Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

System is getting slow


  • Please log in to reply

#1
debodun

debodun

    Member

  • Member
  • PipPipPip
  • 567 posts

My OS is Windows 7 - 64 bit with SP1, a 1.86 GHz Intel Core 2 Duo CPU and a 3 GB  Dual Channel DDR2@332MHz.

 

Problems - slow booting, slow shut-down, type lagging, Firefox browser slow on sites using Flash Player. I have run system scans with MBAM and MSE- they show nothing. Other than that, I am not very computer savvy. Just wanted to check and make sure everything was okat. Herear emy FRST scan results:

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10.10.2018
Ran by Owner (administrator) on OWNER-PC (16-10-2018 13:32:24)
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{E05E619F-5932-445D-9D21-1FC2630E6BEE}: [DhcpNameServer] 209.18.47.61 209.18.47.62

Internet Explorer:
==================
HKU\S-1-5-21-3384263181-369055421-3260215636-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab

FireFox:
========
FF DefaultProfile: 8wi3sbs5.default-1412761564967
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\8wi3sbs5.default-1412761564967 [2018-10-16]
FF Homepage: Mozilla\Firefox\Profiles\8wi3sbs5.default-1412761564967 -> hxxps://www.google.com/ncr
FF Extension: (Telemetry coverage) - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\8wi3sbs5.default-1412761564967\features\{ca98edf8-4172-45d5-83a6-de33cb4054a7}\[email protected] [2018-10-09] [Legacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_122.dll [2018-10-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_122.dll [2018-10-09] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll [2012-10-04] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-03-06] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-08-12] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2013-04-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-09-20] (Adobe Systems Inc.)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
S0 PxHlpa64; C:\Windows\SysWOW64\Drivers\PxHlpa64.sys [26720 2004-09-23] (Sonic Solutions) [File not signed]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-10-16 13:32 - 2018-10-16 13:34 - 000005905 _____ C:\Users\Owner\Desktop\FRST.txt
2018-10-16 13:31 - 2018-10-16 13:31 - 002414592 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
2018-10-09 13:30 - 2018-10-12 13:20 - 000013163 _____ C:\Users\Owner\Documents\funny names.odt
2018-10-01 17:30 - 2018-10-01 17:30 - 000133191 _____ C:\Users\Owner\Documents\jimmie rodgers2b.odt
2018-10-01 17:30 - 2018-10-01 17:30 - 000114154 _____ C:\Users\Owner\Documents\jimmie rodgers2b.pdf
2018-10-01 17:25 - 2018-10-01 17:26 - 000037750 _____ C:\Users\Owner\Documents\jimmie rodgers2.pdf
2018-10-01 17:25 - 2018-10-01 17:25 - 000215791 _____ C:\Users\Owner\Documents\jimmie rodgers2.odt
2018-09-30 18:26 - 2018-09-30 18:26 - 000097548 _____ C:\Users\Owner\Documents\computer startup.odt
2018-09-23 16:30 - 2018-09-23 16:30 - 000011433 _____ C:\Users\Owner\Documents\Columbus weekend sale.odt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-10-16 13:32 - 2015-05-23 12:52 - 000000000 ____D C:\FRST
2018-10-16 13:25 - 2012-01-12 12:24 - 000000000 ___RD C:\Users\Owner\Desktop\misc house contents
2018-10-16 12:54 - 2016-11-16 13:13 - 000000000 ____D C:\Users\Owner\AppData\LocalLow\Mozilla
2018-10-16 10:17 - 2009-07-14 00:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-10-16 10:17 - 2009-07-14 00:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-10-16 10:13 - 2009-07-14 01:13 - 000782510 _____ C:\Windows\system32\PerfStringBackup.INI
2018-10-16 10:13 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf
2018-10-16 10:08 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-10-15 16:54 - 2012-07-22 09:28 - 000000000 ____D C:\ProgramData\TEMP
2018-10-15 16:54 - 2012-07-22 09:28 - 000000000 ____D C:\Program Files (x86)\SpywareBlaster
2018-10-14 18:06 - 2018-02-11 14:15 - 000017478 _____ C:\Users\Owner\Documents\Celebrity Deaths 2018.odt
2018-10-14 16:18 - 2014-01-13 19:27 - 000018407 _____ C:\Users\Owner\Documents\Home Delivered Meals.ods
2018-10-14 16:05 - 2017-06-29 11:22 - 000021969 _____ C:\Users\Owner\Documents\riddles.odt
2018-10-14 13:43 - 2016-09-28 10:41 - 000011789 _____ C:\Users\Owner\Documents\Christmas sale.odt
2018-10-13 15:15 - 2012-01-12 12:23 - 000000000 ____D C:\Users\Owner\Desktop\Things For Sale
2018-10-10 15:48 - 2015-11-01 16:14 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-10-09 13:58 - 2018-03-13 14:58 - 000004462 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-10-09 13:58 - 2013-02-09 11:03 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-10-09 13:58 - 2012-03-31 07:33 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-10-09 13:58 - 2011-12-17 16:43 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-10-09 13:58 - 2011-12-17 16:43 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-10-09 13:58 - 2011-12-17 16:43 - 000000000 ____D C:\Windows\system32\Macromed
2018-10-06 10:32 - 2017-11-04 09:22 - 000011018 _____ C:\Users\Owner\Documents\Weight 2018.ods
2018-10-03 15:15 - 2012-01-12 12:21 - 000000000 ____D C:\Users\Owner\Desktop\silver, jewelry, coins, other metalware
2018-10-02 15:13 - 2014-11-07 08:53 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-10-02 14:32 - 2012-01-12 12:24 - 000007680 _____ C:\Users\Owner\Documents\4 grid.xls
2018-10-01 17:23 - 2012-09-21 14:05 - 000000000 ____D C:\Users\Owner\Desktop\Margaret & Richard
2018-10-01 15:01 - 2017-12-01 12:05 - 000018076 _____ C:\Users\Owner\Documents\Net Worth 2018.ods
2018-09-27 15:15 - 2012-01-12 12:24 - 000041984 _____ C:\Users\Owner\Documents\Depression_Glass.xls
2018-09-26 15:34 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\rescache
2018-09-20 11:00 - 2014-12-23 13:32 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-09-19 15:35 - 2012-01-12 12:24 - 000077312 _____ C:\Users\Owner\Documents\Playing Cards.xls

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-09-26 15:26

==================== End of FRST.txt ============================

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10.10.2018
Ran by Owner (16-10-2018 13:35:21)
Running from C:\Users\Owner\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2011-12-17 19:41:25)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3384263181-369055421-3260215636-500 - Administrator - Disabled)
Guest (S-1-5-21-3384263181-369055421-3260215636-501 - Limited - Disabled)
Owner (S-1-5-21-3384263181-369055421-3260215636-1000 - Administrator - Enabled) => C:\Users\Owner

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.008.20074 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 31 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 31.0.0.122 - Adobe Systems Incorporated)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.122 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.8.638 - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\...\{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}) (Version: 2.1.7 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}) (Version: 5.1.1.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CardRd81 (HKLM-x32\...\{54C8FE84-89C4-40E8-976C-439EB0729BD6}) (Version: 4.00.0000.0004 - EASTMAN KODAK Company) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.23 - Piriform)
CCScore (HKLM-x32\...\{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}) (Version: 5.00.0000.0011 - EASTMAN KODAK Company) Hidden
CR2 (HKLM-x32\...\{432C3720-37BF-4BD7-8E49-F38E090246D0}) (Version: 4.00.0000.0003 - EASTMAN KODAK Company) Hidden
EKS Dinner With Moriarty (HKLM-x32\...\EKS Dinner With Moriarty) (Version:  - )
EKS Sherlock (HKLM-x32\...\EKS Sherlock) (Version:  - )
ESSBrwr (HKLM-x32\...\{643EAE81-920C-4931-9F0B-4B343B225CA6}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
ESSCDBK (HKLM-x32\...\{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
ESScore (HKLM-x32\...\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}) (Version: 5.00.0000.0037 - EASTMAN KODAK Company) Hidden
ESSCT (HKLM-x32\...\{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}) (Version: 5.00.0000.0003 - EASTMAN KODAK Company) Hidden
ESSgui (HKLM-x32\...\{91517631-A9F3-4B7C-B482-43E0068FD55A}) (Version: 5.00.0000.0013 - EASTMAN KODAK Company) Hidden
ESShelp (HKLM-x32\...\{87843A41-7808-4F2E-B13F-25C1E67CF2FD}) (Version: 5.00.0000.0005 - EASTMAN KODAK Company) Hidden
ESSini (HKLM-x32\...\{8E92D746-CD9F-4B90-9668-42B74C14F765}) (Version: 5.00.0000.0010 - EASTMAN KODAK Company) Hidden
ESSPCD (HKLM-x32\...\{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}) (Version: 5.00.0000.0007 - EASTMAN KODAK Company) Hidden
ESSPDock (HKLM-x32\...\{FCDB1C92-03C6-4C76-8625-371224256091}) (Version: 5.00.0000.0020 - EASTMAN KODAK Company) Hidden
ESSSONIC (HKLM-x32\...\{4F677FC7-7AA8-412B-A957-F13CBE1C7331}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
ESSTOOLS (HKLM-x32\...\{8A502E38-29C9-49FA-BCFA-D727CA062589}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
ESSTUTOR (HKLM-x32\...\{CA60320D-6A16-49C8-A34F-84EEF4799567}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
ESSvpaht (HKLM-x32\...\{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESSvpot (HKLM-x32\...\{48C82F7A-F100-4DAB-A310-8E18BF2159E1}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
Free MIDI to MP3 Converter 1.0 (HKLM-x32\...\{181E1175-1FF8-4EA5-BC08-A7CA39B85502}_is1) (Version:  - PolySoft Solutions)
HLPIndex (HKLM-x32\...\{38441BE7-79B0-42B8-8297-833704F949FE}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
HLPPDOCK (HKLM-x32\...\{154508C0-07C5-4659-A7A0-E49968750D21}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
HLPRFO (HKLM-x32\...\{AADAC983-FDE9-42FA-8FD9-7BB324155593}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.6.0 - LIGHTNING UK!)
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
iTunes (HKLM\...\{4BDE7544-0A08-4AD9-8A8F-4B7944471C36}) (Version: 10.6.0.40 - Apple Inc.)
Kodak EasyShare software (HKLM-x32\...\{D32470A1-B10C-4059-BA53-CF0486F68EBC}) (Version:  - Eastman Kodak Company)
KSU (HKLM-x32\...\{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}) (Version: 632.62.0002.0001 - EASTMAN KODAK Company) Hidden
Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 62.0.3 (x64 en-US) (HKLM\...\Mozilla Firefox 62.0.3 (x64 en-US)) (Version: 62.0.3 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Notifier (HKLM-x32\...\{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
OTtBP (HKLM-x32\...\{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}) (Version: 5.00.0000.0003 - EASTMAN KODAK Company) Hidden
OTtBPSDK (HKLM-x32\...\{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}) (Version: 4.00.0000.0000 - EASTMAN KODAK Company) Hidden
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
QuickTime (HKLM-x32\...\QuickTime) (Version:  - )
SFR (HKLM-x32\...\{DB02F716-6275-42E9-B8D2-83BA2BF5100B}) (Version: 5.00.0000.0005 - Eastman Kodak Company) Hidden
SHASTA (HKLM-x32\...\{605A4E39-613C-4A12-B56F-DEFBE6757237}) (Version: 5.00.0000.0003 - EASTMAN KODAK Company) Hidden
SKIN0001 (HKLM-x32\...\{FDF9943A-3D5C-46B3-9679-586BD237DDEE}) (Version: 5.00.0000.0007 - EASTMAN KODAK Company) Hidden
SKINXSDK (HKLM-x32\...\{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
Skype™ 5.5 (HKLM-x32\...\{F1CECE09-7CBE-4E98-B435-DA87CDA86167}) (Version: 5.5.124 - Skype Technologies S.A.)
Speccy (HKLM\...\Speccy) (Version: 1.14 - Piriform)
SpywareBlaster 5.5 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.12541 - TeamViewer)
VLC media player 1.1.11 (HKLM-x32\...\VLC media player) (Version: 1.1.11 - VideoLAN)
VPRINTOL (HKLM-x32\...\{999D43F4-9709-4887-9B1A-83EBB15A8370}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
WIRELESS (HKLM-x32\...\{F9593CFB-D836-49BC-BFF1-0E669A411D9F}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll [2013-04-04] (Malwarebytes Corporation)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2009-09-23] (Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll [2013-04-04] (Malwarebytes Corporation)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0976F330-BF25-4F6F-B0B1-665D9BF7BCC0} - System32\Tasks\{68760510-2907-489D-B7A2-C35A3446BE71} => C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-07-22] ()
Task: {0A0C5E8A-2FCE-4C99-B12F-00B4B70AFB83} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {41E2110D-1421-413B-8E62-70C64466298F} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_122_Plugin.exe [2018-10-09] (Adobe Systems Incorporated)
Task: {52D1B772-A164-4976-9597-5BECD9597361} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3384263181-369055421-3260215636-1000
Task: {5D084169-00AD-4D36-A448-C9A76FB459A9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-10-09] (Adobe Systems Incorporated)
Task: {6B4D3DDA-9B0C-4B4E-A917-B9A141F6ED35} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-09-24] (Piriform Ltd)
Task: {80B7199B-A54D-4E09-84AF-C895D435EF81} - System32\Tasks\{DB28AAC4-58A4-471C-A8CC-0A8B9CBFF8E6} => C:\Users\Owner\Desktop\DD\Games\ASTRO\ASTRO.EXE [1983-11-11] ()
Task: {8A7A4359-A2B1-44AC-879C-D14DD8B5F309} - System32\Tasks\{FB2047DD-47C4-41E8-988F-991725D1BB0D} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {A149C588-D529-48EB-BAE0-95CA7AC5FE1C} - System32\Tasks\{304152A7-70D0-4E91-9F4E-DBD1652C7AAC} => C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-07-22] ()
Task: {A35AB765-EDB9-4C55-9D3E-5E8DBE8B651E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-14] (Adobe Systems Incorporated)
Task: {D8060F20-2AF7-4010-8722-E73039BEA018} - System32\Tasks\{7771A4AC-76DB-4824-A025-706FC8FBFA13} => C:\Users\Owner\Desktop\DD\Games\ASTRO\ASTRO.EXE [1983-11-11] ()
Task: {E1138DDE-FC63-4D5A-A0C5-C13AD4F5AEE0} - System32\Tasks\{11C6843C-087E-401F-A969-AB4FE5F21D3B} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {EB1BC358-EB13-4BA5-93F8-1390C2F2B874} - System32\Tasks\{3831C2E7-DCFA-4E96-9F06-C7CC94D6C4C4} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {FC313E55-25B0-4845-87C6-66F271AE8EC7} - System32\Tasks\{BD4C9F3C-DAAC-4CFE-8FC8-BE1EA0D54E71} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2011-11-02 00:26 - 2011-11-02 00:26 - 000087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-11-02 00:26 - 2011-11-02 00:26 - 001242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\1001movie.com -> 1001movie.com

There are 6091 more sites.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 22:34 - 2014-07-05 11:08 - 000000098 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3384263181-369055421-3260215636-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 209.18.47.61 - 209.18.47.62
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{0E227B60-E7FB-4017-9EC7-A62A5EFA8967}] => (Allow) C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe
FirewallRules: [{C86A2602-2440-441D-972C-BEC7E06FC3E4}] => (Allow) C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe
FirewallRules: [{217F7D9C-49CD-4ED9-9050-3C2E4E9D8CC2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{3994F65F-7D58-4F72-86D1-2E5CD9A2AD1F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{D2F24F04-D188-44AF-8CAB-1440B2782E38}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{1A10243C-DC57-4AFE-AD3D-54A683104F27}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{D920EAFE-1F31-4BB5-BC15-E747556F30C0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D0FFCD08-CDC4-41E1-B87C-BCCEA99F34B6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Restore Points =========================

25-10-2017 15:52:28 Windows Update
29-10-2017 10:24:28 Windows Update
12-11-2017 17:09:38 Windows Update
14-11-2017 15:14:38 Windows Update
19-11-2017 14:39:30 Windows Update
29-11-2017 16:50:04 Windows Update
01-12-2017 15:23:05 Windows Update
12-12-2017 15:53:25 Windows Update
05-01-2018 11:32:58 Windows Update
09-01-2018 15:19:09 Windows Update
19-01-2018 13:53:13 Windows Update
22-01-2018 14:01:03 Windows Update
26-01-2018 15:34:58 Windows Update
13-02-2018 14:49:09 Windows Update
05-03-2018 14:08:47 Windows Update
13-03-2018 13:20:54 Windows Update
30-03-2018 14:10:28 Windows Update
10-04-2018 13:22:19 Windows Update
19-04-2018 13:29:46 Windows Update
05-05-2018 16:40:18 Windows Update
08-05-2018 13:51:18 Windows Update
12-06-2018 13:28:59 Windows Update
06-07-2018 14:15:59 Windows Update
10-07-2018 13:30:24 Windows Update
14-08-2018 13:35:43 Windows Update
07-09-2018 14:46:51 Scheduled Checkpoint
11-09-2018 13:31:49 Windows Update
26-09-2018 15:33:47 Scheduled Checkpoint

==================== Faulty Device Manager Devices =============

Name: PS/2 Compatible Mouse
Description: PS/2 Compatible Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/16/2018 10:10:09 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (10/15/2018 12:19:28 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (10/14/2018 12:10:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (10/13/2018 10:47:56 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (10/12/2018 12:29:41 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (10/11/2018 11:09:16 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (10/10/2018 03:38:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (10/09/2018 09:43:02 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.


System errors:
=============
Error: (10/16/2018 10:09:12 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
PxHlpa64

Error: (10/15/2018 12:18:14 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
PxHlpa64

Error: (10/14/2018 12:09:08 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
PxHlpa64

Error: (10/13/2018 10:46:48 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
PxHlpa64

Error: (10/12/2018 12:28:33 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
PxHlpa64

Error: (10/11/2018 11:08:13 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
PxHlpa64

Error: (10/10/2018 03:37:22 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
PxHlpa64

Error: (10/09/2018 09:42:26 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
PxHlpa64


CodeIntegrity:
===================================

Date: 2018-09-28 13:49:22.921
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.1.7600.16385_none_34b0fc0c53728e43\fveapibase.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-09-28 13:49:21.237
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.1.7600.16385_none_34b0fc0c53728e43\fveapibase.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-09-28 13:49:19.552
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.1.7600.16385_none_34b0fc0c53728e43\fveapibase.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-09-28 13:49:13.218
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\winsxs\x86_microsoft-windows-s..trics-sensoradapter_31bf3856ad364e35_6.1.7600.16385_none_13881e44d6ccca6b\winbiosensoradapter.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-09-28 13:49:11.533
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\winsxs\x86_microsoft-windows-s..trics-sensoradapter_31bf3856ad364e35_6.1.7600.16385_none_13881e44d6ccca6b\winbiosensoradapter.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-09-28 13:49:09.864
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\winsxs\x86_microsoft-windows-s..trics-sensoradapter_31bf3856ad364e35_6.1.7600.16385_none_13881e44d6ccca6b\winbiosensoradapter.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-09-28 13:49:06.494
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\winsxs\x86_microsoft-windows-s..rics-storageadapter_31bf3856ad364e35_6.1.7600.16385_none_d67ca3c3b6af653e\winbiostorageadapter.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-09-28 13:49:04.794
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows.old\Windows\winsxs\x86_microsoft-windows-s..rics-storageadapter_31bf3856ad364e35_6.1.7600.16385_none_d67ca3c3b6af653e\winbiostorageadapter.dll because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: Intel® Core™2 CPU 6300 @ 1.86GHz
Percentage of memory in use: 53%
Total physical RAM: 3063.31 MB
Available physical RAM: 1427.36 MB
Total Virtual: 6124.77 MB
Available Virtual: 4456.71 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:929.56 GB) (Free:720.74 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (OS_TOOLS) (Fixed) (Total:1.95 GB) (Free:1.75 GB) NTFS


==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: CF2E5F36)
Partition 1: (Active) - (Size=929.6 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=2 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

 

 


  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

You have multiple tasks from some very old games, a bad Sonic driver and a Hosts file that is clogged with garbage but that's probably not enough to cause the problem.  Let's get some more info before I give you a fixlist. 

 

Is your sound working?  What make and model, service tag (Dell) or Serial Number (HP)?  Should be a tag on the bottom if laptop, back or side if desktop.

 

Get Process Explorer

http://live.sysinter...com/procexp.exe
Save it to your desktop then run it (Vista or Win7+ - right click and Run As Administrator).  

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  

Wait a full minute then:

File, Save As, Save.  Note the file name.   Open the file  on your desktop and copy and paste the text to a reply.


Copy the next 2 lines:

TASKLIST /SVC  > \junk.txt
notepad \junk.txt

Open an Elevated Command Prompt:
Win 7: Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator
Win 8: http://www.eightforu...indows-8-a.html
win 10: http://www.howtogeek...-in-windows-10/

Right click and Paste (or Edit then Paste) and the copied lines should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.


Get the free version of Speccy:

http://www.filehippo...ownload_speccy/ 

(Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  
Download, Save and Install it.  Tell it you do not need CCLEANER.    Run Speccy.  When it finishes (the little icon in the bottom left will stop moving),
File, Save as Text File,  (to your desktop) note the name it gives. OK.  Open the file in notepad and delete the line that gives the serial number of your Operating System.  
(It will be near the top,  10-20  lines down.) Save the file.  Attach the file to your next post.  Attaching the log is the best option as it is too big for the forum.  Attaching is a multi step process.

First click on More Reply Options
Then scroll down to where you see
Choose File and click on it.  Point it at the file and hit Open.
Now click on Attach this file.


Let's also try Latency Monitor:

Go to

http://www.resplendence.com/downloads

Scroll down to

System Monitoring Tools

and then find

LatencyMon 6.70 (or it may be a higher number if they update)

Click on Download free home edition

Save it then right click and Run As Admin.  It will install and then start the program.  
It will tell you to click on the Start button but there isn't one.  
Instead click on the green arrowhead (looks like a Play button).   Let it run for at least 20 seconds.  Then hit the red box to stop it.

Edit, Copy Report text to Clipboard then move to a REPLY and Ctrl + v to paste the text into a reply.


  • 0

#3
debodun

debodun

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

Here is the process explorer log:

 

Process    CPU    Private Bytes    Working Set    PID    Verified Signer
System Idle Process    94.62    0 K    24 K    0    
procexp64.exe    3.38    17,780 K    36,740 K    2536    (Verified) Microsoft Corporation
firefox.exe    0.71    258,656 K    362,296 K    2208    (Verified) Mozilla Corporation
dwm.exe    0.32    28,408 K    24,456 K    1432    (Verified) Microsoft Windows
Interrupts    0.25    0 K    0 K    n/a    
MsMpEng.exe    0.23    134,836 K    133,888 K    776    (Verified) Microsoft Corporation
csrss.exe    0.15    2,612 K    14,180 K    436    
System    0.14    304 K    3,492 K    4    
lsass.exe    0.13    4,020 K    11,200 K    536    (Verified) Microsoft Windows
explorer.exe    0.04    30,288 K    48,784 K    1488    (Verified) Microsoft Windows
svchost.exe    0.01    17,736 K    31,020 K    1004    (Verified) Microsoft Windows
AppleMobileDeviceService.exe    0.01    2,752 K    8,852 K    1844    (Verified) Apple Inc.
firefox.exe    0.01    178,964 K    239,812 K    1028    (Verified) Mozilla Corporation
taskhost.exe    < 0.01    7,480 K    11,712 K    1352    (Verified) Microsoft Windows
svchost.exe    < 0.01    13,500 K    15,612 K    1056    (Verified) Microsoft Windows
SearchIndexer.exe    < 0.01    33,212 K    14,140 K    2448    (Verified) Microsoft Windows
svchost.exe    < 0.01    83,044 K    88,760 K    932    (Verified) Microsoft Windows
TeamViewer_Service.exe    < 0.01    3,920 K    10,756 K    2072    (Verified) TeamViewer
csrss.exe    < 0.01    2,008 K    4,284 K    364    
WmiPrvSE.exe        2,440 K    6,796 K    2688    
winlogon.exe        2,868 K    7,404 K    476    
wininit.exe        1,484 K    4,484 K    416    
svchost.exe        3,488 K    7,452 K    724    (Verified) Microsoft Windows
svchost.exe        18,332 K    18,956 K    892    (Verified) Microsoft Windows
svchost.exe        3,988 K    9,204 K    648    (Verified) Microsoft Windows
svchost.exe        7,232 K    12,352 K    968    (Verified) Microsoft Windows
svchost.exe        10,840 K    12,544 K    1308    (Verified) Microsoft Windows
svchost.exe        2,104 K    6,740 K    856    (Verified) Microsoft Windows
svchost.exe        2,288 K    5,828 K    368    (Verified) Microsoft Windows
svchost.exe        4,448 K    8,744 K    1252    (Verified) Microsoft Windows
svchost.exe        4,964 K    10,780 K    1784    (Verified) Microsoft Windows
spoolsv.exe        6,536 K    11,888 K    1240    (Verified) Microsoft Windows
smss.exe        448 K    1,240 K    284    
services.exe        4,708 K    9,200 K    520    
procexp.exe        2,344 K    7,644 K    2420    (Verified) Microsoft Corporation
NisSrv.exe        16,884 K    6,044 K    2492    (Verified) Microsoft Corporation
msseces.exe        5,768 K    13,304 K    1048    (Verified) Microsoft Corporation
mDNSResponder.exe        1,992 K    5,680 K    1512    (Verified) Apple Inc.
lsm.exe        2,408 K    4,268 K    544    
igfxtray.exe        2,320 K    6,716 K    1820    (Verified) Intel Corporation
igfxsrvc.exe        2,080 K    6,360 K    1904    (Verified) Intel Corporation
igfxpers.exe        1,888 K    6,360 K    1952    (Verified) Intel Corporation
hkcmd.exe        2,196 K    6,252 K    1880    (Verified) Intel Corporation
firefox.exe        30,136 K    52,024 K    2068    (Verified) Mozilla Corporation
firefox.exe        24,044 K    37,988 K    1176    (Verified) Mozilla Corporation
firefox.exe        11,000 K    45,740 K    2728    (Verified) Mozilla Corporation
armsvc.exe        1,152 K    4,076 K    1628    (Verified) Adobe Systems

 

 

That instruction about the TASKLIST didn't work. I would see the Notepad flash for an instant then disappear. I tried several times. This is as far as I have gone for now. I do have sound, though. And, if I am reading the Service tag correctly, I have an HP Compaq 2UA7370PG4. Maybe I should also mention that I bought this as a refurb from a local electronics repair shop in January 2012. They may have just used the case and put a new OS in it.


Edited by debodun, 19 October 2018 - 12:02 PM.

  • 0

#4
debodun

debodun

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

Here is the Speccy scan

Attached Files


  • 0

#5
debodun

debodun

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

Latency Monitor Scan

 

 

_________________________________________________________________________________________________________
CONCLUSION
_________________________________________________________________________________________________________
Your system appears to be having trouble handling real-time audio and other tasks. You are likely to experience buffer underruns appearing as drop outs, clicks or pops. One problem may be related to power management, disable CPU throttling settings in Control Panel and BIOS setup. Check for BIOS updates.
LatencyMon has been analyzing your system for  0:01:05  (h:mm:ss) on all processors.


_________________________________________________________________________________________________________
SYSTEM INFORMATION
_________________________________________________________________________________________________________
Computer name:                                        OWNER-PC
OS version:                                           Windows 7 Service Pack 1, 6.1, build: 7601 (x64)
Hardware:                                             HP Compaq dc5700 Small Form Factor, Hewlett-Packard, 0A60h
CPU:                                                  GenuineIntel Intel® Core™2 CPU 6300 @ 1.86GHz
Logical processors:                                   2
Processor groups:                                     1
RAM:                                                  3063 MB total


_________________________________________________________________________________________________________
CPU SPEED
_________________________________________________________________________________________________________
Reported CPU speed:                                   1862 MHz

Note: reported execution times may be calculated based on a fixed reported CPU speed. Disable variable speed settings like Intel Speed Step and AMD Cool N Quiet in the BIOS setup for more accurate results.


_________________________________________________________________________________________________________
MEASURED INTERRUPT TO USER PROCESS LATENCIES
_________________________________________________________________________________________________________
The interrupt to process latency reflects the measured interval that a usermode process needed to respond to a hardware request from the moment the interrupt service routine started execution. This includes the scheduling and execution of a DPC routine, the signaling of an event and the waking up of a usermode thread from an idle wait state in response to that event.

Highest measured interrupt to process latency (µs):   4287.887337
Average measured interrupt to process latency (µs):   5.849694

Highest measured interrupt to DPC latency (µs):       124.286589
Average measured interrupt to DPC latency (µs):       1.465625


_________________________________________________________________________________________________________
 REPORTED ISRs
_________________________________________________________________________________________________________
Interrupt service routines are routines installed by the OS and device drivers that execute in response to a hardware interrupt signal.

Highest ISR routine execution time (µs):              50.552632
Driver with highest ISR routine execution time:       dxgkrnl.sys - DirectX Graphics Kernel, Microsoft Corporation

Highest reported total ISR routine time (%):          0.025184
Driver with highest ISR total time:                   dxgkrnl.sys - DirectX Graphics Kernel, Microsoft Corporation

Total time spent in ISRs (%)                          0.038547

ISR count (execution time <250 µs):                   12857
ISR count (execution time 250-500 µs):                0
ISR count (execution time 500-999 µs):                0
ISR count (execution time 1000-1999 µs):              0
ISR count (execution time 2000-3999 µs):              0
ISR count (execution time >=4000 µs):                 0


_________________________________________________________________________________________________________
REPORTED DPCs
_________________________________________________________________________________________________________
DPC routines are part of the interrupt servicing dispatch mechanism and disable the possibility for a process to utilize the CPU while it is interrupted until the DPC has finished execution.

Highest DPC routine execution time (µs):              124.631579
Driver with highest DPC routine execution time:       ndis.sys - NDIS 6.20 driver, Microsoft Corporation

Highest reported total DPC routine time (%):          0.051083
Driver with highest DPC total execution time:         USBPORT.SYS - USB 1.1 & 2.0 Port Driver, Microsoft Corporation

Total time spent in DPCs (%)                          0.163595

DPC count (execution time <250 µs):                   45826
DPC count (execution time 250-500 µs):                0
DPC count (execution time 500-999 µs):                0
DPC count (execution time 1000-1999 µs):              0
DPC count (execution time 2000-3999 µs):              0
DPC count (execution time >=4000 µs):                 0


_________________________________________________________________________________________________________
 REPORTED HARD PAGEFAULTS
_________________________________________________________________________________________________________
Hard pagefaults are events that get triggered by making use of virtual memory that is not resident in RAM but backed by a memory mapped file on disk. The process of resolving the hard pagefault requires reading in the memory from disk while the process is interrupted and blocked from execution.

NOTE: some processes were hit by hard pagefaults. If these were programs producing audio, they are likely to interrupt the audio stream resulting in dropouts, clicks and pops. Check the Processes tab to see which programs were hit.

Process with highest pagefault count:                 svchost.exe

Total number of hard pagefaults                       2
Hard pagefault count of hardest hit process:          1
Number of processes hit:                              1


_________________________________________________________________________________________________________
 PER CPU DATA
_________________________________________________________________________________________________________
CPU 0 Interrupt cycle time (s):                       0.335542
CPU 0 ISR highest execution time (µs):                50.552632
CPU 0 ISR total execution time (s):                   0.050861
CPU 0 ISR count:                                      12857
CPU 0 DPC highest execution time (µs):                124.631579
CPU 0 DPC total execution time (s):                   0.214737
CPU 0 DPC count:                                      45351
_________________________________________________________________________________________________________
CPU 1 Interrupt cycle time (s):                       0.058789
CPU 1 ISR highest execution time (µs):                0.0
CPU 1 ISR total execution time (s):                   0.0
CPU 1 ISR count:                                      0
CPU 1 DPC highest execution time (µs):                22.868421
CPU 1 DPC total execution time (s):                   0.001120
CPU 1 DPC count:                                      475
_________________________________________________________________________________________________________
 


  • 0

#6
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Process Explorer looks very good.  Since it does we don't need the Tasklist stuff.

 

Speccy says the Temps are good which is often a problem with older systems.  They tend to get clogged with dust around the heatsinks and fans.

 

Speccy does show a problem with your hard drive.  Rather high: C3 Hardware ECC Recovered    100 (100) Data 0000343AA0 (we would prefer 0)

and it's only operating at SATA I even tho the motherboard is spec'd for SATA 2 and the drive is SATA 2.  Probably get  better performance if you cloned the drive. (Don't use a Seagate)

 

Also you only have 3 GB of RAM.  You really need at least 4 GB.  You have one slot free so you could add 1 GB for under $10 if you shop around.  Amazon has1GB DDR2 667MHZ Desktop Computer Memory - Hynix HYMP512U64CP8-Y5 which matches your existing RAM for $8.65.  Unfortunately your Motherboard won't take more than 4 GB so that's all you can do.

 

Your Make and model info doesn't work.  Can't find anything from that number.  Are there others?  I'd like to update your video driver but it's always best to check with the manufacturer first to see what they offer.

 

If you are not using it I would uninstall Kodak EasyShare software.

 

Let's turn on boot logging and check that:

 

Search for

 

msconfig

 

hit Enter.  That should bring up a new window.  Click on the Boot tab and then check the Boot Log box.  OK.  Don't reboot yet.

 

Let's go ahead and run a fixlist to clear up some stuff:

 

Download the attached fixlist.txt to the same location as FRST

Attached File  fixlist.txt   2.84KB   174 downloads

Run FRST and press Fix
A fix log will be generated please post that

Reboot if the fix doesn't reboot it for you

Run FRST again as before.  Make sure Addition.txt is checked and hit Scan.  Post both logs.

 

The boot log will be C:\Windows\ntbtlog.txt  Please copy and paste or attach the log.  You may have trouble seeing it.  If so tell Windows to let you see all files:

 

Control Panel, (View By:  Large Icons)  Folder Options, View.

Uncheck Hide Extensions for Known File Types
Uncheck Hide Protected System Files
Check Show Hidden Files,Folders and Drives.
OK

Then you should be able to see it.

 


 

 

 


  • 0

#7
debodun

debodun

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

First, thank you so much for helping me. I was probably a huge effort to go through all those logs! It was comforting to know some things look good.

 

Second, I do use Easy Share quite a bit for downloading photos from my camera and photo editing and I know it is a resource hog. When I use it, I close the program when finished. Also, I'm not sure what numbers you need from the case, all I can do is attach a photo of the external tags. As I mentioned before,this is a re-built system. The case says originally the OS was Vista Business, but I know it is running Windows 7-64 bit as the current OS. The electronics shop probably just used the case installed new software.

 

I will get to those other scans in a day or two - you know how weekends are. Thanks again.

Attached Thumbnails

  • computer case tags.jpg

  • 0

#8
debodun

debodun

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

Is this the boot log you wanted?

 

 

Service Pack 110 22 2018 16:43:32.375
Loaded driver \SystemRoot\system32\ntoskrnl.exe
Loaded driver \SystemRoot\system32\hal.dll
Loaded driver \SystemRoot\system32\kdcom.dll
Loaded driver \SystemRoot\system32\mcupdate_GenuineIntel.dll
Loaded driver \SystemRoot\system32\PSHED.dll
Loaded driver \SystemRoot\system32\CLFS.SYS
Loaded driver \SystemRoot\system32\CI.dll
Loaded driver \SystemRoot\system32\drivers\Wdf01000.sys
Loaded driver \SystemRoot\system32\drivers\WDFLDR.SYS
Loaded driver \SystemRoot\system32\drivers\ACPI.sys
Loaded driver \SystemRoot\system32\drivers\WMILIB.SYS
Loaded driver \SystemRoot\system32\drivers\msisadrv.sys
Loaded driver \SystemRoot\system32\drivers\pci.sys
Loaded driver \SystemRoot\system32\drivers\vdrvroot.sys
Loaded driver \SystemRoot\System32\drivers\partmgr.sys
Loaded driver \SystemRoot\system32\drivers\volmgr.sys
Loaded driver \SystemRoot\System32\drivers\volmgrx.sys
Loaded driver \SystemRoot\system32\drivers\intelide.sys
Loaded driver \SystemRoot\system32\drivers\PCIIDEX.SYS
Loaded driver \SystemRoot\System32\drivers\mountmgr.sys
Loaded driver \SystemRoot\system32\drivers\atapi.sys
Loaded driver \SystemRoot\system32\drivers\ataport.SYS
Loaded driver \SystemRoot\system32\drivers\amdxata.sys
Loaded driver \SystemRoot\system32\drivers\fltmgr.sys
Loaded driver \SystemRoot\system32\drivers\fileinfo.sys
Loaded driver \SystemRoot\system32\DRIVERS\MpFilter.sys
Loaded driver \SystemRoot\System32\Drivers\Ntfs.sys
Loaded driver \SystemRoot\System32\Drivers\msrpc.sys
Loaded driver \SystemRoot\System32\Drivers\ksecdd.sys
Loaded driver \SystemRoot\System32\Drivers\cng.sys
Loaded driver \SystemRoot\System32\drivers\pcw.sys
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.sys
Loaded driver \SystemRoot\system32\drivers\ndis.sys
Loaded driver \SystemRoot\system32\drivers\NETIO.SYS
Loaded driver \SystemRoot\System32\Drivers\ksecpkg.sys
Loaded driver \SystemRoot\System32\drivers\tcpip.sys
Loaded driver \SystemRoot\System32\drivers\fwpkclnt.sys
Loaded driver \SystemRoot\system32\drivers\vmstorfl.sys
Loaded driver \SystemRoot\system32\drivers\volsnap.sys
Loaded driver \SystemRoot\System32\Drivers\spldr.sys
Loaded driver \SystemRoot\System32\drivers\rdyboost.sys
Loaded driver \SystemRoot\System32\Drivers\mup.sys
Loaded driver \SystemRoot\System32\drivers\hwpolicy.sys
Loaded driver \SystemRoot\System32\DRIVERS\fvevol.sys
Loaded driver \SystemRoot\system32\drivers\disk.sys
Loaded driver \SystemRoot\system32\drivers\CLASSPNP.SYS
Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Loaded driver \SystemRoot\System32\drivers\vga.sys
Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
Loaded driver \SystemRoot\system32\drivers\rdpencdd.sys
Loaded driver \SystemRoot\system32\drivers\rdprefmp.sys
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Loaded driver \SystemRoot\system32\DRIVERS\tdx.sys
Loaded driver \SystemRoot\system32\drivers\afd.sys
Loaded driver \SystemRoot\System32\DRIVERS\netbt.sys
Loaded driver \SystemRoot\system32\DRIVERS\wfplwf.sys
Loaded driver \SystemRoot\system32\DRIVERS\pacer.sys
Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
Loaded driver \SystemRoot\system32\DRIVERS\serial.sys
Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
Loaded driver \SystemRoot\system32\drivers\termdd.sys
Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
Loaded driver \SystemRoot\system32\drivers\nsiproxy.sys
Loaded driver \SystemRoot\system32\drivers\mssmbios.sys
Loaded driver \SystemRoot\System32\drivers\discache.sys
Loaded driver \SystemRoot\system32\drivers\csc.sys
Loaded driver \SystemRoot\System32\Drivers\dfsc.sys
Loaded driver \SystemRoot\system32\DRIVERS\blbdrive.sys
Loaded driver \SystemRoot\System32\drivers\dxgkrnl.sys
Loaded driver \SystemRoot\system32\DRIVERS\igdkmd64.sys
Loaded driver \SystemRoot\system32\drivers\usbuhci.sys
Loaded driver \SystemRoot\system32\drivers\usbehci.sys
Loaded driver \SystemRoot\system32\DRIVERS\HDAudBus.sys
Loaded driver \SystemRoot\system32\DRIVERS\b57nd60a.sys
Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\system32\drivers\mouclass.sys
Loaded driver \SystemRoot\system32\drivers\kbdclass.sys
Loaded driver \SystemRoot\system32\DRIVERS\parport.sys
Loaded driver \SystemRoot\system32\DRIVERS\serenum.sys
Loaded driver \SystemRoot\system32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\system32\drivers\intelppm.sys
Loaded driver \SystemRoot\system32\drivers\wmiacpi.sys
Loaded driver \SystemRoot\system32\DRIVERS\CompositeBus.sys
Loaded driver \SystemRoot\system32\DRIVERS\AgileVpn.sys
Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
Loaded driver \SystemRoot\system32\DRIVERS\rassstp.sys
Loaded driver \SystemRoot\system32\DRIVERS\rdpbus.sys
Loaded driver \SystemRoot\system32\drivers\swenum.sys
Loaded driver \SystemRoot\system32\DRIVERS\umbus.sys
Did not load driver \SystemRoot\System32\drivers\vga.sys
Loaded driver \SystemRoot\system32\drivers\usbhub.sys
Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
Loaded driver \SystemRoot\system32\drivers\HdAudio.sys
Loaded driver \SystemRoot\system32\drivers\ksthunk.sys
Loaded driver \SystemRoot\system32\drivers\hidusb.sys
Loaded driver \SystemRoot\system32\DRIVERS\mouhid.sys
Loaded driver \SystemRoot\system32\DRIVERS\monitor.sys
Loaded driver \SystemRoot\system32\drivers\luafv.sys
Loaded driver \SystemRoot\system32\DRIVERS\lltdio.sys
Loaded driver \SystemRoot\system32\DRIVERS\rspndr.sys
Did not load driver \SystemRoot\system32\DRIVERS\MpFilter.sys
Loaded driver \SystemRoot\system32\drivers\HTTP.sys
Loaded driver \SystemRoot\system32\DRIVERS\bowser.sys
Loaded driver \SystemRoot\System32\drivers\mpsdrv.sys
Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb10.sys
Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb20.sys
Loaded driver \SystemRoot\system32\drivers\peauth.sys
Loaded driver \SystemRoot\System32\DRIVERS\srvnet.sys
Loaded driver \SystemRoot\System32\drivers\tcpipreg.sys
Loaded driver \SystemRoot\System32\DRIVERS\srv2.sys
Loaded driver \SystemRoot\System32\DRIVERS\srv.sys
Did not load driver \SystemRoot\System32\DRIVERS\srv.sys
Loaded driver \SystemRoot\system32\DRIVERS\NisDrvWFP.sys
 


  • 0

#9
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Yes that looks pretty clean.  The Did not loads are what we look for and the ones in your log are pretty standard so the boot seems OK.  Don't you have a fixlist to process?


  • 0

#10
debodun

debodun

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

Fix result of Farbar Recovery Scan Tool (x64) Version: 10.10.2018
Ran by Owner (22-10-2018 17:03:19) Run:1
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Boot Mode: Normal
==============================================

fixlist content:
*****************
S0 PxHlpa64; C:\Windows\SysWOW64\Drivers\PxHlpa64.sys [26720 2004-09-23] (Sonic Solutions) [File not signed]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
Task: {52D1B772-A164-4976-9597-5BECD9597361} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3384263181-369055421-3260215636-1000
Task: {80B7199B-A54D-4E09-84AF-C895D435EF81} - System32\Tasks\{DB28AAC4-58A4-471C-A8CC-0A8B9CBFF8E6} => C:\Users\Owner\Desktop\DD\Games\ASTRO\ASTRO.EXE [1983-11-11] ()
Task: {8A7A4359-A2B1-44AC-879C-D14DD8B5F309} - System32\Tasks\{FB2047DD-47C4-41E8-988F-991725D1BB0D} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {D8060F20-2AF7-4010-8722-E73039BEA018} - System32\Tasks\{7771A4AC-76DB-4824-A025-706FC8FBFA13} => C:\Users\Owner\Desktop\DD\Games\ASTRO\ASTRO.EXE [1983-11-11] ()
Task: {E1138DDE-FC63-4D5A-A0C5-C13AD4F5AEE0} - System32\Tasks\{11C6843C-087E-401F-A969-AB4FE5F21D3B} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {EB1BC358-EB13-4BA5-93F8-1390C2F2B874} - System32\Tasks\{3831C2E7-DCFA-4E96-9F06-C7CC94D6C4C4} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {FC313E55-25B0-4845-87C6-66F271AE8EC7} - System32\Tasks\{BD4C9F3C-DAAC-4CFE-8FC8-BE1EA0D54E71} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
Reboot:




Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10.10.2018
Ran by Owner (22-10-2018 17:12:55)
Running from C:\Users\Owner\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2011-12-17 19:41:25)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3384263181-369055421-3260215636-500 - Administrator - Disabled)
Guest (S-1-5-21-3384263181-369055421-3260215636-501 - Limited - Disabled)
Owner (S-1-5-21-3384263181-369055421-3260215636-1000 - Administrator - Enabled) => C:\Users\Owner

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.008.20074 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 31 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 31.0.0.122 - Adobe Systems Incorporated)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.122 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.8.638 - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\...\{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}) (Version: 2.1.7 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}) (Version: 5.1.1.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CardRd81 (HKLM-x32\...\{54C8FE84-89C4-40E8-976C-439EB0729BD6}) (Version: 4.00.0000.0004 - EASTMAN KODAK Company) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.23 - Piriform)
CCScore (HKLM-x32\...\{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}) (Version: 5.00.0000.0011 - EASTMAN KODAK Company) Hidden
CR2 (HKLM-x32\...\{432C3720-37BF-4BD7-8E49-F38E090246D0}) (Version: 4.00.0000.0003 - EASTMAN KODAK Company) Hidden
EKS Dinner With Moriarty (HKLM-x32\...\EKS Dinner With Moriarty) (Version:  - )
EKS Sherlock (HKLM-x32\...\EKS Sherlock) (Version:  - )
ESSBrwr (HKLM-x32\...\{643EAE81-920C-4931-9F0B-4B343B225CA6}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
ESSCDBK (HKLM-x32\...\{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
ESScore (HKLM-x32\...\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}) (Version: 5.00.0000.0037 - EASTMAN KODAK Company) Hidden
ESSCT (HKLM-x32\...\{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}) (Version: 5.00.0000.0003 - EASTMAN KODAK Company) Hidden
ESSgui (HKLM-x32\...\{91517631-A9F3-4B7C-B482-43E0068FD55A}) (Version: 5.00.0000.0013 - EASTMAN KODAK Company) Hidden
ESShelp (HKLM-x32\...\{87843A41-7808-4F2E-B13F-25C1E67CF2FD}) (Version: 5.00.0000.0005 - EASTMAN KODAK Company) Hidden
ESSini (HKLM-x32\...\{8E92D746-CD9F-4B90-9668-42B74C14F765}) (Version: 5.00.0000.0010 - EASTMAN KODAK Company) Hidden
ESSPCD (HKLM-x32\...\{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}) (Version: 5.00.0000.0007 - EASTMAN KODAK Company) Hidden
ESSPDock (HKLM-x32\...\{FCDB1C92-03C6-4C76-8625-371224256091}) (Version: 5.00.0000.0020 - EASTMAN KODAK Company) Hidden
ESSSONIC (HKLM-x32\...\{4F677FC7-7AA8-412B-A957-F13CBE1C7331}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
ESSTOOLS (HKLM-x32\...\{8A502E38-29C9-49FA-BCFA-D727CA062589}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
ESSTUTOR (HKLM-x32\...\{CA60320D-6A16-49C8-A34F-84EEF4799567}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
ESSvpaht (HKLM-x32\...\{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
ESSvpot (HKLM-x32\...\{48C82F7A-F100-4DAB-A310-8E18BF2159E1}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
Free MIDI to MP3 Converter 1.0 (HKLM-x32\...\{181E1175-1FF8-4EA5-BC08-A7CA39B85502}_is1) (Version:  - PolySoft Solutions)
HLPIndex (HKLM-x32\...\{38441BE7-79B0-42B8-8297-833704F949FE}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
HLPPDOCK (HKLM-x32\...\{154508C0-07C5-4659-A7A0-E49968750D21}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
HLPRFO (HKLM-x32\...\{AADAC983-FDE9-42FA-8FD9-7BB324155593}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.6.0 - LIGHTNING UK!)
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
iTunes (HKLM\...\{4BDE7544-0A08-4AD9-8A8F-4B7944471C36}) (Version: 10.6.0.40 - Apple Inc.)
Kodak EasyShare software (HKLM-x32\...\{D32470A1-B10C-4059-BA53-CF0486F68EBC}) (Version:  - Eastman Kodak Company)
KSU (HKLM-x32\...\{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}) (Version: 632.62.0002.0001 - EASTMAN KODAK Company) Hidden
LatencyMon 6.70 (HKLM\...\LatencyMon_is1) (Version:  - Resplendence Software Projects Sp.)
Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 62.0.3 (x64 en-US) (HKLM\...\Mozilla Firefox 62.0.3 (x64 en-US)) (Version: 62.0.3 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Notifier (HKLM-x32\...\{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden
OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
OTtBP (HKLM-x32\...\{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}) (Version: 5.00.0000.0003 - EASTMAN KODAK Company) Hidden
OTtBPSDK (HKLM-x32\...\{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}) (Version: 4.00.0000.0000 - EASTMAN KODAK Company) Hidden
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
QuickTime (HKLM-x32\...\QuickTime) (Version:  - )
SFR (HKLM-x32\...\{DB02F716-6275-42E9-B8D2-83BA2BF5100B}) (Version: 5.00.0000.0005 - Eastman Kodak Company) Hidden
SHASTA (HKLM-x32\...\{605A4E39-613C-4A12-B56F-DEFBE6757237}) (Version: 5.00.0000.0003 - EASTMAN KODAK Company) Hidden
SKIN0001 (HKLM-x32\...\{FDF9943A-3D5C-46B3-9679-586BD237DDEE}) (Version: 5.00.0000.0007 - EASTMAN KODAK Company) Hidden
SKINXSDK (HKLM-x32\...\{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}) (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
Skype™ 5.5 (HKLM-x32\...\{F1CECE09-7CBE-4E98-B435-DA87CDA86167}) (Version: 5.5.124 - Skype Technologies S.A.)
Speccy (HKLM\...\Speccy) (Version: 1.14 - Piriform)
SpywareBlaster 5.5 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.12541 - TeamViewer)
VLC media player 1.1.11 (HKLM-x32\...\VLC media player) (Version: 1.1.11 - VideoLAN)
VPRINTOL (HKLM-x32\...\{999D43F4-9709-4887-9B1A-83EBB15A8370}) (Version: 5.00.0000.0002 - EASTMAN KODAK Company) Hidden
WIRELESS (HKLM-x32\...\{F9593CFB-D836-49BC-BFF1-0E669A411D9F}) (Version: 5.00.0000.0001 - EASTMAN KODAK Company) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll [2013-04-04] (Malwarebytes Corporation)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2009-09-23] (Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll [2013-04-04] (Malwarebytes Corporation)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0976F330-BF25-4F6F-B0B1-665D9BF7BCC0} - System32\Tasks\{68760510-2907-489D-B7A2-C35A3446BE71} => C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-07-22] ()
Task: {0A0C5E8A-2FCE-4C99-B12F-00B4B70AFB83} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {41E2110D-1421-413B-8E62-70C64466298F} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_122_Plugin.exe [2018-10-09] (Adobe Systems Incorporated)
Task: {5D084169-00AD-4D36-A448-C9A76FB459A9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-10-09] (Adobe Systems Incorporated)
Task: {6B4D3DDA-9B0C-4B4E-A917-B9A141F6ED35} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-09-24] (Piriform Ltd)
Task: {A149C588-D529-48EB-BAE0-95CA7AC5FE1C} - System32\Tasks\{304152A7-70D0-4E91-9F4E-DBD1652C7AAC} => C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-07-22] ()
Task: {A35AB765-EDB9-4C55-9D3E-5E8DBE8B651E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-14] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2011-11-02 00:26 - 2011-11-02 00:26 - 000087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-11-02 00:26 - 2011-11-02 00:26 - 001242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-3384263181-369055421-3260215636-1000\...\1001movie.com -> 1001movie.com

There are 6091 more sites.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 22:34 - 2014-07-05 11:08 - 000000098 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3384263181-369055421-3260215636-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 209.18.47.61 - 209.18.47.62
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{0E227B60-E7FB-4017-9EC7-A62A5EFA8967}] => (Allow) C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe
FirewallRules: [{C86A2602-2440-441D-972C-BEC7E06FC3E4}] => (Allow) C:\Program Files (x86)\Kodak\Kodak EasyShare software\bin\EasyShare.exe
FirewallRules: [{217F7D9C-49CD-4ED9-9050-3C2E4E9D8CC2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{3994F65F-7D58-4F72-86D1-2E5CD9A2AD1F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{D2F24F04-D188-44AF-8CAB-1440B2782E38}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{1A10243C-DC57-4AFE-AD3D-54A683104F27}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{D920EAFE-1F31-4BB5-BC15-E747556F30C0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D0FFCD08-CDC4-41E1-B87C-BCCEA99F34B6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Restore Points =========================

25-10-2017 15:52:28 Windows Update
29-10-2017 10:24:28 Windows Update
12-11-2017 17:09:38 Windows Update
14-11-2017 15:14:38 Windows Update
19-11-2017 14:39:30 Windows Update
29-11-2017 16:50:04 Windows Update
01-12-2017 15:23:05 Windows Update
12-12-2017 15:53:25 Windows Update
05-01-2018 11:32:58 Windows Update
09-01-2018 15:19:09 Windows Update
19-01-2018 13:53:13 Windows Update
22-01-2018 14:01:03 Windows Update
26-01-2018 15:34:58 Windows Update
13-02-2018 14:49:09 Windows Update
05-03-2018 14:08:47 Windows Update
13-03-2018 13:20:54 Windows Update
30-03-2018 14:10:28 Windows Update
10-04-2018 13:22:19 Windows Update
19-04-2018 13:29:46 Windows Update
05-05-2018 16:40:18 Windows Update
08-05-2018 13:51:18 Windows Update
12-06-2018 13:28:59 Windows Update
06-07-2018 14:15:59 Windows Update
10-07-2018 13:30:24 Windows Update
14-08-2018 13:35:43 Windows Update
07-09-2018 14:46:51 Scheduled Checkpoint
11-09-2018 13:31:49 Windows Update
26-09-2018 15:33:47 Scheduled Checkpoint

==================== Faulty Device Manager Devices =============

Name: PS/2 Compatible Mouse
Description: PS/2 Compatible Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/22/2018 05:06:31 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.


System errors:
=============

==================== Memory info ===========================

Processor: Intel® Core™2 CPU 6300 @ 1.86GHz
Percentage of memory in use: 37%
Total physical RAM: 3063.31 MB
Available physical RAM: 1910.41 MB
Total Virtual: 6124.77 MB
Available Virtual: 4981.63 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:929.56 GB) (Free:719.62 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (OS_TOOLS) (Fixed) (Total:1.95 GB) (Free:1.75 GB) NTFS


==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: CF2E5F36)
Partition 1: (Active) - (Size=929.6 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=2 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================


  • 0

Advertisements


#11
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Where is the fixlog?  You posted the fixlist which is what I sent you.  You are supposed to:

 

Download the attached fixlist.txt to the same location as FRST



Run FRST and press Fix
A fix log will be generated please post that

 


  • 0

#12
debodun

debodun

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

I thought I did. This is the only fixlog.txt on the desktop:

 

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 10.10.2018
Ran by Owner (22-10-2018 17:03:19) Run:1
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Boot Mode: Normal
==============================================

fixlist content:
*****************
S0 PxHlpa64; C:\Windows\SysWOW64\Drivers\PxHlpa64.sys [26720 2004-09-23] (Sonic Solutions) [File not signed]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
Task: {52D1B772-A164-4976-9597-5BECD9597361} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3384263181-369055421-3260215636-1000
Task: {80B7199B-A54D-4E09-84AF-C895D435EF81} - System32\Tasks\{DB28AAC4-58A4-471C-A8CC-0A8B9CBFF8E6} => C:\Users\Owner\Desktop\DD\Games\ASTRO\ASTRO.EXE [1983-11-11] ()
Task: {8A7A4359-A2B1-44AC-879C-D14DD8B5F309} - System32\Tasks\{FB2047DD-47C4-41E8-988F-991725D1BB0D} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {D8060F20-2AF7-4010-8722-E73039BEA018} - System32\Tasks\{7771A4AC-76DB-4824-A025-706FC8FBFA13} => C:\Users\Owner\Desktop\DD\Games\ASTRO\ASTRO.EXE [1983-11-11] ()
Task: {E1138DDE-FC63-4D5A-A0C5-C13AD4F5AEE0} - System32\Tasks\{11C6843C-087E-401F-A969-AB4FE5F21D3B} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {EB1BC358-EB13-4BA5-93F8-1390C2F2B874} - System32\Tasks\{3831C2E7-DCFA-4E96-9F06-C7CC94D6C4C4} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {FC313E55-25B0-4845-87C6-66F271AE8EC7} - System32\Tasks\{BD4C9F3C-DAAC-4CFE-8FC8-BE1EA0D54E71} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
Reboot:


 


Edited by debodun, 22 October 2018 - 03:33 PM.

  • 0

#13
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Is that the whole log?  Doesn't look like the fix finished if it is.


  • 0

#14
debodun

debodun

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 567 posts

I tried again by downloading that fixlist,txt you posted to the desktop, opened the FTSR and ran FIX. This is the log it generated after rebooting:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 10.10.2018
Ran by Owner (23-10-2018 11:47:03) Run:2
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Boot Mode: Normal
==============================================

fixlist content:
*****************
S0 PxHlpa64; C:\Windows\SysWOW64\Drivers\PxHlpa64.sys [26720 2004-09-23] (Sonic Solutions) [File not signed]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
Task: {52D1B772-A164-4976-9597-5BECD9597361} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3384263181-369055421-3260215636-1000
Task: {80B7199B-A54D-4E09-84AF-C895D435EF81} - System32\Tasks\{DB28AAC4-58A4-471C-A8CC-0A8B9CBFF8E6} => C:\Users\Owner\Desktop\DD\Games\ASTRO\ASTRO.EXE [1983-11-11] ()
Task: {8A7A4359-A2B1-44AC-879C-D14DD8B5F309} - System32\Tasks\{FB2047DD-47C4-41E8-988F-991725D1BB0D} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {D8060F20-2AF7-4010-8722-E73039BEA018} - System32\Tasks\{7771A4AC-76DB-4824-A025-706FC8FBFA13} => C:\Users\Owner\Desktop\DD\Games\ASTRO\ASTRO.EXE [1983-11-11] ()
Task: {E1138DDE-FC63-4D5A-A0C5-C13AD4F5AEE0} - System32\Tasks\{11C6843C-087E-401F-A969-AB4FE5F21D3B} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {EB1BC358-EB13-4BA5-93F8-1390C2F2B874} - System32\Tasks\{3831C2E7-DCFA-4E96-9F06-C7CC94D6C4C4} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
Task: {FC313E55-25B0-4845-87C6-66F271AE8EC7} - System32\Tasks\{BD4C9F3C-DAAC-4CFE-8FC8-BE1EA0D54E71} => C:\Users\Owner\Desktop\DD\Games\Crazy 8s\CRAZY8S.EXE [1994-11-08] ()
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
Reboot:

 


  • 0

#15
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Something not working right.  Did you right click on FRST(64) and Run As Admin?  Can I see a new FRST scan?


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP