Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

PC browser redirects are affecting everything. [Solved]


  • This topic is locked This topic is locked

#1
kid@hrt

kid@hrt

    Member

  • Member
  • PipPip
  • 55 posts

Hi

I knew better but,

I downloaded a program that was bundled with malware. My browsers are all redirecting and have annoying pop ups. Media download,

Ilivid download and cdn.downloaddaft.com are a few of the sites that I have been redirected to.

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Mom (administrator) on MOM-PC on 24-03-2015 18:12:00
Running from C:\Users\Mom\Desktop
Loaded Profiles: Mom (Available profiles: Mom & Guest)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
() C:\Program Files (x86)\Ncmanthicisinessibias\Ncmanthicisinessibias.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2015-03-17] (Malwarebytes Corporation)
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [S-1-5-21-2005915866-3535303436-4220142520-1000] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-2005915866-3535303436-4220142520-1000] => http=127.0.0.1:9880
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...d=ie&ar=msnhome
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1me10IE11ENUS/MCM_WCP
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab
DPF: HKLM-x32 {1C11B948-582A-433F-A98D-A8C4D5CC64F2} https://lowes.2020.n...yerAX_Win32.cab
DPF: HKLM-x32 {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinn...0/tpir/tpir.cab
DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.co...iaSmartScan.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab
DPF: HKLM-x32 {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinn...ed/wwlaunch.cab
DPF: HKLM-x32 {E7DA7F8D-27AB-4EE9-8FC0-3FEC9ECFE758} https://www.compass....micWebTWAIN.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{F5AA37F8-C1BB-4651-A345-B8D6F02AE8C5}: [NameServer] 8.8.8.8,8.8.4.4

FireFox:
========
FF ProfilePath: C:\Users\Mom\AppData\Roaming\Mozilla\Firefox\Profiles\rdzkj16m.default-1427158167491
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-18] ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2010-12-03] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-18] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-11-09] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-11-09] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @millisecond.com/npInquisit,version=3.0 -> C:\Program Files (x86)\Millisecond Software\Inquisit 3.0 Mozilla Plugin\npInquisit_3060.dll [2011-10-26] (Millisecond Software)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-07] (Google Inc.)
FF Plugin HKU\S-1-5-21-2005915866-3535303436-4220142520-1000: @millisecond.com/npInquisit,version=3.0 -> C:\Program Files (x86)\Millisecond Software\Inquisit 3.0 Mozilla Plugin\npInquisit_3060.dll [2011-10-26] (Millisecond Software)
FF Plugin HKU\S-1-5-21-2005915866-3535303436-4220142520-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Mom\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll No File
FF Plugin HKU\S-1-5-21-2005915866-3535303436-4220142520-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Mom\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll No File

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "https://www.google.com/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.758\_platform_specific\win_x86\widevinecdmadapter.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\internal-nacl-plugin No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
CHR Plugin: (Java Deployment Toolkit 8.0.250.18) - C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java™ Platform SE 8 U25) - C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Inquisit Web Edition) - C:\Program Files (x86)\Millisecond Software\Inquisit 3.0 Mozilla Plugin\npInquisit_3060.dll (Millisecond Software)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll No File
CHR Profile: C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-20]
CHR Extension: (The Treasures Of Mystery Island) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\cakimmoclemogopdpkmnhnhlbdbhople [2014-09-07]
CHR Extension: (Do Not Track) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckdcpbflcbeillmamogkpmdhnbeggfja [2014-09-07]
CHR Extension: (Google Calendar) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2014-09-07]
CHR Extension: (AdBlock) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-09-07]
CHR Extension: (ERPLY Accounting) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnoijkgmmjjimafnfhlcmnicnedcai [2015-02-15]
CHR Extension: (Autodesk Homestyler) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2014-09-07]
CHR Extension: (Free Invoice Maker) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\kebnkbogolcjifklpmgidaaoogjflajp [2014-09-07]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-05]
CHR Extension: (Google Maps) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-09-07]
CHR Extension: (Google Wallet) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-07]
CHR Extension: (Picasa) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-09-07]
CHR Extension: (Click&Clean App) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2014-09-07]
CHR Extension: (Gmail) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-07]
CHR HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Mom\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-08-19]
CHR HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.goo...ice/update2/crx

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-04-30] (Advanced Micro Devices, Inc.) [File not signed]
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
R2 Ncmanthicisinessibias; C:\Program Files (x86)\Ncmanthicisinessibias\Ncmanthicisinessibias.exe [256512 2015-03-19] () [File not signed] <==== ATTENTION
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
R1 BIOS; C:\Windows\system32\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
R1 BIOS; C:\Windows\SysWOW64\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
U0 hepdcw; C:\Windows\System32\drivers\eequn.sys [79064 2015-03-24] (Malwarebytes Corporation)
R0 Lbd; C:\Windows\System32\DRIVERS\Lbd.sys [69152 2010-09-23] (Lavasoft AB)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [136408 2015-03-24] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [28416 2008-04-16] (Research In Motion Limited)
S3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-01-08] (Wondershare)
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-24 18:07 - 2015-03-24 18:12 - 00000000 ____D () C:\FRST
2015-03-24 18:06 - 2015-03-24 18:06 - 02095616 _____ (Farbar) C:\Users\Mom\Desktop\FRST64.exe
2015-03-24 18:06 - 2015-03-24 18:06 - 00000000 _____ () C:\Windows\setuperr.log
2015-03-24 18:06 - 2015-03-24 18:06 - 00000000 _____ () C:\Windows\setupact.log
2015-03-24 17:47 - 2015-03-24 17:47 - 00079064 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\eequn.sys
2015-03-23 20:07 - 2015-03-23 20:54 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\Compete
2015-03-23 17:29 - 2015-03-24 15:39 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-23 17:28 - 2015-03-23 17:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-23 17:28 - 2015-03-23 17:28 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-23 17:28 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-03-23 17:28 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-03-23 17:28 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-23 17:07 - 2015-03-23 17:09 - 00053248 ___SH () C:\Users\Mom\Desktop\Thumbs.db
2015-03-22 17:56 - 2015-03-22 17:56 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\WebplayerRemote
2015-03-22 17:47 - 2015-03-22 17:47 - 00000000 __SHD () C:\Program Files (x86)\Ncmanthicisinessibias
2015-03-22 17:32 - 2015-03-22 17:32 - 01315328 _____ () C:\Users\Mom\AppData\Roaming\JLS.exe
2015-03-22 17:31 - 2015-03-23 16:59 - 00000000 ___HD () C:\Users\Public\Temp
2015-03-22 17:30 - 2015-03-22 17:31 - 00000000 ____D () C:\Program Files (x86)\75f58658-1636-481b-bb93-681528a7e956
2015-03-22 17:30 - 2015-03-22 17:30 - 00003278 _____ () C:\Windows\System32\Tasks\xOyz777ub8w9gWE
2015-03-22 17:30 - 2015-03-22 17:30 - 00003236 _____ () C:\Windows\System32\Tasks\vhSk5fGmqffH4XR
2015-03-22 17:30 - 2015-03-22 17:30 - 00003234 _____ () C:\Windows\System32\Tasks\QV7WrfASweRbfs0
2015-03-22 17:30 - 2015-03-22 17:30 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\PsjDFS8
2015-03-22 17:30 - 2015-03-22 17:30 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\Cd23RUL
2015-03-22 17:30 - 2015-03-22 17:30 - 00000000 ____D () C:\ProgramData\atjs
2015-03-22 17:29 - 2015-03-22 17:30 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\Shafelo
2015-03-22 17:29 - 2015-03-22 17:30 - 00000000 ____D () C:\ProgramData\NVSMpxS
2015-03-22 17:28 - 2015-03-23 20:54 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2015-03-22 17:28 - 2015-03-22 17:28 - 01945600 _____ () C:\Users\Mom\AppData\Roaming\TNGJRWN.exe
2015-03-22 17:28 - 2015-03-22 17:28 - 00000000 ____D () C:\Users\Mom\AppData\Local\globalUpdate
2015-03-22 17:28 - 2015-03-12 02:40 - 04687360 _____ () C:\Windows\rcore.exe
2015-03-22 17:27 - 2015-03-22 17:27 - 00000000 ____D () C:\ProgramData\10a33e9e6bdb4696920e1858a4196f36
2015-03-22 14:43 - 2015-03-22 14:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-22 14:31 - 2015-03-22 14:38 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\Foxit Software
2015-03-22 14:31 - 2015-03-22 14:31 - 00000000 ____D () C:\Users\Public\Foxit Software
2015-03-22 14:31 - 2015-03-22 14:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2015-03-22 14:31 - 2015-03-22 14:31 - 00000000 ____D () C:\Program Files (x86)\Foxit Software
2015-03-22 14:27 - 2015-03-22 14:28 - 38624744 _____ (Foxit Software Inc. ) C:\Users\Mom\Downloads\FoxitReader710.0306_prom_enu_Setup.exe
2015-03-20 17:56 - 2015-03-20 17:57 - 03894696 _____ (solvusoft Corporation ) C:\Users\Mom\Desktop\Tsusbhub.sys_Error_Repair_Tool-WinThruster.exe
2015-03-20 17:46 - 2015-03-20 17:46 - 02135814 _____ () C:\Windows\system32\config\wfpstate.xml
2015-03-20 17:46 - 2015-03-20 17:46 - 01609647 _____ () C:\Windows\system32\config\wfpfilters.xml
2015-03-20 17:46 - 2015-03-20 17:46 - 00358797 _____ () C:\Windows\system32\config\netevents.xml
2015-03-20 17:46 - 2015-03-20 17:46 - 00069632 _____ () C:\Windows\system32\config\WindowsFirewallLogVerbose.evtx
2015-03-20 17:46 - 2015-03-20 17:46 - 00069632 _____ () C:\Windows\system32\config\WindowsFirewallConsecLogVerbose.evtx
2015-03-20 17:46 - 2015-03-20 17:46 - 00042461 _____ () C:\Windows\system32\config\Dns.txt
2015-03-20 17:46 - 2015-03-20 17:46 - 00037434 _____ () C:\Windows\system32\config\WcnInfo.txt
2015-03-20 17:46 - 2015-03-20 17:46 - 00002573 _____ () C:\Windows\system32\config\FileSharing.txt
2015-03-20 17:46 - 2015-03-20 17:46 - 00002303 _____ () C:\Windows\system32\config\gpresult.txt
2015-03-20 17:46 - 2015-03-20 17:46 - 00002148 _____ () C:\Windows\system32\config\Neighbors.txt
2015-03-20 17:46 - 2015-03-20 17:46 - 00000484 _____ () C:\Windows\system32\config\sysports.xml
2015-03-20 17:46 - 2015-03-20 17:46 - 00000237 _____ () C:\Windows\system32\config\netiostate.txt
2015-03-20 17:46 - 2015-03-20 17:46 - 00000062 _____ () C:\Windows\system32\config\wfplog.log
2015-03-20 17:45 - 2015-03-20 17:46 - 00000000 ____D () C:\Windows\system32\config\LocaleMetaData
2015-03-20 17:45 - 2015-03-20 17:45 - 01118208 _____ () C:\Windows\system32\config\WindowsFirewallLog.evtx
2015-03-20 17:45 - 2015-03-20 17:45 - 00431374 _____ () C:\Windows\system32\config\WindowsFirewallConfig.txt
2015-03-20 17:45 - 2015-03-20 17:45 - 00069632 _____ () C:\Windows\system32\config\WLANAutoConfigLog.evtx
2015-03-20 17:45 - 2015-03-20 17:45 - 00069632 _____ () C:\Windows\system32\config\WindowsFirewallConsecLog.evtx
2015-03-20 17:45 - 2015-03-20 17:45 - 00048646 _____ () C:\Windows\system32\config\WindowsFirewallEffectiveRules.txt
2015-03-20 17:45 - 2015-03-20 17:45 - 00015700 _____ () C:\Windows\system32\config\envinfo.txt
2015-03-20 17:45 - 2015-03-20 17:45 - 00014361 _____ () C:\Windows\system32\config\osinfo.txt
2015-03-20 17:45 - 2015-03-20 17:45 - 00004526 _____ () C:\Windows\system32\tempfile.txt
2015-03-20 17:45 - 2015-03-20 17:45 - 00000883 _____ () C:\Windows\system32\config\adapterinfo.txt
2015-03-20 17:45 - 2015-03-20 17:45 - 00000000 ____D () C:\Windows\system32\Reg
2015-03-19 19:33 - 2015-03-08 10:22 - 00670880 _____ (Sysinternals - www.sysinternals.com) C:\Users\Mom\Desktop\autoruns.exe
2015-03-19 15:56 - 2015-03-19 15:56 - 00008126 _____ () C:\Users\Mom\Desktop\cc_20150319_155607.reg
2015-03-19 15:49 - 2015-03-19 15:49 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\VSRevoGroup
2015-03-19 12:09 - 2015-03-22 18:00 - 00000000 ____D () C:\Users\Mom\Desktop\brusch
2015-03-11 19:52 - 2015-03-11 19:52 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-03-11 19:52 - 2015-03-11 19:52 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-03-11 19:52 - 2015-03-11 19:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2015-03-11 19:37 - 2015-03-11 19:52 - 00001945 _____ () C:\Windows\epplauncher.mif
2015-03-10 19:38 - 2015-02-20 00:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-10 19:38 - 2015-02-20 00:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-10 19:38 - 2015-02-20 00:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-10 19:38 - 2015-02-20 00:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-10 19:38 - 2015-02-20 00:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-03-10 19:38 - 2015-02-20 00:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-03-10 19:38 - 2015-02-20 00:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-03-10 19:38 - 2015-02-20 00:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-03-10 19:38 - 2015-02-19 23:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-10 19:38 - 2015-02-19 23:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-03-10 19:38 - 2015-02-02 23:34 - 05554104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-10 19:38 - 2015-02-02 23:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-03-10 19:38 - 2015-02-02 23:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-03-10 19:38 - 2015-02-02 23:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-03-10 19:38 - 2015-02-02 23:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-03-10 19:38 - 2015-02-02 23:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-03-10 19:38 - 2015-02-02 23:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-03-10 19:38 - 2015-02-02 23:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-10 19:38 - 2015-02-02 23:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-03-10 19:38 - 2015-02-02 23:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-03-10 19:38 - 2015-02-02 23:30 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-10 19:38 - 2015-02-02 23:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-03-10 19:38 - 2015-02-02 23:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-03-10 19:38 - 2015-02-02 23:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-03-10 19:38 - 2015-02-02 23:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-03-10 19:38 - 2015-02-02 23:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-03-10 19:38 - 2015-02-02 23:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-03-10 19:38 - 2015-02-02 23:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-03-10 19:38 - 2015-02-02 23:28 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-10 19:38 - 2015-02-02 23:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-03-10 19:38 - 2015-02-02 23:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-03-10 19:38 - 2015-02-02 23:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-03-10 19:38 - 2015-02-02 23:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-03-10 19:38 - 2015-02-02 23:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-03-10 19:38 - 2015-02-02 23:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-03-10 19:38 - 2015-02-02 23:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-03-10 19:38 - 2015-02-02 23:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-03-10 19:38 - 2015-02-02 23:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2015-03-10 19:38 - 2015-02-02 23:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2015-03-10 19:38 - 2015-02-02 23:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2015-03-10 19:38 - 2015-02-02 23:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-03-10 19:38 - 2015-02-02 22:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-03-10 19:38 - 2014-10-31 18:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-03-10 19:38 - 2014-06-27 20:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-03-10 19:38 - 2014-06-27 20:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-03-10 19:37 - 2015-03-06 01:56 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-10 19:37 - 2015-03-06 01:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-10 19:37 - 2015-03-06 01:42 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-10 19:37 - 2015-03-06 01:42 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-10 19:37 - 2015-03-06 01:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-10 19:37 - 2015-03-06 01:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-10 19:37 - 2015-03-06 01:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-10 19:37 - 2015-03-06 01:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-10 19:37 - 2015-03-06 01:42 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-10 19:37 - 2015-03-06 01:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-10 19:37 - 2015-03-06 01:42 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-10 19:37 - 2015-03-06 01:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-10 19:37 - 2015-03-06 01:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-10 19:37 - 2015-03-06 01:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-10 19:37 - 2015-03-06 01:41 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-10 19:37 - 2015-03-06 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-10 19:37 - 2015-03-06 01:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-10 19:37 - 2015-03-06 01:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-10 19:37 - 2015-03-06 01:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-03-10 19:37 - 2015-03-06 01:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-03-10 19:37 - 2015-03-06 01:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-03-10 19:37 - 2015-03-06 01:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-03-10 19:37 - 2015-03-06 01:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-03-10 19:37 - 2015-03-06 01:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-03-10 19:37 - 2015-03-06 01:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-03-10 19:37 - 2015-03-06 01:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-03-10 19:37 - 2015-03-06 01:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-03-10 19:37 - 2015-03-06 01:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-03-10 19:37 - 2015-03-06 01:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-03-10 19:37 - 2015-03-06 01:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-03-10 19:37 - 2015-03-06 01:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-03-10 19:37 - 2015-02-13 01:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-03-10 19:37 - 2015-02-13 01:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-10 19:37 - 2015-02-02 23:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-10 19:37 - 2015-02-02 23:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2015-03-10 19:37 - 2015-01-30 23:48 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-10 19:37 - 2015-01-30 23:48 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-10 19:37 - 2015-01-30 19:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-10 19:37 - 2015-01-30 19:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-10 19:36 - 2015-02-25 23:25 - 03204096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-10 19:36 - 2015-02-23 23:15 - 00389800 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-10 19:36 - 2015-02-23 22:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-03-10 19:36 - 2015-02-20 21:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-10 19:36 - 2015-02-20 20:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-03-10 19:36 - 2015-02-20 20:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-03-10 19:36 - 2015-02-20 20:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-03-10 19:36 - 2015-02-20 20:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-03-10 19:36 - 2015-02-20 19:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-10 19:36 - 2015-02-20 19:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-03-10 19:36 - 2015-02-19 23:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-10 19:36 - 2015-02-19 23:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-10 19:36 - 2015-02-19 22:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-10 19:36 - 2015-02-19 22:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-10 19:36 - 2015-02-19 22:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-10 19:36 - 2015-02-19 22:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-10 19:36 - 2015-02-19 22:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-10 19:36 - 2015-02-19 22:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-10 19:36 - 2015-02-19 22:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-10 19:36 - 2015-02-19 22:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-10 19:36 - 2015-02-19 22:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-10 19:36 - 2015-02-19 22:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-10 19:36 - 2015-02-19 22:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-10 19:36 - 2015-02-19 22:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-10 19:36 - 2015-02-19 22:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-10 19:36 - 2015-02-19 22:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-03-10 19:36 - 2015-02-19 22:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-10 19:36 - 2015-02-19 22:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-10 19:36 - 2015-02-19 22:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-03-10 19:36 - 2015-02-19 22:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-10 19:36 - 2015-02-19 22:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-03-10 19:36 - 2015-02-19 22:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-03-10 19:36 - 2015-02-19 22:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-03-10 19:36 - 2015-02-19 22:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-10 19:36 - 2015-02-19 22:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-03-10 19:36 - 2015-02-19 22:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-03-10 19:36 - 2015-02-19 22:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-03-10 19:36 - 2015-02-19 21:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-03-10 19:36 - 2015-02-19 21:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-03-10 19:36 - 2015-02-19 21:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-03-10 19:36 - 2015-02-19 21:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-10 19:36 - 2015-02-19 21:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-10 19:36 - 2015-02-19 21:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-10 19:36 - 2015-02-19 21:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-10 19:36 - 2015-02-19 21:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-10 19:36 - 2015-02-19 21:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-10 19:36 - 2015-02-19 21:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-03-10 19:36 - 2015-02-19 21:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-03-10 19:36 - 2015-02-19 21:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-10 19:36 - 2015-02-19 21:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-03-10 19:36 - 2015-02-19 21:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-03-10 19:36 - 2015-02-19 21:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-03-10 19:36 - 2015-02-19 21:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-10 19:36 - 2015-02-19 21:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-10 19:36 - 2015-02-19 21:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-03-10 19:36 - 2015-02-19 20:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-03-10 19:36 - 2015-02-19 20:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-03-10 19:36 - 2015-02-02 23:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-10 19:36 - 2015-02-02 23:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-10 19:36 - 2015-01-16 22:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-10 19:36 - 2015-01-16 22:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2015-03-10 19:35 - 2015-02-03 23:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-10 19:35 - 2015-02-03 22:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2015-03-09 17:30 - 2015-03-09 17:30 - 00005487 _____ () C:\Users\Mom\AppData\Roaming\TNGJRWN
2015-03-05 19:39 - 2015-03-19 15:57 - 00000000 ____D () C:\Users\Mom\Desktop\Stuff
2015-03-05 19:30 - 2015-03-05 19:30 - 00001117 _____ () C:\Users\Mom\Desktop\Dropbox.lnk
2015-03-05 19:28 - 2015-03-05 19:28 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-03-05 19:26 - 2015-03-05 19:27 - 00355632 _____ (Dropbox, Inc.) C:\Users\Mom\Downloads\DropboxInstaller.exe
2015-03-04 08:54 - 2015-03-04 08:54 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Macromedia
2015-03-04 08:54 - 2015-03-04 08:54 - 00000000 ____D () C:\Users\Guest\AppData\Local\Macromedia
2015-03-04 08:53 - 2015-03-04 08:53 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Mozilla
2015-03-04 08:53 - 2015-03-04 08:53 - 00000000 ____D () C:\Users\Guest\AppData\Local\Mozilla
2015-02-28 18:47 - 2015-02-28 17:38 - 1423871935 _____ () C:\Users\Mom\Documents\ADancewithDragonsASongofIceandFireBook5_ep6_A132NK9ZH3BI6N.aax
2015-02-28 15:04 - 2015-02-28 15:04 - 01730272 _____ (Audible Inc.) C:\Users\Mom\Downloads\ActiveSetupN(1).exe
2015-02-28 14:52 - 2015-02-28 14:52 - 00000000 ____D () C:\Users\Public\Documents\Audible
2015-02-28 14:52 - 2015-02-28 14:52 - 00000000 ____D () C:\Users\Mom\Documents\Audible
2015-02-28 14:52 - 2015-02-28 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudibleManager
2015-02-28 14:52 - 2015-02-28 14:52 - 00000000 ____D () C:\ProgramData\Documents\Audible
2015-02-28 14:52 - 2015-02-28 14:52 - 00000000 ____D () C:\Program Files (x86)\Audible
2015-02-28 14:51 - 2015-02-28 14:51 - 01672880 _____ (Audible, Inc.) C:\Users\Mom\Downloads\AudibleDM_iTunesSetup.exe
2015-02-28 14:48 - 2015-02-28 14:48 - 01730272 _____ (Audible Inc.) C:\Users\Mom\Downloads\ActiveSetupN.exe
2015-02-26 19:25 - 2015-01-08 19:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls
2015-02-26 19:25 - 2015-01-08 19:43 - 00419936 _____ () C:\Windows\system32\locale.nls

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-24 18:11 - 2009-07-14 00:45 - 00023824 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-24 18:11 - 2009-07-14 00:45 - 00023824 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-24 16:56 - 2010-12-03 08:56 - 01182771 ____N () C:\Windows\WindowsUpdate.log
2015-03-24 15:39 - 2010-12-05 19:55 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\foobar2000
2015-03-24 11:20 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-23 20:55 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\Help
2015-03-23 20:37 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-03-23 18:10 - 2009-07-14 01:08 - 00032596 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-23 16:55 - 2013-04-10 13:57 - 00000000 ___RD () C:\Users\Mom\Dropbox
2015-03-23 16:54 - 2012-10-19 20:46 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\Dropbox
2015-03-22 18:09 - 2009-07-14 01:13 - 00800010 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-22 18:02 - 2015-01-20 19:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-22 17:26 - 2011-06-17 17:24 - 00000000 ____D () C:\Users\Mom\AppData\Local\Deployment
2015-03-22 14:27 - 2010-12-03 17:14 - 00000000 ____D () C:\Users\Mom\AppData\Local\Adobe
2015-03-22 14:26 - 2010-12-02 17:51 - 00000000 ____D () C:\ProgramData\Adobe
2015-03-20 16:48 - 2015-01-18 20:58 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-20 16:48 - 2014-07-14 14:10 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-20 16:48 - 2014-07-14 14:10 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-19 19:52 - 2015-01-18 20:58 - 00003770 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-03-19 19:52 - 2014-07-14 14:10 - 00003906 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-03-19 19:52 - 2014-07-14 14:10 - 00003654 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-03-19 17:54 - 2012-11-24 19:19 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\Spotify
2015-03-19 17:05 - 2013-10-19 23:09 - 00000000 ____D () C:\Users\Mom\AppData\Local\Spotify
2015-03-19 15:43 - 2015-02-17 18:14 - 00000000 ____D () C:\Windows\Minidump
2015-03-18 18:01 - 2014-12-15 17:13 - 00000000 ____D () C:\Users\Mom\Desktop\Justin
2015-03-18 13:57 - 2015-01-18 20:58 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-03-18 13:57 - 2015-01-18 20:58 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-17 13:40 - 2012-11-06 16:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-03-12 15:08 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2015-03-12 13:59 - 2013-05-06 20:23 - 00001710 _____ () C:\Users\Mom\Documents\password.txt
2015-03-12 13:44 - 2009-07-14 01:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2015-03-12 13:44 - 2009-07-14 00:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-03-12 13:41 - 2013-01-12 12:50 - 00554592 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-12 13:38 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-03-12 13:38 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-03-12 13:38 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system
2015-03-11 19:44 - 2015-02-14 14:15 - 00175933 _____ () C:\Windows\system\tubelist.dat
2015-03-11 19:43 - 2014-12-02 13:05 - 00162854 _____ () C:\Windows\system\latest.dat
2015-03-11 19:43 - 2014-12-02 13:05 - 00000122 _____ () C:\Windows\system\update.dat
2015-03-11 19:35 - 2013-04-10 22:30 - 00000476 _____ () C:\Windows\wininit.ini
2015-03-11 19:35 - 2013-04-07 19:49 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-03-10 19:46 - 2012-06-01 19:13 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-10 19:46 - 2009-07-13 22:34 - 00000647 _____ () C:\Windows\win.ini
2015-03-10 19:44 - 2013-08-15 03:01 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-10 19:40 - 2010-12-04 10:21 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-05 19:51 - 2012-11-06 16:46 - 00000000 ___RD () C:\Users\Mom\Google Drive
2015-03-03 09:17 - 2010-12-02 17:58 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-03-02 16:54 - 2012-03-31 15:23 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\Canon
2015-03-02 11:22 - 2013-11-16 17:38 - 00000000 ___RD () C:\Users\Mom\Documents\Tax, Fax, letters and landlord
2015-02-28 15:10 - 2011-10-29 13:18 - 00000000 ____D () C:\Windows\pss

==================== Files in the root of some directories =======

2013-04-12 10:57 - 2013-04-12 10:57 - 0000000 _____ () C:\Users\Mom\AppData\Roaming\bibstats
2015-01-25 12:12 - 2015-01-25 12:12 - 0002086 _____ () C:\Users\Mom\AppData\Roaming\JLS
2015-03-22 17:32 - 2015-03-22 17:32 - 1315328 _____ () C:\Users\Mom\AppData\Roaming\JLS.exe
2015-03-09 17:30 - 2015-03-09 17:30 - 0005487 _____ () C:\Users\Mom\AppData\Roaming\TNGJRWN
2015-03-22 17:28 - 2015-03-22 17:28 - 1945600 _____ () C:\Users\Mom\AppData\Roaming\TNGJRWN.exe
2014-01-10 20:40 - 2014-01-28 17:40 - 0000137 _____ () C:\Users\Mom\AppData\Roaming\WB.CFG
2014-01-10 20:40 - 2014-01-28 17:40 - 0000005 _____ () C:\Users\Mom\AppData\Roaming\WBPU-TTL.DAT
2011-01-05 20:31 - 2014-02-12 20:02 - 0028802 _____ () C:\Users\Mom\AppData\Roaming\wklnhst.dat
2013-03-31 17:59 - 2013-04-28 17:33 - 0009216 _____ () C:\Users\Mom\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-12-25 14:33 - 2012-12-25 14:33 - 0000091 _____ () C:\Users\Mom\AppData\Local\fusioncache.dat
2013-04-18 15:14 - 2013-04-18 15:14 - 0008526 _____ () C:\Users\Mom\AppData\Local\recently-used.xbel
2012-06-24 16:09 - 2013-01-06 14:27 - 0007603 _____ () C:\Users\Mom\AppData\Local\Resmon.ResmonCfg
2012-10-11 12:29 - 2012-10-11 12:35 - 0012770 _____ () C:\Users\Mom\AppData\Local\slot1.mm1

Files to move or delete:
====================
C:\Users\Mom\jobq.dat


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 

 

Addition.txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by Mom at 2015-03-24 18:08:57
Running from C:\Users\Mom\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 15.0.0.293 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{37FCE154-7F59-74F0-3A35-BF503CEB230B}) (Version: 8.0.877.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\...\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{0DF7096B-715A-4233-8633-C7A16ED6D616}) (Version: 3.1.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Big Fish: Game Manager (HKLM-x32\...\BFGC) (Version: 3.3.0.2 - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.06 - Piriform)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Crayon Physics Deluxe version 55 (HKLM-x32\...\{4CA1E8E2-B2A9-40C1-8EC4-BBCB23BAAA19}_is1) (Version: 55 - Kloonigames, Ltd)
CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version:  3.0 - Acro Software Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dropbox (HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\...\Dropbox) (Version: 3.2.9 - Dropbox, Inc.)
FamilySearch Indexing 3.15.1 (HKLM-x32\...\0591-8077-9297-0833) (Version: 3.15.1 - FamilySearch)
foobar2000 v1.1.1 (HKLM-x32\...\foobar2000) (Version: 1.1.1 - Peter Pawlowski)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.1.0.306 - Foxit Software Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.89 - Google Inc.)
Google Drive (HKLM-x32\...\{6C36881B-0E51-4231-9D02-BF2149664D34}) (Version: 1.20.8672.3137 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
Home Sweet Home (HKLM-x32\...\BFG-Home Sweet Home) (Version:  - )
Home Sweet Home 2: Kitchens and Baths (HKLM-x32\...\BFG-Home Sweet Home 2 - Kitchens and Baths) (Version:  - )
Home Sweet Home: Christmas Edition (HKLM-x32\...\BFG-Home Sweet Home - Christmas Edition) (Version:  - )
iTunes (HKLM\...\{D227565A-0033-40AD-89BA-653A205CDC11}) (Version: 12.1.1.4 - Apple Inc.)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
K-Lite Codec Pack 7.0.0 (Standard) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 7.0.0 - )
Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Digital Image Standard 2006 Update (HKLM-x32\...\PictureItPrem_v12) (Version: 11.0.2018 - Microsoft Corporation)
Microsoft Office Access Runtime (English) 2007 (HKLM-x32\...\{90120000-001C-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-0081-0409-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\...\{95140000-007D-0409-0000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Word 2002 (HKLM-x32\...\{911B0409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
Microsoft Works 6-9 Converter (HKLM-x32\...\{95140000-0137-0409-0000-0000000FF1CE}) (Version: 14.0.6120.5002 - Microsoft Corporation)
Microsoft Works Suite 2006 Setup Launcher (HKLM-x32\...\Works2006Setup) (Version:  - )
Microsoft Works Suite Add-in for Microsoft Word (HKLM-x32\...\{17E3A651-12B9-4149-BAE8-E6FB9A5ADC4F}) (Version: 8.0.0.0000 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker 6.0 for Windows 7 (64-bit) (HKLM\...\{A7395F20-2B22-4CB8-8510-B452C0F47E02}) (Version: 6.0.0 - Microsoft Corporation)
Mozilla Firefox 36.0.4 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 36.0.4 (x86 en-US)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0 - Mozilla)
MP3 To WAV Decoder version 1.0 r2 (HKLM-x32\...\{05B3E767-B182-4279-A35A-A56810C77CFD}_is1) (Version: 1.0 r2 - )
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Music Manager (HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\...\MusicManager) (Version:  - Google, Inc.)
MyHeritage Family Tree Builder (HKLM-x32\...\Family Tree Builder) (Version: 7.0.0.7138 - MyHeritage.com)
NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5896 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.18.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.18.0 - NVIDIA Corporation)
PDF-XChange 3 (HKLM\...\PDF-XChange 3_is1) (Version:  - Tracker Software)
PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5928 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Smilebox (HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\...\Smilebox) (Version: 1.0.0.28051 - Smilebox, Inc.)
Spotify (HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Ulead Photo Express My Scrapbook 2.0 (HKLM-x32\...\{CF404C21-47EB-4FA5-B920-91746874ED43}) (Version:  - )
UserTesting.com Recorder Plugin (HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\...\UserTestingPlugin) (Version:  - UserTesting.com)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM-x32\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
WinRAR 5.00 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
Works Upgrade (x32 Version: 8.0.0.0000 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2005915866-3535303436-4220142520-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2005915866-3535303436-4220142520-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2005915866-3535303436-4220142520-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2005915866-3535303436-4220142520-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2005915866-3535303436-4220142520-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2005915866-3535303436-4220142520-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2005915866-3535303436-4220142520-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2005915866-3535303436-4220142520-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2005915866-3535303436-4220142520-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mom\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)

==================== Restore Points  =========================

11-03-2015 19:34:21 Revo Uninstaller's restore point - Spybot - Search & Destroy
11-03-2015 19:36:14 Revo Uninstaller's restore point - ESET Online Scanner v3
11-03-2015 19:45:37 Revo Uninstaller's restore point - Adobe Reader XI (11.0.08)
11-03-2015 20:17:49 Windows Update
17-03-2015 13:35:06 Windows Update
19-03-2015 15:44:36 Revo Uninstaller's restore point - Adobe Reader XI (11.0.08)
20-03-2015 16:50:43 Windows Update
22-03-2015 17:34:57 Revo Uninstaller's restore point - Consumer Input
22-03-2015 17:36:29 Revo Uninstaller's restore point - Consumer Input (remove only)
22-03-2015 17:40:22 Revo Uninstaller's restore point - Foxit Cloud
22-03-2015 17:41:31 Revo Uninstaller's restore point - GamesDesktop 025.340
22-03-2015 17:42:37 Revo Uninstaller's restore point - GamesDesktop 025.340
22-03-2015 17:44:13 Revo Uninstaller's restore point - MediaPv2.6
22-03-2015 17:44:55 Revo Uninstaller's restore point - Local Temperature
22-03-2015 17:46:44 Revo Uninstaller's restore point - Movie Wizard
22-03-2015 17:47:28 Revo Uninstaller's restore point - OBRONA Cleaner
22-03-2015 17:48:47 Revo Uninstaller's restore point - Microsoft XNA Framework Redistributable 3.1
22-03-2015 17:50:20 Revo Uninstaller's restore point - Microsoft XNA Framework Redistributable 3.1
22-03-2015 17:50:59 Revo Uninstaller's restore point - SmartPurple
22-03-2015 17:53:08 Revo Uninstaller's restore point - PepperZip 2.0
22-03-2015 17:54:02 Revo Uninstaller's restore point - TheBestDeals
22-03-2015 17:54:57 Revo Uninstaller's restore point - StormWatch
22-03-2015 17:57:59 Supprimé Webplayer Remote
23-03-2015 17:03:54 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2012-09-26 11:19 - 2014-09-04 19:10 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {08AEE9B9-7DAE-427D-8853-93288ED79AF6} - System32\Tasks\xOyz777ub8w9gWE => C:\Users\Mom\AppData\Roaming\PsjDFS8\tPXFXtg.exe [2015-03-22] ()
Task: {137C7262-0DF3-4489-9F0E-FC84A6C0857E} - \CIMT_S-1-5-21-2005915866-3535303436-4220142520-1000 No Task File <==== ATTENTION
Task: {28BEF8B8-3CBD-47CE-A17D-538434CDFC89} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-5 No Task File <==== ATTENTION
Task: {297CC9FC-A122-46D2-B3E0-D2FDEF3A4DCA} - System32\Tasks\vhSk5fGmqffH4XR => C:\Users\Mom\AppData\Roaming\Cd23RUL\4mdbvfy.exe [2015-03-22] ( )
Task: {2CD2E74C-8DE7-4AA4-9B2A-8515C9B33570} - \Startup Time Check No Task File <==== ATTENTION
Task: {34A9A280-F251-4877-B32A-D7967E245BEE} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-7 No Task File <==== ATTENTION
Task: {350C4730-87B0-44E5-8FF2-D180098D64DB} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {36ED84F4-18D5-4156-9974-196CE15BF211} - \CIMT_daily_S-1-5-21-2005915866-3535303436-4220142520-1000 No Task File <==== ATTENTION
Task: {4BE93E40-334C-4A04-A40F-0252AF58B0A2} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-10_user No Task File <==== ATTENTION
Task: {6E0DC5F9-984F-483F-949D-AF6C41C961EA} - System32\Tasks\{75C18BE2-499E-466E-BFCD-75CEC0390CC0} => pcalua.exe -a "C:\Users\vin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H7D3XJTX\PlayerSetup[1].exe" -d C:\Users\vin\Desktop
Task: {8B0DA266-5086-4271-8FCE-1CE626019856} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-6 No Task File <==== ATTENTION
Task: {9FB5E7F8-28A6-43F1-8BC4-23B57C269DD6} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {A5678122-6EE9-4E63-9EC6-FFF16CEEE6ED} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-5_user No Task File <==== ATTENTION
Task: {AD33A4A5-E5D0-42E9-AD59-C4FB2C16D533} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-04] (Google Inc.)
Task: {AF497096-509C-46F5-81B6-1FC836B7583C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-11-04] (Google Inc.)
Task: {B2BF22C8-D6DD-47CC-A046-7CEB168E98EB} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-4 No Task File <==== ATTENTION
Task: {BACBC0CE-317F-46F7-80B3-4E11186E49BB} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {BE3E001F-C45A-43A9-99ED-F54A26D29D43} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {BEE727AA-AF36-4766-A6E7-75640C848D11} - \ObronaCleanerUacSkip No Task File <==== ATTENTION
Task: {D764DC59-8EA6-4521-959E-F6426A047AA6} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-1-7 No Task File <==== ATTENTION
Task: {DA15D996-A98A-4949-9C31-8F425EFBB798} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-18] (Adobe Systems Incorporated)
Task: {DBA01E38-CA1B-4131-B0B9-69D6320BB468} - System32\Tasks\QV7WrfASweRbfs0 => C:\Users\Mom\AppData\Roaming\Shafelo\5BqPNyx.exe [2015-03-22] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2015-03-22 17:47 - 2015-03-19 13:01 - 00256512 ___SH () C:\Program Files (x86)\Ncmanthicisinessibias\Ncmanthicisinessibias.exe
2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2015-02-14 20:40 - 2015-02-14 20:40 - 00381440 _____ () C:\Windows\mod_frst.exe

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:27790C06
AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F
AlternateDataStreams: C:\ProgramData\TEMP:D987CB43

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Gambali => ""="service"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\Classes\.exe:  =>  <===== ATTENTION!

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: !SASCORE => 2
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AeLookupSvc => 3
MSCONFIG\Services: ALG => 3
MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: AMD FUEL Service => 2
MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: defragsvc => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: SDScannerService => 2
MSCONFIG\Services: SDUpdateService => 2
MSCONFIG\Services: SDWSCService => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Audible Download Manager.lnk => C:\Windows\pss\Audible Download Manager.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^T.O.V.A. 8 (automatic startup).lnk => C:\Windows\pss\T.O.V.A. 8 (automatic startup).lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Mom^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Mom^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: 20131121 => C:\Program Files\AVAST Software\Avast\setup\emupdate\1e782172-f6bf-484c-b313-e7a7a52baeaa.exe /check
MSCONFIG\startupreg: AdAwareTray => "C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.2.5952.0\AdAwareTray.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Synchronizer => "C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AdobeCollabSync.exe"
MSCONFIG\startupreg: AMD AVT => Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
MSCONFIG\startupreg: avast => "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
MSCONFIG\startupreg: C77B34DEB73DE0849E4BE289D36231EA4CA83D43._service_run => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service
MSCONFIG\startupreg: Family Tree Builder Update => C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe
MSCONFIG\startupreg: Google Update => "C:\Users\Mom\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Logitech Download Assistant => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
MSCONFIG\startupreg: MFNetworkScanUtility => C:\Program Files\Canon\Canon MF Network Scan Utility\CNMFSUT6.EXE
MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
MSCONFIG\startupreg: OfficeSyncProcess => "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
MSCONFIG\startupreg: SmileboxTray => "C:\Users\Mom\AppData\Roaming\Smilebox\SmileboxTray.exe"
MSCONFIG\startupreg: Spotify => "C:\Users\Mom\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Mom\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

==================== Accounts: =============================

Administrator (S-1-5-21-2005915866-3535303436-4220142520-500 - Administrator - Disabled)
Guest (S-1-5-21-2005915866-3535303436-4220142520-501 - Limited - Enabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-2005915866-3535303436-4220142520-1004 - Limited - Enabled)
Mom (S-1-5-21-2005915866-3535303436-4220142520-1000 - Administrator - Enabled) => C:\Users\Mom

==================== Faulty Device Manager Devices =============

Name: Xbox 360
Description: Xbox 360
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/23/2015 08:34:54 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={204D2DD0-70BC-4343-9330-B294D96463A0}: The user Mom-PC\Mom dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.

Error: (03/23/2015 06:10:06 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out

Error: (03/22/2015 05:34:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program gentlemjmp_ieeuu.tmp version 51.52.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 17fc

Start Time: 01d064e7d83e4170

Termination Time: 0

Application Path: C:\Users\Mom\AppData\Local\Temp\is-FBDQ9.tmp\gentlemjmp_ieeuu.tmp

Report Id:

Error: (03/22/2015 05:34:21 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program majmp_gentleeeuu.tmp version 51.52.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1a40

Start Time: 01d064e7d2cdbd10

Termination Time: 0

Application Path: C:\Users\Mom\AppData\Local\Temp\is-8BS6R.tmp\majmp_gentleeeuu.tmp

Report Id:

Error: (03/22/2015 05:33:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_PcaSvc, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: pcasvc.dll, version: 6.1.7601.18741, time stamp: 0x54d04099
Exception code: 0xc0000005
Fault offset: 0x0000000000007a41
Faulting process id: 0x144
Faulting application start time: 0xsvchost.exe_PcaSvc0
Faulting application path: svchost.exe_PcaSvc1
Faulting module path: svchost.exe_PcaSvc2
Report Id: svchost.exe_PcaSvc3

Error: (03/22/2015 05:30:41 PM) (Source: MsiInstaller) (EventID: 11309) (User: Mom-PC)
Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt.  System error 3.  Verify that the file exists and that you can access it.

Error: (03/22/2015 05:30:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ObronaCleaner.exe, version: 1.0.0.0, time stamp: 0x54ede102
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x74001024
Faulting process id: 0x14a8
Faulting application start time: 0xObronaCleaner.exe0
Faulting application path: ObronaCleaner.exe1
Faulting module path: ObronaCleaner.exe2
Report Id: ObronaCleaner.exe3

Error: (03/22/2015 05:30:26 PM) (Source: MsiInstaller) (EventID: 11316) (User: Mom-PC)
Description: Product: Consumer Input Update Helper -- Error 1316. The specified account already exists.

Error: (03/22/2015 02:26:18 PM) (Source: MsiInstaller) (EventID: 1024) (User: Mom-PC)
Description: Product: Adobe Reader XI (11.0.10) - Update 'Adobe Reader XI (11.0.10)' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft....k/?LinkId=23127

Error: (03/22/2015 02:26:15 PM) (Source: MsiInstaller) (EventID: 11402) (User: Mom-PC)
Description: Product: Adobe Reader XI (11.0.10) -- Error 1402.Could not open key: HKEY_LOCAL_MACHINE32\Software\MozillaPlugins\Adobe Reader.  System error 5.  Verify that you have sufficient access to that key, or contact your support personnel.


System errors:
=============
Error: (03/24/2015 05:48:41 PM) (Source: Microsoft Antimalware) (EventID: 3002) (User: )
Description: %%860 Real-Time Protection feature has encountered an error and failed.

    Feature: %%886

    Error Code: 0x80070005

    Error description: Access is denied.

    Reason: %%858

Error: (03/24/2015 05:48:36 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error:
%%5

Error: (03/24/2015 03:38:10 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error:
%%5

Error: (03/24/2015 11:30:52 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for FailureCommand with the following error:
%%5

Error: (03/24/2015 11:30:48 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error:
%%5

Error: (03/23/2015 08:15:13 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The IPsec Policy Agent service terminated with the following error:
%%10106

Error: (03/23/2015 08:15:13 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The IPsec Policy Agent service terminated with the following error:
%%10106

Error: (03/23/2015 08:12:48 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The IPsec Policy Agent service terminated with the following error:
%%10106

Error: (03/23/2015 08:12:46 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The IPsec Policy Agent service terminated with the following error:
%%10106

Error: (03/23/2015 08:08:06 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The IPsec Policy Agent service terminated with the following error:
%%10106


Microsoft Office Sessions:
=========================
Error: (03/23/2015 08:34:54 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: {204D2DD0-70BC-4343-9330-B294D96463A0}Mom-PC\MomBroadband Connection651

Error: (03/23/2015 06:10:06 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out

Error: (03/22/2015 05:34:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: gentlemjmp_ieeuu.tmp51.52.0.017fc01d064e7d83e41700C:\Users\Mom\AppData\Local\Temp\is-FBDQ9.tmp\gentlemjmp_ieeuu.tmp

Error: (03/22/2015 05:34:21 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: majmp_gentleeeuu.tmp51.52.0.01a4001d064e7d2cdbd100C:\Users\Mom\AppData\Local\Temp\is-8BS6R.tmp\majmp_gentleeeuu.tmp

Error: (03/22/2015 05:33:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe_PcaSvc6.1.7600.163854a5bc3c1pcasvc.dll6.1.7601.1874154d04099c00000050000000000007a4114401d064cc359afc80C:\Windows\System32\svchost.exec:\windows\system32\pcasvc.dll1bff8f90-d0db-11e4-982e-003067529c86

Error: (03/22/2015 05:30:41 PM) (Source: MsiInstaller) (EventID: 11309) (User: Mom-PC)
Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt.  System error 3.  Verify that the file exists and that you can access it.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/22/2015 05:30:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ObronaCleaner.exe1.0.0.054ede102unknown0.0.0.000000000c00000057400102414a801d064e72b4dd340C:\Users\Mom\AppData\Local\Obrona Cleaner\ObronaCleaner.exeunknowna8e29110-d0da-11e4-982e-003067529c86

Error: (03/22/2015 05:30:26 PM) (Source: MsiInstaller) (EventID: 11316) (User: Mom-PC)
Description: Product: Consumer Input Update Helper -- Error 1316. The specified account already exists.
(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/22/2015 02:26:18 PM) (Source: MsiInstaller) (EventID: 1024) (User: Mom-PC)
Description: Adobe Reader XI (11.0.10)Adobe Reader XI (11.0.10)1603(NULL)(NULL)(NULL)

Error: (03/22/2015 02:26:15 PM) (Source: MsiInstaller) (EventID: 11402) (User: Mom-PC)
Description: Product: Adobe Reader XI (11.0.10) -- Error 1402.Could not open key: HKEY_LOCAL_MACHINE32\Software\MozillaPlugins\Adobe Reader.  System error 5.  Verify that you have sufficient access to that key, or contact your support personnel.(NULL)(NULL)(NULL)(NULL)(NULL)


CodeIntegrity Errors:
===================================
  Date: 2013-05-04 13:49:49.966
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Lisa_wysong.exe\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-05-04 13:49:49.701
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Lisa_wysong.exe\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-02-09 20:00:05.120
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-02-09 20:00:04.949
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: AMD Athlon™ II X3 445 Processor
Percentage of memory in use: 29%
Total physical RAM: 6143.37 MB
Available physical RAM: 4341.77 MB
Total Pagefile: 12284.92 MB
Available Pagefile: 10698.88 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.73 GB) (Free:79.95 GB) NTFS
Drive z: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.8 GB) (Disk ID: E686F016)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.7 GB) - (Type=07 NTFS)

==================== End Of Log ============================


  • 0

Advertisements


#2
DanoNH

DanoNH

    Trusted Helper

  • Malware Removal
  • 2,155 posts

Hello and Welcome! :welcome:

My name is Dan, and I'll be helping you with your issues. If someone else is helping you, either here or at another malware removal assistance site, please let me know so that I may direct my efforts to helping another user.  The Staff at Geeks To Go are ALL volunteers; please keep that in mind if I don’t answer your post as quickly as you’d like. I give what time I can.  PLEASE be patient. ;)

I am currently in training, so there will be another person reviewing my work.  This may cause a bit of a delay in my responses, but on the positive side, you will have two sets of eyes reviewing your logs instead of one... :cool:

  • Please note that you should have Administrator rights to perform any fixes.
     
  • Before we proceed, you may wish to print instructions for easy reference during the fix.  Please be aware that many of the required URLs are hyperlinks in the blue names shown on your screen. Part of the fix may require you to be in Safe Mode, which might not allow you to access the internet, or my instructions.
     
  • Please understand that malware removal is a complicated, multi-step process.  Therefore please stay with me until I tell you that your system is clean. 
     
  • Please do NOT make any system or program changes, or run ANY tools unless I specifically ask you to.  Attempting malware removal or clean-up yourself will only extend the time it will take to get your system clean.    If you get stuck or have questions, please stop and ask so I can help you.
     
  • Be sure to back up any personal data files you need to keep (documents, photos, etc.) to a USB flash drive or external hard disk.  While every attempt will be made to precisely repair the infections on your computer, due to the complexity and unpredictability of malware clean-up, there is always a risk of data loss.
     
  • When posting logs, please Copy & Paste the log file contents into a reply.  Use multiple posts if necessary, but please do not attach them or post them on a file hosting site.
     

I will return with next steps for you.  In the meantime please ensure you have your personal files, photos, bookmarks, etc. backed up. 

 

Your patience is greatly appreciated. :D


  • 0

#3
kid@hrt

kid@hrt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts
Hi Dan,
I have backed up all important files to Dropbox. I will be at work till 5:30 and ready to take on the challenge of cleaning up the mess I made of my PC. ☺

Thanks
Lisa
  • 0

#4
DanoNH

DanoNH

    Trusted Helper

  • Malware Removal
  • 2,155 posts

That's good to know, thanks.  I'm almost ready myself.  :) 


  • 0

#5
DanoNH

DanoNH

    Trusted Helper

  • Malware Removal
  • 2,155 posts

Do you use DSL for internet access?


  • 0

#6
kid@hrt

kid@hrt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts

Hi Dan

 

Yes, unfortunately I do.


  • 0

#7
kid@hrt

kid@hrt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts

Hi Dano

 

While I was away yesterday my son, who actually knows his way around a computer, he has an Associates in Networking overheard me complaining about my PC. He came over and ran Malwarebytes, and Adware.

I really hope this isn't going to mess you up. 

 

The PC seems a bit better not nearly as many popups, or redirects.  

He also took a screen shot of Msconfig under the services tab is a service that is really strange 

it is ---- Ncmanthicisinessbias 

I attached the pic just in case 

 

I will post the scans.

 

Again I hope this helps instead of hinders.

LISA

 

 

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
 
Protection, 3/25/2015 12:32:41 PM, SYSTEM, MOM-PC, Protection, Malware Protection, Starting, 
Protection, 3/25/2015 12:32:41 PM, SYSTEM, MOM-PC, Protection, Malware Protection, Started, 
Protection, 3/25/2015 12:32:41 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, Starting, 
Protection, 3/25/2015 12:32:59 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, Started, 
Detection, 3/25/2015 12:39:51 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 49352, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 12:39:51 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 49352, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 12:46:31 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 49689, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 12:48:10 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 50110, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 12:58:01 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 50648, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 12:59:58 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 50720, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:02:20 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 50814, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:05:29 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 51055, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:11:58 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 51192, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:11:58 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 51202, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:13:49 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 51365, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:14:34 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 51493, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:15:09 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 51548, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:16:08 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 51640, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:17:28 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 51802, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Update, 3/25/2015 1:17:38 PM, SYSTEM, MOM-PC, Scheduler, Malware Database, 2015.3.24.9, 2015.3.25.5, 
Protection, 3/25/2015 1:17:38 PM, SYSTEM, MOM-PC, Protection, Refresh, Starting, 
Protection, 3/25/2015 1:17:38 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 3/25/2015 1:17:38 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 3/25/2015 1:17:44 PM, SYSTEM, MOM-PC, Protection, Refresh, Success, 
Protection, 3/25/2015 1:17:44 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, Starting, 
Protection, 3/25/2015 1:17:44 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, Started, 
Detection, 3/25/2015 1:23:34 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 51975, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:23:34 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 51975, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:24:46 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 52115, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:27:00 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 52192, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:27:29 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 52304, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:29:52 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 52419, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
Detection, 3/25/2015 1:30:22 PM, SYSTEM, MOM-PC, Protection, Malicious Website Protection, IP, 
 
5.153.38.134, gpm.sekgaagzz.com, 52611, Outbound, C:\Program Files (x86)\Ncmanthicisinessibias
 
\Ncmanthicisinessibias.exe, 
 
(end)
 
AdwCleaner[RO]
 
# AdwCleaner v4.113 - Logfile created 25/03/2015 at 19:54:05
# Updated 22/03/2015 by Xplode
# Database : 2015-03-23.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Mom - MOM-PC
# Running from : C:\Users\Mom\Desktop\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
File Found : C:\Users\Mom\AppData\Roaming\Mozilla\Firefox\Profiles\zt4oxhk2.default\user.js
File Found : C:\Windows\rcore.exe
Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\ProgramData\apn
Folder Found : C:\ProgramData\Yahoo! Companion
Folder Found : C:\Users\Mom\AppData\Local\globalUpdate
Folder Found : C:\Users\Mom\AppData\Roaming\download Manager
 
***** [ Scheduled tasks ] *****
 
Task Found : globalUpdateUpdateTaskMachineCore
Task Found : globalUpdateUpdateTaskMachineUA
Task Found : ObronaCleanerUacSkip
Task Found : Startup Time Check
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>
Key Found : HKCU\Software\AppDataLow\Software\adawarebp
Key Found : HKCU\Software\AppDataLow\Software\Compete
Key Found : HKCU\Software\AppDataLow\Software\RewardsArcadeSuite
Key Found : HKCU\Software\Compete
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\Kreapixel
Key Found : HKCU\Software\powerpack
Key Found : [x64] HKCU\Software\Compete
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\Kreapixel
Key Found : [x64] HKCU\Software\powerpack
Key Found : HKLM\SOFTWARE\61a67e44-9c83-4d24-bca7-f2190c7c2909
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Found : HKLM\SOFTWARE\CompeteInc
Key Found : HKLM\SOFTWARE\ec6993aa-9a0d-4ba6-a0cf-a310ef9a9ed8
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-
 
499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Consumer Input Installer
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Key Found : HKLM\SOFTWARE\TermTutor
Key Found : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-
 
18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17689
 
 
-\\ Mozilla Firefox v36.0.4 (x86 en-US)
 
 
-\\ Google Chrome v41.0.2272.89
 
[C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : 
 
hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : 
 
hxxp://www.ask.com/web?q={searchTerms}
*************************
 
AdwCleaner[R0].txt - [5336 bytes] - [25/03/2015 19:54:06]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [5395 bytes] ##########
 
AdwCleaner[SO]
 
# AdwCleaner v4.113 - Logfile created 25/03/2015 at 19:58:42
# Updated 22/03/2015 by Xplode
# Database : 2015-03-23.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Mom - MOM-PC
# Running from : C:\Users\Mom\Desktop\AdwCleaner.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\Yahoo! Companion
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Users\Mom\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Mom\AppData\Roaming\download Manager
File Deleted : C:\Windows\rcore.exe
File Deleted : C:\Users\Mom\AppData\Roaming\Mozilla\Firefox\Profiles\zt4oxhk2.default\user.js
 
***** [ Scheduled tasks ] *****
 
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : ObronaCleanerUacSkip
Task Deleted : Startup Time Check
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\61a67e44-9c83-4d24-bca7-f2190c7c2909
Key Deleted : HKLM\SOFTWARE\ec6993aa-9a0d-4ba6-a0cf-a310ef9a9ed8
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-
 
499A-87B4-0DBF742404C1}
Key Deleted : HKCU\Software\Compete
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\powerpack
Key Deleted : HKCU\Software\Kreapixel
Key Deleted : HKCU\Software\AppDataLow\Software\adawarebp
Key Deleted : HKCU\Software\AppDataLow\Software\Compete
Key Deleted : HKCU\Software\AppDataLow\Software\RewardsArcadeSuite
Key Deleted : HKLM\SOFTWARE\CompeteInc
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\TermTutor
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Consumer Input Installer
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-
 
18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17689
 
 
-\\ Mozilla Firefox v36.0.4 (x86 en-US)
 
 
-\\ Google Chrome v41.0.2272.89
 
[C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : 
 
hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : 
 
hxxp://www.ask.com/web?q={searchTerms}
 
*************************
 
AdwCleaner[R0].txt - [5498 bytes] - [25/03/2015 19:54:06]
AdwCleaner[S0].txt - [5372 bytes] - [25/03/2015 19:58:42]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5431  bytes] ##########
 

 

Attached Thumbnails

  • Umsconfig.gif

  • 0

#8
DanoNH

DanoNH

    Trusted Helper

  • Malware Removal
  • 2,155 posts

Hello kid@hrt,
 
I realize your son was probably only trying to help, however I will remind you that running tools I don't ask for can make more work for both of us, and extend the amount of time it takes to get your system clean.  Please advise your son of this, as well as any others who may attempt similar steps.  Our progress can take even longer because I have to seek approval before I can provide any system-changing repair steps - that's just part of my current training here.  Some malware can generate new files or even hide when cleaning attempts are made, requiring new logs and another whole analysis of the system.   ;)

 

As an aside, I myself have a BSEE/CS and have been working in the field for 15+ years.  I've also been working with computers/networking for 30+ years (think pre-AOL days ;) ).  There's so much to learn about this constantly evolving topic (malware) that it's hard for anyone to keep up!  Thank goodness for the awesomely talented teachers and staff here, some of whom actually work for big name anti-virus/anti-malware software companies... ;)

 

That said, are you ready?  I am... :)
 
Please stop and let me know if you have any questions about or trouble with any of the steps we are going to complete on our way to getting your machine clean.
 
First
Run a FRST Fix
 

  • Download the attached fixlist.txt file and save it to the DESKTOP.
    Attached File  fixlist.txt   8.05KB   300 downloads
    (NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.)

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.

     
  • Run FRST/FRST64 from your Desktop and press the Fix button just once and wait.

    FRST_Fix_zps8lrdygec.png
  • If for some reason the tool needs a restart, please make sure you let the system restart normally.  After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop named Fixlog.txt. Please post the contents of that log file into your next reply.

 
Second
Run Junkware Removal Tool:

Please download Junkware Removal Tool to your DESKTOP.

  • Shut down your protection software now to avoid potential conflicts.  See here for more information.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator". 
  • The tool will open and start scanning your system. 
  • Please be patient as this can take a while to complete depending on your system's specifications. 
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open. 
  • Post the contents of JRT.txt into your next message.

 

Finally
Please post the contents of the requested logs in your reply:

  • FRST fixlog
  • JRT log

 


  • 0

#9
kid@hrt

kid@hrt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts

Hi Dan

 

I am truly sorry again for any trouble that my son might have caused, and thank you again for helping me.

 

Here are the logs. 

 

Fixlog.txt

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by Mom at 2015-03-27 11:06:21 Run:2
Running from C:\Users\Mom\Desktop
Loaded Profiles: Mom (Available profiles: Mom & Guest)
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
CreateRestorePoint:
() C:\Program Files (x86)\Ncmanthicisinessibias\Ncmanthicisinessibias.exe
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No FileHKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [S-1-5-21-2005915866-3535303436-4220142520-1000] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-2005915866-3535303436-4220142520-1000] => http=127.0.0.1:9880
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1me10IE11ENUS/MCM_WCP
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin HKU\S-1-5-21-2005915866-3535303436-4220142520-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Mom\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll No File
FF Plugin HKU\S-1-5-21-2005915866-3535303436-4220142520-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Mom\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll No File
CHR HomePage: Default -> hxxp://www.google.com/
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Mom\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.758\_platform_specific\win_x86\widevinecdmadapter.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\internal-nacl-plugin No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll No File
CHR HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Mom\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-08-19]
R2 Ncmanthicisinessibias; C:\Program Files (x86)\Ncmanthicisinessibias\Ncmanthicisinessibias.exe [256512 2015-03-19] () [File not signed] <==== ATTENTION
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
2015-03-22 17:56 - 2015-03-22 17:56 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\WebplayerRemote
2015-03-22 17:47 - 2015-03-22 17:47 - 00000000 __SHD () C:\Program Files (x86)\Ncmanthicisinessibias
2015-03-22 17:32 - 2015-03-22 17:32 - 01315328 _____ () C:\Users\Mom\AppData\Roaming\JLS.exe
2015-03-22 17:31 - 2015-03-23 16:59 - 00000000 ___HD () C:\Users\Public\Temp
2015-03-22 17:30 - 2015-03-22 17:31 - 00000000 ____D () C:\Program Files (x86)\75f58658-1636-481b-bb93-681528a7e956
2015-03-22 17:30 - 2015-03-22 17:30 - 00003278 _____ () C:\Windows\System32\Tasks\xOyz777ub8w9gWE
2015-03-22 17:30 - 2015-03-22 17:30 - 00003236 _____ () C:\Windows\System32\Tasks\vhSk5fGmqffH4XR
2015-03-22 17:30 - 2015-03-22 17:30 - 00003234 _____ () C:\Windows\System32\Tasks\QV7WrfASweRbfs0
2015-03-22 17:30 - 2015-03-22 17:30 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\PsjDFS8
2015-03-22 17:30 - 2015-03-22 17:30 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\Cd23RUL
2015-03-22 17:30 - 2015-03-22 17:30 - 00000000 ____D () C:\ProgramData\atjs
2015-03-22 17:29 - 2015-03-22 17:30 - 00000000 ____D () C:\Users\Mom\AppData\Roaming\Shafelo
2015-03-22 17:29 - 2015-03-22 17:30 - 00000000 ____D () C:\ProgramData\NVSMpxS
2015-03-22 17:28 - 2015-03-23 20:54 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2015-03-22 17:28 - 2015-03-22 17:28 - 01945600 _____ () C:\Users\Mom\AppData\Roaming\TNGJRWN.exe
2015-03-22 17:28 - 2015-03-22 17:28 - 00000000 ____D () C:\Users\Mom\AppData\Local\globalUpdate
2015-03-22 17:28 - 2015-03-12 02:40 - 04687360 _____ () C:\Windows\rcore.exe
2015-03-22 17:27 - 2015-03-22 17:27 - 00000000 ____D () C:\ProgramData\10a33e9e6bdb4696920e1858a4196f36
2015-03-20 17:56 - 2015-03-20 17:57 - 03894696 _____ (solvusoft Corporation ) C:\Users\Mom\Desktop\Tsusbhub.sys_Error_Repair_Tool-WinThruster.exe
2015-01-25 12:12 - 2015-01-25 12:12 - 0002086 _____ () C:\Users\Mom\AppData\Roaming\JLS
2015-03-22 17:32 - 2015-03-22 17:32 - 1315328 _____ () C:\Users\Mom\AppData\Roaming\JLS.exe
2015-03-09 17:30 - 2015-03-09 17:30 - 0005487 _____ () C:\Users\Mom\AppData\Roaming\TNGJRWN
2015-03-22 17:28 - 2015-03-22 17:28 - 1945600 _____ () C:\Users\Mom\AppData\Roaming\TNGJRWN.exe
C:\Users\Mom\jobq.dat
Task: {08AEE9B9-7DAE-427D-8853-93288ED79AF6} - System32\Tasks\xOyz777ub8w9gWE => C:\Users\Mom\AppData\Roaming\PsjDFS8\tPXFXtg.exe [2015-03-22] ()
Task: {137C7262-0DF3-4489-9F0E-FC84A6C0857E} - \CIMT_S-1-5-21-2005915866-3535303436-4220142520-1000 No Task File <==== ATTENTION
Task: {28BEF8B8-3CBD-47CE-A17D-538434CDFC89} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-5 No Task File <==== ATTENTION
Task: {297CC9FC-A122-46D2-B3E0-D2FDEF3A4DCA} - System32\Tasks\vhSk5fGmqffH4XR => C:\Users\Mom\AppData\Roaming\Cd23RUL\4mdbvfy.exe [2015-03-22] ( )
Task: {2CD2E74C-8DE7-4AA4-9B2A-8515C9B33570} - \Startup Time Check No Task File <==== ATTENTION
Task: {34A9A280-F251-4877-B32A-D7967E245BEE} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-7 No Task File <==== ATTENTION
Task: {350C4730-87B0-44E5-8FF2-D180098D64DB} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {36ED84F4-18D5-4156-9974-196CE15BF211} - \CIMT_daily_S-1-5-21-2005915866-3535303436-4220142520-1000 No Task File <==== ATTENTION
Task: {4BE93E40-334C-4A04-A40F-0252AF58B0A2} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-10_user No Task File <==== ATTENTION
Task: {6E0DC5F9-984F-483F-949D-AF6C41C961EA} - System32\Tasks\{75C18BE2-499E-466E-BFCD-75CEC0390CC0} => pcalua.exe -a "C:\Users\vin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H7D3XJTX\PlayerSetup[1].exe" -d C:\Users\vin\Desktop
Task: {8B0DA266-5086-4271-8FCE-1CE626019856} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-6 No Task File <==== ATTENTION
Task: {9FB5E7F8-28A6-43F1-8BC4-23B57C269DD6} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {A5678122-6EE9-4E63-9EC6-FFF16CEEE6ED} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-5_user No Task File <==== ATTENTION
Task: {B2BF22C8-D6DD-47CC-A046-7CEB168E98EB} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-4 No Task File <==== ATTENTION
Task: {BEE727AA-AF36-4766-A6E7-75640C848D11} - \ObronaCleanerUacSkip No Task File <==== ATTENTION
Task: {D764DC59-8EA6-4521-959E-F6426A047AA6} - \9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-1-7 No Task File <==== ATTENTION
Task: {DBA01E38-CA1B-4131-B0B9-69D6320BB468} - System32\Tasks\QV7WrfASweRbfs0 => C:\Users\Mom\AppData\Roaming\Shafelo\5BqPNyx.exe [2015-03-22] ()
2015-03-22 17:47 - 2015-03-19 13:01 - 00256512 ___SH () C:\Program Files (x86)\Ncmanthicisinessibias\Ncmanthicisinessibias.exe
AlternateDataStreams: C:\ProgramData\TEMP:27790C06
AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F
AlternateDataStreams: C:\ProgramData\TEMP:D987CB43
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Gambali => ""="service"
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\Classes\.exe:  =>  <===== ATTENTION!
cmd: ipconfig /release
cmd: ipconfig /renew 
cmd: ipconfig /flushdns 
cmd: netsh winsock reset all 
cmd: netsh int ip reset all
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state on
CMD: bitsadmin /reset /allusers
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
*****************
 
Restore point was successfully created.
C:\Program Files (x86)\Ncmanthicisinessibias\Ncmanthicisinessibias.exe => No running process found
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE => Value not found.
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE => Value not found.
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Control Panel\Desktop\\SCRNSAVE.EXE => Value not found.
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE => Value not found.
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => Key not found. 
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\SOFTWARE\Policies\Microsoft\Internet Explorer => Key not found. 
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value not found.
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\Microsoft\Internet Explorer\Main\\First Home Page => Value not found.
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331 => Key not found. 
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\MozillaPlugins\@tools.google.com/Google Update;version=3 => Key not found. 
C:\Users\Mom\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll not found.
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\MozillaPlugins\@tools.google.com/Google Update;version=9 => Key not found. 
C:\Users\Mom\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll not found.
Chrome HomePage deleted successfully.
C:\Users\Mom\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.758\_platform_specific\win_x86\widevinecdmadapter.dll not found.
C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\PepperFlash\pepflashplayer.dll not found.
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\internal-nacl-plugin No File not found.
C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.115\pdf.dll not found.
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll not found.
C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll not found.
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll not found.
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\SOFTWARE\Google\Chrome\Extensions\apdfllckaahabafndbhieahigkjlhalf => Key not found. 
"C:\Users\Mom\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx" => File/Directory not found.
Ncmanthicisinessibias => Service not found.
nvlddmkm => Service not found.
"C:\Users\Mom\AppData\Roaming\WebplayerRemote" => File/Directory not found.
"C:\Program Files (x86)\Ncmanthicisinessibias" => File/Directory not found.
"C:\Users\Mom\AppData\Roaming\JLS.exe" => File/Directory not found.
"C:\Users\Public\Temp" => File/Directory not found.
"C:\Program Files (x86)\75f58658-1636-481b-bb93-681528a7e956" => File/Directory not found.
"C:\Windows\System32\Tasks\xOyz777ub8w9gWE" => File/Directory not found.
"C:\Windows\System32\Tasks\vhSk5fGmqffH4XR" => File/Directory not found.
"C:\Windows\System32\Tasks\QV7WrfASweRbfs0" => File/Directory not found.
"C:\Users\Mom\AppData\Roaming\PsjDFS8" => File/Directory not found.
"C:\Users\Mom\AppData\Roaming\Cd23RUL" => File/Directory not found.
"C:\ProgramData\atjs" => File/Directory not found.
"C:\Users\Mom\AppData\Roaming\Shafelo" => File/Directory not found.
"C:\ProgramData\NVSMpxS" => File/Directory not found.
"C:\Program Files (x86)\globalUpdate" => File/Directory not found.
"C:\Users\Mom\AppData\Roaming\TNGJRWN.exe" => File/Directory not found.
"C:\Users\Mom\AppData\Local\globalUpdate" => File/Directory not found.
"C:\Windows\rcore.exe" => File/Directory not found.
"C:\ProgramData\10a33e9e6bdb4696920e1858a4196f36" => File/Directory not found.
"C:\Users\Mom\Desktop\Tsusbhub.sys_Error_Repair_Tool-WinThruster.exe" => File/Directory not found.
"C:\Users\Mom\AppData\Roaming\JLS" => File/Directory not found.
"C:\Users\Mom\AppData\Roaming\JLS.exe" => File/Directory not found.
"C:\Users\Mom\AppData\Roaming\TNGJRWN" => File/Directory not found.
"C:\Users\Mom\AppData\Roaming\TNGJRWN.exe" => File/Directory not found.
"C:\Users\Mom\jobq.dat" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{08AEE9B9-7DAE-427D-8853-93288ED79AF6} => Key not found. 
C:\Windows\System32\Tasks\xOyz777ub8w9gWE not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\xOyz777ub8w9gWE => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{137C7262-0DF3-4489-9F0E-FC84A6C0857E} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CIMT_S-1-5-21-2005915866-3535303436-4220142520-1000 => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{28BEF8B8-3CBD-47CE-A17D-538434CDFC89} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-5 => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{297CC9FC-A122-46D2-B3E0-D2FDEF3A4DCA} => Key not found. 
C:\Windows\System32\Tasks\vhSk5fGmqffH4XR not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\vhSk5fGmqffH4XR => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2CD2E74C-8DE7-4AA4-9B2A-8515C9B33570} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Startup Time Check => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{34A9A280-F251-4877-B32A-D7967E245BEE} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-7 => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{350C4730-87B0-44E5-8FF2-D180098D64DB} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36ED84F4-18D5-4156-9974-196CE15BF211} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CIMT_daily_S-1-5-21-2005915866-3535303436-4220142520-1000 => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4BE93E40-334C-4A04-A40F-0252AF58B0A2} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-10_user => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6E0DC5F9-984F-483F-949D-AF6C41C961EA} => Key not found. 
C:\Windows\System32\Tasks\{75C18BE2-499E-466E-BFCD-75CEC0390CC0} not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{75C18BE2-499E-466E-BFCD-75CEC0390CC0} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B0DA266-5086-4271-8FCE-1CE626019856} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-6 => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9FB5E7F8-28A6-43F1-8BC4-23B57C269DD6} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A5678122-6EE9-4E63-9EC6-FFF16CEEE6ED} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-5_user => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2BF22C8-D6DD-47CC-A046-7CEB168E98EB} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-4 => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BEE727AA-AF36-4766-A6E7-75640C848D11} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ObronaCleanerUacSkip => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D764DC59-8EA6-4521-959E-F6426A047AA6} => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9202acc2-e6ac-4b14-b5c4-24e28cf25bdb-1-7 => Key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DBA01E38-CA1B-4131-B0B9-69D6320BB468} => Key not found. 
C:\Windows\System32\Tasks\QV7WrfASweRbfs0 not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\QV7WrfASweRbfs0 => Key not found. 
"C:\Program Files (x86)\Ncmanthicisinessibias\Ncmanthicisinessibias.exe" => File/Directory not found.
"C:\ProgramData\TEMP" => ":27790C06" ADS not found.
"C:\ProgramData\TEMP" => ":2CB9631F" ADS not found.
"C:\ProgramData\TEMP" => ":D987CB43" ADS not found.
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\Gambali => Key not found. 
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\Classes\.exe => Key not found. 
 
=========  ipconfig /release =========
 
 
Windows IP Configuration
 
 
Ethernet adapter Local Area Connection:
 
   Connection-specific DNS Suffix  . : 
   Link-local IPv6 Address . . . . . : fe80::7c07:c893:1eed:7a66%10
   Default Gateway . . . . . . . . . : 
 
Tunnel adapter isatap.Home:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Teredo Tunneling Pseudo-Interface:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
========= End of CMD: =========
 
 
=========  ipconfig /renew =========
 
 
Windows IP Configuration
 
 
Ethernet adapter Local Area Connection:
 
   Connection-specific DNS Suffix  . : Home
   Link-local IPv6 Address . . . . . : fe80::7c07:c893:1eed:7a66%10
   IPv4 Address. . . . . . . . . . . : 192.168.254.6
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.254.254
 
Tunnel adapter isatap.Home:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
Tunnel adapter Teredo Tunneling Pseudo-Interface:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
 
========= End of CMD: =========
 
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========  netsh winsock reset all =========
 
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
========= End of CMD: =========
 
 
=========  netsh int ip reset all =========
 
Reseting Interface, OK!
Restart the computer to complete this action.
 
 
========= End of CMD: =========
 
 
=========  netsh advfirewall reset =========
 
Ok.
 
 
========= End of CMD: =========
 
 
=========  netsh advfirewall set allprofiles state on =========
 
Ok.
 
 
========= End of CMD: =========
 
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
Unable to cancel {6AFCD99C-E809-4BD8-AF65-494EB044BFA0}.
0 out of 1 jobs canceled.
 
========= End of CMD: =========
 
 
========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= RemoveProxy: =========
 
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully.
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully.
HKU\S-1-5-21-2005915866-3535303436-4220142520-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully.
 
 
========= End of RemoveProxy: =========
 
EmptyTemp: => Removed 12.5 GB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 11:39:22 ====
 
 
 
JRT.txt
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.6 (03.22.2015:1)
OS: Windows 7 Ultimate x64
Ran by Mom on Fri 03/27/2015 at 11:57:13.97
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-2005915866-3535303436-4220142520-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 03/27/2015 at 12:01:15.25
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

  • 0

#10
DanoNH

DanoNH

    Trusted Helper

  • Malware Removal
  • 2,155 posts

Thanks for the logs.  As far as the changes your son made, no worries here on my end.  These things happen.  I'm sure his intentions were good; he must be a wonderful son to want to help you out like that. :)

 

We have gotten most of the malware at this point, but there's still something going on with your system that I need to investigate some more.  I'll be back with further instructions soon...

 

In the meantime, please let me know how your computer is running.


  • 0

Advertisements


#11
kid@hrt

kid@hrt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts

Hello,

 

The redirects and popups seem to have stopped. The pc does take a long to boot up, and is sluggish sometimes. Occasionally when I click on something nothing happens, I have noticed it mostly with Chrome.

Also before the malware issue I had trouble with my display, it would freeze and the I would get a message saying "your display driver has stopped responding and has recovered".

I have know idea what that means. I was going to see if the inside of my computer tower was dirty and it may be overheating.

 

Thanks that's all I can think of right now.

 

Thanks again

LISA 


  • 0

#12
DanoNH

DanoNH

    Trusted Helper

  • Malware Removal
  • 2,155 posts

Hello Lisa,

 

This is great news!   Please understand that we are not quite done yet, so please hang on until I declare your system is clean.  I would appreciate your answers to my numbered questions below, and of course there are a couple more troubleshooting steps after those. :)

 

  1. Was the slow start-up and sluggish behavior there before the malware issues?  You do have a Tri-Core CPU with 6GB of RAM, which should be fine for most everyday use. 
     
  2. The message you are getting seems to point to an outdated graphics driver.  There is some further reading on that here (it's rather technical, however...).  You seem to have both AMD and nVidia display software installed (AMD Catalyst Install Manager, NVIDIA Display Control Panel, NVIDIA Drivers), which could create a potential conflict and possibly some of the slowdowns you are experiencing.  One of the tools we will run will collect that info for my review.  :geek:
     
  3. Is this a custom-built computer?  I didn't see much of the usual branding in your logs, like Dell or HP systems usually produce.  If it's not custom-built, what is the make and model (and approximate age)?
     
  4. Have you ever cleaned the fans and heat sinks inside your computer case before?  I have a pretty high-end system in my home office and clean it once a month, although my system is on 24/7.  Depending on use, I would check it every 1-3 months for dust build-up and the need for careful cleaning... (something your son might like to help with?). :)

 

OK, back to work getting you finished up here. ;)

 

 

First

Run a FRST Fix
 

  • Download the attached fixlist.txt file and save it to the DESKTOP.
    Attached File  fixlist.txt   117bytes   218 downloads
    (NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.)

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.
  • Run FRST/FRST64 from your Desktop and press the Fix button just once and wait.
    FRST_Fix_zps8lrdygec.png
  • If for some reason the tool needs a restart, please make sure you let the system restart normally.  After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop named Fixlog.txt. Please post the contents of that log file into your next reply.


Second

Generate an MSinfo32 log:

  • Go to Start > Run > type "msinfo32.exe"
  • In the left column, make sure to click on the words System Summary at the top.
  • Select File > Export
  • Browse to an appropriate location to save the file
  • Type a filename into the appropriate field and ensure the "Save as type" is set to "Text File (*.txt)"
  • Click the "Save" button.
  • Attach the log to your next post.

  • 0

#13
kid@hrt

kid@hrt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts

Good Evening,
 
 
1.  Yes, the pc was booting up slowing before the malware problem.
 
2. Should I use the fixitforme? 
 
3. Yes my computer is custom built.
 
4. I have cleaned the fans and heat sink, but it has been several months.
 
 
Fixlog.txt
 
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by Mom at 2015-03-27 18:22:23 Run:3
Running from C:\Users\Mom\Desktop
Loaded Profiles: Mom (Available profiles: Mom & Guest)
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
start
CreateRestorePoint:
CMD: bitsadmin /list /allusers /verbose
CMD: bitsadmin /reset /allusers
EmptyTemp:
end
*****************
 
Restore point was successfully created.
 
=========  bitsadmin /list /allusers /verbose =========
 
 
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
Listed 0 job(s).
 
========= End of CMD: =========
 
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
0 out of 0 jobs canceled.
 
========= End of CMD: =========
 
EmptyTemp: => Removed 294.7 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 18:22:41 ====
 
 
System Summary
 
System Information report written at: 03/27/15 18:30:49
System Name: MOM-PC
[System Summary]
 
Item Value
OS Name Microsoft Windows 7 Ultimate
Version 6.1.7601 Service Pack 1 Build 7601
Other OS Description Not Available
OS Manufacturer Microsoft Corporation
System Name MOM-PC
System Manufacturer BIOSTAR Group
System Model MCP6P3
System Type x64-based PC
Processor AMD Athlon™ II X3 445 Processor, 3100 Mhz, 3 Core(s), 3 Logical Processor(s)
BIOS Version/Date American Megatrends Inc. 080015, 11/24/2009
SMBIOS Version 2.6
Windows Directory C:\Windows
System Directory C:\Windows\system32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "6.1.7601.17514"
User Name Mom-PC\Mom
Time Zone Eastern Daylight Time
Installed Physical Memory (RAM) 6.00 GB
Total Physical Memory 6.00 GB
Available Physical Memory 3.56 GB
Total Virtual Memory 12.0 GB
Available Virtual Memory 9.70 GB
Page File Space 6.00 GB
Page File C:\pagefile.sys
 
[Hardware Resources]
 
 
 
[Conflicts/Sharing]
 
Resource Device
I/O Port 0x00000000-0x00000CF7 PCI bus
I/O Port 0x00000000-0x00000CF7 Direct memory access controller
 
I/O Port 0x000003C0-0x000003DF ATI Radeon HD 4800 Series
I/O Port 0x000003C0-0x000003DF PCI Express standard Root Port
 
IRQ 20 NVIDIA nForce System Management Controller
IRQ 20 NVIDIA nForce Serial ATA Controller
IRQ 20 NVIDIA nForce 10/100 Mbps Ethernet
 
IRQ 21 NVIDIA nForce Serial ATA Controller
IRQ 21 High Definition Audio Controller
 
I/O Port 0x0000E000-0x0000E0FF ATI Radeon HD 4800 Series
I/O Port 0x0000E000-0x0000E0FF PCI Express standard Root Port
 
Memory Address 0xFEC00000-0xFFFFFFFF System board
Memory Address 0xFEC00000-0xFFFFFFFF Motherboard resources
 
Memory Address 0xC0000000-0xDFFFFFFF PCI bus
Memory Address 0xC0000000-0xDFFFFFFF ATI Radeon HD 4800 Series
Memory Address 0xC0000000-0xDFFFFFFF PCI Express standard Root Port
 
Memory Address 0xD0000-0xDFFFF PCI bus
Memory Address 0xD0000-0xDFFFF Motherboard resources
 
Memory Address 0xA0000-0xBFFFF PCI bus
Memory Address 0xA0000-0xBFFFF ATI Radeon HD 4800 Series
Memory Address 0xA0000-0xBFFFF PCI Express standard Root Port
 
I/O Port 0x000003B0-0x000003BB ATI Radeon HD 4800 Series
I/O Port 0x000003B0-0x000003BB PCI Express standard Root Port
 
 
[DMA]
 
Resource Device Status
Channel 2 Standard floppy disk controller OK
Channel 4 Direct memory access controller OK
 
[Forced Hardware]
 
Device PNP Device ID
 
[I/O]
 
Resource Device Status
0x00000378-0x0000037F Printer Port (LPT1) OK
0x000001F0-0x000001F7 ATA Channel 0 OK
0x000003F6-0x000003F6 ATA Channel 0 OK
0x000003F8-0x000003FF Communications Port (COM1) OK
0x000003F0-0x000003F5 Standard floppy disk controller OK
0x000003F7-0x000003F7 Standard floppy disk controller OK
0x00000170-0x00000177 ATA Channel 1 OK
0x00000376-0x00000376 ATA Channel 1 OK
0x00000061-0x00000061 System speaker OK
0x00000000-0x00000CF7 PCI bus OK
0x00000000-0x00000CF7 Direct memory access controller OK
0x00000D00-0x0000FFFF PCI bus OK
0x00000070-0x00000071 System CMOS/real time clock OK
0x00000060-0x00000060 Motherboard resources OK
0x00000064-0x00000064 Motherboard resources OK
0x00000010-0x0000001F Motherboard resources OK
0x00000022-0x0000003F Motherboard resources OK
0x00000044-0x0000004D Motherboard resources OK
0x00000050-0x0000005F Motherboard resources OK
0x00000062-0x00000063 Motherboard resources OK
0x00000065-0x0000006F Motherboard resources OK
0x00000072-0x0000007F Motherboard resources OK
0x00000080-0x00000080 Motherboard resources OK
0x00000084-0x00000086 Motherboard resources OK
0x00000088-0x00000088 Motherboard resources OK
0x0000008C-0x0000008E Motherboard resources OK
0x00000090-0x0000009F Motherboard resources OK
0x000000A2-0x000000BF Motherboard resources OK
0x000000E0-0x000000EF Motherboard resources OK
0x000004D0-0x000004D1 Motherboard resources OK
0x00000800-0x0000080F Motherboard resources OK
0x00004000-0x0000407F Motherboard resources OK
0x00004080-0x000040FF Motherboard resources OK
0x00004400-0x0000447F Motherboard resources OK
0x00004480-0x000044FF Motherboard resources OK
0x00004800-0x0000487F Motherboard resources OK
0x00004880-0x000048FF Motherboard resources OK
0x00004C00-0x00004C7F Motherboard resources OK
0x00004C80-0x00004CFF Motherboard resources OK
0x00004900-0x0000493F NVIDIA nForce System Management OK
0x00004D00-0x00004D3F NVIDIA nForce System Management OK
0x00004E00-0x00004E3F NVIDIA nForce System Management OK
0x00000A00-0x00000A0F Motherboard resources OK
0x00000A10-0x00000A1F Motherboard resources OK
0x00000A20-0x00000A2F Motherboard resources OK
0x00000A30-0x00000A3F Motherboard resources OK
0x000000F0-0x000000FF Numeric data processor OK
0x0000FFA0-0x0000FFAF Standard Dual Channel PCI IDE Controller OK
0x0000D400-0x0000D407 NVIDIA nForce Serial ATA Controller OK
0x0000D080-0x0000D083 NVIDIA nForce Serial ATA Controller OK
0x0000D000-0x0000D007 NVIDIA nForce Serial ATA Controller OK
0x0000CC00-0x0000CC03 NVIDIA nForce Serial ATA Controller OK
0x0000C880-0x0000C88F NVIDIA nForce Serial ATA Controller OK
0x0000C800-0x0000C807 NVIDIA nForce Serial ATA Controller OK
0x0000C480-0x0000C483 NVIDIA nForce Serial ATA Controller OK
0x0000C400-0x0000C407 NVIDIA nForce Serial ATA Controller OK
0x0000C080-0x0000C083 NVIDIA nForce Serial ATA Controller OK
0x0000C000-0x0000C00F NVIDIA nForce Serial ATA Controller OK
0x0000E000-0x0000E0FF ATI Radeon HD 4800 Series OK
0x0000E000-0x0000E0FF PCI Express standard Root Port OK
0x000003B0-0x000003BB ATI Radeon HD 4800 Series OK
0x000003B0-0x000003BB PCI Express standard Root Port OK
0x000003C0-0x000003DF ATI Radeon HD 4800 Series OK
0x000003C0-0x000003DF PCI Express standard Root Port OK
0x00000020-0x00000021 Programmable interrupt controller OK
0x000000A0-0x000000A1 Programmable interrupt controller OK
0x00000040-0x00000043 System timer OK
0x00000081-0x00000083 Direct memory access controller OK
0x00000087-0x00000087 Direct memory access controller OK
0x00000089-0x0000008B Direct memory access controller OK
0x0000008F-0x0000008F Direct memory access controller OK
0x000000C0-0x000000DF Direct memory access controller OK
 
[IRQs]
 
Resource Device Status
IRQ 4294967293 PCI Express standard Root Port OK
IRQ 22 Standard Enhanced PCI to USB Host Controller OK
IRQ 14 ATA Channel 0 OK
IRQ 4 Communications Port (COM1) OK
IRQ 6 Standard floppy disk controller OK
IRQ 15 ATA Channel 1 OK
IRQ 4294967292 PCI Express standard Root Port OK
IRQ 8 System CMOS/real time clock OK
IRQ 20 NVIDIA nForce System Management Controller OK
IRQ 20 NVIDIA nForce Serial ATA Controller OK
IRQ 20 NVIDIA nForce 10/100 Mbps Ethernet OK
IRQ 11 NVIDIA nForce System Management OK
IRQ 13 Numeric data processor OK
IRQ 81 Microsoft ACPI-Compliant System OK
IRQ 82 Microsoft ACPI-Compliant System OK
IRQ 83 Microsoft ACPI-Compliant System OK
IRQ 84 Microsoft ACPI-Compliant System OK
IRQ 85 Microsoft ACPI-Compliant System OK
IRQ 86 Microsoft ACPI-Compliant System OK
IRQ 87 Microsoft ACPI-Compliant System OK
IRQ 88 Microsoft ACPI-Compliant System OK
IRQ 89 Microsoft ACPI-Compliant System OK
IRQ 90 Microsoft ACPI-Compliant System OK
IRQ 91 Microsoft ACPI-Compliant System OK
IRQ 92 Microsoft ACPI-Compliant System OK
IRQ 93 Microsoft ACPI-Compliant System OK
IRQ 94 Microsoft ACPI-Compliant System OK
IRQ 95 Microsoft ACPI-Compliant System OK
IRQ 96 Microsoft ACPI-Compliant System OK
IRQ 97 Microsoft ACPI-Compliant System OK
IRQ 98 Microsoft ACPI-Compliant System OK
IRQ 99 Microsoft ACPI-Compliant System OK
IRQ 100 Microsoft ACPI-Compliant System OK
IRQ 101 Microsoft ACPI-Compliant System OK
IRQ 102 Microsoft ACPI-Compliant System OK
IRQ 103 Microsoft ACPI-Compliant System OK
IRQ 104 Microsoft ACPI-Compliant System OK
IRQ 105 Microsoft ACPI-Compliant System OK
IRQ 106 Microsoft ACPI-Compliant System OK
IRQ 107 Microsoft ACPI-Compliant System OK
IRQ 108 Microsoft ACPI-Compliant System OK
IRQ 109 Microsoft ACPI-Compliant System OK
IRQ 110 Microsoft ACPI-Compliant System OK
IRQ 111 Microsoft ACPI-Compliant System OK
IRQ 112 Microsoft ACPI-Compliant System OK
IRQ 113 Microsoft ACPI-Compliant System OK
IRQ 114 Microsoft ACPI-Compliant System OK
IRQ 115 Microsoft ACPI-Compliant System OK
IRQ 116 Microsoft ACPI-Compliant System OK
IRQ 117 Microsoft ACPI-Compliant System OK
IRQ 118 Microsoft ACPI-Compliant System OK
IRQ 119 Microsoft ACPI-Compliant System OK
IRQ 120 Microsoft ACPI-Compliant System OK
IRQ 121 Microsoft ACPI-Compliant System OK
IRQ 122 Microsoft ACPI-Compliant System OK
IRQ 123 Microsoft ACPI-Compliant System OK
IRQ 124 Microsoft ACPI-Compliant System OK
IRQ 125 Microsoft ACPI-Compliant System OK
IRQ 126 Microsoft ACPI-Compliant System OK
IRQ 127 Microsoft ACPI-Compliant System OK
IRQ 128 Microsoft ACPI-Compliant System OK
IRQ 129 Microsoft ACPI-Compliant System OK
IRQ 130 Microsoft ACPI-Compliant System OK
IRQ 131 Microsoft ACPI-Compliant System OK
IRQ 132 Microsoft ACPI-Compliant System OK
IRQ 133 Microsoft ACPI-Compliant System OK
IRQ 134 Microsoft ACPI-Compliant System OK
IRQ 135 Microsoft ACPI-Compliant System OK
IRQ 136 Microsoft ACPI-Compliant System OK
IRQ 137 Microsoft ACPI-Compliant System OK
IRQ 138 Microsoft ACPI-Compliant System OK
IRQ 139 Microsoft ACPI-Compliant System OK
IRQ 140 Microsoft ACPI-Compliant System OK
IRQ 141 Microsoft ACPI-Compliant System OK
IRQ 142 Microsoft ACPI-Compliant System OK
IRQ 143 Microsoft ACPI-Compliant System OK
IRQ 144 Microsoft ACPI-Compliant System OK
IRQ 145 Microsoft ACPI-Compliant System OK
IRQ 146 Microsoft ACPI-Compliant System OK
IRQ 147 Microsoft ACPI-Compliant System OK
IRQ 148 Microsoft ACPI-Compliant System OK
IRQ 149 Microsoft ACPI-Compliant System OK
IRQ 150 Microsoft ACPI-Compliant System OK
IRQ 151 Microsoft ACPI-Compliant System OK
IRQ 152 Microsoft ACPI-Compliant System OK
IRQ 153 Microsoft ACPI-Compliant System OK
IRQ 154 Microsoft ACPI-Compliant System OK
IRQ 155 Microsoft ACPI-Compliant System OK
IRQ 156 Microsoft ACPI-Compliant System OK
IRQ 157 Microsoft ACPI-Compliant System OK
IRQ 158 Microsoft ACPI-Compliant System OK
IRQ 159 Microsoft ACPI-Compliant System OK
IRQ 160 Microsoft ACPI-Compliant System OK
IRQ 161 Microsoft ACPI-Compliant System OK
IRQ 162 Microsoft ACPI-Compliant System OK
IRQ 163 Microsoft ACPI-Compliant System OK
IRQ 164 Microsoft ACPI-Compliant System OK
IRQ 165 Microsoft ACPI-Compliant System OK
IRQ 166 Microsoft ACPI-Compliant System OK
IRQ 167 Microsoft ACPI-Compliant System OK
IRQ 168 Microsoft ACPI-Compliant System OK
IRQ 169 Microsoft ACPI-Compliant System OK
IRQ 170 Microsoft ACPI-Compliant System OK
IRQ 171 Microsoft ACPI-Compliant System OK
IRQ 172 Microsoft ACPI-Compliant System OK
IRQ 173 Microsoft ACPI-Compliant System OK
IRQ 174 Microsoft ACPI-Compliant System OK
IRQ 175 Microsoft ACPI-Compliant System OK
IRQ 176 Microsoft ACPI-Compliant System OK
IRQ 177 Microsoft ACPI-Compliant System OK
IRQ 178 Microsoft ACPI-Compliant System OK
IRQ 179 Microsoft ACPI-Compliant System OK
IRQ 180 Microsoft ACPI-Compliant System OK
IRQ 181 Microsoft ACPI-Compliant System OK
IRQ 182 Microsoft ACPI-Compliant System OK
IRQ 183 Microsoft ACPI-Compliant System OK
IRQ 184 Microsoft ACPI-Compliant System OK
IRQ 185 Microsoft ACPI-Compliant System OK
IRQ 186 Microsoft ACPI-Compliant System OK
IRQ 187 Microsoft ACPI-Compliant System OK
IRQ 188 Microsoft ACPI-Compliant System OK
IRQ 189 Microsoft ACPI-Compliant System OK
IRQ 190 Microsoft ACPI-Compliant System OK
IRQ 21 NVIDIA nForce Serial ATA Controller OK
IRQ 21 High Definition Audio Controller OK
IRQ 4294967291 ATI Radeon HD 4800 Series OK
IRQ 0 System timer OK
IRQ 18 High Definition Audio Controller OK
IRQ 4294967294 PCI Express standard Root Port OK
IRQ 23 Standard OpenHCD USB Host Controller OK
 
[Memory]
 
Resource Device Status
0xDFE7EC00-0xDFE7ECFF Standard Enhanced PCI to USB Host Controller OK
0xA0000-0xBFFFF PCI bus OK
0xA0000-0xBFFFF ATI Radeon HD 4800 Series OK
0xA0000-0xBFFFF PCI Express standard Root Port OK
0xD0000-0xDFFFF PCI bus OK
0xD0000-0xDFFFF Motherboard resources OK
0xC0000000-0xDFFFFFFF PCI bus OK
0xC0000000-0xDFFFFFFF ATI Radeon HD 4800 Series OK
0xC0000000-0xDFFFFFFF PCI Express standard Root Port OK
0xF0000000-0xFEBFFFFF PCI bus OK
0xFEB80000-0xFEBFFFFF NVIDIA nForce System Management Controller OK
0x0000-0x9FFFF System board OK
0xC0000-0xCFFFF System board OK
0xE0000-0xFFFFF System board OK
0x100000-0xBFFFFFFF System board OK
0xFEC00000-0xFFFFFFFF System board OK
0xFEC00000-0xFFFFFFFF Motherboard resources OK
0xFEE00000-0xFEE00FFF Motherboard resources OK
0xD4000-0xD7FFF Motherboard resources OK
0xDE000-0xDFFFF Motherboard resources OK
0xFEC80000-0xFD93FFFF Motherboard resources OK
0xFEFE0000-0xFEFE01FF Motherboard resources OK
0xFEFE1000-0xFEFE1FFF Motherboard resources OK
0xFEE01000-0xFEEFFFFF Motherboard resources OK
0xFFB80000-0xFFFFFFFF Motherboard resources OK
0xE0000000-0xEFFFFFFF Motherboard resources OK
0xDFE7C000-0xDFE7CFFF NVIDIA nForce Serial ATA Controller OK
0xDFE7D000-0xDFE7DFFF NVIDIA nForce 10/100 Mbps Ethernet OK
0xDFE77000-0xDFE77FFF NVIDIA nForce Serial ATA Controller OK
0xDFFF0000-0xDFFFFFFF ATI Radeon HD 4800 Series OK
0xDFE78000-0xDFE7BFFF High Definition Audio Controller OK
0xDFFEC000-0xDFFEFFFF High Definition Audio Controller OK
0xDFF00000-0xDFFFFFFF PCI Express standard Root Port OK
0xDFE7F000-0xDFE7FFFF Standard OpenHCD USB Host Controller OK
0xFEFF0000-0xFEFF0FFF High precision event timer OK
 
[Components]
 
 
 
[Multimedia]
 
 
 
[Audio Codecs]
 
CODEC Manufacturer Description Status File Version Size Creation Date
c:\windows\system32\imaadp32.acm Microsoft Corporation OK C:\Windows\system32\IMAADP32.ACM 6.1.7600.16385 21.50 KB (22,016 bytes) 7/13/2009 8:18 PM
c:\windows\system32\msg711.acm Microsoft Corporation OK C:\Windows\system32\MSG711.ACM 6.1.7600.16385 14.50 KB (14,848 bytes) 7/13/2009 8:18 PM
c:\windows\system32\msgsm32.acm Microsoft Corporation OK C:\Windows\system32\MSGSM32.ACM 6.1.7600.16385 28.50 KB (29,184 bytes) 7/13/2009 8:18 PM
c:\windows\system32\msadp32.acm Microsoft Corporation OK C:\Windows\system32\MSADP32.ACM 6.1.7600.16385 23.50 KB (24,064 bytes) 7/13/2009 8:18 PM
c:\windows\system32\l3codeca.acm Fraunhofer Institut Integrierte Schaltungen IIS Fraunhofer IIS MPEG Layer-3 Codec OK C:\Windows\system32\L3CODECA.ACM 1.9.0.401 79.50 KB (81,408 bytes) 7/13/2009 8:22 PM
 
[Video Codecs]
 
CODEC Manufacturer Description Status File Version Size Creation Date
c:\windows\system32\msvidc32.dll Microsoft Corporation OK C:\Windows\system32\MSVIDC32.DLL 6.1.7601.17514 38.00 KB (38,912 bytes) 7/3/2011 10:51 AM
c:\windows\system32\msrle32.dll Microsoft Corporation OK C:\Windows\system32\MSRLE32.DLL 6.1.7601.17514 16.00 KB (16,384 bytes) 7/3/2011 10:50 AM
c:\windows\system32\msyuv.dll Microsoft Corporation OK C:\Windows\system32\MSYUV.DLL 6.1.7601.17514 25.00 KB (25,600 bytes) 7/3/2011 10:50 AM
c:\windows\system32\iyuv_32.dll Microsoft Corporation OK C:\Windows\system32\IYUV_32.DLL 6.1.7601.17514 53.00 KB (54,272 bytes) 7/3/2011 10:51 AM
c:\windows\system32\tsbyuv.dll Microsoft Corporation OK C:\Windows\system32\TSBYUV.DLL 6.1.7601.17514 14.50 KB (14,848 bytes) 7/3/2011 10:50 AM
 
[CD-ROM]
 
Item Value
Drive E:
Description CD-ROM Drive
Media Loaded No
Media Type DVD-ROM
Name HL-DT-ST DVD-ROM GDRH10N SCSI CdRom Device
Manufacturer (Standard CD-ROM drives)
Status OK
Transfer Rate -1.00 kbytes/sec
SCSI Target ID 0
PNP Device ID SCSI\CDROM&VEN_HL-DT-ST&PROD_DVD-ROM_GDRH10N\4&3409F703&0&000000
Driver c:\windows\system32\drivers\cdrom.sys (6.1.7601.17514, 144.00 KB (147,456 bytes), 7/3/2011 10:50 AM)
 
Drive D:
Description CD-ROM Drive
Media Loaded No
Media Type DVD Writer
Name TSSTcorp DVD+-RW TS-H553A SCSI CdRom Device
Manufacturer (Standard CD-ROM drives)
Status OK
Transfer Rate -1.00 kbytes/sec
SCSI Target ID 1
PNP Device ID SCSI\CDROM&VEN_TSSTCORP&PROD_DVD+-RW_TS-H553A\4&2150465E&0&010100
Driver c:\windows\system32\drivers\cdrom.sys (6.1.7601.17514, 144.00 KB (147,456 bytes), 7/3/2011 10:50 AM)
 
[Sound Device]
 
Item Value
Name AMD High Definition Audio Device
Manufacturer Advanced Micro Devices
Status OK
PNP Device ID HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1001\5&16921D69&0&0001
Driver c:\windows\system32\drivers\atihdw76.sys (7.12.0.7708, 94.63 KB (96,896 bytes), 5/14/2012 2:12 AM)
 
Name Realtek High Definition Audio
Manufacturer Realtek
Status OK
PNP Device ID HDAUDIO\FUNC_01&VEN_10EC&DEV_0662&SUBSYS_1565821F&REV_1001\4&3B48D8A0&0&0001
Driver c:\windows\system32\drivers\rtkvhd64.sys (6.0.1.5928, 1.90 MB (1,992,352 bytes), 12/2/2010 4:38 PM)
 
[Display]
 
Item Value
Name ATI Radeon HD 4800 Series
PNP Device ID PCI\VEN_1002&DEV_9442&SUBSYS_22661787&REV_00\4&43FF784&0&0048
Adapter Type ATI display adapter (0x9442), Advanced Micro Devices, Inc. compatible
Adapter Description ATI Radeon HD 4800 Series
Adapter RAM 512.00 MB (536,870,912 bytes)
Installed Drivers aticfx64.dll,aticfx64.dll,aticfx64.dll,aticfx32,aticfx32,aticfx32,atiumd64.dll,atidxx64.dll,atidxx64.dll,atiumdag,atidxx32,atidxx32,atiumdva,atiumd6a.cap,atitmm64.dll
Driver Version 8.970.100.7000
INF File oem19.inf (ati2mtag_RV7X section)
Color Planes Not Available
Color Table Entries 4294967296
Resolution 1920 x 1080 x 60 hertz
Bits/Pixel 32
Memory Address 0xC0000000-0xDFFFFFFF
Memory Address 0xDFFF0000-0xDFFFFFFF
I/O Port 0x0000E000-0x0000E0FF
IRQ Channel IRQ 4294967291
I/O Port 0x000003B0-0x000003BB
I/O Port 0x000003C0-0x000003DF
Memory Address 0xA0000-0xBFFFF
Driver c:\windows\system32\drivers\atikmpag.sys (8.14.1.6264, 351.50 KB (359,936 bytes), 11/16/2012 2:39 PM)
 
[Infrared]
 
Item Value
 
[Input]
 
 
 
[Keyboard]
 
Item Value
Description USB Input Device
Name Enhanced (101- or 102-key)
Layout 00000409
PNP Device ID USB\VID_413C&PID_2003\5&2B6C59D0&0&4
Number of Function Keys 12
Driver c:\windows\system32\drivers\hidusb.sys (6.1.7601.17514, 29.50 KB (30,208 bytes), 7/3/2011 10:50 AM)
 
[Pointing Device]
 
Item Value
Hardware Type USB Input Device
Number of Buttons 0
Status OK
PNP Device ID USB\VID_046D&PID_C025\5&2B6C59D0&0&3
Power Management Supported No
Double Click Threshold Not Available
Handedness Not Available
Driver c:\windows\system32\drivers\hidusb.sys (6.1.7601.17514, 29.50 KB (30,208 bytes), 7/3/2011 10:50 AM)
 
[Modem]
 
Item Value
 
[Network]
 
 
 
[Adapter]
 
Item Value
Name [00000000] WAN Miniport (SSTP)
Adapter Type Not Available
Product Type WAN Miniport (SSTP)
Installed Yes
PNP Device ID ROOT\MS_SSTPMINIPORT\0000
Last Reset 3/27/2015 6:23 PM
Index 0
Service Name RasSstp
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
Driver c:\windows\system32\drivers\rassstp.sys (6.1.7600.16385, 82.00 KB (83,968 bytes), 7/13/2009 8:10 PM)
 
Name [00000001] WAN Miniport (IKEv2)
Adapter Type Not Available
Product Type WAN Miniport (IKEv2)
Installed Yes
PNP Device ID ROOT\MS_AGILEVPNMINIPORT\0000
Last Reset 3/27/2015 6:23 PM
Index 1
Service Name RasAgileVpn
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
Driver c:\windows\system32\drivers\agilevpn.sys (6.1.7600.16385, 59.00 KB (60,416 bytes), 7/13/2009 8:10 PM)
 
Name [00000002] WAN Miniport (L2TP)
Adapter Type Not Available
Product Type WAN Miniport (L2TP)
Installed Yes
PNP Device ID ROOT\MS_L2TPMINIPORT\0000
Last Reset 3/27/2015 6:23 PM
Index 2
Service Name Rasl2tp
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
Driver c:\windows\system32\drivers\rasl2tp.sys (6.1.7601.17514, 126.50 KB (129,536 bytes), 7/3/2011 10:51 AM)
 
Name [00000003] WAN Miniport (PPTP)
Adapter Type Not Available
Product Type WAN Miniport (PPTP)
Installed Yes
PNP Device ID ROOT\MS_PPTPMINIPORT\0000
Last Reset 3/27/2015 6:23 PM
Index 3
Service Name PptpMiniport
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
Driver c:\windows\system32\drivers\raspptp.sys (6.1.7601.17514, 108.50 KB (111,104 bytes), 7/3/2011 10:51 AM)
 
Name [00000004] WAN Miniport (PPPOE)
Adapter Type Not Available
Product Type WAN Miniport (PPPOE)
Installed Yes
PNP Device ID ROOT\MS_PPPOEMINIPORT\0000
Last Reset 3/27/2015 6:23 PM
Index 4
Service Name RasPppoe
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
Driver c:\windows\system32\drivers\raspppoe.sys (6.1.7600.16385, 90.50 KB (92,672 bytes), 7/13/2009 8:10 PM)
 
Name [00000005] WAN Miniport (IPv6)
Adapter Type Not Available
Product Type WAN Miniport (IPv6)
Installed Yes
PNP Device ID ROOT\MS_NDISWANIPV6\0000
Last Reset 3/27/2015 6:23 PM
Index 5
Service Name NdisWan
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
Driver c:\windows\system32\drivers\ndiswan.sys (6.1.7601.17514, 160.50 KB (164,352 bytes), 7/3/2011 10:51 AM)
 
Name [00000006] WAN Miniport (Network Monitor)
Adapter Type Not Available
Product Type WAN Miniport (Network Monitor)
Installed Yes
PNP Device ID ROOT\MS_NDISWANBH\0000
Last Reset 3/27/2015 6:23 PM
Index 6
Service Name NdisWan
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
Driver c:\windows\system32\drivers\ndiswan.sys (6.1.7601.17514, 160.50 KB (164,352 bytes), 7/3/2011 10:51 AM)
 
Name [00000007] NVIDIA nForce Networking Controller
Adapter Type Ethernet 802.3
Product Type NVIDIA nForce Networking Controller
Installed Yes
PNP Device ID PCI\VEN_10DE&DEV_03EF&SUBSYS_34071565&REV_A2\3&267A616A&0&38
Last Reset 3/27/2015 6:23 PM
Index 7
Service Name NVNET
IP Address 192.168.254.6, fe80::7c07:c893:1eed:7a66
IP Subnet 255.255.255.0, 64
Default IP Gateway 192.168.254.254
DHCP Enabled Yes
DHCP Server 192.168.254.254
DHCP Lease Expires 9/17/2022 9:24 AM
DHCP Lease Obtained 3/27/2015 6:24 PM
MAC Address 00:30:67:52:9C:86
Memory Address 0xDFE7D000-0xDFE7DFFF
IRQ Channel IRQ 20
Driver c:\windows\system32\drivers\nvmf6264.sys (7.3.1.7335, 342.73 KB (350,952 bytes), 8/12/2010 12:07 PM)
 
Name [00000008] WAN Miniport (IP)
Adapter Type Not Available
Product Type WAN Miniport (IP)
Installed Yes
PNP Device ID ROOT\MS_NDISWANIP\0000
Last Reset 3/27/2015 6:23 PM
Index 8
Service Name NdisWan
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
Driver c:\windows\system32\drivers\ndiswan.sys (6.1.7601.17514, 160.50 KB (164,352 bytes), 7/3/2011 10:51 AM)
 
Name [00000009] Microsoft ISATAP Adapter
Adapter Type Tunnel
Product Type Microsoft ISATAP Adapter
Installed Yes
PNP Device ID ROOT\*ISATAP\0000
Last Reset 3/27/2015 6:23 PM
Index 9
Service Name tunnel
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
Driver c:\windows\system32\drivers\tunnel.sys (6.1.7601.17514, 122.50 KB (125,440 bytes), 7/3/2011 10:50 AM)
 
Name [00000010] RAS Async Adapter
Adapter Type Not Available
Product Type RAS Async Adapter
Installed Yes
PNP Device ID Not Available
Last Reset 3/27/2015 6:23 PM
Index 10
Service Name AsyncMac
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
 
Name [00000011] Microsoft Teredo Tunneling Adapter
Adapter Type Tunnel
Product Type Microsoft Teredo Tunneling Adapter
Installed Yes
PNP Device ID ROOT\*TEREDO\0000
Last Reset 3/27/2015 6:23 PM
Index 11
Service Name tunnel
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
Driver c:\windows\system32\drivers\tunnel.sys (6.1.7601.17514, 122.50 KB (125,440 bytes), 7/3/2011 10:50 AM)
 
Name [00000012] Microsoft ISATAP Adapter
Adapter Type Tunnel
Product Type Microsoft ISATAP Adapter
Installed Yes
PNP Device ID ROOT\*ISATAP\0001
Last Reset 3/27/2015 6:23 PM
Index 12
Service Name tunnel
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled No
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
Driver c:\windows\system32\drivers\tunnel.sys (6.1.7601.17514, 122.50 KB (125,440 bytes), 7/3/2011 10:50 AM)
 
Name [00000013] SAMSUNG Android USB Remote NDIS Network Device
Adapter Type Not Available
Product Type SAMSUNG Android USB Remote NDIS Network Device
Installed Yes
PNP Device ID Not Available
Last Reset 3/27/2015 6:23 PM
Index 13
Service Name usb_rndisx
IP Address Not Available
IP Subnet Not Available
Default IP Gateway Not Available
DHCP Enabled Yes
DHCP Server Not Available
DHCP Lease Expires Not Available
DHCP Lease Obtained Not Available
MAC Address Not Available
 
[Protocol]
 
Item Value
Name MSAFD Tcpip [TCP/IPv6]
Connectionless Service No
Guarantees Delivery Yes
Guarantees Sequencing Yes
Maximum Address Size 28 bytes
Maximum Message Size 0 bytes
Message Oriented No
Minimum Address Size 28 bytes
Pseudo Stream Oriented No
Supports Broadcasting No
Supports Connect Data No
Supports Disconnect Data No
Supports Encryption No
Supports Expedited Data Yes
Supports Graceful Closing Yes
Supports Guaranteed Bandwidth No
Supports Multicasting No
 
Name MSAFD Tcpip [UDP/IPv6]
Connectionless Service Yes
Guarantees Delivery No
Guarantees Sequencing No
Maximum Address Size 28 bytes
Maximum Message Size 63.99 KB (65,527 bytes)
Message Oriented Yes
Minimum Address Size 28 bytes
Pseudo Stream Oriented No
Supports Broadcasting Yes
Supports Connect Data No
Supports Disconnect Data No
Supports Encryption No
Supports Expedited Data No
Supports Graceful Closing No
Supports Guaranteed Bandwidth No
Supports Multicasting Yes
 
Name MSAFD Tcpip [TCP/IP]
Connectionless Service No
Guarantees Delivery Yes
Guarantees Sequencing Yes
Maximum Address Size 16 bytes
Maximum Message Size 0 bytes
Message Oriented No
Minimum Address Size 16 bytes
Pseudo Stream Oriented No
Supports Broadcasting No
Supports Connect Data No
Supports Disconnect Data No
Supports Encryption No
Supports Expedited Data Yes
Supports Graceful Closing Yes
Supports Guaranteed Bandwidth No
Supports Multicasting No
 
Name MSAFD Tcpip [UDP/IP]
Connectionless Service Yes
Guarantees Delivery No
Guarantees Sequencing No
Maximum Address Size 16 bytes
Maximum Message Size 63.99 KB (65,527 bytes)
Message Oriented Yes
Minimum Address Size 16 bytes
Pseudo Stream Oriented No
Supports Broadcasting Yes
Supports Connect Data No
Supports Disconnect Data No
Supports Encryption No
Supports Expedited Data No
Supports Graceful Closing No
Supports Guaranteed Bandwidth No
Supports Multicasting Yes
 
Name RSVP TCPv6 Service Provider
Connectionless Service No
Guarantees Delivery Yes
Guarantees Sequencing Yes
Maximum Address Size 28 bytes
Maximum Message Size 0 bytes
Message Oriented No
Minimum Address Size 28 bytes
Pseudo Stream Oriented No
Supports Broadcasting No
Supports Connect Data No
Supports Disconnect Data No
Supports Encryption Yes
Supports Expedited Data Yes
Supports Graceful Closing Yes
Supports Guaranteed Bandwidth No
Supports Multicasting No
 
Name RSVP TCP Service Provider
Connectionless Service No
Guarantees Delivery Yes
Guarantees Sequencing Yes
Maximum Address Size 16 bytes
Maximum Message Size 0 bytes
Message Oriented No
Minimum Address Size 16 bytes
Pseudo Stream Oriented No
Supports Broadcasting No
Supports Connect Data No
Supports Disconnect Data No
Supports Encryption Yes
Supports Expedited Data Yes
Supports Graceful Closing Yes
Supports Guaranteed Bandwidth No
Supports Multicasting No
 
Name RSVP UDPv6 Service Provider
Connectionless Service Yes
Guarantees Delivery No
Guarantees Sequencing No
Maximum Address Size 28 bytes
Maximum Message Size 63.99 KB (65,527 bytes)
Message Oriented Yes
Minimum Address Size 28 bytes
Pseudo Stream Oriented No
Supports Broadcasting Yes
Supports Connect Data No
Supports Disconnect Data No
Supports Encryption Yes
Supports Expedited Data No
Supports Graceful Closing No
Supports Guaranteed Bandwidth No
Supports Multicasting Yes
 
Name RSVP UDP Service Provider
Connectionless Service Yes
Guarantees Delivery No
Guarantees Sequencing No
Maximum Address Size 16 bytes
Maximum Message Size 63.99 KB (65,527 bytes)
Message Oriented Yes
Minimum Address Size 16 bytes
Pseudo Stream Oriented No
Supports Broadcasting Yes
Supports Connect Data No
Supports Disconnect Data No
Supports Encryption Yes
Supports Expedited Data No
Supports Graceful Closing No
Supports Guaranteed Bandwidth No
Supports Multicasting Yes
 
[WinSock]
 
Item Value
File c:\windows\syswow64\wsock32.dll
Size 15.00 KB (15,360 bytes)
Version 6.1.7600.16385
 
File c:\windows\system32\wsock32.dll
Size 18.00 KB (18,432 bytes)
Version 6.1.7600.16385
 
[Ports]
 
 
 
[Serial]
 
Item Value
Name Communications Port (COM1)
Status OK
PNP Device ID ACPI\PNP0501\1
Maximum Input Buffer Size 0
Maximum Output Buffer Size No
Settable Baud Rate Yes
Settable Data Bits Yes
Settable Flow Control Yes
Settable Parity Yes
Settable Parity Check Yes
Settable Stop Bits Yes
Settable RLSD Yes
Supports RLSD Yes
Supports 16 Bit Mode No
Supports Special Characters No
Baud Rate 9600
Bits/Byte 8
Stop Bits 1
Parity None
Busy No
Abort Read/Write on Error No
Binary Mode Enabled Yes
Continue XMit on XOff No
CTS Outflow Control No
Discard NULL Bytes No
DSR Outflow Control 0
DSR Sensitivity 0
DTR Flow Control Type Enable
EOF Character 0
Error Replace Character 0
Error Replacement Enabled No
Event Character 0
Parity Check Enabled No
RTS Flow Control Type Enable
XOff Character 19
XOffXMit Threshold 512
XOn Character 17
XOnXMit Threshold 2048
XOnXOff InFlow Control 0
XOnXOff OutFlow Control 0
I/O Port 0x000003F8-0x000003FF
IRQ Channel IRQ 4
Driver c:\windows\system32\drivers\serial.sys (6.1.7600.16385, 92.00 KB (94,208 bytes), 7/13/2009 8:00 PM)
 
[Parallel]
 
Item Value
Name LPT1
PNP Device ID ACPI\PNP0400\4&39C67ADA&0
I/O Port 0x00000378-0x0000037F
Driver c:\windows\system32\drivers\parport.sys (6.1.7600.16385, 95.00 KB (97,280 bytes), 7/13/2009 8:00 PM)
 
[Storage]
 
 
 
[Drives]
 
Item Value
Drive A:
Description 3 1/2 Inch Floppy Drive
 
Drive C:
Description Local Fixed Disk
Compressed No
File System NTFS
Size 232.73 GB (249,892,433,920 bytes)
Free Space 158.72 GB (170,422,190,080 bytes)
Volume Name
Volume Serial Number 4C83792D
 
Drive D:
Description CD-ROM Disc
 
Drive E:
Description CD-ROM Disc
 
Drive F:
Description Removable Disk
 
Drive G:
Description Removable Disk
 
Drive H:
Description Removable Disk
 
Drive I:
Description Removable Disk
 
Drive Z:
Description Local Fixed Disk
Compressed No
File System NTFS
Size 100.00 MB (104,853,504 bytes)
Free Space 65.30 MB (68,468,736 bytes)
Volume Name System Reserved
Volume Serial Number A47DEC39
 
[Disks]
 
Item Value
Description Disk drive
Manufacturer (Standard disk drives)
Model ST325082 4AS SCSI Disk Device
Bytes/Sector 512
Media Loaded Yes
Media Type Fixed hard disk
Partitions 2
SCSI Bus 0
SCSI Logical Unit 0
SCSI Port 2
SCSI Target ID 0
Sectors/Track 63
Size 232.83 GB (249,999,160,320 bytes)
Total Cylinders 30,394
Total Sectors 488,279,610
Total Tracks 7,750,470
Tracks/Cylinder 255
Partition Disk #0, Partition #0
Partition Size 100.00 MB (104,857,600 bytes)
Partition Starting Offset 1,048,576 bytes
Partition Disk #0, Partition #1
Partition Size 232.73 GB (249,892,438,016 bytes)
Partition Starting Offset 105,906,176 bytes
 
