HP Compaq 8000 running Win 7 Pro
slow startup, slow operation , it appears the C drive disk space used has grown in size, screen display changes in mid use sometimes
aswMBR and FRST results pasted below,
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-07-18 16:36:57
—————————–
16:36:57.186 OS Version: Windows 6.1.7601 Service Pack 1
16:36:57.196 Number of processors: 2 586 0x170A
16:36:57.196 ComputerName: PC-MXL0280 UserName: jndinonno
16:37:56.706 Initialize success
16:37:57.198 VM: initialized successfully
16:37:57.208 VM: Intel CPU BiosDisabled
16:40:14.476 AVAST engine defs: 16071801
16:42:35.736 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4
16:42:35.746 Disk 0 Vendor: HDS728080PLA380 PF2OA63A Size: 76293MB BusType: 11
16:42:35.896 Disk 0 MBR read successfully
16:42:35.906 Disk 0 MBR scan
16:42:36.028 Disk 0 Windows 7 default MBR code
16:42:36.048 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 6000 MB offset 2048
16:42:36.078 Disk 0 default boot code
16:42:36.185 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 70291 MB offset 12290048
16:42:36.270 Disk 0 scanning sectors +156247952
16:42:36.503 Disk 0 scanning C:\windows\system32\drivers
16:43:04.237 Service scanning
16:43:24.008 Service MpKsl41b11dbf c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D158A5B6-59D3-40C0-A5B8-5B668C88B6DC}\MpKsl41b11dbf.sys **LOCKED** 32
16:43:43.637 Modules scanning
16:43:43.637 Disk 0 trace - called modules:
16:43:43.647 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys
16:43:43.647 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85c3a228]
16:43:43.647 3 CLASSPNP.SYS[88dc659e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0x85723908]
16:43:44.077 AVAST engine scan C:\windows
16:43:47.009 AVAST engine scan C:\windows\system32
16:48:52.623 AVAST engine scan C:\windows\system32\drivers
16:49:17.276 AVAST engine scan C:\Users\jndinonno
16:52:04.085 Disk 0 MBR has been saved successfully to "C:\Users\jndinonno\Desktop\MBR.dat"
16:52:04.125 The log file has been saved successfully to "C:\Users\jndinonno\Desktop\aswMBR.txt"
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-07-2016
Ran by [removed] (administrator) on PC-MXL0280 (18-07-2016 16:55:08)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgcsrvx.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgwdsvcx.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgui.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgemcx.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_21_0_0_242_ActiveX.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\…\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguirnx.exe [186640 2016-06-21] (AVG Technologies CZ, s.r.o.)
HKLM\…\Run: [AVG_UI] => C:\Program Files\AVG\Av\avgui.exe [5351184 2016-06-29] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\…\MountPoints2: D - D:\Autorun.exe
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\…\MountPoints2: {5aec79a5-ad61-11e5-b3fd-0023240a3369} - J:\LaunchU3.exe -a
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\ssText3d.scr [293888 2010-11-20] (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: [S-1-5-21-4252558748-1657619972-2942562243-1001] => localhost:8080
AutoConfigURL: [S-1-5-21-4252558748-1657619972-2942562243-1001] => localhost:8080
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{55D1C7AC-33B4-4BD8-B4DC-A42D2B45F190}: [DhcpNameServer] 192.168.1.254
Internet Explorer:
==================
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpage.com/
SearchScopes: HKU\S-1-5-21-4252558748-1657619972-2942562243-1001 -> DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://search.yahoo.com/search?ei=ISO-8859-1&fr;=chr-vmn&type;=egames3_1yach&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-4252558748-1657619972-2942562243-1001 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://search.yahoo.com/search?ei=ISO-8859-1&fr;=chr-vmn&type;=egames3_1yach&q;={searchTerms}
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_77\bin\ssv.dll [2016-04-18] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-18] (Oracle Corporation)
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} hxxp://www.shockwave.com/content/zuma/sis/popcaploader_v10.cab
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_11_5_502_118.dll [2015-01-25] ()
FF Plugin: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-18] (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2012-12-12] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-19]
CHR Extension: (Google Drive) - C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-19]
CHR Extension: (YouTube) - C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-03-19]
CHR Extension: (Gmail) - C:\Users\jndinonno\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-19]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AvgAMPS; C:\Program Files\AVG\Av\avgamps.exe [637944 2016-06-29] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files\AVG\Av\avgidsagent.exe [4092672 2016-06-29] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [890128 2016-06-21] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\Av\avgwdsvcx.exe [594904 2016-06-29] (AVG Technologies CZ, s.r.o.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 Avgdiskx; C:\windows\System32\DRIVERS\avgdiskx.sys [134912 2016-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\windows\System32\DRIVERS\avgidsdriverx.sys [255744 2016-06-09] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\windows\System32\DRIVERS\avgidshx.sys [201472 2016-06-01] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\windows\System32\DRIVERS\avgidsshimx.sys [31664 2015-11-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\windows\System32\DRIVERS\avgldx86.sys [212736 2016-06-01] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\windows\System32\DRIVERS\avglogx.sys [287008 2016-02-16] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\windows\System32\DRIVERS\avgmfx86.sys [191744 2016-06-02] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\windows\System32\DRIVERS\avgrkx86.sys [47360 2016-06-01] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\windows\System32\DRIVERS\avgtdix.sys [217344 2016-06-01] (AVG Technologies CZ, s.r.o.)
R0 Avgunivx; C:\windows\System32\DRIVERS\avgunivx.sys [65280 2016-06-01] (AVG Technologies CZ, s.r.o.)
S3 EsgScanner; C:\windows\System32\DRIVERS\EsgScanner.sys [19984 2016-01-18] ()
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R1 MpKsl41b11dbf; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D158A5B6-59D3-40C0-A5B8-5B668C88B6DC}\MpKsl41b11dbf.sys [39168 2016-07-18] (Microsoft Corporation)
S3 MxEF; C:\windows\system32\drivers\MxEF32.sys [81920 2011-08-15] (Matrox Graphics Inc.)
S3 MxEFLF; C:\windows\system32\drivers\MxEFLF32.sys [80384 2011-08-15] (Matrox Graphics Inc.)
S3 MxEFUF; C:\windows\system32\drivers\MxEFUF32.sys [108544 2011-08-15] (Matrox Graphics Inc.)
S3 MxEMgr; C:\windows\system32\drivers\MxEMgr32.sys [92192 2011-08-16] (Matrox Graphics Inc.)
S3 SWDUMon; C:\windows\System32\DRIVERS\SWDUMon.sys [22728 2016-04-18] (SlimWare Utilities, Inc.)
S3 RtlWlanu; system32\DRIVERS\rtwlanu.sys [X]
U3 aswMBR; \??\C:\Users\JNDINO~1\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\JNDINO~1\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-18 16:54 - 2016-07-18 16:54 - 00022441 _____ C:\Users\jndinonno\Desktop\Addition.txt
2016-07-18 16:53 - 2016-07-18 16:55 - 00010041 _____ C:\Users\jndinonno\Desktop\FRST.txt
2016-07-18 16:53 - 2016-07-18 16:55 - 00000000 ____D C:\FRST
2016-07-18 16:52 - 2016-07-18 16:52 - 00002103 _____ C:\Users\jndinonno\Desktop\aswMBR.txt
2016-07-18 16:52 - 2016-07-18 16:52 - 00000512 _____ C:\Users\jndinonno\Desktop\MBR.dat
2016-07-18 16:35 - 2016-07-18 16:35 - 01741824 _____ (Farbar) C:\Users\jndinonno\Desktop\FRST.exe
2016-07-18 16:32 - 2016-07-18 16:32 - 05198336 _____ (AVAST Software) C:\Users\jndinonno\Desktop\aswMBR.exe
2016-07-18 16:31 - 2016-07-18 16:31 - 05198336 _____ (AVAST Software) C:\Users\jndinonno\Downloads\aswMBR.exe
2016-07-10 16:08 - 2016-07-10 16:08 - 00688992 _____ (Swearware) C:\Users\jndinonno\Downloads\dds.scr
2016-07-10 15:43 - 2016-07-10 15:43 - 00000000 ____D C:\Users\jndinonno\AppData\Roaming\SparkTrust
2016-07-10 15:42 - 2016-07-10 15:58 - 00000000 ____D C:\ProgramData\SparkTrust
2016-07-10 14:49 - 2016-07-10 14:49 - 00000000 ____D C:\Users\jndinonno\AppData\Roaming\Panda Security
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-07-18 16:11 - 2009-07-13 23:34 - 00025680 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-07-18 16:11 - 2009-07-13 23:34 - 00025680 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-07-18 16:09 - 2015-09-15 16:20 - 00000000 ____D C:\ProgramData\MFAData
2016-07-18 16:04 - 2009-07-13 23:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-07-15 16:41 - 2016-01-28 18:12 - 00000913 _____ C:\Users\Public\Desktop\AVG Protection.lnk
2016-07-15 16:41 - 2016-01-28 18:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2016-07-14 17:28 - 2016-04-04 15:22 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-07-13 16:05 - 2010-11-20 16:01 - 00713888 _____ C:\windows\system32\PerfStringBackup.INI
2016-07-13 16:05 - 2009-07-13 21:37 - 00000000 ____D C:\windows\inf
2016-07-10 15:35 - 2015-11-08 08:51 - 00000000 ____D C:\Users\jndinonno\AppData\Local\AvgSetupLog
2016-07-10 15:05 - 2015-03-14 17:12 - 00069488 _____ C:\Users\jndinonno\AppData\Local\GDIPFONTCACHEV1.DAT
2016-07-10 15:05 - 2009-07-13 23:33 - 00320768 _____ C:\windows\system32\FNTCACHE.DAT
2016-07-10 15:02 - 2015-03-14 12:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
2016-07-10 15:01 - 2015-03-14 12:47 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-07-06 19:39 - 2015-01-25 10:28 - 00400552 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2016-06-19 17:28 - 2016-05-11 20:54 - 00000906 _____ C:\windows\Rtcwplat.INI
2016-06-19 17:27 - 2016-05-11 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Return to Castle Wolfenstein - Platinum Edition
==================== Files in the root of some directories =======
2015-09-15 15:56 - 2015-09-15 15:56 - 6420480 _____ () C:\Program Files\GUTAC46.tmp
2016-07-10 15:43 - 2016-07-10 15:57 - 0000115 _____ () C:\Users\jndinonno\AppData\Roaming\LogFile.txt
2015-07-04 15:14 - 2015-07-04 17:51 - 0001462 _____ () C:\Users\jndinonno\AppData\Local\seed.log
Some files in TEMP:
====================
C:\Users\jndinonno\AppData\Local\Temp\avguirn_081822105457.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_082005766906.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_08678561444.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_08875019647.exe
C:\Users\jndinonno\AppData\Local\Temp\avguirn_0894033522.exe
C:\Users\jndinonno\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\jndinonno\AppData\Local\Temp\{488B1925-1C11-4BD2-B75E-6C0B09FE41BA}.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-07-08 18:10
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 18-07-2016
Ran by [removed] (2016-07-18 16:55:26)
Running from C:\Users\[removed]\Desktop
Microsoft Windows 7 Professional Service Pack 1 (X86) (2015-03-14 16:42:26)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-4252558748-1657619972-2942562243-500 - Administrator - Disabled)
Guest (S-1-5-21-4252558748-1657619972-2942562243-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4252558748-1657619972-2942562243-1003 - Limited - Enabled)
jndinonno (S-1-5-21-4252558748-1657619972-2942562243-1001 - Administrator - Enabled) => C:\Users\jndinonno
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AV: AVG AntiVirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC (HKLM\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20050 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM\…\Adobe Flash Player Plugin) (Version: 11.5.502.118 - Adobe Systems Incorporated)
Adobe Flash Player 21 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 21.0.0.242 - Adobe Systems Incorporated)
AVG (Version: 16.91.7688 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4627 - AVG Technologies) Hidden
AVG Protection (HKLM\…\AVG) (Version: 2016.91.7688 - AVG Technologies)
FMW 1 (Version: 1.102.4 - AVG Technologies) Hidden
Google Update Helper (Version: 1.3.21.115 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2555 - Intel Corporation)
Java 8 Update 77 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation)
K-Lite Mega Codec Pack 9.4.0 (HKLM\…\KLiteCodecPack_is1) (Version: 9.4.0 - )
LibreOffice 4.0.0.3 (HKLM\…\{8EA569F1-97AF-4C3E-A0CB-4846C2D35A81}) (Version: 4.0.0.3 - The Document Foundation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\…\{CA8A885F-E95B-3FC6-BB91-F4D9377C7686}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
NVIDIA PhysX (HKLM\…\{1C4551A6-4743-4093-91E4-1477CD655043}) (Version: 9.09.0203 - NVIDIA Corporation)
Visual Studio 2012 x86 Redistributables (HKLM\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.5 (HKLM\…\VLC media player) (Version: 2.0.5 - VideoLAN)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {3EDD6BE6-F18D-4529-BCB8-A88C127C5C2A} - System32\Tasks\{549ADB0D-5803-4C05-8230-C578E9C45DB2} => pcalua.exe -a D:\AUTORUN.EXE -d D:\
Task: {530552B9-0625-4250-9849-47BBF657EAB7} - System32\Tasks\{B3D02667-810A-45E4-9121-17F064257326} => pcalua.exe -a D:\Launch.exe -d D:\
Task: {7E711CFB-10BA-4E2D-BE49-9F779681CB68} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {89004A4F-D66C-4B28-A59B-DC5372E1DD88} - System32\Tasks\{28A0B97E-FE6D-46D8-A747-D76974ABB84A} => pcalua.exe -a D:\setup\rsrc\Autorun.exe -d D:\
Task: {983A35D8-28B4-4CCB-B9E8-5930BDF6064C} - System32\Tasks\{01A390F8-7802-4C2C-8C9E-0F64AAF1140C} => pcalua.exe -a D:\Launch.exe -d D:\
Task: {BB91FA11-EA2B-4E11-B536-6689F7149523} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2016-03-20] (Oracle Corporation)
Task: {D451111B-DAB4-4BE1-9053-DC026CEE44EA} - System32\Tasks\{8D36B067-EA32-4531-B04B-41712C5B7BAD} => pcalua.exe -a D:\setup\rsrc\Autorun.exe -d D:\
Task: {FCE9D161-145E-4CB2-B309-BBAFB41D2636} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\jndinonno\AppData\Local\Microsoft\Windows\GameExplorer\{5259B043-6F4D-4B1F-907F-F17C15BD6AF7}\SupportTasks\1\Support.lnk -> hxxp://techsupport.ea.com/
Shortcut: C:\Users\jndinonno\AppData\Local\Microsoft\Windows\GameExplorer\{5259B043-6F4D-4B1F-907F-F17C15BD6AF7}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.battlefieldvietnam.ea.com/
==================== Loaded Modules (Whitelisted) ==============
2016-01-28 18:10 - 2016-04-13 12:37 - 40500224 _____ () C:\Program Files\AVG\UiDll\2171\libcef.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 21:04 - 2009-06-10 16:39 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4252558748-1657619972-2942562243-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\jndinonno\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{EF2159CE-4E19-4DE3-8063-A630701BC948}] => (Allow) LPort=1542
FirewallRules: [{972078FE-F776-4B4B-A319-CA631CA5FF79}] => (Allow) LPort=1542
FirewallRules: [{24C123BC-4266-41EA-878E-64B4DF235E2A}] => (Allow) LPort=53
FirewallRules: [{DCACB5AA-6AEA-4E81-B88C-E7553C89CB66}] => (Allow) LPort=67
FirewallRules: [{C57F6107-AD8B-4DD6-9606-6021CC00ABE3}] => (Allow) LPort=68
FirewallRules: [{FAC73D9E-E0DB-4DFC-9E2B-293DC9CD4F4E}] => (Allow) LPort=53
FirewallRules: [{1D589291-6FFD-43E4-9F43-083C82617AA3}] => (Allow) LPort=53
FirewallRules: [TCP Query User{DE6B0BF0-CD67-4A1C-A182-D3BA48D05B55}C:\program files\ea games\mohaa\moh_breakthrough.exe] => (Allow) C:\program files\ea games\mohaa\moh_breakthrough.exe
FirewallRules: [UDP Query User{508449E1-7C7D-4CC7-8829-2B8F454C36C2}C:\program files\ea games\mohaa\moh_breakthrough.exe] => (Allow) C:\program files\ea games\mohaa\moh_breakthrough.exe
FirewallRules: [TCP Query User{CFFE12D2-3AC3-44AF-B84F-F24BE6C8D939}C:\program files\ea games\mohaa\mohaa.exe] => (Allow) C:\program files\ea games\mohaa\mohaa.exe
FirewallRules: [UDP Query User{89526612-2754-4E55-BE9F-B5A866A2417A}C:\program files\ea games\mohaa\mohaa.exe] => (Allow) C:\program files\ea games\mohaa\mohaa.exe
FirewallRules: [TCP Query User{8B4EB969-BF23-4753-B7AF-F8C96F7D371D}C:\program files\ea games\battlefield vietnam\bfvietnam.exe] => (Allow) C:\program files\ea games\battlefield vietnam\bfvietnam.exe
FirewallRules: [UDP Query User{E232E712-56F5-4006-B800-1A394B0D0310}C:\program files\ea games\battlefield vietnam\bfvietnam.exe] => (Allow) C:\program files\ea games\battlefield vietnam\bfvietnam.exe
FirewallRules: [TCP Query User{8F3E7797-FF56-44CC-964F-98FB62D1F609}C:\program files\ea games\mohaa\moh_spearhead.exe] => (Allow) C:\program files\ea games\mohaa\moh_spearhead.exe
FirewallRules: [UDP Query User{4D68700E-DC54-457C-A171-6756A1D620FD}C:\program files\ea games\mohaa\moh_spearhead.exe] => (Allow) C:\program files\ea games\mohaa\moh_spearhead.exe
FirewallRules: [{37E8B1EE-D83F-4D9A-88A8-E2BFE3A31BDD}] => (Allow) C:\Program Files\AVG\Av\avgmfapx.exe
FirewallRules: [{E73A364D-F2BF-43E3-AAE5-7F4B1BF7F3BF}] => (Allow) C:\Program Files\AVG\Av\avgmfapx.exe
FirewallRules: [TCP Query User{2899FA4F-4CC1-4D51-9BCA-D26342499228}C:\program files\wolfenstein - enemy territory\et.exe] => (Allow) C:\program files\wolfenstein - enemy territory\et.exe
FirewallRules: [UDP Query User{0CAC7AF5-8B9E-408C-96DE-22D548D35C07}C:\program files\wolfenstein - enemy territory\et.exe] => (Allow) C:\program files\wolfenstein - enemy territory\et.exe
FirewallRules: [{ECE204ED-CD5C-44EB-874A-B3840A56EA7C}] => (Allow) C:\Program Files\AVG\Av\avgnsx.exe
FirewallRules: [{D576E899-BCB7-4F69-B3D2-47A4E8EAB806}] => (Allow) C:\Program Files\AVG\Av\avgnsx.exe
FirewallRules: [{BE6A8B73-F576-4EF0-8984-D8F85E6F3005}] => (Allow) C:\Program Files\AVG\Av\avgdiagex.exe
FirewallRules: [{91E64870-A3BC-4C21-9234-1EE402FF0756}] => (Allow) C:\Program Files\AVG\Av\avgdiagex.exe
FirewallRules: [{71F923DE-9460-4DE8-AF0E-04EDB7E90B76}] => (Allow) C:\Program Files\AVG\Av\avgemcx.exe
FirewallRules: [{F09E7A69-A641-4959-A6D2-1CE31341F185}] => (Allow) C:\Program Files\AVG\Av\avgemcx.exe
==================== Restore Points =========================
12-05-2016 15:54:58 Windows Update
18-05-2016 11:31:04 Windows Update
27-05-2016 15:56:12 Windows Update
02-06-2016 17:53:30 Windows Update
15-06-2016 21:31:47 Scheduled Checkpoint
16-06-2016 15:42:20 Windows Update
21-06-2016 18:32:37 Windows Update
27-06-2016 17:17:54 Windows Update
01-07-2016 18:05:54 Windows Update
08-07-2016 18:17:34 Scheduled Checkpoint
10-07-2016 13:45:16 Windows Update
10-07-2016 14:54:34 Removed Clifford Phonics
10-07-2016 14:55:05 Removed Sesame Street - Learn, Play & Grow.
10-07-2016 14:58:43 Removed Medal of Honor Allied Assault™ Spearhead
10-07-2016 14:59:55 Removed Medal of Honor Allied Assault™ Breakthrough
10-07-2016 15:01:54 Removed Medal of Honor Allied Assault
10-07-2016 16:22:02 Windows Update
14-07-2016 21:36:31 Windows Update
==================== Faulty Device Manager Devices =============
Name: PS/2 Compatible Mouse
Description: PS/2 Compatible Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/18/2016 04:05:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/16/2016 10:10:48 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/15/2016 04:06:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/14/2016 10:48:01 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/14/2016 09:35:51 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/14/2016 05:17:51 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/13/2016 04:03:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/12/2016 08:56:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/12/2016 04:02:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/11/2016 04:18:48 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (07/15/2016 04:41:29 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The AVGIDSAgent service terminated with service-specific error %%-536753635.
Error: (07/13/2016 05:13:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 116.12.0.0
Update Source: %NT AUTHORITY51
Update Stage: 4.6.0305.00
Source Path: 4.6.0305.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (07/13/2016 05:13:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.225.1232.0
Update Source: %NT AUTHORITY51
Update Stage: 4.6.0305.00
Source Path: 4.6.0305.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (07/13/2016 05:13:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.225.1232.0
Update Source: %NT AUTHORITY51
Update Stage: 4.6.0305.00
Source Path: 4.6.0305.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (07/13/2016 05:13:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.225.1232.0
Update Source: %NT AUTHORITY59
Update Stage: 4.6.0305.00
Source Path: 4.6.0305.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\SYSTEM
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (07/13/2016 04:02:56 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 116.12.0.0
Update Source: %NT AUTHORITY51
Update Stage: 4.6.0305.00
Source Path: 4.6.0305.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (07/13/2016 04:02:56 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.225.1232.0
Update Source: %NT AUTHORITY51
Update Stage: 4.6.0305.00
Source Path: 4.6.0305.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (07/13/2016 04:02:56 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.225.1232.0
Update Source: %NT AUTHORITY51
Update Stage: 4.6.0305.00
Source Path: 4.6.0305.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (07/13/2016 04:02:55 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.225.1232.0
Update Source: %NT AUTHORITY59
Update Stage: 4.6.0305.00
Source Path: 4.6.0305.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\SYSTEM
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (07/12/2016 09:06:56 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 116.12.0.0
Update Source: %NT AUTHORITY51
Update Stage: 4.6.0305.00
Source Path: 4.6.0305.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz
Percentage of memory in use: 72%
Total physical RAM: 1993.25 MB
Available physical RAM: 541.31 MB
Total Virtual: 3986.49 MB
Available Virtual: 2067.6 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:68.64 GB) (Free:12.97 GB) NTFS
Drive r: (Recovery) (Fixed) (Total:5.86 GB) (Free:1.54 GB) NTFS ==>[system with boot components (obtained from drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 74.5 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=5.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=68.6 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================