I was given a laptop by a friend of mine. She didn't use it anymore because her kids had gotten a LOT of viruses on it. Need help to either clean it, or preferably just do a factory reset. I tried that first but couldn't get anywhere. Here are the required scans.
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-12-27 09:08:44
—————————–
09:08:45.012 OS Version: Windows x64 6.1.7601 Service Pack 1
09:08:45.012 Number of processors: 2 586 0x2505
09:08:45.012 ComputerName: TERESA-PC UserName: Teresa
09:08:53.389 Initialize success
09:11:42.895 AVAST engine defs: 16122700
09:36:25.222 The log file has been saved successfully to "C:\Users\Teresa\Desktop\aswMBR.txt"
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-12-2016
Ran by [removed] (administrator) on TERESA-PC (27-12-2016 16:58:18)
Running from C:\Users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VITUUM5Z
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode:
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\Re-markit-soft\Re-markitw.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(COMPANYVERS_NAME) C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39barsvc.exe
(COMPANYVERS_NAME) C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5abarsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccsvchst.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
() C:\Program Files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
(Novatel Wireless Inc.) C:\Program Files (x86)\Novatel Wireless\Drivers\NWHelper.exe
() C:\Program Files (x86)\Re-markit-soft\Re-markitBG175.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
() C:\Program Files (x86)\CDDCF87A-3EAD-40C4-8099-34C6869D3E9D\SupraSavingsService64.exe
() C:\Program Files\003\vxlsnyaiet64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccsvchst.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportInjService_x64.exe
(Microsoft Corporation) C:\Windows\System32\CompatTel\wicainventory.exe
(Facebook Inc.) C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe
() C:\Program Files (x86)\Re-markit-soft\Re-markitj73.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-22] (Acer Incorporated)
HKLM\…\Run: [MyWebFace Home Page Guard 64 bit] => C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\AppIntegrator64.exe [485448 2014-02-12] ( )
HKLM-x32\…\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1092688 2011-03-31] (Dritek System Inc.)
HKLM-x32\…\Run: [Bell Canada Connection Manager] => C:\Program Files (x86)\Bell\Mobile Connect\MobileConnect.exe [87576 2011-06-15] (Bell)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.)
HKLM-x32\…\Run: [MapsGalaxy Search Scope Monitor] => C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrchMn.exe [38440 2012-01-29] (MindSpark)
HKLM-x32\…\Run: [MapsGalaxy_39 Browser Plugin Loader] => C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39brmon.exe [30096 2012-01-29] (VER_COMPANY_NAME)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM-x32\…\Run: [Browser companion helper] => C:\Program Files (x86)\BrowserCompanion\BCHelper.exe [187696 2011-12-15] (Blabbers Communications LTD)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776 2012-09-09] (Apple Inc.)
HKLM-x32\…\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKLM-x32\…\Run: [MyWebFace EPM Support] => C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5amedint.exe [12872 2014-02-12] (Mindspark Interactive Network, Inc.)
HKLM-x32\…\Run: [MyWebFace Search Scope Monitor] => C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5aSrchMn.exe [55368 2014-02-12] (Mindspark)
HKLM-x32\…\Run: [MyWebFace_5a Browser Plugin Loader] => C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5abrmon.exe [61512 2014-02-12] (VER_COMPANY_NAME)
HKLM-x32\…\Run: [MyWebFace_5a Browser Plugin Loader 64] => C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5abrmon64.exe [71752 2014-02-12] (VER_COMPANY_NAME)
HKLM-x32\…\Run: [fst_ca_99] => [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Run: [Facebook Update] => C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-11] (Facebook Inc.)
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.)
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Run: [PriceMeterW] => "C:\Users\Teresa\AppData\Local\PriceMeter\pricemeterw.exe"
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [135112 2014-05-09] (PC Utilities Software Limited)
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_15_0_0_152_Plugin.exe [854192 2014-09-11] (Adobe Systems Incorporated)
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\MountPoints2: {cdca7044-329d-11e1-840e-b870f47876ce} - E:\AutoLaunch.exe
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-18\…\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\Program Files (x86)\SupTab\SearchProtect64.dll [102512 2014-05-08] (Skytech Co., Ltd.)
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => C:\Program Files (x86)\SupTab\SearchProtect32.dll [91248 2014-05-08] (Skytech Co., Ltd.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2012-05-19]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Teresa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2014-05-19]
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [S-1-5-21-504136971-1847211166-3120143677-1000] => Proxy is enabled.
ProxyServer: [S-1-5-21-504136971-1847211166-3120143677-1000] => http=127.0.0.1:14427;https=127.0.0.1:14427
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5B06BF4C-FFD7-4511-9771-B9D290391CC5}: [DhcpNameServer] 192.168.1.254 [removed]
Tcpip\..\Interfaces\{8BBE56C8-9777-40E5-ADEE-9E92F232A69F}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{BA035D19-38CF-4A21-8CB0-017F1CCBC26C}: [DhcpNameServer] [removed]
ManualProxies: 1http=127.0.0.1:14103;https=127.0.0.1:14103
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.v9.com/?type=hp&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.v9.com/?type=hp&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.v9.com/?type=hp&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
URLSearchHook: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 - (No Name) - {b54561db-0bbb-41b4-a814-df8301fe0a8e} - No File
URLSearchHook: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 - (No Name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll (MindSpark)
URLSearchHook: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 - (No Name) - {8040829d-1177-46e2-9157-8282438b79c7} - C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5aSrcAs.dll (Mindspark)
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://speedial.com/results.php?f=4&q;={searchTerms}&a;=spd_secureddownload_14_21_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzyBtDtN1L2XzutBtFtBtDtFtCtAtFtDtN1L1CzutCyEtDtAtDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2StC0A0EtAyEyDtByCtGtByCzyzztG0AtByCzztGtC0ByCtDtGyCtCtC0F0CyByE0B0C0Dzz0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=264653511&ir;=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM -> {31090377-0740-419E-BEFC-A56E50500D5B} URL =
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
SearchScopes: HKLM -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=107&systemid;=2&sr;=0&q;={searchTerms}
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=384&systemid;=406&sr;=0&q;={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=107&systemid;=2&sr;=0&q;={searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=384&systemid;=406&sr;=0&q;={searchTerms}
SearchScopes: HKLM-x32 -> {E627DC4B-8C04-4234-A2D4-1D634EE01C41} URL = hxxp://www.bigseekpro.com/search/toolbar/mp3rocket/{730F4B83-001C-80BE-0B4C-C3B978797925}?q={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://speedial.com/results.php?f=4&q;={searchTerms}&a;=spd_secureddownload_14_21_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzyBtDtN1L2XzutBtFtBtDtFtCtAtFtDtN1L1CzutCyEtDtAtDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2StC0A0EtAyEyDtByCtGtByCzyzztG0AtByCzztGtC0ByCtDtGyCtCtC0F0CyByE0B0C0Dzz0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=264653511&ir;=
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://speedial.com/results.php?f=4&q;={searchTerms}&a;=spd_secureddownload_14_21_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzyBtDtN1L2XzutBtFtBtDtFtCtAtFtDtN1L1CzutCyEtDtAtDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2StC0A0EtAyEyDtByCtGtByCzyzztG0AtByCzztGtC0ByCtDtGyCtCtC0F0CyByE0B0C0Dzz0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=264653511&ir;=
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID;=112060&tt;=010712_8&babsrc;=SP_ss&mntrId;=b4a493270000000000000aa3c4b8a45a
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3319611&octid;=EB_ORIGINAL_CTID&SearchSource;=58&CUI;=&UM;=5&UP;=SPD1FAFB5A-19BE-4978-B8F6-4E387A8BCC8C&q;={searchTerms}&SSPV;=
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://start.mysearchdial.com/results.php?f=4&q;={searchTerms}&a;=cmi_14_24_ff&cd;=2XzuyEtN2Y1L1Qzu0BzzyBtD0FyEyBzzyByC0C0EzytAtByBtN0D0Tzu0SzzzyyDtN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyC0Azy0E0CyBtD0BtGtBtDyEtDtGtA0DtC0CtG0EyE0BtCtGtCtCyDzz0Czy0DtBtDtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBtByBtCtB0CyB0AtG0A0EtDtBtGyCyDyB0CtG0D0D0D0AtGyE0F0D0Bzy0D0DtDzz0EyC0B2Q&cr;=1655770617&ir;=
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://www.ask.com/web?l=dis&o;=41648007&gct;=sb&qsrc;=2869&apn;_dtid=^YYYYYY^YY^CA&apn;_ptnrs=^8M&apn;_uid=8439412123714045&p2;=^8M^YYYYYY^YY^CA&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {4BC552F8-FE4F-4BAB-BFF6-8D5C9183C7F0} URL = hxxp://websearch.ask.com/redirect?client=ie&tb;=ORJ&o;=100000027&src;=kw&q;={searchTerms}&locale;=&apn;_ptnrs=U3&apn;_dtid=YYYYYYYYCA&apn;_uid=F37AA36C-B573-4DFE-9D09-DFD39434B78E&apn;_sauid=B91E7160-B9C4-4DDE-8591-CECC082B5A1C
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {5BBA514E-D260-4565-B9CD-E792047B6F2D} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3268494&CUI;=UN73002158717166189&UM;=2
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {74E7751D-8DE8-42C7-A65D-555854303C6C} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3101810
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://search.v9.com/web/?type=ds&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=107&systemid;=2&sr;=0&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid;=384&systemid;=406&sr;=0&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {A6CA5EA8-2AF9-42B8-8970-91DA32ACD4F5} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {DC72F286-063B-41E9-8DC2-1DD46D642351} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3071132
SearchScopes: HKU\S-1-5-21-504136971-1847211166-3120143677-1000 -> {E627DC4B-8C04-4234-A2D4-1D634EE01C41} URL = hxxp://www.bigseekpro.com/search/toolbar/mp3rocket/{730F4B83-001C-80BE-0B4C-C3B978797925}?q={searchTerms}
BHO: Websaver -> {1470D9B2-6DB1-8015-3543-ED4858FFE508} -> C:\ProgramData\Websaver\R3.x64.dll [2014-08-03] ()
BHO: EXattraShopper -> {23BADEE4-2438-F09C-5FFE-EC5973CC1CF8} -> C:\ProgramData\EXattraShopper\jUuR3.x64.dll [2014-09-12] ()
BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL => No File
BHO: avast! Online Security -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll => No File
BHO: ExTraShoPPeR -> {31b76765-eac3-4e65-8a3e-764222fb09c4} -> C:\ProgramData\ExTraShoPPeR\9K0lnxXfNNUQ1H.x64.dll [2014-11-26] ()
BHO: saverneti -> {5F81FE2B-A7C6-4913-1FB0-8CD63FEC8C51} -> C:\ProgramData\saverneti\9y.x64.dll [2014-07-19] ()
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
BHO: LUckyCOUpoon -> {C089BF59-2120-84F6-00C3-D185F7DB4B45} -> C:\ProgramData\LUckyCOUpoon\5McC9VhD1M.x64.dll [2014-09-11] ()
BHO: PrOOShoepper -> {C0B2DEB7-D5C8-20BF-FC61-65D4267D6E9C} -> C:\ProgramData\PrOOShoepper\IvSjUoob21.x64.dll [2014-07-06] ()
BHO: PriceDoownlloader -> {D9F6F33C-DF70-07B9-3306-A835A4169C03} -> C:\ProgramData\PriceDoownlloader\Y.x64.dll [2014-07-03] ()
BHO-x32: Chatvibes Browser Helper -> {00cbb66b-1d3b-46d3-9577-323a336acb50} -> C:\Program Files (x86)\BrowserCompanion\jsloader.dll [2011-10-27] ( )
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO-x32: Search Assistant BHO -> {14d02517-c8be-4735-a344-3c8366c77aa0} -> C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5aSrcAs.dll [2014-02-12] (Mindspark)
BHO-x32: Toolbar BHO -> {1e91a655-bb4b-4693-a05e-2edebc4c9d89} -> C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39bar.dll [2012-01-29] (MindSpark)
BHO-x32: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\progra~1\mcafee\msk\mskapbho.dll => No File
BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\SupTab\SupTab.dll [2014-05-08] (Thinknice Co. Limited)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\coIEPlg.dll [2014-04-29] (Symantec Corporation)
BHO-x32: Re-markit -> {609467CB-A447-E4FA-5EEE-CEE0E56F306B} -> C:\Program Files (x86)\Re-markit-soft\175.dll [2014-07-19] ()
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\IPS\IPSBHO.DLL [2013-04-08] (Symantec Corporation)
BHO-x32: Search Assistant BHO -> {71c1d63a-c944-428a-a5bd-ba513190e5d2} -> C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll [2012-01-29] (MindSpark)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll [2012-05-04] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Chatvibes Browser Helper Verifier -> {963B125B-8B21-49A2-A3A8-E37092276531} -> C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll [2011-10-27] ( )
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO-x32: Toolbar BHO -> {b1df253a-9e7a-480d-b6a5-7a435b520dbb} -> C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5abar.dll [2014-02-12] (Mindspark)
BHO-x32: Wincore Mediabar -> {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} -> C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll => No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll [2012-05-04] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - !{364ea597-e728-4ce4-bb4a-ed846ef47970} - No File
Toolbar: HKLM - No Name - !{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKLM - No Name - !{af94b35c-3ac5-4030-9f9c-15fb4e3dc339} - No File
Toolbar: HKLM-x32 - Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll No File
Toolbar: HKLM-x32 - No Name - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM-x32 - No Name - !{364ea597-e728-4ce4-bb4a-ed846ef47970} - No File
Toolbar: HKLM-x32 - No Name - !{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKLM-x32 - No Name - !{af94b35c-3ac5-4030-9f9c-15fb4e3dc339} - No File
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\coIEPlg.dll [2014-04-29] (Symantec Corporation)
Handler-x32: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll [2011-10-27] (Blabbers Communications Ltd)
Handler-x32: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll [2011-10-27] (Blabbers Communications Ltd)
Handler-x32: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll [2011-10-27] (Blabbers Communications Ltd)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-04-08] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default [2016-12-27]
FF user.js: detected! => C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\user.js [2014-07-19]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\eq94y0o8.default -> v9
FF DefaultSearchUrl: Mozilla\Firefox\Profiles\eq94y0o8.default -> hxxp://www.bigseekpro.com/search/toolbar/mp3rocket/{730F4B83-001C-80BE-0B4C-C3B978797925}?q={searchTerms}
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\eq94y0o8.default -> Search Results
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\eq94y0o8.default -> v9
FF Homepage: Mozilla\Firefox\Profiles\eq94y0o8.default -> hxxp://www.v9.com/?type=hppp&ts;=1402694841&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=344123f43
FF Session Restore: Mozilla\Firefox\Profiles\eq94y0o8.default -> is enabled.
FF Keyword.URL: Mozilla\Firefox\Profiles\eq94y0o8.default -> hxxp://trovi.com/ResultsExt.aspx?ctid=CT3268494&SearchSource;=2&CUI;=UN33218121551869822&UM;=2&q;=
FF Extension: (No Name) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\39ffxtbr@MapsGalaxy_39.com [2012-01-29] [not signed]
FF Extension: (FulAShhCouuPon) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-10-11] [not signed]
FF Extension: (No Name) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\5affxtbr@MyWebFace_5a.com [2014-02-12] [not signed]
FF Extension: (LUckyyShoPper) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-10-11] [not signed]
FF Extension: (Browser Companion Helper) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2012-07-07] [not signed]
FF Extension: (Tiger Savings) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-07-12] [not signed]
FF Extension: (ProuShopper) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-07-12] [not signed]
FF Extension: (Babylon) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2012-01-21] [not signed]
FF Extension: (ExTraShopPere) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-11-26] [not signed]
FF Extension: (savernneT) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-07-19] [not signed]
FF Extension: (websaver) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-10-11] [not signed]
FF Extension: (Quick Start) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-06-13] [not signed]
FF Extension: (easYatoshop) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\[removed] [2014-07-03] [not signed]
FF Extension: (VisualBee V.1 ) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\{7aeae561-714b-45f6-ace3-4a8aed6e227b} [2014-07-12] [not signed]
FF Extension: (Somoto ) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\{bb45ef8e-1e36-4535-a017-ec908fb1e335} [2014-07-14] [not signed]
FF Extension: (Speedial) - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\Extensions\{fa95f577-07cb-4470-ac90-e843f5f83c52} [2014-05-19] [not signed]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\askcom.xml [2012-07-07]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\conduit-search.xml [2014-03-16]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\Mysearchdial.xml [2014-06-13]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\search.xml [2012-07-17]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\Search_Results.xml [2012-09-02]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\Speedial.xml [2014-05-19]
FF SearchPlugin: C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\searchplugins\visualbee-v1-customized-web-search.xml [2014-05-19]
FF Extension: (Skype Click to Call) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [39ffxtbr@MapsGalaxy_39.com] - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin
FF Extension: (No Name) - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin [2012-01-29] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-05-19] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn
FF Extension: (Norton Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn [2016-12-27] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFF
FF Extension: (Norton Vulnerability Protection) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFF [2014-01-25] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\eq94y0o8.default\extensions\[removed]
FF HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\Firefox\Extensions: [{D2B1635C-3660-A50D-0853-6CBFDB7D714E}] - C:\Program Files (x86)\Re-markit-soft\175.xpi
FF Extension: (Re-markit) - C:\Program Files (x86)\Re-markit-soft\175.xpi [2014-07-19] [not signed]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml [2012-07-07]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\searchresultstb.xml [2012-07-16]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml [2012-09-02]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\v9.xml [2016-12-27]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll [2014-09-11] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll [2014-09-11] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-08-08] ()
FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-05-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 -> C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll [2012-05-04] (Oracle Corporation)
FF Plugin-x32: @MapsGalaxy_39.com/Plugin -> C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\NP39Stub.dll [2012-01-29] (MindSpark)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @MyWebFace_5a.com/Plugin -> C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\NP5aStub.dll [2014-02-12] (Mindspark)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-06-23] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-06-23] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll [2012-07-03] ()
FF Plugin HKU\S-1-5-21-504136971-1847211166-3120143677-1000: @lightspark.github.com/Lightspark;version=1 -> C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll [No File]
FF Plugin HKU\S-1-5-21-504136971-1847211166-3120143677-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Teresa\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR DefaultProfile: Default
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HKLM\…\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-504136971-1847211166-3120143677-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-504136971-1847211166-3120143677-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [nlndmljfcnlkbcbbneenigbpikmdfcdh] - C:\Users\Teresa\AppData\Local\CRE\nlndmljfcnlkbcbbneenigbpikmdfcdh.crx [2013-04-14]
CHR HKU\S-1-5-21-504136971-1847211166-3120143677-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [bakijjialdiiboeaknfpmflphhmljfkd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\Exts\Chrome.crx [2014-05-02]
CHR HKLM-x32\…\Chrome\Extension: [clbfjfbnelcflpgpklppgplejolacbej] - C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx [2011-12-22]
CHR HKLM-x32\…\Chrome\Extension: [jealjalmcelnenljclnadlblookmkmdc] - C:\Users\Teresa\AppData\Local\Temp\crx8DFB.tmp [2011-08-27]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM-x32\…\Chrome\Extension: [nlndmljfcnlkbcbbneenigbpikmdfcdh] - C:\Users\Teresa\AppData\Local\CRE\nlndmljfcnlkbcbbneenigbpikmdfcdh.crx [2013-04-14]
CHR HKLM-x32\…\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - chrome.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 64af91bf; c:\ProgramData\Fast And Safe\FastAndSafeSvc.dll [186192 2014-07-03] () [File not signed]
R2 70e6ca8c; c:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll [186496 2014-06-13] () [File not signed]
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36392 2014-03-14] (Just Develop It) [File not signed] <==== ATTENTION
S3 BellCanadaRcAppSvc; C:\Program Files (x86)\Bell\Mobile Connect\RcAppSvc.exe [120344 2011-05-31] (SmithMicro Inc.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 CABellCanada; C:\Program Files (x86)\Bell\Mobile Connect\ConAppsSvc.exe [124440 2011-05-31] (SmithMicro Inc.)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED)
R2 MapsGalaxy_39Service; C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39barsvc.exe [42504 2012-01-29] (COMPANYVERS_NAME)
R2 MyWebFace_5aService; C:\Program Files (x86)\MyWebFace_5a\bar\1.bin\5abarsvc.exe [88648 2014-02-12] (COMPANYVERS_NAME)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccSvcHst.exe [144368 2013-05-20] (Symantec Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe [132504 2013-03-11] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation)
R2 NvtlService; C:\Program Files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe [92504 2011-02-18] ()
R2 NWHelper; C:\Program Files (x86)\Novatel Wireless\Drivers\NWHelper.exe [270336 2010-10-07] (Novatel Wireless Inc.) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
S3 ProfileImpSvc; C:\Program Files (x86)\Bell\Mobile Connect\ProfileImpSvc.exe [169496 2011-05-31] (SmithMicro Inc.)
R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1919256 2014-12-22] (IBM Corp.)
R2 Re-markit; C:\Program Files (x86)\Re-markit-soft\Re-markitBG175.exe [160768 2014-07-19] () [File not signed] <==== ATTENTION
R2 SupraSavingsService64; C:\Program Files (x86)\CDDCF87A-3EAD-40C4-8099-34C6869D3E9D\SupraSavingsService64.exe [172544 2014-06-25] () [File not signed]
R2 vxlsnyaiet64; C:\Program Files\003\vxlsnyaiet64.exe [706560 2014-06-13] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20140214.001\BHDrvx64.sys [1526488 2014-01-21] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1405000.01C\ccSetx64.sys [169048 2013-04-15] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2014-01-23] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2014-01-23] (Symantec Corporation) [File not signed]
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2011-05-24] (Huawei Technologies Co., Ltd.)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20140321.001\IDSvia64.sys [524504 2014-03-15] (Symantec Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20140322.002\ENG64.SYS [126040 2014-02-21] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20140322.002\EX64.SYS [2099288 2014-02-21] (Symantec Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-07-08] (NetFilterSDK.com)
S3 NWRmNet; C:\Windows\System32\DRIVERS\NWRmNet.sys [295424 2010-10-27] (Novatel Wireless Inc.)
S3 PCTINDIS5X64; C:\Windows\system32\PCTINDIS5X64.SYS [43032 2010-08-05] (Smith Micro Inc.)
S1 RapportCerberus_80120; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_80120.sys [845464 2016-12-27] (IBM Corp.)
S1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [445816 2014-12-22] (IBM Corp.)
S0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [535576 2014-12-22] (IBM Corp.)
S1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [558872 2014-12-22] (IBM Corp.)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1405000.01C\SRTSP64.SYS [796760 2013-05-15] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1405000.01C\SRTSPX64.SYS [36952 2013-03-04] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1405000.01C\SYMDS64.SYS [493656 2013-05-20] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1405000.01C\SYMEFA64.SYS [1139800 2013-05-22] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2014-01-26] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1405000.01C\Ironx64.SYS [224416 2013-03-04] (Symantec Corporation)
S1 SymNetS; C:\Windows\System32\Drivers\NISx64\1405000.01C\SYMNETS.SYS [433752 2013-04-24] (Symantec Corporation)
R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}Gw64; C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}Gw64.sys [61112 2014-05-16] (StdLib)
R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64; C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys [61112 2014-06-05] (StdLib)
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
U3 aswMBR; \??\C:\Users\Teresa\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Teresa\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-27 16:57 - 2016-12-27 16:58 - 00000000 ____D C:\FRST
2016-12-27 09:36 - 2016-12-27 09:36 - 00000480 _____ C:\Users\Teresa\Desktop\aswMBR.txt
2016-12-26 23:41 - 2016-12-26 23:47 - 00000000 ____D C:\Users\Teresa\AppData\Local\{6D2F5B73-4987-37CB-241F-12230077EEBB}
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-27 17:03 - 2009-07-13 22:13 - 00783464 _____ C:\Windows\system32\PerfStringBackup.INI
2016-12-27 17:03 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\inf
2016-12-27 16:59 - 2014-07-19 22:18 - 00000408 _____ C:\Windows\Tasks\Re-markit Update.job
2016-12-27 16:56 - 2014-07-19 22:18 - 00000388 _____ C:\Windows\Tasks\Re-markit_wd.job
2016-12-27 16:56 - 2012-12-22 19:46 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-12-27 16:56 - 2011-11-18 12:06 - 00000910 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000Core.job
2016-12-27 16:56 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-12-27 16:54 - 2009-07-13 22:08 - 00032562 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-12-27 16:48 - 2014-06-13 14:17 - 00000296 _____ C:\Windows\Tasks\MySearchDial.job
2016-12-27 16:48 - 2014-05-19 15:41 - 00000296 _____ C:\Windows\Tasks\Speedial.job
2016-12-27 16:48 - 2012-12-22 19:47 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-12-27 16:48 - 2012-12-22 19:46 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-12-27 16:48 - 2011-11-18 12:06 - 00000932 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000UA.job
2016-12-27 16:48 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\tracing
2016-12-27 09:10 - 2014-06-27 00:09 - 00000000 ____D C:\Program Files\SupraSavings
2016-12-27 09:02 - 2014-01-23 16:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection
2016-12-27 09:01 - 2012-01-26 15:32 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2016-12-27 08:55 - 2014-01-02 12:32 - 00252842 _____ C:\Windows\ntbtlog.txt
2016-12-27 08:34 - 2011-08-23 12:32 - 00000000 ____D C:\Users\Teresa\AppData\Roaming\Skype
2016-12-26 23:41 - 2014-05-19 20:42 - 00000178 _____ C:\Users\Teresa\AppData\Roaming\WB.CFG
2016-12-26 23:40 - 2011-12-26 22:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-12-26 23:35 - 2009-07-13 21:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-12-26 23:35 - 2009-07-13 21:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-12-26 18:24 - 2011-12-26 21:27 - 00000000 ____D C:\Users\Teresa\AppData\Local\ElevatedDiagnostics
2016-12-26 18:24 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
==================== Files in the root of some directories =======
2013-12-29 17:59 - 2013-12-29 17:59 - 49940480 _____ () C:\Program Files (x86)\GUT2C1F.tmp
2014-05-19 20:51 - 2014-05-19 20:52 - 0001186 _____ () C:\Users\Teresa\AppData\Roaming\aps.scan.quick.results
2014-05-19 20:51 - 2014-05-19 20:51 - 0000000 _____ () C:\Users\Teresa\AppData\Roaming\aps.scan.results
2014-05-19 20:51 - 2014-05-19 20:52 - 0000320 _____ () C:\Users\Teresa\AppData\Roaming\aps.uninstall.scan.results
2014-05-19 20:42 - 2016-12-26 23:41 - 0000178 _____ () C:\Users\Teresa\AppData\Roaming\WB.CFG
2014-05-19 20:46 - 2014-05-19 06:19 - 1705063 _____ (AnyProtect.com) C:\Users\Teresa\AppData\Local\AnyProtectScannerSetup.exe
2012-01-23 20:45 - 2012-12-08 17:31 - 0008192 _____ () C:\Users\Teresa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-02-04 18:42 - 2013-02-04 18:42 - 0000017 _____ () C:\Users\Teresa\AppData\Local\resmon.resmoncfg
2011-05-04 16:07 - 2011-05-04 16:10 - 0015211 _____ () C:\ProgramData\ArcadeDeluxe5.log
2012-05-19 11:00 - 2014-03-16 11:49 - 0009733 _____ () C:\ProgramData\hpzinstall.log
2014-01-18 15:22 - 2014-01-18 15:25 - 0000032 _____ () C:\ProgramData\PS.log
Some files in TEMP:
====================
C:\Users\Teresa\AppData\Local\Temp\BackupSetup.exe
C:\Users\Teresa\AppData\Local\Temp\BearShare_setup.exe
C:\Users\Teresa\AppData\Local\Temp\conduitinstaller.exe
C:\Users\Teresa\AppData\Local\Temp\DefaultAssets.exe
C:\Users\Teresa\AppData\Local\Temp\DefaultOfflineContent.exe
C:\Users\Teresa\AppData\Local\Temp\dlLogic.exe
C:\Users\Teresa\AppData\Local\Temp\eTypeSetup.exe
C:\Users\Teresa\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe
C:\Users\Teresa\AppData\Local\Temp\GCVerifier.dll
C:\Users\Teresa\AppData\Local\Temp\HitmanPro.exe
C:\Users\Teresa\AppData\Local\Temp\ICReinstall_MediaCodec.exe
C:\Users\Teresa\AppData\Local\Temp\iMesh_setup.exe
C:\Users\Teresa\AppData\Local\Temp\incredibar_installer.exe
C:\Users\Teresa\AppData\Local\Temp\Installhelper.dll
C:\Users\Teresa\AppData\Local\Temp\jre-7u11-windows-i586-iftw.exe
C:\Users\Teresa\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Teresa\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe
C:\Users\Teresa\AppData\Local\Temp\mconduitinstaller.exe
C:\Users\Teresa\AppData\Local\Temp\MindsparkAssets.exe
C:\Users\Teresa\AppData\Local\Temp\minibar-master.exe
C:\Users\Teresa\AppData\Local\Temp\NLStubInstallerResources.dll
C:\Users\Teresa\AppData\Local\Temp\nsb27D7.exe
C:\Users\Teresa\AppData\Local\Temp\nsb6CC9.tmp.exe
C:\Users\Teresa\AppData\Local\Temp\nsb8C2D.exe
C:\Users\Teresa\AppData\Local\Temp\nsbF0A9.exe
C:\Users\Teresa\AppData\Local\Temp\nsc8C14.exe
C:\Users\Teresa\AppData\Local\Temp\nscA2A1.exe
C:\Users\Teresa\AppData\Local\Temp\nscACE6.exe
C:\Users\Teresa\AppData\Local\Temp\nsd1B91.exe
C:\Users\Teresa\AppData\Local\Temp\nsd89EB.exe
C:\Users\Teresa\AppData\Local\Temp\nse4790.exe
C:\Users\Teresa\AppData\Local\Temp\nse9DB.exe
C:\Users\Teresa\AppData\Local\Temp\nseF7F5.exe
C:\Users\Teresa\AppData\Local\Temp\nsgC7FA.exe
C:\Users\Teresa\AppData\Local\Temp\nsjF199.exe
C:\Users\Teresa\AppData\Local\Temp\nsk8FD7.exe
C:\Users\Teresa\AppData\Local\Temp\nskC92.exe
C:\Users\Teresa\AppData\Local\Temp\nslB4F2.exe
C:\Users\Teresa\AppData\Local\Temp\nso3F26.exe
C:\Users\Teresa\AppData\Local\Temp\nso5C19.exe
C:\Users\Teresa\AppData\Local\Temp\nsoBAAD.exe
C:\Users\Teresa\AppData\Local\Temp\nsr1C4D.exe
C:\Users\Teresa\AppData\Local\Temp\nsrB9D9.exe
C:\Users\Teresa\AppData\Local\Temp\nsrDDE7.exe
C:\Users\Teresa\AppData\Local\Temp\nsrF8FA.exe
C:\Users\Teresa\AppData\Local\Temp\nst7709.exe
C:\Users\Teresa\AppData\Local\Temp\nsuDAD.exe
C:\Users\Teresa\AppData\Local\Temp\nsw68B.exe
C:\Users\Teresa\AppData\Local\Temp\nsz21CF.exe
C:\Users\Teresa\AppData\Local\Temp\nsz36AA.exe
C:\Users\Teresa\AppData\Local\Temp\nsz5E36.exe
C:\Users\Teresa\AppData\Local\Temp\optprosetup.exe
C:\Users\Teresa\AppData\Local\Temp\PCCU_Installer.exe
C:\Users\Teresa\AppData\Local\Temp\SecondStepInstaller.exe
C:\Users\Teresa\AppData\Local\Temp\SendMsg.dll
C:\Users\Teresa\AppData\Local\Temp\setup.exe
C:\Users\Teresa\AppData\Local\Temp\SetupDataMngr_Searchqu.exe
C:\Users\Teresa\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Teresa\AppData\Local\Temp\SpOrder.dll
C:\Users\Teresa\AppData\Local\Temp\SPStub.exe
C:\Users\Teresa\AppData\Local\Temp\SRAssetsHelper.dll
C:\Users\Teresa\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\Teresa\AppData\Local\Temp\System.Data.SQLite64855.dll
C:\Users\Teresa\AppData\Local\Temp\tbRad0.dll
C:\Users\Teresa\AppData\Local\Temp\tbSom0.dll
C:\Users\Teresa\AppData\Local\Temp\tbuTor.dll
C:\Users\Teresa\AppData\Local\Temp\tbVisu.dll
C:\Users\Teresa\AppData\Local\Temp\Toolbar_Phpnuke.exe
C:\Users\Teresa\AppData\Local\Temp\vbmz12.exe
C:\Users\Teresa\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Teresa\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Teresa\AppData\Local\Temp\verifier.exe
C:\Users\Teresa\AppData\Local\Temp\_Re-markitV37.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-12-26 18:17
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-12-2016
Ran by [removed] (27-12-2016 17:04:48)
Running from C:\Users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VITUUM5Z
Windows 7 Home Premium Service Pack 1 (X64) (2011-08-17 05:46:08)
Boot Mode:
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-504136971-1847211166-3120143677-500 - Administrator - Disabled)
Guest (S-1-5-21-504136971-1847211166-3120143677-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-504136971-1847211166-3120143677-1002 - Limited - Enabled)
Teresa (S-1-5-21-504136971-1847211166-3120143677-1000 - Administrator - Enabled) => C:\Users\Teresa
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Norton Internet Security (Disabled - Out of date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton Internet Security (Disabled - Out of date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton Internet Security (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
Acer Backup Manager (HKLM-x32\…\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.85 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1523 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.0.1523 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Acer Incorporated)
Acer Games (HKLM-x32\…\WildTangent acer Master Uninstall) (Version: 1.0.2.4 - WildTangent)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.03.3004 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\…\Acer Screensaver) (Version: 1.1.0301.2011 - Acer Incorporated)
Acer Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3005 - Acer Incorporated)
Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\…\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Agatha Christie - 4:50 from Paddington (x32 Version: 2.2.0.95 - WildTangent) Hidden
AnyProtect (HKLM-x32\…\AnyProtect) (Version: 1.0.0.0 - CMI Limited) <==== ATTENTION
Apple Application Support (HKLM-x32\…\{63EC2120-1742-4625-AA47-C6A8AEC9C64C}) (Version: 2.2.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}) (Version: 6.0.0.59 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Backup Manager V3 (x32 Version: 3.0.0.85 - NTI Corporation) Hidden
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom Gigabit NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.6.1.2 - Broadcom Corporation)
BrowserCompanion (HKLM-x32\…\BrowserCompanion) (Version: - ) <==== ATTENTION
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
Build-a-lot 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Coupon Downloader (HKLM\…\Coupon Downloader) (Version: - SupraSavings) <==== ATTENTION
D1600 (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
DJ_SF_06_D1600_SW_Min (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden
ExTraShoPPeR (HKLM-x32\…\{7BCAC0EB-3993-2416-0531-848C39DF8B65}) (Version: - "") <==== ATTENTION
Facebook Video Calling 3.1.0.521 (HKLM-x32\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fast And Safe (HKLM-x32\…\{5F189DF5-2D05-472B-9091-84D9848AE48B}{64af91bf}) (Version: - GTgroup) <==== ATTENTION
FATE - The Traitor Soul (x32 Version: 2.2.0.95 - WildTangent) Hidden
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Drive (HKLM-x32\…\{D9F75285-4864-461D-83DA-8D056BAC44D1}) (Version: 1.16.6866.4367 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HP Deskjet D1600 Printer Driver Software 13.0 Rel .6 (HKLM\…\{2CD0168D-FBBC-4667-8810-105CB6EC6348}) (Version: 13.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Print Projects 1.0 (HKLM\…\HP Print Projects) (Version: 1.0 - HP)
HP Smart Web Printing 4.5 (HKLM\…\HP Smart Web Printing) (Version: 4.5 - HP)
HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM-x32\…\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: 4.000.011.006 - Hewlett-Packard)
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
hpPrintProjects (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
hpWLPGInstaller (x32 Version: 130.0.303.000 - Hewlett-Packard) Hidden
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3006 - Acer Incorporated)
iLivid (HKLM-x32\…\iLivid) (Version: 1.92 - Bandoo Media Inc) <==== ATTENTION
iMesh (HKLM-x32\…\iMesh) (Version: 12.0.0.130408 - iMesh Inc.) <==== ATTENTION
iMesh (x32 Version: 12.0.0.130408 - iMesh Inc.) Hidden <==== ATTENTION
InstallVC90Support (x32 Version: 1.01.0000 - Novatel Wireless) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2182 - Intel Corporation)
iTunes (HKLM\…\{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}) (Version: 10.7.0.21 - Apple Inc.)
Java(TM) 7 Update 5 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217005FF}) (Version: 7.0.50 - Oracle)
JavaFX 2.1.1 (HKLM-x32\…\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jewel Quest Heritage (x32 Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.5 - Acer Inc.)
LUckyCOUpoon (HKLM-x32\…\{BA5D43C9-D633-D0EC-CFEA-2ABA974B333D}) (Version: - LuckyCoupon) <==== ATTENTION
MapsGalaxy (HKLM-x32\…\MapsGalaxy_39bar Uninstall) (Version: - MapsGalaxy)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\…\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5131.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mobile Broadband Generic Drivers (HKLM-x32\…\{333494BF-7B36-4681-896A-C7AB23D31E17}) (Version: 2.03.25.001.11 - Novatel Wireless)
Mobile Connect (HKLM\…\{B12E09C4-C55E-48BD-9732-C68AB92DE847}) (Version: 4.02.0031.0 - Smith Micro)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 9.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 9.0.1 (x86 en-US)) (Version: 9.0.1 - Mozilla)
MP3 Rocket (HKLM-x32\…\MP3 Rocket) (Version: - )
MyPC Backup (HKLM\…\MyPC Backup) (Version: - JDi Backup Ltd) <==== ATTENTION
Mysearchdial (HKLM-x32\…\mysearchdial) (Version: - Mysearchdial) <==== ATTENTION
Mystery P.I. - Stolen in San Francisco (x32 Version: 2.2.0.95 - WildTangent) Hidden
MyWebFace Internet Explorer Toolbar (HKLM-x32\…\MyWebFace_5abar Uninstall Internet Explorer) (Version: - Mindspark Interactive Network) <==== ATTENTION
Namco All-Stars: PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden
Norton Internet Security (HKLM-x32\…\NIS) (Version: 20.5.0.28 - Symantec Corporation)
Norton Online Backup (HKLM-x32\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
Norton PC Checkup (HKLM-x32\…\Norton PC Checkup_is1) (Version: 3.0.5.71.0 - Symantec Corporation)
NTI Media Maker 9 (HKLM-x32\…\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8942 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.8942 - NTI Corporation) Hidden
Optimizer Pro v3.2 (HKLM-x32\…\Optimizer Pro_is1) (Version: - ) <==== ATTENTION
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
PriceDoownlloader (HKLM-x32\…\{2D471A31-4FA7-95BA-1880-D441113ED736}) (Version: - PRIceDownLoaaderr) <==== ATTENTION
PrOOShoepper (HKLM-x32\…\{8F213470-964F-4092-6B31-BC7570F31B5A}) (Version: - PiroShoappperr) <==== ATTENTION
Rapport (x32 Version: 3.5.1404.61 - Trusteer) Hidden
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30124 - Realtek Semiconductor Corp.)
Re-markit (HKLM-x32\…\DBD5527E-9DDF-2BF0-9B71-93D32BDD7FDD) (Version: - Re-markit-software) <==== ATTENTION
saverneti (HKLM-x32\…\{614925F9-841A-53FE-A28F-DC30FA07239B}) (Version: - savieronnet) <==== ATTENTION
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 6.16 (HKLM-x32\…\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SuperManCoupon (HKLM-x32\…\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - SuperManCoupon) <==== ATTENTION
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
Torchlight (x32 Version: 2.2.0.95 - WildTangent) Hidden
TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden
Trusteer Endpoint Protection (HKLM-x32\…\Rapport_msi) (Version: 3.5.1404.61 - Trusteer)
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
v9 uninstaller (HKLM-x32\…\v9 uninstaller) (Version: - v9)
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95 - WildTangent) Hidden
VisualBee for Microsoft PowerPoint (HKU\S-1-5-21-504136971-1847211166-3120143677-1000\…\VisualBee for Microsoft PowerPoint) (Version: V3.6 - VisualBee.com)
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Websaver (HKLM-x32\…\{5CDF2354-26AF-2DBC-1012-44FEDFCC75BB}) (Version: - Websavver) <==== ATTENTION
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.02.3102 - Acer Incorporated)
WildTangent Games App (Acer Games) (x32 Version: 4.0.5.36 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Zuma's Revenge (x32 Version: 2.2.0.95 - WildTangent) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0AC44FBC-E220-4E15-8B15-9D0B7EA42962} - System32\Tasks\Re-markit Update => C:\Program Files (x86)\Re-markit-soft\Re-markitj73.exe [2014-07-19] () <==== ATTENTION
Task: {1E652AFE-E14F-4238-91CF-F22848870A26} - System32\Tasks\Re-markit_wd => C:\Program Files (x86)\Re-markit-soft\Re-markitw.exe [2014-07-19] () <==== ATTENTION
Task: {35D64B9F-A9F4-41AB-94FA-4CA19622304A} - System32\Tasks\{0AD51ECA-09F6-43C2-BB66-40A5DA138F34} => C:\Program Files (x86)\MP3 Rocket\MP3Rocket.exe [2012-05-09] ()
Task: {6CD519A0-A5D2-4F64-8AB5-8BDD7473961A} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe [2014-03-14] (MyPCBackup.com) <==== ATTENTION
Task: {7066A1FB-068F-4CAE-9CFD-23B67F57A73E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-26] (Adobe Systems Incorporated)
Task: {7096EC12-5813-473C-B80D-2EF9397C94DA} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {77DE6872-4424-4406-83D5-11A8B305FC55} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000UA => C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-11] (Facebook Inc.)
Task: {8265B201-9E57-4B5F-B330-9C1C8277E2D8} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\SymErr.exe [2013-06-03] (Symantec Corporation)
Task: {8D8BD5F9-FCB9-42B0-BAFE-5CB5905DB422} - System32\Tasks\Speedial => C:\Users\Teresa\AppData\Roaming\Speedial\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {8EAD082B-D456-4DE6-BB72-2E505B183147} - System32\Tasks\VisualBeeRecovery => C:\Users\Teresa\AppData\Local\VisualBeeExe\VisualBeeRecovery.exe [2012-03-14] () <==== ATTENTION
Task: {9BC3AF30-DCE7-4456-AAA0-C5CB21F75A0F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000Core => C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-11] (Facebook Inc.)
Task: {A2D208A8-BAF0-4506-8E9D-0383014E7E1D} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\SymErr.exe [2013-06-03] (Symantec Corporation)
Task: {D3211F0A-FF58-4495-99DC-B6048B355F20} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-22] (Google Inc.)
Task: {D593745A-1AD4-4B47-A97B-EF68CAB6F3AB} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\WSCStub.exe [2014-04-29] (Symantec Corporation)
Task: {E9FD0CF4-8115-4F06-8426-694915405C59} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-22] (Google Inc.)
Task: {EF396D68-E8AB-452B-A20A-C7FFD5E56572} - System32\Tasks\MySearchDial => C:\Users\Teresa\AppData\Roaming\MySearchDial\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000Core.job => C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-504136971-1847211166-3120143677-1000UA.job => C:\Users\Teresa\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\Teresa\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\Re-markit Update.job => C:\Program Files (x86)\Re-markit-soft\Re-markitj73.exe <==== ATTENTION
Task: C:\Windows\Tasks\Re-markit_wd.job => C:\Program Files (x86)\Re-markit-soft\Re-markitw.exe <==== ATTENTION
Task: C:\Windows\Tasks\Speedial.job => C:\Users\Teresa\AppData\Roaming\Speedial\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (2).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
ShortcutWithArgument: C:\Users\Teresa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.v9.com/?type=sc&ts;=1402690892&from;=adks&uid;=TOSHIBAXMK3259GSXP_31QOD04DBXX31QOD04DB&i;=psd&t;=34411a4f9
==================== Loaded Modules (Whitelisted) ==============
2014-05-19 15:20 - 2014-07-19 22:16 - 00097792 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markitw.exe
2011-02-18 10:48 - 2011-02-18 10:48 - 00092504 _____ () C:\Program Files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
2014-07-19 22:16 - 2014-07-19 22:16 - 00160768 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markitBG175.exe
2014-06-25 10:58 - 2014-06-25 10:58 - 00172544 _____ () C:\Program Files (x86)\CDDCF87A-3EAD-40C4-8099-34C6869D3E9D\SupraSavingsService64.exe
2014-06-12 12:05 - 2014-06-12 12:05 - 00110080 _____ () C:\Program Files (x86)\CDDCF87A-3EAD-40C4-8099-34C6869D3E9D\nfapi.dll
2014-06-12 12:05 - 2014-06-12 12:05 - 00456192 _____ () C:\Program Files (x86)\CDDCF87A-3EAD-40C4-8099-34C6869D3E9D\ProtocolFilters.dll
2014-06-13 13:42 - 2014-06-13 13:42 - 00706560 _____ () C:\Program Files\003\vxlsnyaiet64.exe
2014-07-19 22:16 - 2014-07-19 22:16 - 00422400 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markitj73.exe
2014-07-03 23:18 - 2014-07-03 23:18 - 00186192 _____ () c:\ProgramData\Fast And Safe\FastAndSafeSvc.dll
2014-07-03 23:18 - 2014-07-03 23:18 - 04125696 _____ () c:\ProgramData\Fast And Safe\FastAndSafe.dll
2014-06-13 14:16 - 2014-06-13 14:16 - 00186496 _____ () c:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll
2014-06-13 14:16 - 2014-06-13 14:16 - 03000776 _____ () c:\Program Files (x86)\Optimizer Pro\OptProCrash.dll
2011-11-01 23:26 - 2011-11-01 23:26 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-11-01 23:26 - 2011-11-01 23:26 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-02-15 11:37 - 2011-02-15 11:37 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2011-02-15 11:36 - 2011-02-15 11:36 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2011-02-15 11:37 - 2011-02-15 11:37 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2014-07-19 22:16 - 2014-07-19 22:16 - 00171520 _____ () C:\Program Files (x86)\Re-markit-soft\Re-markitBG175.dll
2014-05-02 01:35 - 2012-05-29 23:51 - 00699280 ____R () C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.5.0.28\wincfi39.dll
2014-03-23 16:04 - 2014-03-23 16:04 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:373E1720 [118]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="3"
e"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-504136971-1847211166-3120143677-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Teresa\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{2EA1B7D1-33A0-41CE-B717-85B54487E5C5}C:\program files (x86)\java\jre7\bin\javaw.exe] => C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{36CFCEED-2BC5-4BF9-8F09-94071B94F244}C:\program files (x86)\java\jre7\bin\javaw.exe] => C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{20485983-4894-4690-B68C-558A8C2C1ACF}] => C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe
FirewallRules: [{5E59B09D-A799-4BA1-B58B-69E65A770351}] => C:\Program Files (x86)\BearShare Applications\BearShare\BearShare.exe
FirewallRules: [{4E7CB2FE-92C9-4BBF-A943-2391C7EED270}] => C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{E8B371CF-D704-4131-BFF1-FB82796669E7}C:\users\teresa\appdata\local\facebook\video\skype\facebookvideocalling.exe] => C:\users\teresa\appdata\local\facebook\video\skype\facebookvideocalling.exe
FirewallRules: [UDP Query User{02CC8718-A8BB-48FD-B9C7-BAA600B49B46}C:\users\teresa\appdata\local\facebook\video\skype\facebookvideocalling.exe] => C:\users\teresa\appdata\local\facebook\video\skype\facebookvideocalling.exe
FirewallRules: [{580697C3-3EA8-4D9F-9FB1-8879B212997C}] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{E90A528C-2DB6-4B73-A201-B9FA9D4F9381}] => C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{3B682BBB-19C8-4A01-9149-ED2E4A85C089}] => C:\Program Files (x86)\iMesh Applications\iMesh\iMesh.exe
FirewallRules: [{FB5A0965-EB93-406E-83C6-3B837D8CCA57}] => C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{1E6849BF-0FE3-4594-ABE6-481485477CAF}] => LPort=2869
FirewallRules: [{1143AE03-1067-45B6-BFFB-32B641E5D226}] => LPort=1900
FirewallRules: [{6642BE79-FFAC-443B-8161-16FEE295D939}] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{D8B78F3C-20ED-4806-A8DD-ECB482895D77}] => C:\Users\Teresa\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
==================== Restore Points =========================
02-07-2014 09:37:48 Scheduled Checkpoint
03-07-2014 16:18:18 Installed Rapport
12-07-2014 01:49:25 Windows Update
13-07-2014 05:12:12 Windows Update
02-08-2014 19:33:45 Windows Update
14-10-2014 13:07:31 Windows Update
26-11-2014 20:38:10 Windows Modules Installer
26-12-2016 18:24:21 Scheduled Checkpoint
==================== Faulty Device Manager Devices =============
Name: Link-Layer Topology Discovery Responder
Description: Link-Layer Topology Discovery Responder
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: rspndr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Link-Layer Topology Discovery Mapper I/O Driver
Description: Link-Layer Topology Discovery Mapper I/O Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: lltdio
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: avast! Firewall NDIS Filter Miniport
Description: avast! Firewall NDIS Filter Miniport
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: ALWIL Software
Service: aswNdis
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
Name: avast! Firewall NDIS Filter Miniport
Description: avast! Firewall NDIS Filter Miniport
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: ALWIL Software
Service: aswNdis
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: RapportEI64
Description: RapportEI64
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: RapportEI64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: RapportKE64
Description: RapportKE64
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: RapportKE64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: RapportPG64
Description: RapportPG64
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: RapportPG64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Symantec Network Security WFP Driver
Description: Symantec Network Security WFP Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SymNetS
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/27/2016 04:55:58 PM) (Source: Customer Experience Improvement Program) (EventID: 1006) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being consolidated into files that can be sent to Microsoft, (Error 80004005).
Error: (12/27/2016 04:55:45 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (12/27/2016 04:52:40 PM) (Source: Software Protection Platform Service) (EventID: 1001) (User: )
Description: The Software Protection service failed to start. 0x80070002
6.1.7601.17514
Error: (12/27/2016 04:49:53 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 25633367
Error: (12/27/2016 04:49:53 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 25633367
Error: (12/27/2016 04:49:53 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (12/27/2016 04:49:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 25617767
Error: (12/27/2016 04:49:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 25617767
Error: (12/27/2016 04:49:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (12/27/2016 04:49:21 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 25602167
System errors:
=============
Error: (12/27/2016 04:57:02 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error:
An instance of the service is already running.
Error: (12/27/2016 04:57:02 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Multimedia Class Scheduler service, but this action failed with the following error:
An instance of the service is already running.
Error: (12/27/2016 04:57:02 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Computer Browser service, but this action failed with the following error:
An instance of the service is already running.
Error: (12/27/2016 04:56:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.
Error: (12/27/2016 04:56:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.
Error: (12/27/2016 04:56:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.
Error: (12/27/2016 04:55:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.
Error: (12/27/2016 04:55:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.
Error: (12/27/2016 04:55:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.
Error: (12/27/2016 04:55:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RapportIaso service failed to start due to the following error:
{Application Error}
The application was unable to start correctly (0x%lx). Click OK to close the application.
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU P4600 @ 2.00GHz
Percentage of memory in use: 93%
Total physical RAM: 2806.7 MB
Available physical RAM: 185.94 MB
Total Virtual: 5611.59 MB
Available Virtual: 2209.2 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:281.99 GB) (Free:165.35 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: D65CE497)
Partition 1: (Not Active) - (Size=16 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=282 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================