Description Disk drive
Manufacturer (Standard disk drives)
Model TEAC USB   HS-CF Card USB Device
Bytes/Sector Not Available
Media Loaded Yes
Media Type Not Available
Partitions 0
SCSI Bus Not Available
SCSI Logical Unit Not Available
SCSI Port Not Available
SCSI Target ID Not Available
Sectors/Track Not Available
Size Not Available
Total Cylinders Not Available
Total Sectors Not Available
Total Tracks Not Available
Tracks/Cylinder Not Available
 
Description Disk drive
Manufacturer (Standard disk drives)
Model TEAC USB   HS-MS Card USB Device
Bytes/Sector Not Available
Media Loaded Yes
Media Type Not Available
Partitions 0
SCSI Bus Not Available
SCSI Logical Unit Not Available
SCSI Port Not Available
SCSI Target ID Not Available
Sectors/Track Not Available
Size Not Available
Total Cylinders Not Available
Total Sectors Not Available
Total Tracks Not Available
Tracks/Cylinder Not Available
 
Description Disk drive
Manufacturer (Standard disk drives)
Model TEAC USB   HS-SD Card USB Device
Bytes/Sector Not Available
Media Loaded Yes
Media Type Not Available
Partitions 0
SCSI Bus Not Available
SCSI Logical Unit Not Available
SCSI Port Not Available
SCSI Target ID Not Available
Sectors/Track Not Available
Size Not Available
Total Cylinders Not Available
Total Sectors Not Available
Total Tracks Not Available
Tracks/Cylinder Not Available
 
Description Disk drive
Manufacturer (Standard disk drives)
Model TEAC USB   HS-xD/SM USB Device
Bytes/Sector Not Available
Media Loaded Yes
Media Type Not Available
Partitions 0
SCSI Bus Not Available
SCSI Logical Unit Not Available
SCSI Port Not Available
SCSI Target ID Not Available
Sectors/Track Not Available
Size Not Available
Total Cylinders Not Available
Total Sectors Not Available
Total Tracks Not Available
Tracks/Cylinder Not Available
 
[SCSI]
 
Item Value
 
[IDE]
 
Item Value
Name ATA Channel 0
Manufacturer (Standard IDE ATA/ATAPI controllers)
Status OK
PNP Device ID PCIIDE\IDECHANNEL\4&1897E3C4&0&0
I/O Port 0x000001F0-0x000001F7
I/O Port 0x000003F6-0x000003F6
IRQ Channel IRQ 14
Driver c:\windows\system32\drivers\atapi.sys (6.1.7600.16385, 23.56 KB (24,128 bytes), 7/13/2009 7:19 PM)
 
Name ATA Channel 1
Manufacturer (Standard IDE ATA/ATAPI controllers)
Status OK
PNP Device ID PCIIDE\IDECHANNEL\4&1897E3C4&0&1
I/O Port 0x00000170-0x00000177
I/O Port 0x00000376-0x00000376
IRQ Channel IRQ 15
Driver c:\windows\system32\drivers\atapi.sys (6.1.7600.16385, 23.56 KB (24,128 bytes), 7/13/2009 7:19 PM)
 
Name Standard Dual Channel PCI IDE Controller
Manufacturer (Standard IDE ATA/ATAPI controllers)
Status OK
PNP Device ID PCI\VEN_10DE&DEV_03EC&SUBSYS_34071565&REV_A2\3&267A616A&0&30
I/O Port 0x0000FFA0-0x0000FFAF
Driver c:\windows\system32\drivers\pciide.sys (6.1.7600.16385, 12.06 KB (12,352 bytes), 7/13/2009 7:19 PM)
 
Name NVIDIA nForce Serial ATA Controller
Manufacturer NVIDIA Corporation
Status OK
PNP Device ID PCI\VEN_10DE&DEV_03F6&SUBSYS_54051565&REV_A2\3&267A616A&0&40
I/O Port 0x0000D400-0x0000D407
I/O Port 0x0000D080-0x0000D083
I/O Port 0x0000D000-0x0000D007
I/O Port 0x0000CC00-0x0000CC03
I/O Port 0x0000C880-0x0000C88F
Memory Address 0xDFE7C000-0xDFE7CFFF
IRQ Channel IRQ 20
Driver c:\windows\system32\drivers\nvstor64.sys (11.1.0.30, 235.53 KB (241,184 bytes), 6/30/2009 6:33 PM)
 
Name NVIDIA nForce Serial ATA Controller
Manufacturer NVIDIA Corporation
Status OK
PNP Device ID PCI\VEN_10DE&DEV_03F6&SUBSYS_54051565&REV_A2\3&267A616A&0&41
I/O Port 0x0000C800-0x0000C807
I/O Port 0x0000C480-0x0000C483
I/O Port 0x0000C400-0x0000C407
I/O Port 0x0000C080-0x0000C083
I/O Port 0x0000C000-0x0000C00F
Memory Address 0xDFE77000-0xDFE77FFF
IRQ Channel IRQ 21
Driver c:\windows\system32\drivers\nvstor64.sys (11.1.0.30, 235.53 KB (241,184 bytes), 6/30/2009 6:33 PM)
 
[Printing]
 
Name Driver Port Name Server Name
Foxit Reader PDF Printer Foxit Reader PDF Printer Driver FOXIT_Reader: Not Available
Fax Microsoft Shared Fax Driver SHRFAX: Not Available
CutePDF Writer CutePDF Writer CPW2: Not Available
 
[Problem Devices]
 
Device PNP Device ID Error Code
 
[USB]
 
Device PNP Device ID
Standard Enhanced PCI to USB Host Controller PCI\VEN_10DE&DEV_03F2&SUBSYS_34071565&REV_A3\3&267A616A&0&11
Standard OpenHCD USB Host Controller PCI\VEN_10DE&DEV_03F1&SUBSYS_34071565&REV_A3\3&267A616A&0&10
 
[Software Environment]
 
 
 
[System Drivers]
 
Name Description File Type Started Start Mode State Status Error Control Accept Pause Accept Stop
1394ohci 1394 OHCI Compliant Host Controller c:\windows\system32\drivers\1394ohci.sys Kernel Driver No Manual Stopped OK Normal No No
acpi Microsoft ACPI Driver c:\windows\system32\drivers\acpi.sys Kernel Driver Yes Boot Running OK Critical No Yes
acpipmi ACPI Power Meter Driver c:\windows\system32\drivers\acpipmi.sys Kernel Driver No Manual Stopped OK Normal No No
adp94xx adp94xx c:\windows\system32\drivers\adp94xx.sys Kernel Driver No Manual Stopped OK Normal No No
adpahci adpahci c:\windows\system32\drivers\adpahci.sys Kernel Driver No Manual Stopped OK Normal No No
adpu320 adpu320 c:\windows\system32\drivers\adpu320.sys Kernel Driver No Manual Stopped OK Normal No No
afd Ancillary Function Driver for Winsock c:\windows\system32\drivers\afd.sys Kernel Driver Yes System Running OK Normal No Yes
agp440 Intel AGP Bus Filter c:\windows\system32\drivers\agp440.sys Kernel Driver No Manual Stopped OK Normal No No
aliide aliide c:\windows\system32\drivers\aliide.sys Kernel Driver No Manual Stopped OK Critical No No
amdide amdide c:\windows\system32\drivers\amdide.sys Kernel Driver No Manual Stopped OK Critical No No
amdiox64 AMD IO Driver c:\windows\system32\drivers\amdiox64.sys Kernel Driver No Manual Stopped OK Normal No No
amdk8 AMD K8 Processor Driver c:\windows\system32\drivers\amdk8.sys Kernel Driver No Manual Stopped OK Normal No No
amdkmdag amdkmdag c:\windows\system32\drivers\atikmdag.sys Kernel Driver No Manual Stopped OK Ignore No No
amdkmdap amdkmdap c:\windows\system32\drivers\atikmpag.sys Kernel Driver No Manual Stopped OK Ignore No No
amdppm AMD Processor Driver c:\windows\system32\drivers\amdppm.sys Kernel Driver No Manual Stopped OK Normal No No
amdsata amdsata c:\windows\system32\drivers\amdsata.sys Kernel Driver No Disabled Stopped OK Normal No No
amdsbs amdsbs c:\windows\system32\drivers\amdsbs.sys Kernel Driver No Manual Stopped OK Normal No No
amdxata amdxata c:\windows\system32\drivers\amdxata.sys Kernel Driver Yes Boot Running OK Normal No Yes
aoddriver4.1 AODDriver4.1 \??\c:\program files\ati technologies\ati.ace\fuel\amd64\aoddriver2.sys Kernel Driver Yes Auto Running OK Normal No Yes
appid AppID Driver c:\windows\system32\drivers\appid.sys Kernel Driver No Manual Stopped OK Normal No No
arc arc c:\windows\system32\drivers\arc.sys Kernel Driver No Manual Stopped OK Normal No No
arcsas arcsas c:\windows\system32\drivers\arcsas.sys Kernel Driver No Manual Stopped OK Normal No No
asyncmac RAS Asynchronous Media Driver c:\windows\system32\drivers\asyncmac.sys Kernel Driver No Manual Stopped OK Normal No No
atapi IDE Channel c:\windows\system32\drivers\atapi.sys Kernel Driver Yes Boot Running OK Critical No Yes
atihdaudioservice AMD Function Driver for HD Audio Service c:\windows\system32\drivers\atihdw76.sys Kernel Driver No Manual Stopped OK Normal No No
atikmdag atikmdag c:\windows\system32\drivers\atikmdag.sys Kernel Driver No Manual Stopped OK Ignore No No
b06bdrv Broadcom NetXtreme II VBD c:\windows\system32\drivers\bxvbda.sys Kernel Driver No Manual Stopped OK Normal No No
b57nd60a Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 c:\windows\system32\drivers\b57nd60a.sys Kernel Driver No Manual Stopped OK Normal No No
beep Beep c:\windows\system32\drivers\beep.sys Kernel Driver Yes System Running OK Normal No Yes
bios BIOS \??\c:\windows\system32\drivers\bios64.sys Kernel Driver Yes System Running OK Normal No Yes
blbdrive blbdrive c:\windows\system32\drivers\blbdrive.sys Kernel Driver Yes System Running OK Normal No Yes
bowser Browser Support Driver c:\windows\system32\drivers\bowser.sys File System Driver Yes Manual Running OK Normal No Yes
brfiltlo Brother USB Mass-Storage Lower Filter Driver c:\windows\system32\drivers\brfiltlo.sys Kernel Driver No Manual Stopped OK Normal No No
brfiltup Brother USB Mass-Storage Upper Filter Driver c:\windows\system32\drivers\brfiltup.sys Kernel Driver No Manual Stopped OK Normal No No
bridgemp MAC Bridge Miniport c:\windows\system32\drivers\bridge.sys Kernel Driver No Manual Stopped OK Normal No No
brserid Brother MFC Serial Port Interface Driver (WDM) c:\windows\system32\drivers\brserid.sys Kernel Driver No Manual Stopped OK Normal No No
brserwdm Brother WDM Serial driver c:\windows\system32\drivers\brserwdm.sys Kernel Driver No Manual Stopped OK Normal No No
brusbmdm Brother MFC USB Fax Only Modem c:\windows\system32\drivers\brusbmdm.sys Kernel Driver No Manual Stopped OK Normal No No
brusbser Brother MFC USB Serial WDM Driver c:\windows\system32\drivers\brusbser.sys Kernel Driver No Manual Stopped OK Normal No No
bthmodem Bluetooth Serial Communications Driver c:\windows\system32\drivers\bthmodem.sys Kernel Driver No Manual Stopped OK Normal No No
cdfs CD/DVD File System Reader c:\windows\system32\drivers\cdfs.sys File System Driver No Disabled Stopped OK Normal No No
cdrom CD-ROM Driver c:\windows\system32\drivers\cdrom.sys Kernel Driver Yes System Running OK Normal No Yes
circlass Consumer IR Devices c:\windows\system32\drivers\circlass.sys Kernel Driver No Manual Stopped OK Normal No No
clfs Common Log (CLFS) c:\windows\system32\clfs.sys Kernel Driver Yes Boot Running OK Critical No Yes
cmbatt Microsoft ACPI Control Method Battery Driver c:\windows\system32\drivers\cmbatt.sys Kernel Driver No Manual Stopped OK Normal No No
cmdide cmdide c:\windows\system32\drivers\cmdide.sys Kernel Driver No Manual Stopped OK Critical No No
cng CNG c:\windows\system32\drivers\cng.sys Kernel Driver Yes Boot Running OK Critical No Yes
compbatt Compbatt c:\windows\system32\drivers\compbatt.sys Kernel Driver No Manual Stopped OK Critical No No
compositebus Composite Bus Enumerator Driver c:\windows\system32\drivers\compositebus.sys Kernel Driver No Manual Stopped OK Normal No No
crcdisk Crcdisk Filter Driver c:\windows\system32\drivers\crcdisk.sys Kernel Driver No Disabled Stopped OK Normal No No
csc Offline Files Driver c:\windows\system32\drivers\csc.sys Kernel Driver Yes System Running OK Normal No Yes
dfsc DFS Namespace Client Driver c:\windows\system32\drivers\dfsc.sys File System Driver Yes System Running OK Normal No Yes
discache System Attribute Cache c:\windows\system32\drivers\discache.sys Kernel Driver Yes System Running OK Normal No Yes
disk Disk Driver c:\windows\system32\drivers\disk.sys Kernel Driver Yes Boot Running OK Normal No Yes
drmkaud Microsoft Trusted Audio Drivers c:\windows\system32\drivers\drmkaud.sys Kernel Driver No Manual Stopped OK Normal No No
dxgkrnl LDDM Graphics Subsystem c:\windows\system32\drivers\dxgkrnl.sys Kernel Driver No Manual Stopped OK Ignore No No
ebdrv Broadcom NetXtreme II 10 GigE VBD c:\windows\system32\drivers\evbda.sys Kernel Driver No Manual Stopped OK Normal No No
elxstor elxstor c:\windows\system32\drivers\elxstor.sys Kernel Driver No Manual Stopped OK Normal No No
errdev Microsoft Hardware Error Device Driver c:\windows\system32\drivers\errdev.sys Kernel Driver No Manual Stopped OK Normal No No
exfat exFAT File System Driver c:\windows\system32\drivers\exfat.sys File System Driver No Manual Stopped OK Normal No No
fastfat FAT12/16/32 File System Driver c:\windows\system32\drivers\fastfat.sys File System Driver No Manual Stopped OK Normal No No
fdc Floppy Disk Controller Driver c:\windows\system32\drivers\fdc.sys Kernel Driver No Manual Stopped OK Normal No No
fileinfo File Information FS MiniFilter c:\windows\system32\drivers\fileinfo.sys File System Driver Yes Boot Running OK Normal No Yes
filetrace Filetrace c:\windows\system32\drivers\filetrace.sys File System Driver No Manual Stopped OK Normal No No
flpydisk Floppy Disk Driver c:\windows\system32\drivers\flpydisk.sys Kernel Driver No Manual Stopped OK Normal No No
fltmgr FltMgr c:\windows\system32\drivers\fltmgr.sys File System Driver Yes Boot Running OK Critical No Yes
fsdepends File System Dependency Minifilter c:\windows\system32\drivers\fsdepends.sys File System Driver No Manual Stopped OK Critical No No
fvevol Bitlocker Drive Encryption Filter Driver c:\windows\system32\drivers\fvevol.sys Kernel Driver Yes Boot Running OK Critical No Yes
gagp30kx Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms c:\windows\system32\drivers\gagp30kx.sys Kernel Driver No Manual Stopped OK Normal No No
gearaspiwdm GEAR ASPI Filter Driver c:\windows\system32\drivers\gearaspiwdm.sys Kernel Driver No Manual Stopped OK Normal No No
hcw85cir Hauppauge Consumer Infrared Receiver c:\windows\system32\drivers\hcw85cir.sys Kernel Driver No Manual Stopped OK Normal No No
hdaudaddservice Microsoft 1.1 UAA Function Driver for High Definition Audio Service c:\windows\system32\drivers\hdaudio.sys Kernel Driver No Manual Stopped OK Normal No No
hdaudbus Microsoft UAA Bus Driver for High Definition Audio c:\windows\system32\drivers\hdaudbus.sys Kernel Driver No Manual Stopped OK Normal No No
hidbatt HID UPS Battery Driver c:\windows\system32\drivers\hidbatt.sys Kernel Driver No Manual Stopped OK Normal No No
hidbth Microsoft Bluetooth HID Miniport c:\windows\system32\drivers\hidbth.sys Kernel Driver No Manual Stopped OK Ignore No No
hidir Microsoft Infrared HID Driver c:\windows\system32\drivers\hidir.sys Kernel Driver No Manual Stopped OK Ignore No No
hidusb Microsoft HID Class Driver c:\windows\system32\drivers\hidusb.sys Kernel Driver No Manual Stopped OK Ignore No No
hpsamd HpSAMD c:\windows\system32\drivers\hpsamd.sys Kernel Driver No Manual Stopped OK Normal No No
http HTTP c:\windows\system32\drivers\http.sys Kernel Driver Yes Manual Running OK Normal No Yes
hwpolicy Hardware Policy Driver c:\windows\system32\drivers\hwpolicy.sys Kernel Driver Yes Boot Running OK Normal No Yes
i8042prt i8042 Keyboard and PS/2 Mouse Port Driver c:\windows\system32\drivers\i8042prt.sys Kernel Driver No Manual Stopped OK Normal No No
iastorv Intel RAID Controller Windows 7 c:\windows\system32\drivers\iastorv.sys Kernel Driver No Manual Stopped OK Normal No No
iirsp iirsp c:\windows\system32\drivers\iirsp.sys Kernel Driver No Manual Stopped OK Normal No No
intcazaudaddservice Service for Realtek HD Audio (WDM) c:\windows\system32\drivers\rtkvhd64.sys Kernel Driver No Manual Stopped OK Normal No No
intelide intelide c:\windows\system32\drivers\intelide.sys Kernel Driver No Manual Stopped OK Critical No No
intelppm Intel Processor Driver c:\windows\system32\drivers\intelppm.sys Kernel Driver No Manual Stopped OK Normal No No
ipfilterdriver IP Traffic Filter Driver c:\windows\system32\drivers\ipfltdrv.sys Kernel Driver No Manual Stopped OK Normal No No
ipmidrv IPMIDRV c:\windows\system32\drivers\ipmidrv.sys Kernel Driver No Manual Stopped OK Normal No No
ipnat IP Network Address Translator c:\windows\system32\drivers\ipnat.sys Kernel Driver No Manual Stopped OK Normal No No
irenum IR Bus Enumerator c:\windows\system32\drivers\irenum.sys Kernel Driver No Manual Stopped OK Ignore No No
isapnp isapnp c:\windows\system32\drivers\isapnp.sys Kernel Driver No Manual Stopped OK Critical No No
iscsiprt iScsiPort Driver c:\windows\system32\drivers\msiscsi.sys Kernel Driver No Manual Stopped OK Normal No No
kbdclass Keyboard Class Driver c:\windows\system32\drivers\kbdclass.sys Kernel Driver No Manual Stopped OK Normal No No
kbdhid Keyboard HID Driver c:\windows\system32\drivers\kbdhid.sys Kernel Driver No Manual Stopped OK Ignore No No
ksecdd KSecDD c:\windows\system32\drivers\ksecdd.sys Kernel Driver Yes Boot Running OK Critical No Yes
ksecpkg KSecPkg c:\windows\system32\drivers\ksecpkg.sys Kernel Driver Yes Boot Running OK Critical No Yes
ksthunk Kernel Streaming Thunks c:\windows\system32\drivers\ksthunk.sys Kernel Driver No Manual Stopped OK Normal No No
lbd Lbd c:\windows\system32\drivers\lbd.sys File System Driver Yes Boot Running OK Normal No Yes
lltdio Link-Layer Topology Discovery Mapper I/O Driver c:\windows\system32\drivers\lltdio.sys Kernel Driver Yes Auto Running OK Normal No Yes
lsi_fc LSI_FC c:\windows\system32\drivers\lsi_fc.sys Kernel Driver No Manual Stopped OK Normal No No
lsi_sas LSI_SAS c:\windows\system32\drivers\lsi_sas.sys Kernel Driver No Manual Stopped OK Normal No No
lsi_sas2 LSI_SAS2 c:\windows\system32\drivers\lsi_sas2.sys Kernel Driver No Manual Stopped OK Normal No No
lsi_scsi LSI_SCSI c:\windows\system32\drivers\lsi_scsi.sys Kernel Driver No Manual Stopped OK Normal No No
luafv UAC File Virtualization c:\windows\system32\drivers\luafv.sys File System Driver Yes Auto Running OK Normal No Yes
mbamprotector MBAMProtector \??\c:\windows\system32\drivers\mbam.sys File System Driver No Manual Stopped OK Normal No No
mbamwebaccesscontrol MBAMWebAccessControl \??\c:\windows\system32\drivers\mwac.sys File System Driver No Manual Stopped OK Normal No No
megasas megasas c:\windows\system32\drivers\megasas.sys Kernel Driver No Manual Stopped OK Normal No No
megasr MegaSR c:\windows\system32\drivers\megasr.sys Kernel Driver No Manual Stopped OK Normal No No
modem Modem c:\windows\system32\drivers\modem.sys Kernel Driver No Manual Stopped OK Ignore No No
monitor Microsoft Monitor Class Function Driver Service c:\windows\system32\drivers\monitor.sys Kernel Driver No Manual Stopped OK Normal No No
mouclass Mouse Class Driver c:\windows\system32\drivers\mouclass.sys Kernel Driver No Manual Stopped OK Normal No No
mouhid Mouse HID Driver c:\windows\system32\drivers\mouhid.sys Kernel Driver No Manual Stopped OK Ignore No No
mountmgr Mount Point Manager c:\windows\system32\drivers\mountmgr.sys Kernel Driver Yes Boot Running OK Critical No Yes
mpfilter Microsoft Malware Protection Driver c:\windows\system32\drivers\mpfilter.sys File System Driver Yes Boot Running OK Normal No Yes
mpio Microsoft Multi-Path Bus Driver c:\windows\system32\drivers\mpio.sys Kernel Driver No Manual Stopped OK Normal No No
mpsdrv Windows Firewall Authorization Driver c:\windows\system32\drivers\mpsdrv.sys Kernel Driver Yes Manual Running OK Normal No Yes
mrxdav WebDav Client Redirector Driver c:\windows\system32\drivers\mrxdav.sys File System Driver No Manual Stopped OK Normal No No
mrxsmb SMB MiniRedirector Wrapper and Engine c:\windows\system32\drivers\mrxsmb.sys File System Driver Yes Manual Running OK Normal No Yes
mrxsmb10 SMB 1.x MiniRedirector c:\windows\system32\drivers\mrxsmb10.sys File System Driver Yes Manual Running OK Normal No Yes
mrxsmb20 SMB 2.0 MiniRedirector c:\windows\system32\drivers\mrxsmb20.sys File System Driver Yes Manual Running OK Normal No Yes
msahci msahci c:\windows\system32\drivers\msahci.sys Kernel Driver No Manual Stopped OK Critical No No
msdsm Microsoft Multi-Path Device Specific Module c:\windows\system32\drivers\msdsm.sys Kernel Driver No Manual Stopped OK Normal No No
msfs Msfs c:\windows\system32\drivers\msfs.sys File System Driver Yes System Running OK Normal No Yes
mshidkmdf Pass-through HID to KMDF Filter Driver c:\windows\system32\drivers\mshidkmdf.sys Kernel Driver No Manual Stopped OK Ignore No No
msisadrv msisadrv c:\windows\system32\drivers\msisadrv.sys Kernel Driver Yes Boot Running OK Critical No Yes
mskssrv Microsoft Streaming Service Proxy c:\windows\system32\drivers\mskssrv.sys Kernel Driver No Manual Stopped OK Normal No No
mspclock Microsoft Streaming Clock Proxy c:\windows\system32\drivers\mspclock.sys Kernel Driver No Manual Stopped OK Normal No No
mspqm Microsoft Streaming Quality Manager Proxy c:\windows\system32\drivers\mspqm.sys Kernel Driver No Manual Stopped OK Normal No No
msrpc MsRPC c:\windows\system32\drivers\msrpc.sys Kernel Driver No Manual Stopped OK Normal No No
mssmbios Microsoft System Management BIOS Driver c:\windows\system32\drivers\mssmbios.sys Kernel Driver Yes System Running OK Normal No Yes
mstee Microsoft Streaming Tee/Sink-to-Sink Converter c:\windows\system32\drivers\mstee.sys Kernel Driver No Manual Stopped OK Normal No No
mtconfig Microsoft Input Configuration Driver c:\windows\system32\drivers\mtconfig.sys Kernel Driver No Manual Stopped OK Normal No No
mup Mup c:\windows\system32\drivers\mup.sys File System Driver Yes Boot Running OK Normal No Yes
nativewifip NativeWiFi Filter c:\windows\system32\drivers\nwifi.sys Kernel Driver No Manual Stopped OK Normal No No
ndis NDIS System Driver c:\windows\system32\drivers\ndis.sys Kernel Driver Yes Boot Running OK Critical No Yes
ndiscap NDIS Capture LightWeight Filter c:\windows\system32\drivers\ndiscap.sys Kernel Driver No Manual Stopped OK Normal No No
ndistapi Remote Access NDIS TAPI Driver c:\windows\system32\drivers\ndistapi.sys Kernel Driver No Manual Stopped OK Normal No No
ndisuio NDIS Usermode I/O Protocol c:\windows\system32\drivers\ndisuio.sys Kernel Driver No Manual Stopped OK Normal No No
ndiswan Remote Access NDIS WAN Driver c:\windows\system32\drivers\ndiswan.sys Kernel Driver No Manual Stopped OK Normal No No
ndproxy NDIS Proxy c:\windows\system32\drivers\ndproxy.sys Kernel Driver No Manual Stopped OK Normal No No
netbios NetBIOS Interface c:\windows\system32\drivers\netbios.sys File System Driver Yes System Running OK Normal No Yes
netbt NetBT c:\windows\system32\drivers\netbt.sys Kernel Driver Yes System Running OK Normal No Yes
nfrd960 nfrd960 c:\windows\system32\drivers\nfrd960.sys Kernel Driver No Manual Stopped OK Normal No No
nisdrv Microsoft Network Inspection System c:\windows\system32\drivers\nisdrvwfp.sys Kernel Driver Yes Auto Running OK Normal No Yes
npfs Npfs c:\windows\system32\drivers\npfs.sys File System Driver Yes System Running OK Normal No Yes
nsiproxy NSI proxy service driver. c:\windows\system32\drivers\nsiproxy.sys Kernel Driver Yes System Running OK Normal No Yes
ntfs Ntfs c:\windows\system32\drivers\ntfs.sys File System Driver No Manual Stopped OK Normal No No
null Null c:\windows\system32\drivers\null.sys Kernel Driver Yes System Running OK Normal No Yes
nvenetfd NVIDIA nForce Networking Controller Driver c:\windows\system32\drivers\nvm62x64.sys Kernel Driver No Manual Stopped OK Normal No No
nvhda Service for NVIDIA High Definition Audio Driver c:\windows\system32\drivers\nvhda64v.sys Kernel Driver No Manual Stopped OK Normal No No
nvnet NVIDIA nForce Ethernet Driver c:\windows\system32\drivers\nvmf6264.sys Kernel Driver No Manual Stopped OK Normal No No
nvraid nvraid c:\windows\system32\drivers\nvraid.sys Kernel Driver No Manual Stopped OK Normal No No
nvsmu nvsmu c:\windows\system32\drivers\nvsmu.sys Kernel Driver No Manual Stopped OK Ignore No No
nvstor nvstor c:\windows\system32\drivers\nvstor.sys Kernel Driver Yes Boot Running OK Critical No Yes
nvstor64 nvstor64 c:\windows\system32\drivers\nvstor64.sys Kernel Driver Yes Boot Running OK Critical No Yes
nv_agp NVIDIA nForce AGP Bus Filter c:\windows\system32\drivers\nv_agp.sys Kernel Driver No Manual Stopped OK Normal No No
ohci1394 1394 OHCI Compliant Host Controller (Legacy) c:\windows\system32\drivers\ohci1394.sys Kernel Driver No Manual Stopped OK Normal No No
parport Parallel port driver c:\windows\system32\drivers\parport.sys Kernel Driver No Manual Stopped OK Ignore No No
partmgr Partition Manager c:\windows\system32\drivers\partmgr.sys Kernel Driver Yes Boot Running OK Critical No Yes
pci PCI Bus Driver c:\windows\system32\drivers\pci.sys Kernel Driver Yes Boot Running OK Critical No Yes
pciide pciide c:\windows\system32\drivers\pciide.sys Kernel Driver Yes Boot Running OK Critical No Yes
pcmcia pcmcia c:\windows\system32\drivers\pcmcia.sys Kernel Driver No Manual Stopped OK Normal No No
pcw Performance Counters for Windows Driver c:\windows\system32\drivers\pcw.sys Kernel Driver Yes Boot Running OK Normal No Yes
peauth PEAUTH c:\windows\system32\drivers\peauth.sys Kernel Driver Yes Auto Running OK Normal No Yes
pptpminiport WAN Miniport (PPTP) c:\windows\system32\drivers\raspptp.sys Kernel Driver No Manual Stopped OK Normal No No
processor Processor Driver c:\windows\system32\drivers\processr.sys Kernel Driver No Manual Stopped OK Normal No No
psched QoS Packet Scheduler c:\windows\system32\drivers\pacer.sys Kernel Driver Yes System Running OK Normal No Yes
ql2300 ql2300 c:\windows\system32\drivers\ql2300.sys Kernel Driver No Manual Stopped OK Normal No No
ql40xx ql40xx c:\windows\system32\drivers\ql40xx.sys Kernel Driver No Manual Stopped OK Normal No No
qwavedrv QWAVE driver c:\windows\system32\drivers\qwavedrv.sys Kernel Driver No Manual Stopped OK Normal No No
rasacd Remote Access Auto Connection Driver c:\windows\system32\drivers\rasacd.sys Kernel Driver No Manual Stopped OK Normal No No
rasagilevpn WAN Miniport (IKEv2) c:\windows\system32\drivers\agilevpn.sys Kernel Driver No Manual Stopped OK Normal No No
rasl2tp WAN Miniport (L2TP) c:\windows\system32\drivers\rasl2tp.sys Kernel Driver No Manual Stopped OK Normal No No
raspppoe Remote Access PPPOE Driver c:\windows\system32\drivers\raspppoe.sys Kernel Driver No Manual Stopped OK Normal No No
rassstp WAN Miniport (SSTP) c:\windows\system32\drivers\rassstp.sys Kernel Driver No Manual Stopped OK Normal No No
rdbss Redirected Buffering Sub Sysytem c:\windows\system32\drivers\rdbss.sys File System Driver Yes System Running OK Normal No Yes
rdpbus Remote Desktop Device Redirector Bus Driver c:\windows\system32\drivers\rdpbus.sys Kernel Driver No Manual Stopped OK Normal No No
rdpcdd RDPCDD c:\windows\system32\drivers\rdpcdd.sys Kernel Driver Yes System Running OK Ignore No Yes
rdpdr Terminal Server Device Redirector Driver c:\windows\system32\drivers\rdpdr.sys Kernel Driver Yes Manual Running OK Normal No Yes
rdpencdd RDP Encoder Mirror Driver c:\windows\system32\drivers\rdpencdd.sys Kernel Driver Yes System Running OK Ignore No Yes
rdprefmp Reflector Display Driver used to gain access to graphics data c:\windows\system32\drivers\rdprefmp.sys Kernel Driver Yes System Running OK Ignore No Yes
rdpvideominiport Remote Desktop Video Miniport Driver c:\windows\system32\drivers\rdpvideominiport.sys Kernel Driver No Manual Stopped OK Normal No No
rdpwd RDP Winstation Driver c:\windows\system32\drivers\rdpwd.sys Kernel Driver No Manual Stopped OK Ignore No No
rdyboost ReadyBoost c:\windows\system32\drivers\rdyboost.sys Kernel Driver Yes Boot Running OK Critical No Yes
rimusb BlackBerry Smartphone c:\windows\system32\drivers\rimusb_amd64.sys Kernel Driver No Manual Stopped OK Normal No No
rspndr Link-Layer Topology Discovery Responder c:\windows\system32\drivers\rspndr.sys Kernel Driver Yes Auto Running OK Normal No Yes
s3cap s3cap c:\windows\system32\drivers\vms3cap.sys Kernel Driver No Manual Stopped OK Normal No No
sbp2port SBP-2 Transport/Protocol Bus Driver c:\windows\system32\drivers\sbp2port.sys Kernel Driver No Manual Stopped OK Normal No No
scfilter Smart card PnP Class Filter Driver c:\windows\system32\drivers\scfilter.sys Kernel Driver No Manual Stopped OK Normal No No
secdrv Security Driver c:\windows\system32\drivers\secdrv.sys Kernel Driver Yes Auto Running OK Normal No Yes
serenum Serenum Filter Driver c:\windows\system32\drivers\serenum.sys Kernel Driver No Manual Stopped OK Normal No No
serial Serial port driver c:\windows\system32\drivers\serial.sys Kernel Driver Yes System Running OK Ignore No Yes
sermouse Serial Mouse Driver c:\windows\system32\drivers\sermouse.sys Kernel Driver No Manual Stopped OK Normal No No
sffdisk SFF Storage Class Driver c:\windows\system32\drivers\sffdisk.sys Kernel Driver No Manual Stopped OK Normal No No
sffp_mmc SFF Storage Protocol Driver for MMC c:\windows\system32\drivers\sffp_mmc.sys Kernel Driver No Manual Stopped OK Normal No No
sffp_sd SFF Storage Protocol Driver for SDBus c:\windows\system32\drivers\sffp_sd.sys Kernel Driver No Manual Stopped OK Normal No No
sfloppy High-Capacity Floppy Disk Drive c:\windows\system32\drivers\sfloppy.sys Kernel Driver No Manual Stopped OK Normal No No
sisraid2 SiSRaid2 c:\windows\system32\drivers\sisraid2.sys Kernel Driver No Manual Stopped OK Normal No No
sisraid4 SiSRaid4 c:\windows\system32\drivers\sisraid4.sys Kernel Driver No Manual Stopped OK Normal No No
smb Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session) c:\windows\system32\drivers\smb.sys Kernel Driver No Manual Stopped OK Normal No No
spldr Security Processor Loader Driver c:\windows\system32\drivers\spldr.sys Kernel Driver Yes Boot Running OK Critical No Yes
srv Server SMB 1.xxx Driver c:\windows\system32\drivers\srv.sys File System Driver Yes Manual Running OK Normal No Yes
srv2 Server SMB 2.xxx Driver c:\windows\system32\drivers\srv2.sys File System Driver Yes Manual Running OK Normal No Yes
srvnet srvnet c:\windows\system32\drivers\srvnet.sys File System Driver Yes Manual Running OK Normal No Yes
stexstor stexstor c:\windows\system32\drivers\stexstor.sys Kernel Driver No Manual Stopped OK Normal No No
stillcam Still Serial Digital Camera Driver c:\windows\system32\drivers\serscan.sys Kernel Driver No Manual Stopped OK Normal No No
storflt Disk Virtual Machine Bus Acceleration Filter Driver c:\windows\system32\drivers\vmstorfl.sys Kernel Driver Yes Boot Running OK Normal No Yes
storvsc storvsc c:\windows\system32\drivers\storvsc.sys Kernel Driver No Manual Stopped OK Normal No No
swenum Software Bus Driver c:\windows\system32\drivers\swenum.sys Kernel Driver No Manual Stopped OK Normal No No
tcpip TCP/IP Protocol Driver c:\windows\system32\drivers\tcpip.sys Kernel Driver Yes Boot Running OK Normal No Yes
tcpip6 Microsoft IPv6 Protocol Driver c:\windows\system32\drivers\tcpip.sys Kernel Driver No Manual Stopped OK Normal No No
tcpipreg TCP/IP Registry Compatibility c:\windows\system32\drivers\tcpipreg.sys Kernel Driver Yes Auto Running OK Normal No Yes
tdpipe TDPIPE c:\windows\system32\drivers\tdpipe.sys Kernel Driver No Manual Stopped OK Normal No No
tdtcp TDTCP c:\windows\system32\drivers\tdtcp.sys Kernel Driver No Manual Stopped OK Normal No No
tdx NetIO Legacy TDI Support Driver c:\windows\system32\drivers\tdx.sys Kernel Driver Yes System Running OK Normal No Yes
termdd Terminal Device Driver c:\windows\system32\drivers\termdd.sys Kernel Driver Yes System Running OK Normal No Yes
tssecsrv Remote Desktop Services Security Filter Driver c:\windows\system32\drivers\tssecsrv.sys Kernel Driver No Manual Stopped OK Ignore No No
tsusbflt TsUsbFlt c:\windows\system32\drivers\tsusbflt.sys Kernel Driver No Manual Stopped OK Normal No No
tunnel Microsoft Tunnel Miniport Adapter Driver c:\windows\system32\drivers\tunnel.sys Kernel Driver No Manual Stopped OK Normal No No
uagp35 Microsoft AGPv3.5 Filter c:\windows\system32\drivers\uagp35.sys Kernel Driver No Manual Stopped OK Normal No No
udfs udfs c:\windows\system32\drivers\udfs.sys File System Driver No Disabled Stopped OK Normal No No
uliagpkx Uli AGP Bus Filter c:\windows\system32\drivers\uliagpkx.sys Kernel Driver No Manual Stopped OK Normal No No
umbus UMBus Enumerator Driver c:\windows\system32\drivers\umbus.sys Kernel Driver No Manual Stopped OK Normal No No
umpass Microsoft UMPass Driver c:\windows\system32\drivers\umpass.sys Kernel Driver No Manual Stopped OK Normal No No
usbaapl64 Apple Mobile USB Driver c:\windows\system32\drivers\usbaapl64.sys Kernel Driver No Manual Stopped OK Normal No No
usbccgp Microsoft USB Generic Parent Driver c:\windows\system32\drivers\usbccgp.sys Kernel Driver No Manual Stopped OK Normal No No
usbcir eHome Infrared Receiver (USBCIR) c:\windows\system32\drivers\usbcir.sys Kernel Driver No Manual Stopped OK Normal No No
usbehci Microsoft USB 2.0 Enhanced Host Controller Miniport Driver c:\windows\system32\drivers\usbehci.sys Kernel Driver No Manual Stopped OK Normal No No
usbhub Microsoft USB Standard Hub Driver c:\windows\system32\drivers\usbhub.sys Kernel Driver No Manual Stopped OK Normal No No
usbohci Microsoft USB Open Host Controller Miniport Driver c:\windows\system32\drivers\usbohci.sys Kernel Driver No Manual Stopped OK Normal No No
usbprint Microsoft USB PRINTER Class c:\windows\system32\drivers\usbprint.sys Kernel Driver No Manual Stopped OK Normal No No
usbscan USB Scanner Driver c:\windows\system32\drivers\usbscan.sys Kernel Driver No Manual Stopped OK Normal No No
usbstor USB Mass Storage Driver c:\windows\system32\drivers\usbstor.sys Kernel Driver No Manual Stopped OK Normal No No
usbuhci Microsoft USB Universal Host Controller Miniport Driver c:\windows\system32\drivers\usbuhci.sys Kernel Driver No Manual Stopped OK Normal No No
usb_rndisx USB RNDIS Adapter c:\windows\system32\drivers\usb8023x.sys Kernel Driver No Manual Stopped OK Normal No No
vdrvroot Microsoft Virtual Drive Enumerator Driver c:\windows\system32\drivers\vdrvroot.sys Kernel Driver Yes Boot Running OK Critical No Yes
vga vga c:\windows\system32\drivers\vgapnp.sys Kernel Driver No Manual Stopped OK Ignore No No
vgasave VgaSave c:\windows\system32\drivers\vga.sys Kernel Driver Yes System Running OK Ignore No Yes
vhdmp vhdmp c:\windows\system32\drivers\vhdmp.sys Kernel Driver No Manual Stopped OK Normal No No
viaide viaide c:\windows\system32\drivers\viaide.sys Kernel Driver No Manual Stopped OK Critical No No
vmbus Virtual Machine Bus c:\windows\system32\drivers\vmbus.sys Kernel Driver Yes Boot Running OK Normal No Yes
vmbushid VMBusHID c:\windows\system32\drivers\vmbushid.sys Kernel Driver No Manual Stopped OK Ignore No No
volmgr Volume Manager Driver c:\windows\system32\drivers\volmgr.sys Kernel Driver Yes Boot Running OK Critical No Yes
volmgrx Dynamic Volume Manager c:\windows\system32\drivers\volmgrx.sys Kernel Driver Yes Boot Running OK Critical No Yes
volsnap Storage volumes c:\windows\system32\drivers\volsnap.sys Kernel Driver Yes Boot Running OK Critical No Yes
vsmraid vsmraid c:\windows\system32\drivers\vsmraid.sys Kernel Driver No Manual Stopped OK Normal No No
vwifibus Virtual WiFi Bus Driver c:\windows\system32\drivers\vwifibus.sys Kernel Driver No Manual Stopped OK Ignore No No
wacompen Wacom Serial Pen HID Driver c:\windows\system32\drivers\wacompen.sys Kernel Driver No Manual Stopped OK Normal No No
wanarp Remote Access IP ARP Driver c:\windows\system32\drivers\wanarp.sys Kernel Driver No Manual Stopped OK Normal No No
wanarpv6 Remote Access IPv6 ARP Driver c:\windows\system32\drivers\wanarp.sys Kernel Driver Yes System Running OK Normal No Yes
wd Wd c:\windows\system32\drivers\wd.sys Kernel Driver No Manual Stopped OK Normal No No
wdf01000 Kernel Mode Driver Frameworks service c:\windows\system32\drivers\wdf01000.sys Kernel Driver Yes Boot Running OK Normal No Yes
wfplwf WFP Lightweight Filter c:\windows\system32\drivers\wfplwf.sys Kernel Driver Yes System Running OK Normal No Yes
wimmount WIMMount c:\windows\system32\drivers\wimmount.sys File System Driver No Manual Stopped OK Normal No No
winusb Android USB Driver c:\windows\system32\drivers\winusb.sys Kernel Driver No Manual Stopped OK Normal No No
wmiacpi Microsoft Windows Management Interface for ACPI c:\windows\system32\drivers\wmiacpi.sys Kernel Driver No Manual Stopped OK Normal No No
ws2ifsl Windows Socket 2.0 Non-IFS Service Provider Support Environment c:\windows\system32\drivers\ws2ifsl.sys Kernel Driver Yes System Running OK Normal No Yes
wsaudio_device WsAudio_Device c:\windows\system32\drivers\virtualaudio.sys Kernel Driver No Manual Stopped OK Normal No No
wudfpf User Mode Driver Frameworks Platform Driver c:\windows\system32\drivers\wudfpf.sys Kernel Driver Yes Manual Running OK Normal No Yes
wudfrd WUDFRd c:\windows\system32\drivers\wudfrd.sys Kernel Driver No Manual Stopped OK Normal No No
 
[Environment Variables]
 
Variable Value User Name
AMDAPPSDKROOT C:\Program Files (x86)\AMD APP\ <SYSTEM>
ComSpec %SystemRoot%\system32\cmd.exe <SYSTEM>
FP_NO_HOST_CHECK NO <SYSTEM>
NUMBER_OF_PROCESSORS 3 <SYSTEM>
OS Windows_NT <SYSTEM>
Path C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\AMD APP\bin\x86_64;C:\Program Files (x86)\AMD APP\bin\x86;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\QuickTime\QTSystem;C:\Program Files (x86)\Common Files\Ulead Systems\MPEG;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Windows Live\Shared <SYSTEM>
PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC <SYSTEM>
PROCESSOR_ARCHITECTURE AMD64 <SYSTEM>
PROCESSOR_IDENTIFIER AMD64 Family 16 Model 5 Stepping 3, AuthenticAMD <SYSTEM>
PROCESSOR_LEVEL 16 <SYSTEM>
PROCESSOR_REVISION 0503 <SYSTEM>
PSModulePath %SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\ <SYSTEM>
TEMP %SystemRoot%\TEMP <SYSTEM>
TMP %SystemRoot%\TEMP <SYSTEM>
USERNAME SYSTEM <SYSTEM>
windir %SystemRoot% <SYSTEM>
TEMP %USERPROFILE%\AppData\Local\Temp NT AUTHORITY\SYSTEM
TMP %USERPROFILE%\AppData\Local\Temp NT AUTHORITY\SYSTEM
path C:\Users\Mom\AppData\Local\Bandizip\7z Mom-PC\Mom
TEMP %USERPROFILE%\AppData\Local\Temp Mom-PC\Mom
TMP %USERPROFILE%\AppData\Local\Temp Mom-PC\Mom
 
[Print Jobs]
 
Document Size Owner Notify Status Time Submitted Start Time Until Time Elapsed Time Pages Printed Job ID Priority Parameters Driver Print Processor Host Print Queue Data Type Name
 
[Network Connections]
 
Local Name Remote Name Type Status User Name
 
[Running Tasks]
 
Name Path Process ID Priority Min Working Set Max Working Set Start Time Version Size File Date
system idle process Not Available 0 0 Not Available Not Available Not Available Not Available Not Available Not Available
system Not Available 4 8 Not Available Not Available 3/27/2015 6:23 PM Not Available Not Available Not Available
smss.exe Not Available 288 11 Not Available Not Available 3/27/2015 6:23 PM Not Available Not Available Not Available
csrss.exe Not Available 412 13 Not Available Not Available 3/27/2015 6:23 PM Not Available Not Available Not Available
wininit.exe Not Available 484 13 Not Available Not Available 3/27/2015 6:23 PM Not Available Not Available Not Available
csrss.exe Not Available 512 13 Not Available Not Available 3/27/2015 6:23 PM Not Available Not Available Not Available
services.exe Not Available 544 9 Not Available Not Available 3/27/2015 6:23 PM Not Available Not Available Not Available
lsass.exe Not Available 560 9 Not Available Not Available 3/27/2015 6:23 PM Not Available Not Available Not Available
lsm.exe Not Available 568 8 Not Available Not Available 3/27/2015 6:23 PM Not Available Not Available Not Available
winlogon.exe Not Available 648 13 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
svchost.exe Not Available 720 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
svchost.exe Not Available 800 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
msmpeng.exe Not Available 860 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
svchost.exe Not Available 1012 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
svchost.exe Not Available 372 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
svchost.exe Not Available 404 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
svchost.exe Not Available 392 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
audiodg.exe Not Available 376 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
svchost.exe Not Available 1052 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
svchost.exe Not Available 1120 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
spoolsv.exe Not Available 1256 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
svchost.exe Not Available 1300 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
taskhost.exe c:\windows\system32\taskhost.exe 1508 8 200 1380 3/27/2015 6:24 PM 6.1.7601.18010 67.00 KB (68,608 bytes) 1/9/2013 5:00 AM
explorer.exe c:\windows\explorer.exe 1584 8 200 1380 3/27/2015 6:24 PM 6.1.7601.17567 2.74 MB (2,871,808 bytes) 4/27/2011 9:07 AM
smsvchost.exe Not Available 1864 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
wlidsvc.exe Not Available 2000 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
wlidsvcm.exe Not Available 1332 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
rundll32.exe c:\windows\system32\rundll32.exe 2236 8 200 1380 3/27/2015 6:24 PM 6.1.7600.16385 44.50 KB (45,568 bytes) 7/13/2009 7:57 PM
wudfhost.exe Not Available 2388 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
searchindexer.exe Not Available 2956 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
svchost.exe Not Available 2208 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
svchost.exe Not Available 2868 8 Not Available Not Available 3/27/2015 6:24 PM Not Available Not Available Not Available
chrome.exe c:\program files (x86)\google\chrome\application\chrome.exe 1480 8 200 1380 3/27/2015 6:25 PM 41.0.2272.89 790.32 KB (809,288 bytes) 12/7/2013 10:53 AM
chrome.exe c:\program files (x86)\google\chrome\application\chrome.exe 3064 8 200 1380 3/27/2015 6:25 PM 41.0.2272.89 790.32 KB (809,288 bytes) 12/7/2013 10:53 AM
nissrv.exe Not Available 2436 8 Not Available Not Available 3/27/2015 6:25 PM Not Available Not Available Not Available
chrome.exe c:\program files (x86)\google\chrome\application\chrome.exe 3496 8 200 1380 3/27/2015 6:26 PM 41.0.2272.89 790.32 KB (809,288 bytes) 12/7/2013 10:53 AM
chrome.exe c:\program files (x86)\google\chrome\application\chrome.exe 3560 8 200 1380 3/27/2015 6:26 PM 41.0.2272.89 790.32 KB (809,288 bytes) 12/7/2013 10:53 AM
chrome.exe c:\program files (x86)\google\chrome\application\chrome.exe 3624 8 200 1380 3/27/2015 6:26 PM 41.0.2272.89 790.32 KB (809,288 bytes) 12/7/2013 10:53 AM
wmiprvse.exe Not Available 2952 8 Not Available Not Available 3/27/2015 6:27 PM Not Available Not Available Not Available
trustedinstaller.exe Not Available 3320 8 Not Available Not Available 3/27/2015 6:28 PM Not Available Not Available Not Available
chrome.exe c:\program files (x86)\google\chrome\application\chrome.exe 3680 8 200 1380 3/27/2015 6:28 PM 41.0.2272.89 790.32 KB (809,288 bytes) 12/7/2013 10:53 AM
searchprotocolhost.exe Not Available 3988 4 Not Available Not Available 3/27/2015 6:29 PM Not Available Not Available Not Available
searchfilterhost.exe Not Available 3972 4 Not Available Not Available 3/27/2015 6:29 PM Not Available Not Available Not Available
msinfo32.exe c:\windows\system32\msinfo32.exe 732 8 200 1380 3/27/2015 6:29 PM 6.1.7601.17514 370.00 KB (378,880 bytes) 7/3/2011 10:51 AM
wmiprvse.exe Not Available 2268 8 Not Available Not Available 3/27/2015 6:29 PM Not Available Not Available Not Available
 
[Loaded Modules]
 
Name Version Size File Date Manufacturer Path
taskhost 6.1.7601.18010 67.00 KB (68,608 bytes) 1/9/2013 5:00 AM Microsoft Corporation c:\windows\system32\taskhost.exe
ntdll 6.1.7601.18247 1.65 MB (1,732,032 bytes) 10/9/2013 11:39 AM Microsoft Corporation c:\windows\system32\ntdll.dll
kernel32 6.1.7601.18409 1.11 MB (1,163,264 bytes) 4/8/2014 5:51 PM Microsoft Corporation c:\windows\system32\kernel32.dll
kernelbase 6.1.7601.18409 415.00 KB (424,960 bytes) 5/14/2014 6:27 AM Microsoft Corporation c:\windows\system32\kernelbase.dll
msvcrt 7.0.7601.17744 620.00 KB (634,880 bytes) 2/14/2012 9:47 PM Microsoft Corporation c:\windows\system32\msvcrt.dll
ole32 6.1.7601.17514 1.99 MB (2,086,912 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\ole32.dll
gdi32 6.1.7601.18577 395.00 KB (404,480 bytes) 9/4/2014 1:45 PM Microsoft Corporation c:\windows\system32\gdi32.dll
user32 6.1.7601.17514 984.50 KB (1,008,128 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\user32.dll
lpk 6.1.7601.18768 41.00 KB (41,984 bytes) 3/10/2015 7:38 PM Microsoft Corporation c:\windows\system32\lpk.dll
usp10 1.626.7601.18454 782.50 KB (801,280 bytes) 7/5/2014 6:13 PM Microsoft Corporation c:\windows\system32\usp10.dll
rpcrt4 6.1.7601.18532 1.16 MB (1,216,000 bytes) 8/17/2014 1:41 PM Microsoft Corporation c:\windows\system32\rpcrt4.dll
oleaut32 6.1.7601.18679 841.50 KB (861,696 bytes) 2/14/2015 1:56 PM Microsoft Corporation c:\windows\system32\oleaut32.dll
imm32 6.1.7600.16385 163.50 KB (167,424 bytes) 7/13/2009 7:38 PM Microsoft Corporation c:\windows\system32\imm32.dll
msctf 6.1.7601.18731 1.02 MB (1,067,520 bytes) 3/10/2015 7:36 PM Microsoft Corporation c:\windows\system32\msctf.dll
cryptbase 6.1.7600.16385 43.00 KB (44,032 bytes) 7/13/2009 7:20 PM Microsoft Corporation c:\windows\system32\cryptbase.dll
sechost 6.1.7600.16385 111.00 KB (113,664 bytes) 7/13/2009 7:20 PM Microsoft Corporation c:\windows\system32\sechost.dll
advapi32 6.1.7601.18247 857.50 KB (878,080 bytes) 10/9/2013 11:39 AM Microsoft Corporation c:\windows\system32\advapi32.dll
dwmapi 6.1.7600.16385 80.50 KB (82,432 bytes) 7/13/2009 7:37 PM Microsoft Corporation c:\windows\system32\dwmapi.dll
clbcatq 2001.12.8530.16385 593.50 KB (607,744 bytes) 7/13/2009 8:00 PM Microsoft Corporation c:\windows\system32\clbcatq.dll
msctfmonitor 6.1.7600.16385 27.50 KB (28,160 bytes) 7/13/2009 7:39 PM Microsoft Corporation c:\windows\system32\msctfmonitor.dll
msutb 6.1.7600.16385 230.00 KB (235,520 bytes) 7/13/2009 7:39 PM Microsoft Corporation c:\windows\system32\msutb.dll
winsta 6.1.7601.18540 230.00 KB (235,520 bytes) 10/16/2014 8:20 AM Microsoft Corporation c:\windows\system32\winsta.dll
wtsapi32 6.1.7600.16385 53.00 KB (54,272 bytes) 7/13/2009 8:17 PM Microsoft Corporation c:\windows\system32\wtsapi32.dll
uxtheme 6.1.7600.16385 324.50 KB (332,288 bytes) 7/13/2009 7:55 PM Microsoft Corporation c:\windows\system32\uxtheme.dll
playsndsrv 6.1.7600.16385 83.00 KB (84,992 bytes) 7/13/2009 8:18 PM Microsoft Corporation c:\windows\system32\playsndsrv.dll
wininet 11.0.9600.17689 2.25 MB (2,358,784 bytes) 3/10/2015 7:36 PM Microsoft Corporation c:\windows\system32\wininet.dll
api-ms-win-downlevel-user32-l1-1-0 6.2.9200.16492 4.00 KB (4,096 bytes) 2/28/2013 3:00 AM Microsoft Corporation c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
api-ms-win-downlevel-shlwapi-l1-1-0 6.2.9200.16492 9.50 KB (9,728 bytes) 2/28/2013 3:00 AM Microsoft Corporation c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
shlwapi 6.1.7601.17514 438.00 KB (448,512 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\shlwapi.dll
api-ms-win-downlevel-version-l1-1-0 6.2.9200.16492 3.00 KB (3,072 bytes) 2/28/2013 3:00 AM Microsoft Corporation c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
version 6.1.7600.16385 28.50 KB (29,184 bytes) 7/13/2009 7:57 PM Microsoft Corporation c:\windows\system32\version.dll
api-ms-win-downlevel-normaliz-l1-1-0 6.2.9200.16492 2.50 KB (2,560 bytes) 2/28/2013 3:00 AM Microsoft Corporation c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
normaliz 6.1.7600.16385 2.50 KB (2,560 bytes) 7/13/2009 7:26 PM Microsoft Corporation c:\windows\system32\normaliz.dll
iertutil 11.0.9600.17689 2.75 MB (2,886,144 bytes) 3/10/2015 7:36 PM Microsoft Corporation c:\windows\system32\iertutil.dll
api-ms-win-downlevel-advapi32-l1-1-0 6.2.9200.16492 10.50 KB (10,752 bytes) 2/28/2013 3:00 AM Microsoft Corporation c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
userenv 6.1.7601.17514 106.50 KB (109,056 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\userenv.dll
profapi 6.1.7600.16385 43.00 KB (44,032 bytes) 7/13/2009 7:20 PM Microsoft Corporation c:\windows\system32\profapi.dll
hotstartuseragent 6.1.7601.17514 26.50 KB (27,136 bytes) 7/3/2011 10:50 AM Microsoft Corporation c:\windows\system32\hotstartuseragent.dll
slc 6.1.7600.16385 30.00 KB (30,720 bytes) 7/13/2009 7:51 PM Microsoft Corporation c:\windows\system32\slc.dll
api-ms-win-downlevel-ole32-l1-1-0 6.2.9200.16492 5.50 KB (5,632 bytes) 2/28/2013 3:00 AM Microsoft Corporation c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
rpcrtremote 6.1.7601.17514 64.00 KB (65,536 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\rpcrtremote.dll
api-ms-win-downlevel-advapi32-l2-1-0 6.2.9200.16492 3.50 KB (3,584 bytes) 2/28/2013 3:00 AM Microsoft Corporation c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
esent 6.1.7601.17577 2.45 MB (2,565,632 bytes) 4/27/2011 9:07 AM Microsoft Corporation c:\windows\system32\esent.dll
psapi 6.1.7600.16385 9.00 KB (9,216 bytes) 7/13/2009 7:26 PM Microsoft Corporation c:\windows\system32\psapi.dll
shell32 6.1.7601.18762 13.52 MB (14,177,280 bytes) 3/10/2015 7:37 PM Microsoft Corporation c:\windows\system32\shell32.dll
winmm 6.1.7600.16385 212.50 KB (217,600 bytes) 7/13/2009 8:18 PM Microsoft Corporation c:\windows\system32\winmm.dll
dimsjob 6.1.7600.16385 39.50 KB (40,448 bytes) 7/13/2009 7:53 PM Microsoft Corporation c:\windows\system32\dimsjob.dll
taskschd 6.1.7601.17514 1.14 MB (1,197,056 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\taskschd.dll
sspicli 6.1.7601.18779 133.00 KB (136,192 bytes) 3/10/2015 7:37 PM Microsoft Corporation c:\windows\system32\sspicli.dll
netprofm 6.1.7600.16385 449.00 KB (459,776 bytes) 7/13/2009 8:12 PM Microsoft Corporation c:\windows\system32\netprofm.dll
nsi 6.1.7600.16385 13.50 KB (13,824 bytes) 7/13/2009 7:21 PM Microsoft Corporation c:\windows\system32\nsi.dll
nlaapi 6.1.7601.17964 69.00 KB (70,656 bytes) 11/14/2012 2:29 AM Microsoft Corporation c:\windows\system32\nlaapi.dll
cryptsp 6.1.7601.18741 80.50 KB (82,432 bytes) 3/10/2015 7:38 PM Microsoft Corporation c:\windows\system32\cryptsp.dll
rsaenh 6.1.7600.16385 274.66 KB (281,256 bytes) 7/13/2009 7:53 PM Microsoft Corporation c:\windows\system32\rsaenh.dll
npmproxy 6.1.7600.16385 31.00 KB (31,744 bytes) 7/13/2009 8:12 PM Microsoft Corporation c:\windows\system32\npmproxy.dll
sqmapi 6.2.9200.16384 286.16 KB (293,032 bytes) 3/10/2015 7:36 PM Microsoft Corporation c:\program files\internet explorer\sqmapi.dll
explorer 6.1.7601.17567 2.74 MB (2,871,808 bytes) 4/27/2011 9:07 AM Microsoft Corporation c:\windows\explorer.exe
explorerframe 6.1.7601.17514 1.78 MB (1,866,240 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\explorerframe.dll
duser 6.1.7600.16385 254.50 KB (260,608 bytes) 7/13/2009 7:39 PM Microsoft Corporation c:\windows\system32\duser.dll
dui70 6.1.7600.16385 954.00 KB (976,896 bytes) 7/13/2009 7:41 PM Microsoft Corporation c:\windows\system32\dui70.dll
powrprof 6.1.7600.16385 163.50 KB (167,424 bytes) 7/13/2009 7:27 PM Microsoft Corporation c:\windows\system32\powrprof.dll
setupapi 6.1.7601.17514 1.81 MB (1,900,544 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\setupapi.dll
cfgmgr32 6.1.7601.17514 203.00 KB (207,872 bytes) 6/29/2011 3:05 AM Microsoft Corporation c:\windows\system32\cfgmgr32.dll
devobj 6.1.7600.16385 91.00 KB (93,184 bytes) 7/13/2009 7:26 PM Microsoft Corporation c:\windows\system32\devobj.dll
gdiplus 6.1.7601.18455 2.07 MB (2,166,272 bytes) 7/5/2014 6:11 PM Microsoft Corporation c:\windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_2b283fd671e9bf4d\gdiplus.dll
secur32 6.1.7601.18779 27.50 KB (28,160 bytes) 3/10/2015 7:37 PM Microsoft Corporation c:\windows\system32\secur32.dll
propsys 7.0.7601.17514 1.16 MB (1,212,416 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\propsys.dll
comctl32 6.10.7601.17514 1.94 MB (2,030,080 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll
windowscodecs 6.2.9200.17251 1.36 MB (1,424,896 bytes) 3/10/2015 7:36 PM Microsoft Corporation c:\windows\system32\windowscodecs.dll
apphelp 6.1.7601.17514 334.00 KB (342,016 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\apphelp.dll
DropboxExt64.25 1.0.0.25 181.47 KB (185,824 bytes) 3/4/2015 5:27 PM Dropbox, Inc. c:\users\mom\appdata\roaming\dropbox\bin\dropboxext64.25.dll
ehstorshell 6.1.7600.16385 198.50 KB (203,264 bytes) 7/13/2009 8:00 PM Microsoft Corporation c:\windows\system32\ehstorshell.dll
googledrivesync64 1.20.8672.3137 756.32 KB (774,472 bytes) 2/19/2015 1:24 PM Google c:\program files (x86)\google\drive\googledrivesync64.dll
msvcp90 9.0.30729.6161 833.33 KB (853,328 bytes) 6/16/2011 6:40 PM Microsoft Corporation c:\windows\winsxs\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_08e61857a83bc251\msvcp90.dll
msvcr90 9.0.30729.6161 626.33 KB (641,360 bytes) 6/16/2011 6:40 PM Microsoft Corporation c:\windows\winsxs\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_08e61857a83bc251\msvcr90.dll
iconcodecservice 6.1.7600.16385 14.00 KB (14,336 bytes) 7/13/2009 7:37 PM Microsoft Corporation c:\windows\system32\iconcodecservice.dll
sndvolsso 6.1.7601.17514 220.00 KB (225,280 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\sndvolsso.dll
hid 6.1.7600.16385 29.50 KB (30,208 bytes) 7/13/2009 8:06 PM Microsoft Corporation c:\windows\system32\hid.dll
mmdevapi 6.1.7600.16385 277.50 KB (284,160 bytes) 7/13/2009 8:18 PM Microsoft Corporation c:\windows\system32\mmdevapi.dll
timedate 6.1.7601.17753 503.50 KB (515,584 bytes) 2/14/2012 9:47 PM Microsoft Corporation c:\windows\system32\timedate.cpl
atl 3.5.2284.0 88.50 KB (90,624 bytes) 7/13/2009 8:34 PM Microsoft Corporation c:\windows\system32\atl.dll
winbrand 6.1.7600.16385 16.00 KB (16,384 bytes) 7/13/2009 7:30 PM Microsoft Corporation c:\windows\system32\winbrand.dll
actxprxy 6.1.7601.17514 936.00 KB (958,464 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\actxprxy.dll
ntmarta 6.1.7600.16385 158.50 KB (162,304 bytes) 7/13/2009 7:50 PM Microsoft Corporation c:\windows\system32\ntmarta.dll
wldap32 6.1.7601.17514 305.50 KB (312,832 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\wldap32.dll
shdocvw 6.1.7601.18222 192.50 KB (197,120 bytes) 9/11/2013 1:13 AM Microsoft Corporation c:\windows\system32\shdocvw.dll
linkinfo 6.1.7600.16385 29.00 KB (29,696 bytes) 7/13/2009 7:55 PM Microsoft Corporation c:\windows\system32\linkinfo.dll
shacct 6.1.7601.17514 132.00 KB (135,168 bytes) 7/3/2011 10:50 AM Microsoft Corporation c:\windows\system32\shacct.dll
samlib 6.1.7600.16385 104.50 KB (107,008 bytes) 7/13/2009 7:53 PM Microsoft Corporation c:\windows\system32\samlib.dll
msftedit 5.41.21.2510 781.00 KB (799,744 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\msftedit.dll
msls31 3.10.349.0 242.00 KB (247,808 bytes) 11/25/2013 4:19 PM Microsoft Corporation c:\windows\system32\msls31.dll
tiptsf 6.1.7601.18512 491.50 KB (503,296 bytes) 7/12/2014 12:24 PM Microsoft Corporation c:\program files\common files\microsoft shared\ink\tiptsf.dll
authui 6.1.7601.18493 1.85 MB (1,941,504 bytes) 8/17/2014 1:41 PM Microsoft Corporation c:\windows\system32\authui.dll
cryptui 6.1.7601.18741 1.02 MB (1,069,056 bytes) 3/10/2015 7:38 PM Microsoft Corporation c:\windows\system32\cryptui.dll
crypt32 6.1.7601.18741 1.41 MB (1,480,192 bytes) 3/10/2015 7:38 PM Microsoft Corporation c:\windows\system32\crypt32.dll
msasn1 6.1.7601.17514 45.50 KB (46,592 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\msasn1.dll
xmllite 1.3.1001.0 195.00 KB (199,680 bytes) 8/10/2011 1:55 PM Microsoft Corporation c:\windows\system32\xmllite.dll
networkexplorer 6.1.7601.17514 1.60 MB (1,672,704 bytes) 7/3/2011 10:50 AM Microsoft Corporation c:\windows\system32\networkexplorer.dll
mpr 6.1.7600.16385 79.00 KB (80,896 bytes) 7/13/2009 8:10 PM Microsoft Corporation c:\windows\system32\mpr.dll
ieframe 11.0.9600.17689 13.73 MB (14,398,976 bytes) 3/10/2015 7:36 PM Microsoft Corporation c:\windows\system32\ieframe.dll
api-ms-win-downlevel-shell32-l1-1-0 6.2.9200.16492 3.00 KB (3,072 bytes) 2/28/2013 3:00 AM Microsoft Corporation c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
api-ms-win-downlevel-shlwapi-l2-1-0 6.2.9200.16492 5.50 KB (5,632 bytes) 2/28/2013 3:00 AM Microsoft Corporation c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
ntshrui 6.1.7601.17755 498.00 KB (509,952 bytes) 2/14/2012 9:47 PM Microsoft Corporation c:\windows\system32\ntshrui.dll
srvcli 6.1.7601.17514 125.00 KB (128,000 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\srvcli.dll
cscapi 6.1.7601.17514 45.00 KB (46,080 bytes) 7/3/2011 10:50 AM Microsoft Corporation c:\windows\system32\cscapi.dll
wdmaud 6.1.7601.17514 212.00 KB (217,088 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\wdmaud.drv
ksuser 6.1.7600.16385 5.00 KB (5,120 bytes) 7/13/2009 8:18 PM Microsoft Corporation c:\windows\system32\ksuser.dll
avrt 6.1.7600.16385 18.00 KB (18,432 bytes) 7/13/2009 8:22 PM Microsoft Corporation c:\windows\system32\avrt.dll
audioses 6.1.7601.18741 289.50 KB (296,448 bytes) 3/10/2015 7:38 PM Microsoft Corporation c:\windows\system32\audioses.dll
msacm32 6.1.7600.16385 25.00 KB (25,600 bytes) 7/13/2009 8:18 PM Microsoft Corporation c:\windows\system32\msacm32.drv
msacm32 6.1.7600.16385 81.50 KB (83,456 bytes) 7/13/2009 8:18 PM Microsoft Corporation c:\windows\system32\msacm32.dll
midimap 6.1.7600.16385 20.00 KB (20,480 bytes) 7/13/2009 8:18 PM Microsoft Corporation c:\windows\system32\midimap.dll
gameux 6.1.7601.18020 2.62 MB (2,746,368 bytes) 1/9/2013 5:01 AM Microsoft Corporation c:\windows\system32\gameux.dll
wer 6.1.7601.18381 473.50 KB (484,864 bytes) 3/19/2014 12:14 AM Microsoft Corporation c:\windows\system32\wer.dll
msiltcfg 5.0.7600.16385 19.50 KB (19,968 bytes) 7/13/2009 7:48 PM Microsoft Corporation c:\windows\system32\msiltcfg.dll
msi 5.0.7601.18637 3.09 MB (3,241,984 bytes) 11/11/2014 7:39 PM Microsoft Corporation c:\windows\system32\msi.dll
stobject 6.1.7601.17514 251.00 KB (257,024 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\stobject.dll
batmeter 6.1.7601.17514 732.00 KB (749,568 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\batmeter.dll
es 2001.12.8530.16385 393.50 KB (402,944 bytes) 7/13/2009 8:00 PM Microsoft Corporation c:\windows\system32\es.dll
prnfldr 6.1.7601.17514 406.50 KB (416,256 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\prnfldr.dll
winspool 6.1.7601.17514 432.00 KB (442,368 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\winspool.drv
dxp 6.1.7601.17514 449.00 KB (459,776 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\dxp.dll
urlmon 11.0.9600.17689 1.48 MB (1,548,288 bytes) 3/10/2015 7:36 PM Microsoft Corporation c:\windows\system32\urlmon.dll
wintrust 6.1.7601.18741 224.00 KB (229,376 bytes) 3/10/2015 7:38 PM Microsoft Corporation c:\windows\system32\wintrust.dll
syncreg 2007.94.7600.16385 72.00 KB (73,728 bytes) 7/13/2009 8:22 PM Microsoft Corporation c:\windows\system32\syncreg.dll
ehsso 6.1.7600.16385 25.50 KB (26,112 bytes) 7/13/2009 8:24 PM Microsoft Corporation c:\windows\ehome\ehsso.dll
netshell 6.1.7601.17514 2.53 MB (2,652,160 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\netshell.dll
iphlpapi 6.1.7601.17514 142.50 KB (145,920 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\iphlpapi.dll
winnsi 6.1.7600.16385 25.50 KB (26,112 bytes) 7/13/2009 7:21 PM Microsoft Corporation c:\windows\system32\winnsi.dll
alttab 6.1.7600.16385 52.00 KB (53,248 bytes) 7/13/2009 7:55 PM Microsoft Corporation c:\windows\system32\alttab.dll
wpdshserviceobj 6.1.7601.17514 112.50 KB (115,200 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\wpdshserviceobj.dll
portabledevicetypes 6.1.7600.16385 214.50 KB (219,648 bytes) 7/13/2009 8:21 PM Microsoft Corporation c:\windows\system32\portabledevicetypes.dll
portabledeviceapi 6.1.7601.17514 740.50 KB (758,272 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\portabledeviceapi.dll
mssprxy 7.0.7600.16385 98.00 KB (100,352 bytes) 7/13/2009 8:29 PM Microsoft Corporation c:\windows\system32\mssprxy.dll
pnidui 6.1.7601.17514 1.72 MB (1,808,384 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\pnidui.dll
qutil 6.1.7601.17514 105.00 KB (107,520 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\qutil.dll
wevtapi 6.1.7600.16385 418.00 KB (428,032 bytes) 7/13/2009 7:46 PM Microsoft Corporation c:\windows\system32\wevtapi.dll
dhcpcsvc6 6.1.7601.17970 54.00 KB (55,296 bytes) 11/14/2012 2:29 AM Microsoft Corporation c:\windows\system32\dhcpcsvc6.dll
ws2_32 6.1.7601.17514 291.00 KB (297,984 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\ws2_32.dll
dhcpcsvc 6.1.7600.16385 85.00 KB (87,040 bytes) 7/13/2009 7:21 PM Microsoft Corporation c:\windows\system32\dhcpcsvc.dll
credssp 6.1.7601.18779 21.50 KB (22,016 bytes) 3/10/2015 7:37 PM Microsoft Corporation c:\windows\system32\credssp.dll
cscui 6.1.7601.17514 487.00 KB (498,688 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\cscui.dll
cscdll 6.1.7601.17514 29.50 KB (30,208 bytes) 7/3/2011 10:50 AM Microsoft Corporation c:\windows\system32\cscdll.dll
wlanapi 6.1.7600.16385 111.50 KB (114,176 bytes) 7/13/2009 8:07 PM Microsoft Corporation c:\windows\system32\wlanapi.dll
wlanutil 6.1.7600.16385 10.50 KB (10,752 bytes) 7/13/2009 8:07 PM Microsoft Corporation c:\windows\system32\wlanutil.dll
wwanapi 6.1.7600.16385 360.00 KB (368,640 bytes) 7/13/2009 8:12 PM Microsoft Corporation c:\windows\system32\wwanapi.dll
wwapi 8.1.2.0 35.50 KB (36,352 bytes) 7/13/2009 8:12 PM Microsoft Corporation c:\windows\system32\wwapi.dll
qagent 6.1.7601.17514 260.00 KB (266,240 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\qagent.dll
srchadmin 7.0.7601.17514 333.00 KB (340,992 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\srchadmin.dll
bthprops 6.1.7601.17514 704.50 KB (721,408 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\bthprops.cpl
actioncenter 6.1.7601.17514 762.50 KB (780,800 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\actioncenter.dll
fxsst 6.1.7600.16385 843.50 KB (863,744 bytes) 7/13/2009 8:35 PM Microsoft Corporation c:\windows\system32\fxsst.dll
fxsapi 6.1.7601.17514 608.50 KB (623,104 bytes) 7/3/2011 10:50 AM Microsoft Corporation c:\windows\system32\fxsapi.dll
fxsresm 6.1.7600.16385 903.50 KB (925,184 bytes) 7/13/2009 8:36 PM Microsoft Corporation c:\windows\system32\fxsresm.dll
synccenter 6.1.7601.17514 2.16 MB (2,262,528 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\synccenter.dll
imapi2 6.1.7601.17514 491.50 KB (503,296 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\imapi2.dll
hgcpl 6.1.7601.17514 324.50 KB (332,288 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\hgcpl.dll
provsvc 6.1.7601.17514 183.50 KB (187,904 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\provsvc.dll
sxs 6.1.7601.17514 569.00 KB (582,656 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\sxs.dll
wkscli 6.1.7601.17514 70.00 KB (71,680 bytes) 7/3/2011 10:50 AM Microsoft Corporation c:\windows\system32\wkscli.dll
netutils 6.1.7601.17514 28.50 KB (29,184 bytes) 7/3/2011 10:50 AM Microsoft Corporation c:\windows\system32\netutils.dll
devrtl 6.1.7600.16385 57.00 KB (58,368 bytes) 7/13/2009 7:26 PM Microsoft Corporation c:\windows\system32\devrtl.dll
wscinterop 6.1.7600.16385 143.00 KB (146,432 bytes) 7/13/2009 7:48 PM Microsoft Corporation c:\windows\system32\wscinterop.dll
wscapi 6.1.7601.17514 62.00 KB (63,488 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\wscapi.dll
wscui 6.1.7600.16385 1.11 MB (1,162,240 bytes) 7/13/2009 7:48 PM Microsoft Corporation c:\windows\system32\wscui.cpl
werconcpl 6.1.7601.17514 1.22 MB (1,281,024 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\werconcpl.dll
framedynos 6.1.7601.17514 289.00 KB (295,936 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\framedynos.dll
wercplsupport 6.1.7600.16385 82.50 KB (84,480 bytes) 7/13/2009 7:40 PM Microsoft Corporation c:\windows\system32\wercplsupport.dll
msxml6 6.30.7601.18431 1.91 MB (2,002,432 bytes) 7/5/2014 6:13 PM Microsoft Corporation c:\windows\system32\msxml6.dll
msoxmlmf 14.0.4750.1000 54.88 KB (56,192 bytes) 2/28/2010 1:24 AM Microsoft Corporation c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
hcproviders 6.1.7600.16385 30.50 KB (31,232 bytes) 7/13/2009 7:56 PM Microsoft Corporation c:\windows\system32\hcproviders.dll
ieproxy 11.0.9600.17689 725.00 KB (742,400 bytes) 3/10/2015 7:36 PM Microsoft Corporation c:\program files\internet explorer\ieproxy.dll
searchfolder 6.1.7601.17514 847.50 KB (867,840 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\searchfolder.dll
drprov 6.1.7600.16385 24.00 KB (24,576 bytes) 7/13/2009 8:17 PM Microsoft Corporation c:\windows\system32\drprov.dll
ntlanman 6.1.7601.17514 126.50 KB (129,536 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\ntlanman.dll
davclnt 6.1.7601.18201 100.00 KB (102,400 bytes) 10/9/2013 11:39 AM Microsoft Corporation c:\windows\system32\davclnt.dll
davhlpr 6.1.7600.16385 25.00 KB (25,600 bytes) 7/13/2009 7:23 PM Microsoft Corporation c:\windows\system32\davhlpr.dll
mlang 6.1.7600.16385 221.50 KB (226,816 bytes) 7/13/2009 7:55 PM Microsoft Corporation c:\windows\system32\mlang.dll
rundll32 6.1.7600.16385 44.50 KB (45,568 bytes) 7/13/2009 7:57 PM Microsoft Corporation c:\windows\system32\rundll32.exe
imagehlp 6.1.7601.18288 79.50 KB (81,408 bytes) 12/11/2013 2:51 PM Microsoft Corporation c:\windows\system32\imagehlp.dll
chrome 41.0.2272.89 790.32 KB (809,288 bytes) 12/7/2013 10:53 AM Google Inc. c:\program files (x86)\google\chrome\application\chrome.exe
wow64 6.1.7601.18409 238.00 KB (243,712 bytes) 4/8/2014 5:51 PM Microsoft Corporation c:\windows\system32\wow64.dll
wow64win 6.1.7601.18409 354.00 KB (362,496 bytes) 4/8/2014 5:51 PM Microsoft Corporation c:\windows\system32\wow64win.dll
wow64cpu 6.1.7601.18409 13.00 KB (13,312 bytes) 4/8/2014 5:51 PM Microsoft Corporation c:\windows\system32\wow64cpu.dll
msinfo32 6.1.7601.17514 370.00 KB (378,880 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\msinfo32.exe
mfc42u 6.6.8064.0 1.30 MB (1,359,872 bytes) 4/15/2011 1:53 AM Microsoft Corporation c:\windows\system32\mfc42u.dll
odbc32 6.1.7601.17514 704.00 KB (720,896 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\odbc32.dll
comdlg32 6.1.7601.17514 580.50 KB (594,432 bytes) 7/3/2011 10:52 AM Microsoft Corporation c:\windows\system32\comdlg32.dll
odbcint 6.1.7600.16385 224.00 KB (229,376 bytes) 7/13/2009 8:28 PM Microsoft Corporation c:\windows\system32\odbcint.dll
wbemprox 6.1.7600.16385 42.50 KB (43,520 bytes) 7/13/2009 7:46 PM Microsoft Corporation c:\windows\system32\wbem\wbemprox.dll
wbemcomn 6.1.7601.17514 517.00 KB (529,408 bytes) 7/3/2011 10:47 AM Microsoft Corporation c:\windows\system32\wbemcomn.dll
wbemsvc 6.1.7600.16385 63.00 KB (64,512 bytes) 7/13/2009 7:46 PM Microsoft Corporation c:\windows\system32\wbem\wbemsvc.dll
fastprox 6.1.7600.16385 888.00 KB (909,312 bytes) 7/13/2009 7:47 PM Microsoft Corporation c:\windows\system32\wbem\fastprox.dll
ntdsapi 6.1.7600.16385 148.50 KB (152,064 bytes) 7/13/2009 7:54 PM Microsoft Corporation c:\windows\system32\ntdsapi.dll
structuredquery 7.0.7601.17514 472.50 KB (483,840 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\structuredquery.dll
thumbcache 6.1.7601.17514 110.00 KB (112,640 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\thumbcache.dll
oleacc 7.0.0.0 324.00 KB (331,776 bytes) 10/12/2011 11:19 PM Microsoft Corporation c:\windows\system32\oleacc.dll
fundisc 6.1.7600.16385 190.00 KB (194,560 bytes) 7/13/2009 7:35 PM Microsoft Corporation c:\windows\system32\fundisc.dll
fdproxy 6.1.7601.17514 72.50 KB (74,240 bytes) 7/3/2011 10:50 AM Microsoft Corporation c:\windows\system32\fdproxy.dll
networkitemfactory 6.1.7600.16385 52.00 KB (53,248 bytes) 7/13/2009 8:08 PM Microsoft Corporation c:\windows\system32\networkitemfactory.dll
dtsh 6.1.7600.16385 35.50 KB (36,352 bytes) 7/13/2009 8:08 PM Microsoft Corporation c:\windows\system32\dtsh.dll
firewallapi 6.1.7600.16385 730.50 KB (748,032 bytes) 7/13/2009 8:08 PM Microsoft Corporation c:\windows\system32\firewallapi.dll
fdwcn 6.1.7600.16385 99.00 KB (101,376 bytes) 7/13/2009 8:08 PM Microsoft Corporation c:\windows\system32\fdwcn.dll
wcnapi 6.1.7600.16385 118.00 KB (120,832 bytes) 7/13/2009 8:08 PM Microsoft Corporation c:\windows\system32\wcnapi.dll
fdwnet 6.1.7600.16385 27.50 KB (28,160 bytes) 7/13/2009 7:35 PM Microsoft Corporation c:\windows\system32\fdwnet.dll
dfscli 6.1.7600.16385 61.50 KB (62,976 bytes) 7/13/2009 7:53 PM Microsoft Corporation c:\windows\system32\dfscli.dll
browcli 6.1.7601.17887 58.00 KB (59,392 bytes) 8/15/2012 1:42 PM Microsoft Corporation c:\windows\system32\browcli.dll
ehstorapi 6.1.7601.17514 141.50 KB (144,896 bytes) 7/3/2011 10:50 AM Microsoft Corporation c:\windows\system32\ehstorapi.dll
cabview 6.1.7601.17514 136.00 KB (139,264 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\cabview.dll
twext 6.1.7601.17514 168.50 KB (172,544 bytes) 7/3/2011 10:51 AM Microsoft Corporation c:\windows\system32\twext.dll
 
[Services]
 
Display Name Name State Start Mode Service Type Path Error Control Start Name Tag ID
Adobe Acrobat Update Service AdobeARMservice Stopped Disabled Own Process "c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe" Ignore LocalSystem 0
Adobe Flash Player Update Service AdobeFlashPlayerUpdateSvc Stopped Disabled Own Process c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe Normal LocalSystem 0
Application Experience AeLookupSvc Stopped Disabled Share Process c:\windows\system32\svchost.exe -k netsvcs Normal localSystem 0
Application Layer Gateway Service ALG Stopped Disabled Own Process c:\windows\system32\alg.exe Normal NT AUTHORITY\LocalService 0
AMD External Events Utility AMD External Events Utility Stopped Disabled Own Process c:\windows\system32\atiesrxx.exe Normal LocalSystem 0
AMD FUEL Service AMD FUEL Service Stopped Disabled Own Process c:\program files\ati technologies\ati.ace\fuel\fuel.service.exe /launchservice Normal LocalSystem 0
Application Identity AppIDSvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k localserviceandnoimpersonation Normal NT Authority\LocalService 0
Application Information Appinfo Running Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Apple Mobile Device Service Apple Mobile Device Service Stopped Disabled Own Process "c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe" Normal LocalSystem 0
Application Management AppMgmt Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
ASP.NET State Service aspnet_state Stopped Manual Own Process c:\windows\microsoft.net\framework64\v4.0.30319\aspnet_state.exe Normal NT AUTHORITY\NetworkService 0
Windows Audio Endpoint Builder AudioEndpointBuilder Running Auto Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
Windows Audio AudioSrv Running Auto Share Process c:\windows\system32\svchost.exe -k localservicenetworkrestricted Normal NT AUTHORITY\LocalService 0
ActiveX Installer (AxInstSV) AxInstSV Stopped Manual Share Process c:\windows\system32\svchost.exe -k axinstsvgroup Normal LocalSystem 0
BitLocker Drive Encryption Service BDESVC Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal localSystem 0
Base Filtering Engine BFE Running Auto Share Process c:\windows\system32\svchost.exe -k localservicenonetwork Normal NT AUTHORITY\LocalService 0
Background Intelligent Transfer Service BITS Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Bonjour Service Bonjour Service Stopped Disabled Own Process "c:\program files\bonjour\mdnsresponder.exe" Normal LocalSystem 0
Computer Browser Browser Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Bluetooth Support Service bthserv Stopped Manual Share Process c:\windows\system32\svchost.exe -k bthsvcs Normal NT AUTHORITY\LocalService 0
Certificate Propagation CertPropSvc Running Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Microsoft .NET Framework NGEN v2.0.50727_X86 clr_optimization_v2.0.50727_32 Stopped Disabled Own Process c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe Ignore LocalSystem 0
Microsoft .NET Framework NGEN v2.0.50727_X64 clr_optimization_v2.0.50727_64 Stopped Disabled Own Process c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe Ignore LocalSystem 0
Microsoft .NET Framework NGEN v4.0.30319_X86 clr_optimization_v4.0.30319_32 Stopped Auto Own Process c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe Ignore LocalSystem 0
Microsoft .NET Framework NGEN v4.0.30319_X64 clr_optimization_v4.0.30319_64 Stopped Auto Own Process c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe Ignore LocalSystem 0
COM+ System Application COMSysApp Stopped Manual Own Process c:\windows\system32\dllhost.exe /processid:{02d4b3f1-fd88-11d1-960d-00805fc79235} Normal LocalSystem 0
Cryptographic Services CryptSvc Running Manual Share Process c:\windows\system32\svchost.exe -k networkservice Normal NT Authority\NetworkService 0
Offline Files CscService Stopped Manual Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
DCOM Server Process Launcher DcomLaunch Running Auto Share Process c:\windows\system32\svchost.exe -k dcomlaunch Normal LocalSystem 0
Disk Defragmenter defragsvc Stopped Disabled Own Process c:\windows\system32\svchost.exe -k defragsvc Normal localSystem 0
DHCP Client Dhcp Running Auto Share Process c:\windows\system32\svchost.exe -k localservicenetworkrestricted Normal NT Authority\LocalService 0
DNS Client Dnscache Running Auto Share Process c:\windows\system32\svchost.exe -k networkservice Normal NT AUTHORITY\NetworkService 0
Wired AutoConfig dot3svc Stopped Manual Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal localSystem 0
Diagnostic Policy Service DPS Running Auto Share Process c:\windows\system32\svchost.exe -k localservicenonetwork Normal NT AUTHORITY\LocalService 0
Extensible Authentication Protocol EapHost Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal localSystem 0
Encrypting File System (EFS) EFS Stopped Manual Share Process c:\windows\system32\lsass.exe Normal LocalSystem 0
Windows Media Center Receiver Service ehRecvr Stopped Manual Own Process c:\windows\ehome\ehrecvr.exe Ignore NT AUTHORITY\networkService 0
Windows Media Center Scheduler Service ehSched Stopped Manual Own Process c:\windows\ehome\ehsched.exe Ignore NT AUTHORITY\networkService 0
Windows Event Log eventlog Running Auto Share Process c:\windows\system32\svchost.exe -k localservicenetworkrestricted Normal NT AUTHORITY\LocalService 0
COM+ Event System EventSystem Running Auto Share Process c:\windows\system32\svchost.exe -k localservice Normal NT AUTHORITY\LocalService 0
Fax Fax Stopped Manual Own Process c:\windows\system32\fxssvc.exe Normal NT AUTHORITY\NetworkService 0
Function Discovery Provider Host fdPHost Running Manual Share Process c:\windows\system32\svchost.exe -k localservice Normal NT AUTHORITY\LocalService 0
Function Discovery Resource Publication FDResPub Running Manual Share Process c:\windows\system32\svchost.exe -k localserviceandnoimpersonation Normal NT AUTHORITY\LocalService 0
Windows Font Cache Service FontCache Running Auto Share Process c:\windows\system32\svchost.exe -k localservice Normal NT AUTHORITY\LocalService 0
Windows Presentation Foundation Font Cache 3.0.0.0 FontCache3.0.0.0 Stopped Manual Own Process c:\windows\microsoft.net\framework64\v3.0\wpf\presentationfontcache.exe Normal NT Authority\LocalService 0
Group Policy Client gpsvc Running Auto Own Process c:\windows\system32\svchost.exe -k gpsvcgroup Normal LocalSystem 0
Google Update Service (gupdate) gupdate Stopped Disabled Own Process "c:\program files (x86)\google\update\googleupdate.exe" /svc Normal LocalSystem 0
Google Update Service (gupdatem) gupdatem Stopped Disabled Own Process "c:\program files (x86)\google\update\googleupdate.exe" /medsvc Normal LocalSystem 0
Human Interface Device Access hidserv Stopped Manual Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
Health Key and Certificate Management hkmsvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal localSystem 0
HomeGroup Provider HomeGroupProvider Running Manual Share Process c:\windows\system32\svchost.exe -k localservicenetworkrestricted Normal NT AUTHORITY\LocalService 0
Windows CardSpace idsvc Stopped Manual Share Process "c:\windows\microsoft.net\framework64\v3.0\windows communication foundation\infocard.exe" Normal LocalSystem 0
Internet Explorer ETW Collector Service IEEtwCollectorService Stopped Manual Own Process c:\windows\system32\ieetwcollector.exe /v Normal LocalSystem 0
IKE and AuthIP IPsec Keying Modules IKEEXT Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
PnP-X IP Bus Enumerator IPBusEnum Running Auto Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
IP Helper iphlpsvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
iPod Service iPod Service Stopped Disabled Own Process "c:\program files\ipod\bin\ipodservice.exe" Normal LocalSystem 0
CNG Key Isolation KeyIso Stopped Manual Share Process c:\windows\system32\lsass.exe Normal LocalSystem 0
KtmRm for Distributed Transaction Coordinator KtmRm Stopped Manual Share Process c:\windows\system32\svchost.exe -k networkserviceandnoimpersonation Normal NT AUTHORITY\NetworkService 0
Server LanmanServer Running Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Workstation LanmanWorkstation Running Auto Share Process c:\windows\system32\svchost.exe -k networkservice Normal NT AUTHORITY\NetworkService 0
Link-Layer Topology Discovery Mapper lltdsvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k localservice Normal NT AUTHORITY\LocalService 0
TCP/IP NetBIOS Helper lmhosts Running Manual Share Process c:\windows\system32\svchost.exe -k localservicenetworkrestricted Normal NT AUTHORITY\LocalService 0
MBAMScheduler MBAMScheduler Stopped Auto Own Process "c:\program files (x86)\malwarebytes anti-malware\mbamscheduler.exe" Normal LocalSystem 0
MBAMService MBAMService Stopped Auto Own Process "c:\program files (x86)\malwarebytes anti-malware\mbamservice.exe" Normal LocalSystem 0
Media Center Extender Service Mcx2Svc Stopped Disabled Share Process c:\windows\system32\svchost.exe -k localserviceandnoimpersonation Normal NT Authority\LocalService 0
Microsoft SharePoint Workspace Audit Service Microsoft SharePoint Workspace Audit Service Stopped Manual Own Process "c:\program files (x86)\microsoft office\office14\groove.exe" /auditservice Normal NT AUTHORITY\LocalService 0
Multimedia Class Scheduler MMCSS Running Auto Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Mozilla Maintenance Service MozillaMaintenance Stopped Disabled Own Process "c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe" Normal LocalSystem 0
Windows Firewall MpsSvc Running Auto Share Process c:\windows\system32\svchost.exe -k localservicenonetwork Normal NT Authority\LocalService 0
Distributed Transaction Coordinator MSDTC Stopped Manual Own Process c:\windows\system32\msdtc.exe Normal NT AUTHORITY\NetworkService 0
Microsoft iSCSI Initiator Service MSiSCSI Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Windows Installer msiserver Stopped Manual Own Process c:\windows\system32\msiexec.exe /v Normal LocalSystem 0
Microsoft Antimalware Service MsMpSvc Running Auto Own Process "c:\program files\microsoft security client\msmpeng.exe" Normal LocalSystem 0
Network Access Protection Agent napagent Stopped Manual Share Process c:\windows\system32\svchost.exe -k networkservice Normal NT AUTHORITY\NetworkService 0
Netlogon Netlogon Stopped Manual Share Process c:\windows\system32\lsass.exe Normal LocalSystem 0
Network Connections Netman Running Manual Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
Net.Msmq Listener Adapter NetMsmqActivator Stopped Disabled Share Process "c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe" -netmsmqactivator Normal NT AUTHORITY\NetworkService 0
Net.Pipe Listener Adapter NetPipeActivator Stopped Disabled Share Process c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe Normal NT AUTHORITY\LocalService 0
Network List Service netprofm Running Manual Share Process c:\windows\system32\svchost.exe -k localservice Normal NT AUTHORITY\LocalService 0
Net.Tcp Listener Adapter NetTcpActivator Stopped Disabled Share Process c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe Normal NT AUTHORITY\LocalService 0
Net.Tcp Port Sharing Service NetTcpPortSharing Running Auto Share Process c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe Normal NT AUTHORITY\LocalService 0
Microsoft Network Inspection NisSrv Running Manual Own Process "c:\program files\microsoft security client\nissrv.exe" Normal NT AUTHORITY\LocalService 0
Network Location Awareness NlaSvc Running Auto Share Process c:\windows\system32\svchost.exe -k networkservice Normal NT AUTHORITY\NetworkService 0
Network Store Interface Service nsi Running Auto Share Process c:\windows\system32\svchost.exe -k localservice Normal NT Authority\LocalService 0
Office  Source Engine ose Stopped Manual Own Process "c:\program files (x86)\common files\microsoft shared\source engine\ose.exe" Normal LocalSystem 0
Office Software Protection Platform osppsvc Stopped Manual Own Process "c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe" Normal NT AUTHORITY\NetworkService 0
Peer Networking Identity Manager p2pimsvc Running Manual Share Process c:\windows\system32\svchost.exe -k localservicepeernet Normal NT AUTHORITY\LocalService 0
Peer Networking Grouping p2psvc Running Manual Share Process c:\windows\system32\svchost.exe -k localservicepeernet Normal NT AUTHORITY\LocalService 0
Program Compatibility Assistant Service PcaSvc Running Auto Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
BranchCache PeerDistSvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k peerdist Normal NT AUTHORITY\NetworkService 0
Performance Counter DLL Host PerfHost Stopped Manual Own Process c:\windows\syswow64\perfhost.exe Normal NT AUTHORITY\LocalService 0
Performance Logs & Alerts pla Stopped Manual Share Process c:\windows\system32\svchost.exe -k localservicenonetwork Normal NT AUTHORITY\LocalService 0
Plug and Play PlugPlay Running Auto Share Process c:\windows\system32\svchost.exe -k dcomlaunch Normal LocalSystem 0
PNRP Machine Name Publication Service PNRPAutoReg Stopped Manual Share Process c:\windows\system32\svchost.exe -k localservicepeernet Normal NT AUTHORITY\LocalService 0
Peer Name Resolution Protocol PNRPsvc Running Manual Share Process c:\windows\system32\svchost.exe -k localservicepeernet Normal NT AUTHORITY\LocalService 0
IPsec Policy Agent PolicyAgent Stopped Manual Share Process c:\windows\system32\svchost.exe -k networkservicenetworkrestricted Normal NT Authority\NetworkService 0
Power Power Running Auto Share Process c:\windows\system32\svchost.exe -k dcomlaunch Normal LocalSystem 0
User Profile Service ProfSvc Running Auto Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Protected Storage ProtectedStorage Stopped Manual Share Process c:\windows\system32\lsass.exe Normal LocalSystem 0
Quality Windows Audio Video Experience QWAVE Stopped Manual Share Process c:\windows\system32\svchost.exe -k localserviceandnoimpersonation Normal NT AUTHORITY\LocalService 0
Remote Access Auto Connection Manager RasAuto Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal localSystem 0
Remote Access Connection Manager RasMan Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal localSystem 0
Routing and Remote Access RemoteAccess Stopped Disabled Share Process c:\windows\system32\svchost.exe -k netsvcs Normal localSystem 0
Remote Registry RemoteRegistry Stopped Manual Share Process c:\windows\system32\svchost.exe -k regsvc Normal NT AUTHORITY\LocalService 0
RPC Endpoint Mapper RpcEptMapper Running Auto Share Process c:\windows\system32\svchost.exe -k rpcss Normal NT AUTHORITY\NetworkService 0
Remote Procedure Call (RPC) Locator RpcLocator Stopped Manual Own Process c:\windows\system32\locator.exe Normal NT AUTHORITY\NetworkService 0
Remote Procedure Call (RPC) RpcSs Running Auto Share Process c:\windows\system32\svchost.exe -k rpcss Normal NT AUTHORITY\NetworkService 0
Security Accounts Manager SamSs Running Auto Share Process c:\windows\system32\lsass.exe Normal LocalSystem 0
Smart Card SCardSvr Stopped Manual Share Process c:\windows\system32\svchost.exe -k localserviceandnoimpersonation Normal NT AUTHORITY\LocalService 0
Task Scheduler Schedule Running Auto Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Smart Card Removal Policy SCPolicySvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Windows Backup SDRSVC Stopped Manual Own Process c:\windows\system32\svchost.exe -k sdrsvc Normal localSystem 0
Secondary Logon seclogon Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
System Event Notification Service SENS Running Auto Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Adaptive Brightness SensrSvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k localserviceandnoimpersonation Normal NT AUTHORITY\LocalService 0
Remote Desktop Configuration SessionEnv Running Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal localSystem 0
Internet Connection Sharing (ICS) SharedAccess Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Shell Hardware Detection ShellHWDetection Running Auto Share Process c:\windows\system32\svchost.exe -k netsvcs Ignore LocalSystem 0
SNMP Trap SNMPTRAP Stopped Manual Own Process c:\windows\system32\snmptrap.exe Normal NT AUTHORITY\LocalService 0
Print Spooler Spooler Running Auto Own Process c:\windows\system32\spoolsv.exe Normal LocalSystem 0
Software Protection sppsvc Stopped Auto Own Process c:\windows\system32\sppsvc.exe Normal NT AUTHORITY\NetworkService 0
SPP Notification Service sppuinotify Stopped Manual Share Process c:\windows\system32\svchost.exe -k localservice Normal NT AUTHORITY\LocalService 0
SSDP Discovery SSDPSRV Running Manual Share Process c:\windows\system32\svchost.exe -k localserviceandnoimpersonation Normal NT AUTHORITY\LocalService 0
Secure Socket Tunneling Protocol Service SstpSvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k localservice Normal NT Authority\LocalService 0
Steam Client Service Steam Client Service Stopped Disabled Own Process c:\program files (x86)\common files\steam\steamservice.exe /runasservice Normal LocalSystem 0
Windows Image Acquisition (WIA) stisvc Stopped Manual Own Process c:\windows\system32\svchost.exe -k imgsvc Normal NT Authority\LocalService 0
Microsoft Software Shadow Copy Provider swprv Stopped Manual Own Process c:\windows\system32\svchost.exe -k swprv Normal LocalSystem 0
Superfetch SysMain Running Auto Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Ignore LocalSystem 0
Tablet PC Input Service TabletInputService Stopped Manual Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
Telephony TapiSrv Stopped Manual Share Process c:\windows\system32\svchost.exe -k networkservice Normal NT AUTHORITY\NetworkService 0
TPM Base Services TBS Stopped Manual Share Process c:\windows\system32\svchost.exe -k localserviceandnoimpersonation Normal NT AUTHORITY\LocalService 0
Remote Desktop Services TermService Running Manual Share Process c:\windows\system32\svchost.exe -k networkservice Normal NT Authority\NetworkService 0
Themes Themes Running Auto Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Thread Ordering Server THREADORDER Stopped Manual Share Process c:\windows\system32\svchost.exe -k localservice Normal NT AUTHORITY\LocalService 0
Distributed Link Tracking Client TrkWks Running Auto Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
Windows Modules Installer TrustedInstaller Running Manual Own Process c:\windows\servicing\trustedinstaller.exe Normal localSystem 0
Interactive Services Detection UI0Detect Stopped Manual Own Process c:\windows\system32\ui0detect.exe Normal LocalSystem 0
Remote Desktop Services UserMode Port Redirector UmRdpService Running Manual Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal localSystem 0
UPnP Device Host upnphost Stopped Manual Share Process c:\windows\system32\svchost.exe -k localserviceandnoimpersonation Normal NT AUTHORITY\LocalService 0
Desktop Window Manager Session Manager UxSms Stopped Manual Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal localSystem 0
Credential Manager VaultSvc Stopped Manual Share Process c:\windows\system32\lsass.exe Normal LocalSystem 0
Virtual Disk vds Stopped Manual Own Process c:\windows\system32\vds.exe Normal LocalSystem 0
Volume Shadow Copy VSS Stopped Manual Own Process c:\windows\system32\vssvc.exe Normal LocalSystem 0
Windows Time W32Time Stopped Manual Share Process c:\windows\system32\svchost.exe -k localservice Normal NT AUTHORITY\LocalService 0
Windows Activation Technologies Service WatAdminSvc Stopped Manual Own Process c:\windows\system32\wat\watadminsvc.exe Normal LocalSystem 0
Block Level Backup Engine Service wbengine Stopped Manual Own Process "c:\windows\system32\wbengine.exe" Normal localSystem 0
Windows Biometric Service WbioSrvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k wbiosvcgroup Normal LocalSystem 0
Windows Connect Now - Config Registrar wcncsvc Running Manual Share Process c:\windows\system32\svchost.exe -k localserviceandnoimpersonation Normal NT AUTHORITY\LocalService 0
Windows Color System WcsPlugInService Stopped Manual Share Process c:\windows\system32\svchost.exe -k wcssvc Normal NT AUTHORITY\LocalService 0
Diagnostic Service Host WdiServiceHost Running Manual Share Process c:\windows\system32\svchost.exe -k localservice Normal NT AUTHORITY\LocalService 0
Diagnostic System Host WdiSystemHost Running Manual Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
WebClient WebClient Stopped Manual Share Process c:\windows\system32\svchost.exe -k localservice Normal NT AUTHORITY\LocalService 0
Windows Event Collector Wecsvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k networkservice Normal NT AUTHORITY\NetworkService 0
Problem Reports and Solutions Control Panel Support wercplsupport Stopped Manual Share Process c:\windows\system32\svchost.exe -k netsvcs Normal localSystem 0
Windows Error Reporting Service WerSvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k wersvcgroup Ignore localSystem 0
Windows Defender WinDefend Stopped Manual Share Process c:\windows\system32\svchost.exe -k secsvcs Normal LocalSystem 0
WinHTTP Web Proxy Auto-Discovery Service WinHttpAutoProxySvc Running Manual Share Process c:\windows\system32\svchost.exe -k localservice Normal NT AUTHORITY\LocalService 0
Windows Management Instrumentation Winmgmt Running Auto Share Process c:\windows\system32\svchost.exe -k netsvcs Ignore localSystem 0
Windows Remote Management (WS-Management) WinRM Stopped Manual Share Process c:\windows\system32\svchost.exe -k networkservice Normal NT AUTHORITY\NetworkService 0
WLAN AutoConfig Wlansvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
Windows Live ID Sign-in Assistant wlidsvc Running Auto Own Process "c:\program files\common files\microsoft shared\windows live\wlidsvc.exe" Normal LocalSystem 0
WMI Performance Adapter wmiApSrv Stopped Manual Own Process c:\windows\system32\wbem\wmiapsrv.exe Normal localSystem 0
Windows Media Player Network Sharing Service WMPNetworkSvc Stopped Disabled Own Process "c:\program files\windows media player\wmpnetwk.exe" Normal NT AUTHORITY\NetworkService 0
Parental Controls WPCSvc Stopped Disabled Share Process c:\windows\system32\svchost.exe -k localservicenetworkrestricted Normal NT Authority\LocalService 0
Portable Device Enumerator Service WPDBusEnum Running Manual Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
Security Center wscsvc Running Auto Share Process c:\windows\system32\svchost.exe -k localservicenetworkrestricted Normal NT AUTHORITY\LocalService 0
Windows Search WSearch Running Manual Own Process c:\windows\system32\searchindexer.exe /embedding Normal LocalSystem 0
Windows Update wuauserv Running Auto Share Process c:\windows\system32\svchost.exe -k netsvcs Normal LocalSystem 0
Windows Driver Foundation - User-mode Driver Framework wudfsvc Running Manual Share Process c:\windows\system32\svchost.exe -k localsystemnetworkrestricted Normal LocalSystem 0
WWAN AutoConfig WwanSvc Stopped Manual Share Process c:\windows\system32\svchost.exe -k localservicenonetwork Normal NT Authority\LocalService 0
 
[Program Groups]
 
Group Name Name User Name
Start Menu Default:Start Menu Default
Start Menu\Programs Default:Start Menu\Programs Default
Start Menu\Programs\Accessories Default:Start Menu\Programs\Accessories Default
Start Menu\Programs\Accessories\Accessibility Default:Start Menu\Programs\Accessories\Accessibility Default
Start Menu\Programs\Accessories\System Tools Default:Start Menu\Programs\Accessories\System Tools Default
Start Menu\Programs\Maintenance Default:Start Menu\Programs\Maintenance Default
Start Menu Public:Start Menu Public
Start Menu\Programs Public:Start Menu\Programs Public
Start Menu\Programs\Accessories Public:Start Menu\Programs\Accessories Public
Start Menu\Programs\Accessories\Accessibility Public:Start Menu\Programs\Accessories\Accessibility Public
Start Menu\Programs\Accessories\System Tools Public:Start Menu\Programs\Accessories\System Tools Public
Start Menu\Programs\Accessories\Tablet PC Public:Start Menu\Programs\Accessories\Tablet PC Public
Start Menu\Programs\Accessories\Windows PowerShell Public:Start Menu\Programs\Accessories\Windows PowerShell Public
Start Menu\Programs\Administrative Tools Public:Start Menu\Programs\Administrative Tools Public
Start Menu\Programs\AMD VISION Engine Control Center Public:Start Menu\Programs\AMD VISION Engine Control Center Public
Start Menu\Programs\AudibleManager Public:Start Menu\Programs\AudibleManager Public
Start Menu\Programs\Canon MX300 series Manual Public:Start Menu\Programs\Canon MX300 series Manual Public
Start Menu\Programs\CCleaner Public:Start Menu\Programs\CCleaner Public
Start Menu\Programs\Crayon Physics Deluxe Public:Start Menu\Programs\Crayon Physics Deluxe Public
Start Menu\Programs\CutePDF Public:Start Menu\Programs\CutePDF Public
Start Menu\Programs\CutePDF\PDF Writer Public:Start Menu\Programs\CutePDF\PDF Writer Public
Start Menu\Programs\FamilySearch Public:Start Menu\Programs\FamilySearch Public
Start Menu\Programs\Foxit Reader Public:Start Menu\Programs\Foxit Reader Public
Start Menu\Programs\GameHouse Public:Start Menu\Programs\GameHouse Public
Start Menu\Programs\Games Public:Start Menu\Programs\Games Public
Start Menu\Programs\Google Chrome Public:Start Menu\Programs\Google Chrome Public
Start Menu\Programs\Google Drive Public:Start Menu\Programs\Google Drive Public
Start Menu\Programs\Home Sweet Home Public:Start Menu\Programs\Home Sweet Home Public
Start Menu\Programs\Home Sweet Home - Christmas Edition Public:Start Menu\Programs\Home Sweet Home - Christmas Edition Public
Start Menu\Programs\Home Sweet Home 2 - Kitchens and Baths Public:Start Menu\Programs\Home Sweet Home 2 - Kitchens and Baths Public
Start Menu\Programs\iTunes Public:Start Menu\Programs\iTunes Public
Start Menu\Programs\Java Public:Start Menu\Programs\Java Public
Start Menu\Programs\Maintenance Public:Start Menu\Programs\Maintenance Public
Start Menu\Programs\Malwarebytes Anti-Malware Public:Start Menu\Programs\Malwarebytes Anti-Malware Public
Start Menu\Programs\Malwarebytes Anti-Malware\Tools Public:Start Menu\Programs\Malwarebytes Anti-Malware\Tools Public
Start Menu\Programs\Microsoft Digital Image Standard 2006 Public:Start Menu\Programs\Microsoft Digital Image Standard 2006 Public
Start Menu\Programs\Microsoft Office Public:Start Menu\Programs\Microsoft Office Public
Start Menu\Programs\Microsoft Office\Microsoft Office 2010 Tools Public:Start Menu\Programs\Microsoft Office\Microsoft Office 2010 Tools Public
Start Menu\Programs\Microsoft Office Tools Public:Start Menu\Programs\Microsoft Office Tools Public
Start Menu\Programs\Microsoft Silverlight Public:Start Menu\Programs\Microsoft Silverlight Public
Start Menu\Programs\Microsoft Works Public:Start Menu\Programs\Microsoft Works Public
Start Menu\Programs\MP3 To WAV Decoder Public:Start Menu\Programs\MP3 To WAV Decoder Public
Start Menu\Programs\PDF-XChange 3 Public:Start Menu\Programs\PDF-XChange 3 Public
Start Menu\Programs\SharePoint Public:Start Menu\Programs\SharePoint Public
Start Menu\Programs\Startup Public:Start Menu\Programs\Startup Public
Start Menu\Programs\Tablet PC Public:Start Menu\Programs\Tablet PC Public
Start Menu\Programs\Windows Media Public:Start Menu\Programs\Windows Media Public
Start Menu\Programs\Windows Media\Utilities Public:Start Menu\Programs\Windows Media\Utilities Public
Start Menu\Programs\WinRAR Public:Start Menu\Programs\WinRAR Public
Start Menu Mom-PC\Mom:Start Menu Mom-PC\Mom
Start Menu\Programs Mom-PC\Mom:Start Menu\Programs Mom-PC\Mom
Start Menu\Programs\Accessories Mom-PC\Mom:Start Menu\Programs\Accessories Mom-PC\Mom
Start Menu\Programs\Accessories\Accessibility Mom-PC\Mom:Start Menu\Programs\Accessories\Accessibility Mom-PC\Mom
Start Menu\Programs\Accessories\System Tools Mom-PC\Mom:Start Menu\Programs\Accessories\System Tools Mom-PC\Mom
Start Menu\Programs\Administrative Tools Mom-PC\Mom:Start Menu\Programs\Administrative Tools Mom-PC\Mom
Start Menu\Programs\Android_Activator Mom-PC\Mom:Start Menu\Programs\Android_Activator Mom-PC\Mom
Start Menu\Programs\Dropbox Mom-PC\Mom:Start Menu\Programs\Dropbox Mom-PC\Mom
Start Menu\Programs\Games Mom-PC\Mom:Start Menu\Programs\Games Mom-PC\Mom
Start Menu\Programs\Google Chrome Mom-PC\Mom:Start Menu\Programs\Google Chrome Mom-PC\Mom
Start Menu\Programs\Maintenance Mom-PC\Mom:Start Menu\Programs\Maintenance Mom-PC\Mom
Start Menu\Programs\Music Manager Mom-PC\Mom:Start Menu\Programs\Music Manager Mom-PC\Mom
Start Menu\Programs\MyHeritage.com Mom-PC\Mom:Start Menu\Programs\MyHeritage.com Mom-PC\Mom
Start Menu\Programs\Revo Uninstaller Mom-PC\Mom:Start Menu\Programs\Revo Uninstaller Mom-PC\Mom
Start Menu\Programs\Startup Mom-PC\Mom:Start Menu\Programs\Startup Mom-PC\Mom
Start Menu\Programs\Steam Mom-PC\Mom:Start Menu\Programs\Steam Mom-PC\Mom
Start Menu\Programs\UserTesting_Activator Mom-PC\Mom:Start Menu\Programs\UserTesting_Activator Mom-PC\Mom
Start Menu\Programs\WinRAR Mom-PC\Mom:Start Menu\Programs\WinRAR Mom-PC\Mom
 
[Startup Programs]
 
Program Command User Name Location
 
[OLE Registration]
 
Object Local Server
WordPad Document "%programfiles%\windows nt\accessories\wordpad.exe"
Paintbrush Picture %systemroot%\system32\mspaint.exe
Drawing Not Available
Package Not Available
Microsoft PenInputPanel Control Not Available
 
[Windows Error Reporting]
 
Time Type Details


  • 0

#14
DanoNH

DanoNH

    Trusted Helper

  • Malware Removal
  • 2,155 posts

Hello Lisa,
 
Ok, your video card is an ATI Radeon HD 4800 Series, and you have Driver Version 8.970.100.7000 installed.  The lastest official AMD Display Driver on their web site is ver. 8.97.100.11.  This would tell me you have a newer driver, but from where I wonder.  Maybe the Lenovo driver I found in my searching, but I am concerned the driver you have installed may be a driver for Windows XP and not fully Vista compatible.
 
I therefore would recommend that you update your video driver to the latest "official" AMD released one for Windows Vista 32-bit.  The link to the latest AMD official driver is here for your reference only.
 
If you or your son decide to do this, the most important thing is to make sure you fully uninstall your existing AMD Catalyst and Drivers software and REBOOT before installing a different version.

At any rate, I wouldn't worry about updating the video drivers in our session here.  I'm thinking that it may be part of the reason why you see the "display driver has stopped responding" message.  If you need help with installing video drivers I would gladly refer you to our Hardware, Components and Peripherals forum. ;)
 
I would suggest a thorough cleaning of the inside of your tower, as well as maybe some new thermal paste on your processor heat sink.  Maybe your son can help with that part. :cool:
 
AND, to answer your question about the FixIt at my last link, I would HOLD OFF on doing that until you try the Official AMD drivers and see if the problem is resolved. ;)
 
Continuing on...
 
I'd like you to reset your Chrome browser to see if that helps with it's performance, and we should do one more scan to get a second opinion here.
 
First
Reset Google Chrome
Information on exporting your bookmarks for later importing can be found here.

  • Open Chrome
  • Goto the Menu icon ChromeMenu_zpsr7fyk3vo.png
  • Select Settings
  • Scroll down the page and look for + Show advanced settings
  • Scroll down to the end of the page and click the Reset browser settings button
  • Click Reset once more
  • Restart Chrome

Second
Please run a free online scan with the ESET Online Scanner:

IMPORTANT: You MUST use Internet Explorer and also disable your Anti-Virus scanner for this step!

  • Visit the ESET Online Scanner Web Page
     
  • Select the blue Run ESET Online Scanner button:
    ESET1_zps23a5e840.png
     
  • Tick the box next to YES, I accept the Terms of Use and click Start
    ESET_EULA2_zps9451f1c3.png
     
  • When asked, allow the ActiveX control to install.
     
  • Select Enable detection of potentially unwanted applications and select Advanced Settings:
    ESET2_zpsc701c045.png
     
  • Make sure to check the options Remove found threats and Enable Anti-Stealth technology are checked:
    ESET4_zps0afafd0d.png
     
  • Click Start.  (This scan can take several hours, so please be patient):
    ESET3_zpsccd1657d.png
     
  • Allow the program to update:
    ESETupdate_zps36feabec.png
     
  • Once the scan is completed, select List of found threats:
    ESET5_zpsd27be299.png
     
  • Select Export to text file... and save the file as ESETlog.txt on your Desktop:
    ESET6_zpsc17d154e.png
     
  • Click the Back button.
     
  • Click the Finish button:
    ESET9_zps51587217.png
     
  • Use Notepad to open the saved log file (on your Desktop- ESET.txt)
     
  • Copy and paste that log as a reply to this topic.

  • 0

#15
kid@hrt

kid@hrt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 55 posts

Hi

 

I'm not going to worry about the display driver just yet. Thanks for the info.

 

I tried to reset Chrome but nothing really happened. I still have all my bookmarks, history was not cleared and my password for this site was till saved. 

The computer seems to be ok, 

 

ESET.txt

 

 

C:\Documents and Settings\Mom\AppData\Local\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setu...app_2628e500709a5a3f_0000.0000_98efa27be2418ac1\7b2.exe a variant of Win32/Toolbar.CrossRider.BX potentially unwanted application
C:\Documents and Settings\Mom\AppData\Local\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setu...app_2628e500709a5a3f_0000.0000_98efa27be2418ac1\SetupWizard.exe a variant of Win32/SoftPulse.X potentially unwanted application
C:\Documents and Settings\Mom\AppData\Local\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setup.exe_2628e500709a5a3f_0000.0000_none_2ec04aa37f001876\SetupWizard.exe a variant of Win32/SoftPulse.X potentially unwanted application
C:\Documents and Settings\Mom\Local Settings\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setu...app_2628e500709a5a3f_0000.0000_98efa27be2418ac1\7b2.exe a variant of Win32/Toolbar.CrossRider.BX potentially unwanted application
C:\Documents and Settings\Mom\Local Settings\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setu...app_2628e500709a5a3f_0000.0000_98efa27be2418ac1\SetupWizard.exe a variant of Win32/SoftPulse.X potentially unwanted application
C:\Documents and Settings\Mom\Local Settings\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setup.exe_2628e500709a5a3f_0000.0000_none_2ec04aa37f001876\SetupWizard.exe a variant of Win32/SoftPulse.X potentially unwanted application
C:\Users\Mom\AppData\Local\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setu...app_2628e500709a5a3f_0000.0000_98efa27be2418ac1\7b2.exe a variant of Win32/Toolbar.CrossRider.BX potentially unwanted application
C:\Users\Mom\AppData\Local\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setu...app_2628e500709a5a3f_0000.0000_98efa27be2418ac1\SetupWizard.exe a variant of Win32/SoftPulse.X potentially unwanted application
C:\Users\Mom\AppData\Local\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setup.exe_2628e500709a5a3f_0000.0000_none_2ec04aa37f001876\SetupWizard.exe a variant of Win32/SoftPulse.X potentially unwanted application
C:\Users\Mom\Local Settings\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setu...app_2628e500709a5a3f_0000.0000_98efa27be2418ac1\7b2.exe a variant of Win32/Toolbar.CrossRider.BX potentially unwanted application
C:\Users\Mom\Local Settings\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setu...app_2628e500709a5a3f_0000.0000_98efa27be2418ac1\SetupWizard.exe a variant of Win32/SoftPulse.X potentially unwanted application
C:\Users\Mom\Local Settings\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setup.exe_2628e500709a5a3f_0000.0000_none_2ec04aa37f001876\SetupWizard.exe a variant of Win32/SoftPulse.X potentially unwanted application
C:\Documents and Settings\Mom\AppData\Local\Application Data\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setu...app_2628e500709a5a3f_0000.0000_98efa27be2418ac1\7b2.exe a variant of Win32/Toolbar.CrossRider.BX potentially unwanted application deleted - quarantined
C:\Documents and Settings\Mom\AppData\Local\Application Data\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setu...app_2628e500709a5a3f_0000.0000_98efa27be2418ac1\SetupWizard.exe a variant of Win32/SoftPulse.X potentially unwanted application deleted - quarantined
C:\Documents and Settings\Mom\AppData\Local\Application Data\Apps\2.0\A4OJKQJH.00R\39WRQJYQ.A37\setup.exe_2628e500709a5a3f_0000.0000_none_2ec04aa37f001876\SetupWizard.exe a variant of Win32/SoftPulse.X potentially unwanted application deleted - quarantined
C:\FRST\Quarantine\C\ProgramData\NVSMpxS\dat\WjNhpTx.dll a variant of MSIL/Adware.PullUpdate.K.gen application cleaned by deleting - quarantined
C:\FRST\Quarantine\C\Users\Mom\Desktop\Tsusbhub.sys_Error_Repair_Tool-WinThruster.exe.xBAD Win32/Systweak potentially unwanted application deleted - quarantined
C:\Program Files (x86)\Free mp3 Wma Converter\Helper.dll a variant of Win32/Toolbar.SearchSuite.W potentially unwanted application deleted - quarantined
 

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP