Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

virus - can only boot in safe mode, antivirus infected [Closed]


  • This topic is locked This topic is locked

#1
Jdailey91

Jdailey91

    Member

  • Member
  • PipPip
  • 18 posts

Hello and thanks for the help in advance!

(I am helping my friend fix his computer, so if I sound technical and ignorant that's why lol)

I am running Windows 8.1 (64bit). My friend said he downloaded a program from cnet and he thinks that program also installed a program called Pokki. He said he deleted it when he noticed it, but when I ran autoruns.exe from microsoft (sysinternals.com) I saw entries for Pokki but it didn't give me the locations of the files and said they were missing.

The one out of ten times we can boot the computer normally, whatever virus is still on here slows the computer down so much I can't open task manager or any other programs. I'm in safe mode with networking right now. The virus corrupted AVG and that will not run now. I downloaded and attempted to install and run avast, but that won't run in safe mode, that or it couldn't properly install in safe mode (it gave me no errors saying that though).

I can't find one abnormal thing running in safe mode, so I don't have any leads on where to start to remove the viruses still on here.

Malwarebytes log incoming...

p.s.
Your link to malwarebytes didn't work for me, it probably needs updated.


  • 0

Advertisements


#2
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,590 posts

Hi. My name is Brian, and I would be happy to look into your issue.
 


- General Instructions -

  • Please read all instructions and fixes thoroughly. Read the ENTIRE post BEFORE performing any steps so you understand all that needs to be done.
  • I would advise printing any instructions for easy reference as some of the fixes may require you to boot in Safe mode. Access to these instructions may not be available in Safe Mode.
  • Any fixes provided by myself are for this log file only and should not be used on any other systems.
  • Do not run any other removal software or perform updates other than the ones I provide, as it will complicate the cleaning process.
  • It's very likely that part of our cleanup will include emptying your recycle bin. If you use your recycle bin as an archive and do not wish this to be emptied, please let me know.
  • You have 4 days to reply to each post or the topic will be closed. You will be able to request that the topic be re-opened by sending me a PM (Personal Message) or PM a moderator.
  • Please feel free to ask any questions, especially if you are having problems with my instructions.


- Save ALL Tools to your Desktop-

 

All tools that I have you download should be placed on the desktop unless otherwise stated. If you are familiar with how to save files to the desktop then you can skip this step.
 
Since you are continuing with this step then I assume you are unfamiliar with saving files to your desktop. As a result it's easiest if you configure your browser(s) to download any tools to the desktop by default. Please use the appropriate instructions below depending on the browser you are using.
Chrome.JPGGoogle Chrome - Click the "Customize and control Google Chrome" button in the upper right-corner of the browser.Settings.JPG Choose Settings. at the bottom of the screen click the
"Show advanced settings..." link. Scroll down to find the Downloads section and click the Change... button. Select your desktop and click OK.
Firefox.JPGMozilla Firefox - Click the "Open Menu" button in the upper right-corner of the browser. Settings.JPG Choose Options. In the downloads section, click the Browse button, click on the Desktop folder
and the click the "Select Folder" button. Click OK to get out of the Options menu.
IE.jpgInternet Explorer - Click the Tools menu in the upper right-corner of the browser. Tools.JPG Select View downloads. Select the Options link in the lower left of the window. Click Browse and
select the Desktop and then choose the Select Folder button. Click OK to get out of the download options screen and then click Close to get out of the View Downloads screen.
NOTE: IE8 Does not support changing download locations in this manner. You will need to download the tool(s) to the default folder, usually Downloads, then copy them to the desktop.
 

- Finally Before We Start-

 
Removing malware is a complicated multiple step process, Please stay with me until I have declared your system clean. I strongly recommend you backup your personal files and folders. Although rare, attempting to remove malware can render your machine unbootable or cause data loss. Having backups of your data is your responsibility. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.

 

 

 

 

Let's take a look. Can you download the following tool but run it when you are normally booted instead of Safe Mode with Networking? If you can't then simply run it in Safe Mode With Networking.

 

Step#1 - FRST Scan
1. Please download Farbar Recovery Scan Tool and save it to your Desktop.
    Note: You need to run the 64-bit Version so please ensure you download that one.
2. Right click to run as administrator. When the tool opens click Yes to disclaimer.
3. Please ensure you place a check mark in the Addition.txt check box at the bottom of the form before running (if not already).
4. Press Scan button.
5. It will produce a log called FRST.txt in the same directory the tool is run from (which should now be the desktop)
6. Please copy and paste log back here.
7. Another log (Addition.txt - also located in the same directory as FRST64.exe) will be generated Please also paste that along with the FRST.txt into your reply.

 

 


  • 0

#3
Jdailey91

Jdailey91

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts

Should I continue or cancel the malwarebytes scan for it's log? I know I'm not supposed to run two scans at once.


  • 0

#4
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,590 posts

You can finish the Malwarebytes scan first if you wish. Ensure you click the View detailed log link at the end of the scan, click the Copy to clipboard button and paste the log in your next post along with the FRST scan. But again if you are able to run the FRST scan from normal mode instead of Safe Mode With Networking that would be ideal.

 

Thank you.


  • 0

#5
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,590 posts

I should have said to post the Malwarebytes log when it's done. Then reboot into Normal mode and run the FRST scan and post the FRST and Addition logs.

 

Thanks.


  • 0

#6
Jdailey91

Jdailey91

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 1/15/2015
Scan Time: 7:45:47 PM
Logfile: 
Administrator: Yes
 
Version: 2.00.4.1028
Malware Database: v2015.01.15.16
Rootkit Database: v2015.01.14.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Josh
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 327331
Time Elapsed: 51 min, 57 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 2
PUP.Optional.AZLyrics.A, C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage, , [5a62e1162663979fa30e50240300b14f], 
PUP.Optional.AZLyrics.A, C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal, , [f7c572856623e84e03ae353fae55b14f], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
And I was not able to boot up into safe mode. ): 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-01-2015 01
Ran by Josh at 2015-01-15 20:39:38
Running from C:\Users\Josh\Desktop
Boot Mode: Safe Mode (with Networking)
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: AVG AntiVirus Free Edition 2015 (Enabled - Out of date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Out of date) {B5F5C120-2089-702E-0001-553BB0D5A664}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
4 Elements II (x32 Version: 2.2.0.98 - WildTangent) Hidden
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version:  - )
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.3.183.90 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.)
Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version:  - Hidden Path Entertainment, Ensemble Studios)
Archeage (HKLM-x32\...\Glyph Archeage) (Version:  - Trion Worlds, Inc.)
Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.00 - Ubisoft)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5645 - AVG Technologies)
AVG 2015 (Version: 15.0.4260 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.5645 - AVG Technologies) Hidden
Azkend 2: The World Beneath (x32 Version: 2.2.0.98 - WildTangent) Hidden
Barn Yarn Collector's Edition (x32 Version: 3.0.2.48 - WildTangent) Hidden
Batman: Arkham Asylum GOTY Edition (HKLM-x32\...\Steam App 35140) (Version:  - Rocksteady Studios)
Batman: Arkham City GOTY (HKLM-x32\...\Steam App 200260) (Version:  - Rocksteady Studios)
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Build-a-lot Mysteries (x32 Version: 3.0.2.51 - WildTangent) Hidden
Building the Great Wall of China Collector's Edition (x32 Version: 3.0.2.48 - WildTangent) Hidden
Bully Scholarship Edition (HKLM-x32\...\InstallShield_{A724605D-B399-4304-B8C7-33B3EF7D4677}) (Version: 1.00.0154 - Rockstar Games)
Bully Scholarship Edition (x32 Version: 1.00.0154 - Rockstar Games) Hidden
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco NAC Agent  (HKLM-x32\...\{3657178B-CDB0-46B0-8C43-E1FB50DA313D}) (Version: 4.9.4.3 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Curse at Twilight (x32 Version: 3.0.2.51 - WildTangent) Hidden
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.6.3728 - CyberLink Corp.)
CyberLink MediaEspresso 6.7 (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.7.1.5112 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.4.4824 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.6.3821 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.6.3912 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 5.0.3.3907 - CyberLink Corp.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Dead Space 2 (HKLM-x32\...\{8A96EA3C-7FDD-4B98-872E-1A20572BED61}_is1) (Version: Dead Space 2 - eviboss)
Delicious - Emily's Wonder Wedding Premium Edition (x32 Version: 3.0.2.48 - WildTangent) Hidden
DisableMSDefender (Version: 1.0.0 - Hewlett-Packard Company) Hidden
Dolphin x86 (HKLM-x32\...\Dolphin x86) (Version: 4.0.2 - Dolphin Development Team)
Energy Star (HKLM\...\{465CA2B6-98AF-4E77-BE22-A908C34BB9EC}) (Version: 1.0.9 - Hewlett-Packard Company)
Evernote v. 5.2 (HKLM-x32\...\{412F6426-A3C7-11E3-8A71-00163E98E7D6}) (Version: 5.2.0.2951 - Evernote Corp.)
Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Fishdom 3: Collector's Edition (x32 Version: 3.0.2.38 - WildTangent) Hidden
Fort Defense (x32 Version: 3.0.2.51 - WildTangent) Hidden
FrostWire 5.7.7 (HKLM-x32\...\FrostWire 5) (Version: 5.7.7.1 - FrostWire LLC)
Glyph (HKLM-x32\...\Glyph) (Version:  - Trion Worlds, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
HP 3D DriveGuard (HKLM-x32\...\{F90A86C9-7779-47DD-AC06-8EE832C55F55}) (Version: 6.0.18.1 - Hewlett-Packard Company)
HP CoolSense (HKLM-x32\...\{E2C8D0C2-1C97-4C05-939A-5B13A0FE655C}) (Version: 2.20.31 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\...\{4C0ABC2F-CC83-4417-8B3E-A26A04FBB860}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7493.4758 - Hewlett-Packard)
HP SimplePass (HKLM-x32\...\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.01.11 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\...\{8C696B4B-6AB1-44BC-9416-96EAC474CABE}) (Version: 7.5.2.12 - Hewlett-Packard Company)
HP System Event Utility (HKLM-x32\...\{E9FA2CA2-B7B2-43E6-8449-A1618B042EAE}) (Version: 1.1.3 - Hewlett-Packard Company)
HP Utility Center (HKLM\...\{36F80C5F-DC0D-4DF4-AF09-DC1867F0EB0A}) (Version: 2.4.4 - Hewlett-Packard Company)
HP Wireless Button Driver (HKLM-x32\...\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company)
Inst5675 (Version: 8.01.11 - Softex Inc.) Hidden
Inst5676 (Version: 8.01.11 - Softex Inc.) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3540 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.9.0.1001 - Intel Corporation)
Intel® Smart Connect Technology (HKLM\...\{6EB4AC9E-01E9-4B8C-96C8-281ECAF3A687}) (Version: 5.0.10.2793 - Intel Corporation)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Joining Hands 2 (x32 Version: 3.0.2.51 - WildTangent) Hidden
King Oddball (x32 Version: 3.0.2.48 - WildTangent) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Lost in Reefs 2 (x32 Version: 3.0.2.51 - WildTangent) Hidden
LUXOR Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Medieval II: Total War (HKLM-x32\...\Steam App 4700) (Version:  - The Creative Assembly)
Microsoft Office Home and Student 2013 - en-us (HKLM\...\HomeStudentRetail - en-us) (Version: 15.0.4675.1003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Mystery P.I. - Curious Case of Counterfeit Cove (x32 Version: 2.2.0.98 - WildTangent) Hidden
NVIDIA GeForce Experience 2.1.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.5 - NVIDIA Corporation)
NVIDIA Graphics Driver 344.75 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.75 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2-r5875) (Version:  - )
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
Pinger (HKLM-x32\...\Pinger 1.4.0.1) (Version: 1.4.0.1 - Pinger Inc.)
Pinger (x32 Version: 1.4.0.1 - Pinger Inc.) Hidden
Pinnacle Game Profiler (HKLM-x32\...\{49BF48CC-ABB6-4795-9B35-B5DE005D8612}) (Version: 8.0.0 - PowerUp Software)
PlanetSide 2 (HKLM-x32\...\Steam App 218230) (Version:  - Sony Online Entertainment)
PlanetSide 2 (HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\SOE-PlanetSide 2) (Version:  - Sony Online Entertainment)
Plants vs. Zombies - Game of the Year (x32 Version: 3.0.2.51 - WildTangent) Hidden
Polar Bowler 1st Frame (x32 Version: 3.0.2.59 - WildTangent) Hidden
Razer Synapse 2.0 (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.18.23036 - Razer Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21247 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7213 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.00.13.1216 - REALTEK Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Roads of Rome 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
SHIELD Streaming (Version: 3.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.18.9 - NVIDIA Corporation) Hidden
Sid Meiers Civilization Beyond Earth (HKLM-x32\...\U2lkTWVpZXJzQ2l2aWxpemF0aW9uQmV5b25kRWFydGg=_is1) (Version: 1 - )
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Sid Meier's Civilization V Brave New World (HKLM-x32\...\U2lkTWVpZXJzQ2l2aWxpemF0aW9uVg==_is1) (Version: 1 - )
Skype™ 6.22 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.105 - Skype Technologies S.A.)
Smite (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 1.0.2435.3 - Hi-Rez Studios)
Solitaire Mystery Four Seasons (x32 Version: 3.0.2.51 - WildTangent) Hidden
Sparkle 2 (x32 Version: 3.0.2.51 - WildTangent) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 18.1.7.8 - Synaptics Incorporated)
System Requirements Lab Detection (HKLM-x32\...\{BD191CC1-66EE-47C6-A0CB-4EC7FA40EC27}) (Version: 2.2.3.0 - Husdawg, LLC)
Tales of Lagoona (x32 Version: 2.2.0.110 - WildTangent) Hidden
The Elder Scrolls V Skyrim (HKLM-x32\...\{4FEF52F2-3C2C-4B80-9443-3D6A654328D0}_is1) (Version:  - Bethesda Softworks)
Tom Clancy's Ghost Recon Phantoms - NA (HKLM-x32\...\Steam App 243870) (Version:  - Ubisoft Singapore)
Total War ROME II (HKLM-x32\...\VG90YWxXYXJST01FSUk=_is1) (Version: 1 - )
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Vacation Quest™ - Australia (x32 Version: 3.0.2.32 - WildTangent) Hidden
Viking Saga (x32 Version: 3.0.2.48 - WildTangent) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App for HP (x32 Version: 4.0.11.2 - WildTangent) Hidden
Wrye Bash (HKLM-x32\...\Wrye Bash) (Version: 0.3.0.5 - Wrye & Wrye Bash Development Team)
Youda Jewel Shop (x32 Version: 3.0.2.51 - WildTangent) Hidden
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-1204343423-3542177778-238362734-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-1204343423-3542177778-238362734-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Josh\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation)
 
==================== Restore Points  =========================
 
09-12-2014 18:01:16 Scheduled Checkpoint
25-12-2014 09:07:11 Scheduled Checkpoint
26-12-2014 15:34:27 Installed DirectX
01-01-2015 01:07:37 Windows Update
13-01-2015 16:33:30 Removed AVG 2015
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {03D28DBA-7843-4869-820C-85E875373BFF} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-1204343423-3542177778-238362734-1001 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe
Task: {06379F8C-7BC2-4E8F-A013-CD60D63A21F7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company)
Task: {12B9E78E-6B5E-4FDB-80EE-6A698B73AA12} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [2014-03-07] (CyberLink Corp.)
Task: {32B91918-7A7F-4038-9185-44BA73ADAB81} - System32\Tasks\{52448607-DDB2-4FE9-BD63-52D978CBEE77} => pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\"
Task: {4DA0A6C4-3D9C-45E8-95E2-F7C69AB0870B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-11-29] (Hewlett-Packard Company)
Task: {680BCE6A-ED19-41B8-B254-67A6BC7B617B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-01-01] (Microsoft Corporation)
Task: {6C286192-AFF6-4C78-ACFD-5178EF97FDD4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-02] (Google Inc.)
Task: {6D4BFE68-4AD9-48C9-B874-7ECE4EF20FF2} - System32\Tasks\{F80A4447-B56A-4A9F-B643-01D128D83DC3} => pcalua.exe -a C:\Steam\SteamApps\common\skyrim\SkyrimLauncher.exe -d C:\Steam\SteamApps\common\skyrim
Task: {A2B4CF3C-0CEE-4C0B-B759-619314461363} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-12-18] (Hewlett-Packard)
Task: {A37F421E-F06C-4AC2-A608-9D8AF3C07A33} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-11-04] (Microsoft Corporation)
Task: {A41889F5-BCD8-4FD1-BE87-8676473A9188} - System32\Tasks\Hewlett-Packard\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2013-11-01] (Hewlett-Packard Development Company, L.P.)
Task: {A7EE097C-1F30-44A8-BF8D-FA61990F3BA7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-12-18] (Hewlett-Packard)
Task: {C4D27BFB-9933-419E-A438-70A18C630292} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-02] (Google Inc.)
Task: {DEDEEA82-2A9C-4A70-9EC2-E3FDC02596B8} - System32\Tasks\{65422384-8627-4914-B432-E3D0A01C3773} => pcalua.exe -a "C:\Riot Games\League of Legends\lol.launcher.exe" -d "C:\Riot Games\League of Legends\"
Task: {FA34ACED-893F-4A66-A911-E300E579F3E2} - System32\Tasks\{E940F1B3-208D-4F24-A799-B86A510FF027} => pcalua.exe -a "C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" -c scenario=install baseurl="C:\Program Files\Microsoft Office 15" platform=x86 version=15.0.4569.1506 culture=en-us productstoremove=HomeStudentRetail_en-us_x-none
Task: {FC9F84FF-1A79-44F7-8DB5-F1F68B49B982} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company)
Task: C:\Windows\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast1\AvastEmUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2014-11-21 16:19 - 2014-11-21 16:19 - 08897696 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-11-02 10:48 - 2014-10-21 23:04 - 01042760 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\libglesv2.dll
2014-11-02 10:48 - 2014-10-21 23:04 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\libegl.dll
2014-11-02 10:48 - 2014-10-21 23:04 - 08910664 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll
2014-11-02 10:48 - 2014-10-21 23:04 - 01681224 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ffmpegsumo.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:DocumentSummaryInformation
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:SummaryInformation
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
 
========================= Accounts: ==========================
 
Administrator (S-1-5-21-1204343423-3542177778-238362734-500 - Administrator - Disabled)
Guest (S-1-5-21-1204343423-3542177778-238362734-501 - Limited - Disabled)
Josh (S-1-5-21-1204343423-3542177778-238362734-1001 - Administrator - Enabled) => C:\Users\Josh
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (01/15/2015 07:02:31 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: An unspecified error occurred during System Restore: (Installed DirectX). Additional information: 0x80070017.
 
Error: (01/13/2015 11:00:52 PM) (Source: HiRezSoftwareManagerSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.Xml.XmlException: Root element is missing.
   at System.Xml.XmlTextReaderImpl.Throw(Exception e)
   at System.Xml.XmlTextReaderImpl.ParseDocumentContent()
   at System.Xml.XmlLoader.Load(XmlDocument doc, XmlReader reader, Boolean preserveWhitespace)
   at System.Xml.XmlDocument.Load(XmlReader reader)
   at System.Xml.XmlDocument.Load(String filename)
   at Hirez.Utilities.HirezConfigSettings.LoadConfigDocument(String filePath)
   at Hirez.Utilities.HirezConfigSettings.ReadSetting(String filePath, String key)
   at Hirez.Patcher.PatchNetworkClient.(NewMessageCallback )
   at Hirez.Patcher.PatchNetworkClient..ctor(String appConfigFilePath, NewMessageCallback logCallback)
   at Hirez.Patcher.HiPatchService.InternalStart()
   at Hirez.Patcher.HiPatchService.OnStart(String[] badDontWorkMicrosoftBugArgs)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (01/13/2015 10:20:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Avast.VC110.CRT,processorArchitecture="x86",publicKeyToken="2036b14a11e83e4a",type="win32",version="11.0.60610.1"1".
Dependent Assembly Avast.VC110.CRT,processorArchitecture="x86",publicKeyToken="2036b14a11e83e4a",type="win32",version="11.0.60610.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (01/13/2015 04:40:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: avgnsa.exe, version: 15.0.0.5577, time stamp: 0x545fd3e5
Faulting module name: avgntopenssla.dll, version: 6.3.9600.17278, time stamp: 0x53eebd22
Exception code: 0xc0000135
Fault offset: 0x00000000000ec0b4
Faulting process id: 0x43c
Faulting application start time: 0xavgnsa.exe0
Faulting application path: avgnsa.exe1
Faulting module path: avgnsa.exe2
Report Id: avgnsa.exe3
Faulting package full name: avgnsa.exe4
Faulting package-relative application ID: avgnsa.exe5
 
Error: (01/13/2015 04:38:01 PM) (Source: MsiInstaller) (EventID: 11922) (User: Envy)
Description: SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2015 -- Error 1922. SA_Error1922: StandardAction(0xC0070782): Service 'AVGIDSAgent' (AVGIDSAgent) could not be deleted. Verify that you have sufficient privileges to remove system services.
 
Error: (01/13/2015 04:33:30 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
 
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
 
System Error:
The parameter is incorrect.
.
 
Error: (01/13/2015 04:33:29 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
 
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
 
System Error:
The parameter is incorrect.
.
 
Error: (01/13/2015 04:27:27 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" on line C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
 
Error: (01/13/2015 04:27:27 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" on line C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
 
Error: (01/13/2015 04:27:27 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" on line C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
 
 
System errors:
=============
Error: (01/15/2015 08:39:42 PM) (Source: DCOM) (EventID: 10005) (User: Envy)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (01/15/2015 08:39:42 PM) (Source: DCOM) (EventID: 10005) (User: Envy)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (01/15/2015 08:39:39 PM) (Source: DCOM) (EventID: 10005) (User: Envy)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (01/15/2015 08:39:39 PM) (Source: DCOM) (EventID: 10005) (User: Envy)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (01/15/2015 08:39:36 PM) (Source: DCOM) (EventID: 10005) (User: Envy)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (01/15/2015 08:39:36 PM) (Source: DCOM) (EventID: 10005) (User: Envy)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (01/15/2015 08:39:14 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (01/15/2015 08:39:02 PM) (Source: DCOM) (EventID: 10005) (User: Envy)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (01/15/2015 08:39:02 PM) (Source: DCOM) (EventID: 10005) (User: Envy)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (01/15/2015 08:39:02 PM) (Source: DCOM) (EventID: 10005) (User: Envy)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
 
Microsoft Office Sessions:
=========================
Error: (01/15/2015 07:02:31 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: Installed DirectX0x80070017
 
Error: (01/13/2015 11:00:52 PM) (Source: HiRezSoftwareManagerSvc) (EventID: 0) (User: )
Description: Service cannot be started. System.Xml.XmlException: Root element is missing.
   at System.Xml.XmlTextReaderImpl.Throw(Exception e)
   at System.Xml.XmlTextReaderImpl.ParseDocumentContent()
   at System.Xml.XmlLoader.Load(XmlDocument doc, XmlReader reader, Boolean preserveWhitespace)
   at System.Xml.XmlDocument.Load(XmlReader reader)
   at System.Xml.XmlDocument.Load(String filename)
   at Hirez.Utilities.HirezConfigSettings.LoadConfigDocument(String filePath)
   at Hirez.Utilities.HirezConfigSettings.ReadSetting(String filePath, String key)
   at Hirez.Patcher.PatchNetworkClient.(NewMessageCallback )
   at Hirez.Patcher.PatchNetworkClient..ctor(String appConfigFilePath, NewMessageCallback logCallback)
   at Hirez.Patcher.HiPatchService.InternalStart()
   at Hirez.Patcher.HiPatchService.OnStart(String[] badDontWorkMicrosoftBugArgs)
   at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
 
Error: (01/13/2015 10:20:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Avast.VC110.CRT,processorArchitecture="x86",publicKeyToken="2036b14a11e83e4a",type="win32",version="11.0.60610.1"C:\Program Files\AVAST Software\Avast\setup\iplugins\IStats.dll
 
Error: (01/13/2015 04:40:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: avgnsa.exe15.0.0.5577545fd3e5avgntopenssla.dll6.3.9600.1727853eebd22c000013500000000000ec0b443c01d02f79848dbc05C:\Program Files (x86)\AVG\AVG2015\avgnsa.exeavgntopenssla.dllc2431951-9b6c-11e4-8276-645106ffb2c2
 
Error: (01/13/2015 04:38:01 PM) (Source: MsiInstaller) (EventID: 11922) (User: Envy)
Description: SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2015 -- Error 1922. SA_Error1922: StandardAction(0xC0070782): Service 'AVGIDSAgent' (AVGIDSAgent) could not be deleted. Verify that you have sufficient privileges to remove system services.(NULL)(NULL)(NULL)(NULL)(NULL)
 
Error: (01/13/2015 04:33:30 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: 
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
 
System Error:
The parameter is incorrect.
 
Error: (01/13/2015 04:33:29 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: 
Details:
AddCoreCsiFiles : BeginFileEnumeration() failed.
 
System Error:
The parameter is incorrect.
 
Error: (01/13/2015 04:27:27 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Users\Josh\AppData\Local\Pokki\Uninstall.exe
 
Error: (01/13/2015 04:27:27 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Users\Josh\AppData\Local\Pokki\Uninstall.exe
 
Error: (01/13/2015 04:27:27 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Users\Josh\AppData\Local\Pokki\Uninstall.exe
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-4712HQ CPU @ 2.30GHz
Percentage of memory in use: 20%
Total physical RAM: 8115.02 MB
Available physical RAM: 6482.57 MB
Total Pagefile: 14771.02 MB
Available Pagefile: 13106.25 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:676.93 GB) (Free:352.13 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:20.69 GB) (Free:2.08 GB) NTFS ==>[System with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 1E1F4777)
 
Partition: GPT Partition Type.
 
==================== End Of Log ============================

  • 0

#7
Jdailey91

Jdailey91

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts

Here is the FRST log, I accidentally posted the addition log first.

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-01-2015 01

Ran by Josh (administrator) on ENVY on 15-01-2015 20:39:01
Running from C:\Users\Josh\Desktop
Loaded Profiles: Josh (Available profiles: Josh)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\nacl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\nacl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-12] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7569112 2014-03-31] (Realtek Semiconductor)
HKLM\...\Run: [ISCT Tray] => C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTsysTray8.exe [5860656 2014-02-21] (Intel Corporation)
HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [3962936 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [415288 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [415288 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2818800 2014-04-21] (Synaptics Incorporated)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [126240 2014-02-13] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [475448 2014-03-04] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [NACAgentUI] => C:\Program Files (x86)\Cisco\Cisco NAC Agent\NACAgentUI.exe [621384 2013-12-04] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2014-11-03] (Razer Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast1\AvastUI.exe [5227112 2015-01-13] (AVAST Software)
HKLM-x32\...\RunOnce: [20150107] => C:\Program Files\AVAST Software\Avast1\setup\emupdate\8d08991f-7a72-4b80-a1fb-9371fcb03ac4.exe [183232 2015-01-13] (AVAST Software)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {11570c50-63b5-11e4-8264-645106ffb2c2} - "G:\setup.exe" 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {687084d4-62b9-11e4-8262-645106ffb2c2} - "F:\setup.exe" 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {a399963a-6aee-11e4-8267-645106ffb2c2} - "H:\setup.exe" 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {d87be0ff-8e85-11e4-826f-645106ffb2c2} - "I:\MotorolaDeviceManagerSetup.exe" -a
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {fa931d62-61e4-11e4-825d-645106ffb2c2} - "E:\Skyrim_setup.exe" 
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast1\ashShA64.dll (AVAST Software)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT14/1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT14/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT14/1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT14/1
SearchScopes: HKLM -> {09AA7E49-473B-498C-BF4A-BDD9F9F5E12B} URL = http://www.amazon.co...s={searchTerms}
SearchScopes: HKLM-x32 -> {09AA7E49-473B-498C-BF4A-BDD9F9F5E12B} URL = http://www.amazon.co...s={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
 
FireFox:
========
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3319434&octid=EB_ORIGINAL_CTID&ISID=ME221F28A-8DF4-4747-BCE2-4FFC6F4F211A&SearchSource=55&CUI=&UM=6&UP=SP2ADEA651-92F8-421E-8633-D00C86706548&SSPV=
CHR Profile: C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-02]
CHR Extension: (Adblock Plus) - C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-02]
CHR Extension: (Spellchecker.lu Mini) - C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmcmejmpjaeofdedldgfnpidfmnngdib [2014-11-02]
CHR Extension: (ProShopper) - C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\daehcioiappbaoecfmpnfkinodcoeadf [2014-11-01]
CHR Extension: (Hola Better Internet) - C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-11-02]
CHR Extension: (Spell Checker for Chrome) - C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfpdnkkdgghlpdgldicfgnnnkhdfhocg [2014-11-02]
CHR Extension: (Video Maximizer) - C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\lklonajanpefnlmpnmkdbideaejaakge [2014-11-02]
CHR Extension: (Google Wallet) - C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-02]
CHR Extension: (Game of Thrones: Targaryen) - C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\onjgpcbclcdefijdpgjnkmiifmngkgeo [2014-11-01]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast1\AvastSvc.exe [50344 2015-01-13] (AVAST Software)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3432976 2014-12-18] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-12-18] (AVG Technologies CZ, s.r.o.)
S2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
S4 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-01-27] (WildTangent)
S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-12] (NVIDIA Corporation)
S2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-08-22] (Hi-Rez Studios) [File not signed]
S2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2014-01-13] (Hewlett-Packard Company) [File not signed]
S2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [469304 2014-03-04] (Hewlett-Packard Development Company, L.P.)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-11-21] (Intel Corporation)
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [296432 2014-04-11] (Intel Corporation)
S2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel® Corporation)
S2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-12-09] (Intel Corporation)
S2 ISCTAgent; C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe [209712 2014-02-21] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-12-09] (Intel Corporation)
S2 NACAgent; C:\Program Files (x86)\Cisco\Cisco NAC Agent\NACAgent.exe [1289544 2013-12-04] (Cisco Systems, Inc.)
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-12] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-12] (NVIDIA Corporation) [File not signed]
S2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [88064 2014-03-28] (Softex Inc.) [File not signed]
S2 PinnacleUpdateSvc; C:\Program Files (x86)\PowerUp Software\Pinnacle Game Profiler\pinnacle_updater.exe [438272 2014-01-12] (PowerUp Software, LLC) [File not signed]
S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [183488 2014-10-31] ()
S2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor)
S2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [191728 2014-04-21] (Synaptics Incorporated)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-04-02] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-21] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-21] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-13] ()
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2015-01-13] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-13] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-13] ()
S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-13] (AVAST Software)
S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-13] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-13] (AVAST Software)
S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-13] ()
R0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
S1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [260888 2014-12-08] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [203544 2014-11-18] (AVG Technologies CZ, s.r.o.)
S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [277784 2014-09-24] (AVG Technologies CZ, s.r.o.)
S1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-11-01] (Disc Soft Ltd)
R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [22216 2014-02-03] ()
R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [22728 2014-02-03] ()
S3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [23936 2014-02-03] ()
R3 ISCT; C:\Windows\System32\drivers\ISCTD.sys [44744 2014-02-03] ()
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-09] (Intel Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-12] (NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [466136 2014-01-14] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3406552 2014-04-01] (Realtek Semiconductor Corporation                           )
S3 rzendpt; C:\Windows\System32\drivers\rzendpt.sys [39592 2014-09-04] (Razer Inc)
S2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2014-10-31] (Razer, Inc.)
S2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-11-17] (Razer, Inc.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2014-04-21] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2014-04-21] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-21] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation)
S4 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 IntcDAud; \SystemRoot\system32\DRIVERS\IntcDAud.sys [X]
U3 McAPExe; No ImagePath
U3 McMPFSvc; No ImagePath
U3 McNaiAnn; No ImagePath
U3 mcpltsvc; No ImagePath
U3 McProxy; No ImagePath
U3 mfecore; No ImagePath
U3 MSK80Service; No ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-01-15 20:39 - 2015-01-15 20:39 - 00018838 _____ () C:\Users\Josh\Desktop\FRST.txt
2015-01-15 20:38 - 2015-01-15 20:39 - 00000000 ____D () C:\FRST
2015-01-15 20:06 - 2015-01-15 20:06 - 02125312 _____ (Farbar) C:\Users\Josh\Desktop\FRST64.exe
2015-01-15 19:45 - 2015-01-15 19:45 - 00001121 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-15 19:44 - 2015-01-15 19:44 - 00001170 _____ () C:\Users\Josh\Desktop\post.txt
2015-01-15 19:43 - 2015-01-15 19:43 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Josh\Desktop\mbam-setup-2.0.4.1028 (1).exe
2015-01-13 22:41 - 2015-01-13 22:41 - 00000000 ____D () C:\Users\Josh\AppData\Roaming\AVAST Software
2015-01-13 22:28 - 2015-01-13 22:40 - 00002240 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-01-13 22:28 - 2015-01-13 22:28 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-01-13 22:28 - 2015-01-13 22:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-01-13 22:13 - 2015-01-13 22:28 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2015-01-13 22:13 - 2015-01-13 22:28 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-01-13 22:13 - 2015-01-13 22:28 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-01-13 22:13 - 2015-01-13 22:28 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-01-13 22:13 - 2015-01-13 22:28 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-01-13 22:13 - 2015-01-13 22:28 - 00083280 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-01-13 22:13 - 2015-01-13 22:28 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-01-13 22:13 - 2015-01-13 22:28 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-01-13 22:13 - 2015-01-13 22:28 - 00000352 ____H () C:\Windows\Tasks\avast! Emergency Update.job
2015-01-13 22:13 - 2015-01-13 22:13 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-01-13 22:12 - 2015-01-13 22:28 - 00000000 ____D () C:\Program Files\AVAST Software
2015-01-13 22:09 - 2015-01-13 22:12 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-01-13 21:25 - 2015-01-13 21:25 - 00000000 ____D () C:\Users\Josh\Desktop\Autoruns
2015-01-13 21:25 - 2015-01-13 21:12 - 15340120 _____ () C:\Users\Josh\Desktop\RogueKiller.exe
2015-01-13 21:25 - 2015-01-13 21:12 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\Josh\Desktop\rkill.exe
2015-01-13 21:25 - 2015-01-13 21:11 - 05609736 _____ (Swearware) C:\Users\Josh\Desktop\ComboFix.exe
2015-01-13 20:49 - 2015-01-13 20:49 - 00000988 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2015-01-13 16:53 - 2015-01-13 16:53 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Josh\Desktop\mbam-setup-2.0.4.1028.exe
2015-01-13 16:52 - 2014-12-31 06:14 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-13 16:49 - 2015-01-13 16:52 - 01251660 _____ (Malwarebytes Corporation ) C:\Users\Josh\Downloads\5F90.tmp
2015-01-13 16:27 - 2015-01-13 16:27 - 00000000 ____D () C:\Users\Public\Pokki
2015-01-04 12:06 - 2015-01-04 12:06 - 00101376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-01-04 12:03 - 2015-01-04 12:03 - 00275312 _____ (Microsoft Corporation) C:\Windows\system32\powrprof.dll
2015-01-04 12:01 - 2015-01-04 12:01 - 00789184 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-01-04 12:00 - 2015-01-04 12:00 - 00359424 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2015-01-03 23:15 - 2015-01-03 23:15 - 00000000 ____D () C:\$WINDOWS.~BT
2015-01-03 21:38 - 2015-01-03 21:38 - 00000000 __SHD () C:\found.000
2015-01-03 20:57 - 2015-01-03 20:57 - 433642800 _____ () C:\Windows\MEMORY.DMP
2015-01-02 23:57 - 2015-01-02 23:57 - 00019826 _____ () C:\Users\Josh\Desktop\[kickass.so]the.dark.knight.2008.720p.brrip.x264.yify.torrent
2014-12-27 23:49 - 2014-12-27 23:49 - 00003160 _____ () C:\Windows\System32\Tasks\{65422384-8627-4914-B432-E3D0A01C3773}
2014-12-26 23:20 - 2014-11-22 05:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-12-26 23:20 - 2014-11-22 05:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-12-26 15:36 - 2014-12-26 15:36 - 00000000 ____D () C:\Users\Josh\Documents\Square Enix
2014-12-25 11:59 - 2014-10-30 17:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-12-25 11:59 - 2014-10-30 17:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-12-25 10:35 - 2014-11-21 22:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-25 10:35 - 2014-11-21 21:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-25 10:35 - 2014-11-21 20:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-25 10:35 - 2014-11-21 20:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-25 10:34 - 2014-11-21 21:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-25 10:34 - 2014-11-21 21:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-25 10:34 - 2014-11-21 21:49 - 00417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-12-25 10:34 - 2014-11-21 21:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-25 10:34 - 2014-11-21 21:35 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-12-25 10:34 - 2014-11-21 21:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-25 10:34 - 2014-11-21 21:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-25 10:34 - 2014-11-21 21:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-25 10:34 - 2014-11-21 21:06 - 00340992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-12-25 10:34 - 2014-11-21 21:06 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-12-25 10:34 - 2014-11-21 21:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-25 10:34 - 2014-11-21 21:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-25 10:34 - 2014-11-21 21:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-25 10:34 - 2014-11-21 20:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-12-25 10:34 - 2014-11-21 20:55 - 00661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-12-25 10:34 - 2014-11-21 20:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-12-25 10:34 - 2014-11-21 20:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-25 10:34 - 2014-11-21 20:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-25 10:34 - 2014-11-21 20:49 - 00373760 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-25 10:34 - 2014-11-21 20:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-25 10:34 - 2014-11-21 20:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-25 10:34 - 2014-11-21 20:34 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-12-25 10:34 - 2014-11-21 20:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-25 10:34 - 2014-11-21 20:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-25 10:34 - 2014-11-21 20:29 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-12-25 10:34 - 2014-11-21 20:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-25 10:34 - 2014-11-21 20:25 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-12-25 10:34 - 2014-11-21 20:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-25 10:34 - 2014-11-21 20:23 - 00326656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-25 10:34 - 2014-11-21 20:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-25 10:34 - 2014-11-21 20:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-25 10:34 - 2014-11-21 20:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-25 10:34 - 2014-11-21 20:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-25 10:34 - 2014-11-21 19:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-25 10:34 - 2014-11-21 19:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-25 10:12 - 2014-11-06 23:16 - 01762840 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-25 10:12 - 2014-11-06 22:26 - 01489072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-25 09:59 - 2014-10-30 18:39 - 01970432 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-12-25 09:59 - 2014-10-30 18:38 - 01612992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-12-25 09:24 - 2014-10-12 21:43 - 00238912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2014-12-25 09:24 - 2014-10-12 21:43 - 00153920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2014-12-25 09:24 - 2014-10-12 21:43 - 00086336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2014-12-25 09:24 - 2014-10-12 21:43 - 00039744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelpep.sys
2014-12-25 09:11 - 2014-11-09 21:29 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupStatusProvider.dll
2014-12-25 09:11 - 2014-11-09 20:51 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DeviceSetupStatusProvider.dll
2014-12-25 08:58 - 2014-10-31 18:57 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-12-25 08:58 - 2014-10-31 18:47 - 00790528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-01-15 19:45 - 2014-11-01 21:58 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-15 19:45 - 2014-11-01 21:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-15 19:45 - 2014-11-01 21:58 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-13 23:31 - 2014-11-01 12:13 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-13 23:00 - 2013-08-22 09:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-13 22:38 - 2014-03-18 04:44 - 00028546 _____ () C:\Windows\PFRO.log
2015-01-13 22:17 - 2014-11-01 11:37 - 00000000 ____D () C:\Users\Josh
2015-01-13 21:45 - 2013-08-22 09:46 - 00028755 _____ () C:\Windows\setupact.log
2015-01-13 21:39 - 2014-11-01 11:37 - 01644565 _____ () C:\Windows\WindowsUpdate.log
2015-01-13 21:24 - 2014-03-18 04:53 - 00958356 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-13 21:15 - 2014-11-02 10:47 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-13 21:00 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\sru
2015-01-13 20:55 - 2014-11-15 10:08 - 00000000 ____D () C:\Users\Josh\Documents\Youcam
2015-01-13 20:54 - 2014-11-02 10:47 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-13 20:54 - 2014-11-01 08:43 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1204343423-3542177778-238362734-1001
2015-01-13 20:49 - 2014-11-01 12:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-01-13 20:42 - 2014-11-02 12:39 - 00119296 _____ () C:\Windows\SysWOW64\zlib.dll
2015-01-13 16:43 - 2014-11-14 19:12 - 00000000 ____D () C:\Program Files (x86)\Total War ROME II
2015-01-13 16:43 - 2013-08-22 08:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2015-01-13 16:42 - 2013-08-22 10:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-01-13 16:30 - 2014-11-01 11:42 - 00003906 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{A922D9DE-7823-4898-AE3D-C5573AE15A3A}
2015-01-13 16:30 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-01-13 16:28 - 2014-11-01 11:37 - 00000000 ____D () C:\Users\Josh\AppData\Local\Pokki
2015-01-03 23:53 - 2014-10-31 22:28 - 00000000 _____ () C:\Recovery.txt
2015-01-03 13:56 - 2014-11-01 11:27 - 00000000 ____D () C:\Users\Josh\.frostwire5
2015-01-03 13:49 - 2013-08-22 08:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-01-03 13:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-RS
2015-01-03 13:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS
2015-01-03 13:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-01-01 01:14 - 2014-11-03 02:46 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-01 01:10 - 2014-11-03 02:46 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-28 00:35 - 2014-11-01 09:36 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-12-26 15:36 - 2014-11-05 12:06 - 00000000 ____D () C:\Users\Josh\AppData\Roaming\NVIDIA
2014-12-26 15:35 - 2014-11-01 10:56 - 00352212 _____ () C:\Windows\DirectX.log
2014-12-25 08:37 - 2014-11-21 15:10 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-12-16 21:05 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\NDF
 
Some content of TEMP:
====================
C:\Users\Josh\AppData\Local\Temp\20141104100350318jniverify.dll
C:\Users\Josh\AppData\Local\Temp\ochelper.dll
C:\Users\Josh\AppData\Local\Temp\ochelper.exe
C:\Users\Josh\AppData\Local\Temp\oct4E6F.tmp.exe
C:\Users\Josh\AppData\Local\Temp\octAF0E.tmp.exe
C:\Users\Josh\AppData\Local\Temp\OptimizerPro.exe
C:\Users\Josh\AppData\Local\Temp\optprosetup.exe
C:\Users\Josh\AppData\Local\Temp\procexp64.exe
C:\Users\Josh\AppData\Local\Temp\__pythonRunner.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-12-30 05:06
 
==================== End Of Log ============================

  • 0

#8
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,590 posts

Thanks for the information. Please do the following and let me know if you can boot your machine normally.

 

Step#1 - Question

In the end, what Antivirus do you wish to be running? We need to ensure only one is running as having more than one running can cause performance issues/conflicts etc. I personally use the built-in Windows Defender on my Windows 8 machines but the choice is yours (or your friends). :)

 

Windows Defender

AVG 2015

Avast

 

Step#2 - FRST Fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
1. Download attached file and save it to the Desktop. Attached File  fixlist.txt   2.59KB   146 downloads
Note. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work (in this case...the desktop).
2. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
3. Press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
4. When finished FRST64 will generate a log on the Desktop (Fixlog.txt). Please post the contents of it in your reply.

 

 

 

Items for your next post

1. Answer to my question

2. FRST Fix log

3. Does your machine boot normally now?


  • 0

#9
Jdailey91

Jdailey91

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts

So FRST64 has been repairing for about an hour and a half now. How long should it take? It doesn't appear to be frozen.


  • 0

#10
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,590 posts

That's too long. It's likely stuck. Reboot your machine and see if it boots normally into windows. Let me know.


  • 0

Advertisements


#11
Jdailey91

Jdailey91

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts

No it gets stuck on the log in screen, where you can select your profile/type in your password.


  • 0

#12
Jdailey91

Jdailey91

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
This is the fixlog it generated, but it never finished.
 
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-01-2015 01
Ran by Josh at 2015-01-15 22:40:37 Run:5
Running from C:\Users\Josh\Desktop
Loaded Profiles: Josh (Available profiles: Josh)
Boot Mode: Safe Mode (with Networking)
==============================================
 
Content of fixlist:
*****************
CreateRestorePoint:
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\nacl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\nacl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {11570c50-63b5-11e4-8264-645106ffb2c2} - "G:\setup.exe" 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {687084d4-62b9-11e4-8262-645106ffb2c2} - "F:\setup.exe" 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {a399963a-6aee-11e4-8267-645106ffb2c2} - "H:\setup.exe" 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {d87be0ff-8e85-11e4-826f-645106ffb2c2} - "I:\MotorolaDeviceManagerSetup.exe" -a
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {fa931d62-61e4-11e4-825d-645106ffb2c2} - "E:\Skyrim_setup.exe" 
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3319434&octid=EB_ORIGINAL_CTID&ISID=ME221F28A-8DF4-4747-BCE2-4FFC6F4F211A&SearchSource=55&CUI=&UM=6&UP=SP2ADEA651-92F8-421E-8633-D00C86706548&SSPV=
CHR Extension: (ProShopper) - C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\daehcioiappbaoecfmpnfkinodcoeadf [2014-11-01]
U3 McAPExe; No ImagePath
U3 McMPFSvc; No ImagePath
U3 McNaiAnn; No ImagePath
U3 mcpltsvc; No ImagePath
U3 McProxy; No ImagePath
U3 mfecore; No ImagePath
U3 MSK80Service; No ImagePath
2015-01-13 16:27 - 2015-01-13 16:27 - 00000000 ____D () C:\Users\Public\Pokki
2015-01-13 16:28 - 2014-11-01 11:37 - 00000000 ____D () C:\Users\Josh\AppData\Local\Pokki
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage
C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal
EmptyTemp:
*****************
 
Error: Restore point can only be created in normal mode.

  • 0

#13
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,590 posts

OK, let's do the following.

 

Boot back into Safe Mode with Networking and then do this.

 

Step#1 - FRST Fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
1. Download attached file and save it to the Desktop.Attached File  fixlist.txt   1.82KB   178 downloads
Note. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work (in this case...the desktop).
2. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
3. Press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
4. When finished FRST64 will generate a log on the Desktop (Fixlog.txt). Please post the contents of it in your reply.

 

 

Step#2 - Rootkit Scan
1. Download aswMBR to your desktop.
2. Right-click on aswMBR.exe and select Run as administrator to run it.
3. If you get a question about Virtualization Technology, answer Yes.
4. If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
5. Click the "Scan" button to start scan.
6. On completion of the scan click "Save log", save it to your desktop and post in your next reply.
NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

 

Step#3 - Retrieve Logs

It appears you may have run Rougekiller and Combofix? If this is the case can you post the logs?

-For RougeKiller there may be logs on the desktop beginning with RKreport

-For Combofix there should be a combofix.txt on your C:\ drive

 

 

 

Items for your next post

1. FRST Fix

2. Rootkit Scan Log

3. RogueKiller and Combofix logs

4. Which antivirus do you ultimately want to end up with?

 


  • 0

#14
Jdailey91

Jdailey91

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts

I installed RougeKiller and Combofix but I never ran them. I want to end up with Avast. I was using AVG when this all happened so I want to switch to Avast. I'm not sure if this helps or not, but I have noticed all of these scans either get froze on my Nvida drivers or become really slow as they're scanning them.

---------------------------------

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-01-2015 01
Ran by Josh at 2015-01-15 23:27:51 Run:7
Running from C:\Users\Josh\Desktop
Loaded Profiles: Josh (Available profiles: Josh)
Boot Mode: Safe Mode (with Networking)
==============================================
 
Content of fixlist:
*****************
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {11570c50-63b5-11e4-8264-645106ffb2c2} - "G:\setup.exe" 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {687084d4-62b9-11e4-8262-645106ffb2c2} - "F:\setup.exe" 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {a399963a-6aee-11e4-8267-645106ffb2c2} - "H:\setup.exe" 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {d87be0ff-8e85-11e4-826f-645106ffb2c2} - "I:\MotorolaDeviceManagerSetup.exe" -a
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\...\MountPoints2: {fa931d62-61e4-11e4-825d-645106ffb2c2} - "E:\Skyrim_setup.exe" 
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3319434&octid=EB_ORIGINAL_CTID&ISID=ME221F28A-8DF4-4747-BCE2-4FFC6F4F211A&SearchSource=55&CUI=&UM=6&UP=SP2ADEA651-92F8-421E-8633-D00C86706548&SSPV=
CHR Extension: (ProShopper) - C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\daehcioiappbaoecfmpnfkinodcoeadf [2014-11-01]
U3 McAPExe; No ImagePath
U3 McMPFSvc; No ImagePath
U3 McNaiAnn; No ImagePath
U3 mcpltsvc; No ImagePath
U3 McProxy; No ImagePath
U3 mfecore; No ImagePath
U3 MSK80Service; No ImagePath
2015-01-13 16:27 - 2015-01-13 16:27 - 00000000 ____D () C:\Users\Public\Pokki
2015-01-13 16:28 - 2014-11-01 11:37 - 00000000 ____D () C:\Users\Josh\AppData\Local\Pokki
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage
C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal
EmptyTemp:
*****************
 
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value not found.
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{11570c50-63b5-11e4-8264-645106ffb2c2} => Key not found. 
HKCR\CLSID\{11570c50-63b5-11e4-8264-645106ffb2c2} => Key not found. 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{687084d4-62b9-11e4-8262-645106ffb2c2} => Key not found. 
HKCR\CLSID\{687084d4-62b9-11e4-8262-645106ffb2c2} => Key not found. 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a399963a-6aee-11e4-8267-645106ffb2c2} => Key not found. 
HKCR\CLSID\{a399963a-6aee-11e4-8267-645106ffb2c2} => Key not found. 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d87be0ff-8e85-11e4-826f-645106ffb2c2} => Key not found. 
HKCR\CLSID\{d87be0ff-8e85-11e4-826f-645106ffb2c2} => Key not found. 
HKU\S-1-5-21-1204343423-3542177778-238362734-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fa931d62-61e4-11e4-825d-645106ffb2c2} => Key not found. 
HKCR\CLSID\{fa931d62-61e4-11e4-825d-645106ffb2c2} => Key not found. 
HKLM\SOFTWARE\Policies\Google => Key not found. 
Chrome HomePage deleted successfully.
C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\daehcioiappbaoecfmpnfkinodcoeadf directory not found.
McAPExe => Service not found.
McMPFSvc => Service not found.
McNaiAnn => Service not found.
mcpltsvc => Service not found.
McProxy => Service not found.
mfecore => Service not found.
MSK80Service => Service not found.
"C:\Users\Public\Pokki" => File/Directory not found.
"C:\Users\Josh\AppData\Local\Pokki" => File/Directory not found.
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => Key not found. 
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => Key not found. 
"C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage" => File/Directory not found.
"C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal" => File/Directory not found.
EmptyTemp: => Removed 6.6 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 23:27:57 ====
 
-------------------------------------------------------------------------
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-01-15 23:33:38
-----------------------------
23:33:38.182    OS Version: Windows x64 6.3.9600 
23:33:38.182    Number of processors: 8 586 0x3C03
23:33:38.182    ComputerName: ENVY  UserName: Josh
23:33:40.215    Initialize success
23:33:44.087    AVAST engine defs: 14110700
23:33:59.361    Disk 0 MBR fix error
23:34:32.690    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000039
23:34:32.691    Disk 0 Vendor: HGST_HTS541075A9E680 JA2OA710 Size: 715404MB BusType: 8
23:34:32.818    Disk 0 MBR read successfully
23:34:32.820    Disk 0 MBR scan
23:34:33.320    Disk 0 unknown MBR code
23:34:33.341    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
23:34:33.860    Disk 0 scanning C:\Windows\system32\drivers
23:34:44.544    Service scanning
23:35:27.885    Modules scanning
23:35:27.889    Disk 0 trace - called modules:
23:35:27.899    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ACPI.sys storport.sys hal.dll iaStorA.sys 
23:35:27.901    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe001dff6a6a0]
23:35:27.905    3 CLASSPNP.SYS[fffff8005e94d27b] -> nt!IofCallDriver -> [0xffffe001dff6a040]
23:35:27.908    5 hpdskflt.sys[fffff8006040242b] -> nt!IofCallDriver -> [0xffffe001dcd08660]
23:35:27.910    7 ACPI.sys[fffff8005e5757aa] -> nt!IofCallDriver -> \Device\00000039[0xffffe001de8c97f0]
23:35:28.799    AVAST engine scan C:\Windows
23:35:30.732    AVAST engine scan C:\Windows\system32
23:38:26.152    AVAST engine scan C:\Windows\system32\drivers
23:38:38.720    AVAST engine scan C:\Users\Josh
23:42:12.457    AVAST engine scan C:\ProgramData
23:43:29.305    Disk 0 statistics 3644837/0/0 @ 4.57 MB/s
23:43:29.310    Scan finished successfully
23:43:52.413    Disk 0 MBR has been saved successfully to "C:\Users\Josh\Desktop\MBR.dat"
23:43:52.428    The log file has been saved successfully to "C:\Users\Josh\Desktop\aswMBR.txt"
------------------------------
 
What do I do with the MBR.dat file?

Edited by Jdailey91, 15 January 2015 - 10:45 PM.

  • 0

#15
Jdailey91

Jdailey91

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts

PS. The program tried to restart my computer back into normal windows, but it became froze on the log in screen once again. So I had to restart it back into safe mode with networking.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP