Fix button just once and wait.
The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.
 
Please reboot the computer again after this step, and let me know how the system is behaving at this point. 

Awesome, here is the log

Fix result of Farbar Recovery Scan Tool (x64) Version:18-04-2016
Ran by [removed] (2016-04-20 21:07:56) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
 
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
 
U2 IAStorDataMgrSvc; no ImagePath
U2 MSSQL$DDNI; no ImagePath
 
C:\Users\Owner\AppData\Local\Temp\EAD1C17.exe
C:\Users\Owner\AppData\Local\Temp\EAD254B.exe
C:\Users\Owner\AppData\Local\Temp\EAD2838.exe
C:\Users\Owner\AppData\Local\Temp\EAD369.exe
C:\Users\Owner\AppData\Local\Temp\EAD3F31.exe
C:\Users\Owner\AppData\Local\Temp\EAD6FB3.exe
C:\Users\Owner\AppData\Local\Temp\EAD8E5.exe
C:\Users\Owner\AppData\Local\Temp\EADF9A9.exe
C:\Users\Owner\AppData\Local\Temp\i4jdel0.exe
C:\Users\Owner\AppData\Local\Temp\i7FbB4Tr1u.exe
C:\Users\Owner\AppData\Local\Temp\JNL0dxjqko.exe
C:\Users\Owner\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u51-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u73-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\MSN3B1E.exe
C:\Users\Owner\AppData\Local\Temp\nb8knocy.dll
C:\Users\Owner\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Owner\AppData\Local\Temp\xzhOtGfLMo.exe
C:\Users\Owner\AppData\Local\Temp\Y2CbLGIyip.exe
C:\Users\Owner\AppData\Local\Temp\yu5iEn8UzC.exe
 
Task: {05EA6B03-C37D-4AD1-BA96-EFC4A4CDDA70} - \StartPoint -> No File <==== ATTENTION
Task: {4E7E5A7C-C174-43A0-8052-7245972BE631} - \StartPoint Updater -> No File <==== ATTENTION
Task: {7337D2C6-A80F-4D7C-BE3B-D1136175FD97} - System32\Tasks\Telni => C:\PROGRA~1\Faxci\Saesu.bat <==== ATTENTION
 
AlternateDataStreams: C:\Windows\system32\Drivers\bwsojnng.sys:changelist [1282]
AlternateDataStreams: C:\Windows\system32\Drivers\kuzmlcql.sys:changelist [1282]
*****************
 
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-2212292319-1339573239-2403685339-1005\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
IAStorDataMgrSvc => service removed successfully
MSSQL$DDNI => service removed successfully
C:\Users\Owner\AppData\Local\Temp\EAD1C17.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\EAD254B.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\EAD2838.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\EAD369.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\EAD3F31.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\EAD6FB3.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\EAD8E5.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\EADF9A9.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\i4jdel0.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\i7FbB4Tr1u.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\JNL0dxjqko.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\jre-8u51-windows-au.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\jre-8u60-windows-au.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\jre-8u73-windows-au.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\jre-8u77-windows-au.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\MSN3B1E.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\nb8knocy.dll => moved successfully
C:\Users\Owner\AppData\Local\Temp\UninstallEADM.dll => moved successfully
C:\Users\Owner\AppData\Local\Temp\xzhOtGfLMo.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\Y2CbLGIyip.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\yu5iEn8UzC.exe => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{05EA6B03-C37D-4AD1-BA96-EFC4A4CDDA70}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{05EA6B03-C37D-4AD1-BA96-EFC4A4CDDA70}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\StartPoint => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4E7E5A7C-C174-43A0-8052-7245972BE631}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E7E5A7C-C174-43A0-8052-7245972BE631}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\StartPoint Updater => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7337D2C6-A80F-4D7C-BE3B-D1136175FD97}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7337D2C6-A80F-4D7C-BE3B-D1136175FD97}" => key removed successfully
C:\Windows\System32\Tasks\Telni => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Telni" => key removed successfully
"C:\Windows\system32\Drivers\bwsojnng.sys" => ":changelist" ADS not found.
"C:\Windows\system32\Drivers\kuzmlcql.sys" => ":changelist" ADS not found.
 
==== End of Fixlog 21:08:11 ====

 

So I am getting a terraclicks redirect each time i open Chrome.  My settings are to pick up where I left off when I close chrome, but this tab keeps reopening regardless of how much I close it whenever I relaunch Chrome.  I haven't noticed anything else weird though.  So yay for that!  Thanks for you help!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI