My computer is really slow. Especially at start up, takes about 15 minutes. I get a message that says, “host process for windows services stopped working and must close.”
Any help would be appreciated.
Here are my logs.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-11-2016
Ran by [removed] (administrator) on STEARNS-PC (04-11-2016 12:33:25)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\AESTSr64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files (x86)\SMINST\BLService.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
() C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
() C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe
(CBS Interactive Inc.) C:\Program Files (x86)\CBS Interactive\Download App\CBSI.AppStore.Scanner.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqgpc01.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(AVAST Software) C:\Users\raypahl\Desktop\aswMBR.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\…\Run: [SmartMenu] => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [915000 2009-01-08] (Hewlett-Packard)
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-20] (Microsoft Corporation)
HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [463360 2009-01-28] (IDT, Inc.)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169744 2015-09-12] (Apple Inc.)
HKLM-x32\…\Run: [DVDAgent] => C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe [1148200 2008-11-28] (CyberLink Corp.)
HKLM-x32\…\Run: [TVAgent] => C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe [202024 2009-05-11] (CyberLink Corp.)
HKLM-x32\…\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.)
HKLM-x32\…\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-01-13] (CyberLink Corp.)
HKLM-x32\…\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [323640 2010-02-25] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\…\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-04] (CyberLink Corp.)
HKLM-x32\…\Run: [UpdatePDIRShortCut] => C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [218408 2008-12-04] (CyberLink Corp.)
HKLM-x32\…\Run: [HP Health Check Scheduler] => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-10-09] (Hewlett-Packard)
HKLM-x32\…\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [484408 2009-01-23] (Hewlett-Packard)
HKLM-x32\…\Run: [TSMAgent] => C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe [1328424 2009-04-29] (CyberLink Corp.)
HKLM-x32\…\Run: [CLMLServer for HP TouchSmart] => C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [185640 2009-04-29] (CyberLink)
HKLM-x32\…\Run: [UCam_Menu] => C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9099440 2016-11-03] (AVAST Software)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKLM-x32\…\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2014-04-23] (Lavasoft)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)
HKU\S-1-5-20\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [cdloader] => C:\Users\raypahl\AppData\Roaming\mjusbsp\cdloader2.exe [50520 2009-08-01] (magicJack L.P.)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818720 2016-09-19] (Google)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-11-11] (Electronic Arts)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [736701A46C7D59E46F8F7D9F95111119F406C6DA._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.)
HKU\S-1-5-21-513785977-584283709-202011636-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [334336 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [cdloader] => C:\Users\raypahl\AppData\Roaming\mjusbsp\cdloader2.exe [50520 2009-08-01] (magicJack L.P.)
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818720 2016-09-19] (Google)
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-11-11] (Electronic Arts)
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [736701A46C7D59E46F8F7D9F95111119F406C6DA._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.)
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [334336 2008-01-20] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-29] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2014-04-30]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\raypahl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Download App.lnk [2015-02-15]
ShortcutTarget: Download App.lnk -> C:\Program Files (x86)\CBS Interactive\Download App\CBSI.AppStore.Scanner.exe (CBS Interactive Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{801647DA-8FFF-4244-BC31-E0870B9F67FE}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{94FA59CE-8C9A-4984-B67B-149BBF13BD4C}: [NameServer] 8.8.8.8,208.67.222.222,8.8.4.4,208.67.220.220
Tcpip\..\Interfaces\{94FA59CE-8C9A-4984-B67B-149BBF13BD4C}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID;=130892846893110000&GUID;=764FC242-5591-4ABF-9B6A-E9976335B01D
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {7EEAD0DA-121E-498E-B773-B8F0B4C4AAB1} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {94A0FAC8-4922-45B9-B85C-DE11B41E351F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSERBM&pc;=MSERT1
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {A9E5F592-BF1B-41BF-AFF4-9CAC82733B93} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_ie_syc_oracle&type;=orcl_default
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid;=1&pid;=21&src;=sgsearch&v;=1.15.414.3&searchparam;={SearchTerms}
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {7EEAD0DA-121E-498E-B773-B8F0B4C4AAB1} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {94A0FAC8-4922-45B9-B85C-DE11B41E351F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSERBM&pc;=MSERT1
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {A9E5F592-BF1B-41BF-AFF4-9CAC82733B93} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_ie_syc_oracle&type;=orcl_default
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid;=1&pid;=21&src;=sgsearch&v;=1.15.414.3&searchparam;={SearchTerms}
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO-x32: PDF Suite 2015 Helper -> {5B91DFF7-1E67-4A1E-99D4-F3A09B8459AD} -> C:\Program Files (x86)\PDF Suite 2015\creator-ie-helper.dll [2015-01-23] (Interactive Brands Malta Limited)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\IPS\IPSBHO.DLL => No File
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)
Toolbar: HKLM-x32 - PDF Suite 2015 Toolbar - {D623F6CA-49B6-4097-A62F-4D60C829D63D} - C:\Program Files (x86)\PDF Suite 2015\creator-ie-plugin.dll [2015-01-23] (Interactive Brands Malta Limited)
Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {8714912E-380D-11D5-B8AA-00D0B78F3D48} hxxp://chat.yahoo.com/cab/yuplapp.cab
FireFox:
========
FF HKLM\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.2.15\coFFAddon => not found
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-29]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-08-29]
FF HKLM-x32\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-22] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-04-30] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\PDF Suite 2015\resources\pdfsuite2015firefoxextension
FF Extension: (PDF Suite 2015) - C:\Program Files (x86)\PDF Suite 2015\resources\pdfsuite2015firefoxextension [2016-02-20] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_205.dll [2016-11-03] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll [2016-11-03] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2012-04-11] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin-x32: PDF Suite 2015 -> C:\Program Files (x86)\PDF Suite 2015\np-previewer.dll [2015-01-23] (Interactive Brands Malta Limited)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp
CHR StartupUrls: Default -> "hxxps://www.facebook.com/","hxxps://www.google.com/","hxxps://www.bing.com/"
CHR DefaultSearchURL: Default -> hxxp://www.search.ask.com/web?q={searchTerms}
CHR DefaultSearchKeyword: Default -> search.ask.com
CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li;=ff&q;={searchTerms}
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\pdf.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (TelevisionFanatic Installer Plugin Stub) - C:\Program Files (x86)\TelevisionFanaticEI\Installr\1.bin\NP64EISB.dll => No File
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll => No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default [2016-11-04]
CHR Extension: (Google Drive) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-25]
CHR Extension: (Pearltrees Extension) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgngjfgpahnnncnimlhjgjhdajmaeeoa [2016-08-23]
CHR Extension: (ShopAtHome.com: Deals + Cash Back) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlmebkoiahbppacaicbgncnjhbpdfkcc [2016-10-21]
CHR Extension: (CyberGhost VPN - Free Proxy) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcbnikgemihknccdjaihjnfbapinljpi [2015-08-10]
CHR Extension: (Google Docs Offline) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-01]
CHR Extension: (Avast Online Security) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-11-03]
CHR Extension: (Bing Rewards Helper) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\neodenankcjdlhndmpcffjmcealafaig [2016-02-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-06]
CHR Extension: (Bing) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofgaflfnfknmefgjhlgkohmpekighhdi [2016-09-15]
CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security Suite\Engine\22.8.0.50\Exts\Chrome.crx
CHR HKLM\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\Exts\Chrome.crx
CHR HKU\S-1-5-21-513785977-584283709-202011636-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\raypahl\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-12-22]
CHR HKU\S-1-5-21-513785977-584283709-202011636-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\raypahl\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-12-22]
CHR HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gihfmmedoddijgnhkgfgnkeohkpbipol] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\AESTSr64.exe [88576 2008-11-17] (Andrea Electronics Corporation)
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-29] (AVAST Software)
R2 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1037824 2009-09-08] (Hewlett-Packard Co.) [File not signed]
S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
S3 Interactive Brands CrashHandler; C:\Program Files (x86)\PDF Suite 2015\crash-handler-ws.exe [745800 2015-01-23] (Interactive Brands Malta Limited)
S2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2008-06-09] (Hewlett-Packard Company) [File not signed]
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-11] (Electronic Arts)
S3 PDF Suite 2015; C:\Program Files (x86)\PDF Suite 2015\ws.exe [1676104 2015-01-23] (Interactive Brands Malta Limited)
S2 PDF Suite 2015 Creator; C:\Program Files (x86)\PDF Suite 2015\creator-ws.exe [622920 2015-01-23] (Interactive Brands Malta Limited)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Recovery Service for Windows; C:\Program Files (x86)\SMINST\BLService.exe [365952 2008-12-23] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2008-11-25] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\STacSV64.exe [290304 2009-01-28] (IDT, Inc.)
R2 TVCapSvc; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [296320 2008-11-26] ()
R2 TVSched; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [116096 2008-11-26] ()
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-20] (Microsoft Corporation)
S3 WsAppService; C:\Program Files (x86)\Wondershare\WAF\WsAppService.exe [252816 2015-04-30] (Wondershare)
S2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 Amfilter; C:\Windows\System32\DRIVERS\Amfltx64.sys [12288 2007-10-15] ((Standard mouse types))
S3 Amusbprt; C:\Windows\System32\DRIVERS\Amusbx64.sys [17920 2008-02-13] (A4Tech Co.,Ltd.)
S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [78640 2016-06-21] (AVAST Software)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-29] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-29] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-29] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [74032 2016-08-29] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-29] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-22] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [224616 2016-08-29] (AVAST Software)
S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [74544 2016-08-29] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-11-04] (Malwarebytes)
R2 SADP_NPF; C:\Windows\SysWOW64\drivers\sadp_npf64.sys [35344 2012-07-02] (CACE Technologies, Inc.)
S3 ssmirrdr; C:\Windows\System32\DRIVERS\ssmirrdr.sys [10112 2016-02-09] (support.com, Inc)
R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [146928 2008-11-28] (CyberLink Corp.)
S1 AntiLog32; \??\C:\Windows\system32\drivers\AntiLog64.sys [X]
U4 eabfiltr; no ImagePath
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 keycrypt; system32\DRIVERS\KeyCrypt64.sys [X]
S3 NAVENG; \??\C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\SDSDefs\20160808.001\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\SDSDefs\20160808.001\EX64.SYS [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U3 aswMBR; \??\C:\Users\raypahl\AppData\Local\Temp\aswMBR.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-11-04 12:38 - 2016-11-04 12:38 - 00000512 _____ C:\Users\raypahl\Documents\MBR.dat
2016-11-04 12:33 - 2016-11-04 12:39 - 00036142 _____ C:\Users\raypahl\Desktop\FRST.txt
2016-11-04 12:31 - 2016-11-04 12:32 - 02409984 _____ (Farbar) C:\Users\raypahl\Desktop\FRST64.exe
2016-11-03 18:57 - 2016-11-03 18:57 - 00000000 ____D C:\ProgramData\EA Logs
2016-10-24 21:36 - 2016-10-24 21:36 - 00002052 _____ C:\Users\Public\Desktop\NTI Digital Jack.lnk
2016-10-24 21:36 - 2016-10-24 21:36 - 00001930 _____ C:\Users\Public\Desktop\NTI Ripper.lnk
2016-10-24 21:36 - 2016-10-24 21:36 - 00000941 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI DigitalJack.lnk
2016-10-24 21:36 - 2016-10-24 21:36 - 00000839 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Ripper.lnk
2016-10-24 21:35 - 2016-10-24 21:35 - 00001024 ___RH C:\Windows\SysWOW64\NTIRIPPER.dll
2016-10-24 21:34 - 2016-11-03 19:08 - 00000584 _____ C:\Users\raypahl\Shadow.xml
2016-10-24 21:32 - 2016-10-24 21:32 - 00000036 __RSH C:\.uid_xxx
2016-10-24 21:28 - 2016-10-24 21:28 - 00001960 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Shadow.lnk
2016-10-24 21:28 - 2016-10-24 21:28 - 00000841 _____ C:\Users\Public\Desktop\NTI Shadow.lnk
2016-10-24 21:28 - 2000-08-02 20:50 - 01056768 _____ (eHelp Corporation.) C:\Windows\SysWOW64\roboex32.dll
2016-10-24 21:26 - 2016-10-24 21:36 - 00000000 ____D C:\Program Files (x86)\NewTech Infosystems
2016-10-24 15:40 - 2016-10-24 15:40 - 00282144 _____ C:\Windows\Minidump\Mini102416-02.dmp
2016-10-24 13:01 - 2016-10-24 13:07 - 00282256 _____ C:\Windows\Minidump\Mini102416-01.dmp
2016-10-21 11:36 - 2016-09-29 23:09 - 17975808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-10-21 11:36 - 2016-09-29 23:07 - 10891264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-10-21 11:36 - 2016-09-29 23:07 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-10-21 11:36 - 2016-09-29 23:06 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-10-21 11:36 - 2016-09-29 23:05 - 02129920 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-10-21 11:36 - 2016-09-29 23:05 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 01296384 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 00887296 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 00528896 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 00234496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-10-21 11:36 - 2016-09-29 23:05 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2016-10-21 11:36 - 2016-09-29 23:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2016-10-21 11:36 - 2016-09-29 23:05 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2016-10-21 11:36 - 2016-09-29 22:39 - 12859392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-10-21 11:36 - 2016-09-29 22:39 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-10-21 11:36 - 2016-09-29 22:37 - 09731584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-10-21 11:36 - 2016-09-29 22:36 - 01831424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-10-21 11:36 - 2016-09-29 22:36 - 01436160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-10-21 11:36 - 2016-09-29 22:36 - 01095168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-10-21 11:36 - 2016-09-29 22:36 - 01089024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-10-21 11:36 - 2016-09-29 22:36 - 00711168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-10-21 11:36 - 2016-09-29 22:36 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2016-10-21 11:36 - 2016-09-29 22:36 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-10-21 11:36 - 2016-09-29 22:36 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-10-21 11:36 - 2016-09-29 22:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-10-21 11:36 - 2016-09-29 22:35 - 01789952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-10-21 11:36 - 2016-09-29 22:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-10-21 11:36 - 2016-09-29 22:35 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-10-21 11:36 - 2016-09-29 22:35 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-10-21 11:36 - 2016-09-29 22:35 - 00217088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-10-21 11:36 - 2016-09-29 22:35 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-10-21 11:36 - 2016-09-29 22:35 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-10-21 11:36 - 2016-09-29 22:35 - 00042496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2016-10-21 11:36 - 2016-09-29 22:35 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2016-10-21 11:36 - 2016-09-29 22:35 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2016-10-21 04:18 - 2016-09-30 11:17 - 04693224 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-10-21 03:21 - 2016-09-10 11:30 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-10-21 03:20 - 2016-09-10 11:45 - 01690624 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-10-21 03:20 - 2016-09-10 11:44 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll
2016-10-21 03:20 - 2016-09-10 11:27 - 00075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2016-10-21 03:03 - 2016-09-10 10:24 - 02803712 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-10-21 03:03 - 2016-09-09 10:34 - 01268224 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2016-10-21 03:03 - 2016-09-09 10:34 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2016-10-21 03:03 - 2016-09-09 10:34 - 00287232 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2016-10-21 03:03 - 2016-09-09 10:34 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2016-10-21 03:03 - 2016-09-09 10:15 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2016-10-21 03:03 - 2016-09-09 10:15 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2016-10-21 03:03 - 2016-09-09 10:15 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2016-10-21 03:03 - 2016-09-09 10:15 - 00160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2016-10-21 03:03 - 2016-09-09 09:57 - 02002944 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2016-10-21 03:03 - 2016-09-09 09:56 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2016-10-21 03:03 - 2016-09-09 09:44 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2016-10-21 03:03 - 2016-09-09 09:43 - 01561600 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2016-10-21 03:03 - 2016-09-09 09:42 - 01154560 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2016-10-21 03:03 - 2016-09-09 09:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2016-10-21 03:03 - 2016-09-09 09:32 - 00486912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2016-10-21 03:03 - 2016-09-09 09:23 - 00682496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2016-10-21 03:03 - 2016-09-09 09:21 - 01073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2016-10-21 03:02 - 2016-09-08 09:39 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-10-21 03:02 - 2016-09-08 09:39 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2016-10-21 03:02 - 2016-09-03 11:08 - 02528768 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2016-10-21 03:02 - 2016-09-03 10:50 - 01544704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2016-10-21 03:01 - 2016-09-14 20:41 - 00975872 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-10-21 03:01 - 2016-09-14 20:29 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2016-10-21 03:01 - 2016-09-14 19:23 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2016-10-21 03:01 - 2016-09-14 19:01 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-11-04 12:38 - 2015-03-26 15:47 - 00002398 _____ C:\Users\raypahl\Documents\aswMBR.txt
2016-11-04 12:33 - 2014-09-03 12:51 - 00000000 ____D C:\FRST
2016-11-04 11:50 - 2012-08-15 05:37 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-11-04 11:48 - 2012-03-30 23:57 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-11-04 11:14 - 2014-08-25 16:46 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-11-04 11:13 - 2013-12-22 22:18 - 00000000 ___RD C:\Users\raypahl\Google Drive
2016-11-04 11:13 - 2011-10-05 06:39 - 00000000 ____D C:\Users\raypahl\AppData\Local\CrashDumps
2016-11-04 11:12 - 2009-03-06 02:08 - 00003584 _____ C:\Windows\System32\Tasks\HP Health Check
2016-11-04 11:09 - 2009-07-21 13:32 - 00009308 _____ C:\ProgramData\HPWALog.txt
2016-11-04 11:00 - 2012-08-15 05:37 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-11-04 10:58 - 2016-02-02 22:57 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0.job
2016-11-04 10:53 - 2006-11-02 10:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-11-04 10:47 - 2006-11-02 10:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2016-11-04 10:47 - 2006-11-02 10:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2016-11-03 20:05 - 2009-03-06 00:13 - 00000012 _____ C:\Windows\bthservsdp.dat
2016-11-03 20:05 - 2006-11-02 10:42 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-11-03 19:43 - 2012-03-30 23:58 - 00003682 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-11-03 19:42 - 2012-03-30 23:57 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-11-03 19:42 - 2011-12-07 21:31 - 00000000 ____D C:\Windows\system32\Macromed
2016-11-03 19:42 - 2011-09-30 18:29 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-11-03 19:42 - 2009-03-06 01:12 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-11-03 19:32 - 2015-03-26 15:55 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-11-03 19:10 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\Resources
2016-11-03 19:09 - 2014-08-25 23:08 - 00000000 ____D C:\AdwCleaner
2016-11-03 19:03 - 2012-07-05 02:08 - 00006756 _____ C:\Users\raypahl\AppData\Local\d3d9caps.dat
2016-11-03 19:03 - 2009-03-06 00:47 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-11-03 19:02 - 2014-03-17 11:47 - 00000000 ____D C:\Users\raypahl\Documents\Electronic Arts
2016-11-03 19:02 - 2014-03-16 11:43 - 00000000 ____D C:\Program Files (x86)\Origin Games
2016-11-03 18:55 - 2016-08-18 21:11 - 00000000 ____D C:\Program Files (x86)\SwannView Link
2016-11-03 18:54 - 2015-01-29 20:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
2016-11-03 18:54 - 2015-01-29 20:15 - 00000000 ____D C:\Program Files (x86)\Coupons
2016-11-03 16:35 - 2016-04-06 19:42 - 00468790 _____ C:\Windows\ntbtlog.txt
2016-11-03 16:13 - 2014-08-25 16:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-11-03 16:13 - 2014-08-25 16:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-10-29 21:57 - 2009-07-21 13:21 - 00000000 ____D C:\Users\raypahl
2016-10-29 21:57 - 2006-11-02 08:34 - 00000000 ____D C:\Windows\system32\spool
2016-10-29 21:57 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\registration
2016-10-29 21:57 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\inf
2016-10-29 21:57 - 2006-11-02 07:33 - 91226112 _____ C:\Windows\system32\config\software_previous
2016-10-29 21:57 - 2006-11-02 07:33 - 36438016 _____ C:\Windows\system32\config\system_previous
2016-10-29 21:51 - 2006-11-02 07:33 - 00262144 _____ C:\Windows\system32\config\security_previous
2016-10-29 21:51 - 2006-11-02 07:33 - 00262144 _____ C:\Windows\system32\config\sam_previous
2016-10-29 20:05 - 2016-07-13 03:17 - 00000000 _____ C:\Windows\SysWOW64\last.dump
2016-10-29 11:59 - 2006-11-02 07:33 - 00524288 _____ C:\Windows\system32\config\default_previous
2016-10-29 11:49 - 2006-11-02 07:33 - 69992448 _____ C:\Windows\system32\config\components_previous
2016-10-25 13:51 - 2011-10-07 07:07 - 00000000 ____D C:\Program Files (x86)\NortonInstaller
2016-10-25 13:51 - 2009-03-06 00:49 - 00000000 ____D C:\ProgramData\Norton
2016-10-25 11:50 - 2011-10-30 10:04 - 00000000 ____D C:\Users\raypahl\AppData\Roaming\HpUpdate
2016-10-24 21:30 - 2013-08-24 14:09 - 00000000 ____D C:\Users\raypahl\Documents\deb
2016-10-24 21:24 - 2006-11-02 07:46 - 00763734 _____ C:\Windows\system32\PerfStringBackup.INI
2016-10-24 18:29 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-10-24 17:38 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\rescache
2016-10-24 16:32 - 2014-04-30 17:50 - 00001795 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2016-10-24 16:29 - 2014-08-07 13:48 - 00000000 ____D C:\Users\raypahl\Documents\My Scans
2016-10-24 15:40 - 2011-10-12 14:02 - 00000000 ____D C:\Windows\Minidump
2016-10-24 15:39 - 2014-10-28 04:11 - 433651867 _____ C:\Windows\MEMORY.DMP
2016-10-21 15:53 - 2013-08-13 08:08 - 00000000 ____D C:\ProgramData\HP
2016-10-21 12:54 - 2014-05-03 12:39 - 00000000 ____D C:\Users\raypahl\AppData\LocalLow\HPAppData
2016-10-21 04:39 - 2006-11-02 10:21 - 00329512 _____ C:\Windows\system32\FNTCACHE.DAT
2016-10-21 04:38 - 2009-03-06 01:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-10-21 04:37 - 2006-11-02 10:07 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer
2016-10-21 04:04 - 2014-02-25 09:26 - 00757538 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-10-21 03:20 - 2013-08-14 03:11 - 00000000 ____D C:\Windows\system32\MRT
2016-10-21 03:06 - 2006-11-02 07:35 - 143495576 ____C (Microsoft Corporation) C:\Windows\system32\mrt.exe
2016-10-21 03:05 - 2010-12-20 08:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-10-20 15:15 - 2016-09-23 06:44 - 00000000 ____D C:\Windows\System32\Tasks\Remediation
2016-10-13 06:20 - 2015-03-26 15:54 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-10-10 20:52 - 2013-12-22 21:32 - 00001865 _____ C:\Users\Public\Desktop\Google Slides.lnk
2016-10-10 20:52 - 2013-12-22 21:32 - 00001863 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2016-10-10 20:52 - 2013-12-22 21:32 - 00001853 _____ C:\Users\Public\Desktop\Google Docs.lnk
2016-10-10 20:52 - 2013-12-22 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
==================== Files in the root of some directories =======
2013-10-13 21:44 - 2013-10-13 21:44 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
2014-08-25 22:22 - 2014-10-08 11:21 - 0000004 _____ () C:\Users\raypahl\AppData\Roaming\appdataFr2.bin
2014-03-18 17:00 - 2014-04-04 03:00 - 0000082 _____ () C:\Users\raypahl\AppData\Roaming\WB.CFG
2015-12-03 21:41 - 2016-04-02 00:12 - 0000994 _____ () C:\Users\raypahl\AppData\Roaming\wklnhst.dat
2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\AtStart.txt
2012-07-05 02:08 - 2016-11-03 19:03 - 0006756 _____ () C:\Users\raypahl\AppData\Local\d3d9caps.dat
2016-08-22 15:02 - 2016-08-22 15:12 - 0000732 _____ () C:\Users\raypahl\AppData\Local\d3d9caps64.dat
2012-09-03 18:33 - 2016-08-29 20:23 - 0151552 _____ () C:\Users\raypahl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-11 05:47 - 2013-12-11 05:49 - 0004170 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI0287.txt
2013-12-11 06:05 - 2013-12-11 06:05 - 0354328 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI0FE9.txt
2011-10-01 00:07 - 2011-10-01 00:08 - 0460566 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI3785.txt
2016-08-22 17:25 - 2016-08-22 17:25 - 0389670 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI3940.txt
2014-01-11 19:16 - 2014-01-11 19:18 - 0444592 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI6339.txt
2016-02-20 05:30 - 2016-02-20 05:31 - 0001848 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI6DAF.txt
2016-02-20 05:50 - 2016-02-20 05:51 - 0405314 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI7CE3.txt
2013-12-11 05:47 - 2013-12-11 05:48 - 0012516 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI0287.txt
2013-12-11 06:05 - 2013-12-11 06:05 - 0015670 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI0FE9.txt
2011-10-01 00:07 - 2011-10-01 00:08 - 0014878 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI3785.txt
2016-08-22 17:25 - 2016-08-22 17:25 - 0011478 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI3940.txt
2014-01-11 19:16 - 2014-01-11 19:18 - 0043456 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI6339.txt
2016-02-20 05:30 - 2016-02-20 05:31 - 0026324 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI6DAF.txt
2016-02-20 05:50 - 2016-02-20 05:51 - 0013546 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI7CE3.txt
2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\DSwitch.txt
2011-09-30 19:28 - 2016-04-06 19:16 - 0000000 _____ () C:\Users\raypahl\AppData\Local\FnF4.txt
2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\QSwitch.txt
2011-05-27 22:02 - 2011-10-01 00:34 - 0001940 _____ () C:\Users\raypahl\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
2009-07-21 13:32 - 2016-11-04 11:09 - 0009308 _____ () C:\ProgramData\HPWALog.txt
2013-08-13 08:08 - 2014-04-30 21:37 - 0003705 _____ () C:\ProgramData\hpzinstall.log
2014-05-27 14:19 - 2016-04-18 20:53 - 0000614 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2009-06-13 23:40 - 2009-06-13 23:40 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2009-03-06 01:55 - 2009-03-06 01:55 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2009-06-13 23:39 - 2009-06-13 23:39 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2009-03-06 01:48 - 2009-03-06 01:50 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2009-06-13 23:38 - 2009-06-13 23:38 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2009-06-13 23:39 - 2009-06-13 23:39 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2009-03-06 01:47 - 2009-03-06 01:48 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2009-03-06 01:50 - 2009-03-06 01:55 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2009-06-13 23:39 - 2009-06-13 23:39 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
Some files in TEMP:
====================
C:\Users\raypahl\AppData\Local\Temp\cct.dll
C:\Users\raypahl\AppData\Local\Temp\HPPSdr.exe
C:\Users\raypahl\AppData\Local\Temp\JavaIC.dll
C:\Users\raypahl\AppData\Local\Temp\jre-8u101-windows-au.exe
C:\Users\raypahl\AppData\Local\Temp\jre-8u111-windows-au.exe
C:\Users\raypahl\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\raypahl\AppData\Local\Temp\jre-8u71-windows-au.exe
C:\Users\raypahl\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\raypahl\AppData\Local\Temp\msscct32.dll
C:\Users\raypahl\AppData\Local\Temp\mstsdhav.dll
C:\Users\raypahl\AppData\Local\Temp\Quarantine.exe
C:\Users\raypahl\AppData\Local\Temp\YSearchUtil.dll
C:\Users\raypahl\AppData\Local\Temp\ytb.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{03643C3A-276A-495F-A3F9-37428AF4434A}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{07CAF0E7-1697-4F67-B23C-ACFC3C227971}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{0BB9737D-9D31-4451-BEB6-239DBA7AE291}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{1ED5386F-F337-4F65-AAE0-6474DDC0870A}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{28689526-4B9A-4E80-B7C4-32CA21B40F1E}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{2E7A0B92-9E55-4DEA-BBA3-F93D732A56B1}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{3B47A66E-B640-42C1-A6CE-40F7EC6273F5}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{40718227-A6E2-4B8B-B82C-6F40933D8327}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{46949032-B4EE-4CF7-BBC4-B5A45B5A9E87}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{55E8CAEA-22C3-41F6-AB08-97D890FFC4E5}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{6440939F-A05A-484F-8E4C-EEC99859BE44}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{69A5BD0D-4B3F-47AA-B77A-450017E65E02}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{6D72D734-48F4-4782-A52E-E5447A8484CA}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{76B58018-5D24-4DC5-868E-031DC7F79E26}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{8A503156-F723-4955-BA4E-5B879A529AEA}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{BD1D630A-95F8-44BD-83D2-CE9F3897210E}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{C2B850D8-9D4A-4F7D-B6C4-1370929A49DC}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CAA2EB40-4B39-4B63-93B5-D34FDD3A127C}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CD9087A2-63C7-435F-90ED-8DC90B695CC3}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CF7A6E42-6A6C-436F-95BB-E7DDBA6857A4}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{D3A389BA-4739-4992-AA76-08E8EF1B6BCE}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{E3A7B323-B837-426D-B8CB-63625BEEF743}.exe
C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{FF1742B3-43A5-4AB3-830F-EAD205065B03}.exe
C:\Users\raypahl\AppData\Local\Temp\{2588712D-0BFD-439A-81E4-7E5EEA9F67EA}-45.0.2454.93_45.0.2454.85_chrome_updater.exe
C:\Users\raypahl\AppData\Local\Temp\{DDE604EF-4F5C-4B52-B6F9-092F33452B06}-45.0.2454.85_44.0.2403.157_chrome_updater.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-11-04 11:14
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-11-2016
Ran by [removed] (04-11-2016 12:41:59)
Running from C:\Users\[removed]\Desktop
Windows Vista (TM) Home Premium Service Pack 2 (X64) (2009-06-14 03:35:45)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-513785977-584283709-202011636-500 - Administrator - Disabled)
Guest (S-1-5-21-513785977-584283709-202011636-501 - Limited - Disabled)
raypahl (S-1-5-21-513785977-584283709-202011636-1000 - Administrator - Enabled) => C:\Users\raypahl
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
4500_G510gm_Help (x32 Version: 000.0.440.000 - Hewlett-Packard) Hidden
4500G510gm (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden
4500G510gm_Software_Min (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Acrobat.com (HKLM-x32\…\{77DCDCE3-2DED-62F3-8154-05E745472D07}) (Version: 1.1.377 - Adobe Systems Incorporated)
Activation Assistant for the 2007 Microsoft Office suites (HKLM-x32\…\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0 - Microsoft Corporation) Hidden
ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.2 - Hewlett-Packard) Hidden
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 23.0.0.257 - Adobe Systems Incorporated)
Adobe Flash Player 23 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 23.0.0.205 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.205 - Adobe Systems Incorporated)
Adobe Reader X (10.1.16) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Amazon Kindle (HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Amazon Kindle) (Version: - Amazon)
Amazon Kindle (HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Amazon Kindle) (Version: - Amazon)
Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Atheros Driver Installation Program (HKLM-x32\…\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 5.2 - Atheros)
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)
BCL easyConverter Desktop 3 (Word Version) (HKLM-x32\…\{8C5845B5-729F-40E3-A945-4454E67F65F4}) (Version: 3.0.18 - BCL Technologies)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 4.17 - Piriform)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CyberLink DVD Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.2512 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden
DocMgr (x32 Version: 130.0.000.000 - Hewlett-Packard) Hidden
DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Download App (HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Download App) (Version: 1.8.0 - CBS Interactive)
Download App (HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Download App) (Version: 1.8.0 - CBS Interactive)
ENE CIR Receiver Driver (12/30/2008 2.7.2.0) (HKLM\…\703AB19C282B6ED3F1D3CE92F8DAA864B68A7C91) (Version: 12/30/2008 2.7.2.0 - ENE)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
ESU for Microsoft Vista (HKLM-x32\…\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)
Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Drive (HKLM-x32\…\{FDEDE86B-3597-40D7-8568-4649F651EDBD}) (Version: 1.32.3363.5836 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HP Active Support Library (HKLM-x32\…\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}) (Version: 3.1.9.1 - Hewlett-Packard)
HP Customer Experience Enhancements (HKLM-x32\…\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}) (Version: 5.7.0.2664 - Hewlett-Packard)
HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Document Manager 2.0 (HKLM\…\HP Document Manager) (Version: 2.0 - HP)
HP Help and Support (HKLM-x32\…\{0054A0F6-00C9-4498-B821-B5C9578F433E}) (Version: 2.1.3.0 - Hewlett-Packard Company)
HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP)
HP MediaSmart DVD (HKLM-x32\…\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 2.1.2328 - Hewlett-Packard)
HP MediaSmart Music/Photo/Video (HKLM-x32\…\InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}) (Version: 2.2.2829 - Hewlett-Packard)
HP MediaSmart SlingPlayer (HKLM-x32\…\HP.MediaSmartSlingPlayer_is1) (Version: 2.1 - Sling Media, Inc.)
HP MediaSmart SmartMenu (HKLM\…\{0BC595C4-F736-4EB4-A1C0-32C7E81800F0}) (Version: 2.1.10 - Hewlett-Packard)
HP MediaSmart TV (HKLM-x32\…\InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}) (Version: 2.1.1709 - Hewlett-Packard)
HP MediaSmart Webcam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.2.1621 - Hewlett-Packard)
HP Officejet 4500 G510g-m (HKLM\…\{E5083D57-D93F-404C-A91F-1C50D67C2BEB}) (Version: 13.0 - HP)
HP Quick Launch Buttons (HKLM-x32\…\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.17.1 - Hewlett-Packard Company)
HP Smart Web Printing 4.5 (HKLM\…\HP Smart Web Printing) (Version: 4.5 - HP)
HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Support Solutions Framework (HKLM-x32\…\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company)
HP Total Care Advisor (HKLM-x32\…\{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}) (Version: 2.4.5991.2847 - Hewlett-Packard)
HP Total Care Setup (HKLM-x32\…\{95A747E0-DF19-46CB-A622-20A0107201BD}) (Version: 1.1.2413.2876 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP User Guides 0135 (HKLM-x32\…\{372ED957-0FB5-487B-B51A-388B3D393F7A}) (Version: 1.01.0000 - Hewlett-Packard)
HP Wireless Assistant (HKLM-x32\…\{462DED50-EC2E-4237-ABCF-B5C463C0EE51}) (Version: 3.50.3.1 - Hewlett-Packard)
HPAsset component for HP Active Support Library (x32 Version: 3.0.2.2 - Hewlett-Packard) Hidden
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6146.0 - IDT)
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: - Intel Corporation)
iTunes (HKLM\…\{CEC7613B-E286-4A31-BEE3-3F7798488D9F}) (Version: 12.1.3.6 - Apple Inc.)
Java 8 Update 60 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1312 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.1312 - CyberLink Corp.) Hidden
LightScribe System Software 1.14.17.1 (HKLM-x32\…\{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}) (Version: 1.14.17.1 - LightScribe)
Logitech Unifying Software 2.10 (HKLM\…\Logitech Unifying) (Version: 2.10.37 - Logitech)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\…\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Standard Edition 2003 (HKLM-x32\…\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\…\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\…\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\…\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
muvee Reveal (HKLM-x32\…\{DE626616-D7C4-4F00-7E0B-EAF26FA65749}) (Version: 7.0.43.12698 - muvee Technologies Pte Ltd)
My HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.0.62 - WildTangent)
Network64 (Version: 130.0.550.000 - Hewlett-Packard) Hidden
NTI Ripper (HKLM-x32\…\{88A785A2-3EA6-4A2D-ABEE-68E9E55A39F8}) (Version: 2.0.0.17 - NewTech Infosystems)
NTI Shadow 3 (HKLM-x32\…\{E9EB5689-4F76-4E3C-A675-5ED5F52AB890}) (Version: 3.1.4.0 - NewTech Infosystems)
OCR Software by I.R.I.S. 13.0 (HKLM\…\HPOCR) (Version: 13.0 - HP)
Origin (HKLM-x32\…\Origin) (Version: 9.4.6.2792 - Electronic Arts, Inc.)
PDF Suite 2015 (HKLM-x32\…\PDF Suite 2015) (Version: 13.0.10.21694 - Interactive Brands Malta Limited)
PDF Suite 2015 (x32 Version: 13.0.23.21617 - Interactive Brands Malta Limited) Hidden
PDF Suite 2015 OCR Module (x32 Version: 13.0.23.21617 - Interactive Brands Malta Limited) Hidden
PhotoScape (HKLM-x32\…\PhotoScape) (Version: - )
Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.2512 - CyberLink Corp.)
Power2Go (x32 Version: 6.0.2512 - CyberLink Corp.) Hidden
PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2512 - CyberLink Corp.)
PowerDirector (x32 Version: 7.0.2512 - CyberLink Corp.) Hidden
ProtectSmart Hard Drive Protection (HKLM\…\{2F97CE84-9C33-4631-821B-85EA371EA254}) (Version: 3.10.1.7 - Hewlett-Packard)
QLBCASL (x32 Version: 6.40.17.2 - Hewlett-Packard) Hidden
QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: 6.0.6000.20113 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SafeZone Stable 1.48.2066.114 (x32 Version: 1.48.2066.114 - Avast Software) Hidden
Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Segoe UI (x32 Version: 15.4.2271.0615 - Microsoft Corp) Hidden
Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 13.0 - HP)
Slingbox - Watch Your TV Anywhere (HKLM-x32\…\{7B798B31-2F33-4DC8-BDA4-D36488E86636}) (Version: 1.0.0 - Sling Media)
SlingPlayer (HKLM-x32\…\InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}) (Version: 1.04.0206 - Sling Media)
SlingPlayer (x32 Version: 1.04.0206 - Sling Media) Hidden
SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spelling Dictionaries Support For Adobe Reader 9 (HKLM-x32\…\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Steam (HKLM-x32\…\Steam) (Version: - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated)
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden
TurboTax 2012 (HKLM-x32\…\TurboTax 2012) (Version: 2012.0 - Intuit, Inc)
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
WildTangent Games App (HP Games) (HKLM-x32\…\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.31 - WildTangent)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}) (Version: 14.0.8064.206 - Microsoft Corporation)
Xilisoft Video Converter Ultimate (HKLM-x32\…\Xilisoft Video Converter Ultimate) (Version: 7.7.3.20131014 - Xilisoft)
Yahoo Search Set (HKLM-x32\…\Yahoo! SearchSet) (Version: - Yahoo Inc.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {1E47DECC-A445-437E-BA49-BF68A0FE709D} - System32\Tasks\HP Health Check => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09] (Hewlett-Packard)
Task: {1EEC94E2-3371-4445-B69E-06C410B6EE74} - System32\Tasks\{6EA9492D-AFAD-4611-B778-FEF2E452B324} => pcalua.exe -a "C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GJQZPLZ1\Athena[1].exe" -d C:\Users\raypahl\Desktop
Task: {24AF7C9D-752C-4445-A82B-1BE9CDF09079} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {2676CF9D-8246-4E69-9166-E93FAAEF4707} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-03] (Adobe Systems Incorporated)
Task: {3712F5A0-0477-4593-898F-2D6722E1694A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {5BF15EEE-CE81-46B3-97C4-2F0217BF3198} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)
Task: {6E74CFCE-FF9D-417D-9884-56337FA84896} - System32\Tasks\HPCeeScheduleForraypahl => C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe [2008-05-19] (Hewlett-Packard)
Task: {C4A2780D-68B8-4F95-A118-6E5DD88047E0} - System32\Tasks\NetworkWizardHNW => C:\Program Files (x86)\Hewlett-Packard\HP TCS\RemEngine.exe [2008-12-17] ()
Task: {E226896F-2D00-4835-94CA-6E3EE9E822E0} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-29] (AVAST Software)
Task: {EC1DA6EA-D89F-45D1-96DA-F64D32C2C68E} - System32\Tasks\SafeZone scheduled Autoupdate 1468319266 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-06-17] (Avast Software)
Task: {EC3518F0-B320-4AC6-B0D1-D131875A226A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {ECBDA076-B4B3-4E77-8185-DC8446925D32} - System32\Tasks\{2DF12692-40FF-4911-A6C8-8B1BF5365384} => pcalua.exe -a C:\Users\raypahl\AppData\Local\Microsoft\Windows\Burn\Burn\callatlanta_setup.exe
Task: {F1351889-C902-458D-940D-9EEB132FCC88} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {FD30349E-1798-46DF-A9FF-96869C61C29C} - System32\Tasks\{B8696691-6D99-40A1-8CEE-83EC12275D01} => pcalua.exe -a C:\Users\raypahl\Desktop\esetsmartinstaller_enu.exe -d C:\Users\raypahl\Desktop
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForraypahl.job => C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\raypahl\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.com
==================== Loaded Modules (Whitelisted) ==============
2009-03-06 02:02 - 2008-12-23 19:18 - 00365952 _____ () C:\Program Files (x86)\SMINST\BLService.exe
2009-03-06 01:55 - 2008-11-25 18:29 - 00247152 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2008-11-26 19:13 - 2008-11-26 19:13 - 00296320 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
2008-11-26 19:13 - 2008-11-26 19:13 - 00116096 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
2015-03-20 18:12 - 2015-03-20 18:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2008-11-26 19:12 - 2008-11-26 19:12 - 00074536 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\Common\MCEMediaStatus64.dll
2009-07-01 15:44 - 2009-07-01 15:44 - 00632888 _____ () C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
2016-08-29 18:18 - 2016-08-29 18:18 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-11-04 08:16 - 2016-11-04 08:16 - 03127760 _____ () C:\Program Files\AVAST Software\Avast\defs\16110400\algo.dll
2016-08-29 18:18 - 2016-08-29 18:18 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2009-03-06 02:02 - 2008-12-23 19:18 - 00132480 _____ () C:\Program Files (x86)\SMINST\STWmiM.dll
2009-03-06 01:55 - 2008-11-25 18:29 - 00034088 _____ () C:\Program Files (x86)\Cyberlink\Shared files\RichVideops.dll
2008-11-26 19:13 - 2008-11-26 19:13 - 00263560 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLCapEngine.dll
2008-11-26 19:13 - 2008-11-26 19:13 - 00038184 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLCapSvcps.dll
2007-07-12 15:55 - 2007-07-12 15:55 - 01581056 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
2007-08-14 15:59 - 2007-08-14 15:59 - 06365184 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
2007-07-12 15:55 - 2007-07-12 15:55 - 00131072 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2014-10-10 12:41 - 2014-10-10 12:41 - 01255936 _____ () C:\Program Files (x86)\CBS Interactive\Download App\libcurl.dll
2014-10-10 12:39 - 2014-10-10 12:39 - 00066560 _____ () C:\Program Files (x86)\CBS Interactive\Download App\zlib.dll
2008-11-26 19:13 - 2008-11-26 19:13 - 00349480 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLTinyDB.dll
2009-04-29 22:11 - 2009-04-29 22:11 - 00906536 ____N () C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
2016-07-11 22:01 - 2016-07-11 22:02 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-11-04 11:08 - 2016-11-04 11:08 - 00098816 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32api.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00110080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pywintypes27.dll
2016-11-04 11:08 - 2016-11-04 11:08 - 00364544 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pythoncom27.dll
2016-11-04 11:08 - 2016-11-04 11:08 - 00320512 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32com.shell.shell.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00914432 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_hashlib.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 01176576 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._core_.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00806400 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._gdi_.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00816128 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._windows_.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 01067008 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._controls_.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00733184 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._misc_.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00682496 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pysqlite2._sqlite.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00088064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_ctypes.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00686080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\unicodedata.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00119808 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32file.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00108544 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32security.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00007168 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\hashobjs_ext.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00017920 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\thumbnails_ext.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00088064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\usb_ext.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00012800 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\common.time34.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00018432 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32event.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00167936 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32gui.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00046080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_socket.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 01303552 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_ssl.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00128512 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_elementtree.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00127488 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pyexpat.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00038912 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32inet.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00036864 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_psutil_windows.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00524248 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\windows._lib_cacheinvalidation.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00011264 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32crypt.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00123392 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._wizard.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00077312 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._html2.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00027648 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_multiprocessing.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00020480 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_yappi.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00035840 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32process.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00078848 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._animate.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00024064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32pipe.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00010240 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\select.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00025600 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32pdh.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00017408 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32profile.pyd
2016-11-04 11:08 - 2016-11-04 11:08 - 00022528 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32ts.pyd
2016-09-06 14:28 - 2016-09-06 12:00 - 05197312 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libglesv2.dll
2016-09-06 14:28 - 2016-09-06 12:00 - 00147456 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libegl.dll
2016-07-13 04:28 - 2016-07-06 18:01 - 17602240 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\PepperFlash\22.0.0.209\pepflashplayer.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
HKLM\…\cmdfile\DefaultIcon: %SystemRoot%\System32\shell32.dll,-153 <===== ATTENTION
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-513785977-584283709-202011636-1000\…\intuit.com -> hxxps://accounts.intuit.com
IE trusted site: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\intuit.com -> hxxps://accounts.intuit.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 07:34 - 2006-09-18 16:37 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-21-513785977-584283709-202011636-1000\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Constant Guard.lnk => C:\Windows\pss\Constant Guard.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Fast Connect.lnk => C:\Windows\pss\Fast Connect.lnk.CommonStartup
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [{85CA64C5-0E24-49D3-962C-757C4D4EF5EA}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE
FirewallRules: [{C056B941-D6C9-43C2-BC46-C8062C7E9591}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe
FirewallRules: [{A477DEFD-C4F3-49DF-9493-DCB0193B3DC2}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe
FirewallRules: [{9DA0FA66-F81F-4C49-93E4-0C736F80D266}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe
FirewallRules: [{D62589CC-FCFC-474B-897E-5F4E2E376DB6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\TSMAgent.exe
FirewallRules: [{0C18A91B-06AB-412C-A4FB-56721866C9EB}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe
FirewallRules: [{90B91326-6994-4D67-8710-402213196972}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe
FirewallRules: [{892F181D-FCD8-4749-A566-1DDE9D5E06C6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QP.exe
FirewallRules: [{218696AD-0268-44D1-958A-9FB0C07367EE}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QPService.exe
FirewallRules: [{C0D11A95-3BAB-4C69-9B2F-ABDF0DE00382}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{DA361D62-6094-45AB-8548-C892212DD857}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe
FirewallRules: [{E29DF1CE-61F4-4C67-B5E6-018649FED1F0}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe
FirewallRules: [{28D8EE93-F60E-412F-B1D8-2540677725C9}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe
FirewallRules: [{2C5DE510-0436-4BA6-9D33-EA65AD777F21}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
FirewallRules: [{2121075F-A168-42F2-A24D-D0A4C9205054}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
FirewallRules: [{899817AC-8E24-4616-A1BB-9CF013A72458}] => (Allow) LPort=80
FirewallRules: [{801C85E3-1031-4FA1-9462-DDCCDD72601F}] => (Allow) LPort=80
FirewallRules: [{2A217FCB-85BA-4D43-88A5-E696A21C17BE}] => (Allow) LPort=80
FirewallRules: [{67913156-DF65-4018-B0AC-C4BA598F0458}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{F97F9C53-4B16-44C5-9DAB-BE26D646BB2E}] => (Allow) LPort=2869
FirewallRules: [{ECDA4AA6-F84F-4F8C-A5C2-0981BEB965AB}] => (Allow) LPort=1900
FirewallRules: [{99E21AA7-60B0-4758-9700-947CE68E6FC4}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{556638C7-DDD1-49D4-B540-2BF1813097BE}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{BA7B17AA-ECB1-48CA-B123-DEDEF25F5280}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C8533641-5BA2-4226-AFAD-01CAA75D4BC3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2079C40C-30DB-4EC9-A37D-2A69F7CB2B9A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{7AA88511-8B20-4763-AB96-65C325F436C2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8338DBF9-E8CD-40AC-A575-BC1C4D3264AE}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{49D4AFA4-BDA6-4F09-A81E-C49E81BDD809}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{F2531826-2F73-4998-9503-3CB1A9EF475A}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{50BB60C3-956B-46D3-BD6E-BF3715DAEAA8}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{938E4FAF-25DE-43F0-8941-BAB51D00909F}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{32D0853C-F33F-4CA2-BDD9-EB0E43C2C1A9}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe
FirewallRules: [{028CDA9D-6AA2-48CC-97F4-8CB3BFFEDCAE}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe
FirewallRules: [{24ED04E3-69B3-4EF6-AB2B-774FF6EBB341}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{B498508E-E2F8-420D-AF6B-5E4EB2847438}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{149237F6-0247-4D6A-9B24-6284C0EC1F6E}] => (Allow) LPort=80
FirewallRules: [{0D5BE560-6B3C-4CA0-A163-4A0D4761952F}] => (Allow) LPort=3074
FirewallRules: [{46BBA3EE-07CF-43BA-B750-B59D6FEA6E67}] => (Allow) LPort=53
FirewallRules: [{1937BBB4-CCBA-487B-ABF4-965EBD64F35D}] => (Allow) LPort=88
FirewallRules: [{0B06D53B-770D-4F4F-8750-588083139BD4}] => (Allow) LPort=3074
FirewallRules: [{63DB0018-84DB-4F7D-91A6-5EEB5D473E2C}] => (Allow) LPort=53
FirewallRules: [{4BD011AB-0AC7-4B5A-A0CF-466CC36B4E10}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS6610\HPDiagnosticCoreUI.exe
FirewallRules: [{5CFF6CC9-FFCC-4E3F-BC41-D4AC77525B27}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS6610\HPDiagnosticCoreUI.exe
FirewallRules: [{D627BCA2-CF30-4E83-813D-55AE2787BACA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{8EBE220A-A2E8-47DC-9A52-C00C722B2B36}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{67F0DD1B-2C2B-4DF0-83BD-CA448BAF87E8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{277CCB2A-D8F2-4438-8B24-11CC51D7A2DD}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{A4D4FBBF-F068-4D39-8BE3-74355B903AB7}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3C2E\HPDiagnosticCoreUI.exe
FirewallRules: [{71675975-38A1-48EA-ACCB-FABEF0BD9D13}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3C2E\HPDiagnosticCoreUI.exe
FirewallRules: [{56345E73-9C25-4274-A858-4690E48E1F67}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS64AB\HPDiagnosticCoreUI.exe
FirewallRules: [{E16F485C-ED68-4BD6-8805-2A64A9D96A39}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS64AB\HPDiagnosticCoreUI.exe
FirewallRules: [{31BE109E-8AF9-4143-AD52-57F7DB7FAED8}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS0964\HPDiagnosticCoreUI.exe
FirewallRules: [{A93D5B10-FD8F-4B4F-B432-6A12E6A2D0DC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS0964\HPDiagnosticCoreUI.exe
FirewallRules: [{7C26B91E-B117-486A-B514-1E931777327D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{3D0B25BE-B075-4318-8FAD-AA4378D408D4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{3190CC53-3DB5-4C54-B6F1-0770B51650F2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{D9A183D9-B520-4D17-8D52-4341A9CFBBEC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{BCEEDD97-2D66-466F-B460-54D582497581}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{603C8A2D-FB38-49BD-9FDD-2934CAECAE11}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{DDEE3F5E-97F1-4B23-9929-9B3755027FC8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{38A2B6F1-AE10-4306-AC8B-57D65B8552FB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{A6BD5514-3186-4D82-ACE9-8AFC163F591F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{E5BEACAE-D7A3-4D30-8284-ED4CDC7EE1F1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{55C0994B-0B3E-444F-A6F1-771232CE4C04}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{24942CC8-CEE3-42BD-AE57-6FC7B5B01D26}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{80E01553-7E49-42EB-84AA-260B63480BFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{3D37A03B-72C1-4951-AACC-F8F9842EAC32}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{9851363A-29E7-4066-808D-76F09B44EAA9}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{6DF5A30B-3B0F-4CC8-91E7-C21179661239}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{00C3DF64-1789-45C4-826E-F88407B37F60}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{8060B257-FF11-4A7E-B4D6-8822812D5766}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{FDC220B2-E26C-439A-8AEE-6CB05A6A9CDF}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{0548CB3C-9BAA-419F-AC3C-CF92119ECF94}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{23D1FC3D-674C-44F8-9961-46BBEB100F2F}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{069C9567-F251-4E40-B6F7-7B7D7D9109AC}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{D99F3B45-4583-426E-8CDF-DF5E521807C6}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{D41E6F5E-2589-4C57-9E12-1D63C165791D}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{6DEEE18D-D523-45BF-932E-CE5743988EE8}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{43D52C1D-478B-4FCE-9745-AAF8982DF4DC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS175A\HPDiagnosticCoreUI.exe
FirewallRules: [{A707CC94-5C2F-4D23-8BCD-1307DBA1F380}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS175A\HPDiagnosticCoreUI.exe
FirewallRules: [{D5F39F1E-2D2C-4FE4-AC8F-7D1244D261F1}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS17E3\HPDiagnosticCoreUI.exe
FirewallRules: [{98DD6223-287E-4612-84C7-8256612DF4EE}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS17E3\HPDiagnosticCoreUI.exe
FirewallRules: [{A5F88943-D64D-41D9-ACDD-54EDBEC8ECC3}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS61A2\HPDiagnosticCoreUI.exe
FirewallRules: [{0295B60A-D80C-449F-A559-2559D30C56ED}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS61A2\HPDiagnosticCoreUI.exe
FirewallRules: [{B26FD28B-080C-4DC6-84AF-10360A7C1848}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS326C\HPDiagnosticCoreUI.exe
FirewallRules: [{EDDD3BB6-DE4D-491F-9E82-60EED756FAB0}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS326C\HPDiagnosticCoreUI.exe
FirewallRules: [{720847F8-E7ED-4F05-A979-64A3CABFD9A4}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{9DED4120-5843-4CD7-96F8-BA8DC78DD4D2}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{5188845E-5ABE-493A-8AE3-C562AF667662}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3742\HPDiagnosticCoreUI.exe
FirewallRules: [{87FB02D8-EDC9-4628-8196-40F55E2955A2}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3742\HPDiagnosticCoreUI.exe
FirewallRules: [{37154139-4F88-40F7-8C66-F721A336A600}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3780\HPDiagnosticCoreUI.exe
FirewallRules: [{D47BCBCC-ADF9-4F87-BCFB-E6EFD8A23273}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3780\HPDiagnosticCoreUI.exe
FirewallRules: [{C550D466-6DA9-4CF3-AF39-E1B7B9D3491A}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS5F6B\HPDiagnosticCoreUI.exe
FirewallRules: [{ABBB6631-70E4-4D5A-8D5D-105E6B6C2047}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS5F6B\HPDiagnosticCoreUI.exe
FirewallRules: [{735A1C21-05AD-49A7-B856-D8DB046D814B}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{072D341C-F0AA-4EC4-B256-90AA1A0371D6}] => (Allow) C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe
FirewallRules: [{0E09CE06-6B58-4C5C-B41F-9CBC3C28310F}] => (Allow) C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe
FirewallRules: [{AF858CCB-A6DC-41B2-A8F1-DEC030D92EEB}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{4850BCB1-4BDE-4888-9338-413BF216736F}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{37A8803F-79F3-4EA8-B4DC-EFC8C0988147}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{05B7B3B1-49C4-42B6-B68A-EFF0B868DFBB}C:\program files (x86)\swannview link\mydvr.exe] => (Allow) C:\program files (x86)\swannview link\mydvr.exe
FirewallRules: [UDP Query User{3A8123E3-4600-46C8-8ACE-AF6FB9F3DE3D}C:\program files (x86)\swannview link\mydvr.exe] => (Allow) C:\program files (x86)\swannview link\mydvr.exe
FirewallRules: [TCP Query User{0B8D5604-9A95-4CBA-99CC-80CD63F8BD63}C:] => (Allow) C:\
FirewallRules: [UDP Query User{423E6DF9-8B53-405B-8F7D-6926AE5B5679}C:] => (Allow) C:\
FirewallRules: [{954DDB9D-8A37-4449-BC09-F3070B20367E}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS420D\HPDiagnosticCoreUI.exe
FirewallRules: [{DA174395-2E36-4D4D-B5EC-11BFF9576FD7}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS420D\HPDiagnosticCoreUI.exe
FirewallRules: [{53EE87C1-3AC3-43AD-B1D9-4ECE6A351714}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS42CB\HPDiagnosticCoreUI.exe
FirewallRules: [{6A40C1D8-44EC-4858-97A6-EAE58655C9EC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS42CB\HPDiagnosticCoreUI.exe
FirewallRules: [{5537C001-D930-41E2-B89C-942DB712A6B9}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS4196\HPDiagnosticCoreUI.exe
FirewallRules: [{665ECD78-617F-490D-B46F-145BA00FC68D}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS4196\HPDiagnosticCoreUI.exe
==================== Restore Points =========================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (11/04/2016 11:13:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application jucheck.exe, version 2.8.60.27, time stamp 0x55c116b1, faulting module jucheck.exe, version 2.8.60.27, time stamp 0x55c116b1, exception code 0x40000015, fault offset 0x00052d24,
process id 0x13fc, application start time 0x01d236b6291b8d5d.
Error: (11/04/2016 11:12:07 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Host Process for Windows Services because of this error.
Program: Host Process for Windows Services
File: C:\Windows\Prefetch\AgRobust.db
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
Additional Data
Error value: C0000185
Disk type: 3
Error: (11/04/2016 11:12:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,
process id 0xfa0, application start time 0x01d236b5be6c075d.
Error: (11/04/2016 11:08:36 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Host Process for Windows Services because of this error.
Program: Host Process for Windows Services
File: C:\Windows\Prefetch\AgRobust.db
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
Additional Data
Error value: C0000185
Disk type: 3
Error: (11/04/2016 11:08:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,
process id 0xb08, application start time 0x01d236b55e2842ad.
Error: (11/04/2016 11:06:08 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (11/04/2016 11:05:19 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Host Process for Windows Services because of this error.
Program: Host Process for Windows Services
File: C:\Windows\Prefetch\AgRobust.db
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
Additional Data
Error value: C0000185
Disk type: 3
Error: (11/04/2016 11:05:19 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,
process id 0x200, application start time 0x01d236b296f38870.
Error: (11/03/2016 08:34:51 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Host Process for Windows Services because of this error.
Program: Host Process for Windows Services
File: C:\Windows\Prefetch\AgRobust.db
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
Additional Data
Error value: C0000185
Disk type: 3
Error: (11/03/2016 08:34:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,
process id 0x105c, application start time 0x01d2363b354c4410.
System errors:
=============
Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
CodeIntegrity:
===================================
Date: 2016-11-04 11:16:11.209
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-11-04 11:16:10.273
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-11-04 11:16:09.368
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-11-04 11:16:08.463
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-11-04 11:16:07.403
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-11-04 11:16:06.420
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-11-04 11:16:02.192
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-11-04 11:16:01.225
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-11-04 11:16:00.242
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-11-04 11:15:59.259
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz
Percentage of memory in use: 77%
Total physical RAM: 3998.02 MB
Available physical RAM: 897.88 MB
Total Virtual: 8221.28 MB
Available Virtual: 4898.43 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:452.13 GB) (Free:143.29 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (RECOVERY) (Fixed) (Total:13.62 GB) (Free:2.09 GB) NTFS ==>[system with boot components (obtained from drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 636BBFB1)
Partition 1: (Active) - (Size=452.1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=13.6 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-11-04 12:17:48
—————————–
12:17:48.853 OS Version: Windows x64 6.0.6002 Service Pack 2
12:17:48.853 Number of processors: 2 586 0x170A
12:17:48.853 ComputerName: STEARNS-PC UserName: raypahl
12:18:03.243 Initialize success
12:18:03.259 VM: initialized successfully
12:18:03.259 VM: Intel CPU virtualization not supported
12:18:17.053 AVAST engine defs: 16110400
12:18:33.738 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
12:18:33.738 Disk 0 Vendor: TOSHIBA_MK5055GSX FG002C Size: 476940MB BusType: 3
12:18:34.284 Disk 0 MBR read successfully
12:18:34.300 Disk 0 MBR scan
12:18:34.628 Disk 0 unknown MBR code
12:18:34.674 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 462985 MB offset 2048
12:18:35.064 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 13951 MB offset 948195328
12:18:36.094 Disk 0 scanning C:\Windows\system32\drivers
12:19:48.861 Service scanning
12:23:22.187 Modules scanning
12:23:22.187 Disk 0 trace - called modules:
12:23:22.732 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
12:23:22.732 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006478060]
12:23:22.748 3 CLASSPNP.SYS[fffffa6000a4ec33] -> nt!IofCallDriver -> [0xfffffa8006245310]
12:23:22.748 5 hpdskflt.sys[fffffa6001802189] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004bf1590]
12:23:35.110 AVAST engine scan C:\Windows
12:23:52.825 AVAST engine scan C:\Windows\system32
12:38:13.645 Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\MBR.dat"
12:38:13.661 The log file has been saved successfully to "C:\Users\raypahl\Documents\aswMBR.txt"
12:38:52.007 AVAST engine scan C:\Windows\system32\drivers
12:40:35.754 AVAST engine scan C:\Users\raypahl
13:04:35.987 Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\MBR.dat"
13:04:36.031 The log file has been saved successfully to "C:\Users\raypahl\Documents\aswMBR.txt"
13:07:08.922 Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\deb\computer help\MBR.dat"
13:07:08.929 The log file has been saved successfully to "C:\Users\raypahl\Documents\deb\computer help\aswMBR.txt"