This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Really Slow (previously closed) [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry, I had previously posted for help and topic was closed.  My husband rescued a puppy and he was really sick.  That sickness spread to our other dog, so I’ve been taking care of some sick pups for the past couple of days.

 

Ken 545 had asked make/model.  It is a HP pavilion dv3-2155mx notebook.  Yes, it is Vista and yes it is old.  I was hoping to make it a little bit longer, maybe catch some sales around Christmas, but may not be able to huh?

 

Didn’t know if they were required again or not, so here are my logs again.  Thanks.

 

 

My computer is really slow.  Especially at start up, takes about 15 minutes.  I get a message that says, “host process for windows services stopped working and must close.”

 

Any help would be appreciated.

 

Here are my logs.

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-11-2016

Ran by [removed] (administrator) on STEARNS-PC (04-11-2016 12:33:25)

Running from C:\Users\[removed]\Desktop

[removed]

Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) Language: English (United States)

Internet Explorer Version 9 (Default browser: Chrome)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\stacsv64.exe

(Microsoft Corporation) C:\Windows\System32\SLsvc.exe

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe

(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\AESTSr64.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe

() C:\Program Files (x86)\SMINST\BLService.exe

() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

() C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe

() C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe

(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE

(Intel Corporation) C:\Windows\System32\igfxtray.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe

(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe

(Microsoft Corporation) C:\Windows\ehome\ehtray.exe

(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe

(CBS Interactive Inc.) C:\Program Files (x86)\CBS Interactive\Download App\CBSI.AppStore.Scanner.exe

(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe

(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe

( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe

(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe

(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe

(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe

(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe

(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe

(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe

(Intel Corporation) C:\Windows\System32\igfxsrvc.exe

(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe

(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe

(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqste08.exe

(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqbam08.exe

(Hewlett-Packard) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqgpc01.exe

(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe

(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe

(AVAST Software) C:\Users\raypahl\Desktop\aswMBR.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

 

 

==================== Registry (Whitelisted) ====================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)

HKLM\…\Run: [SmartMenu] => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [915000 2009-01-08] (Hewlett-Packard)

HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-20] (Microsoft Corporation)

HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [463360 2009-01-28] (IDT, Inc.)

HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169744 2015-09-12] (Apple Inc.)

HKLM-x32\…\Run: [DVDAgent] => C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe [1148200 2008-11-28] (CyberLink Corp.)

HKLM-x32\…\Run: [TVAgent] => C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe [202024 2009-05-11] (CyberLink Corp.)

HKLM-x32\…\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.)

HKLM-x32\…\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-01-13] (CyberLink Corp.)

HKLM-x32\…\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [323640 2010-02-25] ( Hewlett-Packard Development Company, L.P.)

HKLM-x32\…\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-04] (CyberLink Corp.)

HKLM-x32\…\Run: [UpdatePDIRShortCut] => C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [218408 2008-12-04] (CyberLink Corp.)

HKLM-x32\…\Run: [HP Health Check Scheduler] => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-10-09] (Hewlett-Packard)

HKLM-x32\…\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [484408 2009-01-23] (Hewlett-Packard)

HKLM-x32\…\Run: [TSMAgent] => C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe [1328424 2009-04-29] (CyberLink Corp.)

HKLM-x32\…\Run: [CLMLServer for HP TouchSmart] => C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [185640 2009-04-29] (CyberLink)

HKLM-x32\…\Run: [UCam_Menu] => C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.)

HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)

HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)

HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9099440 2016-11-03] (AVAST Software)

HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)

HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)

HKLM-x32\…\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2014-04-23] (Lavasoft)

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

HKU\S-1-5-19\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-20\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [WindowsWelcomeCenter] => C:\Windows\system32\oobefldr.dll [2438656 2009-04-11] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [cdloader] => C:\Users\raypahl\AppData\Roaming\mjusbsp\cdloader2.exe [50520 2009-08-01] (magicJack L.P.)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818720 2016-09-19] (Google)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-11-11] (Electronic Arts)

HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [736701A46C7D59E46F8F7D9F95111119F406C6DA._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.)

HKU\S-1-5-21-513785977-584283709-202011636-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [334336 2008-01-20] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [cdloader] => C:\Users\raypahl\AppData\Roaming\mjusbsp\cdloader2.exe [50520 2009-08-01] (magicJack L.P.)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818720 2016-09-19] (Google)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-11-11] (Electronic Arts)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [736701A46C7D59E46F8F7D9F95111119F406C6DA._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.)

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [334336 2008-01-20] (Microsoft Corporation)

ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)

ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)

ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-09-19] (Google)

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-29] (AVAST Software)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2014-04-30]

ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

Startup: C:\Users\raypahl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Download App.lnk [2015-02-15]

ShortcutTarget: Download App.lnk -> C:\Program Files (x86)\CBS Interactive\Download App\CBSI.AppStore.Scanner.exe (CBS Interactive Inc.)

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76

Tcpip\..\Interfaces\{801647DA-8FFF-4244-BC31-E0870B9F67FE}: [DhcpNameServer] 75.75.75.75 75.75.76.76

Tcpip\..\Interfaces\{94FA59CE-8C9A-4984-B67B-149BBF13BD4C}: [NameServer] 8.8.8.8,208.67.222.222,8.8.4.4,208.67.220.220

Tcpip\..\Interfaces\{94FA59CE-8C9A-4984-B67B-149BBF13BD4C}: [DhcpNameServer] 75.75.75.75 75.75.76.76

 

Internet Explorer:

==================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID;=130892846893110000&GUID;=764FC242-5591-4ABF-9B6A-E9976335B01D

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =

HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006

SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {7EEAD0DA-121E-498E-B773-B8F0B4C4AAB1} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {94A0FAC8-4922-45B9-B85C-DE11B41E351F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSERBM&pc;=MSERT1

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {A9E5F592-BF1B-41BF-AFF4-9CAC82733B93} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_ie_syc_oracle&type;=orcl_default

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid;=1&pid;=21&src;=sgsearch&v;=1.15.414.3&searchparam;={SearchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {7EEAD0DA-121E-498E-B773-B8F0B4C4AAB1} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {94A0FAC8-4922-45B9-B85C-DE11B41E351F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSERBM&pc;=MSERT1

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {A9E5F592-BF1B-41BF-AFF4-9CAC82733B93} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_ie_syc_oracle&type;=orcl_default

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid;=1&pid;=21&src;=sgsearch&v;=1.15.414.3&searchparam;={SearchTerms}

SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}

BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software)

BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)

BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File

BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)

BHO-x32: PDF Suite 2015 Helper -> {5B91DFF7-1E67-4A1E-99D4-F3A09B8459AD} -> C:\Program Files (x86)\PDF Suite 2015\creator-ie-helper.dll [2015-01-23] (Interactive Brands Malta Limited)

BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\IPS\IPSBHO.DLL => No File

BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software)

BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)

BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation)

BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)

Toolbar: HKLM-x32 - PDF Suite 2015 Toolbar - {D623F6CA-49B6-4097-A62F-4D60C829D63D} - C:\Program Files (x86)\PDF Suite 2015\creator-ie-plugin.dll [2015-01-23] (Interactive Brands Malta Limited)

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File

Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File

DPF: HKLM-x32 {8714912E-380D-11D5-B8AA-00D0B78F3D48} hxxp://chat.yahoo.com/cab/yuplapp.cab

 

FireFox:

========

FF HKLM\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.2.15\coFFAddon => not found

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF

FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-29]

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF

FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-08-29]

FF HKLM-x32\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-22] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-04-30] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\PDF Suite 2015\resources\pdfsuite2015firefoxextension

FF Extension: (PDF Suite 2015) - C:\Program Files (x86)\PDF Suite 2015\resources\pdfsuite2015firefoxextension [2016-02-20] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF

FF HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_205.dll [2016-11-03] ()

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll [2016-11-03] ()

FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)

FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)

FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)

FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)

FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2012-04-11] ()

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)

FF Plugin-x32: PDF Suite 2015 -> C:\Program Files (x86)\PDF Suite 2015\np-previewer.dll [2015-01-23] (Interactive Brands Malta Limited)

 

Chrome:

=======

CHR DefaultProfile: Default

CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp

CHR StartupUrls: Default -> "hxxps://www.facebook.com/","hxxps://www.google.com/","hxxps://www.bing.com/"

CHR DefaultSearchURL: Default -> hxxp://www.search.ask.com/web?q={searchTerms}

CHR DefaultSearchKeyword: Default -> search.ask.com

CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li;=ff&q;={searchTerms}

CHR Plugin: (Widevine Content Decryption Module) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll => No File

CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\PepperFlash\pepflashplayer.dll ()

CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => No File

CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\pdf.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll => No File

CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll => No File

CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll => No File

CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll => No File

CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll => No File

CHR Plugin: (Java(TM) Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File

CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)

CHR Plugin: (TelevisionFanatic Installer Plugin Stub) - C:\Program Files (x86)\TelevisionFanaticEI\Installr\1.bin\NP64EISB.dll => No File

CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()

CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll => No File

CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll => No File

CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

CHR Profile: C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default [2016-11-04]

CHR Extension: (Google Drive) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-25]

CHR Extension: (Pearltrees Extension) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgngjfgpahnnncnimlhjgjhdajmaeeoa [2016-08-23]

CHR Extension: (ShopAtHome.com: Deals + Cash Back) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlmebkoiahbppacaicbgncnjhbpdfkcc [2016-10-21]

CHR Extension: (CyberGhost VPN - Free Proxy) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcbnikgemihknccdjaihjnfbapinljpi [2015-08-10]

CHR Extension: (Google Docs Offline) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-01]

CHR Extension: (Avast Online Security) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-11-03]

CHR Extension: (Bing Rewards Helper) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\neodenankcjdlhndmpcffjmcealafaig [2016-02-11]

CHR Extension: (Chrome Web Store Payments) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-06]

CHR Extension: (Bing) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofgaflfnfknmefgjhlgkohmpekighhdi [2016-09-15]

CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security Suite\Engine\22.8.0.50\Exts\Chrome.crx

CHR HKLM\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\Exts\Chrome.crx

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\raypahl\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-12-22]

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\raypahl\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-12-22]

CHR HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

CHR HKLM-x32\…\Chrome\Extension: [gihfmmedoddijgnhkgfgnkeohkpbipol] - hxxps://clients2.google.com/service/update2/crx

CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx

 

==================== Services (Whitelisted) ====================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\AESTSr64.exe [88576 2008-11-17] (Andrea Electronics Corporation)

S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-29] (AVAST Software)

R2 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [File not signed]

R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]

R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]

R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1037824 2009-09-08] (Hewlett-Packard Co.) [File not signed]

S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)

S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]

S3 Interactive Brands CrashHandler; C:\Program Files (x86)\PDF Suite 2015\crash-handler-ws.exe [745800 2015-01-23] (Interactive Brands Malta Limited)

S2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2008-06-09] (Hewlett-Packard Company) [File not signed]

S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]

S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-11] (Electronic Arts)

S3 PDF Suite 2015; C:\Program Files (x86)\PDF Suite 2015\ws.exe [1676104 2015-01-23] (Interactive Brands Malta Limited)

S2 PDF Suite 2015 Creator; C:\Program Files (x86)\PDF Suite 2015\creator-ws.exe [622920 2015-01-23] (Interactive Brands Malta Limited)

R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]

R2 Recovery Service for Windows; C:\Program Files (x86)\SMINST\BLService.exe [365952 2008-12-23] ()

R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2008-11-25] ()

R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\STacSV64.exe [290304 2009-01-28] (IDT, Inc.)

R2 TVCapSvc; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [296320 2008-11-26] ()

R2 TVSched; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [116096 2008-11-26] ()

S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-20] (Microsoft Corporation)

S3 WsAppService; C:\Program Files (x86)\Wondershare\WAF\WsAppService.exe [252816 2015-04-30] (Wondershare)

S2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [X]

 

===================== Drivers (Whitelisted) ======================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R1 Amfilter; C:\Windows\System32\DRIVERS\Amfltx64.sys [12288 2007-10-15] ((Standard mouse types))

S3 Amusbprt; C:\Windows\System32\DRIVERS\Amusbx64.sys [17920 2008-02-13] (A4Tech Co.,Ltd.)

S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [78640 2016-06-21] (AVAST Software)

S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-29] (AVAST Software)

R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-29] (AVAST Software)

R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-29] (AVAST Software)

R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [74032 2016-08-29] (AVAST Software)

R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-29] (AVAST Software)

R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-13] (AVAST Software)

R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-22] (AVAST Software)

R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [224616 2016-08-29] (AVAST Software)

S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [74544 2016-08-29] (AVAST Software)

R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)

R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-11-04] (Malwarebytes)

R2 SADP_NPF; C:\Windows\SysWOW64\drivers\sadp_npf64.sys [35344 2012-07-02] (CACE Technologies, Inc.)

S3 ssmirrdr; C:\Windows\System32\DRIVERS\ssmirrdr.sys [10112 2016-02-09] (support.com, Inc)

R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [146928 2008-11-28] (CyberLink Corp.)

S1 AntiLog32; \??\C:\Windows\system32\drivers\AntiLog64.sys [X]

U4 eabfiltr; no ImagePath

S3 IpInIp; system32\DRIVERS\ipinip.sys [X]

S3 keycrypt; system32\DRIVERS\KeyCrypt64.sys [X]

S3 NAVENG; \??\C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\SDSDefs\20160808.001\ENG64.SYS [X]

S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\SDSDefs\20160808.001\EX64.SYS [X]

S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]

S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

U3 aswMBR; \??\C:\Users\raypahl\AppData\Local\Temp\aswMBR.sys [X]

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-11-04 12:38 - 2016-11-04 12:38 - 00000512 _____ C:\Users\raypahl\Documents\MBR.dat

2016-11-04 12:33 - 2016-11-04 12:39 - 00036142 _____ C:\Users\raypahl\Desktop\FRST.txt

2016-11-04 12:31 - 2016-11-04 12:32 - 02409984 _____ (Farbar) C:\Users\raypahl\Desktop\FRST64.exe

2016-11-03 18:57 - 2016-11-03 18:57 - 00000000 ____D C:\ProgramData\EA Logs

2016-10-24 21:36 - 2016-10-24 21:36 - 00002052 _____ C:\Users\Public\Desktop\NTI Digital Jack.lnk

2016-10-24 21:36 - 2016-10-24 21:36 - 00001930 _____ C:\Users\Public\Desktop\NTI Ripper.lnk

2016-10-24 21:36 - 2016-10-24 21:36 - 00000941 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI DigitalJack.lnk

2016-10-24 21:36 - 2016-10-24 21:36 - 00000839 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Ripper.lnk

2016-10-24 21:35 - 2016-10-24 21:35 - 00001024 ___RH C:\Windows\SysWOW64\NTIRIPPER.dll

2016-10-24 21:34 - 2016-11-03 19:08 - 00000584 _____ C:\Users\raypahl\Shadow.xml

2016-10-24 21:32 - 2016-10-24 21:32 - 00000036 __RSH C:\.uid_xxx

2016-10-24 21:28 - 2016-10-24 21:28 - 00001960 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Shadow.lnk

2016-10-24 21:28 - 2016-10-24 21:28 - 00000841 _____ C:\Users\Public\Desktop\NTI Shadow.lnk

2016-10-24 21:28 - 2000-08-02 20:50 - 01056768 _____ (eHelp Corporation.) C:\Windows\SysWOW64\roboex32.dll

2016-10-24 21:26 - 2016-10-24 21:36 - 00000000 ____D C:\Program Files (x86)\NewTech Infosystems

2016-10-24 15:40 - 2016-10-24 15:40 - 00282144 _____ C:\Windows\Minidump\Mini102416-02.dmp

2016-10-24 13:01 - 2016-10-24 13:07 - 00282256 _____ C:\Windows\Minidump\Mini102416-01.dmp

2016-10-21 11:36 - 2016-09-29 23:09 - 17975808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll

2016-10-21 11:36 - 2016-09-29 23:07 - 10891264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll

2016-10-21 11:36 - 2016-09-29 23:07 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec

2016-10-21 11:36 - 2016-09-29 23:06 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb

2016-10-21 11:36 - 2016-09-29 23:05 - 02129920 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl

2016-10-21 11:36 - 2016-09-29 23:05 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 01296384 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00887296 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00528896 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00234496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe

2016-10-21 11:36 - 2016-09-29 23:05 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll

2016-10-21 11:36 - 2016-09-29 23:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe

2016-10-21 11:36 - 2016-09-29 23:05 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe

2016-10-21 11:36 - 2016-09-29 22:39 - 12859392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll

2016-10-21 11:36 - 2016-09-29 22:39 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec

2016-10-21 11:36 - 2016-09-29 22:37 - 09731584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 01831424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 01436160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl

2016-10-21 11:36 - 2016-09-29 22:36 - 01095168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 01089024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 00711168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll

2016-10-21 11:36 - 2016-09-29 22:36 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe

2016-10-21 11:36 - 2016-09-29 22:36 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

2016-10-21 11:36 - 2016-09-29 22:35 - 01789952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00217088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00042496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll

2016-10-21 11:36 - 2016-09-29 22:35 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe

2016-10-21 11:36 - 2016-09-29 22:35 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe

2016-10-21 04:18 - 2016-09-30 11:17 - 04693224 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe

2016-10-21 03:21 - 2016-09-10 11:30 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll

2016-10-21 03:20 - 2016-09-10 11:45 - 01690624 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll

2016-10-21 03:20 - 2016-09-10 11:44 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll

2016-10-21 03:20 - 2016-09-10 11:27 - 00075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll

2016-10-21 03:03 - 2016-09-10 10:24 - 02803712 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys

2016-10-21 03:03 - 2016-09-09 10:34 - 01268224 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll

2016-10-21 03:03 - 2016-09-09 10:34 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll

2016-10-21 03:03 - 2016-09-09 10:34 - 00287232 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll

2016-10-21 03:03 - 2016-09-09 10:34 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll

2016-10-21 03:03 - 2016-09-09 10:15 - 00160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll

2016-10-21 03:03 - 2016-09-09 09:57 - 02002944 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll

2016-10-21 03:03 - 2016-09-09 09:56 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll

2016-10-21 03:03 - 2016-09-09 09:44 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll

2016-10-21 03:03 - 2016-09-09 09:43 - 01561600 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll

2016-10-21 03:03 - 2016-09-09 09:42 - 01154560 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll

2016-10-21 03:03 - 2016-09-09 09:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll

2016-10-21 03:03 - 2016-09-09 09:32 - 00486912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll

2016-10-21 03:03 - 2016-09-09 09:23 - 00682496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll

2016-10-21 03:03 - 2016-09-09 09:21 - 01073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll

2016-10-21 03:02 - 2016-09-08 09:39 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys

2016-10-21 03:02 - 2016-09-08 09:39 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys

2016-10-21 03:02 - 2016-09-03 11:08 - 02528768 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll

2016-10-21 03:02 - 2016-09-03 10:50 - 01544704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll

2016-10-21 03:01 - 2016-09-14 20:41 - 00975872 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll

2016-10-21 03:01 - 2016-09-14 20:29 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll

2016-10-21 03:01 - 2016-09-14 19:23 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll

2016-10-21 03:01 - 2016-09-14 19:01 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-11-04 12:38 - 2015-03-26 15:47 - 00002398 _____ C:\Users\raypahl\Documents\aswMBR.txt

2016-11-04 12:33 - 2014-09-03 12:51 - 00000000 ____D C:\FRST

2016-11-04 11:50 - 2012-08-15 05:37 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2016-11-04 11:48 - 2012-03-30 23:57 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job

2016-11-04 11:14 - 2014-08-25 16:46 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

2016-11-04 11:13 - 2013-12-22 22:18 - 00000000 ___RD C:\Users\raypahl\Google Drive

2016-11-04 11:13 - 2011-10-05 06:39 - 00000000 ____D C:\Users\raypahl\AppData\Local\CrashDumps

2016-11-04 11:12 - 2009-03-06 02:08 - 00003584 _____ C:\Windows\System32\Tasks\HP Health Check

2016-11-04 11:09 - 2009-07-21 13:32 - 00009308 _____ C:\ProgramData\HPWALog.txt

2016-11-04 11:00 - 2012-08-15 05:37 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2016-11-04 10:58 - 2016-02-02 22:57 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0.job

2016-11-04 10:53 - 2006-11-02 10:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT

2016-11-04 10:47 - 2006-11-02 10:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

2016-11-04 10:47 - 2006-11-02 10:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

2016-11-03 20:05 - 2009-03-06 00:13 - 00000012 _____ C:\Windows\bthservsdp.dat

2016-11-03 20:05 - 2006-11-02 10:42 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2016-11-03 19:43 - 2012-03-30 23:58 - 00003682 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

2016-11-03 19:42 - 2012-03-30 23:57 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2016-11-03 19:42 - 2011-12-07 21:31 - 00000000 ____D C:\Windows\system32\Macromed

2016-11-03 19:42 - 2011-09-30 18:29 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2016-11-03 19:42 - 2009-03-06 01:12 - 00000000 ____D C:\Windows\SysWOW64\Macromed

2016-11-03 19:32 - 2015-03-26 15:55 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update

2016-11-03 19:10 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\Resources

2016-11-03 19:09 - 2014-08-25 23:08 - 00000000 ____D C:\AdwCleaner

2016-11-03 19:03 - 2012-07-05 02:08 - 00006756 _____ C:\Users\raypahl\AppData\Local\d3d9caps.dat

2016-11-03 19:03 - 2009-03-06 00:47 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2016-11-03 19:02 - 2014-03-17 11:47 - 00000000 ____D C:\Users\raypahl\Documents\Electronic Arts

2016-11-03 19:02 - 2014-03-16 11:43 - 00000000 ____D C:\Program Files (x86)\Origin Games

2016-11-03 18:55 - 2016-08-18 21:11 - 00000000 ____D C:\Program Files (x86)\SwannView Link

2016-11-03 18:54 - 2015-01-29 20:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons

2016-11-03 18:54 - 2015-01-29 20:15 - 00000000 ____D C:\Program Files (x86)\Coupons

2016-11-03 16:35 - 2016-04-06 19:42 - 00468790 _____ C:\Windows\ntbtlog.txt

2016-11-03 16:13 - 2014-08-25 16:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware

2016-11-03 16:13 - 2014-08-25 16:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware

2016-10-29 21:57 - 2009-07-21 13:21 - 00000000 ____D C:\Users\raypahl

2016-10-29 21:57 - 2006-11-02 08:34 - 00000000 ____D C:\Windows\system32\spool

2016-10-29 21:57 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\registration

2016-10-29 21:57 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\inf

2016-10-29 21:57 - 2006-11-02 07:33 - 91226112 _____ C:\Windows\system32\config\software_previous

2016-10-29 21:57 - 2006-11-02 07:33 - 36438016 _____ C:\Windows\system32\config\system_previous

2016-10-29 21:51 - 2006-11-02 07:33 - 00262144 _____ C:\Windows\system32\config\security_previous

2016-10-29 21:51 - 2006-11-02 07:33 - 00262144 _____ C:\Windows\system32\config\sam_previous

2016-10-29 20:05 - 2016-07-13 03:17 - 00000000 _____ C:\Windows\SysWOW64\last.dump

2016-10-29 11:59 - 2006-11-02 07:33 - 00524288 _____ C:\Windows\system32\config\default_previous

2016-10-29 11:49 - 2006-11-02 07:33 - 69992448 _____ C:\Windows\system32\config\components_previous

2016-10-25 13:51 - 2011-10-07 07:07 - 00000000 ____D C:\Program Files (x86)\NortonInstaller

2016-10-25 13:51 - 2009-03-06 00:49 - 00000000 ____D C:\ProgramData\Norton

2016-10-25 11:50 - 2011-10-30 10:04 - 00000000 ____D C:\Users\raypahl\AppData\Roaming\HpUpdate

2016-10-24 21:30 - 2013-08-24 14:09 - 00000000 ____D C:\Users\raypahl\Documents\deb

2016-10-24 21:24 - 2006-11-02 07:46 - 00763734 _____ C:\Windows\system32\PerfStringBackup.INI

2016-10-24 18:29 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\PolicyDefinitions

2016-10-24 17:38 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\rescache

2016-10-24 16:32 - 2014-04-30 17:50 - 00001795 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk

2016-10-24 16:29 - 2014-08-07 13:48 - 00000000 ____D C:\Users\raypahl\Documents\My Scans

2016-10-24 15:40 - 2011-10-12 14:02 - 00000000 ____D C:\Windows\Minidump

2016-10-24 15:39 - 2014-10-28 04:11 - 433651867 _____ C:\Windows\MEMORY.DMP

2016-10-21 15:53 - 2013-08-13 08:08 - 00000000 ____D C:\ProgramData\HP

2016-10-21 12:54 - 2014-05-03 12:39 - 00000000 ____D C:\Users\raypahl\AppData\LocalLow\HPAppData

2016-10-21 04:39 - 2006-11-02 10:21 - 00329512 _____ C:\Windows\system32\FNTCACHE.DAT

2016-10-21 04:38 - 2009-03-06 01:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight

2016-10-21 04:37 - 2006-11-02 10:07 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer

2016-10-21 04:04 - 2014-02-25 09:26 - 00757538 _____ C:\Windows\SysWOW64\PerfStringBackup.INI

2016-10-21 03:20 - 2013-08-14 03:11 - 00000000 ____D C:\Windows\system32\MRT

2016-10-21 03:06 - 2006-11-02 07:35 - 143495576 ____C (Microsoft Corporation) C:\Windows\system32\mrt.exe

2016-10-21 03:05 - 2010-12-20 08:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight

2016-10-20 15:15 - 2016-09-23 06:44 - 00000000 ____D C:\Windows\System32\Tasks\Remediation

2016-10-13 06:20 - 2015-03-26 15:54 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys

2016-10-10 20:52 - 2013-12-22 21:32 - 00001865 _____ C:\Users\Public\Desktop\Google Slides.lnk

2016-10-10 20:52 - 2013-12-22 21:32 - 00001863 _____ C:\Users\Public\Desktop\Google Sheets.lnk

2016-10-10 20:52 - 2013-12-22 21:32 - 00001853 _____ C:\Users\Public\Desktop\Google Docs.lnk

2016-10-10 20:52 - 2013-12-22 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive

 

==================== Files in the root of some directories =======

 

2013-10-13 21:44 - 2013-10-13 21:44 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll

2014-08-25 22:22 - 2014-10-08 11:21 - 0000004 _____ () C:\Users\raypahl\AppData\Roaming\appdataFr2.bin

2014-03-18 17:00 - 2014-04-04 03:00 - 0000082 _____ () C:\Users\raypahl\AppData\Roaming\WB.CFG

2015-12-03 21:41 - 2016-04-02 00:12 - 0000994 _____ () C:\Users\raypahl\AppData\Roaming\wklnhst.dat

2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\AtStart.txt

2012-07-05 02:08 - 2016-11-03 19:03 - 0006756 _____ () C:\Users\raypahl\AppData\Local\d3d9caps.dat

2016-08-22 15:02 - 2016-08-22 15:12 - 0000732 _____ () C:\Users\raypahl\AppData\Local\d3d9caps64.dat

2012-09-03 18:33 - 2016-08-29 20:23 - 0151552 _____ () C:\Users\raypahl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

2013-12-11 05:47 - 2013-12-11 05:49 - 0004170 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI0287.txt

2013-12-11 06:05 - 2013-12-11 06:05 - 0354328 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI0FE9.txt

2011-10-01 00:07 - 2011-10-01 00:08 - 0460566 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI3785.txt

2016-08-22 17:25 - 2016-08-22 17:25 - 0389670 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI3940.txt

2014-01-11 19:16 - 2014-01-11 19:18 - 0444592 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI6339.txt

2016-02-20 05:30 - 2016-02-20 05:31 - 0001848 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI6DAF.txt

2016-02-20 05:50 - 2016-02-20 05:51 - 0405314 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI7CE3.txt

2013-12-11 05:47 - 2013-12-11 05:48 - 0012516 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI0287.txt

2013-12-11 06:05 - 2013-12-11 06:05 - 0015670 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI0FE9.txt

2011-10-01 00:07 - 2011-10-01 00:08 - 0014878 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI3785.txt

2016-08-22 17:25 - 2016-08-22 17:25 - 0011478 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI3940.txt

2014-01-11 19:16 - 2014-01-11 19:18 - 0043456 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI6339.txt

2016-02-20 05:30 - 2016-02-20 05:31 - 0026324 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI6DAF.txt

2016-02-20 05:50 - 2016-02-20 05:51 - 0013546 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI7CE3.txt

2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\DSwitch.txt

2011-09-30 19:28 - 2016-04-06 19:16 - 0000000 _____ () C:\Users\raypahl\AppData\Local\FnF4.txt

2009-07-21 13:32 - 2009-07-21 13:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\QSwitch.txt

2011-05-27 22:02 - 2011-10-01 00:34 - 0001940 _____ () C:\Users\raypahl\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini

2009-07-21 13:32 - 2016-11-04 11:09 - 0009308 _____ () C:\ProgramData\HPWALog.txt

2013-08-13 08:08 - 2014-04-30 21:37 - 0003705 _____ () C:\ProgramData\hpzinstall.log

2014-05-27 14:19 - 2016-04-18 20:53 - 0000614 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

2009-06-13 23:40 - 2009-06-13 23:40 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log

2009-03-06 01:55 - 2009-03-06 01:55 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log

2009-06-13 23:39 - 2009-06-13 23:39 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log

2009-03-06 01:48 - 2009-03-06 01:50 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log

2009-06-13 23:38 - 2009-06-13 23:38 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log

2009-06-13 23:39 - 2009-06-13 23:39 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log

2009-03-06 01:47 - 2009-03-06 01:48 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log

2009-03-06 01:50 - 2009-03-06 01:55 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log

2009-06-13 23:39 - 2009-06-13 23:39 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log

 

Some files in TEMP:

====================

C:\Users\raypahl\AppData\Local\Temp\cct.dll

C:\Users\raypahl\AppData\Local\Temp\HPPSdr.exe

C:\Users\raypahl\AppData\Local\Temp\JavaIC.dll

C:\Users\raypahl\AppData\Local\Temp\jre-8u101-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u111-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u60-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u71-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\jre-8u77-windows-au.exe

C:\Users\raypahl\AppData\Local\Temp\msscct32.dll

C:\Users\raypahl\AppData\Local\Temp\mstsdhav.dll

C:\Users\raypahl\AppData\Local\Temp\Quarantine.exe

C:\Users\raypahl\AppData\Local\Temp\YSearchUtil.dll

C:\Users\raypahl\AppData\Local\Temp\ytb.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{03643C3A-276A-495F-A3F9-37428AF4434A}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{07CAF0E7-1697-4F67-B23C-ACFC3C227971}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{0BB9737D-9D31-4451-BEB6-239DBA7AE291}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{1ED5386F-F337-4F65-AAE0-6474DDC0870A}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{28689526-4B9A-4E80-B7C4-32CA21B40F1E}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{2E7A0B92-9E55-4DEA-BBA3-F93D732A56B1}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{3B47A66E-B640-42C1-A6CE-40F7EC6273F5}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{40718227-A6E2-4B8B-B82C-6F40933D8327}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{46949032-B4EE-4CF7-BBC4-B5A45B5A9E87}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{55E8CAEA-22C3-41F6-AB08-97D890FFC4E5}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{6440939F-A05A-484F-8E4C-EEC99859BE44}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{69A5BD0D-4B3F-47AA-B77A-450017E65E02}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{6D72D734-48F4-4782-A52E-E5447A8484CA}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{76B58018-5D24-4DC5-868E-031DC7F79E26}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{8A503156-F723-4955-BA4E-5B879A529AEA}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{BD1D630A-95F8-44BD-83D2-CE9F3897210E}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{C2B850D8-9D4A-4F7D-B6C4-1370929A49DC}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CAA2EB40-4B39-4B63-93B5-D34FDD3A127C}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CD9087A2-63C7-435F-90ED-8DC90B695CC3}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{CF7A6E42-6A6C-436F-95BB-E7DDBA6857A4}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{D3A389BA-4739-4992-AA76-08E8EF1B6BCE}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{E3A7B323-B837-426D-B8CB-63625BEEF743}.exe

C:\Users\raypahl\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360__{FF1742B3-43A5-4AB3-830F-EAD205065B03}.exe

C:\Users\raypahl\AppData\Local\Temp\{2588712D-0BFD-439A-81E4-7E5EEA9F67EA}-45.0.2454.93_45.0.2454.85_chrome_updater.exe

C:\Users\raypahl\AppData\Local\Temp\{DDE604EF-4F5C-4B52-B6F9-092F33452B06}-45.0.2454.85_44.0.2403.157_chrome_updater.exe

 

 

==================== Bamital & volsnap ======================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

 

LastRegBack: 2016-11-04 11:14

 

==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-11-2016

Ran by [removed] (04-11-2016 12:41:59)

Running from C:\Users\[removed]\Desktop

Windows Vista (TM) Home Premium Service Pack 2 (X64) (2009-06-14 03:35:45)

Boot Mode: Normal

==========================================================

 

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-513785977-584283709-202011636-500 - Administrator - Disabled)

Guest (S-1-5-21-513785977-584283709-202011636-501 - Limited - Disabled)

raypahl (S-1-5-21-513785977-584283709-202011636-1000 - Administrator - Enabled) => C:\Users\raypahl

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}

AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

 

==================== Installed Programs ======================

 

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

4500_G510gm_Help (x32 Version: 000.0.440.000 - Hewlett-Packard) Hidden

4500G510gm (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden

4500G510gm_Software_Min (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden

Acrobat.com (HKLM-x32\…\{77DCDCE3-2DED-62F3-8154-05E745472D07}) (Version: 1.1.377 - Adobe Systems Incorporated)

Activation Assistant for the 2007 Microsoft Office suites (HKLM-x32\…\Activation Assistant for the 2007 Microsoft Office suites) (Version:  - Microsoft Corporation)

Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0 - Microsoft Corporation) Hidden

ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.2 - Hewlett-Packard) Hidden

Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 23.0.0.257 - Adobe Systems Incorporated)

Adobe Flash Player 23 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 23.0.0.205 - Adobe Systems Incorporated)

Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.205 - Adobe Systems Incorporated)

Adobe Reader X (10.1.16) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)

Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)

Amazon Kindle (HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Amazon Kindle) (Version:  - Amazon)

Amazon Kindle (HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Amazon Kindle) (Version:  - Amazon)

Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)

Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)

Apple Mobile Device Support (HKLM\…\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)

Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)

Atheros Driver Installation Program (HKLM-x32\…\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 5.2 - Atheros)

Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)

BCL easyConverter Desktop 3 (Word Version) (HKLM-x32\…\{8C5845B5-729F-40E3-A945-4454E67F65F4}) (Version: 3.0.18 - BCL Technologies)

Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)

BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden

CCleaner (HKLM\…\CCleaner) (Version: 4.17 - Piriform)

Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)

CyberLink DVD Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.2512 - CyberLink Corp.)

D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden

Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden

DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden

DocMgr (x32 Version: 130.0.000.000 - Hewlett-Packard) Hidden

DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden

Download App (HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Download App) (Version: 1.8.0 - CBS Interactive)

Download App (HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Download App) (Version: 1.8.0 - CBS Interactive)

ENE CIR Receiver Driver (12/30/2008 2.7.2.0) (HKLM\…\703AB19C282B6ED3F1D3CE92F8DAA864B68A7C91) (Version: 12/30/2008 2.7.2.0 - ENE)

eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden

ESU for Microsoft Vista (HKLM-x32\…\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)

Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden

Google Chrome (HKLM-x32\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)

Google Drive (HKLM-x32\…\{FDEDE86B-3597-40D7-8568-4649F651EDBD}) (Version: 1.32.3363.5836 - Google, Inc.)

Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden

Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden

GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden

HP Active Support Library (HKLM-x32\…\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}) (Version: 3.1.9.1 - Hewlett-Packard)

HP Customer Experience Enhancements (HKLM-x32\…\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}) (Version: 5.7.0.2664 - Hewlett-Packard)

HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP)

HP Document Manager 2.0 (HKLM\…\HP Document Manager) (Version: 2.0 - HP)

HP Help and Support (HKLM-x32\…\{0054A0F6-00C9-4498-B821-B5C9578F433E}) (Version: 2.1.3.0 - Hewlett-Packard Company)

HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP)

HP MediaSmart DVD (HKLM-x32\…\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 2.1.2328 - Hewlett-Packard)

HP MediaSmart Music/Photo/Video (HKLM-x32\…\InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}) (Version: 2.2.2829 - Hewlett-Packard)

HP MediaSmart SlingPlayer (HKLM-x32\…\HP.MediaSmartSlingPlayer_is1) (Version: 2.1 - Sling Media, Inc.)

HP MediaSmart SmartMenu (HKLM\…\{0BC595C4-F736-4EB4-A1C0-32C7E81800F0}) (Version: 2.1.10 - Hewlett-Packard)

HP MediaSmart TV (HKLM-x32\…\InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}) (Version: 2.1.1709 - Hewlett-Packard)

HP MediaSmart Webcam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.2.1621 - Hewlett-Packard)

HP Officejet 4500 G510g-m (HKLM\…\{E5083D57-D93F-404C-A91F-1C50D67C2BEB}) (Version: 13.0 - HP)

HP Quick Launch Buttons (HKLM-x32\…\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.17.1 - Hewlett-Packard Company)

HP Smart Web Printing 4.5 (HKLM\…\HP Smart Web Printing) (Version: 4.5 - HP)

HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)

HP Support Solutions Framework (HKLM-x32\…\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company)

HP Total Care Advisor (HKLM-x32\…\{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}) (Version: 2.4.5991.2847 - Hewlett-Packard)

HP Total Care Setup (HKLM-x32\…\{95A747E0-DF19-46CB-A622-20A0107201BD}) (Version: 1.1.2413.2876 - Hewlett-Packard Company)

HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)

HP User Guides 0135 (HKLM-x32\…\{372ED957-0FB5-487B-B51A-388B3D393F7A}) (Version: 1.01.0000 - Hewlett-Packard)

HP Wireless Assistant (HKLM-x32\…\{462DED50-EC2E-4237-ABCF-B5C463C0EE51}) (Version: 3.50.3.1 - Hewlett-Packard)

HPAsset component for HP Active Support Library (x32 Version: 3.0.2.2 - Hewlett-Packard) Hidden

HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden

HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden

HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden

IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6146.0 - IDT)

Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version:  - Intel Corporation)

iTunes (HKLM\…\{CEC7613B-E286-4A31-BEE3-3F7798488D9F}) (Version: 12.1.3.6 - Apple Inc.)

Java 8 Update 60 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)

Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1312 - CyberLink Corp.)

LabelPrint (x32 Version: 2.5.1312 - CyberLink Corp.) Hidden

LightScribe System Software  1.14.17.1 (HKLM-x32\…\{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}) (Version: 1.14.17.1 - LightScribe)

Logitech Unifying Software 2.10 (HKLM\…\Logitech Unifying) (Version: 2.10.37 - Logitech)

Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)

MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden

Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden

Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)

Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)

Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)

Microsoft Office Live Add-in 1.5 (HKLM-x32\…\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)

Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)

Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)

Microsoft Office Standard Edition 2003 (HKLM-x32\…\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)

Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)

Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)

Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\…\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\…\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)

Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\…\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)

MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)

MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)

muvee Reveal (HKLM-x32\…\{DE626616-D7C4-4F00-7E0B-EAF26FA65749}) (Version: 7.0.43.12698 - muvee Technologies Pte Ltd)

My HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.0.62 - WildTangent)

Network64 (Version: 130.0.550.000 - Hewlett-Packard) Hidden

NTI Ripper (HKLM-x32\…\{88A785A2-3EA6-4A2D-ABEE-68E9E55A39F8}) (Version: 2.0.0.17 - NewTech Infosystems)

NTI Shadow 3 (HKLM-x32\…\{E9EB5689-4F76-4E3C-A675-5ED5F52AB890}) (Version: 3.1.4.0 - NewTech Infosystems)

OCR Software by I.R.I.S. 13.0 (HKLM\…\HPOCR) (Version: 13.0 - HP)

Origin (HKLM-x32\…\Origin) (Version: 9.4.6.2792 - Electronic Arts, Inc.)

PDF Suite 2015 (HKLM-x32\…\PDF Suite 2015) (Version: 13.0.10.21694 - Interactive Brands Malta Limited)

PDF Suite 2015 (x32 Version: 13.0.23.21617 - Interactive Brands Malta Limited) Hidden

PDF Suite 2015 OCR Module (x32 Version: 13.0.23.21617 - Interactive Brands Malta Limited) Hidden

PhotoScape (HKLM-x32\…\PhotoScape) (Version:  - )

Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.2512 - CyberLink Corp.)

Power2Go (x32 Version: 6.0.2512 - CyberLink Corp.) Hidden

PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2512 - CyberLink Corp.)

PowerDirector (x32 Version: 7.0.2512 - CyberLink Corp.) Hidden

ProtectSmart Hard Drive Protection (HKLM\…\{2F97CE84-9C33-4631-821B-85EA371EA254}) (Version: 3.10.1.7 - Hewlett-Packard)

QLBCASL (x32 Version: 6.40.17.2 - Hewlett-Packard) Hidden

QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)

Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek)

Realtek USB 2.0 Card Reader (HKLM-x32\…\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: 6.0.6000.20113 - Realtek Semiconductor Corp.)

Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)

SafeZone Stable 1.48.2066.114 (x32 Version: 1.48.2066.114 - Avast Software) Hidden

Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden

Segoe UI (x32 Version: 15.4.2271.0615 - Microsoft Corp) Hidden

Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 13.0 - HP)

Slingbox - Watch Your TV Anywhere (HKLM-x32\…\{7B798B31-2F33-4DC8-BDA4-D36488E86636}) (Version: 1.0.0 - Sling Media)

SlingPlayer (HKLM-x32\…\InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}) (Version: 1.04.0206 - Sling Media)

SlingPlayer (x32 Version: 1.04.0206 - Sling Media) Hidden

SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden

SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden

Spelling Dictionaries Support For Adobe Reader 9 (HKLM-x32\…\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)

Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden

Steam (HKLM-x32\…\Steam) (Version:  - Valve Corporation)

swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden

Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated)

Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden

TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden

TurboTax 2012 (HKLM-x32\…\TurboTax 2012) (Version: 2012.0 - Intuit, Inc)

Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden

WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden

WildTangent Games App (HP Games) (HKLM-x32\…\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.31 - WildTangent)

Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)

Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)

Windows Live Sync (HKLM-x32\…\{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}) (Version: 14.0.8064.206 - Microsoft Corporation)

Xilisoft Video Converter Ultimate (HKLM-x32\…\Xilisoft Video Converter Ultimate) (Version: 7.7.3.20131014 - Xilisoft)

Yahoo Search Set (HKLM-x32\…\Yahoo! SearchSet) (Version:  - Yahoo Inc.)

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {1E47DECC-A445-437E-BA49-BF68A0FE709D} - System32\Tasks\HP Health Check => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09] (Hewlett-Packard)

Task: {1EEC94E2-3371-4445-B69E-06C410B6EE74} - System32\Tasks\{6EA9492D-AFAD-4611-B778-FEF2E452B324} => pcalua.exe -a "C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GJQZPLZ1\Athena[1].exe" -d C:\Users\raypahl\Desktop

Task: {24AF7C9D-752C-4445-A82B-1BE9CDF09079} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

Task: {2676CF9D-8246-4E69-9166-E93FAAEF4707} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-03] (Adobe Systems Incorporated)

Task: {3712F5A0-0477-4593-898F-2D6722E1694A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

Task: {5BF15EEE-CE81-46B3-97C4-2F0217BF3198} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)

Task: {6E74CFCE-FF9D-417D-9884-56337FA84896} - System32\Tasks\HPCeeScheduleForraypahl => C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe [2008-05-19] (Hewlett-Packard)

Task: {C4A2780D-68B8-4F95-A118-6E5DD88047E0} - System32\Tasks\NetworkWizardHNW => C:\Program Files (x86)\Hewlett-Packard\HP TCS\RemEngine.exe [2008-12-17] ()

Task: {E226896F-2D00-4835-94CA-6E3EE9E822E0} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-29] (AVAST Software)

Task: {EC1DA6EA-D89F-45D1-96DA-F64D32C2C68E} - System32\Tasks\SafeZone scheduled Autoupdate 1468319266 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-06-17] (Avast Software)

Task: {EC3518F0-B320-4AC6-B0D1-D131875A226A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

Task: {ECBDA076-B4B3-4E77-8185-DC8446925D32} - System32\Tasks\{2DF12692-40FF-4911-A6C8-8B1BF5365384} => pcalua.exe -a C:\Users\raypahl\AppData\Local\Microsoft\Windows\Burn\Burn\callatlanta_setup.exe

Task: {F1351889-C902-458D-940D-9EEB132FCC88} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)

Task: {FD30349E-1798-46DF-A9FF-96869C61C29C} - System32\Tasks\{B8696691-6D99-40A1-8CEE-83EC12275D01} => pcalua.exe -a C:\Users\raypahl\Desktop\esetsmartinstaller_enu.exe -d C:\Users\raypahl\Desktop

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\HPCeeScheduleForraypahl.job => C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe

 

==================== Shortcuts =============================

 

(The entries could be listed to be restored or removed.)

 

Shortcut: C:\Users\raypahl\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.com

 

==================== Loaded Modules (Whitelisted) ==============

 

2009-03-06 02:02 - 2008-12-23 19:18 - 00365952 _____ () C:\Program Files (x86)\SMINST\BLService.exe

2009-03-06 01:55 - 2008-11-25 18:29 - 00247152 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

2008-11-26 19:13 - 2008-11-26 19:13 - 00296320 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe

2008-11-26 19:13 - 2008-11-26 19:13 - 00116096 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe

2015-03-20 18:12 - 2015-03-20 18:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll

2015-03-20 18:12 - 2015-03-20 18:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll

2008-11-26 19:12 - 2008-11-26 19:12 - 00074536 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\Common\MCEMediaStatus64.dll

2009-07-01 15:44 - 2009-07-01 15:44 - 00632888 _____ () C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe

2016-08-29 18:18 - 2016-08-29 18:18 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll

2016-11-04 08:16 - 2016-11-04 08:16 - 03127760 _____ () C:\Program Files\AVAST Software\Avast\defs\16110400\algo.dll

2016-08-29 18:18 - 2016-08-29 18:18 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll

2009-03-06 02:02 - 2008-12-23 19:18 - 00132480 _____ () C:\Program Files (x86)\SMINST\STWmiM.dll

2009-03-06 01:55 - 2008-11-25 18:29 - 00034088 _____ () C:\Program Files (x86)\Cyberlink\Shared files\RichVideops.dll

2008-11-26 19:13 - 2008-11-26 19:13 - 00263560 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLCapEngine.dll

2008-11-26 19:13 - 2008-11-26 19:13 - 00038184 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLCapSvcps.dll

2007-07-12 15:55 - 2007-07-12 15:55 - 01581056 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll

2007-08-14 15:59 - 2007-08-14 15:59 - 06365184 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll

2007-07-12 15:55 - 2007-07-12 15:55 - 00131072 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll

2014-10-10 12:41 - 2014-10-10 12:41 - 01255936 _____ () C:\Program Files (x86)\CBS Interactive\Download App\libcurl.dll

2014-10-10 12:39 - 2014-10-10 12:39 - 00066560 _____ () C:\Program Files (x86)\CBS Interactive\Download App\zlib.dll

2008-11-26 19:13 - 2008-11-26 19:13 - 00349480 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLTinyDB.dll

2009-04-29 22:11 - 2009-04-29 22:11 - 00906536 ____N () C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll

2016-07-11 22:01 - 2016-07-11 22:02 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

2016-11-04 11:08 - 2016-11-04 11:08 - 00098816 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32api.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00110080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pywintypes27.dll

2016-11-04 11:08 - 2016-11-04 11:08 - 00364544 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pythoncom27.dll

2016-11-04 11:08 - 2016-11-04 11:08 - 00320512 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32com.shell.shell.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00914432 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_hashlib.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 01176576 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._core_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00806400 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._gdi_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00816128 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._windows_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 01067008 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._controls_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00733184 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._misc_.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00682496 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pysqlite2._sqlite.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00088064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_ctypes.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00686080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\unicodedata.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00119808 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32file.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00108544 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32security.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00007168 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\hashobjs_ext.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00017920 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\thumbnails_ext.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00088064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\usb_ext.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00012800 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\common.time34.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00018432 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32event.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00167936 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32gui.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00046080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_socket.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 01303552 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_ssl.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00128512 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_elementtree.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00127488 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\pyexpat.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00038912 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32inet.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00036864 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_psutil_windows.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00524248 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\windows._lib_cacheinvalidation.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00011264 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32crypt.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00123392 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._wizard.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00077312 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._html2.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00027648 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_multiprocessing.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00020480 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\_yappi.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00035840 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32process.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00078848 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\wx._animate.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00024064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32pipe.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00010240 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\select.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00025600 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32pdh.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00017408 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32profile.pyd

2016-11-04 11:08 - 2016-11-04 11:08 - 00022528 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI25322\win32ts.pyd

2016-09-06 14:28 - 2016-09-06 12:00 - 05197312 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libglesv2.dll

2016-09-06 14:28 - 2016-09-06 12:00 - 00147456 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libegl.dll

2016-07-13 04:28 - 2016-07-06 18:01 - 17602240 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\PepperFlash\22.0.0.209\pepflashplayer.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

 

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

 

==================== Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

HKLM\…\cmdfile\DefaultIcon: %SystemRoot%\System32\shell32.dll,-153 <===== ATTENTION

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

IE trusted site: HKU\S-1-5-21-513785977-584283709-202011636-1000\…\intuit.com -> hxxps://accounts.intuit.com

IE trusted site: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\intuit.com -> hxxps://accounts.intuit.com

 

==================== Hosts content: ===============================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2006-11-02 07:34 - 2006-09-18 16:37 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts

 

127.0.0.1       localhost

::1             localhost

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg

HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg

HKU\S-1-5-21-513785977-584283709-202011636-1000\Control Panel\Desktop\\Wallpaper ->

HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper ->

DNS Servers: 75.75.75.75 - 75.75.76.76

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)

Windows Firewall is enabled.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Constant Guard.lnk => C:\Windows\pss\Constant Guard.lnk.CommonStartup

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Fast Connect.lnk => C:\Windows\pss\Fast Connect.lnk.CommonStartup

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe

FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe

FirewallRules: [{85CA64C5-0E24-49D3-962C-757C4D4EF5EA}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE

FirewallRules: [{C056B941-D6C9-43C2-BC46-C8062C7E9591}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe

FirewallRules: [{A477DEFD-C4F3-49DF-9493-DCB0193B3DC2}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe

FirewallRules: [{9DA0FA66-F81F-4C49-93E4-0C736F80D266}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe

FirewallRules: [{D62589CC-FCFC-474B-897E-5F4E2E376DB6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\TSMAgent.exe

FirewallRules: [{0C18A91B-06AB-412C-A4FB-56721866C9EB}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe

FirewallRules: [{90B91326-6994-4D67-8710-402213196972}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe

FirewallRules: [{892F181D-FCD8-4749-A566-1DDE9D5E06C6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QP.exe

FirewallRules: [{218696AD-0268-44D1-958A-9FB0C07367EE}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QPService.exe

FirewallRules: [{C0D11A95-3BAB-4C69-9B2F-ABDF0DE00382}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe

FirewallRules: [{DA361D62-6094-45AB-8548-C892212DD857}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe

FirewallRules: [{E29DF1CE-61F4-4C67-B5E6-018649FED1F0}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe

FirewallRules: [{28D8EE93-F60E-412F-B1D8-2540677725C9}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe

FirewallRules: [{2C5DE510-0436-4BA6-9D33-EA65AD777F21}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe

FirewallRules: [{2121075F-A168-42F2-A24D-D0A4C9205054}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe

FirewallRules: [{899817AC-8E24-4616-A1BB-9CF013A72458}] => (Allow) LPort=80

FirewallRules: [{801C85E3-1031-4FA1-9462-DDCCDD72601F}] => (Allow) LPort=80

FirewallRules: [{2A217FCB-85BA-4D43-88A5-E696A21C17BE}] => (Allow) LPort=80

FirewallRules: [{67913156-DF65-4018-B0AC-C4BA598F0458}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

FirewallRules: [{F97F9C53-4B16-44C5-9DAB-BE26D646BB2E}] => (Allow) LPort=2869

FirewallRules: [{ECDA4AA6-F84F-4F8C-A5C2-0981BEB965AB}] => (Allow) LPort=1900

FirewallRules: [{99E21AA7-60B0-4758-9700-947CE68E6FC4}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

FirewallRules: [{556638C7-DDD1-49D4-B540-2BF1813097BE}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe

FirewallRules: [{BA7B17AA-ECB1-48CA-B123-DEDEF25F5280}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{C8533641-5BA2-4226-AFAD-01CAA75D4BC3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{2079C40C-30DB-4EC9-A37D-2A69F7CB2B9A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{7AA88511-8B20-4763-AB96-65C325F436C2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{8338DBF9-E8CD-40AC-A575-BC1C4D3264AE}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{49D4AFA4-BDA6-4F09-A81E-C49E81BDD809}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{F2531826-2F73-4998-9503-3CB1A9EF475A}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{50BB60C3-956B-46D3-BD6E-BF3715DAEAA8}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe

FirewallRules: [{938E4FAF-25DE-43F0-8941-BAB51D00909F}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{32D0853C-F33F-4CA2-BDD9-EB0E43C2C1A9}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe

FirewallRules: [{028CDA9D-6AA2-48CC-97F4-8CB3BFFEDCAE}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe

FirewallRules: [{24ED04E3-69B3-4EF6-AB2B-774FF6EBB341}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe

FirewallRules: [{B498508E-E2F8-420D-AF6B-5E4EB2847438}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe

FirewallRules: [{149237F6-0247-4D6A-9B24-6284C0EC1F6E}] => (Allow) LPort=80

FirewallRules: [{0D5BE560-6B3C-4CA0-A163-4A0D4761952F}] => (Allow) LPort=3074

FirewallRules: [{46BBA3EE-07CF-43BA-B750-B59D6FEA6E67}] => (Allow) LPort=53

FirewallRules: [{1937BBB4-CCBA-487B-ABF4-965EBD64F35D}] => (Allow) LPort=88

FirewallRules: [{0B06D53B-770D-4F4F-8750-588083139BD4}] => (Allow) LPort=3074

FirewallRules: [{63DB0018-84DB-4F7D-91A6-5EEB5D473E2C}] => (Allow) LPort=53

FirewallRules: [{4BD011AB-0AC7-4B5A-A0CF-466CC36B4E10}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS6610\HPDiagnosticCoreUI.exe

FirewallRules: [{5CFF6CC9-FFCC-4E3F-BC41-D4AC77525B27}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS6610\HPDiagnosticCoreUI.exe

FirewallRules: [{D627BCA2-CF30-4E83-813D-55AE2787BACA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe

FirewallRules: [{8EBE220A-A2E8-47DC-9A52-C00C722B2B36}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe

FirewallRules: [{67F0DD1B-2C2B-4DF0-83BD-CA448BAF87E8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe

FirewallRules: [{277CCB2A-D8F2-4438-8B24-11CC51D7A2DD}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe

FirewallRules: [{A4D4FBBF-F068-4D39-8BE3-74355B903AB7}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3C2E\HPDiagnosticCoreUI.exe

FirewallRules: [{71675975-38A1-48EA-ACCB-FABEF0BD9D13}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3C2E\HPDiagnosticCoreUI.exe

FirewallRules: [{56345E73-9C25-4274-A858-4690E48E1F67}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS64AB\HPDiagnosticCoreUI.exe

FirewallRules: [{E16F485C-ED68-4BD6-8805-2A64A9D96A39}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS64AB\HPDiagnosticCoreUI.exe

FirewallRules: [{31BE109E-8AF9-4143-AD52-57F7DB7FAED8}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS0964\HPDiagnosticCoreUI.exe

FirewallRules: [{A93D5B10-FD8F-4B4F-B432-6A12E6A2D0DC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS0964\HPDiagnosticCoreUI.exe

FirewallRules: [{7C26B91E-B117-486A-B514-1E931777327D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

FirewallRules: [{3D0B25BE-B075-4318-8FAD-AA4378D408D4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe

FirewallRules: [{3190CC53-3DB5-4C54-B6F1-0770B51650F2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe

FirewallRules: [{D9A183D9-B520-4D17-8D52-4341A9CFBBEC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe

FirewallRules: [{BCEEDD97-2D66-466F-B460-54D582497581}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe

FirewallRules: [{603C8A2D-FB38-49BD-9FDD-2934CAECAE11}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe

FirewallRules: [{DDEE3F5E-97F1-4B23-9929-9B3755027FC8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe

FirewallRules: [{38A2B6F1-AE10-4306-AC8B-57D65B8552FB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe

FirewallRules: [{A6BD5514-3186-4D82-ACE9-8AFC163F591F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe

FirewallRules: [{E5BEACAE-D7A3-4D30-8284-ED4CDC7EE1F1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe

FirewallRules: [{55C0994B-0B3E-444F-A6F1-771232CE4C04}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe

FirewallRules: [{24942CC8-CEE3-42BD-AE57-6FC7B5B01D26}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe

FirewallRules: [{80E01553-7E49-42EB-84AA-260B63480BFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe

FirewallRules: [{3D37A03B-72C1-4951-AACC-F8F9842EAC32}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe

FirewallRules: [{9851363A-29E7-4066-808D-76F09B44EAA9}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{6DF5A30B-3B0F-4CC8-91E7-C21179661239}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe

FirewallRules: [{00C3DF64-1789-45C4-826E-F88407B37F60}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{8060B257-FF11-4A7E-B4D6-8822812D5766}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{FDC220B2-E26C-439A-8AEE-6CB05A6A9CDF}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{0548CB3C-9BAA-419F-AC3C-CF92119ECF94}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{23D1FC3D-674C-44F8-9961-46BBEB100F2F}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{069C9567-F251-4E40-B6F7-7B7D7D9109AC}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{D99F3B45-4583-426E-8CDF-DF5E521807C6}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{D41E6F5E-2589-4C57-9E12-1D63C165791D}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{6DEEE18D-D523-45BF-932E-CE5743988EE8}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{43D52C1D-478B-4FCE-9745-AAF8982DF4DC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS175A\HPDiagnosticCoreUI.exe

FirewallRules: [{A707CC94-5C2F-4D23-8BCD-1307DBA1F380}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS175A\HPDiagnosticCoreUI.exe

FirewallRules: [{D5F39F1E-2D2C-4FE4-AC8F-7D1244D261F1}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS17E3\HPDiagnosticCoreUI.exe

FirewallRules: [{98DD6223-287E-4612-84C7-8256612DF4EE}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS17E3\HPDiagnosticCoreUI.exe

FirewallRules: [{A5F88943-D64D-41D9-ACDD-54EDBEC8ECC3}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS61A2\HPDiagnosticCoreUI.exe

FirewallRules: [{0295B60A-D80C-449F-A559-2559D30C56ED}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS61A2\HPDiagnosticCoreUI.exe

FirewallRules: [{B26FD28B-080C-4DC6-84AF-10360A7C1848}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS326C\HPDiagnosticCoreUI.exe

FirewallRules: [{EDDD3BB6-DE4D-491F-9E82-60EED756FAB0}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS326C\HPDiagnosticCoreUI.exe

FirewallRules: [{720847F8-E7ED-4F05-A979-64A3CABFD9A4}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{9DED4120-5843-4CD7-96F8-BA8DC78DD4D2}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{5188845E-5ABE-493A-8AE3-C562AF667662}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3742\HPDiagnosticCoreUI.exe

FirewallRules: [{87FB02D8-EDC9-4628-8196-40F55E2955A2}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3742\HPDiagnosticCoreUI.exe

FirewallRules: [{37154139-4F88-40F7-8C66-F721A336A600}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3780\HPDiagnosticCoreUI.exe

FirewallRules: [{D47BCBCC-ADF9-4F87-BCFB-E6EFD8A23273}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3780\HPDiagnosticCoreUI.exe

FirewallRules: [{C550D466-6DA9-4CF3-AF39-E1B7B9D3491A}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS5F6B\HPDiagnosticCoreUI.exe

FirewallRules: [{ABBB6631-70E4-4D5A-8D5D-105E6B6C2047}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS5F6B\HPDiagnosticCoreUI.exe

FirewallRules: [{735A1C21-05AD-49A7-B856-D8DB046D814B}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{072D341C-F0AA-4EC4-B256-90AA1A0371D6}] => (Allow) C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe

FirewallRules: [{0E09CE06-6B58-4C5C-B41F-9CBC3C28310F}] => (Allow) C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe

FirewallRules: [{AF858CCB-A6DC-41B2-A8F1-DEC030D92EEB}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe

FirewallRules: [{4850BCB1-4BDE-4888-9338-413BF216736F}] => (Allow) C:\Program Files\iTunes\iTunes.exe

FirewallRules: [{37A8803F-79F3-4EA8-B4DC-EFC8C0988147}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

FirewallRules: [TCP Query User{05B7B3B1-49C4-42B6-B68A-EFF0B868DFBB}C:\program files (x86)\swannview link\mydvr.exe] => (Allow) C:\program files (x86)\swannview link\mydvr.exe

FirewallRules: [UDP Query User{3A8123E3-4600-46C8-8ACE-AF6FB9F3DE3D}C:\program files (x86)\swannview link\mydvr.exe] => (Allow) C:\program files (x86)\swannview link\mydvr.exe

FirewallRules: [TCP Query User{0B8D5604-9A95-4CBA-99CC-80CD63F8BD63}C:] => (Allow) C:\

FirewallRules: [UDP Query User{423E6DF9-8B53-405B-8F7D-6926AE5B5679}C:] => (Allow) C:\

FirewallRules: [{954DDB9D-8A37-4449-BC09-F3070B20367E}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS420D\HPDiagnosticCoreUI.exe

FirewallRules: [{DA174395-2E36-4D4D-B5EC-11BFF9576FD7}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS420D\HPDiagnosticCoreUI.exe

FirewallRules: [{53EE87C1-3AC3-43AD-B1D9-4ECE6A351714}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS42CB\HPDiagnosticCoreUI.exe

FirewallRules: [{6A40C1D8-44EC-4858-97A6-EAE58655C9EC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS42CB\HPDiagnosticCoreUI.exe

FirewallRules: [{5537C001-D930-41E2-B89C-942DB712A6B9}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS4196\HPDiagnosticCoreUI.exe

FirewallRules: [{665ECD78-617F-490D-B46F-145BA00FC68D}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS4196\HPDiagnosticCoreUI.exe

 

==================== Restore Points =========================

 

 

==================== Faulty Device Manager Devices =============

 

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (11/04/2016 11:13:24 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application jucheck.exe, version 2.8.60.27, time stamp 0x55c116b1, faulting module jucheck.exe, version 2.8.60.27, time stamp 0x55c116b1, exception code 0x40000015, fault offset 0x00052d24,

process id 0x13fc, application start time 0x01d236b6291b8d5d.

 

Error: (11/04/2016 11:12:07 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/04/2016 11:12:07 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0xfa0, application start time 0x01d236b5be6c075d.

 

Error: (11/04/2016 11:08:36 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/04/2016 11:08:36 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0xb08, application start time 0x01d236b55e2842ad.

 

Error: (11/04/2016 11:06:08 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

 

Error: (11/04/2016 11:05:19 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/04/2016 11:05:19 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0x200, application start time 0x01d236b296f38870.

 

Error: (11/03/2016 08:34:51 PM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program Host Process for Windows Services because of this error.

 

Program: Host Process for Windows Services

File: C:\Windows\Prefetch\AgRobust.db

 

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

            - It is on the network,

your network administrator should verify that there is not a problem with the network and that the server can be contacted.

            - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

 

Additional Data

Error value: C0000185

Disk type: 3

 

Error: (11/03/2016 08:34:51 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,

process id 0x105c, application start time 0x01d2363b354c4410.

 

 

System errors:

=============

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:39 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

Error: (11/04/2016 11:20:35 AM) (Source: atapi) (EventID: 11) (User: )

Description: The driver detected a controller error on \Device\Ide\IdePort0.

 

 

CodeIntegrity:

===================================

  Date: 2016-11-04 11:16:11.209

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:10.273

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:09.368

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:08.463

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:07.403

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:06.420

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:02.192

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:01.225

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:16:00.242

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-11-04 11:15:59.259

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

 

 

==================== Memory info ===========================

 

Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz

Percentage of memory in use: 77%

Total physical RAM: 3998.02 MB

Available physical RAM: 897.88 MB

Total Virtual: 8221.28 MB

Available Virtual: 4898.43 MB

 

==================== Drives ================================

 

Drive c: () (Fixed) (Total:452.13 GB) (Free:143.29 GB) NTFS ==>[drive with boot components (obtained from BCD)]

Drive d: (RECOVERY) (Fixed) (Total:13.62 GB) (Free:2.09 GB) NTFS ==>[system with boot components (obtained from drive)]

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (Size: 465.8 GB) (Disk ID: 636BBFB1)

Partition 1: (Active) - (Size=452.1 GB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=13.6 GB) - (Type=07 NTFS)

 

==================== End of Addition.txt ============================

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software

Run date: 2016-11-04 12:17:48

—————————–

12:17:48.853    OS Version: Windows x64 6.0.6002 Service Pack 2

12:17:48.853    Number of processors: 2 586 0x170A

12:17:48.853    ComputerName: STEARNS-PC  UserName: raypahl

12:18:03.243    Initialize success

12:18:03.259    VM: initialized successfully

12:18:03.259    VM: Intel CPU virtualization not supported

12:18:17.053    AVAST engine defs: 16110400

12:18:33.738    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0

12:18:33.738    Disk 0 Vendor: TOSHIBA_MK5055GSX FG002C Size: 476940MB BusType: 3

12:18:34.284    Disk 0 MBR read successfully

12:18:34.300    Disk 0 MBR scan

12:18:34.628    Disk 0 unknown MBR code

12:18:34.674    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       462985 MB offset 2048

12:18:35.064    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        13951 MB offset 948195328

12:18:36.094    Disk 0 scanning C:\Windows\system32\drivers

12:19:48.861    Service scanning

12:23:22.187    Modules scanning

12:23:22.187    Disk 0 trace - called modules:

12:23:22.732    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys

12:23:22.732    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006478060]

12:23:22.748    3 CLASSPNP.SYS[fffffa6000a4ec33] -> nt!IofCallDriver -> [0xfffffa8006245310]

12:23:22.748    5 hpdskflt.sys[fffffa6001802189] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004bf1590]

12:23:35.110    AVAST engine scan C:\Windows

12:23:52.825    AVAST engine scan C:\Windows\system32

12:38:13.645    Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\MBR.dat"

12:38:13.661    The log file has been saved successfully to "C:\Users\raypahl\Documents\aswMBR.txt"

12:38:52.007    AVAST engine scan C:\Windows\system32\drivers

12:40:35.754    AVAST engine scan C:\Users\raypahl

13:04:35.987    Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\MBR.dat"

13:04:36.031    The log file has been saved successfully to "C:\Users\raypahl\Documents\aswMBR.txt"

13:07:08.922    Disk 0 MBR has been saved successfully to "C:\Users\raypahl\Documents\deb\computer help\MBR.dat"

13:07:08.929    The log file has been saved successfully to "C:\Users\raypahl\Documents\deb\computer help\aswMBR.txt"

 

 

 

Welcome back. Sorry I had to close the thread but forum rules, we close them after 3 days with no reply.

 

Nothing really earth shatterng on your logs, just a few things to take care of. 

 

A heads up on CCleaner, its a very nice program to remove temp files and cookies and things like that but dont ever go into Registry and remove anything , remove the wrong entry or entries and you can make your system unbootable.

 

 

Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint:
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid=1&pid=21&src=sgsearch&v=1.15.414.3&searchparam={SearchTerms}
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid=1&pid=21&src=sgsearch&v=1.15.414.3&searchparam={SearchTerms}
Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp
CHR DefaultSearchURL: Default -> hxxp://www.search.ask.com/web?q={searchTerms}
CHR DefaultSearchKeyword: Default -> search.ask.com
CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li=ff&q={searchTerms}
S2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [X]
CMD: ipconfig /flushdns
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 
 
 
 
Then lets do some general clean up
 
 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
 
[external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
So let me see the following logs please
 
1. Fixlog fron the Frst64 fix
2. AdwCleaner log
3. Junkware removal log

 

I totally understand the reason for closing my first post.  Appreciate the help.  After running the FRST Upon restart, there was a text box that said

MSASCui.exe Application Error.  The application failed to initialize properly (Oxc.000006)

Click OK to terminate.

 

 

And there was another that said, Windows recovered from an unexpected shutown.

 

 

 

Problem signature:

  Problem Event Name:                        BlueScreen

  OS Version:                                          6.0.6002.2.2.0.768.3

  Locale ID:                                             1033

 

Additional information about the problem:

  BCCode:                                               77

  BCP1:                                                    FFFFFFFFC0000185

  BCP2:                                                    FFFFFFFFC0000185

  BCP3:                                                    0000000000000000

  BCP4:                                                    0000000000F83000

  OS Version:                                          6_0_6002

  Service Pack:                                       2_0

  Product:                                               768_1

 

Files that help describe the problem:

  C:\Windows\Minidump\Mini111016-01.dmp

  C:\Users\raypahl\AppData\Local\Temp\WER-2349577-0.sysdata.xml

  C:\Users\raypahl\AppData\Local\Temp\WERD44F.tmp.version.txt

 

Read our privacy statement:

  http://go.microsoft.com/fwlink/?linkid=50163&clcid=0nx0409

 

 

 

Now here's my logs.

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 04-11-2016
Ran by [removed] (10-11-2016 19:59:33) Run:3
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid=1&pid=21&src=sgsearch&v=1.15.414.3&searchparam={SearchTerms}
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {C78F5C05-B08E-4D7F-9EED-BA84396C483B} URL = hxxp://search.whiteskyservices.com/?wstoken=8F5B7C58-90DC-40C6-84D2-082CBCC308CA&dtid=1&pid=21&src=sgsearch&v=1.15.414.3&searchparam={SearchTerms}
Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp
CHR DefaultSearchURL: Default -> hxxp://www.search.ask.com/web?q={searchTerms}
CHR DefaultSearchKeyword: Default -> search.ask.com
CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li=ff&q={searchTerms}
S2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [X]
CMD: ipconfig /flushdns
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
"HKU\S-1-5-21-513785977-584283709-202011636-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C78F5C05-B08E-4D7F-9EED-BA84396C483B}" => key removed successfully
HKCR\CLSID\{C78F5C05-B08E-4D7F-9EED-BA84396C483B} => key not found. 
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C78F5C05-B08E-4D7F-9EED-BA84396C483B} => key not found. 
HKCR\CLSID\{C78F5C05-B08E-4D7F-9EED-BA84396C483B} => key not found. 
HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. 
HKU\S-1-5-21-513785977-584283709-202011636-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value not found.
HKCR\CLSID\Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000-{{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. 
Chrome HomePage => removed successfully
Chrome DefaultSearchURL => removed successfully
Chrome DefaultSearchKeyword => removed successfully
Chrome DefaultSuggestURL => removed successfully
CouponPrinterService => service removed successfully
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 15736154 B
Java, Flash, Steam htmlcache => 1026 B
Windows/system/drivers => 979237047 B
Edge => 0 B
Chrome => 359265186 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 66228 B
systemprofile32 => 99856 B
LocalService => 0 B
LocalService => 0 B
NetworkService => 6557 B
NetworkService => 0 B
raypahl => 2825944965 B
 
RecycleBin => 422272416 B
EmptyTemp: => 4.3 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 20:57:25 ====
 
 
 
# AdwCleaner v6.030 - Logfile created 10/11/2016 at 22:21:53
# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-10-18.1 [Local]
# Operating System : Windows (TM) Vista Home Premium Service Pack 2 (X64)
# Username : raypahl - STEARNS-PC
# Running from : C:\Users\raypahl\Desktop\AdwCleaner.exe
# Mode: Clean
# Support : hxxps://www.malwarebytes.com/support
 
 
 
***** [ Services ] *****
 
 
 
***** [ Folders ] *****
 
[#] Folder deleted on reboot: C:\ProgramData\b3ca538f2e11cdd8
[#] Folder deleted on reboot: C:\Users\raypahl\AppData\Local\DriverTuner
[#] Folder deleted on reboot: C:\Users\raypahl\AppData\Local\YSearchUtil
[#] Folder deleted on reboot: C:\Users\raypahl\AppData\LocalLow\HPAppData
[#] Folder deleted on reboot: C:\Users\raypahl\AppData\LocalLow\Yahoo!\Companion
[#] Folder deleted on reboot: C:\Users\raypahl\AppData\Roaming\Yahoo! Companion
[#] Folder deleted on reboot: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
[#] Folder deleted on reboot: C:\Program Files (x86)\Coupons
[#] Folder deleted on reboot: C:\Program Files (x86)\Yahoo!\yset
[#] Folder deleted on reboot: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil
[#] Folder deleted on reboot: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Fast Free Converter
[#] Folder deleted on reboot: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Yahoo! Companion
[#] Folder deleted on reboot: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Yahoo!\Companion
[#] Folder deleted on reboot: C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ccncljhbalbbkkfgopogabimepmfkmff
 
 
***** [ Files ] *****
 
[-] File deleted: C:\Users\raypahl\AppData\Roaming\appdataFr2.bin
[-] File deleted: C:\prefs.js
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKLM\SOFTWARE\Classes\Applications\iLividSetup-r394-n-bc.exe
[-] Key deleted: HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Key deleted: HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{FCF8BFD3-39B8-4370-B464-EC2AAACD97CF}
[-] Key deleted: HKCU\Software\Classes\CLSID\{BEBBC426-4F16-4567-8FE1-BE198C982027}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{2FF49ED5-A3EF-410B-918E-97DECEB5996D}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2FF49ED5-A3EF-410B-918E-97DECEB5996D}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2FF49ED5-A3EF-410B-918E-97DECEB5996D}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key deleted: HKU\.DEFAULT\Software\Yahoo\Companion
[-] Key deleted: HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\DriverTuner
[-] Key deleted: HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\DriverTuner_Init
[-] Key deleted: HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Yahoo\Companion
[-] Key deleted: HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Yahoo\YFriendsBar
[-] Key deleted: HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\AppDataLow\Software\adawarebp
[-] Key deleted: HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\AppDataLow\Software\Yahoo\Companion
[-] Key deleted: HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4F524A2D-5350-4500-76A7-A758B70C1801}
[-] Key deleted: HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{520C1D80-935C-42B9-9340-E883849D804F}_is1
[-] Key deleted: HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AE9B04F2-E9E8-162C-829B-52C116B3EFCC}
[-] Key deleted: HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yahoo! SearchSet
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-513785977-584283709-202011636-1000\Software\BatBrowse
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-513785977-584283709-202011636-1000\Software\Yahoo\Companion
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-513785977-584283709-202011636-1000\Software\Yahoo\YFriendsBar
[#] Key deleted on reboot: HKU\S-1-5-18\Software\Yahoo\Companion
[#] Key deleted on reboot: HKCU\Software\DriverTuner
[#] Key deleted on reboot: HKCU\Software\DriverTuner_Init
[#] Key deleted on reboot: HKCU\Software\Yahoo\Companion
[#] Key deleted on reboot: HKCU\Software\Yahoo\YFriendsBar
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\adawarebp
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key deleted: HKLM\SOFTWARE\Yahoo\Companion
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! SearchSet
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4F524A2D-5350-4500-76A7-A758B70C1801}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{520C1D80-935C-42B9-9340-E883849D804F}_is1
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AE9B04F2-E9E8-162C-829B-52C116B3EFCC}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yahoo! SearchSet
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-513785977-584283709-202011636-1000\Software\BatBrowse
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-513785977-584283709-202011636-1000\Software\Yahoo\Companion
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-513785977-584283709-202011636-1000\Software\Yahoo\YFriendsBar
[#] Key deleted on reboot: [x64] HKCU\Software\DriverTuner
[#] Key deleted on reboot: [x64] HKCU\Software\DriverTuner_Init
[#] Key deleted on reboot: [x64] HKCU\Software\Yahoo\Companion
[#] Key deleted on reboot: [x64] HKCU\Software\Yahoo\YFriendsBar
[#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\Software\adawarebp
[#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\Software\Yahoo\Companion
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4F524A2D-5350-4500-76A7-A758B70C1801}
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{520C1D80-935C-42B9-9340-E883849D804F}_is1
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{AE9B04F2-E9E8-162C-829B-52C116B3EFCC}
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yahoo! SearchSet
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8036C72171EF4ba46856BF57969F6A36
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89BB7852687BDC34B9A81E01C7FF9173
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89EA4F1B8FBCDEF47AE328E455E28AA0
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CBC85D72B148084ABE8C2F072F781F4
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CC5A38A64D6098468BC8395BA0EFF03
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8DF9A1AC557F56c49B56F6B83E293C15
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97ECFF59EE08D4F47BB1464DEC37DA87
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8CB937199A57E748B6AC433DA453EE2
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A97C590397DCC454AA8923563BAB10E4
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B08932C78B697C244BE7BA3E6FF09B62
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4E78E12704AFCE408C7FBE501F1AA0A
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C6A54B56C58C82a4688AFB93F42EA17B
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CFA51B44D54927c4E9B7BC1D3FD1E49F
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D14A7F65792054F418578C78367D13F7
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DFE9F0BD163D827438CB6AD6B100EC48
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F0390A76D28822743A68D7F1AB22E6D0
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F739A19A8327dc64C9A8B641A9E89646
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0A5AC497E6BBC8D45BE8AD6619DA8217
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\158D6D9E3FE81fa428925F22ACB3A965
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15E6C514FEFC09f45BAFAAE1D7546ED4
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DB42320A8525634AA089F0BEC86473B
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22468B0D6050b2e46B9C4B67A8F59577
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2251BF05A2F606d43BB064BD63CBD87E
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3255D95681398614190EDF0A4F3F77DB
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3CDF313E9B28c944FBC7579CF4949414
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71E54748EDD3dc1468548785DC856EDA
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\754590DD06DE8d249B526503432F99D4
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\tlscdn.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\tlscdn.com
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search\ask.com
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{37AC0F3B-749F-3B22-811B-5A019EED2E85}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{66DF7821-ED6D-3534-893C-0E89E74B0F91}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{755CAFCC-F016-3B06-8F22-945EAA3AD10D}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{903F9872-E87F-3B74-83B0-DBE10073B29D}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{4392A6CC-7940-310E-8E16-799A8D93A438}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{05660A04-00F1-3A04-AB3B-BC1074B84D67}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{9558EEB4-CDA6-3778-B53B-98076F0A1E90}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{76552F88-640C-314D-82B6-0D8A740907F7}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{B25AA9BA-FD52-3E5E-BFE3-9B106779DA6E}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{C852CF9F-37DC-35AC-926A-7E6CFFF7C501}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{C9777796-4378-3C90-B52D-7238FFFC2A5C}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{DB1BC8B2-FDBF-30E7-BE1C-AFF9160059E6}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{F3D5729C-7DEB-3850-A026-D0E323ECFEF5}
[-] Key deleted: HKLM\SOFTWARE\Classes\Record\{FEC70973-CB8B-351C-8047-CAE1274CE249}
[-] Key deleted: HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.apn.native_messaging_host_aaaaaiabcopkplhgaedhbloeejhhankf
[-] Value deleted: HKLM\SOFTWARE\Classes\.torrent [iLivid.torrent_backup]
 
 
***** [ Web browsers ] *****
 
[-] [C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
[-] [C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: r
[-] [C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: dts.search.ask.com
[-] [C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: mysearchdial.com
[-] [C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: groovorio.com
[-] [C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [14062 Bytes] - [10/11/2016 22:21:53]
C:\AdwCleaner\AdwCleaner[R0].txt - [21488 Bytes] - [25/08/2014 22:08:19]
C:\AdwCleaner\AdwCleaner[R1].txt - [16674 Bytes] - [28/08/2014 22:16:54]
C:\AdwCleaner\AdwCleaner[R2].txt - [3238 Bytes] - [04/09/2014 21:11:16]
C:\AdwCleaner\AdwCleaner[R3].txt - [1339 Bytes] - [06/09/2014 21:40:06]
C:\AdwCleaner\AdwCleaner[R4].txt - [1725 Bytes] - [16/09/2014 17:17:28]
C:\AdwCleaner\AdwCleaner[R5].txt - [4345 Bytes] - [03/11/2016 18:06:59]
C:\AdwCleaner\AdwCleaner[S0].txt - [14523 Bytes] - [28/08/2014 22:21:13]
C:\AdwCleaner\AdwCleaner[S1].txt - [3125 Bytes] - [04/09/2014 21:14:41]
C:\AdwCleaner\AdwCleaner[S2].txt - [2890 Bytes] - [06/09/2014 22:09:37]
C:\AdwCleaner\AdwCleaner[S3].txt - [3280 Bytes] - [16/09/2014 17:24:45]
C:\AdwCleaner\AdwCleaner[S4].txt - [5891 Bytes] - [03/11/2016 18:09:39]
C:\AdwCleaner\AdwCleaner[S5].txt - [14249 Bytes] - [10/11/2016 22:21:05]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [15016 Bytes] ##########
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows (TM) Vista Home Premium x64 
Ran by [removed] (Administrator) on Thu 11/10/2016 at 23:19:24.45
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 22 
 
Successfully deleted: C:\ProgramData\ad-aware browsing protection (Folder) 
Successfully deleted: C:\ProgramData\b3ca538f2e11cdd8 (Folder) 
Successfully deleted: C:\Users\raypahl\AppData\Local\adawarebp (Folder) 
Successfully deleted: C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ccncljhbalbbkkfgopogabimepmfkmff (Folder) 
Successfully deleted: C:\Users\raypahl\AppData\Local\ysearchutil (Folder) 
Successfully deleted: C:\Program Files (x86)\coupons (Folder) 
Successfully deleted: C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\36UFTJM1 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62D5VBT8 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\67AQAA5B (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E7T21698 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HCXZ75HA (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IUUS6LG3 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U3CN2DKI (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W53QQLEG (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\36UFTJM1 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62D5VBT8 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\67AQAA5B (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E7T21698 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HCXZ75HA (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IUUS6LG3 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U3CN2DKI (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W53QQLEG (Temporary Internet Files Folder) 
 
 
 
Registry: 4 
 
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\Ad-Aware Browsing Protection (Registry Value) 
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B91DFF7-1E67-4A1E-99D4-F3A09B8459AD} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B91DFF7-1E67-4A1E-99D4-F3A09B8459AD} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{D623F6CA-49B6-4097-A62F-4D60C829D63D} (Registry Value) 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 11/10/2016 at 23:27:31.20
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

Good Morning

 

Losts of garbage removed. That error at start up is related to Windows Defender, do you still get that error on boot up ?

 

You have Malwarebytes installed, going to post the instructions to set it up properly, providing the link in case you need it again if not just bypass it

 

Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
 
  •  
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
 
 
[external image: MBAM221%201043_zpsdtasp5xe.jpg]
 
  •  
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
 

The only error messages I got were the ones I posted.

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 11/11/2016
Scan Time: 2:24:14 PM
Logfile: 
Administrator: Yes
 
Version: 2.2.1.1043
Malware Database: v2016.11.11.08
Rootkit Database: v2016.10.31.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows Vista Service Pack 2
CPU: x64
File System: NTFS
User: raypahl
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 342586
Time Elapsed: 1 hr, 50 min, 9 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

What I was asking is are you still getting that error message or was it a one time thing

 

 

How is your system behaving now, any better ?

I am still getting the error message "Host Process for Windows Services stopped working and was closed."

The others no, not anymoer.  Seems to be better with the exception of start up.  Takes probably a good 25 minutes to get started.

Lets take a look at whats starting up

 

On your keyboard press Ctrl.   Alt. Del , this should open Task Manager, when it opens click on the Startup tab on the top, when that opens click the box to expand it to make it full screen , then take a snapshot of it and paste it back in this thread

      I didn't see a "Start Up" menu on the task manager, so I copied the processes and services tabs.  When I tried to paste it, I only got an empty box, so I did use Hijack This as you suggested, here it is.

 

StartupList report, 11/13/2016, 7:18:41 PM
StartupList version: 1.52.2
Started from : C:\Users\raypahl\Desktop\HijackThis.EXE
Detected: Windows Vista SP2 (WinNT 6.00.1906)
Detected: Internet Explorer v9.00 (9.00.8112.16830)
* Using default options
==================================================
 
Running processes:
 
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\CBS Interactive\Download App\CBSI.AppStore.Scanner.exe
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\raypahl\Desktop\HijackThis.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
————————————————–
 
Listing of startup folders:
 
Shell folders Startup:
[C:\Users\raypahl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
Download App.lnk = ?
 
Shell folders Common Startup:
[C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe
 
————————————————–
 
Checking Windows NT UserInit:
 
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = userinit.exe,
 
————————————————–
 
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
 
DVDAgent = "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
TVAgent = "C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe"
UpdateLBPShortCut = "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
UpdatePSTShortCut = "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
QlbCtrl.exe = "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
UpdateP2GoShortCut = "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
UpdatePDIRShortCut = "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
HP Health Check Scheduler = c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
WirelessAssistant = C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
TSMAgent = "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
CLMLServer for HP TouchSmart = "C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
UCam_Menu = "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
HP Software Update = C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
APSDaemon = "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
AvastUI.exe = "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
Adobe ARM = "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
SunJavaUpdateSched = "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
 
————————————————–
 
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
 
LightScribe Control Panel = C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
cdloader = "C:\Users\raypahl\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK
ehTray.exe = C:\Windows\ehome\ehTray.exe
GoogleDriveSync = "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
EADM = "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
736701A46C7D59E46F8F7D9F95111119F406C6DA._service_run = "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" –type=service
 
————————————————–
 
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command
 
(Default) = C:\Windows\SysWOW64\mshta.exe "%1" %*
 
————————————————–
 
Shell & screensaver key from C:\Windows\SYSTEM.INI:
 
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
 
Shell & screensaver key from Registry:
 
Shell=explorer.exe
SCRNSAVE.EXE=C:\Windows\system32\ssText3d.scr
drivers=*Registry value not found*
 
Policies Shell key:
 
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
 
————————————————–
 
 
Enumerating Browser Helper Objects:
 
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll - {0347C33E-8762-4905-BF09-768834316C61}
Norton Vulnerability Protection - C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\IPS\IPSBHO.DLL (file missing) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C}
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
(no name) - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
(no name) - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll - {9FDDE16B-836F-4806-AB1F-1455CBEFF289}
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}
 
————————————————–
 
Enumerating Task Scheduler jobs:
 
Adobe Flash Player Updater.job
GoogleUpdateTaskMachineCore.job
GoogleUpdateTaskMachineCore1d15e36ffe9eaa0.job
GoogleUpdateTaskMachineUA.job
HPCeeScheduleForraypahl.job
 
————————————————–
 
Enumerating Download Program Files:
 
[Yahoo! Webcam Upload Wrapper]
InProcServer32 = C:\Windows\Downloaded Program Files\yuplapp.dll
CODEBASE = http://chat.yahoo.com/cab/yuplapp.cab
 
————————————————–
 
Enumerating Winsock LSP files:
 
NameSpace #1: C:\Windows\system32\NLAapi.dll
NameSpace #2: C:\Windows\system32\napinsp.dll
NameSpace #3: C:\Windows\system32\pnrpnsp.dll
NameSpace #4: C:\Windows\system32\pnrpnsp.dll
NameSpace #5: C:\Windows\system32\wshbth.dll
NameSpace #8: C:\Program Files (x86)\Bonjour\mdnsNSP.dll
 
————————————————–
 
Enumerating ShellServiceObjectDelayLoad items:
 
WebCheck: C:\Windows\SysWOW64\webcheck.dll
 
————————————————–
End of report, 8,996 bytes
Report generated in 0.156 seconds
 
Command line options:
   /verbose  - to add additional info on each section
   /complete - to include empty sections and unsuspicious data
   /full     - to include several rarely-important sections
   /force9x  - to include Win9x-only startups even if running on WinNT
   /forcent  - to include WinNT-only startups even if running on Win9x
   /forceall - to include all Win9x and WinNT startups, regardless of platform
   /history  - to list version history only

Most of your start up is related to HP , you also have Origin starting up which is related to gaming which can be taking up a lot of system resources. . I am not looking at any malware of viruses that are in your start up folder.

 

Open up FRST64 by right cllicking on the icon and select RUN AS ADMINISTRATOR, make sure Additions is checked , leave everything else as is. Click on Scan and post both new logs please

Well, there's not a whole bunch of game playing going on, so I can uninstall Origins?  

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-11-2016
Ran by [removed] (administrator) on STEARNS-PC (14-11-2016 09:55:28)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\stacsv64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\AESTSr64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
() C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
() C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe
(CBS Interactive Inc.) C:\Program Files (x86)\CBS Interactive\Download App\CBSI.AppStore.Scanner.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqgpc01.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Interactive Brands Malta Limited) C:\Program Files (x86)\PDF Suite 2015\creator-ws.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\…\Run: [SmartMenu] => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [915000 2009-01-08] (Hewlett-Packard)
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-20] (Microsoft Corporation)
HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [463360 2009-01-28] (IDT, Inc.)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169744 2015-09-12] (Apple Inc.)
HKLM-x32\…\Run: [DVDAgent] => C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe [1148200 2008-11-28] (CyberLink Corp.)
HKLM-x32\…\Run: [TVAgent] => C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe [202024 2009-05-11] (CyberLink Corp.)
HKLM-x32\…\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.)
HKLM-x32\…\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-01-13] (CyberLink Corp.)
HKLM-x32\…\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [323640 2010-02-25] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\…\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-04] (CyberLink Corp.)
HKLM-x32\…\Run: [UpdatePDIRShortCut] => C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [218408 2008-12-04] (CyberLink Corp.)
HKLM-x32\…\Run: [HP Health Check Scheduler] => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-10-09] (Hewlett-Packard)
HKLM-x32\…\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [484408 2009-01-23] (Hewlett-Packard)
HKLM-x32\…\Run: [TSMAgent] => C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe [1328424 2009-04-29] (CyberLink Corp.)
HKLM-x32\…\Run: [CLMLServer for HP TouchSmart] => C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [185640 2009-04-29] (CyberLink)
HKLM-x32\…\Run: [UCam_Menu] => C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9044392 2016-11-09] (AVAST Software)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2008-06-09] (Hewlett-Packard Company)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [cdloader] => C:\Users\raypahl\AppData\Roaming\mjusbsp\cdloader2.exe [50520 2009-08-01] (magicJack L.P.)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818712 2016-10-12] (Google)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-11-11] (Electronic Arts)
HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Run: [736701A46C7D59E46F8F7D9F95111119F406C6DA._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [874648 2016-04-06] (Google Inc.)
HKU\S-1-5-21-513785977-584283709-202011636-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [334336 2008-01-20] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-10-12] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-10-12] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-10-12] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-29] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2014-04-30]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\raypahl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Download App.lnk [2015-02-15]
ShortcutTarget: Download App.lnk -> C:\Program Files (x86)\CBS Interactive\Download App\CBSI.AppStore.Scanner.exe (CBS Interactive Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{801647DA-8FFF-4244-BC31-E0870B9F67FE}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{94FA59CE-8C9A-4984-B67B-149BBF13BD4C}: [NameServer] 8.8.8.8,208.67.222.222,8.8.4.4,208.67.220.220
Tcpip\..\Interfaces\{94FA59CE-8C9A-4984-B67B-149BBF13BD4C}: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID;=130892846893110000&GUID;=764FC242-5591-4ABF-9B6A-E9976335B01D
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
HKU\S-1-5-21-513785977-584283709-202011636-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {7EEAD0DA-121E-498E-B773-B8F0B4C4AAB1} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=HPNTDF&pc;=HPNTDF&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {94A0FAC8-4922-45B9-B85C-DE11B41E351F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSERBM&pc;=MSERT1
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {A9E5F592-BF1B-41BF-AFF4-9CAC82733B93} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_ie_syc_oracle&type;=orcl_default
SearchScopes: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q;={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\IPS\IPSBHO.DLL => No File
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-22] (Microsoft Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)
Toolbar: HKU\S-1-5-21-513785977-584283709-202011636-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
DPF: HKLM-x32 {8714912E-380D-11D5-B8AA-00D0B78F3D48} hxxp://chat.yahoo.com/cab/yuplapp.cab
 
FireFox:
========
FF HKLM\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.2.15\coFFAddon => not found
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-29]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-08-29]
FF HKLM-x32\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-22] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-04-30] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\PDF Suite 2015\resources\pdfsuite2015firefoxextension
FF Extension: (PDF Suite 2015) - C:\Program Files (x86)\PDF Suite 2015\resources\pdfsuite2015firefoxextension [2016-02-20] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_207.dll [2016-11-09] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_207.dll [2016-11-09] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-14] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2012-04-11] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin-x32: PDF Suite 2015 -> C:\Program Files (x86)\PDF Suite 2015\np-previewer.dll [2015-01-23] (Interactive Brands Malta Limited)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR StartupUrls: Default -> "hxxps://www.facebook.com/","hxxps://www.google.com/"
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_chr_syc_oracle&type;=default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command;={searchTerms}&nResults;=10
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.112\pdf.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (TelevisionFanatic Installer Plugin Stub) - C:\Program Files (x86)\TelevisionFanaticEI\Installr\1.bin\NP64EISB.dll => No File
CHR Plugin: (Windows LiveÃÂÃÂÃÂÃÂ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll => No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default [2016-11-14]
CHR Extension: (Google Drive) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-10]
CHR Extension: (Google Docs Offline) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-10]
CHR Extension: (Avast Online Security) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-11-10]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2016-11-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-10]
CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security Suite\Engine\22.8.0.50\Exts\Chrome.crx
CHR HKLM\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\Exts\Chrome.crx
CHR HKU\S-1-5-21-513785977-584283709-202011636-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\raypahl\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-12-22]
CHR HKU\S-1-5-21-513785977-584283709-202011636-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gihfmmedoddijgnhkgfgnkeohkpbipol] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\AESTSr64.exe [88576 2008-11-17] (Andrea Electronics Corporation)
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-29] (AVAST Software)
R2 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1037824 2009-09-08] (Hewlett-Packard Co.) [File not signed]
S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
S3 Interactive Brands CrashHandler; C:\Program Files (x86)\PDF Suite 2015\crash-handler-ws.exe [745800 2015-01-23] (Interactive Brands Malta Limited)
S2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2008-06-09] (Hewlett-Packard Company) [File not signed]
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-11] (Electronic Arts)
S3 PDF Suite 2015; C:\Program Files (x86)\PDF Suite 2015\ws.exe [1676104 2015-01-23] (Interactive Brands Malta Limited)
R2 PDF Suite 2015 Creator; C:\Program Files (x86)\PDF Suite 2015\creator-ws.exe [622920 2015-01-23] (Interactive Brands Malta Limited)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S2 Recovery Service for Windows; C:\Program Files (x86)\SMINST\BLService.exe [365952 2008-12-23] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2008-11-25] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_7477fb4c\STacSV64.exe [290304 2009-01-28] (IDT, Inc.)
R2 TVCapSvc; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [296320 2008-11-26] ()
R2 TVSched; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [116096 2008-11-26] ()
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-20] (Microsoft Corporation)
S3 WsAppService; C:\Program Files (x86)\Wondershare\WAF\WsAppService.exe [252816 2015-04-30] (Wondershare)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 Amfilter; C:\Windows\System32\DRIVERS\Amfltx64.sys [12288 2007-10-15] ((Standard mouse types))
S3 Amusbprt; C:\Windows\System32\DRIVERS\Amusbx64.sys [17920 2008-02-13] (A4Tech Co.,Ltd.)
S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [78640 2016-06-21] (AVAST Software)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-29] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-29] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-29] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [74032 2016-08-29] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-29] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-22] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [224616 2016-08-29] (AVAST Software)
S3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [74544 2016-08-29] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)
R2 SADP_NPF; C:\Windows\SysWOW64\drivers\sadp_npf64.sys [35344 2012-07-02] (CACE Technologies, Inc.)
S3 ssmirrdr; C:\Windows\System32\DRIVERS\ssmirrdr.sys [10112 2016-02-09] (support.com, Inc)
R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [146928 2008-11-28] (CyberLink Corp.)
S1 AntiLog32; \??\C:\Windows\system32\drivers\AntiLog64.sys [X]
U4 eabfiltr; no ImagePath
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 keycrypt; system32\DRIVERS\KeyCrypt64.sys [X]
S3 NAVENG; \??\C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\SDSDefs\20160808.001\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security Suite\NortonData\22.5.2.15\Definitions\SDSDefs\20160808.001\EX64.SYS [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-11-13 19:18 - 2016-11-13 19:18 - 00008826 _____ C:\Users\raypahl\Desktop\startuplist.txt
2016-11-10 23:27 - 2016-11-10 23:44 - 00004325 _____ C:\Users\raypahl\Desktop\JRT.txt
2016-11-10 23:14 - 2016-11-10 23:15 - 01631928 _____ (Malwarebytes) C:\Users\raypahl\Desktop\JRT.exe
2016-11-10 23:10 - 2016-11-10 23:10 - 00015276 _____ C:\Users\raypahl\Desktop\AdwCleaner[C0].txt
2016-11-10 22:15 - 2016-11-10 22:15 - 03910208 _____ C:\Users\raypahl\Desktop\AdwCleaner.exe
2016-11-10 19:59 - 2016-11-14 09:55 - 00000000 ____D C:\Users\raypahl\Desktop\FRST-OlderVersion
2016-11-10 19:59 - 2016-11-10 20:57 - 00004002 _____ C:\Users\raypahl\Desktop\Fixlog.txt
2016-11-10 16:29 - 2016-11-10 16:30 - 00282256 _____ C:\Windows\Minidump\Mini111016-01.dmp
2016-11-04 12:14 - 2016-11-04 12:14 - 00000000 ____D C:\Users\raypahl\Downloads\New Folder
2016-11-04 11:41 - 2016-11-04 11:52 - 00061849 _____ C:\Users\raypahl\Desktop\Addition.txt
2016-11-04 11:38 - 2016-11-04 12:04 - 00000512 _____ C:\Users\raypahl\Documents\MBR.dat
2016-11-04 11:33 - 2016-11-14 09:57 - 00029407 _____ C:\Users\raypahl\Desktop\FRST.txt
2016-11-04 11:31 - 2016-11-14 09:55 - 02411520 _____ (Farbar) C:\Users\raypahl\Desktop\FRST64.exe
2016-11-03 17:57 - 2016-11-03 17:57 - 00000000 ____D C:\ProgramData\EA Logs
2016-10-24 20:36 - 2016-10-24 20:36 - 00002052 _____ C:\Users\Public\Desktop\NTI Digital Jack.lnk
2016-10-24 20:36 - 2016-10-24 20:36 - 00001930 _____ C:\Users\Public\Desktop\NTI Ripper.lnk
2016-10-24 20:36 - 2016-10-24 20:36 - 00000941 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI DigitalJack.lnk
2016-10-24 20:36 - 2016-10-24 20:36 - 00000839 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Ripper.lnk
2016-10-24 20:35 - 2016-10-24 20:35 - 00001024 ___RH C:\Windows\SysWOW64\NTIRIPPER.dll
2016-10-24 20:34 - 2016-11-03 18:08 - 00000584 _____ C:\Users\raypahl\Shadow.xml
2016-10-24 20:32 - 2016-10-24 20:32 - 00000036 __RSH C:\.uid_xxx
2016-10-24 20:28 - 2016-10-24 20:28 - 00001960 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Shadow.lnk
2016-10-24 20:28 - 2016-10-24 20:28 - 00000841 _____ C:\Users\Public\Desktop\NTI Shadow.lnk
2016-10-24 20:28 - 2000-08-02 19:50 - 01056768 _____ (eHelp Corporation.) C:\Windows\SysWOW64\roboex32.dll
2016-10-24 20:26 - 2016-10-24 20:36 - 00000000 ____D C:\Program Files (x86)\NewTech Infosystems
2016-10-24 14:40 - 2016-10-24 14:40 - 00282144 _____ C:\Windows\Minidump\Mini102416-02.dmp
2016-10-24 12:01 - 2016-10-24 12:07 - 00282256 _____ C:\Windows\Minidump\Mini102416-01.dmp
2016-10-21 10:36 - 2016-09-29 22:09 - 17975808 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-10-21 10:36 - 2016-09-29 22:07 - 10891264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-10-21 10:36 - 2016-09-29 22:07 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-10-21 10:36 - 2016-09-29 22:06 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-10-21 10:36 - 2016-09-29 22:05 - 02129920 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-10-21 10:36 - 2016-09-29 22:05 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 01296384 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 00887296 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 00528896 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 00234496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-10-21 10:36 - 2016-09-29 22:05 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2016-10-21 10:36 - 2016-09-29 22:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2016-10-21 10:36 - 2016-09-29 22:05 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2016-10-21 10:36 - 2016-09-29 21:39 - 12859392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-10-21 10:36 - 2016-09-29 21:39 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-10-21 10:36 - 2016-09-29 21:37 - 09731584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-10-21 10:36 - 2016-09-29 21:36 - 01831424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-10-21 10:36 - 2016-09-29 21:36 - 01436160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-10-21 10:36 - 2016-09-29 21:36 - 01095168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-10-21 10:36 - 2016-09-29 21:36 - 01089024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-10-21 10:36 - 2016-09-29 21:36 - 00711168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-10-21 10:36 - 2016-09-29 21:36 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2016-10-21 10:36 - 2016-09-29 21:36 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-10-21 10:36 - 2016-09-29 21:36 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-10-21 10:36 - 2016-09-29 21:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-10-21 10:36 - 2016-09-29 21:35 - 01789952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-10-21 10:36 - 2016-09-29 21:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-10-21 10:36 - 2016-09-29 21:35 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-10-21 10:36 - 2016-09-29 21:35 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-10-21 10:36 - 2016-09-29 21:35 - 00217088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-10-21 10:36 - 2016-09-29 21:35 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-10-21 10:36 - 2016-09-29 21:35 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-10-21 10:36 - 2016-09-29 21:35 - 00042496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2016-10-21 10:36 - 2016-09-29 21:35 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2016-10-21 10:36 - 2016-09-29 21:35 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2016-10-21 03:18 - 2016-09-30 10:17 - 04693224 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-10-21 02:21 - 2016-09-10 10:30 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-10-21 02:20 - 2016-09-10 10:45 - 01690624 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-10-21 02:20 - 2016-09-10 10:44 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll
2016-10-21 02:20 - 2016-09-10 10:27 - 00075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2016-10-21 02:03 - 2016-09-10 09:24 - 02803712 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-10-21 02:03 - 2016-09-09 09:34 - 01268224 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2016-10-21 02:03 - 2016-09-09 09:34 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2016-10-21 02:03 - 2016-09-09 09:34 - 00287232 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2016-10-21 02:03 - 2016-09-09 09:34 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2016-10-21 02:03 - 2016-09-09 09:15 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2016-10-21 02:03 - 2016-09-09 09:15 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2016-10-21 02:03 - 2016-09-09 09:15 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2016-10-21 02:03 - 2016-09-09 09:15 - 00160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2016-10-21 02:03 - 2016-09-09 08:57 - 02002944 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2016-10-21 02:03 - 2016-09-09 08:56 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2016-10-21 02:03 - 2016-09-09 08:44 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2016-10-21 02:03 - 2016-09-09 08:43 - 01561600 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2016-10-21 02:03 - 2016-09-09 08:42 - 01154560 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2016-10-21 02:03 - 2016-09-09 08:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2016-10-21 02:03 - 2016-09-09 08:32 - 00486912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2016-10-21 02:03 - 2016-09-09 08:23 - 00682496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2016-10-21 02:03 - 2016-09-09 08:21 - 01073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2016-10-21 02:02 - 2016-09-08 08:39 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-10-21 02:02 - 2016-09-08 08:39 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2016-10-21 02:02 - 2016-09-03 10:08 - 02528768 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2016-10-21 02:02 - 2016-09-03 09:50 - 01544704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2016-10-21 02:01 - 2016-09-14 19:41 - 00975872 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-10-21 02:01 - 2016-09-14 19:29 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2016-10-21 02:01 - 2016-09-14 18:23 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2016-10-21 02:01 - 2016-09-14 18:01 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-11-14 09:55 - 2014-09-03 11:51 - 00000000 ____D C:\FRST
2016-11-14 08:34 - 2014-05-03 11:39 - 00000000 ____D C:\Users\raypahl\AppData\LocalLow\HPAppData
2016-11-13 18:53 - 2009-07-21 12:32 - 00015747 _____ C:\ProgramData\HPWALog.txt
2016-11-13 18:50 - 2012-08-15 04:37 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-11-13 18:49 - 2012-08-15 04:37 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-11-13 18:46 - 2012-09-03 17:33 - 00151552 _____ C:\Users\raypahl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-11-13 18:42 - 2012-03-30 22:57 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-11-12 20:56 - 2016-02-02 21:57 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0.job
2016-11-11 21:50 - 2015-03-26 14:55 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-11-11 21:33 - 2006-11-02 09:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-11-11 20:43 - 2006-11-02 09:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2016-11-11 20:43 - 2006-11-02 09:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2016-11-11 20:08 - 2009-03-05 23:13 - 00000012 _____ C:\Windows\bthservsdp.dat
2016-11-11 20:08 - 2006-11-02 09:42 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-11-11 16:00 - 2016-07-13 02:17 - 00000000 _____ C:\Windows\SysWOW64\last.dump
2016-11-11 14:22 - 2014-08-25 15:46 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-11-11 12:47 - 2006-11-02 07:33 - 00000000 ____D C:\Windows\inf
2016-11-11 12:47 - 2006-11-02 06:46 - 00763734 _____ C:\Windows\system32\PerfStringBackup.INI
2016-11-11 12:38 - 2009-07-21 12:29 - 00081016 _____ C:\Users\raypahl\AppData\Local\GDIPFONTCACHEV1.DAT
2016-11-11 12:26 - 2006-11-02 09:21 - 00329512 _____ C:\Windows\system32\FNTCACHE.DAT
2016-11-10 22:21 - 2014-08-25 22:08 - 00000000 ____D C:\AdwCleaner
2016-11-10 16:56 - 2009-03-06 01:08 - 00003584 _____ C:\Windows\System32\Tasks\HP Health Check
2016-11-10 16:29 - 2011-10-12 13:02 - 00000000 ____D C:\Windows\Minidump
2016-11-10 16:28 - 2014-10-28 03:11 - 564954891 _____ C:\Windows\MEMORY.DMP
2016-11-10 15:50 - 2011-10-30 09:04 - 00000000 ____D C:\Users\raypahl\AppData\Roaming\HpUpdate
2016-11-09 14:42 - 2012-03-30 22:58 - 00003682 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-11-09 14:42 - 2012-03-30 22:57 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-11-09 14:42 - 2011-12-07 20:31 - 00000000 ____D C:\Windows\system32\Macromed
2016-11-09 14:42 - 2011-09-30 17:29 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-11-09 14:42 - 2009-03-06 00:12 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-11-04 16:52 - 2013-12-22 21:18 - 00000000 ___RD C:\Users\raypahl\Google Drive
2016-11-04 16:51 - 2013-12-22 20:32 - 00001865 _____ C:\Users\Public\Desktop\Google Slides.lnk
2016-11-04 16:51 - 2013-12-22 20:32 - 00001863 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2016-11-04 16:51 - 2013-12-22 20:32 - 00001853 _____ C:\Users\Public\Desktop\Google Docs.lnk
2016-11-04 16:51 - 2013-12-22 20:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-11-04 12:07 - 2013-08-24 13:09 - 00000000 ____D C:\Users\raypahl\Documents\deb
2016-11-04 12:04 - 2015-03-26 14:47 - 00004561 _____ C:\Users\raypahl\Documents\aswMBR.txt
2016-11-04 10:13 - 2011-10-05 05:39 - 00000000 ____D C:\Users\raypahl\AppData\Local\CrashDumps
2016-11-03 18:10 - 2006-11-02 07:33 - 00000000 ____D C:\Windows\Resources
2016-11-03 18:03 - 2012-07-05 01:08 - 00006756 _____ C:\Users\raypahl\AppData\Local\d3d9caps.dat
2016-11-03 18:03 - 2009-03-05 23:47 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-11-03 18:02 - 2014-03-17 10:47 - 00000000 ____D C:\Users\raypahl\Documents\Electronic Arts
2016-11-03 18:02 - 2014-03-16 10:43 - 00000000 ____D C:\Program Files (x86)\Origin Games
2016-11-03 17:55 - 2016-08-18 20:11 - 00000000 ____D C:\Program Files (x86)\SwannView Link
2016-11-03 15:35 - 2016-04-06 18:42 - 00468790 _____ C:\Windows\ntbtlog.txt
2016-11-03 15:13 - 2014-08-25 15:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-11-03 15:13 - 2014-08-25 15:45 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-10-29 20:57 - 2009-07-21 12:21 - 00000000 ____D C:\Users\raypahl
2016-10-29 20:57 - 2006-11-02 07:34 - 00000000 ____D C:\Windows\system32\spool
2016-10-29 20:57 - 2006-11-02 07:33 - 00000000 ____D C:\Windows\registration
2016-10-29 20:57 - 2006-11-02 06:33 - 91226112 _____ C:\Windows\system32\config\software_previous
2016-10-29 20:57 - 2006-11-02 06:33 - 36438016 _____ C:\Windows\system32\config\system_previous
2016-10-29 20:51 - 2006-11-02 06:33 - 00262144 _____ C:\Windows\system32\config\security_previous
2016-10-29 20:51 - 2006-11-02 06:33 - 00262144 _____ C:\Windows\system32\config\sam_previous
2016-10-29 10:59 - 2006-11-02 06:33 - 00524288 _____ C:\Windows\system32\config\default_previous
2016-10-29 10:49 - 2006-11-02 06:33 - 69992448 _____ C:\Windows\system32\config\components_previous
2016-10-25 12:51 - 2011-10-07 06:07 - 00000000 ____D C:\Program Files (x86)\NortonInstaller
2016-10-25 12:51 - 2009-03-05 23:49 - 00000000 ____D C:\ProgramData\Norton
2016-10-24 17:29 - 2006-11-02 07:33 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-10-24 16:38 - 2006-11-02 07:33 - 00000000 ____D C:\Windows\rescache
2016-10-24 15:32 - 2014-04-30 16:50 - 00001795 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2016-10-24 15:29 - 2014-08-07 12:48 - 00000000 ____D C:\Users\raypahl\Documents\My Scans
2016-10-21 14:53 - 2013-08-13 07:08 - 00000000 ____D C:\ProgramData\HP
2016-10-21 03:38 - 2009-03-06 00:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-10-21 03:37 - 2006-11-02 09:07 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer
2016-10-21 03:04 - 2014-02-25 08:26 - 00757538 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-10-21 02:20 - 2013-08-14 02:11 - 00000000 ____D C:\Windows\system32\MRT
2016-10-21 02:06 - 2006-11-02 06:35 - 143495576 ____C (Microsoft Corporation) C:\Windows\system32\mrt.exe
2016-10-21 02:05 - 2010-12-20 07:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-10-20 14:15 - 2016-09-23 05:44 - 00000000 ____D C:\Windows\System32\Tasks\Remediation
 
==================== Files in the root of some directories =======
 
2013-10-13 20:44 - 2013-10-13 20:44 - 2174976 _____ (Advanced Micro Devices Inc.) C:\Program Files (x86)\Common Files\atimpenc.dll
2014-03-18 16:00 - 2014-04-04 02:00 - 0000082 _____ () C:\Users\raypahl\AppData\Roaming\WB.CFG
2015-12-03 20:41 - 2016-04-01 23:12 - 0000994 _____ () C:\Users\raypahl\AppData\Roaming\wklnhst.dat
2009-07-21 12:32 - 2009-07-21 12:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\AtStart.txt
2012-07-05 01:08 - 2016-11-03 18:03 - 0006756 _____ () C:\Users\raypahl\AppData\Local\d3d9caps.dat
2016-08-22 14:02 - 2016-08-22 14:12 - 0000732 _____ () C:\Users\raypahl\AppData\Local\d3d9caps64.dat
2012-09-03 17:33 - 2016-11-13 18:46 - 0151552 _____ () C:\Users\raypahl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-11 04:47 - 2013-12-11 04:49 - 0004170 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI0287.txt
2013-12-11 05:05 - 2013-12-11 05:05 - 0354328 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI0FE9.txt
2011-09-30 23:07 - 2011-09-30 23:08 - 0460566 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI3785.txt
2016-08-22 16:25 - 2016-08-22 16:25 - 0389670 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI3940.txt
2014-01-11 18:16 - 2014-01-11 18:18 - 0444592 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI6339.txt
2016-02-20 04:30 - 2016-02-20 04:31 - 0001848 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI6DAF.txt
2016-02-20 04:50 - 2016-02-20 04:51 - 0405314 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistMSI7CE3.txt
2013-12-11 04:47 - 2013-12-11 04:48 - 0012516 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI0287.txt
2013-12-11 05:05 - 2013-12-11 05:05 - 0015670 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI0FE9.txt
2011-09-30 23:07 - 2011-09-30 23:08 - 0014878 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI3785.txt
2016-08-22 16:25 - 2016-08-22 16:25 - 0011478 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI3940.txt
2014-01-11 18:16 - 2014-01-11 18:18 - 0043456 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI6339.txt
2016-02-20 04:30 - 2016-02-20 04:31 - 0026324 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI6DAF.txt
2016-02-20 04:50 - 2016-02-20 04:51 - 0013546 _____ () C:\Users\raypahl\AppData\Local\dd_vcredistUI7CE3.txt
2009-07-21 12:32 - 2009-07-21 12:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\DSwitch.txt
2011-09-30 18:28 - 2016-04-06 18:16 - 0000000 _____ () C:\Users\raypahl\AppData\Local\FnF4.txt
2009-07-21 12:32 - 2009-07-21 12:32 - 0000000 _____ () C:\Users\raypahl\AppData\Local\QSwitch.txt
2011-05-27 21:02 - 2011-09-30 23:34 - 0001940 _____ () C:\Users\raypahl\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
2009-07-21 12:32 - 2016-11-13 18:53 - 0015747 _____ () C:\ProgramData\HPWALog.txt
2013-08-13 07:08 - 2014-04-30 20:37 - 0003705 _____ () C:\ProgramData\hpzinstall.log
2014-05-27 13:19 - 2016-04-18 19:53 - 0000614 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2009-06-13 22:40 - 2009-06-13 22:40 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2009-03-06 00:55 - 2009-03-06 00:55 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2009-06-13 22:39 - 2009-06-13 22:39 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2009-03-06 00:48 - 2009-03-06 00:50 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2009-06-13 22:38 - 2009-06-13 22:38 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2009-06-13 22:39 - 2009-06-13 22:39 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2009-03-06 00:47 - 2009-03-06 00:48 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2009-03-06 00:50 - 2009-03-06 00:55 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2009-06-13 22:39 - 2009-06-13 22:39 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
 
Some files in TEMP:
====================
C:\Users\raypahl\AppData\Local\Temp\libeay32.dll
C:\Users\raypahl\AppData\Local\Temp\msvcr120.dll
C:\Users\raypahl\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-11-12 09:55
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-11-2016
Ran by [removed] (14-11-2016 10:01:30)
Running from C:\Users\[removed]\Desktop
Windows Vista (TM) Home Premium Service Pack 2 (X64) (2009-06-14 03:35:45)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-513785977-584283709-202011636-500 - Administrator - Disabled)
Guest (S-1-5-21-513785977-584283709-202011636-501 - Limited - Disabled)
raypahl (S-1-5-21-513785977-584283709-202011636-1000 - Administrator - Enabled) => C:\Users\raypahl
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
4500_G510gm_Help (x32 Version: 000.0.440.000 - Hewlett-Packard) Hidden
4500G510gm (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden
4500G510gm_Software_Min (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Acrobat.com (HKLM-x32\…\{77DCDCE3-2DED-62F3-8154-05E745472D07}) (Version: 1.1.377 - Adobe Systems Incorporated)
Activation Assistant for the 2007 Microsoft Office suites (HKLM-x32\…\Activation Assistant for the 2007 Microsoft Office suites) (Version:  - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0 - Microsoft Corporation) Hidden
ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.2 - Hewlett-Packard) Hidden
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 23.0.0.257 - Adobe Systems Incorporated)
Adobe Flash Player 23 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 23.0.0.207 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.207 - Adobe Systems Incorporated)
Adobe Reader X (10.1.16) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Amazon Kindle (HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Amazon Kindle) (Version:  - Amazon)
Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Atheros Driver Installation Program (HKLM-x32\…\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 5.2 - Atheros)
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)
BCL easyConverter Desktop 3 (Word Version) (HKLM-x32\…\{8C5845B5-729F-40E3-A945-4454E67F65F4}) (Version: 3.0.18 - BCL Technologies)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 4.17 - Piriform)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CyberLink DVD Suite (HKLM-x32\…\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.2512 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden
DocMgr (x32 Version: 130.0.000.000 - Hewlett-Packard) Hidden
DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Download App (HKU\S-1-5-21-513785977-584283709-202011636-1000\…\Download App) (Version: 1.8.0 - CBS Interactive)
ENE CIR Receiver Driver (12/30/2008 2.7.2.0) (HKLM\…\703AB19C282B6ED3F1D3CE92F8DAA864B68A7C91) (Version: 12/30/2008 2.7.2.0 - ENE)
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
ESU for Microsoft Vista (HKLM-x32\…\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)
Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Drive (HKLM-x32\…\{3D7AB4D4-2E45-4986-BAC5-5B3CEED21FAA}) (Version: 1.32.3592.6117 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HP Active Support Library (HKLM-x32\…\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}) (Version: 3.1.9.1 - Hewlett-Packard)
HP Customer Experience Enhancements (HKLM-x32\…\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}) (Version: 5.7.0.2664 - Hewlett-Packard)
HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Document Manager 2.0 (HKLM\…\HP Document Manager) (Version: 2.0 - HP)
HP Help and Support (HKLM-x32\…\{0054A0F6-00C9-4498-B821-B5C9578F433E}) (Version: 2.1.3.0 - Hewlett-Packard Company)
HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP)
HP MediaSmart DVD (HKLM-x32\…\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 2.1.2328 - Hewlett-Packard)
HP MediaSmart Music/Photo/Video (HKLM-x32\…\InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}) (Version: 2.2.2829 - Hewlett-Packard)
HP MediaSmart SlingPlayer (HKLM-x32\…\HP.MediaSmartSlingPlayer_is1) (Version: 2.1 - Sling Media, Inc.)
HP MediaSmart SmartMenu (HKLM\…\{0BC595C4-F736-4EB4-A1C0-32C7E81800F0}) (Version: 2.1.10 - Hewlett-Packard)
HP MediaSmart TV (HKLM-x32\…\InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}) (Version: 2.1.1709 - Hewlett-Packard)
HP MediaSmart Webcam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.2.1621 - Hewlett-Packard)
HP Officejet 4500 G510g-m (HKLM\…\{E5083D57-D93F-404C-A91F-1C50D67C2BEB}) (Version: 13.0 - HP)
HP Quick Launch Buttons (HKLM-x32\…\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.17.1 - Hewlett-Packard Company)
HP Smart Web Printing 4.5 (HKLM\…\HP Smart Web Printing) (Version: 4.5 - HP)
HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Support Solutions Framework (HKLM-x32\…\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company)
HP Total Care Advisor (HKLM-x32\…\{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}) (Version: 2.4.5991.2847 - Hewlett-Packard)
HP Total Care Setup (HKLM-x32\…\{95A747E0-DF19-46CB-A622-20A0107201BD}) (Version: 1.1.2413.2876 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP User Guides 0135 (HKLM-x32\…\{372ED957-0FB5-487B-B51A-388B3D393F7A}) (Version: 1.01.0000 - Hewlett-Packard)
HP Wireless Assistant (HKLM-x32\…\{462DED50-EC2E-4237-ABCF-B5C463C0EE51}) (Version: 3.50.3.1 - Hewlett-Packard)
HPAsset component for HP Active Support Library (x32 Version: 3.0.2.2 - Hewlett-Packard) Hidden
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6146.0 - IDT)
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version:  - Intel Corporation)
iTunes (HKLM\…\{CEC7613B-E286-4A31-BEE3-3F7798488D9F}) (Version: 12.1.3.6 - Apple Inc.)
Java 8 Update 60 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1312 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.1312 - CyberLink Corp.) Hidden
LightScribe System Software  1.14.17.1 (HKLM-x32\…\{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}) (Version: 1.14.17.1 - LightScribe)
Logitech Unifying Software 2.10 (HKLM\…\Logitech Unifying) (Version: 2.10.37 - Logitech)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\…\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Standard Edition 2003 (HKLM-x32\…\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\…\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\…\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\…\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\…\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
muvee Reveal (HKLM-x32\…\{DE626616-D7C4-4F00-7E0B-EAF26FA65749}) (Version: 7.0.43.12698 - muvee Technologies Pte Ltd)
My HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.0.62 - WildTangent)
Network64 (Version: 130.0.550.000 - Hewlett-Packard) Hidden
NTI Ripper (HKLM-x32\…\{88A785A2-3EA6-4A2D-ABEE-68E9E55A39F8}) (Version: 2.0.0.17 - NewTech Infosystems)
NTI Shadow 3 (HKLM-x32\…\{E9EB5689-4F76-4E3C-A675-5ED5F52AB890}) (Version: 3.1.4.0 - NewTech Infosystems)
OCR Software by I.R.I.S. 13.0 (HKLM\…\HPOCR) (Version: 13.0 - HP)
Origin (HKLM-x32\…\Origin) (Version: 9.4.6.2792 - Electronic Arts, Inc.)
PDF Suite 2015 (HKLM-x32\…\PDF Suite 2015) (Version: 13.0.10.21694 - Interactive Brands Malta Limited)
PDF Suite 2015 (x32 Version: 13.0.23.21617 - Interactive Brands Malta Limited) Hidden
PDF Suite 2015 OCR Module (x32 Version: 13.0.23.21617 - Interactive Brands Malta Limited) Hidden
PhotoScape (HKLM-x32\…\PhotoScape) (Version:  - )
Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.2512 - CyberLink Corp.)
Power2Go (x32 Version: 6.0.2512 - CyberLink Corp.) Hidden
PowerDirector (HKLM-x32\…\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.2512 - CyberLink Corp.)
PowerDirector (x32 Version: 7.0.2512 - CyberLink Corp.) Hidden
ProtectSmart Hard Drive Protection (HKLM\…\{2F97CE84-9C33-4631-821B-85EA371EA254}) (Version: 3.10.1.7 - Hewlett-Packard)
QLBCASL (x32 Version: 6.40.17.2 - Hewlett-Packard) Hidden
QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: 6.0.6000.20113 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SafeZone Stable 1.48.2066.114 (x32 Version: 1.48.2066.114 - Avast Software) Hidden
Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Segoe UI (x32 Version: 15.4.2271.0615 - Microsoft Corp) Hidden
Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 13.0 - HP)
Slingbox - Watch Your TV Anywhere (HKLM-x32\…\{7B798B31-2F33-4DC8-BDA4-D36488E86636}) (Version: 1.0.0 - Sling Media)
SlingPlayer (HKLM-x32\…\InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}) (Version: 1.04.0206 - Sling Media)
SlingPlayer (x32 Version: 1.04.0206 - Sling Media) Hidden
SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spelling Dictionaries Support For Adobe Reader 9 (HKLM-x32\…\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Steam (HKLM-x32\…\Steam) (Version:  - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated)
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden
TurboTax 2012 (HKLM-x32\…\TurboTax 2012) (Version: 2012.0 - Intuit, Inc)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
WildTangent Games App (HP Games) (HKLM-x32\…\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.31 - WildTangent)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}) (Version: 14.0.8064.206 - Microsoft Corporation)
Xilisoft Video Converter Ultimate (HKLM-x32\…\Xilisoft Video Converter Ultimate) (Version: 7.7.3.20131014 - Xilisoft)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1E47DECC-A445-437E-BA49-BF68A0FE709D} - System32\Tasks\HP Health Check => c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09] (Hewlett-Packard)
Task: {1EEC94E2-3371-4445-B69E-06C410B6EE74} - System32\Tasks\{6EA9492D-AFAD-4611-B778-FEF2E452B324} => pcalua.exe -a "C:\Users\raypahl\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GJQZPLZ1\Athena[1].exe" -d C:\Users\raypahl\Desktop
Task: {24AF7C9D-752C-4445-A82B-1BE9CDF09079} - System32\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {2676CF9D-8246-4E69-9166-E93FAAEF4707} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-09] (Adobe Systems Incorporated)
Task: {3712F5A0-0477-4593-898F-2D6722E1694A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {5BF15EEE-CE81-46B3-97C4-2F0217BF3198} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
Task: {6E74CFCE-FF9D-417D-9884-56337FA84896} - System32\Tasks\HPCeeScheduleForraypahl => C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe [2008-05-19] (Hewlett-Packard)
Task: {C4A2780D-68B8-4F95-A118-6E5DD88047E0} - System32\Tasks\NetworkWizardHNW => C:\Program Files (x86)\Hewlett-Packard\HP TCS\RemEngine.exe [2008-12-17] ()
Task: {E226896F-2D00-4835-94CA-6E3EE9E822E0} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-29] (AVAST Software)
Task: {EC1DA6EA-D89F-45D1-96DA-F64D32C2C68E} - System32\Tasks\SafeZone scheduled Autoupdate 1468319266 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-06-17] (Avast Software)
Task: {EC3518F0-B320-4AC6-B0D1-D131875A226A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {ECBDA076-B4B3-4E77-8185-DC8446925D32} - System32\Tasks\{2DF12692-40FF-4911-A6C8-8B1BF5365384} => pcalua.exe -a C:\Users\raypahl\AppData\Local\Microsoft\Windows\Burn\Burn\callatlanta_setup.exe
Task: {F1351889-C902-458D-940D-9EEB132FCC88} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {FD30349E-1798-46DF-A9FF-96869C61C29C} - System32\Tasks\{B8696691-6D99-40A1-8CEE-83EC12275D01} => pcalua.exe -a C:\Users\raypahl\Desktop\esetsmartinstaller_enu.exe -d C:\Users\raypahl\Desktop
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15e36ffe9eaa0.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForraypahl.job => C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\raypahl\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.com
 
==================== Loaded Modules (Whitelisted) ==============
 
2009-03-06 00:55 - 2008-11-25 17:29 - 00247152 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2008-11-26 18:13 - 2008-11-26 18:13 - 00296320 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
2008-11-26 18:13 - 2008-11-26 18:13 - 00116096 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
2015-03-20 17:12 - 2015-03-20 17:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 17:12 - 2015-03-20 17:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2008-11-26 18:12 - 2008-11-26 18:12 - 00074536 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\Common\MCEMediaStatus64.dll
2009-07-01 14:44 - 2009-07-01 14:44 - 00632888 _____ () C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
2016-08-29 17:18 - 2016-08-29 17:18 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-08-29 17:18 - 2016-08-29 17:18 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-11-14 06:46 - 2016-11-14 06:46 - 03130832 _____ () C:\Program Files\AVAST Software\Avast\defs\16111400\algo.dll
2009-03-06 00:55 - 2008-11-25 17:29 - 00034088 _____ () C:\Program Files (x86)\Cyberlink\Shared files\RichVideops.dll
2008-11-26 18:13 - 2008-11-26 18:13 - 00263560 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLCapEngine.dll
2008-11-26 18:13 - 2008-11-26 18:13 - 00038184 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLCapSvcps.dll
2007-07-12 14:55 - 2007-07-12 14:55 - 01581056 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
2007-08-14 14:59 - 2007-08-14 14:59 - 06365184 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
2007-07-12 14:55 - 2007-07-12 14:55 - 00131072 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2014-10-10 11:41 - 2014-10-10 11:41 - 01255936 _____ () C:\Program Files (x86)\CBS Interactive\Download App\libcurl.dll
2014-10-10 11:39 - 2014-10-10 11:39 - 00066560 _____ () C:\Program Files (x86)\CBS Interactive\Download App\zlib.dll
2008-11-26 18:13 - 2008-11-26 18:13 - 00349480 ____N () C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\CLTinyDB.dll
2009-04-29 21:11 - 2009-04-29 21:11 - 00906536 ____N () C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
2016-07-11 21:01 - 2016-07-11 21:02 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-11-11 21:50 - 2016-11-11 21:50 - 00098816 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32api.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00110080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\pywintypes27.dll
2016-11-11 21:50 - 2016-11-11 21:50 - 00364544 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\pythoncom27.dll
2016-11-11 21:50 - 2016-11-11 21:50 - 00320512 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32com.shell.shell.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00914432 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\_hashlib.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 01176576 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\wx._core_.pyd
2016-11-11 21:50 - 2016-11-11 21:51 - 00806400 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\wx._gdi_.pyd
2016-11-11 21:51 - 2016-11-11 21:51 - 00816128 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\wx._windows_.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 01067008 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\wx._controls_.pyd
2016-11-11 21:51 - 2016-11-11 21:51 - 00733184 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\wx._misc_.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00682496 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\pysqlite2._sqlite.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00088064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\_ctypes.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00686080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\unicodedata.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00119808 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32file.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00108544 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32security.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00007168 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\hashobjs_ext.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00017920 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\thumbnails_ext.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00088064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\usb_ext.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00012800 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\common.time34.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00018432 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32event.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00167936 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32gui.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00046080 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\_socket.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 01303552 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\_ssl.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00128512 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\_elementtree.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00127488 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\pyexpat.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00038912 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32inet.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00036864 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\_psutil_windows.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00524248 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\windows._lib_cacheinvalidation.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00011264 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32crypt.pyd
2016-11-11 21:51 - 2016-11-11 21:51 - 00123392 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\wx._wizard.pyd
2016-11-11 21:51 - 2016-11-11 21:51 - 00077312 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\wx._html2.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00027648 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\_multiprocessing.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00020480 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\_yappi.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00035840 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32process.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00078848 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\wx._animate.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00024064 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32pipe.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00010240 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\select.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00025600 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32pdh.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00017408 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32profile.pyd
2016-11-11 21:50 - 2016-11-11 21:50 - 00022528 ____R () C:\Users\raypahl\AppData\Local\Temp\_MEI26722\win32ts.pyd
2016-09-06 13:28 - 2016-09-06 11:00 - 05197312 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libglesv2.dll
2016-09-06 13:28 - 2016-09-06 11:00 - 00147456 _____ () C:\Users\raypahl\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKLM\…\cmdfile\DefaultIcon: %SystemRoot%\System32\shell32.dll,-153 <===== ATTENTION
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-513785977-584283709-202011636-1000\…\intuit.com -> hxxps://accounts.intuit.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 06:34 - 2006-09-18 15:37 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
::1             localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-513785977-584283709-202011636-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\img24.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Constant Guard.lnk => C:\Windows\pss\Constant Guard.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Fast Connect.lnk => C:\Windows\pss\Fast Connect.lnk.CommonStartup
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [{85CA64C5-0E24-49D3-962C-757C4D4EF5EA}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE
FirewallRules: [{C056B941-D6C9-43C2-BC46-C8062C7E9591}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe
FirewallRules: [{A477DEFD-C4F3-49DF-9493-DCB0193B3DC2}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe
FirewallRules: [{9DA0FA66-F81F-4C49-93E4-0C736F80D266}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe
FirewallRules: [{D62589CC-FCFC-474B-897E-5F4E2E376DB6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\TSMAgent.exe
FirewallRules: [{0C18A91B-06AB-412C-A4FB-56721866C9EB}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe
FirewallRules: [{90B91326-6994-4D67-8710-402213196972}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe
FirewallRules: [{892F181D-FCD8-4749-A566-1DDE9D5E06C6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QP.exe
FirewallRules: [{218696AD-0268-44D1-958A-9FB0C07367EE}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Media\TV\QPService.exe
FirewallRules: [{C0D11A95-3BAB-4C69-9B2F-ABDF0DE00382}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{DA361D62-6094-45AB-8548-C892212DD857}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe
FirewallRules: [{E29DF1CE-61F4-4C67-B5E6-018649FED1F0}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe
FirewallRules: [{28D8EE93-F60E-412F-B1D8-2540677725C9}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe
FirewallRules: [{2C5DE510-0436-4BA6-9D33-EA65AD777F21}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
FirewallRules: [{2121075F-A168-42F2-A24D-D0A4C9205054}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
FirewallRules: [{899817AC-8E24-4616-A1BB-9CF013A72458}] => (Allow) LPort=80
FirewallRules: [{801C85E3-1031-4FA1-9462-DDCCDD72601F}] => (Allow) LPort=80
FirewallRules: [{2A217FCB-85BA-4D43-88A5-E696A21C17BE}] => (Allow) LPort=80
FirewallRules: [{67913156-DF65-4018-B0AC-C4BA598F0458}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{F97F9C53-4B16-44C5-9DAB-BE26D646BB2E}] => (Allow) LPort=2869
FirewallRules: [{ECDA4AA6-F84F-4F8C-A5C2-0981BEB965AB}] => (Allow) LPort=1900
FirewallRules: [{99E21AA7-60B0-4758-9700-947CE68E6FC4}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{556638C7-DDD1-49D4-B540-2BF1813097BE}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{BA7B17AA-ECB1-48CA-B123-DEDEF25F5280}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C8533641-5BA2-4226-AFAD-01CAA75D4BC3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2079C40C-30DB-4EC9-A37D-2A69F7CB2B9A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{7AA88511-8B20-4763-AB96-65C325F436C2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8338DBF9-E8CD-40AC-A575-BC1C4D3264AE}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{49D4AFA4-BDA6-4F09-A81E-C49E81BDD809}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{F2531826-2F73-4998-9503-3CB1A9EF475A}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{50BB60C3-956B-46D3-BD6E-BF3715DAEAA8}] => (Allow) C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{938E4FAF-25DE-43F0-8941-BAB51D00909F}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{32D0853C-F33F-4CA2-BDD9-EB0E43C2C1A9}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe
FirewallRules: [{028CDA9D-6AA2-48CC-97F4-8CB3BFFEDCAE}] => (Allow) C:\Program Files (x86)\Origin\Origin.exe
FirewallRules: [{24ED04E3-69B3-4EF6-AB2B-774FF6EBB341}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{B498508E-E2F8-420D-AF6B-5E4EB2847438}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{149237F6-0247-4D6A-9B24-6284C0EC1F6E}] => (Allow) LPort=80
FirewallRules: [{0D5BE560-6B3C-4CA0-A163-4A0D4761952F}] => (Allow) LPort=3074
FirewallRules: [{46BBA3EE-07CF-43BA-B750-B59D6FEA6E67}] => (Allow) LPort=53
FirewallRules: [{1937BBB4-CCBA-487B-ABF4-965EBD64F35D}] => (Allow) LPort=88
FirewallRules: [{0B06D53B-770D-4F4F-8750-588083139BD4}] => (Allow) LPort=3074
FirewallRules: [{63DB0018-84DB-4F7D-91A6-5EEB5D473E2C}] => (Allow) LPort=53
FirewallRules: [{4BD011AB-0AC7-4B5A-A0CF-466CC36B4E10}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS6610\HPDiagnosticCoreUI.exe
FirewallRules: [{5CFF6CC9-FFCC-4E3F-BC41-D4AC77525B27}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS6610\HPDiagnosticCoreUI.exe
FirewallRules: [{D627BCA2-CF30-4E83-813D-55AE2787BACA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{8EBE220A-A2E8-47DC-9A52-C00C722B2B36}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{67F0DD1B-2C2B-4DF0-83BD-CA448BAF87E8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{277CCB2A-D8F2-4438-8B24-11CC51D7A2DD}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{A4D4FBBF-F068-4D39-8BE3-74355B903AB7}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3C2E\HPDiagnosticCoreUI.exe
FirewallRules: [{71675975-38A1-48EA-ACCB-FABEF0BD9D13}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3C2E\HPDiagnosticCoreUI.exe
FirewallRules: [{56345E73-9C25-4274-A858-4690E48E1F67}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS64AB\HPDiagnosticCoreUI.exe
FirewallRules: [{E16F485C-ED68-4BD6-8805-2A64A9D96A39}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS64AB\HPDiagnosticCoreUI.exe
FirewallRules: [{31BE109E-8AF9-4143-AD52-57F7DB7FAED8}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS0964\HPDiagnosticCoreUI.exe
FirewallRules: [{A93D5B10-FD8F-4B4F-B432-6A12E6A2D0DC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS0964\HPDiagnosticCoreUI.exe
FirewallRules: [{7C26B91E-B117-486A-B514-1E931777327D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{3D0B25BE-B075-4318-8FAD-AA4378D408D4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{3190CC53-3DB5-4C54-B6F1-0770B51650F2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{D9A183D9-B520-4D17-8D52-4341A9CFBBEC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{BCEEDD97-2D66-466F-B460-54D582497581}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{603C8A2D-FB38-49BD-9FDD-2934CAECAE11}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{DDEE3F5E-97F1-4B23-9929-9B3755027FC8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{38A2B6F1-AE10-4306-AC8B-57D65B8552FB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{A6BD5514-3186-4D82-ACE9-8AFC163F591F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{E5BEACAE-D7A3-4D30-8284-ED4CDC7EE1F1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{55C0994B-0B3E-444F-A6F1-771232CE4C04}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{24942CC8-CEE3-42BD-AE57-6FC7B5B01D26}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{80E01553-7E49-42EB-84AA-260B63480BFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{3D37A03B-72C1-4951-AACC-F8F9842EAC32}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{9851363A-29E7-4066-808D-76F09B44EAA9}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{6DF5A30B-3B0F-4CC8-91E7-C21179661239}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{00C3DF64-1789-45C4-826E-F88407B37F60}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{8060B257-FF11-4A7E-B4D6-8822812D5766}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{FDC220B2-E26C-439A-8AEE-6CB05A6A9CDF}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{0548CB3C-9BAA-419F-AC3C-CF92119ECF94}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{23D1FC3D-674C-44F8-9961-46BBEB100F2F}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{069C9567-F251-4E40-B6F7-7B7D7D9109AC}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{D99F3B45-4583-426E-8CDF-DF5E521807C6}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{D41E6F5E-2589-4C57-9E12-1D63C165791D}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{6DEEE18D-D523-45BF-932E-CE5743988EE8}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{43D52C1D-478B-4FCE-9745-AAF8982DF4DC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS175A\HPDiagnosticCoreUI.exe
FirewallRules: [{A707CC94-5C2F-4D23-8BCD-1307DBA1F380}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS175A\HPDiagnosticCoreUI.exe
FirewallRules: [{D5F39F1E-2D2C-4FE4-AC8F-7D1244D261F1}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS17E3\HPDiagnosticCoreUI.exe
FirewallRules: [{98DD6223-287E-4612-84C7-8256612DF4EE}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS17E3\HPDiagnosticCoreUI.exe
FirewallRules: [{A5F88943-D64D-41D9-ACDD-54EDBEC8ECC3}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS61A2\HPDiagnosticCoreUI.exe
FirewallRules: [{0295B60A-D80C-449F-A559-2559D30C56ED}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS61A2\HPDiagnosticCoreUI.exe
FirewallRules: [{B26FD28B-080C-4DC6-84AF-10360A7C1848}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS326C\HPDiagnosticCoreUI.exe
FirewallRules: [{EDDD3BB6-DE4D-491F-9E82-60EED756FAB0}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS326C\HPDiagnosticCoreUI.exe
FirewallRules: [{720847F8-E7ED-4F05-A979-64A3CABFD9A4}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{9DED4120-5843-4CD7-96F8-BA8DC78DD4D2}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{5188845E-5ABE-493A-8AE3-C562AF667662}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3742\HPDiagnosticCoreUI.exe
FirewallRules: [{87FB02D8-EDC9-4628-8196-40F55E2955A2}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3742\HPDiagnosticCoreUI.exe
FirewallRules: [{37154139-4F88-40F7-8C66-F721A336A600}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3780\HPDiagnosticCoreUI.exe
FirewallRules: [{D47BCBCC-ADF9-4F87-BCFB-E6EFD8A23273}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS3780\HPDiagnosticCoreUI.exe
FirewallRules: [{C550D466-6DA9-4CF3-AF39-E1B7B9D3491A}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS5F6B\HPDiagnosticCoreUI.exe
FirewallRules: [{ABBB6631-70E4-4D5A-8D5D-105E6B6C2047}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS5F6B\HPDiagnosticCoreUI.exe
FirewallRules: [{735A1C21-05AD-49A7-B856-D8DB046D814B}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{072D341C-F0AA-4EC4-B256-90AA1A0371D6}] => (Allow) C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe
FirewallRules: [{0E09CE06-6B58-4C5C-B41F-9CBC3C28310F}] => (Allow) C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\dtUser.exe
FirewallRules: [{AF858CCB-A6DC-41B2-A8F1-DEC030D92EEB}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{4850BCB1-4BDE-4888-9338-413BF216736F}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{37A8803F-79F3-4EA8-B4DC-EFC8C0988147}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{05B7B3B1-49C4-42B6-B68A-EFF0B868DFBB}C:\program files (x86)\swannview link\mydvr.exe] => (Allow) C:\program files (x86)\swannview link\mydvr.exe
FirewallRules: [UDP Query User{3A8123E3-4600-46C8-8ACE-AF6FB9F3DE3D}C:\program files (x86)\swannview link\mydvr.exe] => (Allow) C:\program files (x86)\swannview link\mydvr.exe
FirewallRules: [TCP Query User{0B8D5604-9A95-4CBA-99CC-80CD63F8BD63}C:] => (Allow) C:\
FirewallRules: [UDP Query User{423E6DF9-8B53-405B-8F7D-6926AE5B5679}C:] => (Allow) C:\
FirewallRules: [{954DDB9D-8A37-4449-BC09-F3070B20367E}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS420D\HPDiagnosticCoreUI.exe
FirewallRules: [{DA174395-2E36-4D4D-B5EC-11BFF9576FD7}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS420D\HPDiagnosticCoreUI.exe
FirewallRules: [{53EE87C1-3AC3-43AD-B1D9-4ECE6A351714}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS42CB\HPDiagnosticCoreUI.exe
FirewallRules: [{6A40C1D8-44EC-4858-97A6-EAE58655C9EC}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS42CB\HPDiagnosticCoreUI.exe
FirewallRules: [{5537C001-D930-41E2-B89C-942DB712A6B9}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS4196\HPDiagnosticCoreUI.exe
FirewallRules: [{665ECD78-617F-490D-B46F-145BA00FC68D}] => (Allow) C:\Users\raypahl\AppData\Local\Temp\7zS4196\HPDiagnosticCoreUI.exe
 
==================== Restore Points =========================
 
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/14/2016 09:28:57 AM) (Source: Software Licensing Service) (EventID: 8198) (User: )
Description: License Activation (SLUI.exe) failed with the following error code:
0x80070057
 
Error: (11/14/2016 06:05:50 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16830 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 1844
Start Time: 01d23e6f689eef00
Termination Time: 15
 
Error: (11/13/2016 07:00:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 9.0.8112.16830 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 9a0
Start Time: 01d23e126e9d9c10
Termination Time: 15
 
Error: (11/13/2016 06:38:43 PM) (Source: MsiInstaller) (EventID: 11706) (User: STEARNS-PC)
Description: Product: Status – Error 1706. An installation package for the product Status cannot be found. Try the installation again using a valid copy of the installation package 'status.msi'.
 
Error: (11/11/2016 09:53:11 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons: 
there is a problem with the network connection, the disk that the file is stored on, or the storage 
drivers installed on this computer; or the disk is missing. 
Windows closed the program Host Process for Windows Services because of this error.
 
Program: Host Process for Windows Services
File: C:\Windows\Prefetch\AgRobust.db
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again. 
This situation might be a temporary problem that corrects itself when the program runs again.
2. 
If the file still cannot be accessed and
- It is on the network, 
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for 
further assistance.
 
Additional Data
Error value: C0000185
Disk type: 3
 
Error: (11/11/2016 09:53:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,
process id 0x102c, application start time 0x01d23c97d7336908.
 
Error: (11/11/2016 09:48:57 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons: 
there is a problem with the network connection, the disk that the file is stored on, or the storage 
drivers installed on this computer; or the disk is missing. 
Windows closed the program Host Process for Windows Services because of this error.
 
Program: Host Process for Windows Services
File: C:\Windows\Prefetch\AgRobust.db
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again. 
This situation might be a temporary problem that corrects itself when the program runs again.
2. 
If the file still cannot be accessed and
- It is on the network, 
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for 
further assistance.
 
Additional Data
Error value: C0000185
Disk type: 3
 
Error: (11/11/2016 09:48:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,
process id 0x6b0, application start time 0x01d23c973e3e65b8.
 
Error: (11/11/2016 09:45:23 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\AgRobust.db for one of the following reasons: 
there is a problem with the network connection, the disk that the file is stored on, or the storage 
drivers installed on this computer; or the disk is missing. 
Windows closed the program Host Process for Windows Services because of this error.
 
Program: Host Process for Windows Services
File: C:\Windows\Prefetch\AgRobust.db
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again. 
This situation might be a temporary problem that corrects itself when the program runs again.
2. 
If the file still cannot be accessed and
- It is on the network, 
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for 
further assistance.
 
Additional Data
Error value: C0000185
Disk type: 3
 
Error: (11/11/2016 09:45:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application svchost.exe_SysMain, version 6.0.6001.18000, time stamp 0x47919291, faulting module sysmain.dll, version 6.0.6002.18005, time stamp 0x49e04208, exception code 0xc0000006, fault offset 0x000000000006f355,
process id 0x17c, application start time 0x01d23c94d278a75e.
 
 
System errors:
=============
Error: (11/14/2016 09:57:29 AM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
 
Error: (11/13/2016 06:34:15 PM) (Source: volsnap) (EventID: 14) (User: )
Description: The shadow copies of volume C: were aborted because of an IO failure on volume C:.
 
Error: (11/13/2016 06:31:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Pml Driver HPZ12 service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (11/13/2016 06:31:06 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {28778B62-8481-400D-8E8A-A4C81ED3F65C} did not register with DCOM within the required timeout.
 
Error: (11/13/2016 06:30:29 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Pml Driver HPZ12 service to connect.
 
Error: (11/12/2016 09:57:10 PM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
 
Error: (11/11/2016 09:58:35 PM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
 
Error: (11/11/2016 09:53:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Diagnostic System Host service terminated unexpectedly.  It has done this 3 time(s).
 
Error: (11/11/2016 09:53:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Tablet PC Input Service service terminated unexpectedly.  It has done this 3 time(s).
 
Error: (11/11/2016 09:53:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Superfetch service terminated unexpectedly.  It has done this 3 time(s).
 
 
CodeIntegrity:
===================================
  Date: 2016-11-11 15:43:08.375
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-11-11 15:43:07.610
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-11-11 15:43:06.830
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-11-11 15:43:05.941
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-11-11 15:43:05.114
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-11-11 15:43:04.319
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-11-11 15:43:03.584
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-11-11 15:43:02.773
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-11-11 15:43:01.978
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-11-11 15:43:01.120
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz
Percentage of memory in use: 61%
Total physical RAM: 3998.02 MB
Available physical RAM: 1549.99 MB
Total Virtual: 8229.28 MB
Available Virtual: 5636.42 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:452.13 GB) (Free:145.54 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (RECOVERY) (Fixed) (Total:13.62 GB) (Free:2.09 GB) NTFS ==>[system with boot components (obtained from drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 636BBFB1)
Partition 1: (Active) - (Size=452.1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=13.6 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

I would go ahead and uninstall Origins if you dont use it, you can find it Programs and Features in the Control Panel, let me know how that went and we can remove any leftovers 

Nothing much has changed.  The computer does seem to be functioning a little quicker with the exception of starting up.  I still have the host message thing at start up and now I also get a text box that says, "log on process has failed to create the security options dialog and then there is a big red circle with an X in it next to "failure - security options"

We have cleaned you up quite a bit and your still having some problems, at this point I dont believe there malware related. I think a new computer may be in order, or maybe reinstalling windows nice and clean. With the age of this computer and it running Vista, upgrading to XP would be a mistake and trying to upgrade to Win 7 or 8 may not be an option as your drivers and what not that run your sound, video may not be available from the manufacturer if you upgraded.  I would suggest posting in our windows forum and see if they can come up with some answers. As this forum is for malware removal this is as far as i can go.

 

 

Double click on AdwCleaner.exe to run the tool again.
  •  
  • Click on the Uninstall button.
  • Click Yes when asked are you sure you want to uninstall.
  • Both AdwCleaner.exe, its folder and all logs will be removed.
 
 
 
==========================================================
 
 
Open up Malwarebytes
  •  
  • On the Dashboard…click on History
  • Then click on Quarantine
  • Make everything is checked
  • Then click on Delete All
  • Close out Malwarebytes
 
 
 
==========================================================
 
 
Please download DelFix and save the file to your Desktop.
 
[external image: DelFix_zps139e2ea1.jpg]
 
  •  
  • Windows XP Double Click DelFix.exe to run the program. 
  • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
  • Checkmark " Remove Disinfection Tools"
  • Click the Run button
 
 
This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
 
 
 
 
So How did I get infected in the first place <– Some reading for you to keep yourself safe online
 
 
Safe Surfn
Ken
 
 
 
 
 
 
 
 
 
 

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI