This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Really Slow [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is really slow.  Especially at start up, takes about 15 minutes.  I get a message that says, “host process for windows services stopped working and must close.”

 

Any help would be appreciated.

 

Here are my logs.

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-11-2016

Ran by [removed] (administrator) on STEARNS-PC (04-11-2016 12:33:25)

Running from C:\Users\[removed]\Desktop

[removed]

Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) Language: English (United States)

Internet Explorer Version 9 (Default browser: Chrome)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\stacsv64.exe

(Microsoft Corporation) C:\Windows\System32\SLsvc.exe

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe

(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\AESTSr64.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe

() C:\Program Files (x86)\SMINST\BLService.exe

() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

() C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe

() C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe

(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE

(Intel Corporation) C:\Windows\System32\igfxtray.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe

(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe

(Microsoft Corporation) C:\Windows\ehome\ehtray.exe

(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe

(CBS Interactive Inc.) C:\Program Files (x86)\CBS Interactive\Download App\CBSI.AppStore.Scanner.exe

(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe

(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe

( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe

(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe

(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe

(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe

(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe

(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe

(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe

(Intel Corporation) C:\Windows\System32\igfxsrvc.exe

(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe

(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe

(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqste08.exe

(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqbam08.exe

(Hewlett-Packard) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqgpc01.exe

(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe

(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe

(AVAST Software) C:\Users\raypahl\Desktop\aswMBR.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

 

 

==================== Registry (Whitelisted) ====================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)

HKLM\…\Run: [SmartMenu] => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [915000 2009-01-08] (Hewlett-Packard)

HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-20] (Microsoft Corporation)

HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [463360 2009-01-28] (IDT, Inc.)

HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169744 2015-09-12] (Apple Inc.)

HKLM-x32\…\Run: [DVDAgent] => C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe [1148200 2008-11-28] (CyberLink Corp.)

HKLM-x32\…\Run: [TVAgent] => C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe [202024 2009-05-11] (CyberLink Corp.)

HKLM-x32\…\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.)

HKLM-x32\…\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-01-13] (CyberLink Corp.)

HKLM-x32\…\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [323640 2010-02-25] ( Hewlett-Packard Development Company, L.P.)

HKLM-x32\…\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-04] (CyberLink Corp.)

HKLM-x32\…\Run: [UpdatePDIRShortCut] => C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [218408 2008-12-04] (CyberLink Corp.)

HKLM-x32\…\Run: [HP Health Check Scheduler] => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-10-09] (Hewlett-Packard)

HKLM-x32\…\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [484408 2009-01-23] (Hewlett-Packard)

HKLM-x32\…\Run: [TSMAgent] => C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe [1328424 2009-04-29] (CyberLink Corp.)

HKLM-x32\…\Run: [CLMLServer for HP TouchSmart] => C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [185640 2009-04-29] (CyberLink)

HKLM-x32\…\Run: [UCam_Menu] => C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.)

HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)

HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)

HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9099440 2016-11-03] (AVAST Software)

HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)

HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)

HKLM-x32\…\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2014-04-23] (Lavasoft)

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

HKU\S-1-5-19\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-20\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [cdloader] => C:\Users\raypahl\AppData\Roaming\mjusbsp\cdloader2.exe [50520 2009-08-01] (magicJack L.P.)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818720 2016-09-19] (Google)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-11-11] (Electronic Arts)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [736701A46C7D59E46F8F7D9F95111119F406C6DA._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.)

HKU\S-1-5-21-513785977-584283709-202011636-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [334336 2008-01-20] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [cdloader] => C:\Users\raypahl\AppData\Roaming\mjusbsp\cdloader2.exe [50520 2009-08-01] (magicJack L.P.)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818720 2016-09-19] (Google)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-11-11] (Electronic Arts)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [736701A46C7D59E46F8F7D9F95111119F406C6DA._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [334336 2008-01-20] (Microsoft Corporation)

ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)

ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)

ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-29] (AVAST Software)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2014-04-30]

ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

Startup: C:\Users\raypahl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Download App.lnk [2015-02-15]

ShortcutTarget: Download App.lnk -> C:\Program Files (x86)\CBS Interactive\Download App\CBSI.AppStore.Scanner.exe (CBS Interactive Inc.)

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76

Tcpip\..\Interfaces\{801647DA-8FFF-4244-BC31-E0870B9F67FE}: [DhcpNameServer] 75.75.75.75 75.75.76.76

Tcpip\..\Interfaces\{94FA59CE-8C9A-4984-B67B-149BBF13BD4C}: [NameServer] 8.8.8.8,208.67.222.222,8.8.4.4,208.67.220.220

Tcpip\..\Interfaces\{94FA59CE-8C9A-4984-B67B-149BBF13BD4C}: [DhcpNameServer] 75.75.75.75 75.75.76.76

 

Internet Explorer:

==================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID;=130892846893110000&GUID;=764FC242-5591-4ABF-9B6A-E9976335B01D

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =

HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006

SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {7EEAD0DA-121E-498E-B773-B8F0B4C4AAB1} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {94A0FAC8-4922-45B9-B85C-DE11B41E351F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSERBM&pc;=MSERT1

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {A9E5F592-BF1B-41BF-AFF4-9CAC82733B93} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_ie_syc_oracle&type;=orcl_default

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid;=1&pid;=21&src;=sgsearch&v;=1.15.414.3&searchparam;={SearchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {7EEAD0DA-121E-498E-B773-B8F0B4C4AAB1} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {94A0FAC8-4922-45B9-B85C-DE11B41E351F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSERBM&pc;=MSERT1

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {A9E5F592-BF1B-41BF-AFF4-9CAC82733B93} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_ie_syc_oracle&type;=orcl_default

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid;=1&pid;=21&src;=sgsearch&v;=1.15.414.3&searchparam;={SearchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software)

BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)

BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File

BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)

BHO-x32: PDF Suite 2015 Helper -> {5B91DFF7-1E67-4A1E-99D4-F3A09B8459AD} -> C:\Program Files (x86)\PDF Suite 2015\creator-ie-helper.dll [2015-01-23] (Interactive Brands Malta Limited)

BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\IPS\IPSBHO.DLL => No File

BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software)

BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)

BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation)

BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)

Toolbar: HKLM-x32 - PDF Suite 2015 Toolbar - {D623F6CA-49B6-4097-A62F-4D60C829D63D} - C:\Program Files (x86)\PDF Suite 2015\creator-ie-plugin.dll [2015-01-23] (Interactive Brands Malta Limited)

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File

DPF: HKLM-x32 {8714912E-380D-11D5-B8AA-00D0B78F3D48} hxxp://chat.yahoo.com/cab/yuplapp.cab

 

FireFox:

========

FF HKLM\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.2.15\coFFAddon => not found

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF

FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-29]

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF

FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-08-29]

FF HKLM-x32\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-22] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-04-30] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\PDF Suite 2015\resources\pdfsuite2015firefoxextension

FF Extension: (PDF Suite 2015) - C:\Program Files (x86)\PDF Suite 2015\resources\pdfsuite2015firefoxextension [2016-02-20] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF

FF HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_205.dll [2016-11-03] ()

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll [2016-11-03] ()

FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)

FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)

FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)

FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)

FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2012-04-11] ()

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)

FF Plugin-x32: PDF Suite 2015 -> C:\Program Files (x86)\PDF Suite 2015\np-previewer.dll [2015-01-23] (Interactive Brands Malta Limited)

 

Chrome:

=======

CHR DefaultProfile: Default

CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp

CHR StartupUrls: Default -> "hxxps://www.facebook.com/","hxxps://www.google.com/","hxxps://www.bing.com/"

CHR DefaultSearchURL: Default -> hxxp://www.search.ask.com/web?q={searchTerms}

CHR DefaultSearchKeyword: Default -> search.ask.com

CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li;=ff&q;={searchTerms}

CHR Plugin: (Widevine Content Decryption Module) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll => No File

CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\PepperFlash\pepflashplayer.dll ()

CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => No File

CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\pdf.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll => No File

CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll => No File

CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll => No File

CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll => No File

CHR Plugin: (Java(TM) Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File

CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)

CHR Plugin: (TelevisionFanatic Installer Plugin Stub) - C:\Program Files (x86)\TelevisionFanaticEI\Installr\1.bin\NP64EISB.dll => No File

CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()

CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll => No File

CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll => No File

CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

CHR Profile: C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default [2016-11-04]

CHR Extension: (Google Drive) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-25]

CHR Extension: (Pearltrees Extension) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgngjfgpahnnncnimlhjgjhdajmaeeoa [2016-08-23]

CHR Extension: (ShopAtHome.com: Deals + Cash Back) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlmebkoiahbppacaicbgncnjhbpdfkcc [2016-10-21]

CHR Extension: (CyberGhost VPN - Free Proxy) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcbnikgemihknccdjaihjnfbapinljpi [2015-08-10]

CHR Extension: (Google Docs Offline) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-01]

CHR Extension: (Avast Online Security) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-11-03]

CHR Extension: (Bing Rewards Helper) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\neodenankcjdlhndmpcffjmcealafaig [2016-02-11]

CHR Extension: (Chrome Web Store Payments) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-06]

CHR Extension: (Bing) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofgaflfnfknmefgjhlgkohmpekighhdi [2016-09-15]

CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security Suite\Engine\22.8.0.50\Exts\Chrome.crx

CHR HKLM\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\Exts\Chrome.crx

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\raypahl\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-12-22]

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\raypahl\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-12-22]

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

CHR HKLM-x32\…\Chrome\Extension: [gihfmmedoddijgnhkgfgnkeohkpbipol] - hxxps://clients2.google.com/service/update2/crx

CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx

 

==================== Services (Whitelisted) ====================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\AESTSr64.exe [88576 2008-11-17] (Andrea Electronics Corporation)

S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-29] (AVAST Software)

R2 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [File not signed]

R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]

R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]

R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1037824 2009-09-08] (Hewlett-Packard Co.) [File not signed]

S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)

S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]

S3 Interactive Brands CrashHandler; C:\Program Files (x86)\PDF Suite 2015\crash-handler-ws.exe [745800 2015-01-23] (Interactive Brands Malta Limited)

S2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2008-06-09] (Hewlett-Packard Company) [File not signed]

S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]

S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-11] (Electronic Arts)

S3 PDF Suite 2015; C:\Program Files (x86)\PDF Suite 2015\ws.exe [1676104 2015-01-23] (Interactive Brands Malta Limited)

S2 PDF Suite 2015 Creator; C:\Program Files (x86)\PDF Suite 2015\creator-ws.exe [622920 2015-01-23] (Interactive Brands Malta Limited)

R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]

R2 Recovery Service for Windows; C:\Program Files (x86)\SMINST\BLService.exe [365952 2008-12-23] ()

R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2008-11-25] ()

R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\STacSV64.exe [290304 2009-01-28] (IDT, Inc.)

R2 TVCapSvc; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [296320 2008-11-26] ()

R2 TVSched; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [116096 2008-11-26] ()

S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-20] (Microsoft Corporation)

S3 WsAppService; C:\Program Files (x86)\Wondershare\WAF\WsAppService.exe [252816 2015-04-30] (Wondershare)

S2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [X]

 

===================== Drivers (Whitelisted) ======================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R1 Amfilter; C:\Windows\System32\DRIVERS\Amfltx64.sys [12288 2007-10-15] ((Standard mouse types))

S3 Amusbprt; C:\Windows\System32\DRIVERS\Amusbx64.sys [17920 2008-02-13] (A4Tech Co.,Ltd.)

S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [78640 2016-06-21] (AVAST Software)

S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-29] (AVAST Software)

R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-29] (AVAST Software)

R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-29] (AVAST Software)

R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [74032 2016-08-29] (AVAST Software)

R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-29] (AVAST Software)

R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-13] (AVAST Software)

R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-22] (AVAST Software)

R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [224616 2016-08-29] (AVAST Software)

S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [74544 2016-08-29] (AVAST Software)

R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)

R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-11-04] (Malwarebytes)

R2 SADP_NPF; C:\Windows\SysWOW64\drivers\sadp_npf64.sys [35344 2012-07-02] (CACE Technologies, Inc.)

S3 ssmirrdr; C:\Windows\System32\DRIVERS\ssmirrdr.sys [10112 2016-02-09] (support.com, Inc)

R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [146928 2008-11-28] (CyberLink Corp.)

S1 AntiLog32; \??\C:\Windows\system32\drivers\AntiLog64.sys [X]

U4 eabfiltr; no ImagePath

S3 IpInIp; system32\DRIVERS\ipinip.sys [X]

S3 keycrypt; system32\DRIVERS\KeyCrypt64.sys [X]

S3 NAVENG; \??\C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\SDSDefs\20160808.001\ENG64.SYS [X]

S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\SDSDefs\20160808.001\EX64.SYS [X]

S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]

S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

U3 aswMBR; \??\C:\Users\raypahl\AppData\Local\Temp\aswMBR.sys [X]

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-11-04 12:38 - 2016-11-04 12:38 - 00000512 _____ C:\Users\raypahl\Documents\MBR.dat

2016-11-04 12:33 - 2016-11-04 12:39 - 00036142 _____ C:\Users\raypahl\Desktop\FRST.txt

2016-11-04 12:31 - 2016-11-04 12:32 - 02409984 _____ (Farbar) C:\Users\raypahl\Desktop\FRST64.exe

2016-11-03 18:57 - 2016-11-03 18:57 - 00000000 ____D C:\ProgramData\EA Logs

2016-10-24 21:36 - 2016-10-24 21:36 - 00002052 _____ C:\Users\Public\Desktop\NTI Digital Jack.lnk

2016-10-24 21:36 - 2016-10-24 21:36 - 00001930 _____ C:\Users\Public\Desktop\NTI Ripper.lnk

2016-10-24 21:36 - 2016-10-24 21:36 - 00000941 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI DigitalJack.lnk

2016-10-24 21:36 - 2016-10-24 21:36 - 00000839 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Ripper.lnk

2016-10-24 21:35 - 2016-10-24 21:35 - 00001024 ___RH C:\Windows\SysWOW64\NTIRIPPER.dll

2016-10-24 21:34 - 2016-11-03 19:08 - 00000584 _____ C:\Users\raypahl\Shadow.xml

2016-10-24 21:32 - 2016-10-24 21:32 - 00000036 __RSH C:\.uid_xxx

2016-10-24 21:28 - 2016-10-24 21:28 - 00001960 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Shadow.lnk

2016-10-24 21:28 - 2016-10-24 21:28 - 00000841 _____ C:\Users\Public\Desktop\NTI Shadow.lnk

2016-10-24 21:28 - 2000-08-02 20:50 - 01056768 _____ (eHelp Corporation.) C:\Windows\SysWOW64\roboex32.dll

2016-10-24 21:26 - 2016-10-24 21:36 - 00000000 ____D C:\Program Files (x86)\NewTech Infosystems

2016-10-24 15:40 - 2016-10-24 15:40 - 00282144 _____ C:\Windows\Minidump\Mini102416-02.dmp

2016-10-24 13:01 - 2016-10-24 13:07 - 00282256 _____ C:\Windows\Minidump\Mini102416-01.dmp

2016-10-21 11:36 - 2016-09-29 23:09 - 17975808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll

2016-10-21 11:36 - 2016-09-29 23:07 - 10891264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll

2016-10-21 11:36 - 2016-09-29 23:07 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec

2016-10-21 11:36 - 2016-09-29 23:06 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb

2016-10-21 11:36 - 2016-09-29 23:05 - 02129920 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl

2016-10-21 11:36 - 2016-09-29 23:05 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 01296384 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00887296 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00528896 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00234496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe

2016-10-21 11:36 - 2016-09-29 23:05 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe

2016-10-21 11:36 - 2016-09-29 23:05 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe

2016-10-21 11:36 - 2016-09-29 22:39 - 12859392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll

2016-10-21 11:36 - 2016-09-29 22:39 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec

2016-10-21 11:36 - 2016-09-29 22:37 - 09731584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 01831424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 01436160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl

2016-10-21 11:36 - 2016-09-29 22:36 - 01095168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 01089024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 00711168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe

2016-10-21 11:36 - 2016-09-29 22:36 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

2016-10-21 11:36 - 2016-09-29 22:35 - 01789952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00217088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00042496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe

2016-10-21 11:36 - 2016-09-29 22:35 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe

2016-10-21 04:18 - 2016-09-30 11:17 - 04693224 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe

2016-10-21 03:21 - 2016-09-10 11:30 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll

2016-10-21 03:20 - 2016-09-10 11:45 - 01690624 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll

2016-10-21 03:20 - 2016-09-10 11:44 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll

2016-10-21 03:20 - 2016-09-10 11:27 - 00075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll

2016-10-21 03:03 - 2016-09-10 10:24 - 02803712 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys

2016-10-21 03:03 - 2016-09-09 10:34 - 01268224 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll

2016-10-21 03:03 - 2016-09-09 10:34 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll

2016-10-21 03:03 - 2016-09-09 10:34 - 00287232 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll

2016-10-21 03:03 - 2016-09-09 10:34 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 00160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll

2016-10-21 03:03 - 2016-09-09 09:57 - 02002944 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll

2016-10-21 03:03 - 2016-09-09 09:56 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll

2016-10-21 03:03 - 2016-09-09 09:44 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll

2016-10-21 03:03 - 2016-09-09 09:43 - 01561600 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll

2016-10-21 03:03 - 2016-09-09 09:42 - 01154560 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll

2016-10-21 03:03 - 2016-09-09 09:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll

2016-10-21 03:03 - 2016-09-09 09:32 - 00486912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll

2016-10-21 03:03 - 2016-09-09 09:23 - 00682496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll

2016-10-21 03:03 - 2016-09-09 09:21 - 01073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll

2016-10-21 03:02 - 2016-09-08 09:39 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys

2016-10-21 03:02 - 2016-09-08 09:39 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys

2016-10-21 03:02 - 2016-09-03 11:08 - 02528768 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll

2016-10-21 03:02 - 2016-09-03 10:50 - 01544704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll

2016-10-21 03:01 - 2016-09-14 20:41 - 00975872 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll

2016-10-21 03:01 - 2016-09-14 20:29 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll

2016-10-21 03:01 - 2016-09-14 19:23 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll

2016-10-21 03:01 - 2016-09-14 19:01 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-11-04 12:38 - 2015-03-26 15:47 - 00002398 _____ C:\Users\raypahl\Documents\aswMBR.txt

2016-11-04 12:33 - 2014-09-03 12:51 - 00000000 ____D C:\FRST

2016-11-04 11:50 - 2012-08-15 05:37 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2016-11-04 11:48 - 2012-03-30 23:57 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job

2016-11-04 11:14 - 2014-08-25 16:46 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

2016-11-04 11:13 - 2013-12-22 22:18 - 00000000 ___RD C:\Users\raypahl\Google Drive

2016-11-04 11:13 - 2011-10-05 06:39 - 00000000 ____D C:\Users\raypahl\AppData\Local\CrashDumps

2016-11-04 11:12 - 2009-03-06 02:08 - 00003584 _____ C:\Windows\System32\Tasks\HP Health Check

2016-11-04 11:09 - 2009-07-21 13:32 - 00009308 _____ C:\ProgramData\HPWALog.txt

2016-11-04 11:00 - 2012-08-15 05:37 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2016-11-04 10:58 - 2016-02-02 22:57 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0.job

2016-11-04 10:53 - 2006-11-02 10:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT

2016-11-04 10:47 - 2006-11-02 10:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

2016-11-04 10:47 - 2006-11-02 10:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

2016-11-03 20:05 - 2009-03-06 00:13 - 00000012 _____ C:\Windows\bthservsdp.dat

2016-11-03 20:05 - 2006-11-02 10:42 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2016-11-03 19:43 - 2012-03-30 23:58 - 00003682 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

2016-11-03 19:42 - 2012-03-30 23:57 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2016-11-03 19:42 - 2011-12-07 21:31 - 00000000 ____D C:\Windows\system32\Macromed

2016-11-03 19:42 - 2011-09-30 18:29 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2016-11-03 19:42 - 2009-03-06 01:12 - 00000000 ____D C:\Windows\SysWOW64\Macromed

2016-11-03 19:32 - 2015-03-26 15:55 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update

2016-11-03 19:10 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\Resources

2016-11-03 19:09 - 2014-08-25 23:08 - 00000000 ____D C:\AdwCleaner

2016-11-03 19:03 - 2012-07-05 02:08 - 00006756 _____ C:\Users\raypahl\AppData\Local\d3d9caps.dat

2016-11-03 19:03 - 2009-03-06 00:47 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2016-11-03 19:02 - 2014-03-17 11:47 - 00000000 ____D C:\Users\raypahl\Documents\Electronic Arts

2016-11-03 19:02 - 2014-03-16 11:43 - 00000000 ____D C:\Program Files (x86)\Origin Games

2016-11-03 18:55 - 2016-08-18 21:11 - 00000000 ____D C:\Program Files (x86)\SwannView Link

2016-11-03 18:54 - 2015-01-29 20:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons

2016-11-03 18:54 - 2015-01-29 20:15 - 00000000 ____D C:\Program Files (x86)\Coupons

2016-11-03 16:35 - 2016-04-06 19:42 - 00468790 _____ C:\Windows\ntbtlog.txt

2016-11-03 16:13 - 2014-08-25 16:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware

2016-11-03 16:13 - 2014-08-25 16:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware

2016-10-29 21:57 - 2009-07-21 13:21 - 00000000 ____D C:\Users\raypahl

2016-10-29 21:57 - 2006-11-02 08:34 - 00000000 ____D C:\Windows\system32\spool

2016-10-29 21:57 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\registration

2016-10-29 21:57 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\inf

2016-10-29 21:57 - 2006-11-02 07:33 - 91226112 _____ C:\Windows\system32\config\software_previous

2016-10-29 21:57 - 2006-11-02 07:33 - 36438016 _____ C:\Windows\system32\config\system_previous

2016-10-29 21:51 - 2006-11-02 07:33 - 00262144 _____ C:\Windows\system32\config\security_previous

2016-10-29 21:51 - 2006-11-02 07:33 - 00262144 _____ C:\Windows\system32\config\sam_previous

2016-10-29 20:05 - 2016-07-13 03:17 - 00000000 _____ C:\Windows\SysWOW64\last.dump

2016-10-29 11:59 - 2006-11-02 07:33 - 00524288 _____ C:\Windows\system32\config\default_previous

2016-10-29 11:49 - 2006-11-02 07:33 - 69992448 _____ C:\Windows\system32\config\components_previous

2016-10-25 13:51 - 2011-10-07 07:07 - 00000000 ____D C:\Program Files (x86)\NortonInstaller

2016-10-25 13:51 - 2009-03-06 00:49 - 00000000 ____D C:\ProgramData\Norton

2016-10-25 11:50 - 2011-10-30 10:04 - 00000000 ____D C:\Users\raypahl\AppData\Roaming\HpUpdate

2016-10-24 21:30 - 2013-08-24 14:09 - 00000000 ____D C:\Users\raypahl\Documents\deb

2016-10-24 21:24 - 2006-11-02 07:46 - 00763734 _____ C:\Windows\system32\PerfStringBackup.INI

2016-10-24 18:29 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\PolicyDefinitions

2016-10-24 17:38 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\rescache

2016-10-24 16:32 - 2014-04-30 17:50 - 00001795 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk

2016-10-24 16:29 - 2014-08-07 13:48 - 00000000 ____D C:\Users\raypahl\Documents\My Scans

2016-10-24 15:40 - 2011-10-12 14:02 - 00000000 ____D C:\Windows\Minidump

2016-10-24 15:39 - 2014-10-28 04:11 - 433651867 _____ C:\Windows\MEMORY.DMP

2016-10-21 15:53 - 2013-08-13 08:08 - 00000000 ____D C:\ProgramData\HP

2016-10-21 12:54 - 2014-05-03 12:39 - 00000000 ____D C:\Users\raypahl\AppData\LocalLow\HPAppData

2016-10-21 04:39 - 2006-11-02 10:21 - 00329512 _____ C:\Windows\system32\FNTCACHE.DAT

2016-10-21 04:38 - 2009-03-06 01:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight

2016-10-21 04:37 - 2006-11-02 10:07 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer

2016-10-21 04:04 - 2014-02-25 09:26 - 00757538 _____ C:\Windows\SysWOW64\PerfStringBackup.INI

2016-10-21 03:20 - 2013-08-14 03:11 - 00000000 ____D C:\Windows\system32\MRT

2016-10-21 03:06 - 2006-11-02 07:35 - 143495576 ____C (Microsoft Corporation) C:\Windows\system32\mrt.exe

2016-10-21 03:05 - 2010-12-20 08:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight

2016-10-20 15:15 - 2016-09-23 06:44 - 00000000 ____D C:\Windows\System32\Tasks\Remediation

2016-10-13 06:20 - 2015-03-26 15:54 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys

2016-10-10 20:52 - 2013-12-22 21:32 - 00001865 _____ C:\Users\Public\Desktop\Google Slides.lnk

2016-10-10 20:52 - 2013-12-22 21:32 - 00001863 _____ C:\Users\Public\Desktop\Google Sheets.lnk

2016-10-10 20:52 - 2013-12-22 21:32 - 00001853 _____ C:\Users\Public\Desktop\Google Docs.lnk

2016-10-10 20:52 - 2013-12-22 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive

 

==================== Files in the root of some directories =======

 

2013-10-13 21:44 - 2013-10-13 21:44 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll

2014-08-25 22:22 - 2014-10-08 11:21 - 0000004 _____ () C:\Users\raypahl\AppData\Roaming\appdataFr2.bin

2014-03-18 17:00 - 2014-04-04 03:00 - 0000082 _____ () C:\Users\raypahl\AppData\Roaming\WB.CFG

2015-12-03 21:41 - 2016-04-02 00:12 - 0000994 _____ () C:\Users\raypahl\AppData\Roaming\wklnhst.dat

2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\AtStart.txt

2012-07-05 02:08 - 2016-11-03 19:03 - 0006756 _____ () C:\Users\raypahl\AppData\Local\d3d9caps.dat

2016-08-22 15:02 - 2016-08-22 15:12 - 0000732 _____ () C:\Users\raypahl\AppData\Local\d3d9caps64.dat

2012-09-03 18:33 - 2016-08-29 20:23 - 0151552 _____ () C:\Users\raypahl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

2013-12-11 05:47 - 2013-12-11 05:49 - 0004170 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI0287.txt

2013-12-11 06:05 - 2013-12-11 06:05 - 0354328 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI0FE9.txt

2011-10-01 00:07 - 2011-10-01 00:08 - 0460566 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI3785.txt

2016-08-22 17:25 - 2016-08-22 17:25 - 0389670 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI3940.txt

2014-01-11 19:16 - 2014-01-11 19:18 - 0444592 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI6339.txt

2016-02-20 05:30 - 2016-02-20 05:31 - 0001848 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI6DAF.txt

2016-02-20 05:50 - 2016-02-20 05:51 - 0405314 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI7CE3.txt

2013-12-11 05:47 - 2013-12-11 05:48 - 0012516 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI0287.txt

2013-12-11 06:05 - 2013-12-11 06:05 - 0015670 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI0FE9.txt

2011-10-01 00:07 - 2011-10-01 00:08 - 0014878 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI3785.txt

2016-08-22 17:25 - 2016-08-22 17:25 - 0011478 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI3940.txt

2014-01-11 19:16 - 2014-01-11 19:18 - 0043456 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI6339.txt

2016-02-20 05:30 - 2016-02-20 05:31 - 0026324 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI6DAF.txt

2016-02-20 05:50 - 2016-02-20 05:51 - 0013546 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI7CE3.txt

2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\DSwitch.txt

2011-09-30 19:28 - 2016-04-06 19:16 - 0000000 _____ () C:\Users\raypahl\AppData\Local\FnF4.txt

2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\QSwitch.txt

2011-05-27 22:02 - 2011-10-01 00:34 - 0001940 _____ () C:\Users\raypahl\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini

2009-07-21 13:32 - 2016-11-04 11:09 - 0009308 _____ () C:\ProgramData\HPWALog.txt

2013-08-13 08:08 - 2014-04-30 21:37 - 0003705 _____ () C:\ProgramData\hpzinstall.log

2014-05-27 14:19 - 2016-04-18 20:53 - 0000614 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

2009-06-13 23:40 - 2009-06-13 23:40 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log

2009-03-06 01:55 - 2009-03-06 01:55 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log

2009-06-13 23:39 - 2009-06-13 23:39 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log

2009-03-06 01:48 - 2009-03-06 01:50 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log

2009-06-13 23:38 - 2009-06-13 23:38 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log

2009-06-13 23:39 - 2009-06-13 23:39 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log

2009-03-06 01:47 - 2009-03-06 01:48 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log

2009-03-06 01:50 - 2009-03-06 01:55 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log

2009-06-13 23:39 - 2009-06-13 23:39 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log

 

Some files in TEMP:

====================

C:\Users\raypahl\AppData\Local\Temp\cct.dll

C:\Users\raypahl\AppData\Local\Temp\HPPSdr.exe

C:\Users\raypahl\AppData\Local\Temp\JavaIC.dll

C:\Users\raypahl\AppData\Local\Temp\jre-8u101-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u111-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u60-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u71-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u77-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\msscct32.dll

C:\Users\raypahl\AppData\Local\Temp\mstsdhav.dll

C:\Users\raypahl\AppData\Local\Temp\Quarantine.exe

C:\Users\raypahl\AppData\Local\Temp\YSearchUtil.dll

C:\Users\raypahl\AppData\Local\Temp\ytb.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{03643C3A-276A-495F-A3F9-37428AF4434A}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{07CAF0E7-1697-4F67-B23C-ACFC3C227971}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{0BB9737D-9D31-4451-BEB6-239DBA7AE291}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{1ED5386F-F337-4F65-AAE0-6474DDC0870A}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{28689526-4B9A-4E80-B7C4-32CA21B40F1E}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{2E7A0B92-9E55-4DEA-BBA3-F93D732A56B1}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{3B47A66E-B640-42C1-A6CE-40F7EC6273F5}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{40718227-A6E2-4B8B-B82C-6F40933D8327}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{46949032-B4EE-4CF7-BBC4-B5A45B5A9E87}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{55E8CAEA-22C3-41F6-AB08-97D890FFC4E5}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{6440939F-A05A-484F-8E4C-EEC99859BE44}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{69A5BD0D-4B3F-47AA-B77A-450017E65E02}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{6D72D734-48F4-4782-A52E-E5447A8484CA}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{76B58018-5D24-4DC5-868E-031DC7F79E26}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{8A503156-F723-4955-BA4E-5B879A529AEA}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{BD1D630A-95F8-44BD-83D2-CE9F3897210E}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{C2B850D8-9D4A-4F7D-B6C4-1370929A49DC}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CAA2EB40-4B39-4B63-93B5-D34FDD3A127C}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CD9087A2-63C7-435F-90ED-8DC90B695CC3}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CF7A6E42-6A6C-436F-95BB-E7DDBA6857A4}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{D3A389BA-4739-4992-AA76-08E8EF1B6BCE}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{E3A7B323-B837-426D-B8CB-63625BEEF743}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{FF1742B3-43A5-4AB3-830F-EAD205065B03}.exe

C:\Users\raypahl\AppData\Local\Temp\{2588712D-0BFD-439A-81E4-7E5EEA9F67EA}-45.0.2454.93_45.0.2454.85_chrome_updater.exe

C:\Users\raypahl\AppData\Local\Temp\{DDE604EF-4F5C-4B52-B6F9-092F33452B06}-45.0.2454.85_44.0.2403.157_chrome_updater.exe

 

 

==================== Bamital & volsnap ======================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

 

LastRegBack: 2016-11-04 11:14

 

==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-11-2016

Ran by [removed] (04-11-2016 12:41:59)

Running from C:\Users\[removed]\Desktop

Windows Vista (TM) Home Premium Service Pack 2 (X64) (2009-06-14 03:35:45)

Boot Mode: Normal

==========================================================

 

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-513785977-584283709-202011636-500 - Administrator - Disabled)

Guest (S-1-5-21-513785977-584283709-202011636-501 - Limited - Disabled)

raypahl (S-1-5-21-513785977-584283709-202011636-1000 - Administrator - Enabled) => C:\Users\raypahl

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}

AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

 

==================== Installed Programs ======================

 

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

4500_G510gm_Help (x32 Version: 000.0.440.000 - Hewlett-Packard) Hidden

4500G510gm (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden

4500G510gm_Software_Min (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden

Acrobat.com (HKLM-x32\…\{77DCDCE3-2DED-62F3-8154-05E745472D07}) (Version: 1.1.377 - Adobe Systems Incorporated)

Activation Assistant for the 2007 Microsoft Office suites (HKLM-x32\…\Activation Assistant for the 2007 Microsoft Office suites) (Version:  - Microsoft Corporation)

Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0 - Microsoft Corporation) Hidden

ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.2 - Hewlett-Packard) Hidden

Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 23.0.0.257 - Adobe Systems Incorporated)

Adobe Flash Player 23 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 23.0.0.205 - Adobe Systems Incorporated)

Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.205 - Adobe Systems Incorporated)

Adobe Reader X (10.1.16) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)

Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)

Amazon Kindle (HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Amazon Kindle) (Version:  - Amazon)

Amazon Kindle (HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Amazon Kindle) (Version:  - Amazon)

Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)

Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)

Apple Mobile Device Support (HKLM\…\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)

Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)

Atheros Driver Installation Program (HKLM-x32\…\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 5.2 - Atheros)

Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)

BCL easyConverter Desktop 3 (Word Version) (HKLM-x32\…\{8C5845B5-729F-40E3-A945-4454E67F65F4}) (Version: 3.0.18 - BCL Technologies)

Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)

BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden

CCleaner (HKLM\…\CCleaner) (Version: 4.17 - Piriform)

Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)

CyberLink DVD Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.2512 - CyberLink Corp.)

D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden

Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden

DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden

DocMgr (x32 Version: 130.0.000.000 - Hewlett-Packard) Hidden

DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden

Download App (HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Download App) (Version: 1.8.0 - CBS Interactive)

Download App (HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Download App) (Version: 1.8.0 - CBS Interactive)

ENE CIR Receiver Driver (12/30/2008 2.7.2.0) (HKLM\…\703AB19C282B6ED3F1D3CE92F8DAA864B68A7C91) (Version: 12/30/2008 2.7.2.0 - ENE)

eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden

ESU for Microsoft Vista (HKLM-x32\…\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)

Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden

Google Chrome (HKLM-x32\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)

Google Drive (HKLM-x32\…\{FDEDE86B-3597-40D7-8568-4649F651EDBD}) (Version: 1.32.3363.5836 - Google, Inc.)

Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden

Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden

GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden

HP Active Support Library (HKLM-x32\…\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}) (Version: 3.1.9.1 - Hewlett-Packard)

HP Customer Experience Enhancements (HKLM-x32\…\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}) (Version: 5.7.0.2664 - Hewlett-Packard)

HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP)

HP Document Manager 2.0 (HKLM\…\HP Document Manager) (Version: 2.0 - HP)

HP Help and Support (HKLM-x32\…\{0054A0F6-00C9-4498-B821-B5C9578F433E}) (Version: 2.1.3.0 - Hewlett-Packard Company)

HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP)

HP MediaSmart DVD (HKLM-x32\…\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 2.1.2328 - Hewlett-Packard)

HP MediaSmart Music/Photo/Video (HKLM-x32\…\InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}) (Version: 2.2.2829 - Hewlett-Packard)

HP MediaSmart SlingPlayer (HKLM-x32\…\HP.MediaSmartSlingPlayer_is1) (Version: 2.1 - Sling Media, Inc.)

HP MediaSmart SmartMenu (HKLM\…\{0BC595C4-F736-4EB4-A1C0-32C7E81800F0}) (Version: 2.1.10 - Hewlett-Packard)

HP MediaSmart TV (HKLM-x32\…\InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}) (Version: 2.1.1709 - Hewlett-Packard)

HP MediaSmart Webcam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.2.1621 - Hewlett-Packard)

HP Officejet 4500 G510g-m (HKLM\…\{E5083D57-D93F-404C-A91F-1C50D67C2BEB}) (Version: 13.0 - HP)

HP Quick Launch Buttons (HKLM-x32\…\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.17.1 - Hewlett-Packard Company)

HP Smart Web Printing 4.5 (HKLM\…\HP Smart Web Printing) (Version: 4.5 - HP)

HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)

HP Support Solutions Framework (HKLM-x32\…\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company)

HP Total Care Advisor (HKLM-x32\…\{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}) (Version: 2.4.5991.2847 - Hewlett-Packard)

HP Total Care Setup (HKLM-x32\…\{95A747E0-DF19-46CB-A622-20A0107201BD}) (Version: 1.1.2413.2876 - Hewlett-Packard Company)

HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)

HP User Guides 0135 (HKLM-x32\…\{372ED957-0FB5-487B-B51A-388B3D393F7A}) (Version: 1.01.0000 - Hewlett-Packard)

HP Wireless Assistant (HKLM-x32\…\{462DED50-EC2E-4237-ABCF-B5C463C0EE51}) (Version: 3.50.3.1 - Hewlett-Packard)

HPAsset component for HP Active Support Library (x32 Version: 3.0.2.2 - Hewlett-Packard) Hidden

HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden

HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden

HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden

IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6146.0 - IDT)

Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version:  - Intel Corporation)

iTunes (HKLM\…\{CEC7613B-E286-4A31-BEE3-3F7798488D9F}) (Version: 12.1.3.6 - Apple Inc.)

Java 8 Update 60 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)

Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1312 - CyberLink Corp.)

LabelPrint (x32 Version: 2.5.1312 - CyberLink Corp.) Hidden

LightScribe System Software  1.14.17.1 (HKLM-x32\…\{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}) (Version: 1.14.17.1 - LightScribe)

Logitech Unifying Software 2.10 (HKLM\…\Logitech Unifying) (Version: 2.10.37 - Logitech)

Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)

MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden

Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden

Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)

Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)

Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)

Microsoft Office Live Add-in 1.5 (HKLM-x32\…\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)

Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)

Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)

Microsoft Office Standard Edition 2003 (HKLM-x32\…\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)

Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)

Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)

Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\…\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\…\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)

Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\…\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)

MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)

MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)

muvee Reveal (HKLM-x32\…\{DE626616-D7C4-4F00-7E0B-EAF26FA65749}) (Version: 7.0.43.12698 - muvee Technologies Pte Ltd)

My HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.0.62 - WildTangent)

Network64 (Version: 130.0.550.000 - Hewlett-Packard) Hidden

NTI Ripper (HKLM-x32\…\{88A785A2-3EA6-4A2D-ABEE-68E9E55A39F8}) (Version: 2.0.0.17 - NewTech Infosystems)

NTI Shadow 3 (HKLM-x32\…\{E9EB5689-4F76-4E3C-A675-5ED5F52AB890}) (Version: 3.1.4.0 - NewTech Infosystems)

OCR Software by I.R.I.S. 13.0 (HKLM\…\HPOCR) (Version: 13.0 - HP)

Origin (HKLM-x32\…\Origin) (Version: 9.4.6.2792 - Electronic Arts, Inc.)

PDF Suite 2015 (HKLM-x32\…\PDF Suite 2015) (Version: 13.0.10.21694 - Interactive Brands Malta Limited)

PDF Suite 2015 (x32 Version: 13.0.23.21617 - Interactive Brands Malta Limited) Hidden

PDF Suite 2015 OCR Module (x32 Version: 13.0.23.21617 - Interactive Brands Malta Limited) Hidden

PhotoScape (HKLM-x32\…\PhotoScape) (Version:  - )

Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.2512 - CyberLink Corp.)

Power2Go (x32 Version: 6.0.2512 - CyberLink Corp.) Hidden

PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2512 - CyberLink Corp.)

PowerDirector (x32 Version: 7.0.2512 - CyberLink Corp.) Hidden

ProtectSmart Hard Drive Protection (HKLM\…\{2F97CE84-9C33-4631-821B-85EA371EA254}) (Version: 3.10.1.7 - Hewlett-Packard)

QLBCASL (x32 Version: 6.40.17.2 - Hewlett-Packard) Hidden

QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)

Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek)

Realtek USB 2.0 Card Reader (HKLM-x32\…\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: 6.0.6000.20113 - Realtek Semiconductor Corp.)

Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)

SafeZone Stable 1.48.2066.114 (x32 Version: 1.48.2066.114 - Avast Software) Hidden

Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden

Segoe UI (x32 Version: 15.4.2271.0615 - Microsoft Corp) Hidden

Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 13.0 - HP)

Slingbox - Watch Your TV Anywhere (HKLM-x32\…\{7B798B31-2F33-4DC8-BDA4-D36488E86636}) (Version: 1.0.0 - Sling Media)

SlingPlayer (HKLM-x32\…\InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}) (Version: 1.04.0206 - Sling Media)

SlingPlayer (x32 Version: 1.04.0206 - Sling Media) Hidden

SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden

SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden

Spelling Dictionaries Support For Adobe Reader 9 (HKLM-x32\…\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)

Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden

Steam (HKLM-x32\…\Steam) (Version:  - Valve Corporation)

swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden

Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated)

Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden

TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden

TurboTax 2012 (HKLM-x32\…\TurboTax 2012) (Version: 2012.0 - Intuit, Inc)

Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden

WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden

WildTangent Games App (HP Games) (HKLM-x32\…\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.31 - WildTangent)

Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)

Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)

Windows Live Sync (HKLM-x32\…\{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}) (Version: 14.0.8064.206 - Microsoft Corporation)

Xilisoft Video Converter Ultimate (HKLM-x32\…\Xilisoft Video Converter Ultimate) (Version: 7.7.3.20131014 - Xilisoft)

Yahoo Search Set (HKLM-x32\…\Yahoo! SearchSet) (Version:  - Yahoo Inc.)

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {1E47DECC-A445-437E-BA49-BF68A0FE709D} - System32\Tasks\HP Health Check => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09] (Hewlett-Packard)

Task: {1EEC94E2-3371-4445-B69E-06C410B6EE74} - System32\Tasks\{6EA9492D-AFAD-4611-B778-FEF2E452B324} => pcalua.exe -a "C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GJQZPLZ1\Athena[1].exe" -d C:\Users\raypahl\Desktop

Task: {24AF7C9D-752C-4445-A82B-1BE9CDF09079} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

Task: {2676CF9D-8246-4E69-9166-E93FAAEF4707} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-03] (Adobe Systems Incorporated)

Task: {3712F5A0-0477-4593-898F-2D6722E1694A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

Task: {5BF15EEE-CE81-46B3-97C4-2F0217BF3198} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)

Task: {6E74CFCE-FF9D-417D-9884-56337FA84896} - System32\Tasks\HPCeeScheduleForraypahl => C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe [2008-05-19] (Hewlett-Packard)

Task: {C4A2780D-68B8-4F95-A118-6E5DD88047E0} - System32\Tasks\NetworkWizardHNW => C:\Program Files (x86)\Hewlett-Packard\HP TCS\RemEngine.exe [2008-12-17] ()

Task: {E226896F-2D00-4835-94CA-6E3EE9E822E0} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-29] (AVAST Software)

Task: {EC1DA6EA-D89F-45D1-96DA-F64D32C2C68E} - System32\Tasks\SafeZone scheduled Autoupdate 1468319266 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-06-17] (Avast Software)

Task: {EC3518F0-B320-4AC6-B0D1-D131875A226A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

Task: {ECBDA076-B4B3-4E77-8185-DC8446925D32} - System32\Tasks\{2DF12692-40FF-4911-A6C8-8B1BF5365384} => pcalua.exe -a C:\Users\raypahl\AppData\Local\Microsoft\Windows\Burn\Burn\callatlanta_setup.exe

Task: {F1351889-C902-458D-940D-9EEB132FCC88} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)

Task: {FD30349E-1798-46DF-A9FF-96869C61C29C} - System32\Tasks\{B8696691-6D99-40A1-8CEE-83EC12275D01} => pcalua.exe -a C:\Users\raypahl\Desktop\esetsmartinstaller_enu.exe -d C:\Users\raypahl\Desktop

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\HPCeeScheduleForraypahl.job => C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe

 

==================== Shortcuts =============================

 

(The entries could be listed to be restored or removed.)

 

Shortcut: C:\Users\raypahl\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.com

 

==================== Loaded Modules (Whitelisted) ==============

 

2009-03-06 02:02 - 2008-12-23 19:18 - 00365952 _____ () C:\Program Files (x86)\SMINST\BLService.exe

2009-03-06 01:55 - 2008-11-25 18:29 - 00247152 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

2008-11-26 19:13 - 2008-11-26 19:13 - 00296320 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe

2008-11-26 19:13 - 2008-11-26 19:13 - 00116096 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe

2015-03-20 18:12 - 2015-03-20 18:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll

2015-03-20 18:12 - 2015-03-20 18:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll

2008-11-26 19:12 - 2008-11-26 19:12 - 00074536 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\Common\MCEMediaStatus64.dll

2009-07-01 15:44 - 2009-07-01 15:44 - 00632888 _____ () C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe

2016-08-29 18:18 - 2016-08-29 18:18 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll

2016-11-04 08:16 - 2016-11-04 08:16 - 03127760 _____ () C:\Program Files\AVAST Software\Avast\defs\16110400\algo.dll

2016-08-29 18:18 - 2016-08-29 18:18 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll

2009-03-06 02:02 - 2008-12-23 19:18 - 00132480 _____ () C:\Program Files (x86)\SMINST\STWmiM.dll

2009-03-06 01:55 - 2008-11-25 18:29 - 00034088 _____ () C:\Program Files (x86)\Cyberlink\Shared files\RichVideops.dll

2008-11-26 19:13 - 2008-11-26 19:13 - 00263560 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLCapEngine.dll

2008-11-26 19:13 - 2008-11-26 19:13 - 00038184 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLCapSvcps.dll

2007-07-12 15:55 - 2007-07-12 15:55 - 01581056 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll

2007-08-14 15:59 - 2007-08-14 15:59 - 06365184 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll

2007-07-12 15:55 - 2007-07-12 15:55 - 00131072 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll

2014-10-10 12:41 - 2014-10-10 12:41 - 01255936 _____ () C:\Program Files (x86)\CBS Interactive\Download App\libcurl.dll

2014-10-10 12:39 - 2014-10-10 12:39 - 00066560 _____ () C:\Program Files (x86)\CBS Interactive\Download App\zlib.dll

2008-11-26 19:13 - 2008-11-26 19:13 - 00349480 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLTinyDB.dll

2009-04-29 22:11 - 2009-04-29 22:11 - 00906536 ____N () C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll

2016-07-11 22:01 - 2016-07-11 22:02 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

2016-11-04 11:08 - 2016-11-04 11:08 - 00098816 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32api.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00110080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pywintypes27.dll

2016-11-04 11:08 - 2016-11-04 11:08 - 00364544 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pythoncom27.dll

2016-11-04 11:08 - 2016-11-04 11:08 - 00320512 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32com.shell.shell.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00914432 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_hashlib.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 01176576 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._core_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00806400 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._gdi_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00816128 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._windows_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 01067008 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._controls_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00733184 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._misc_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00682496 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pysqlite2._sqlite.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00088064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_ctypes.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00686080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\unicodedata.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00119808 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32file.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00108544 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32security.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00007168 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\hashobjs_ext.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00017920 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\thumbnails_ext.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00088064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\usb_ext.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00012800 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\common.time34.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00018432 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32event.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00167936 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32gui.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00046080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_socket.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 01303552 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_ssl.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00128512 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_elementtree.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00127488 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pyexpat.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00038912 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32inet.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00036864 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_psutil_windows.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00524248 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\windows._lib_cacheinvalidation.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00011264 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32crypt.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00123392 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._wizard.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00077312 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._html2.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00027648 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_multiprocessing.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00020480 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_yappi.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00035840 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32process.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00078848 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._animate.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00024064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32pipe.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00010240 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\select.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00025600 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32pdh.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00017408 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32profile.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00022528 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32ts.pyd

2016-09-06 14:28 - 2016-09-06 12:00 - 05197312 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libglesv2.dll

2016-09-06 14:28 - 2016-09-06 12:00 - 00147456 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libegl.dll

2016-07-13 04:28 - 2016-07-06 18:01 - 17602240 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\PepperFlash\22.0.0.209\pepflashplayer.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

 

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

 

==================== Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

HKLM\…\cmdfile\DefaultIcon: %SystemRoot%\System32\shell32.dll,-153 <===== ATTENTION

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

IE trusted site: HKU\S-1-5-21-513785977-584283709-202011636-1000\…\intuit.com -> hxxps://accounts.intuit.com

IE trusted site: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\intuit.com -> hxxps://accounts.intuit.com

 

==================== Hosts content: ===============================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2006-11-02 07:34 - 2006-09-18 16:37 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts

 

127.0.0.1       localhost

::1             localhost

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg

HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg

HKU\S-1-5-21-513785977-584283709-202011636-1000\Control Panel\Desktop\\Wallpaper ->

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper ->

DNS Servers: 75.75.75.75 - 75.75.76.76

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)

Windows Firewall is enabled.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Constant Guard.lnk => C:\Windows\pss\Constant Guard.lnk.CommonStartup

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Fast Connect.lnk => C:\Windows\pss\Fast Connect.lnk.CommonStartup

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe

FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe

FirewallRules: [{85CA64C5-0E24-49D3-962C-757C4D4EF5EA}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE

FirewallRules: [{C056B941-D6C9-43C2-BC46-C8062C7E9591}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe

FirewallRules: [{A477DEFD-C4F3-49DF-9493-DCB0193B3DC2}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe

FirewallRules: [{9DA0FA66-F81F-4C49-93E4-0C736F80D266}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe

FirewallRules: [{D62589CC-FCFC-474B-897E-5F4E2E376DB6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\TSMAgent.exe

FirewallRules: [{0C18A91B-06AB-412C-A4FB-56721866C9EB}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe

FirewallRules: [{90B91326-6994-4D67-8710-402213196972}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe

FirewallRules: [{892F181D-FCD8-4749-A566-1DDE9D5E06C6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QP.exe

FirewallRules: [{218696AD-0268-44D1-958A-9FB0C07367EE}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QPService.exe

FirewallRules: [{C0D11A95-3BAB-4C69-9B2F-ABDF0DE00382}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe

FirewallRules: [{DA361D62-6094-45AB-8548-C892212DD857}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe

FirewallRules: [{E29DF1CE-61F4-4C67-B5E6-018649FED1F0}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe

FirewallRules: [{28D8EE93-F60E-412F-B1D8-2540677725C9}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe

FirewallRules: [{2C5DE510-0436-4BA6-9D33-EA65AD777F21}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe

FirewallRules: [{2121075F-A168-42F2-A24D-D0A4C9205054}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe

FirewallRules: [{899817AC-8E24-4616-A1BB-9CF013A72458}] => (Allow) LPort=80

FirewallRules: [{801C85E3-1031-4FA1-9462-DDCCDD72601F}] => (Allow) LPort=80

FirewallRules: [{2A217FCB-85BA-4D43-88A5-E696A21C17BE}] => (Allow) LPort=80

FirewallRules: [{67913156-DF65-4018-B0AC-C4BA598F0458}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

FirewallRules: [{F97F9C53-4B16-44C5-9DAB-BE26D646BB2E}] => (Allow) LPort=2869

FirewallRules: [{ECDA4AA6-F84F-4F8C-A5C2-0981BEB965AB}] => (Allow) LPort=1900

FirewallRules: [{99E21AA7-60B0-4758-9700-947CE68E6FC4}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

FirewallRules: [{556638C7-DDD1-49D4-B540-2BF1813097BE}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe

FirewallRules: [{BA7B17AA-ECB1-48CA-B123-DEDEF25F5280}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{C8533641-5BA2-4226-AFAD-01CAA75D4BC3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{2079C40C-30DB-4EC9-A37D-2A69F7CB2B9A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{7AA88511-8B20-4763-AB96-65C325F436C2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{8338DBF9-E8CD-40AC-A575-BC1C4D3264AE}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{49D4AFA4-BDA6-4F09-A81E-C49E81BDD809}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{F2531826-2F73-4998-9503-3CB1A9EF475A}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{50BB60C3-956B-46D3-BD6E-BF3715DAEAA8}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{938E4FAF-25DE-43F0-8941-BAB51D00909F}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{32D0853C-F33F-4CA2-BDD9-EB0E43C2C1A9}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe

FirewallRules: [{028CDA9D-6AA2-48CC-97F4-8CB3BFFEDCAE}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe

FirewallRules: [{24ED04E3-69B3-4EF6-AB2B-774FF6EBB341}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe

FirewallRules: [{B498508E-E2F8-420D-AF6B-5E4EB2847438}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe

FirewallRules: [{149237F6-0247-4D6A-9B24-6284C0EC1F6E}] => (Allow) LPort=80

FirewallRules: [{0D5BE560-6B3C-4CA0-A163-4A0D4761952F}] => (Allow) LPort=3074

FirewallRules: [{46BBA3EE-07CF-43BA-B750-B59D6FEA6E67}] => (Allow) LPort=53

FirewallRules: [{1937BBB4-CCBA-487B-ABF4-965EBD64F35D}] => (Allow) LPort=88

FirewallRules: [{0B06D53B-770D-4F4F-8750-588083139BD4}] => (Allow) LPort=3074

FirewallRules: [{63DB0018-84DB-4F7D-91A6-5EEB5D473E2C}] => (Allow) LPort=53

FirewallRules: [{4BD011AB-0AC7-4B5A-A0CF-466CC36B4E10}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS6610\HPDiagnosticCoreUI.exe

FirewallRules: [{5CFF6CC9-FFCC-4E3F-BC41-D4AC77525B27}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS6610\HPDiagnosticCoreUI.exe

FirewallRules: [{D627BCA2-CF30-4E83-813D-55AE2787BACA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe

FirewallRules: [{8EBE220A-A2E8-47DC-9A52-C00C722B2B36}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe

FirewallRules: [{67F0DD1B-2C2B-4DF0-83BD-CA448BAF87E8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe

FirewallRules: [{277CCB2A-D8F2-4438-8B24-11CC51D7A2DD}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe

FirewallRules: [{A4D4FBBF-F068-4D39-8BE3-74355B903AB7}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3C2E\HPDiagnosticCoreUI.exe

FirewallRules: [{71675975-38A1-48EA-ACCB-FABEF0BD9D13}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3C2E\HPDiagnosticCoreUI.exe

FirewallRules: [{56345E73-9C25-4274-A858-4690E48E1F67}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS64AB\HPDiagnosticCoreUI.exe

FirewallRules: [{E16F485C-ED68-4BD6-8805-2A64A9D96A39}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS64AB\HPDiagnosticCoreUI.exe

FirewallRules: [{31BE109E-8AF9-4143-AD52-57F7DB7FAED8}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS0964\HPDiagnosticCoreUI.exe

FirewallRules: [{A93D5B10-FD8F-4B4F-B432-6A12E6A2D0DC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS0964\HPDiagnosticCoreUI.exe

FirewallRules: [{7C26B91E-B117-486A-B514-1E931777327D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

FirewallRules: [{3D0B25BE-B075-4318-8FAD-AA4378D408D4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe

FirewallRules: [{3190CC53-3DB5-4C54-B6F1-0770B51650F2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe

FirewallRules: [{D9A183D9-B520-4D17-8D52-4341A9CFBBEC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe

FirewallRules: [{BCEEDD97-2D66-466F-B460-54D582497581}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe

FirewallRules: [{603C8A2D-FB38-49BD-9FDD-2934CAECAE11}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe

FirewallRules: [{DDEE3F5E-97F1-4B23-9929-9B3755027FC8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe

FirewallRules: [{38A2B6F1-AE10-4306-AC8B-57D65B8552FB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe

FirewallRules: [{A6BD5514-3186-4D82-ACE9-8AFC163F591F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe

FirewallRules: [{E5BEACAE-D7A3-4D30-8284-ED4CDC7EE1F1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe

FirewallRules: [{55C0994B-0B3E-444F-A6F1-771232CE4C04}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe

FirewallRules: [{24942CC8-CEE3-42BD-AE57-6FC7B5B01D26}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe

FirewallRules: [{80E01553-7E49-42EB-84AA-260B63480BFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe

FirewallRules: [{3D37A03B-72C1-4951-AACC-F8F9842EAC32}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe

FirewallRules: [{9851363A-29E7-4066-808D-76F09B44EAA9}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{6DF5A30B-3B0F-4CC8-91E7-C21179661239}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe

FirewallRules: [{00C3DF64-1789-45C4-826E-F88407B37F60}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{8060B257-FF11-4A7E-B4D6-8822812D5766}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{FDC220B2-E26C-439A-8AEE-6CB05A6A9CDF}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{0548CB3C-9BAA-419F-AC3C-CF92119ECF94}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{23D1FC3D-674C-44F8-9961-46BBEB100F2F}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{069C9567-F251-4E40-B6F7-7B7D7D9109AC}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{D99F3B45-4583-426E-8CDF-DF5E521807C6}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{D41E6F5E-2589-4C57-9E12-1D63C165791D}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{6DEEE18D-D523-45BF-932E-CE5743988EE8}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{43D52C1D-478B-4FCE-9745-AAF8982DF4DC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS175A\HPDiagnosticCoreUI.exe

FirewallRules: [{A707CC94-5C2F-4D23-8BCD-1307DBA1F380}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS175A\HPDiagnosticCoreUI.exe

FirewallRules: [{D5F39F1E-2D2C-4FE4-AC8F-7D1244D261F1}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS17E3\HPDiagnosticCoreUI.exe

FirewallRules: [{98DD6223-287E-4612-84C7-8256612DF4EE}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS17E3\HPDiagnosticCoreUI.exe

FirewallRules: [{A5F88943-D64D-41D9-ACDD-54EDBEC8ECC3}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS61A2\HPDiagnosticCoreUI.exe

FirewallRules: [{0295B60A-D80C-449F-A559-2559D30C56ED}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS61A2\HPDiagnosticCoreUI.exe

FirewallRules: [{B26FD28B-080C-4DC6-84AF-10360A7C1848}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS326C\HPDiagnosticCoreUI.exe

FirewallRules: [{EDDD3BB6-DE4D-491F-9E82-60EED756FAB0}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS326C\HPDiagnosticCoreUI.exe

FirewallRules: [{720847F8-E7ED-4F05-A979-64A3CABFD9A4}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{9DED4120-5843-4CD7-96F8-BA8DC78DD4D2}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{5188845E-5ABE-493A-8AE3-C562AF667662}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3742\HPDiagnosticCoreUI.exe

FirewallRules: [{87FB02D8-EDC9-4628-8196-40F55E2955A2}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3742\HPDiagnosticCoreUI.exe

FirewallRules: [{37154139-4F88-40F7-8C66-F721A336A600}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3780\HPDiagnosticCoreUI.exe

FirewallRules: [{D47BCBCC-ADF9-4F87-BCFB-E6EFD8A23273}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3780\HPDiagnosticCoreUI.exe

FirewallRules: [{C550D466-6DA9-4CF3-AF39-E1B7B9D3491A}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS5F6B\HPDiagnosticCoreUI.exe

FirewallRules: [{ABBB6631-70E4-4D5A-8D5D-105E6B6C2047}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS5F6B\HPDiagnosticCoreUI.exe

FirewallRules: [{735A1C21-05AD-49A7-B856-D8DB046D814B}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{072D341C-F0AA-4EC4-B256-90AA1A0371D6}] => (Allow) C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe

FirewallRules: [{0E09CE06-6B58-4C5C-B41F-9CBC3C28310F}] => (Allow) C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe

FirewallRules: [{AF858CCB-A6DC-41B2-A8F1-DEC030D92EEB}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{4850BCB1-4BDE-4888-9338-413BF216736F}] => (Allow) C:\Program Files\iTunes\iTunes.exe

FirewallRules: [{37A8803F-79F3-4EA8-B4DC-EFC8C0988147}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

FirewallRules: [TCP Query User{05B7B3B1-49C4-42B6-B68A-EFF0B868DFBB}C:\program files (x86)\swannview link\mydvr.exe] => (Allow) C:\program files (x86)\swannview link\mydvr.exe

FirewallRules: [UDP Query User{3A8123E3-4600-46C8-8ACE-AF6FB9F3DE3D}C:\program files (x86)\swannview link\mydvr.exe] => (Allow) C:\program files (x86)\swannview link\mydvr.exe

FirewallRules: [TCP Query User{0B8D5604-9A95-4CBA-99CC-80CD63F8BD63}C:] => (Allow) C:\

FirewallRules: [UDP Query User{423E6DF9-8B53-405B-8F7D-6926AE5B5679}C:] => (Allow) C:\

FirewallRules: [{954DDB9D-8A37-4449-BC09-F3070B20367E}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS420D\HPDiagnosticCoreUI.exe

FirewallRules: [{DA174395-2E36-4D4D-B5EC-11BFF9576FD7}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS420D\HPDiagnosticCoreUI.exe

FirewallRules: [{53EE87C1-3AC3-43AD-B1D9-4ECE6A351714}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS42CB\HPDiagnosticCoreUI.exe

FirewallRules: [{6A40C1D8-44EC-4858-97A6-EAE58655C9EC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS42CB\HPDiagnosticCoreUI.exe

FirewallRules: [{5537C001-D930-41E2-B89C-942DB712A6B9}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS4196\HPDiagnosticCoreUI.exe

FirewallRules: [{665ECD78-617F-490D-B46F-145BA00FC68D}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS4196\HPDiagnosticCoreUI.exe

 

==================== Restore Points =========================

 

 

==================== Faulty Device Manager Devices =============

 

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (11/04/2016 11:13:24 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application jucheck.exe, version 2.8.60.27, time stamp 0x55c116b1, faulting module jucheck.exe, version 2.8.60.27, time stamp 0x55c116b1, exception code 0x40000015, fault offset 0x00052d24,

process id 0x13fc, application start time 0x01d236b6291b8d5d.

 

Error: (11/04/2016 11:12:07 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/04/2016 11:12:07 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0xfa0, application start time 0x01d236b5be6c075d.

 

Error: (11/04/2016 11:08:36 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/04/2016 11:08:36 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0xb08, application start time 0x01d236b55e2842ad.

 

Error: (11/04/2016 11:06:08 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

Error: (11/04/2016 11:05:19 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/04/2016 11:05:19 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0x200, application start time 0x01d236b296f38870.

 

Error: (11/03/2016 08:34:51 PM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/03/2016 08:34:51 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0x105c, application start time 0x01d2363b354c4410.

 

 

System errors:

=============

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

 

CodeIntegrity:

===================================

  Date: 2016-11-04 11:16:11.209

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:10.273

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:09.368

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:08.463

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:07.403

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:06.420

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:02.192

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:01.225

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:00.242

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:15:59.259

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

 

==================== Memory info ===========================

 

Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz

Percentage of memory in use: 77%

Total physical RAM: 3998.02 MB

Available physical RAM: 897.88 MB

Total Virtual: 8221.28 MB

Available Virtual: 4898.43 MB

 

==================== Drives ================================

 

Drive c: () (Fixed) (Total:452.13 GB) (Free:143.29 GB) NTFS ==>[drive with boot components (obtained from BCD)]

Drive d: (RECOVERY) (Fixed) (Total:13.62 GB) (Free:2.09 GB) NTFS ==>[system with boot components (obtained from drive)]

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (Size: 465.8 GB) (Disk ID: 636BBFB1)

Partition 1: (Active) - (Size=452.1 GB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=13.6 GB) - (Type=07 NTFS)

 

==================== End of Addition.txt ============================

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software

Run date: 2016-11-04 12:17:48

—————————–

12:17:48.853    OS Version: Windows x64 6.0.6002 Service Pack 2

12:17:48.853    Number of processors: 2 586 0x170A

12:17:48.853    ComputerName: STEARNS-PC  UserName: raypahl

12:18:03.243    Initialize success

12:18:03.259    VM: initialized successfully

12:18:03.259    VM: Intel CPU virtualization not supported

12:18:17.053    AVAST engine defs: 16110400

12:18:33.738    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0

12:18:33.738    Disk 0 Vendor: TOSHIBA_MK5055GSX FG002C Size: 476940MB BusType: 3

12:18:34.284    Disk 0 MBR read successfully

12:18:34.300    Disk 0 MBR scan

12:18:34.628    Disk 0 unknown MBR code

12:18:34.674    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       462985 MB offset 2048

12:18:35.064    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        13951 MB offset 948195328

12:18:36.094    Disk 0 scanning C:\Windows\system32\drivers

12:19:48.861    Service scanning

12:23:22.187    Modules scanning

12:23:22.187    Disk 0 trace - called modules:

12:23:22.732    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys

12:23:22.732    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006478060]

12:23:22.748    3 CLASSPNP.SYS[fffffa6000a4ec33] -> nt!IofCallDriver -> [0xfffffa8006245310]

12:23:22.748    5 hpdskflt.sys[fffffa6001802189] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004bf1590]

12:23:35.110    AVAST engine scan C:\Windows

12:23:52.825    AVAST engine scan C:\Windows\system32

12:38:13.645    Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\MBR.dat"

12:38:13.661    The log file has been saved successfully to "C:\Users\raypahl\Documents\aswMBR.txt"

12:38:52.007    AVAST engine scan C:\Windows\system32\drivers

12:40:35.754    AVAST engine scan C:\Users\raypahl

13:04:35.987    Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\MBR.dat"

13:04:36.031    The log file has been saved successfully to "C:\Users\raypahl\Documents\aswMBR.txt"

13:07:08.922    Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\deb\computer help\MBR.dat"

13:07:08.929    The log file has been saved successfully to "C:\Users\raypahl\Documents\deb\computer help\aswMBR.txt"

 

 

 

My computer is really slow.  Especially at start up, takes about 15 minutes.  I get a message that says, “host process for windows services stopped working and must close.”

 

Any help would be appreciated.

 

Here are my logs.

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-11-2016

Ran by [removed] (administrator) on STEARNS-PC (04-11-2016 12:33:25)

Running from C:\Users\[removed]\Desktop

[removed]

Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) Language: English (United States)

Internet Explorer Version 9 (Default browser: Chrome)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\stacsv64.exe

(Microsoft Corporation) C:\Windows\System32\SLsvc.exe

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe

(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\AESTSr64.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe

() C:\Program Files (x86)\SMINST\BLService.exe

() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

() C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe

() C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe

(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE

(Intel Corporation) C:\Windows\System32\igfxtray.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe

(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe

(Microsoft Corporation) C:\Windows\ehome\ehtray.exe

(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe

(CBS Interactive Inc.) C:\Program Files (x86)\CBS Interactive\Download App\CBSI.AppStore.Scanner.exe

(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe

(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe

( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe

(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe

(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe

(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe

(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe

(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe

(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe

(Intel Corporation) C:\Windows\System32\igfxsrvc.exe

(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe

(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe

(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqste08.exe

(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqbam08.exe

(Hewlett-Packard) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqgpc01.exe

(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe

(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe

(AVAST Software) C:\Users\raypahl\Desktop\aswMBR.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

 

 

==================== Registry (Whitelisted) ====================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)

HKLM\…\Run: [SmartMenu] => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [915000 2009-01-08] (Hewlett-Packard)

HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-20] (Microsoft Corporation)

HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [463360 2009-01-28] (IDT, Inc.)

HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169744 2015-09-12] (Apple Inc.)

HKLM-x32\…\Run: [DVDAgent] => C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe [1148200 2008-11-28] (CyberLink Corp.)

HKLM-x32\…\Run: [TVAgent] => C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe [202024 2009-05-11] (CyberLink Corp.)

HKLM-x32\…\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.)

HKLM-x32\…\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-01-13] (CyberLink Corp.)

HKLM-x32\…\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [323640 2010-02-25] ( Hewlett-Packard Development Company, L.P.)

HKLM-x32\…\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-04] (CyberLink Corp.)

HKLM-x32\…\Run: [UpdatePDIRShortCut] => C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [218408 2008-12-04] (CyberLink Corp.)

HKLM-x32\…\Run: [HP Health Check Scheduler] => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-10-09] (Hewlett-Packard)

HKLM-x32\…\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [484408 2009-01-23] (Hewlett-Packard)

HKLM-x32\…\Run: [TSMAgent] => C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe [1328424 2009-04-29] (CyberLink Corp.)

HKLM-x32\…\Run: [CLMLServer for HP TouchSmart] => C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [185640 2009-04-29] (CyberLink)

HKLM-x32\…\Run: [UCam_Menu] => C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.)

HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)

HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)

HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9099440 2016-11-03] (AVAST Software)

HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)

HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)

HKLM-x32\…\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2014-04-23] (Lavasoft)

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

HKU\S-1-5-19\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-20\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [cdloader] => C:\Users\raypahl\AppData\Roaming\mjusbsp\cdloader2.exe [50520 2009-08-01] (magicJack L.P.)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818720 2016-09-19] (Google)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-11-11] (Electronic Arts)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [736701A46C7D59E46F8F7D9F95111119F406C6DA._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.)

HKU\S-1-5-21-513785977-584283709-202011636-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [334336 2008-01-20] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [cdloader] => C:\Users\raypahl\AppData\Roaming\mjusbsp\cdloader2.exe [50520 2009-08-01] (magicJack L.P.)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818720 2016-09-19] (Google)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-11-11] (Electronic Arts)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [736701A46C7D59E46F8F7D9F95111119F406C6DA._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [334336 2008-01-20] (Microsoft Corporation)

ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)

ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)

ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-29] (AVAST Software)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2014-04-30]

ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

Startup: C:\Users\raypahl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Download App.lnk [2015-02-15]

ShortcutTarget: Download App.lnk -> C:\Program Files (x86)\CBS Interactive\Download App\CBSI.AppStore.Scanner.exe (CBS Interactive Inc.)

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76

Tcpip\..\Interfaces\{801647DA-8FFF-4244-BC31-E0870B9F67FE}: [DhcpNameServer] 75.75.75.75 75.75.76.76

Tcpip\..\Interfaces\{94FA59CE-8C9A-4984-B67B-149BBF13BD4C}: [NameServer] 8.8.8.8,208.67.222.222,8.8.4.4,208.67.220.220

Tcpip\..\Interfaces\{94FA59CE-8C9A-4984-B67B-149BBF13BD4C}: [DhcpNameServer] 75.75.75.75 75.75.76.76

 

Internet Explorer:

==================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID;=130892846893110000&GUID;=764FC242-5591-4ABF-9B6A-E9976335B01D

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =

HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006

SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {7EEAD0DA-121E-498E-B773-B8F0B4C4AAB1} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {94A0FAC8-4922-45B9-B85C-DE11B41E351F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSERBM&pc;=MSERT1

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {A9E5F592-BF1B-41BF-AFF4-9CAC82733B93} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_ie_syc_oracle&type;=orcl_default

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid;=1&pid;=21&src;=sgsearch&v;=1.15.414.3&searchparam;={SearchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {7EEAD0DA-121E-498E-B773-B8F0B4C4AAB1} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {94A0FAC8-4922-45B9-B85C-DE11B41E351F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSERBM&pc;=MSERT1

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {A9E5F592-BF1B-41BF-AFF4-9CAC82733B93} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_ie_syc_oracle&type;=orcl_default

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid;=1&pid;=21&src;=sgsearch&v;=1.15.414.3&searchparam;={SearchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software)

BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)

BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File

BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)

BHO-x32: PDF Suite 2015 Helper -> {5B91DFF7-1E67-4A1E-99D4-F3A09B8459AD} -> C:\Program Files (x86)\PDF Suite 2015\creator-ie-helper.dll [2015-01-23] (Interactive Brands Malta Limited)

BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\IPS\IPSBHO.DLL => No File

BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software)

BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)

BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation)

BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)

Toolbar: HKLM-x32 - PDF Suite 2015 Toolbar - {D623F6CA-49B6-4097-A62F-4D60C829D63D} - C:\Program Files (x86)\PDF Suite 2015\creator-ie-plugin.dll [2015-01-23] (Interactive Brands Malta Limited)

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File

DPF: HKLM-x32 {8714912E-380D-11D5-B8AA-00D0B78F3D48} hxxp://chat.yahoo.com/cab/yuplapp.cab

 

FireFox:

========

FF HKLM\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.2.15\coFFAddon => not found

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF

FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-29]

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF

FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-08-29]

FF HKLM-x32\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-22] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-04-30] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\PDF Suite 2015\resources\pdfsuite2015firefoxextension

FF Extension: (PDF Suite 2015) - C:\Program Files (x86)\PDF Suite 2015\resources\pdfsuite2015firefoxextension [2016-02-20] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF

FF HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_205.dll [2016-11-03] ()

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll [2016-11-03] ()

FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)

FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)

FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)

FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)

FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2012-04-11] ()

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)

FF Plugin-x32: PDF Suite 2015 -> C:\Program Files (x86)\PDF Suite 2015\np-previewer.dll [2015-01-23] (Interactive Brands Malta Limited)

 

Chrome:

=======

CHR DefaultProfile: Default

CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp

CHR StartupUrls: Default -> "hxxps://www.facebook.com/","hxxps://www.google.com/","hxxps://www.bing.com/"

CHR DefaultSearchURL: Default -> hxxp://www.search.ask.com/web?q={searchTerms}

CHR DefaultSearchKeyword: Default -> search.ask.com

CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li;=ff&q;={searchTerms}

CHR Plugin: (Widevine Content Decryption Module) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll => No File

CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\PepperFlash\pepflashplayer.dll ()

CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => No File

CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\pdf.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll => No File

CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll => No File

CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll => No File

CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll => No File

CHR Plugin: (Java(TM) Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File

CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)

CHR Plugin: (TelevisionFanatic Installer Plugin Stub) - C:\Program Files (x86)\TelevisionFanaticEI\Installr\1.bin\NP64EISB.dll => No File

CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()

CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll => No File

CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll => No File

CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

CHR Profile: C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default [2016-11-04]

CHR Extension: (Google Drive) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-25]

CHR Extension: (Pearltrees Extension) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgngjfgpahnnncnimlhjgjhdajmaeeoa [2016-08-23]

CHR Extension: (ShopAtHome.com: Deals + Cash Back) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlmebkoiahbppacaicbgncnjhbpdfkcc [2016-10-21]

CHR Extension: (CyberGhost VPN - Free Proxy) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcbnikgemihknccdjaihjnfbapinljpi [2015-08-10]

CHR Extension: (Google Docs Offline) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-01]

CHR Extension: (Avast Online Security) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-11-03]

CHR Extension: (Bing Rewards Helper) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\neodenankcjdlhndmpcffjmcealafaig [2016-02-11]

CHR Extension: (Chrome Web Store Payments) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-06]

CHR Extension: (Bing) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofgaflfnfknmefgjhlgkohmpekighhdi [2016-09-15]

CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security Suite\Engine\22.8.0.50\Exts\Chrome.crx

CHR HKLM\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\Exts\Chrome.crx

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\raypahl\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-12-22]

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\raypahl\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-12-22]

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

CHR HKLM-x32\…\Chrome\Extension: [gihfmmedoddijgnhkgfgnkeohkpbipol] - hxxps://clients2.google.com/service/update2/crx

CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx

 

==================== Services (Whitelisted) ====================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\AESTSr64.exe [88576 2008-11-17] (Andrea Electronics Corporation)

S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-29] (AVAST Software)

R2 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [File not signed]

R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]

R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]

R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1037824 2009-09-08] (Hewlett-Packard Co.) [File not signed]

S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)

S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]

S3 Interactive Brands CrashHandler; C:\Program Files (x86)\PDF Suite 2015\crash-handler-ws.exe [745800 2015-01-23] (Interactive Brands Malta Limited)

S2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2008-06-09] (Hewlett-Packard Company) [File not signed]

S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]

S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-11] (Electronic Arts)

S3 PDF Suite 2015; C:\Program Files (x86)\PDF Suite 2015\ws.exe [1676104 2015-01-23] (Interactive Brands Malta Limited)

S2 PDF Suite 2015 Creator; C:\Program Files (x86)\PDF Suite 2015\creator-ws.exe [622920 2015-01-23] (Interactive Brands Malta Limited)

R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]

R2 Recovery Service for Windows; C:\Program Files (x86)\SMINST\BLService.exe [365952 2008-12-23] ()

R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2008-11-25] ()

R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\STacSV64.exe [290304 2009-01-28] (IDT, Inc.)

R2 TVCapSvc; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [296320 2008-11-26] ()

R2 TVSched; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [116096 2008-11-26] ()

S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-20] (Microsoft Corporation)

S3 WsAppService; C:\Program Files (x86)\Wondershare\WAF\WsAppService.exe [252816 2015-04-30] (Wondershare)

S2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [X]

 

===================== Drivers (Whitelisted) ======================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R1 Amfilter; C:\Windows\System32\DRIVERS\Amfltx64.sys [12288 2007-10-15] ((Standard mouse types))

S3 Amusbprt; C:\Windows\System32\DRIVERS\Amusbx64.sys [17920 2008-02-13] (A4Tech Co.,Ltd.)

S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [78640 2016-06-21] (AVAST Software)

S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-29] (AVAST Software)

R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-29] (AVAST Software)

R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-29] (AVAST Software)

R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [74032 2016-08-29] (AVAST Software)

R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-29] (AVAST Software)

R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-13] (AVAST Software)

R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-22] (AVAST Software)

R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [224616 2016-08-29] (AVAST Software)

S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [74544 2016-08-29] (AVAST Software)

R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)

R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-11-04] (Malwarebytes)

R2 SADP_NPF; C:\Windows\SysWOW64\drivers\sadp_npf64.sys [35344 2012-07-02] (CACE Technologies, Inc.)

S3 ssmirrdr; C:\Windows\System32\DRIVERS\ssmirrdr.sys [10112 2016-02-09] (support.com, Inc)

R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [146928 2008-11-28] (CyberLink Corp.)

S1 AntiLog32; \??\C:\Windows\system32\drivers\AntiLog64.sys [X]

U4 eabfiltr; no ImagePath

S3 IpInIp; system32\DRIVERS\ipinip.sys [X]

S3 keycrypt; system32\DRIVERS\KeyCrypt64.sys [X]

S3 NAVENG; \??\C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\SDSDefs\20160808.001\ENG64.SYS [X]

S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\SDSDefs\20160808.001\EX64.SYS [X]

S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]

S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

U3 aswMBR; \??\C:\Users\raypahl\AppData\Local\Temp\aswMBR.sys [X]

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-11-04 12:38 - 2016-11-04 12:38 - 00000512 _____ C:\Users\raypahl\Documents\MBR.dat

2016-11-04 12:33 - 2016-11-04 12:39 - 00036142 _____ C:\Users\raypahl\Desktop\FRST.txt

2016-11-04 12:31 - 2016-11-04 12:32 - 02409984 _____ (Farbar) C:\Users\raypahl\Desktop\FRST64.exe

2016-11-03 18:57 - 2016-11-03 18:57 - 00000000 ____D C:\ProgramData\EA Logs

2016-10-24 21:36 - 2016-10-24 21:36 - 00002052 _____ C:\Users\Public\Desktop\NTI Digital Jack.lnk

2016-10-24 21:36 - 2016-10-24 21:36 - 00001930 _____ C:\Users\Public\Desktop\NTI Ripper.lnk

2016-10-24 21:36 - 2016-10-24 21:36 - 00000941 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI DigitalJack.lnk

2016-10-24 21:36 - 2016-10-24 21:36 - 00000839 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Ripper.lnk

2016-10-24 21:35 - 2016-10-24 21:35 - 00001024 ___RH C:\Windows\SysWOW64\NTIRIPPER.dll

2016-10-24 21:34 - 2016-11-03 19:08 - 00000584 _____ C:\Users\raypahl\Shadow.xml

2016-10-24 21:32 - 2016-10-24 21:32 - 00000036 __RSH C:\.uid_xxx

2016-10-24 21:28 - 2016-10-24 21:28 - 00001960 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Shadow.lnk

2016-10-24 21:28 - 2016-10-24 21:28 - 00000841 _____ C:\Users\Public\Desktop\NTI Shadow.lnk

2016-10-24 21:28 - 2000-08-02 20:50 - 01056768 _____ (eHelp Corporation.) C:\Windows\SysWOW64\roboex32.dll

2016-10-24 21:26 - 2016-10-24 21:36 - 00000000 ____D C:\Program Files (x86)\NewTech Infosystems

2016-10-24 15:40 - 2016-10-24 15:40 - 00282144 _____ C:\Windows\Minidump\Mini102416-02.dmp

2016-10-24 13:01 - 2016-10-24 13:07 - 00282256 _____ C:\Windows\Minidump\Mini102416-01.dmp

2016-10-21 11:36 - 2016-09-29 23:09 - 17975808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll

2016-10-21 11:36 - 2016-09-29 23:07 - 10891264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll

2016-10-21 11:36 - 2016-09-29 23:07 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec

2016-10-21 11:36 - 2016-09-29 23:06 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb

2016-10-21 11:36 - 2016-09-29 23:05 - 02129920 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl

2016-10-21 11:36 - 2016-09-29 23:05 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 01296384 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00887296 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00528896 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00234496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe

2016-10-21 11:36 - 2016-09-29 23:05 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe

2016-10-21 11:36 - 2016-09-29 23:05 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe

2016-10-21 11:36 - 2016-09-29 22:39 - 12859392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll

2016-10-21 11:36 - 2016-09-29 22:39 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec

2016-10-21 11:36 - 2016-09-29 22:37 - 09731584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 01831424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 01436160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl

2016-10-21 11:36 - 2016-09-29 22:36 - 01095168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 01089024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 00711168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe

2016-10-21 11:36 - 2016-09-29 22:36 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

2016-10-21 11:36 - 2016-09-29 22:35 - 01789952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00217088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00042496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe

2016-10-21 11:36 - 2016-09-29 22:35 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe

2016-10-21 04:18 - 2016-09-30 11:17 - 04693224 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe

2016-10-21 03:21 - 2016-09-10 11:30 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll

2016-10-21 03:20 - 2016-09-10 11:45 - 01690624 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll

2016-10-21 03:20 - 2016-09-10 11:44 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll

2016-10-21 03:20 - 2016-09-10 11:27 - 00075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll

2016-10-21 03:03 - 2016-09-10 10:24 - 02803712 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys

2016-10-21 03:03 - 2016-09-09 10:34 - 01268224 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll

2016-10-21 03:03 - 2016-09-09 10:34 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll

2016-10-21 03:03 - 2016-09-09 10:34 - 00287232 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll

2016-10-21 03:03 - 2016-09-09 10:34 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 00160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll

2016-10-21 03:03 - 2016-09-09 09:57 - 02002944 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll

2016-10-21 03:03 - 2016-09-09 09:56 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll

2016-10-21 03:03 - 2016-09-09 09:44 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll

2016-10-21 03:03 - 2016-09-09 09:43 - 01561600 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll

2016-10-21 03:03 - 2016-09-09 09:42 - 01154560 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll

2016-10-21 03:03 - 2016-09-09 09:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll

2016-10-21 03:03 - 2016-09-09 09:32 - 00486912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll

2016-10-21 03:03 - 2016-09-09 09:23 - 00682496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll

2016-10-21 03:03 - 2016-09-09 09:21 - 01073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll

2016-10-21 03:02 - 2016-09-08 09:39 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys

2016-10-21 03:02 - 2016-09-08 09:39 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys

2016-10-21 03:02 - 2016-09-03 11:08 - 02528768 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll

2016-10-21 03:02 - 2016-09-03 10:50 - 01544704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll

2016-10-21 03:01 - 2016-09-14 20:41 - 00975872 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll

2016-10-21 03:01 - 2016-09-14 20:29 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll

2016-10-21 03:01 - 2016-09-14 19:23 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll

2016-10-21 03:01 - 2016-09-14 19:01 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-11-04 12:38 - 2015-03-26 15:47 - 00002398 _____ C:\Users\raypahl\Documents\aswMBR.txt

2016-11-04 12:33 - 2014-09-03 12:51 - 00000000 ____D C:\FRST

2016-11-04 11:50 - 2012-08-15 05:37 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2016-11-04 11:48 - 2012-03-30 23:57 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job

2016-11-04 11:14 - 2014-08-25 16:46 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

2016-11-04 11:13 - 2013-12-22 22:18 - 00000000 ___RD C:\Users\raypahl\Google Drive

2016-11-04 11:13 - 2011-10-05 06:39 - 00000000 ____D C:\Users\raypahl\AppData\Local\CrashDumps

2016-11-04 11:12 - 2009-03-06 02:08 - 00003584 _____ C:\Windows\System32\Tasks\HP Health Check

2016-11-04 11:09 - 2009-07-21 13:32 - 00009308 _____ C:\ProgramData\HPWALog.txt

2016-11-04 11:00 - 2012-08-15 05:37 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2016-11-04 10:58 - 2016-02-02 22:57 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0.job

2016-11-04 10:53 - 2006-11-02 10:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT

2016-11-04 10:47 - 2006-11-02 10:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

2016-11-04 10:47 - 2006-11-02 10:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

2016-11-03 20:05 - 2009-03-06 00:13 - 00000012 _____ C:\Windows\bthservsdp.dat

2016-11-03 20:05 - 2006-11-02 10:42 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2016-11-03 19:43 - 2012-03-30 23:58 - 00003682 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

2016-11-03 19:42 - 2012-03-30 23:57 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2016-11-03 19:42 - 2011-12-07 21:31 - 00000000 ____D C:\Windows\system32\Macromed

2016-11-03 19:42 - 2011-09-30 18:29 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2016-11-03 19:42 - 2009-03-06 01:12 - 00000000 ____D C:\Windows\SysWOW64\Macromed

2016-11-03 19:32 - 2015-03-26 15:55 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update

2016-11-03 19:10 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\Resources

2016-11-03 19:09 - 2014-08-25 23:08 - 00000000 ____D C:\AdwCleaner

2016-11-03 19:03 - 2012-07-05 02:08 - 00006756 _____ C:\Users\raypahl\AppData\Local\d3d9caps.dat

2016-11-03 19:03 - 2009-03-06 00:47 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2016-11-03 19:02 - 2014-03-17 11:47 - 00000000 ____D C:\Users\raypahl\Documents\Electronic Arts

2016-11-03 19:02 - 2014-03-16 11:43 - 00000000 ____D C:\Program Files (x86)\Origin Games

2016-11-03 18:55 - 2016-08-18 21:11 - 00000000 ____D C:\Program Files (x86)\SwannView Link

2016-11-03 18:54 - 2015-01-29 20:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons

2016-11-03 18:54 - 2015-01-29 20:15 - 00000000 ____D C:\Program Files (x86)\Coupons

2016-11-03 16:35 - 2016-04-06 19:42 - 00468790 _____ C:\Windows\ntbtlog.txt

2016-11-03 16:13 - 2014-08-25 16:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware

2016-11-03 16:13 - 2014-08-25 16:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware

2016-10-29 21:57 - 2009-07-21 13:21 - 00000000 ____D C:\Users\raypahl

2016-10-29 21:57 - 2006-11-02 08:34 - 00000000 ____D C:\Windows\system32\spool

2016-10-29 21:57 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\registration

2016-10-29 21:57 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\inf

2016-10-29 21:57 - 2006-11-02 07:33 - 91226112 _____ C:\Windows\system32\config\software_previous

2016-10-29 21:57 - 2006-11-02 07:33 - 36438016 _____ C:\Windows\system32\config\system_previous

2016-10-29 21:51 - 2006-11-02 07:33 - 00262144 _____ C:\Windows\system32\config\security_previous

2016-10-29 21:51 - 2006-11-02 07:33 - 00262144 _____ C:\Windows\system32\config\sam_previous

2016-10-29 20:05 - 2016-07-13 03:17 - 00000000 _____ C:\Windows\SysWOW64\last.dump

2016-10-29 11:59 - 2006-11-02 07:33 - 00524288 _____ C:\Windows\system32\config\default_previous

2016-10-29 11:49 - 2006-11-02 07:33 - 69992448 _____ C:\Windows\system32\config\components_previous

2016-10-25 13:51 - 2011-10-07 07:07 - 00000000 ____D C:\Program Files (x86)\NortonInstaller

2016-10-25 13:51 - 2009-03-06 00:49 - 00000000 ____D C:\ProgramData\Norton

2016-10-25 11:50 - 2011-10-30 10:04 - 00000000 ____D C:\Users\raypahl\AppData\Roaming\HpUpdate

2016-10-24 21:30 - 2013-08-24 14:09 - 00000000 ____D C:\Users\raypahl\Documents\deb

2016-10-24 21:24 - 2006-11-02 07:46 - 00763734 _____ C:\Windows\system32\PerfStringBackup.INI

2016-10-24 18:29 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\PolicyDefinitions

2016-10-24 17:38 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\rescache

2016-10-24 16:32 - 2014-04-30 17:50 - 00001795 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk

2016-10-24 16:29 - 2014-08-07 13:48 - 00000000 ____D C:\Users\raypahl\Documents\My Scans

2016-10-24 15:40 - 2011-10-12 14:02 - 00000000 ____D C:\Windows\Minidump

2016-10-24 15:39 - 2014-10-28 04:11 - 433651867 _____ C:\Windows\MEMORY.DMP

2016-10-21 15:53 - 2013-08-13 08:08 - 00000000 ____D C:\ProgramData\HP

2016-10-21 12:54 - 2014-05-03 12:39 - 00000000 ____D C:\Users\raypahl\AppData\LocalLow\HPAppData

2016-10-21 04:39 - 2006-11-02 10:21 - 00329512 _____ C:\Windows\system32\FNTCACHE.DAT

2016-10-21 04:38 - 2009-03-06 01:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight

2016-10-21 04:37 - 2006-11-02 10:07 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer

2016-10-21 04:04 - 2014-02-25 09:26 - 00757538 _____ C:\Windows\SysWOW64\PerfStringBackup.INI

2016-10-21 03:20 - 2013-08-14 03:11 - 00000000 ____D C:\Windows\system32\MRT

2016-10-21 03:06 - 2006-11-02 07:35 - 143495576 ____C (Microsoft Corporation) C:\Windows\system32\mrt.exe

2016-10-21 03:05 - 2010-12-20 08:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight

2016-10-20 15:15 - 2016-09-23 06:44 - 00000000 ____D C:\Windows\System32\Tasks\Remediation

2016-10-13 06:20 - 2015-03-26 15:54 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys

2016-10-10 20:52 - 2013-12-22 21:32 - 00001865 _____ C:\Users\Public\Desktop\Google Slides.lnk

2016-10-10 20:52 - 2013-12-22 21:32 - 00001863 _____ C:\Users\Public\Desktop\Google Sheets.lnk

2016-10-10 20:52 - 2013-12-22 21:32 - 00001853 _____ C:\Users\Public\Desktop\Google Docs.lnk

2016-10-10 20:52 - 2013-12-22 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive

 

==================== Files in the root of some directories =======

 

2013-10-13 21:44 - 2013-10-13 21:44 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll

2014-08-25 22:22 - 2014-10-08 11:21 - 0000004 _____ () C:\Users\raypahl\AppData\Roaming\appdataFr2.bin

2014-03-18 17:00 - 2014-04-04 03:00 - 0000082 _____ () C:\Users\raypahl\AppData\Roaming\WB.CFG

2015-12-03 21:41 - 2016-04-02 00:12 - 0000994 _____ () C:\Users\raypahl\AppData\Roaming\wklnhst.dat

2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\AtStart.txt

2012-07-05 02:08 - 2016-11-03 19:03 - 0006756 _____ () C:\Users\raypahl\AppData\Local\d3d9caps.dat

2016-08-22 15:02 - 2016-08-22 15:12 - 0000732 _____ () C:\Users\raypahl\AppData\Local\d3d9caps64.dat

2012-09-03 18:33 - 2016-08-29 20:23 - 0151552 _____ () C:\Users\raypahl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

2013-12-11 05:47 - 2013-12-11 05:49 - 0004170 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI0287.txt

2013-12-11 06:05 - 2013-12-11 06:05 - 0354328 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI0FE9.txt

2011-10-01 00:07 - 2011-10-01 00:08 - 0460566 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI3785.txt

2016-08-22 17:25 - 2016-08-22 17:25 - 0389670 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI3940.txt

2014-01-11 19:16 - 2014-01-11 19:18 - 0444592 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI6339.txt

2016-02-20 05:30 - 2016-02-20 05:31 - 0001848 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI6DAF.txt

2016-02-20 05:50 - 2016-02-20 05:51 - 0405314 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI7CE3.txt

2013-12-11 05:47 - 2013-12-11 05:48 - 0012516 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI0287.txt

2013-12-11 06:05 - 2013-12-11 06:05 - 0015670 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI0FE9.txt

2011-10-01 00:07 - 2011-10-01 00:08 - 0014878 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI3785.txt

2016-08-22 17:25 - 2016-08-22 17:25 - 0011478 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI3940.txt

2014-01-11 19:16 - 2014-01-11 19:18 - 0043456 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI6339.txt

2016-02-20 05:30 - 2016-02-20 05:31 - 0026324 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI6DAF.txt

2016-02-20 05:50 - 2016-02-20 05:51 - 0013546 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI7CE3.txt

2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\DSwitch.txt

2011-09-30 19:28 - 2016-04-06 19:16 - 0000000 _____ () C:\Users\raypahl\AppData\Local\FnF4.txt

2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\QSwitch.txt

2011-05-27 22:02 - 2011-10-01 00:34 - 0001940 _____ () C:\Users\raypahl\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini

2009-07-21 13:32 - 2016-11-04 11:09 - 0009308 _____ () C:\ProgramData\HPWALog.txt

2013-08-13 08:08 - 2014-04-30 21:37 - 0003705 _____ () C:\ProgramData\hpzinstall.log

2014-05-27 14:19 - 2016-04-18 20:53 - 0000614 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

2009-06-13 23:40 - 2009-06-13 23:40 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log

2009-03-06 01:55 - 2009-03-06 01:55 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log

2009-06-13 23:39 - 2009-06-13 23:39 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log

2009-03-06 01:48 - 2009-03-06 01:50 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log

2009-06-13 23:38 - 2009-06-13 23:38 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log

2009-06-13 23:39 - 2009-06-13 23:39 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log

2009-03-06 01:47 - 2009-03-06 01:48 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log

2009-03-06 01:50 - 2009-03-06 01:55 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log

2009-06-13 23:39 - 2009-06-13 23:39 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log

 

Some files in TEMP:

====================

C:\Users\raypahl\AppData\Local\Temp\cct.dll

C:\Users\raypahl\AppData\Local\Temp\HPPSdr.exe

C:\Users\raypahl\AppData\Local\Temp\JavaIC.dll

C:\Users\raypahl\AppData\Local\Temp\jre-8u101-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u111-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u60-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u71-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u77-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\msscct32.dll

C:\Users\raypahl\AppData\Local\Temp\mstsdhav.dll

C:\Users\raypahl\AppData\Local\Temp\Quarantine.exe

C:\Users\raypahl\AppData\Local\Temp\YSearchUtil.dll

C:\Users\raypahl\AppData\Local\Temp\ytb.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{03643C3A-276A-495F-A3F9-37428AF4434A}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{07CAF0E7-1697-4F67-B23C-ACFC3C227971}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{0BB9737D-9D31-4451-BEB6-239DBA7AE291}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{1ED5386F-F337-4F65-AAE0-6474DDC0870A}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{28689526-4B9A-4E80-B7C4-32CA21B40F1E}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{2E7A0B92-9E55-4DEA-BBA3-F93D732A56B1}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{3B47A66E-B640-42C1-A6CE-40F7EC6273F5}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{40718227-A6E2-4B8B-B82C-6F40933D8327}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{46949032-B4EE-4CF7-BBC4-B5A45B5A9E87}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{55E8CAEA-22C3-41F6-AB08-97D890FFC4E5}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{6440939F-A05A-484F-8E4C-EEC99859BE44}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{69A5BD0D-4B3F-47AA-B77A-450017E65E02}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{6D72D734-48F4-4782-A52E-E5447A8484CA}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{76B58018-5D24-4DC5-868E-031DC7F79E26}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{8A503156-F723-4955-BA4E-5B879A529AEA}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{BD1D630A-95F8-44BD-83D2-CE9F3897210E}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{C2B850D8-9D4A-4F7D-B6C4-1370929A49DC}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CAA2EB40-4B39-4B63-93B5-D34FDD3A127C}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CD9087A2-63C7-435F-90ED-8DC90B695CC3}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CF7A6E42-6A6C-436F-95BB-E7DDBA6857A4}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{D3A389BA-4739-4992-AA76-08E8EF1B6BCE}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{E3A7B323-B837-426D-B8CB-63625BEEF743}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{FF1742B3-43A5-4AB3-830F-EAD205065B03}.exe

C:\Users\raypahl\AppData\Local\Temp\{2588712D-0BFD-439A-81E4-7E5EEA9F67EA}-45.0.2454.93_45.0.2454.85_chrome_updater.exe

C:\Users\raypahl\AppData\Local\Temp\{DDE604EF-4F5C-4B52-B6F9-092F33452B06}-45.0.2454.85_44.0.2403.157_chrome_updater.exe

 

 

==================== Bamital & volsnap ======================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

 

LastRegBack: 2016-11-04 11:14

 

==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-11-2016

Ran by [removed] (04-11-2016 12:41:59)

Running from C:\Users\[removed]\Desktop

Windows Vista (TM) Home Premium Service Pack 2 (X64) (2009-06-14 03:35:45)

Boot Mode: Normal

==========================================================

 

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-513785977-584283709-202011636-500 - Administrator - Disabled)

Guest (S-1-5-21-513785977-584283709-202011636-501 - Limited - Disabled)

raypahl (S-1-5-21-513785977-584283709-202011636-1000 - Administrator - Enabled) => C:\Users\raypahl

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}

AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

 

==================== Installed Programs ======================

 

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

4500_G510gm_Help (x32 Version: 000.0.440.000 - Hewlett-Packard) Hidden

4500G510gm (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden

4500G510gm_Software_Min (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden

Acrobat.com (HKLM-x32\…\{77DCDCE3-2DED-62F3-8154-05E745472D07}) (Version: 1.1.377 - Adobe Systems Incorporated)

Activation Assistant for the 2007 Microsoft Office suites (HKLM-x32\…\Activation Assistant for the 2007 Microsoft Office suites) (Version:  - Microsoft Corporation)

Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0 - Microsoft Corporation) Hidden

ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.2 - Hewlett-Packard) Hidden

Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 23.0.0.257 - Adobe Systems Incorporated)

Adobe Flash Player 23 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 23.0.0.205 - Adobe Systems Incorporated)

Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.205 - Adobe Systems Incorporated)

Adobe Reader X (10.1.16) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)

Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)

Amazon Kindle (HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Amazon Kindle) (Version:  - Amazon)

Amazon Kindle (HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Amazon Kindle) (Version:  - Amazon)

Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)

Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)

Apple Mobile Device Support (HKLM\…\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)

Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)

Atheros Driver Installation Program (HKLM-x32\…\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 5.2 - Atheros)

Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)

BCL easyConverter Desktop 3 (Word Version) (HKLM-x32\…\{8C5845B5-729F-40E3-A945-4454E67F65F4}) (Version: 3.0.18 - BCL Technologies)

Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)

BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden

CCleaner (HKLM\…\CCleaner) (Version: 4.17 - Piriform)

Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)

CyberLink DVD Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.2512 - CyberLink Corp.)

D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden

Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden

DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden

DocMgr (x32 Version: 130.0.000.000 - Hewlett-Packard) Hidden

DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden

Download App (HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Download App) (Version: 1.8.0 - CBS Interactive)

Download App (HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Download App) (Version: 1.8.0 - CBS Interactive)

ENE CIR Receiver Driver (12/30/2008 2.7.2.0) (HKLM\…\703AB19C282B6ED3F1D3CE92F8DAA864B68A7C91) (Version: 12/30/2008 2.7.2.0 - ENE)

eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden

ESU for Microsoft Vista (HKLM-x32\…\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)

Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden

Google Chrome (HKLM-x32\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)

Google Drive (HKLM-x32\…\{FDEDE86B-3597-40D7-8568-4649F651EDBD}) (Version: 1.32.3363.5836 - Google, Inc.)

Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden

Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden

GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden

HP Active Support Library (HKLM-x32\…\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}) (Version: 3.1.9.1 - Hewlett-Packard)

HP Customer Experience Enhancements (HKLM-x32\…\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}) (Version: 5.7.0.2664 - Hewlett-Packard)

HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP)

HP Document Manager 2.0 (HKLM\…\HP Document Manager) (Version: 2.0 - HP)

HP Help and Support (HKLM-x32\…\{0054A0F6-00C9-4498-B821-B5C9578F433E}) (Version: 2.1.3.0 - Hewlett-Packard Company)

HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP)

HP MediaSmart DVD (HKLM-x32\…\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 2.1.2328 - Hewlett-Packard)

HP MediaSmart Music/Photo/Video (HKLM-x32\…\InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}) (Version: 2.2.2829 - Hewlett-Packard)

HP MediaSmart SlingPlayer (HKLM-x32\…\HP.MediaSmartSlingPlayer_is1) (Version: 2.1 - Sling Media, Inc.)

HP MediaSmart SmartMenu (HKLM\…\{0BC595C4-F736-4EB4-A1C0-32C7E81800F0}) (Version: 2.1.10 - Hewlett-Packard)

HP MediaSmart TV (HKLM-x32\…\InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}) (Version: 2.1.1709 - Hewlett-Packard)

HP MediaSmart Webcam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.2.1621 - Hewlett-Packard)

HP Officejet 4500 G510g-m (HKLM\…\{E5083D57-D93F-404C-A91F-1C50D67C2BEB}) (Version: 13.0 - HP)

HP Quick Launch Buttons (HKLM-x32\…\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.17.1 - Hewlett-Packard Company)

HP Smart Web Printing 4.5 (HKLM\…\HP Smart Web Printing) (Version: 4.5 - HP)

HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)

HP Support Solutions Framework (HKLM-x32\…\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company)

HP Total Care Advisor (HKLM-x32\…\{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}) (Version: 2.4.5991.2847 - Hewlett-Packard)

HP Total Care Setup (HKLM-x32\…\{95A747E0-DF19-46CB-A622-20A0107201BD}) (Version: 1.1.2413.2876 - Hewlett-Packard Company)

HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)

HP User Guides 0135 (HKLM-x32\…\{372ED957-0FB5-487B-B51A-388B3D393F7A}) (Version: 1.01.0000 - Hewlett-Packard)

HP Wireless Assistant (HKLM-x32\…\{462DED50-EC2E-4237-ABCF-B5C463C0EE51}) (Version: 3.50.3.1 - Hewlett-Packard)

HPAsset component for HP Active Support Library (x32 Version: 3.0.2.2 - Hewlett-Packard) Hidden

HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden

HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden

HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden

IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6146.0 - IDT)

Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version:  - Intel Corporation)

iTunes (HKLM\…\{CEC7613B-E286-4A31-BEE3-3F7798488D9F}) (Version: 12.1.3.6 - Apple Inc.)

Java 8 Update 60 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)

Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1312 - CyberLink Corp.)

LabelPrint (x32 Version: 2.5.1312 - CyberLink Corp.) Hidden

LightScribe System Software  1.14.17.1 (HKLM-x32\…\{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}) (Version: 1.14.17.1 - LightScribe)

Logitech Unifying Software 2.10 (HKLM\…\Logitech Unifying) (Version: 2.10.37 - Logitech)

Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)

MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden

Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden

Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)

Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)

Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)

Microsoft Office Live Add-in 1.5 (HKLM-x32\…\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)

Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)

Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)

Microsoft Office Standard Edition 2003 (HKLM-x32\…\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)

Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)

Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)

Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\…\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\…\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)

Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\…\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)

MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)

MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)

muvee Reveal (HKLM-x32\…\{DE626616-D7C4-4F00-7E0B-EAF26FA65749}) (Version: 7.0.43.12698 - muvee Technologies Pte Ltd)

My HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.0.62 - WildTangent)

Network64 (Version: 130.0.550.000 - Hewlett-Packard) Hidden

NTI Ripper (HKLM-x32\…\{88A785A2-3EA6-4A2D-ABEE-68E9E55A39F8}) (Version: 2.0.0.17 - NewTech Infosystems)

NTI Shadow 3 (HKLM-x32\…\{E9EB5689-4F76-4E3C-A675-5ED5F52AB890}) (Version: 3.1.4.0 - NewTech Infosystems)

OCR Software by I.R.I.S. 13.0 (HKLM\…\HPOCR) (Version: 13.0 - HP)

Origin (HKLM-x32\…\Origin) (Version: 9.4.6.2792 - Electronic Arts, Inc.)

PDF Suite 2015 (HKLM-x32\…\PDF Suite 2015) (Version: 13.0.10.21694 - Interactive Brands Malta Limited)

PDF Suite 2015 (x32 Version: 13.0.23.21617 - Interactive Brands Malta Limited) Hidden

PDF Suite 2015 OCR Module (x32 Version: 13.0.23.21617 - Interactive Brands Malta Limited) Hidden

PhotoScape (HKLM-x32\…\PhotoScape) (Version:  - )

Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.2512 - CyberLink Corp.)

Power2Go (x32 Version: 6.0.2512 - CyberLink Corp.) Hidden

PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2512 - CyberLink Corp.)

PowerDirector (x32 Version: 7.0.2512 - CyberLink Corp.) Hidden

ProtectSmart Hard Drive Protection (HKLM\…\{2F97CE84-9C33-4631-821B-85EA371EA254}) (Version: 3.10.1.7 - Hewlett-Packard)

QLBCASL (x32 Version: 6.40.17.2 - Hewlett-Packard) Hidden

QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)

Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek)

Realtek USB 2.0 Card Reader (HKLM-x32\…\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: 6.0.6000.20113 - Realtek Semiconductor Corp.)

Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)

SafeZone Stable 1.48.2066.114 (x32 Version: 1.48.2066.114 - Avast Software) Hidden

Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden

Segoe UI (x32 Version: 15.4.2271.0615 - Microsoft Corp) Hidden

Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 13.0 - HP)

Slingbox - Watch Your TV Anywhere (HKLM-x32\…\{7B798B31-2F33-4DC8-BDA4-D36488E86636}) (Version: 1.0.0 - Sling Media)

SlingPlayer (HKLM-x32\…\InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}) (Version: 1.04.0206 - Sling Media)

SlingPlayer (x32 Version: 1.04.0206 - Sling Media) Hidden

SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden

SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden

Spelling Dictionaries Support For Adobe Reader 9 (HKLM-x32\…\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)

Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden

Steam (HKLM-x32\…\Steam) (Version:  - Valve Corporation)

swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden

Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated)

Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden

TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden

TurboTax 2012 (HKLM-x32\…\TurboTax 2012) (Version: 2012.0 - Intuit, Inc)

Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden

WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden

WildTangent Games App (HP Games) (HKLM-x32\…\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.31 - WildTangent)

Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)

Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)

Windows Live Sync (HKLM-x32\…\{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}) (Version: 14.0.8064.206 - Microsoft Corporation)

Xilisoft Video Converter Ultimate (HKLM-x32\…\Xilisoft Video Converter Ultimate) (Version: 7.7.3.20131014 - Xilisoft)

Yahoo Search Set (HKLM-x32\…\Yahoo! SearchSet) (Version:  - Yahoo Inc.)

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {1E47DECC-A445-437E-BA49-BF68A0FE709D} - System32\Tasks\HP Health Check => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09] (Hewlett-Packard)

Task: {1EEC94E2-3371-4445-B69E-06C410B6EE74} - System32\Tasks\{6EA9492D-AFAD-4611-B778-FEF2E452B324} => pcalua.exe -a "C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GJQZPLZ1\Athena[1].exe" -d C:\Users\raypahl\Desktop

Task: {24AF7C9D-752C-4445-A82B-1BE9CDF09079} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

Task: {2676CF9D-8246-4E69-9166-E93FAAEF4707} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-03] (Adobe Systems Incorporated)

Task: {3712F5A0-0477-4593-898F-2D6722E1694A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

Task: {5BF15EEE-CE81-46B3-97C4-2F0217BF3198} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)

Task: {6E74CFCE-FF9D-417D-9884-56337FA84896} - System32\Tasks\HPCeeScheduleForraypahl => C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe [2008-05-19] (Hewlett-Packard)

Task: {C4A2780D-68B8-4F95-A118-6E5DD88047E0} - System32\Tasks\NetworkWizardHNW => C:\Program Files (x86)\Hewlett-Packard\HP TCS\RemEngine.exe [2008-12-17] ()

Task: {E226896F-2D00-4835-94CA-6E3EE9E822E0} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-29] (AVAST Software)

Task: {EC1DA6EA-D89F-45D1-96DA-F64D32C2C68E} - System32\Tasks\SafeZone scheduled Autoupdate 1468319266 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-06-17] (Avast Software)

Task: {EC3518F0-B320-4AC6-B0D1-D131875A226A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

Task: {ECBDA076-B4B3-4E77-8185-DC8446925D32} - System32\Tasks\{2DF12692-40FF-4911-A6C8-8B1BF5365384} => pcalua.exe -a C:\Users\raypahl\AppData\Local\Microsoft\Windows\Burn\Burn\callatlanta_setup.exe

Task: {F1351889-C902-458D-940D-9EEB132FCC88} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)

Task: {FD30349E-1798-46DF-A9FF-96869C61C29C} - System32\Tasks\{B8696691-6D99-40A1-8CEE-83EC12275D01} => pcalua.exe -a C:\Users\raypahl\Desktop\esetsmartinstaller_enu.exe -d C:\Users\raypahl\Desktop

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\HPCeeScheduleForraypahl.job => C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe

 

==================== Shortcuts =============================

 

(The entries could be listed to be restored or removed.)

 

Shortcut: C:\Users\raypahl\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.com

 

==================== Loaded Modules (Whitelisted) ==============

 

2009-03-06 02:02 - 2008-12-23 19:18 - 00365952 _____ () C:\Program Files (x86)\SMINST\BLService.exe

2009-03-06 01:55 - 2008-11-25 18:29 - 00247152 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

2008-11-26 19:13 - 2008-11-26 19:13 - 00296320 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe

2008-11-26 19:13 - 2008-11-26 19:13 - 00116096 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe

2015-03-20 18:12 - 2015-03-20 18:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll

2015-03-20 18:12 - 2015-03-20 18:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll

2008-11-26 19:12 - 2008-11-26 19:12 - 00074536 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\Common\MCEMediaStatus64.dll

2009-07-01 15:44 - 2009-07-01 15:44 - 00632888 _____ () C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe

2016-08-29 18:18 - 2016-08-29 18:18 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll

2016-11-04 08:16 - 2016-11-04 08:16 - 03127760 _____ () C:\Program Files\AVAST Software\Avast\defs\16110400\algo.dll

2016-08-29 18:18 - 2016-08-29 18:18 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll

2009-03-06 02:02 - 2008-12-23 19:18 - 00132480 _____ () C:\Program Files (x86)\SMINST\STWmiM.dll

2009-03-06 01:55 - 2008-11-25 18:29 - 00034088 _____ () C:\Program Files (x86)\Cyberlink\Shared files\RichVideops.dll

2008-11-26 19:13 - 2008-11-26 19:13 - 00263560 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLCapEngine.dll

2008-11-26 19:13 - 2008-11-26 19:13 - 00038184 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLCapSvcps.dll

2007-07-12 15:55 - 2007-07-12 15:55 - 01581056 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll

2007-08-14 15:59 - 2007-08-14 15:59 - 06365184 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll

2007-07-12 15:55 - 2007-07-12 15:55 - 00131072 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll

2014-10-10 12:41 - 2014-10-10 12:41 - 01255936 _____ () C:\Program Files (x86)\CBS Interactive\Download App\libcurl.dll

2014-10-10 12:39 - 2014-10-10 12:39 - 00066560 _____ () C:\Program Files (x86)\CBS Interactive\Download App\zlib.dll

2008-11-26 19:13 - 2008-11-26 19:13 - 00349480 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLTinyDB.dll

2009-04-29 22:11 - 2009-04-29 22:11 - 00906536 ____N () C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll

2016-07-11 22:01 - 2016-07-11 22:02 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

2016-11-04 11:08 - 2016-11-04 11:08 - 00098816 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32api.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00110080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pywintypes27.dll

2016-11-04 11:08 - 2016-11-04 11:08 - 00364544 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pythoncom27.dll

2016-11-04 11:08 - 2016-11-04 11:08 - 00320512 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32com.shell.shell.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00914432 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_hashlib.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 01176576 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._core_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00806400 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._gdi_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00816128 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._windows_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 01067008 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._controls_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00733184 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._misc_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00682496 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pysqlite2._sqlite.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00088064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_ctypes.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00686080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\unicodedata.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00119808 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32file.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00108544 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32security.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00007168 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\hashobjs_ext.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00017920 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\thumbnails_ext.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00088064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\usb_ext.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00012800 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\common.time34.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00018432 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32event.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00167936 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32gui.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00046080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_socket.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 01303552 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_ssl.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00128512 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_elementtree.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00127488 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pyexpat.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00038912 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32inet.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00036864 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_psutil_windows.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00524248 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\windows._lib_cacheinvalidation.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00011264 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32crypt.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00123392 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._wizard.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00077312 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._html2.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00027648 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_multiprocessing.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00020480 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_yappi.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00035840 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32process.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00078848 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._animate.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00024064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32pipe.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00010240 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\select.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00025600 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32pdh.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00017408 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32profile.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00022528 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32ts.pyd

2016-09-06 14:28 - 2016-09-06 12:00 - 05197312 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libglesv2.dll

2016-09-06 14:28 - 2016-09-06 12:00 - 00147456 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libegl.dll

2016-07-13 04:28 - 2016-07-06 18:01 - 17602240 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\PepperFlash\22.0.0.209\pepflashplayer.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

 

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

 

==================== Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

HKLM\…\cmdfile\DefaultIcon: %SystemRoot%\System32\shell32.dll,-153 <===== ATTENTION

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

IE trusted site: HKU\S-1-5-21-513785977-584283709-202011636-1000\…\intuit.com -> hxxps://accounts.intuit.com

IE trusted site: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\intuit.com -> hxxps://accounts.intuit.com

 

==================== Hosts content: ===============================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2006-11-02 07:34 - 2006-09-18 16:37 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts

 

127.0.0.1       localhost

::1             localhost

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg

HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg

HKU\S-1-5-21-513785977-584283709-202011636-1000\Control Panel\Desktop\\Wallpaper ->

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper ->

DNS Servers: 75.75.75.75 - 75.75.76.76

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)

Windows Firewall is enabled.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Constant Guard.lnk => C:\Windows\pss\Constant Guard.lnk.CommonStartup

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Fast Connect.lnk => C:\Windows\pss\Fast Connect.lnk.CommonStartup

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe

FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe

FirewallRules: [{85CA64C5-0E24-49D3-962C-757C4D4EF5EA}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE

FirewallRules: [{C056B941-D6C9-43C2-BC46-C8062C7E9591}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe

FirewallRules: [{A477DEFD-C4F3-49DF-9493-DCB0193B3DC2}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe

FirewallRules: [{9DA0FA66-F81F-4C49-93E4-0C736F80D266}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe

FirewallRules: [{D62589CC-FCFC-474B-897E-5F4E2E376DB6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\TSMAgent.exe

FirewallRules: [{0C18A91B-06AB-412C-A4FB-56721866C9EB}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe

FirewallRules: [{90B91326-6994-4D67-8710-402213196972}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe

FirewallRules: [{892F181D-FCD8-4749-A566-1DDE9D5E06C6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QP.exe

FirewallRules: [{218696AD-0268-44D1-958A-9FB0C07367EE}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QPService.exe

FirewallRules: [{C0D11A95-3BAB-4C69-9B2F-ABDF0DE00382}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe

FirewallRules: [{DA361D62-6094-45AB-8548-C892212DD857}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe

FirewallRules: [{E29DF1CE-61F4-4C67-B5E6-018649FED1F0}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe

FirewallRules: [{28D8EE93-F60E-412F-B1D8-2540677725C9}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe

FirewallRules: [{2C5DE510-0436-4BA6-9D33-EA65AD777F21}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe

FirewallRules: [{2121075F-A168-42F2-A24D-D0A4C9205054}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe

FirewallRules: [{899817AC-8E24-4616-A1BB-9CF013A72458}] => (Allow) LPort=80

FirewallRules: [{801C85E3-1031-4FA1-9462-DDCCDD72601F}] => (Allow) LPort=80

FirewallRules: [{2A217FCB-85BA-4D43-88A5-E696A21C17BE}] => (Allow) LPort=80

FirewallRules: [{67913156-DF65-4018-B0AC-C4BA598F0458}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

FirewallRules: [{F97F9C53-4B16-44C5-9DAB-BE26D646BB2E}] => (Allow) LPort=2869

FirewallRules: [{ECDA4AA6-F84F-4F8C-A5C2-0981BEB965AB}] => (Allow) LPort=1900

FirewallRules: [{99E21AA7-60B0-4758-9700-947CE68E6FC4}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

FirewallRules: [{556638C7-DDD1-49D4-B540-2BF1813097BE}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe

FirewallRules: [{BA7B17AA-ECB1-48CA-B123-DEDEF25F5280}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{C8533641-5BA2-4226-AFAD-01CAA75D4BC3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{2079C40C-30DB-4EC9-A37D-2A69F7CB2B9A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{7AA88511-8B20-4763-AB96-65C325F436C2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{8338DBF9-E8CD-40AC-A575-BC1C4D3264AE}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{49D4AFA4-BDA6-4F09-A81E-C49E81BDD809}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{F2531826-2F73-4998-9503-3CB1A9EF475A}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{50BB60C3-956B-46D3-BD6E-BF3715DAEAA8}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{938E4FAF-25DE-43F0-8941-BAB51D00909F}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{32D0853C-F33F-4CA2-BDD9-EB0E43C2C1A9}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe

FirewallRules: [{028CDA9D-6AA2-48CC-97F4-8CB3BFFEDCAE}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe

FirewallRules: [{24ED04E3-69B3-4EF6-AB2B-774FF6EBB341}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe

FirewallRules: [{B498508E-E2F8-420D-AF6B-5E4EB2847438}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe

FirewallRules: [{149237F6-0247-4D6A-9B24-6284C0EC1F6E}] => (Allow) LPort=80

FirewallRules: [{0D5BE560-6B3C-4CA0-A163-4A0D4761952F}] => (Allow) LPort=3074

FirewallRules: [{46BBA3EE-07CF-43BA-B750-B59D6FEA6E67}] => (Allow) LPort=53

FirewallRules: [{1937BBB4-CCBA-487B-ABF4-965EBD64F35D}] => (Allow) LPort=88

FirewallRules: [{0B06D53B-770D-4F4F-8750-588083139BD4}] => (Allow) LPort=3074

FirewallRules: [{63DB0018-84DB-4F7D-91A6-5EEB5D473E2C}] => (Allow) LPort=53

FirewallRules: [{4BD011AB-0AC7-4B5A-A0CF-466CC36B4E10}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS6610\HPDiagnosticCoreUI.exe

FirewallRules: [{5CFF6CC9-FFCC-4E3F-BC41-D4AC77525B27}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS6610\HPDiagnosticCoreUI.exe

FirewallRules: [{D627BCA2-CF30-4E83-813D-55AE2787BACA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe

FirewallRules: [{8EBE220A-A2E8-47DC-9A52-C00C722B2B36}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe

FirewallRules: [{67F0DD1B-2C2B-4DF0-83BD-CA448BAF87E8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe

FirewallRules: [{277CCB2A-D8F2-4438-8B24-11CC51D7A2DD}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe

FirewallRules: [{A4D4FBBF-F068-4D39-8BE3-74355B903AB7}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3C2E\HPDiagnosticCoreUI.exe

FirewallRules: [{71675975-38A1-48EA-ACCB-FABEF0BD9D13}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3C2E\HPDiagnosticCoreUI.exe

FirewallRules: [{56345E73-9C25-4274-A858-4690E48E1F67}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS64AB\HPDiagnosticCoreUI.exe

FirewallRules: [{E16F485C-ED68-4BD6-8805-2A64A9D96A39}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS64AB\HPDiagnosticCoreUI.exe

FirewallRules: [{31BE109E-8AF9-4143-AD52-57F7DB7FAED8}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS0964\HPDiagnosticCoreUI.exe

FirewallRules: [{A93D5B10-FD8F-4B4F-B432-6A12E6A2D0DC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS0964\HPDiagnosticCoreUI.exe

FirewallRules: [{7C26B91E-B117-486A-B514-1E931777327D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

FirewallRules: [{3D0B25BE-B075-4318-8FAD-AA4378D408D4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe

FirewallRules: [{3190CC53-3DB5-4C54-B6F1-0770B51650F2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe

FirewallRules: [{D9A183D9-B520-4D17-8D52-4341A9CFBBEC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe

FirewallRules: [{BCEEDD97-2D66-466F-B460-54D582497581}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe

FirewallRules: [{603C8A2D-FB38-49BD-9FDD-2934CAECAE11}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe

FirewallRules: [{DDEE3F5E-97F1-4B23-9929-9B3755027FC8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe

FirewallRules: [{38A2B6F1-AE10-4306-AC8B-57D65B8552FB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe

FirewallRules: [{A6BD5514-3186-4D82-ACE9-8AFC163F591F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe

FirewallRules: [{E5BEACAE-D7A3-4D30-8284-ED4CDC7EE1F1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe

FirewallRules: [{55C0994B-0B3E-444F-A6F1-771232CE4C04}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe

FirewallRules: [{24942CC8-CEE3-42BD-AE57-6FC7B5B01D26}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe

FirewallRules: [{80E01553-7E49-42EB-84AA-260B63480BFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe

FirewallRules: [{3D37A03B-72C1-4951-AACC-F8F9842EAC32}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe

FirewallRules: [{9851363A-29E7-4066-808D-76F09B44EAA9}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{6DF5A30B-3B0F-4CC8-91E7-C21179661239}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe

FirewallRules: [{00C3DF64-1789-45C4-826E-F88407B37F60}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{8060B257-FF11-4A7E-B4D6-8822812D5766}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{FDC220B2-E26C-439A-8AEE-6CB05A6A9CDF}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{0548CB3C-9BAA-419F-AC3C-CF92119ECF94}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{23D1FC3D-674C-44F8-9961-46BBEB100F2F}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{069C9567-F251-4E40-B6F7-7B7D7D9109AC}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{D99F3B45-4583-426E-8CDF-DF5E521807C6}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{D41E6F5E-2589-4C57-9E12-1D63C165791D}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{6DEEE18D-D523-45BF-932E-CE5743988EE8}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{43D52C1D-478B-4FCE-9745-AAF8982DF4DC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS175A\HPDiagnosticCoreUI.exe

FirewallRules: [{A707CC94-5C2F-4D23-8BCD-1307DBA1F380}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS175A\HPDiagnosticCoreUI.exe

FirewallRules: [{D5F39F1E-2D2C-4FE4-AC8F-7D1244D261F1}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS17E3\HPDiagnosticCoreUI.exe

FirewallRules: [{98DD6223-287E-4612-84C7-8256612DF4EE}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS17E3\HPDiagnosticCoreUI.exe

FirewallRules: [{A5F88943-D64D-41D9-ACDD-54EDBEC8ECC3}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS61A2\HPDiagnosticCoreUI.exe

FirewallRules: [{0295B60A-D80C-449F-A559-2559D30C56ED}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS61A2\HPDiagnosticCoreUI.exe

FirewallRules: [{B26FD28B-080C-4DC6-84AF-10360A7C1848}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS326C\HPDiagnosticCoreUI.exe

FirewallRules: [{EDDD3BB6-DE4D-491F-9E82-60EED756FAB0}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS326C\HPDiagnosticCoreUI.exe

FirewallRules: [{720847F8-E7ED-4F05-A979-64A3CABFD9A4}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{9DED4120-5843-4CD7-96F8-BA8DC78DD4D2}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{5188845E-5ABE-493A-8AE3-C562AF667662}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3742\HPDiagnosticCoreUI.exe

FirewallRules: [{87FB02D8-EDC9-4628-8196-40F55E2955A2}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3742\HPDiagnosticCoreUI.exe

FirewallRules: [{37154139-4F88-40F7-8C66-F721A336A600}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3780\HPDiagnosticCoreUI.exe

FirewallRules: [{D47BCBCC-ADF9-4F87-BCFB-E6EFD8A23273}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3780\HPDiagnosticCoreUI.exe

FirewallRules: [{C550D466-6DA9-4CF3-AF39-E1B7B9D3491A}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS5F6B\HPDiagnosticCoreUI.exe

FirewallRules: [{ABBB6631-70E4-4D5A-8D5D-105E6B6C2047}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS5F6B\HPDiagnosticCoreUI.exe

FirewallRules: [{735A1C21-05AD-49A7-B856-D8DB046D814B}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{072D341C-F0AA-4EC4-B256-90AA1A0371D6}] => (Allow) C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe

FirewallRules: [{0E09CE06-6B58-4C5C-B41F-9CBC3C28310F}] => (Allow) C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe

FirewallRules: [{AF858CCB-A6DC-41B2-A8F1-DEC030D92EEB}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{4850BCB1-4BDE-4888-9338-413BF216736F}] => (Allow) C:\Program Files\iTunes\iTunes.exe

FirewallRules: [{37A8803F-79F3-4EA8-B4DC-EFC8C0988147}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

FirewallRules: [TCP Query User{05B7B3B1-49C4-42B6-B68A-EFF0B868DFBB}C:\program files (x86)\swannview link\mydvr.exe] => (Allow) C:\program files (x86)\swannview link\mydvr.exe

FirewallRules: [UDP Query User{3A8123E3-4600-46C8-8ACE-AF6FB9F3DE3D}C:\program files (x86)\swannview link\mydvr.exe] => (Allow) C:\program files (x86)\swannview link\mydvr.exe

FirewallRules: [TCP Query User{0B8D5604-9A95-4CBA-99CC-80CD63F8BD63}C:] => (Allow) C:\

FirewallRules: [UDP Query User{423E6DF9-8B53-405B-8F7D-6926AE5B5679}C:] => (Allow) C:\

FirewallRules: [{954DDB9D-8A37-4449-BC09-F3070B20367E}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS420D\HPDiagnosticCoreUI.exe

FirewallRules: [{DA174395-2E36-4D4D-B5EC-11BFF9576FD7}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS420D\HPDiagnosticCoreUI.exe

FirewallRules: [{53EE87C1-3AC3-43AD-B1D9-4ECE6A351714}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS42CB\HPDiagnosticCoreUI.exe

FirewallRules: [{6A40C1D8-44EC-4858-97A6-EAE58655C9EC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS42CB\HPDiagnosticCoreUI.exe

FirewallRules: [{5537C001-D930-41E2-B89C-942DB712A6B9}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS4196\HPDiagnosticCoreUI.exe

FirewallRules: [{665ECD78-617F-490D-B46F-145BA00FC68D}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS4196\HPDiagnosticCoreUI.exe

 

==================== Restore Points =========================

 

 

==================== Faulty Device Manager Devices =============

 

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (11/04/2016 11:13:24 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application jucheck.exe, version 2.8.60.27, time stamp 0x55c116b1, faulting module jucheck.exe, version 2.8.60.27, time stamp 0x55c116b1, exception code 0x40000015, fault offset 0x00052d24,

process id 0x13fc, application start time 0x01d236b6291b8d5d.

 

Error: (11/04/2016 11:12:07 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/04/2016 11:12:07 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0xfa0, application start time 0x01d236b5be6c075d.

 

Error: (11/04/2016 11:08:36 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/04/2016 11:08:36 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0xb08, application start time 0x01d236b55e2842ad.

 

Error: (11/04/2016 11:06:08 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

Error: (11/04/2016 11:05:19 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/04/2016 11:05:19 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0x200, application start time 0x01d236b296f38870.

 

Error: (11/03/2016 08:34:51 PM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/03/2016 08:34:51 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0x105c, application start time 0x01d2363b354c4410.

 

 

System errors:

=============

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

 

CodeIntegrity:

===================================

  Date: 2016-11-04 11:16:11.209

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:10.273

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:09.368

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:08.463

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:07.403

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:06.420

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:02.192

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:01.225

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:00.242

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:15:59.259

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

 

==================== Memory info ===========================

 

Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz

Percentage of memory in use: 77%

Total physical RAM: 3998.02 MB

Available physical RAM: 897.88 MB

Total Virtual: 8221.28 MB

Available Virtual: 4898.43 MB

 

==================== Drives ================================

 

Drive c: () (Fixed) (Total:452.13 GB) (Free:143.29 GB) NTFS ==>[drive with boot components (obtained from BCD)]

Drive d: (RECOVERY) (Fixed) (Total:13.62 GB) (Free:2.09 GB) NTFS ==>[system with boot components (obtained from drive)]

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (Size: 465.8 GB) (Disk ID: 636BBFB1)

Partition 1: (Active) - (Size=452.1 GB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=13.6 GB) - (Type=07 NTFS)

 

==================== End of Addition.txt ============================

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software

Run date: 2016-11-04 12:17:48

—————————–

12:17:48.853    OS Version: Windows x64 6.0.6002 Service Pack 2

12:17:48.853    Number of processors: 2 586 0x170A

12:17:48.853    ComputerName: STEARNS-PC  UserName: raypahl

12:18:03.243    Initialize success

12:18:03.259    VM: initialized successfully

12:18:03.259    VM: Intel CPU virtualization not supported

12:18:17.053    AVAST engine defs: 16110400

12:18:33.738    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0

12:18:33.738    Disk 0 Vendor: TOSHIBA_MK5055GSX FG002C Size: 476940MB BusType: 3

12:18:34.284    Disk 0 MBR read successfully

12:18:34.300    Disk 0 MBR scan

12:18:34.628    Disk 0 unknown MBR code

12:18:34.674    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       462985 MB offset 2048

12:18:35.064    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        13951 MB offset 948195328

12:18:36.094    Disk 0 scanning C:\Windows\system32\drivers

12:19:48.861    Service scanning

12:23:22.187    Modules scanning

12:23:22.187    Disk 0 trace - called modules:

12:23:22.732    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys

12:23:22.732    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006478060]

12:23:22.748    3 CLASSPNP.SYS[fffffa6000a4ec33] -> nt!IofCallDriver -> [0xfffffa8006245310]

12:23:22.748    5 hpdskflt.sys[fffffa6001802189] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004bf1590]

12:23:35.110    AVAST engine scan C:\Windows

12:23:52.825    AVAST engine scan C:\Windows\system32

12:38:13.645    Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\MBR.dat"

12:38:13.661    The log file has been saved successfully to "C:\Users\raypahl\Documents\aswMBR.txt"

12:38:52.007    AVAST engine scan C:\Windows\system32\drivers

12:40:35.754    AVAST engine scan C:\Users\raypahl

13:04:35.987    Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\MBR.dat"

13:04:36.031    The log file has been saved successfully to "C:\Users\raypahl\Documents\aswMBR.txt"

13:07:08.922    Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\deb\computer help\MBR.dat"

13:07:08.929    The log file has been saved successfully to "C:\Users\raypahl\Documents\deb\computer help\aswMBR.txt"

 

 

 

:welcome:

 

Your Operating system is Vista which tells me that your system maybe fairly old. That hosts process error could possibly be related to a failing hard drive.  I see some PUPs ( Potentially Unwanted Programs ) as well.

 

What is the make and model of this computer and is it a laptop or desktop ?

 

 

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI