Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Help with Vosteran search engine


  • Please log in to reply

#1
Steviep

Steviep

    Member

  • Member
  • PipPipPip
  • 338 posts

Hi, I wonder if someone could help with my friends laptop? her son has managed to download something which has resulted in the Vostean search engine being installed, she says she downloaded a program last night which found it and I have run malwarebytes earlier tonight. Here is the OTL log and I would appreciate your help. thanks

 

OTL logfile created on: 25/11/2014 19:31:36 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Jack\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
3.60 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 54.18% Memory free
4.22 Gb Paging File | 2.26 Gb Available in Paging File | 53.47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 445.03 Gb Total Space | 409.32 Gb Free Space | 91.98% Space Free | Partition Type: NTFS
Drive D: | 19.52 Gb Total Space | 1.98 Gb Free Space | 10.13% Space Free | Partition Type: NTFS
 
Computer Name: HOMEPC | User Name: Jack | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/11/25 19:20:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Jack\Downloads\OTL.exe
PRC - [2014/11/14 21:15:26 | 000,856,904 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/11/07 15:20:54 | 003,247,120 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
PRC - [2014/11/07 15:06:46 | 000,289,328 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
PRC - [2014/10/01 11:09:30 | 000,968,504 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
PRC - [2014/10/01 11:09:28 | 001,871,160 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
PRC - [2014/10/01 11:09:20 | 007,229,752 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
PRC - [2014/08/25 12:06:50 | 002,640,408 | ---- | M] () -- C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
PRC - [2014/08/12 17:40:49 | 001,820,184 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe
PRC - [2014/08/12 17:40:49 | 000,159,768 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\loggingserver.exe
PRC - [2014/07/14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2014/07/14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2013/10/08 11:41:28 | 001,039,160 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
PRC - [2013/05/16 02:04:20 | 000,323,584 | ---- | M] (Atheros) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
PRC - [2012/06/08 03:34:06 | 000,111,120 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/11/14 21:15:23 | 009,009,480 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\pdf.dll
MOD - [2014/11/14 21:15:19 | 001,077,064 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libglesv2.dll
MOD - [2014/11/14 21:15:17 | 000,211,272 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libegl.dll
MOD - [2014/11/14 21:15:16 | 001,677,128 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\ffmpegsumo.dll
MOD - [2014/08/25 12:06:50 | 002,640,408 | ---- | M] () -- C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
MOD - [2014/08/12 17:40:49 | 000,519,704 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\log4cplusU.dll
MOD - [2012/06/08 11:34:06 | 000,016,400 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
MOD - [2012/06/08 03:34:06 | 000,627,216 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/11/04 20:10:12 | 000,076,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV:64bit: - [2014/10/31 04:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/10/07 01:54:27 | 000,226,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2014/09/24 17:22:09 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:64bit: - [2014/09/24 16:56:08 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:64bit: - [2014/09/24 16:56:07 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:64bit: - [2014/09/24 16:39:09 | 001,600,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:64bit: - [2014/09/24 16:30:04 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:64bit: - [2014/09/24 16:30:03 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:64bit: - [2014/09/24 16:29:57 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:64bit: - [2014/09/24 16:29:55 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:64bit: - [2014/09/24 16:29:54 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:64bit: - [2014/09/24 16:29:51 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:64bit: - [2014/09/22 03:05:56 | 000,368,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:64bit: - [2014/09/22 03:05:56 | 000,023,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:64bit: - [2014/08/16 03:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:64bit: - [2014/08/16 00:58:35 | 000,287,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:64bit: - [2014/08/16 00:45:51 | 000,267,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:64bit: - [2014/07/21 22:04:24 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2014/07/14 10:26:06 | 000,042,808 | ---- | M] (AVG) [Auto | Stopped] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
SRV:64bit: - [2014/07/04 21:33:34 | 000,344,064 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2014/03/21 15:12:22 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV:64bit: - [2013/08/22 11:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:64bit: - [2013/08/22 11:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:64bit: - [2013/08/22 11:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:64bit: - [2013/08/22 11:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:64bit: - [2013/08/22 11:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:64bit: - [2013/08/22 10:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:64bit: - [2013/08/22 10:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:64bit: - [2013/08/22 10:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:64bit: - [2013/08/22 10:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:64bit: - [2013/08/22 10:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:64bit: - [2013/08/22 10:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:64bit: - [2013/08/22 10:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:64bit: - [2013/08/22 10:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:64bit: - [2013/08/22 10:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:64bit: - [2013/08/22 09:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:64bit: - [2013/08/22 09:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:64bit: - [2013/08/22 09:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:64bit: - [2013/08/22 09:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:64bit: - [2013/08/22 09:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:64bit: - [2013/08/22 09:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:64bit: - [2013/08/22 09:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:64bit: - [2013/08/22 09:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:64bit: - [2013/03/04 22:28:40 | 000,239,176 | ---- | M] (Realtek Semiconductor) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE -- (RtkAudioService)
SRV - [2014/11/07 15:20:54 | 003,247,120 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2014/11/07 15:06:46 | 000,289,328 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2014/11/04 20:10:15 | 000,475,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2014/11/04 20:10:11 | 000,066,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV - [2014/11/04 20:10:10 | 000,062,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2014/10/01 11:09:30 | 000,968,504 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014/10/01 11:09:28 | 001,871,160 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2014/09/24 17:22:08 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2014/08/16 03:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2014/08/12 17:40:49 | 001,820,184 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe -- (vToolbarUpdater18.1.9)
SRV - [2014/07/14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014/07/14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014/07/14 10:26:10 | 002,253,112 | ---- | M] (AVG) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2014/07/14 10:26:06 | 000,035,640 | ---- | M] (AVG) [Auto | Stopped] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
SRV - [2014/04/03 19:21:48 | 000,315,008 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/10/08 11:41:28 | 001,039,160 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] -- c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe -- (HPWMISVC)
SRV - [2013/08/22 03:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2013/08/22 02:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2013/05/16 03:10:24 | 000,310,912 | ---- | M] (Windows ® Win 7 DDK provider) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2013/05/16 02:04:20 | 000,323,584 | ---- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe -- (ZAtheros Bt and Wlan Coex Agent)
SRV - [2012/11/15 23:49:48 | 002,468,496 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/11/25 18:57:57 | 000,129,752 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV:64bit: - [2014/10/29 21:03:36 | 000,123,672 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2014/10/24 10:20:06 | 000,237,848 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2014/10/10 01:58:57 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2014/10/01 11:11:30 | 000,064,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:64bit: - [2014/10/01 11:11:12 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2014/09/24 17:52:43 | 000,055,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:64bit: - [2014/09/24 16:56:15 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:64bit: - [2014/09/24 16:56:09 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:64bit: - [2014/09/24 16:56:08 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:64bit: - [2014/09/24 16:38:59 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:64bit: - [2014/09/24 16:38:56 | 000,468,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:64bit: - [2014/09/24 16:38:56 | 000,412,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:64bit: - [2014/09/24 16:29:56 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
DRV:64bit: - [2014/09/24 16:29:52 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:64bit: - [2014/09/24 16:29:38 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:64bit: - [2014/09/24 16:29:38 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:64bit: - [2014/09/24 16:29:37 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:64bit: - [2014/09/24 16:29:37 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2014/09/24 16:29:37 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BthLEEnum.sys -- (BthLEEnum)
DRV:64bit: - [2014/09/24 16:29:37 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:64bit: - [2014/09/24 16:29:37 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:64bit: - [2014/09/24 16:29:37 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:64bit: - [2014/09/24 16:29:37 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:64bit: - [2014/09/24 16:29:37 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:64bit: - [2014/09/24 15:57:21 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2014/09/22 03:06:16 | 000,258,368 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:64bit: - [2014/09/22 03:06:16 | 000,114,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:64bit: - [2014/09/22 02:49:43 | 000,035,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:64bit: - [2014/08/15 00:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:64bit: - [2014/08/12 17:40:49 | 000,050,976 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2014/07/21 22:04:28 | 013,209,088 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2014/07/21 22:04:28 | 000,626,688 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2014/07/21 20:03:12 | 000,244,504 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2014/06/30 11:43:18 | 000,270,104 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgwfpa.sys -- (Avgwfpa)
DRV:64bit: - [2014/06/30 11:43:02 | 000,152,344 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:64bit: - [2014/06/17 15:07:12 | 000,328,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2014/06/17 15:06:24 | 000,190,744 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2014/06/17 15:06:06 | 000,031,512 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2013/09/04 15:35:06 | 000,020,496 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\avgboota.sys -- (Avgboota)
DRV:64bit: - [2013/08/22 13:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:64bit: - [2013/08/22 13:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2013/08/22 12:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:64bit: - [2013/08/22 12:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:64bit: - [2013/08/22 12:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2013/08/22 12:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:64bit: - [2013/08/22 12:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:64bit: - [2013/08/22 12:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2013/08/22 12:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2013/08/22 12:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:64bit: - [2013/08/22 12:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2013/08/22 12:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:64bit: - [2013/08/22 12:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:64bit: - [2013/08/22 12:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2013/08/22 12:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2013/08/22 12:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:64bit: - [2013/08/22 12:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2013/08/22 12:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:64bit: - [2013/08/22 12:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:64bit: - [2013/08/22 12:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2013/08/22 12:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:64bit: - [2013/08/22 12:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:64bit: - [2013/08/22 12:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2013/08/22 12:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:64bit: - [2013/08/22 12:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:64bit: - [2013/08/22 12:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:64bit: - [2013/08/22 12:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:64bit: - [2013/08/22 12:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:64bit: - [2013/08/22 12:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:64bit: - [2013/08/22 11:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:64bit: - [2013/08/22 11:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:64bit: - [2013/08/22 11:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:64bit: - [2013/08/22 11:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:64bit: - [2013/08/22 11:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:64bit: - [2013/08/22 11:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:64bit: - [2013/08/22 11:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:64bit: - [2013/08/22 11:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:64bit: - [2013/08/22 11:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:64bit: - [2013/08/22 11:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:64bit: - [2013/08/22 11:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:64bit: - [2013/08/22 11:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:64bit: - [2013/08/22 11:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2013/08/22 11:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:64bit: - [2013/08/22 11:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/08/22 11:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:64bit: - [2013/08/22 11:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2013/08/22 11:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:64bit: - [2013/08/22 11:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:64bit: - [2013/08/22 11:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:64bit: - [2013/08/22 11:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:64bit: - [2013/08/22 08:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:64bit: - [2013/08/12 23:25:46 | 000,017,624 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:64bit: - [2013/08/10 00:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:64bit: - [2013/08/07 20:41:38 | 003,915,264 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athw8x.sys -- (athr)
DRV:64bit: - [2013/07/30 18:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:64bit: - [2013/07/25 19:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:64bit: - [2013/06/18 14:46:17 | 000,591,360 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:64bit: - [2013/05/16 19:12:22 | 000,524,016 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2013/05/16 02:06:04 | 000,586,440 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2013/05/16 02:06:04 | 000,347,336 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2013/05/16 02:06:04 | 000,179,432 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2013/05/16 02:06:04 | 000,136,784 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2013/05/16 02:06:04 | 000,115,912 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:64bit: - [2013/05/16 02:06:04 | 000,089,800 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2013/05/16 02:06:04 | 000,077,464 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2013/05/16 02:06:04 | 000,055,448 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AthDfu.sys -- (ATHDFU)
DRV:64bit: - [2013/05/16 02:06:04 | 000,034,384 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2013/05/08 00:41:48 | 000,033,008 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys -- (SmbDrvI)
DRV:64bit: - [2013/05/08 00:41:48 | 000,029,424 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Smb_driver_AMDASF.sys -- (SmbDrv)
DRV:64bit: - [2013/02/14 12:41:14 | 000,094,208 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW86.sys -- (AtiHDAudioService)
DRV:64bit: - [2013/01/24 00:29:56 | 000,288,328 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsP2Stor.sys -- (RSP2STOR)
DRV:64bit: - [2012/11/30 07:31:02 | 000,026,280 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2012/11/30 07:31:00 | 000,080,552 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2012/09/02 02:01:56 | 000,647,736 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:64bit: - [2012/08/31 09:40:24 | 000,020,800 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WirelessButtonDriver64.sys -- (WirelessButtonDriver)
DRV:64bit: - [2012/08/28 13:27:24 | 000,058,536 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2012/06/25 10:24:50 | 000,092,536 | ---- | M] (CyberLink) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\CLVirtualDrive.sys -- (CLVirtualDrive)
DRV - [2014/03/26 08:03:04 | 000,014,112 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM13/2
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPCOM13/2
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{02D2F928-28C8-443F-BACE-BF0A94B5864B}: "URL" = http://www.amazon.co...s={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...0TR&pc=CMNTDFJS
IE:64bit: - HKLM\..\SearchScopes\{8C34C59A-AAAD-4F25-A91A-26FF9664067C}: "URL" = http://www.amazon.co...s={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...9550-11896-25/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{02D2F928-28C8-443F-BACE-BF0A94B5864B}: "URL" = http://www.amazon.co...s={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...0TR&pc=CMNTDFJS
IE - HKLM\..\SearchScopes\{8C34C59A-AAAD-4F25-A91A-26FF9664067C}: "URL" = http://www.amazon.co...s={searchTerms}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM13/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{02D2F928-28C8-443F-BACE-BF0A94B5864B}: "URL" = http://www.amazon.co...s={searchTerms}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://Vosteran.com/...=1045722471&ir=
IE - HKCU\..\SearchScopes\{8C34C59A-AAAD-4F25-A91A-26FF9664067C}: "URL" = http://www.amazon.co...s={searchTerms}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://mysearch.avg.com/search?cid={C7604F8A-EB60-4101-BA30-C722E6E4D463}&mid=ad352bc6dc2a47d29d337592769a1a6f-e770954957f2536e4a3c5f7c39b131495a842c61&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-06-03 16:48:05&v=18.1.0.443&pid=safeguard&sg=&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}: "URL" = http://www.bing.com/...Box&FORM=IESR02
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.9\\npsitesafety.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
 
 
 
========== Chrome  ==========
 
CHR - default_search_provider: FB36D69102B1CA237216348C51615AA26ED091700BBB31777E6327ECA81007F9 ()
CHR - default_search_provider: search_url = 76873609FD74BB2362909199D82767C5C064EDC9C616E86A327E5FFFF5B60C44
CHR - default_search_provider: suggest_url = 
CHR - homepage: F5CA035D04319FAA06233A387743712D6C2EAA245404D9A233107E7A53C906FB
CHR - Extension: No name found = C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.8_0\
CHR - Extension: No name found = C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.0_0\
CHR - Extension: No name found = C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2013/08/22 13:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.9.799\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: BtvStack = "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" (Qualcomm Atheros Commnucations)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 File not found
O9:64bit: - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 194.168.8.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{99433F78-D312-44B6-99B2-D7FC2DC9431D}: DhcpNameServer = 194.168.4.100 194.168.8.100
O18:64bit: - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.9\ViProtocol.dll (AVG Secure Search)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2014/11/24 20:28:57 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{216bd520-50b0-11e3-be73-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{216bd520-50b0-11e3-be73-806e6f6e6963}\Shell\AutoRun\command - "" = "E:\SETUP.EXE" 
O33 - MountPoints2\{216bd520-50b0-11e3-be73-806e6f6e6963}\Shell\configure\command - "" = E:\SETUP.EXE
O33 - MountPoints2\{216bd520-50b0-11e3-be73-806e6f6e6963}\Shell\install\command - "" = E:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/11/25 19:17:36 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2014/11/25 18:59:16 | 000,000,000 | R--D | C] -- C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2014/11/25 18:39:25 | 000,000,000 | ---D | C] -- C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2014/11/25 18:39:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VS Revo Group
[2014/11/25 18:21:21 | 000,129,752 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\4F4061F6.sys
[2014/11/25 18:21:12 | 000,129,752 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2014/11/25 18:20:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014/11/25 18:20:38 | 000,093,400 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbamchameleon.sys
[2014/11/25 18:20:38 | 000,064,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2014/11/25 18:20:38 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2014/11/25 18:20:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014/11/25 18:20:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/11/24 23:06:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2014/11/24 22:38:34 | 000,000,000 | ---D | C] -- C:\Users\Jack\Desktop\jacks stuff
[2014/11/24 21:20:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2014/11/24 21:12:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2014/11/24 21:12:05 | 000,000,000 | ---D | C] -- C:\Users\Jack\AppData\Local\Google
[2014/11/24 21:11:26 | 000,000,000 | ---D | C] -- C:\Users\Jack\AppData\Local\Deployment
[2014/11/24 21:11:26 | 000,000,000 | ---D | C] -- C:\Users\Jack\AppData\Local\Apps
[2014/11/24 20:28:11 | 000,000,000 | ---D | C] -- C:\Users\Jack\Start Menu
[2014/11/24 20:20:11 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2014/11/24 12:06:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\AutoKMS
[2014/11/24 12:05:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Toolkit
[2014/11/23 12:04:04 | 000,000,000 | R--D | C] -- C:\Users\Jack\Creative Cloud Files
[2014/11/23 12:02:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2014/11/23 11:58:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2014/11/23 11:58:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2014/11/23 11:55:13 | 000,000,000 | ---D | C] -- C:\Users\Jack\AppData\Local\Adobe
[2014/11/21 09:17:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\PCHEALTH
[2014/11/21 09:11:34 | 000,000,000 | ---D | C] -- C:\Users\Jack\AppData\Local\Microsoft Help
[2014/11/21 09:11:29 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2014/11/21 09:11:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2014/11/13 07:31:55 | 000,000,000 | -HSD | C] -- C:\Users\Jack\AppData\Local\EmieBrowserModeList
[2014/11/11 20:32:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft OneDrive
[2014/11/11 20:29:25 | 000,000,000 | ---D | C] -- C:\Users\Jack\Documents\Custom Office Templates
[2014/11/11 19:49:51 | 000,000,000 | R--D | C] -- C:\Users\Jack\SkyDrive
[2014/11/08 23:51:18 | 000,000,000 | R--D | C] -- C:\WINDOWS\BrowserChoice
[2014/11/06 20:08:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Security Toolbar
[2014/11/06 20:08:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Avg_Update_1114tb
[2014/11/04 21:05:46 | 000,000,000 | -HSD | C] -- C:\Users\Jack\AppData\Local\EmieUserList
[2014/11/04 21:05:46 | 000,000,000 | -HSD | C] -- C:\Users\Jack\AppData\Local\EmieSiteList
[2014/11/04 21:02:02 | 000,000,000 | ---D | C] -- C:\Users\Jack\AppData\Roaming\Identities
[2014/11/04 20:34:58 | 000,000,000 | --SD | C] -- C:\Users\Jack\AppData\Roaming\Microsoft
[2014/11/04 20:34:58 | 000,000,000 | R--D | C] -- C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2014/11/04 20:34:58 | 000,000,000 | R--D | C] -- C:\Users\Jack\Favorites
[2014/11/04 20:34:58 | 000,000,000 | R--D | C] -- C:\Users\Jack\Desktop
[2014/11/04 20:34:58 | 000,000,000 | R--D | C] -- C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2014/11/04 20:34:58 | 000,000,000 | R--D | C] -- C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2014/11/04 20:34:58 | 000,000,000 | -H-D | C] -- C:\Users\Jack\AppData
[2014/11/04 20:34:58 | 000,000,000 | ---D | C] -- C:\Users\Jack\AppData\Local\Temp
[2014/11/04 20:34:58 | 000,000,000 | ---D | C] -- C:\Users\Jack\AppData\Local\Microsoft
[2014/11/04 20:34:58 | 000,000,000 | ---D | C] -- C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2014/11/04 20:24:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
[2014/11/04 20:24:11 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2014/11/04 20:24:10 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2014/11/04 20:23:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2014/11/04 20:23:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2014/11/04 20:22:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\SRSLabs
[2014/11/04 20:22:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\RTCOM
[2014/11/04 20:22:51 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2014/11/04 20:22:31 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2014/11/04 20:22:01 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2014/11/04 20:20:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2014/11/04 20:19:35 | 000,000,000 | -HSD | C] -- C:\Recovery
[2014/11/04 20:19:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Panther
[2014/11/04 20:10:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
[2014/11/04 20:10:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
[2014/11/04 20:10:23 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2014/11/04 20:10:23 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2014/11/04 20:10:23 | 000,000,000 | ---D | C] -- C:\inetpub
[2014/10/30 08:16:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\AutoUpdateLicense
[2014/10/29 21:03:36 | 000,123,672 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\SysNative\drivers\avgmfx64.sys
 
========== Files - Modified Within 30 Days ==========
 
[2014/11/25 19:17:01 | 000,000,908 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/11/25 19:04:44 | 000,956,476 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2014/11/25 19:04:44 | 000,800,408 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2014/11/25 19:04:44 | 000,165,436 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2014/11/25 18:58:53 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/11/25 18:58:15 | 000,000,904 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/11/25 18:57:57 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2014/11/25 18:56:49 | 3088,904,192 | -HS- | M] () -- C:\hiberfil.sys
[2014/11/25 18:56:49 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014/11/25 18:39:25 | 000,001,251 | ---- | M] () -- C:\Users\Jack\Desktop\Revo Uninstaller.lnk
[2014/11/25 18:21:21 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\4F4061F6.sys
[2014/11/25 18:20:44 | 000,001,085 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/11/24 21:20:58 | 000,002,246 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/11/24 20:28:57 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2014/11/24 19:15:05 | 000,000,069 | ---- | M] () -- C:\Users\Jack\AppData\Roaming\WB.CFG
[2014/11/23 20:22:20 | 000,481,824 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2014/11/18 17:27:34 | 000,000,988 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2014/11/18 06:49:38 | 000,124,906 | ---- | M] () -- C:\Users\Jack\Documents\equiptment log2.pdf
[2014/11/04 20:54:49 | 000,020,958 | ---- | M] () -- C:\WINDOWS\diagwrn.xml
[2014/11/04 20:54:49 | 000,020,958 | ---- | M] () -- C:\WINDOWS\diagerr.xml
[2014/11/04 20:54:21 | 000,022,744 | ---- | M] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2014/11/04 20:27:43 | 000,922,144 | ---- | M] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2014/11/04 20:22:40 | 000,000,000 | ---- | M] () -- C:\WINDOWS\ativpsrm.bin
[2014/11/04 20:22:14 | 000,000,264 | ---- | M] () -- C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job
[2014/11/04 20:22:12 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2014/10/29 21:03:36 | 000,123,672 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\SysNative\drivers\avgmfx64.sys
 
========== Files Created - No Company Name ==========
 
[2014/11/25 18:39:25 | 000,001,251 | ---- | C] () -- C:\Users\Jack\Desktop\Revo Uninstaller.lnk
[2014/11/25 18:20:44 | 000,001,085 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/11/24 21:20:58 | 000,002,246 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/11/24 21:12:21 | 000,000,908 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/11/24 21:12:19 | 000,000,904 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/11/24 20:28:57 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
[2014/11/23 13:15:16 | 000,000,069 | ---- | C] () -- C:\Users\Jack\AppData\Roaming\WB.CFG
[2014/11/18 06:49:37 | 000,124,906 | ---- | C] () -- C:\Users\Jack\Documents\equiptment log2.pdf
[2014/11/12 07:31:41 | 000,389,176 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2014/11/08 23:59:49 | 000,002,143 | R-S- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser Choice.lnk
[2014/11/05 22:59:20 | 000,050,745 | ---- | C] () -- C:\WINDOWS\SysNative\srms.dat
[2014/11/04 21:02:07 | 000,001,453 | ---- | C] () -- C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014/11/04 20:54:22 | 000,022,744 | ---- | C] () -- C:\WINDOWS\SysNative\emptyregdb.dat
[2014/11/04 20:41:41 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2014/11/04 20:34:58 | 000,000,369 | ---- | C] () -- C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
[2014/11/04 20:34:58 | 000,000,369 | ---- | C] () -- C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
[2014/11/04 20:34:42 | 000,020,958 | ---- | C] () -- C:\WINDOWS\diagwrn.xml
[2014/11/04 20:34:42 | 000,020,958 | ---- | C] () -- C:\WINDOWS\diagerr.xml
[2014/11/04 20:27:43 | 000,922,144 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2014/11/04 20:22:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2014/11/04 20:22:14 | 000,000,264 | ---- | C] () -- C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job
[2014/11/04 20:22:12 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2014/10/29 17:21:48 | 000,581,016 | ---- | C] () -- C:\WINDOWS\SysNative\AutoUpdate.exe
[2014/10/29 17:21:47 | 000,010,777 | ---- | C] () -- C:\WINDOWS\SysNative\AutoconfigV2.cab
[2014/09/24 16:30:09 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014/09/24 16:29:39 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2014/07/21 22:04:58 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat
[2014/07/21 22:04:58 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat
[2014/07/21 22:04:46 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat
[2014/07/21 22:04:04 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe
[2014/07/21 22:04:04 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe
[2014/07/21 22:03:42 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2013/08/22 15:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013/08/22 15:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013/08/22 14:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013/08/22 07:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013/08/22 03:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013/08/21 23:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013/08/21 23:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
 
========== ZeroAccess Check ==========
 
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/08/31 00:15:33 | 021,197,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/08/30 22:59:13 | 018,723,112 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 09:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/22 02:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 09:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014/06/02 19:06:16 | 000,000,000 | ---D | M] -- C:\Users\Jack\AppData\Roaming\AVG
[2014/06/02 05:39:53 | 000,000,000 | ---D | M] -- C:\Users\Jack\AppData\Roaming\AVG2014
[2014/03/13 14:13:30 | 000,000,000 | ---D | M] -- C:\Users\Jack\AppData\Roaming\Synaptics
[2014/11/25 18:55:06 | 000,000,000 | ---D | M] -- C:\Users\Jack\AppData\Roaming\systweak
[2014/06/02 05:38:48 | 000,000,000 | ---D | M] -- C:\Users\Jack\AppData\Roaming\TuneUp Software
[2014/06/24 18:44:54 | 000,000,000 | ---D | M] -- C:\Users\Jack\AppData\Roaming\WebApp
 
========== Purity Check ==========
 
 
 
< End of report >
 
 
and the extras log

OTL Extras logfile created on: 25/11/2014 19:31:36 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Jack\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17416)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
3.60 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 54.18% Memory free
4.22 Gb Paging File | 2.26 Gb Available in Paging File | 53.47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 445.03 Gb Total Space | 409.32 Gb Free Space | 91.98% Space Free | Partition Type: NTFS
Drive D: | 19.52 Gb Total Space | 1.98 Gb Free Space | 10.13% Space Free | Partition Type: NTFS
 
Computer Name: HOMEPC | User Name: Jack | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- C:\Program Files (x86)\Advanced System Protector\filetypehelper.exe -scanunknown "%1"
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- C:\Program Files (x86)\Advanced System Protector\filetypehelper.exe -scanunknown "%1"
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" =  [binary data]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0247AEE7-D047-4495-BABE-C44B277F05EC}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | 
"{05CFB2FB-469E-47DB-ACC9-C1C0D00BEFED}" = rport=445 | protocol=6 | dir=out | app=system | 
"{0EC65D60-FC04-4A92-9520-FA705D3CED36}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
"{127C0C1F-8FB0-4002-AC9B-3A36599AB29F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{131007B7-46A5-4203-AB5B-31C0166244C3}" = lport=1688 | protocol=6 | dir=in | app=f:\microsoft toolkit.exe | 
"{2F6B73FF-43D3-445C-AB8A-D15CE020F639}" = lport=138 | protocol=17 | dir=in | app=system | 
"{3DEA5F82-1EFE-4B7E-BA1D-3F6A837CEB95}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{3FCF1F5C-D5E7-4810-B013-36F65E619568}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{44572F5F-476B-41C8-8171-6452EA7FF0AF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{449D22A8-AE51-40A1-9131-AD3D26748AE7}" = lport=139 | protocol=6 | dir=in | app=system | 
"{5699DD97-D6DA-4C29-9245-27FAA231A671}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
"{6F41C9D9-4053-4B1D-8CC7-F6B6BBAB3DBF}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{6F6FD0E5-1E87-4E10-9C9C-A20F5CA5250C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{75287D7C-9CA1-457A-9498-0F0EC5F4DFC4}" = lport=1688 | protocol=6 | dir=out | app=f:\microsoft toolkit.exe | 
"{76912A90-3BE2-4B05-AB2C-F48B51B73ECA}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{7847FACD-5301-4D67-B74B-3D9CBF6909CC}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{7A76641E-BE36-40C3-9CF9-2E5D68A0920B}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{8F2B458D-E3F1-4216-8193-1CD9B18703DA}" = lport=445 | protocol=6 | dir=in | app=system | 
"{91C71E14-C667-4F42-B421-AA66EB18397E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{B4BEA09E-0608-4A46-83DB-CFB1E1A7C30A}" = lport=137 | protocol=17 | dir=in | app=system | 
"{BBBADEB1-02FB-41DF-AA2D-7EB34079BE5C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{BDBFD554-B823-4E9C-BD1D-D070ACE6F181}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 | 
"{C0D2D2AC-20B1-49AF-A2B7-47A9F85E9B73}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{C2AA8F23-3191-44BB-9020-414BD22D1F90}" = rport=138 | protocol=17 | dir=out | app=system | 
"{CEB3F94B-B6B6-4F73-BB75-FAF9F4F530CD}" = rport=137 | protocol=17 | dir=out | app=system | 
"{D6D977A2-0C23-4CD2-8D92-72912B4840BE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{F01F1118-11D5-4760-83EA-60D43E776642}" = rport=139 | protocol=6 | dir=out | app=system | 
"{FAEC9D7A-B3B3-4DA9-B8EF-344C33A3F67E}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08CE1711-8704-4CC7-AC52-1C40FF0CA3AA}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe | 
"{08FE1B23-1FC8-412F-A466-4EF5F900D581}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe | 
"{0E33644F-0B26-4CEE-B84C-96127676F15C}" = protocol=58 | dir=out | [email protected],-28546 | 
"{10D537A1-7144-4088-992D-3257FA766389}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe | 
"{113B8732-8C09-4E4A-B6A3-C77B200EECDA}" = dir=in | name=@{ad2f1837.gettingstartedwithwindows8_1.5.3.1_neutral__v10z8vjag6ke6?ms-resource://ad2f1837.gettingstartedwithwindows8/resources/id_app_title} | 
"{13B79183-7DC0-46D0-956B-291AB32A605C}" = dir=out | name=@{microsoft.bingtravel_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | 
"{172171E2-7CDA-4AD0-A13E-4694B45F562D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{1E4C6B4A-6A0F-4063-984E-EC49F243AA32}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe | 
"{21C84F92-5031-43A4-A0F3-B8F9F6091FA3}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe | 
"{24D611BA-7725-4D03-9216-DBC92863A696}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{24DDAEAF-2C1D-48E8-AAB5-F5FEF34E3A62}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 
"{255E0547-D9EA-43E1-AB5D-6669B2382159}" = dir=out | name=f5 vpn | 
"{25C8A201-E210-4ECD-85A4-6A586E15AD9D}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe | 
"{25E8A6FE-722B-455B-9B12-17B639360951}" = dir=in | name=juniper networks junos pulse | 
"{2DAA9999-4782-4B09-84D0-9DB58E3CB5CF}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe | 
"{2F2C3D6A-4EB9-477C-83C6-3CE6E42D003D}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | 
"{345B61BD-9116-47EC-92D4-BE568F30184F}" = dir=in | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | 
"{357DFCD4-0ACB-465C-A33A-B866F8FAA0FA}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | 
"{35E7CC8E-F6AB-4AEF-A245-1EE103394940}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{39C5E0D7-DE80-4592-AA93-C78D17674D2B}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe | 
"{3E55BABC-EBA6-4122-94FC-D8A14816D3C1}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe | 
"{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | 
"{44575F79-9D29-4A8C-AD2A-E6A5CE77D132}" = dir=out | name=youcam for hp | 
"{44DD8693-3CAA-4CED-AA76-38E80EAD6254}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | 
"{45661DB7-DDA2-44AC-9528-3E7464626930}" = dir=out | name=hp registration | 
"{477C764A-E184-4F26-979D-27DE756BA5A8}" = dir=out | name=hp connected photo | 
"{48233BA4-DE9A-4E8F-A1B5-A133DA439D2C}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{53A83570-4DE4-4A2B-A706-BFD971B8B11A}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{54F91CC8-203B-4E95-B2F4-D4DAC7C5FCEC}" = dir=out | name=@{microsoft.reader_6.2.9200.20780_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | 
"{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | 
"{57896D57-939C-4AB2-AB76-1161207BC58C}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | 
"{58EA2CB0-7C3F-4314-A53B-5C14BE8ABAEC}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | 
"{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | 
"{65646F9F-F7CF-4173-82F6-F96A56D5D6DF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{6686047E-8A32-48CB-8F5F-042965DD3414}" = dir=out | name=windows_ie_ac_001 | 
"{66D33754-1689-4888-90B6-393E100E1C4A}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe | 
"{73D4DF84-4EF8-4F92-9BD9-1C7C05AEA616}" = dir=out | name=skype | 
"{74E857F7-EC5D-4870-9791-2F3D61ADC523}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{765C474C-F2E0-4F47-9647-E482E2EE874A}" = dir=out | name=@{microsoft.bingfinance_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | 
"{7915803E-509A-4438-B6BF-307C250634C4}" = dir=out | name=@{microsoft.zunemusic_2.6.476.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | 
"{7BB8FDDD-718A-4528-9F7C-9E3E066A3B5C}" = dir=out | name=sonicwall mobile connect | 
"{7DEC8933-DEF6-482A-B168-B09D23028FFE}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe | 
"{808DE0B0-AB3C-4EA7-A7A2-2076C2E1AE5B}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | 
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{83C2C7CD-AEAD-4561-B541-8FF6248AEC29}" = dir=out | name=@{microsoft.bingsports_3.0.4.244_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} | 
"{85B1B5FC-622B-498E-86FC-9E94B69E7B44}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{8A6210F6-955E-4DF1-A914-A9AADBA98C1B}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{9186E810-862E-4681-9A8A-B2D54A561865}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{93AA9D34-E8C9-4EF0-AA69-6BEB6A806F24}" = dir=in | name=onenote | 
"{95A2F9AF-C4FB-42F1-9821-2756FC8217DA}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{98ACDA78-2A59-4E27-8775-75B68BBAF0A9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{99B87A08-3C01-46AE-9D0B-A700705D3027}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{9AF0E1B4-1460-46F6-9C49-96C6AC381C09}" = dir=out | name=@{microsoft.bingmaps_1.6.1821.2624_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | 
"{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{9ECDE6CE-068E-4619-B158-49B1674C0CCB}" = dir=out | name=check point vpn | 
"{A2B347A5-C939-41C9-94A5-7D76F5C77D4B}" = protocol=58 | dir=in | [email protected],-28545 | 
"{A4CD94E7-7A36-4232-8277-B19E97DD1761}" = dir=out | name=windows_ie_ac_001 | 
"{A534D0BC-03EE-4AC8-B18E-B365214C00AD}" = dir=out | name=@{microsoft.zunevideo_1.5.902.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | 
"{A53D6672-1C37-428D-8E8C-2923C9874226}" = dir=out | name=@{microsoft.bingnews_3.0.4.213_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | 
"{A5DEEC77-5EDC-4B50-AC53-C221F0489EBD}" = dir=out | name=@{microsoft.xboxlivegames_1.3.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | 
"{A6B5B385-F1CD-46B8-B380-A50C26CB21D6}" = dir=in | name=check point vpn | 
"{A980DD63-2223-432A-BAD0-E51922E88300}" = protocol=1 | dir=in | [email protected],-28543 | 
"{A9A554ED-F3B2-408D-8C6F-2348ACC65959}" = dir=out | name=@{microsoft.zunemusic_1.5.216.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | 
"{AC1D9BE3-2180-4623-B307-B6C9F8BCD50B}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe | 
"{B8659075-0F04-4841-9600-1A2C41E1BCE2}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe | 
"{BBEFA3FF-3D92-49C4-BE0E-0A89BEF7085C}" = dir=in | name=hp connected photo | 
"{BD16F47C-7A96-4088-B7A1-8CC0551766BC}" = dir=out | name=@{microsoft.bingsports_2.0.0.310_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | 
"{BF7C2C2A-579E-4A62-9ABE-257C4B07854C}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | 
"{C1079000-73D0-461F-98D1-17D9562FEFCB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{C5001876-E781-4991-A913-199E3A8565DD}" = dir=out | name=@{microsoft.bingweather_3.0.4.249_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} | 
"{C5E7EBB7-2FF3-4597-BDED-BE8920FB7A5A}" = dir=out | name=@{ad2f1837.gettingstartedwithwindows8_1.5.3.1_neutral__v10z8vjag6ke6?ms-resource://ad2f1837.gettingstartedwithwindows8/resources/id_app_title} | 
"{C7765231-F3AC-41E0-BE65-0F28A285813A}" = dir=out | name=juniper networks junos pulse | 
"{CA37ABD2-EAF0-4397-A934-D81829E3FB1B}" = dir=out | name=hp games | 
"{CBF5DC9A-181B-44FA-9970-77A95173A008}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{CCBA2DD6-68E4-45EE-826C-5A10EDB07040}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{CE99D1BD-79D7-4260-93BD-E8C90FAC6584}" = dir=out | name=@{microsoft.bingnews_2.0.0.308_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | 
"{D0C5E3FF-BF13-4D5F-AC9B-2045FAB03CE9}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{D31BD5EC-996E-4A4C-8B51-8D696F474B8F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{D464D8D6-7D81-43DA-8809-1E17200ABA99}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{D4B1C6B9-D53D-4C01-A1B4-FE11163D4F02}" = protocol=6 | dir=out | app=system | 
"{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | 
"{D960F2C6-A386-4AE4-ADD6-016ED53DAB91}" = dir=out | name=@{microsoft.bingtravel_2.0.0.319_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | 
"{D99A75FE-F450-463F-9E33-CDC33243B079}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{DA8F4E99-0DEB-481C-BD00-062F32A18376}" = dir=in | name=f5 vpn | 
"{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | 
"{E00EFDDD-80BF-4E89-BEF5-8B03553A9F9F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E0EF46DD-CC2F-46BA-9271-8F2FF1829378}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{E450A32F-CB75-4FA2-81E3-A04F403F54A2}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} | 
"{E49274E4-5E8D-47A1-8D4A-89F6210EEC82}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe | 
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{E856AF8D-8862-4A67-8C3D-E27DD101B9C5}" = dir=in | name=skype | 
"{EB5F9BFC-EA30-4A69-AAEC-976CDC76CBC9}" = dir=in | name=sonicwall mobile connect | 
"{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | 
"{EDA2E918-3EB8-4C48-9612-ADCCB8E87B0F}" = dir=out | name=windows_ie_ac_001 | 
"{EFFAD252-718D-4766-8254-11831F5A50A9}" = dir=out | name=@{microsoft.bingfinance_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} | 
"{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | 
"{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | 
"{F9660310-E284-402B-BB17-A02B7ADBBD35}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{FA22F356-268F-4C99-8819-22A2DA547198}" = protocol=1 | dir=out | [email protected],-28544 | 
"{FC997EB0-5C82-4ED8-AE39-E79076C88DF1}" = dir=out | name=@{microsoft.zunevideo_2.6.408.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | 
"{FDB834E1-2255-4620-83B4-F4187DE79115}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe | 
"{FF5D204F-ED48-401F-9884-C1192A4035AB}" = dir=out | name=onenote | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08257488-8829-46D4-892A-BEC4B4785B95}" = AVG 2014
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{4B3EF5E6-9A2C-0A1B-C61C-B1FD444B84BC}" = ccc-utility64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{50268784-08D9-2A2F-9ECE-EADFC45DC50C}" = ccc-utility64
"{6BDFBC8B-558B-471C-B668-33178CEBA2F3}" = AVG 2014
"{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}" = HP Postscript Converter
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{73237EBB-B26F-4628-8754-4EFE563D72E9}" = HP Utility Center
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9CBEB415-30E0-B748-8FAB-0575E433E9DE}" = AMD Fuel
"{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727
"{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64)
"{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727
"{CB4C08E3-800F-65F6-9C00-06814A6B7CE7}" = AMD Catalyst Install Manager
"{D1E8F2D7-7794-4245-B286-87ED86C1893C}" = HP Registration Service
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{E7ACB435-E0B4-4770-77DE-ED38887CD133}" = AMD Fuel
"{E9F0BCD8-6BD5-1ED7-EDA3-9FCF2A478AA1}" = Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64)
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"AVG" = AVG 2014
"SynTPDeinstKey" = Synaptics Pointing Device Driver
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01BD4FC9-2F86-4706-A62E-774BB7E9D308}" = AVG PC TuneUp 2014
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{070232F8-068B-1FF6-B5C4-F8F38E09C7E1}" = CCC Help Turkish
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0B4A6673-753A-9533-45BA-1F355715D9FC}" = CCC Help English
"{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}" = Realtek PCIE Card Reader
"{104DE091-6C4F-C5A9-F619-5D6C965A0296}" = CCC Help Chinese Traditional
"{108B9AEB-5E19-1A4D-BE19-4856C0DCE6F3}" = CCC Help Thai
"{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
"{1AE37508-089E-41AC-95BD-99FF06887C2F}" = HP Recovery Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10
"{1FE80340-264B-4374-8F1C-252931AB3C6A}" = CCC Help Japanese
"{25A3B953-1423-3F15-640E-B620DD0F419A}" = Catalyst Control Center - Branding
"{285C9F30-3BF8-697B-BD1D-353435E94B78}" = CCC Help Hungarian
"{29967A7C-6E18-91CD-BBE4-9C09F401E950}" = CCC Help Italian
"{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8
"{30B2D1D8-0A07-4B71-9553-0710C5D31E35}" = HP Wireless Button Driver
"{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{34C4C52E-E614-E554-2536-0ABAA2D68CE4}" = CCC Help Russian
"{35D41250-CC6E-D266-4A00-958F52562A20}" = CCC Help Korean
"{3D10A855-D379-A188-EE50-64548E1B1976}" = CCC Help Italian
"{3E2EE595-F2BD-8D77-EA86-5B48D407D548}" = Catalyst Control Center InstallProxy
"{4780D5B0-1CE0-CE1A-2F0A-047D12ED04E3}" = CCC Help Czech
"{49110532-D289-4BFF-807C-45B782E66A7C}" = Photo Common
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{5342F310-0B71-761E-48AC-4FBB9D4AD080}" = Catalyst Control Center Localization All
"{54D05374-2428-7BE0-58CD-CE8031163DE6}" = CCC Help Russian
"{574F0207-8E98-46CD-8F79-318348C98C46}" = HP Quick Start
"{5C6AFE98-08BF-086A-300D-18F77D284966}" = CCC Help Swedish
"{5C757800-27E8-2AE3-889A-8B959AE689F8}" = CCC Help Japanese
"{5D2B5E19-C333-4519-3D32-AAB8EEE9ACA4}" = AMD Catalyst Control Center
"{5D3EC645-B957-36A1-068A-FE8450963669}" = CCC Help Spanish
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{61B90A4D-8CC9-2FED-2495-AC8C9467C984}" = CCC Help Norwegian
"{63824BC0-B747-43F3-9863-1066D64AD919}" = Photo Gallery
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{6CEA775F-E70A-4D72-A3B4-1EB3A5AD4B5C}" = Windows Live Essentials
"{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{77750E8C-A73A-1DEE-DA3E-6B6FB768A4C0}" = CCC Help Chinese Standard
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.16
"{7B902CB5-6016-71B6-7388-33D8BDD58D4A}" = CCC Help German
"{7C5B13DA-6A68-86C7-ED29-610CA0F49555}" = CCC Help French
"{7F1EE4DD-4801-DDF7-1083-0AF6C246EA61}" = CCC Help Turkish
"{80680785-2EE1-053F-9CD3-4B2C904596EE}" = Catalyst Control Center InstallProxy
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8A96F685-A07B-2546-54A6-4CCBD119FA41}" = CCC Help Finnish
"{8C1ADF61-4F87-44BC-804C-C20FC70D98BB}" = HP Documentation
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8E6E8CBB-8E58-493C-943F-4664F5F2FEDB}" = Movie Maker
"{95B8F519-8C35-9010-A63C-51B3E0EE8D4E}" = CCC Help Dutch
"{967A3B08-DEC2-4C28-981F-96E86179FA4B}" = AVG PC TuneUp 2014 (en-GB)
"{97D1CCA5-296D-361F-7A5C-D33B7653EDF5}" = CCC Help Norwegian
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3806AB7-AB46-7672-A825-F9AE0DE6910A}" = CCC Help Finnish
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AD59E2EF-0022-6194-C57D-8A3B9140E13F}" = CCC Help Greek
"{AED76532-7302-D855-4780-DB177924E005}" = CCC Help French
"{B079957C-3276-4B9F-DB08-D1CA8C090D9E}" = CCC Help Greek
"{B12BE177-DC00-5746-3AB9-91CD090AF555}" = Catalyst Control Center Localization All
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B27332E6-6781-8804-2355-CB678E218065}" = CCC Help Chinese Traditional
"{B7BF553F-6C08-42DA-FDB2-49C9467070D9}" = CCC Help Spanish
"{BBFFE0C6-CDB9-AD66-18AA-F88D28DAC4C0}" = CCC Help Hungarian
"{BD3F9DD5-C3A6-3CA1-8523-6121F30781DC}" = CCC Help Swedish
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{BF5509A0-250A-25EA-0C19-61505E9EBA13}" = CCC Help Chinese Standard
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Qualcomm Atheros Driver Installation Program
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C4EE2BA3-EEA5-9650-86E0-0405ECA5C22C}" = CCC Help Thai
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C69EA753-0D3F-E48B-8C98-7F6310DC29B8}" = CCC Help German
"{C78E8F51-3EAD-4F0C-83F0-EF371075E0B4}" = HP System Event Utility
"{C89A97B6-F991-EBB5-77B7-927BCF420EBE}" = OEM Application Profile
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{D2993435-FC5D-DFA8-67CB-586957B9302F}" = CCC Help Portuguese
"{D65D424F-72E7-09A3-4BD4-52331A919873}" = CCC Help Danish
"{DB751A71-541C-176C-6DBC-13C061769FA1}" = AMD VISION Engine Control Center
"{DE0887C8-0A44-2CAA-40EB-340BEE05B0D0}" = Catalyst Control Center Graphics Previews Common
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{EB766D4A-C56C-946D-F74D-43C78FE4521E}" = CCC Help Korean
"{EC63AB5A-9694-DA16-6942-43AA10BE5710}" = CCC Help Dutch
"{ED0D7699-1943-0C29-7465-6530F8DE2DA2}" = CCC Help Polish
"{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker
"{EDA5BB56-AAF4-6889-AD8E-E25A17BD140B}" = CCC Help Czech
"{EEEDA52B-3C42-4BD7-BE42-FDB596EAFCEF}" = Catalyst Control Center - Branding
"{EEF14371-2D24-5A2D-0EF2-22010DB4CFA6}" = CCC Help Danish
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F21F0424-B2FF-40BF-A984-9E0D7FB4C97E}" = Windows Live UX Platform Language Pack
"{F4B9B49F-20C7-6FD5-2973-787322D4B53B}" = CCC Help Polish
"{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}" = Energy Star
"{FDD69799-37B2-9ACE-F70C-ABD1F96FD04C}" = CCC Help Portuguese
"{FDF2FE33-426D-45C2-4E70-76C162F1B790}" = CCC Help English
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AVG PC TuneUp" = AVG PC TuneUp 2014
"AVG SafeGuard toolbar" = AVG SafeGuard toolbar
"Google Chrome" = Google Chrome
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10
"InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.3.1025
"Revo Uninstaller" = Revo Uninstaller 1.95
"WinLiveSuite" = Windows Live Essentials
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"OneDriveSetup.exe" = Microsoft OneDrive
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 17/11/2014 03:28:37 | Computer Name = HomePC | Source = Application Error | ID = 1000
Description = Faulting application name: fixmapi.exe, version: 6.3.9600.16384, time
 stamp: 0x52158b32  Faulting module name: KERNELBASE.dll, version: 6.3.9600.17278,
 time stamp: 0x53eeb460  Exception code: 0xc06d007e  Fault offset: 0x00012f71  Faulting
 process ID: 0x23cc  Faulting application start time: 0x01d0023819bf2ec2  Faulting application
 path: C:\WINDOWS\SysWOW64\fixmapi.exe  Faulting module path: C:\WINDOWS\SYSTEM32\KERNELBASE.dll
Report
 ID: 57b0dd5c-6e2b-11e4-bea9-a4db307ef39c  Faulting package full name:   Faulting package-relative
 application ID: 
 
Error - 18/11/2014 02:51:20 | Computer Name = HomePC | Source = Application Error | ID = 1000
Description = Faulting application name: fixmapi.exe, version: 6.3.9600.16384, time
 stamp: 0x52158b32  Faulting module name: KERNELBASE.dll, version: 6.3.9600.17278,
 time stamp: 0x53eeb460  Exception code: 0xc06d007e  Fault offset: 0x00012f71  Faulting
 process ID: 0xe78  Faulting application start time: 0x01d002fc0eb1a3e6  Faulting application
 path: C:\WINDOWS\SysWOW64\fixmapi.exe  Faulting module path: C:\WINDOWS\SYSTEM32\KERNELBASE.dll
Report
 ID: 4cb405c4-6eef-11e4-bea9-a4db307ef39c  Faulting package full name:   Faulting package-relative
 application ID: 
 
Error - 18/11/2014 02:58:41 | Computer Name = HomePC | Source = Application Hang | ID = 1002
Description = The program IEXPLORE.EXE version 11.0.9600.17416 stopped interacting
 with Windows and was closed. To see if more information about the problem is available,
 check the problem history in the Action Center control panel.    Process ID: 2c20    Start
 Time: 01d002fc13274c68    Termination Time: 83    Application Path: C:\Program Files (x86)\Internet
 Explorer\IEXPLORE.EXE    Report Id: 5182c8bc-6ef0-11e4-bea9-a4db307ef39c    Faulting package
 full name:     Faulting package-relative application ID:   
 
Error - 18/11/2014 14:46:06 | Computer Name = HomePC | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17416,
 time stamp: 0x5452eed9  Faulting module name: MSHTML.dll, version: 11.0.9600.17416,
 time stamp: 0x545304c5  Exception code: 0xc0000005  Fault offset: 0x0038dc50  Faulting
 process ID: 0x2b8  Faulting application start time: 0x01d0035fcd929388  Faulting application
 path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE  Faulting module path:
 C:\WINDOWS\SYSTEM32\MSHTML.dll  Report ID: 26fd432c-6f53-11e4-bea9-a4db307ef39c  Faulting
 package full name:   Faulting package-relative application ID: 
 
Error - 20/11/2014 19:11:45 | Computer Name = HomePC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = Activation of application Microsoft.SkypeApp_kzf8qxf38zg5c!App failed
 with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional
 information.
 
Error - 20/11/2014 19:11:45 | Computer Name = HomePC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = Activation of application microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1
 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log
 for additional information.
 
Error - 20/11/2014 19:11:45 | Computer Name = HomePC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = Activation of application microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1
 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log
 for additional information.
 
Error - 21/11/2014 04:37:37 | Computer Name = HomePC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 21/11/2014 04:37:37 | Computer Name = HomePC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1703
 
Error - 21/11/2014 04:37:37 | Computer Name = HomePC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1703
 
[ System Events ]
Error - 14/11/2014 04:09:37 | Computer Name = HomePC | Source = DCOM | ID = 10010
Description = 
 
Error - 14/11/2014 04:10:07 | Computer Name = HomePC | Source = DCOM | ID = 10010
Description = 
 
Error - 14/11/2014 04:40:20 | Computer Name = HomePC | Source = DCOM | ID = 10010
Description = 
 
Error - 14/11/2014 04:40:51 | Computer Name = HomePC | Source = DCOM | ID = 10010
Description = 
 
Error - 14/11/2014 05:15:45 | Computer Name = HomePC | Source = DCOM | ID = 10010
Description = 
 
Error - 14/11/2014 05:16:19 | Computer Name = HomePC | Source = DCOM | ID = 10010
Description = 
 
Error - 14/11/2014 07:06:46 | Computer Name = HomePC | Source = DCOM | ID = 10010
Description = 
 
Error - 14/11/2014 07:07:17 | Computer Name = HomePC | Source = DCOM | ID = 10010
Description = 
 
Error - 14/11/2014 13:06:25 | Computer Name = HomePC | Source = DCOM | ID = 10010
Description = 
 
Error - 14/11/2014 13:06:55 | Computer Name = HomePC | Source = DCOM | ID = 10010
Description = 
 
 
< End of report >
 

 


  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
 
Download : ADWCleaner to your desktop.  Make sure you get the correct Download button.  Sometimes the ads on BleepingComputer will mimic the real Download button which should say: Download Now @BleepingComputer
 
NOTE: If using Internet Explorer and you get an alert that stops the program downloading, click on the warning and allow the download to complete.
 
Close  all programs, pause your anti-virus and run AdwCleaner (Vista or Win 7 => right click and Run As Administrator).
 
scan-results.jpg
 
Click on Scan  and follow the prompts. Let it run unhindered. When done, click on the Clean button, and follow the prompts. Allow the system to reboot. You will then be presented with the report. Copy & Paste this report on your next reply.
 
The report will be saved in the C:\AdwCleaner folder.
 
 
 
Junkware-Removal-Tool
 
Please download Junkware Removal Tool to your desktop.  Make sure you get the correct Download button.  Sometimes the ads on BleepingComputer will mimic the real Download button which should say: Download Now @Author's site
  • Pause your anti-virus.  Close all browsers.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
  •  
     
     
    Please download Farbar Recovery Scan Tool and save it to your Desktop. 
     
    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version. 
     
    •  
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer. 
  • Press Scan button. 
  • It will produce a log called FRST.txt in the same directory the tool is run from.  
  • Please copy and paste log back here. 
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply. 
  •  
    Ron

    • 0

    #3
    Steviep

    Steviep

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 338 posts

    Hi Ron, many thanks for helping here are the logs

     

    # AdwCleaner v4.102 - Report created 26/11/2014 at 19:27:35
    # Updated 23/11/2014 by Xplode
    # Database : 2014-11-26.1 [Live]
    # Operating System : Windows 8.1  (64 bits)
    # Username : Jack - HOMEPC
    # Running from : C:\Users\Jack\Desktop\AdwCleaner.exe
    # Option : Clean
     
    ***** [ Services ] *****
     
    Service Deleted : vToolbarUpdater18.1.9
     
    ***** [ Files / Folders ] *****
     
    Folder Deleted : C:\ProgramData\AVG SafeGuard toolbar
    Folder Deleted : C:\ProgramData\AVG Secure Search
    Folder Deleted : C:\ProgramData\AVG Security Toolbar
    Folder Deleted : C:\ProgramData\Systweak
    Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector
    Folder Deleted : C:\Program Files (x86)\AVG SafeGuard toolbar
    Folder Deleted : C:\Program Files (x86)\AVG Security Toolbar
    Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
    [!] Folder Deleted : C:\Users\Jack\AppData\Local\AVG SafeGuard toolbar
    Folder Deleted : C:\Users\Jack\AppData\Local\Systweak
    Folder Deleted : C:\Users\Jack\AppData\LocalLow\AVG SafeGuard toolbar
    Folder Deleted : C:\Users\Jack\AppData\Roaming\Systweak
    File Deleted : C:\WINDOWS\System32\roboot64.exe
     
    ***** [ Scheduled Tasks ] *****
     
    Task Deleted : Advanced System Protector_startup
     
    ***** [ Shortcuts ] *****
     
     
    ***** [ Registry ] *****
     
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
    Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
    Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
    Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
    Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
    Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
    Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
    Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
    Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
    Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
    Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
    Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    Key Deleted : HKCU\Software\AVG SafeGuard toolbar
    Key Deleted : HKCU\Software\Softonic
    Key Deleted : HKCU\Software\systweak
    Key Deleted : HKCU\Software\Vosteran Browser
    Key Deleted : HKLM\SOFTWARE\AVG SafeGuard toolbar
    Key Deleted : HKLM\SOFTWARE\AVG Security Toolbar
    Key Deleted : HKLM\SOFTWARE\systweak
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar
     
    ***** [ Browsers ] *****
     
    -\\ Internet Explorer v11.0.9600.17416
     
     
    -\\ Google Chrome v39.0.2171.65
     
    [C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://uk.ask.com/web?q={searchTerms}
    [C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ir_14_47_other&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyB0E0FtAzy0CyEzy0D0CtN0D0Tzu0StCtDyDyBtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyE0C0DtC0B0FtByBtG0CyB0D0AtGyB0E0BtCtGzzyB0E0EtGtBzyyB0ByEyCtB0EtD0AtCzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtA0DtD0FtDyB0DtG0AyEtB0CtGyEtByCyBtGzyzy0E0EtG0A0B0C0D0ByEtA0A0EyByDyC2Q&cr=1045722471&ir=
    [C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ir_14_47_other&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDyB0E0FtAzy0CyEzy0D0CtN0D0Tzu0StCtDyDyBtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyE0C0DtC0B0FtByBtG0CyB0D0AtGyB0E0BtCtGzzyB0E0EtGtBzyyB0ByEyCtB0EtD0AtCzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtA0DtD0FtDyB0DtG0AyEtB0CtGyEtByCyBtGzyzy0E0EtG0A0B0C0D0ByEtA0A0EyByDyC2Q&cr=1045722471&ir=
     
    *************************
     
    AdwCleaner[R0].txt - [7315 octets] - [26/11/2014 19:23:45]
    AdwCleaner[S0].txt - [7054 octets] - [26/11/2014 19:27:35]
     
    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7114 octets] ##########
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.3.9 (11.15.2014:2)
    OS: Windows 8.1 x64
    Ran by Jack on 26/11/2014 at 19:35:23.98
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     
     
     
     
    ~~~ Services
     
     
     
    ~~~ Registry Values
     
     
     
    ~~~ Registry Keys
     
     
     
    ~~~ Files
     
     
     
    ~~~ Folders
     
     
     
    ~~~ Event Viewer Logs were cleared
     
     
     
     
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 26/11/2014 at 19:51:40.58
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     
     
    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-11-2014 01
    Ran by Jack (administrator) on HOMEPC on 26-11-2014 19:56:02
    Running from C:\Users\Jack\Desktop
    Loaded Profile: Jack (Available profiles: Jack)
    Platform: Windows 8.1 (X64) OS Language: English (United Kingdom)
    Internet Explorer Version 11
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
     
    ==================== Processes (Whitelisted) =================
     
    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
     
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
    (AMD) C:\Windows\System32\atiesrxx.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
    (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
    (Windows ® Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
    (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
    (Microsoft Corporation) C:\Windows\System32\dasHost.exe
    (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
    (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
    (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
    (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    () C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
     
     
    ==================== Registry (Whitelisted) ==================
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
     
    HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3030256 2013-05-16] (Synaptics Incorporated)
    HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-10-08] (Hewlett-Packard Development Company, L.P.)
    HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
    HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5188112 2014-11-07] (AVG Technologies CZ, s.r.o.)
    HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [133248 2013-05-16] ( (Qualcomm Atheros Commnucations))
    HKU\S-1-5-21-2762176236-1622541777-3508687700-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.)
    HKU\S-1-5-21-2762176236-1622541777-3508687700-1002\...\MountPoints2: {216bd520-50b0-11e3-be73-806e6f6e6963} - "E:\SETUP.EXE" 
    ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
    ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
    ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
     
    ==================== Internet (Whitelisted) ====================
     
    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
     
    HKU\S-1-5-21-2762176236-1622541777-3508687700-1002\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
    HKU\S-1-5-21-2762176236-1622541777-3508687700-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM13/2
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPCOM13/2
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPCOM13/2
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=CMNTDFJS
    SearchScopes: HKLM -> {02D2F928-28C8-443F-BACE-BF0A94B5864B} URL = http://www.amazon.co...s={searchTerms}
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=CMNTDFJS
    SearchScopes: HKLM -> {8C34C59A-AAAD-4F25-A91A-26FF9664067C} URL = http://www.amazon.co...s={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=CMNTDFJS
    SearchScopes: HKLM-x32 -> {02D2F928-28C8-443F-BACE-BF0A94B5864B} URL = http://www.amazon.co...s={searchTerms}
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=CMNTDFJS
    SearchScopes: HKLM-x32 -> {8C34C59A-AAAD-4F25-A91A-26FF9664067C} URL = http://www.amazon.co...s={searchTerms}
    SearchScopes: HKU\S-1-5-21-2762176236-1622541777-3508687700-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-21-2762176236-1622541777-3508687700-1002 -> {02D2F928-28C8-443F-BACE-BF0A94B5864B} URL = http://www.amazon.co...s={searchTerms}
    SearchScopes: HKU\S-1-5-21-2762176236-1622541777-3508687700-1002 -> {8C34C59A-AAAD-4F25-A91A-26FF9664067C} URL = http://www.amazon.co...s={searchTerms}
    SearchScopes: HKU\S-1-5-21-2762176236-1622541777-3508687700-1002 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...9550-11896-25/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
    BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
    BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
    Toolbar: HKU\S-1-5-21-2762176236-1622541777-3508687700-1002 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
    Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
    Tcpip\Parameters: [DhcpNameServer] 194.168.4.100 194.168.8.100
     
    FireFox:
    ========
    FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
    FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
     
    Chrome: 
    =======
    CHR Profile: C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Slides) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-24]
    CHR Extension: (Google Docs) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-24]
    CHR Extension: (Google Drive) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-24]
    CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-24]
    CHR Extension: (YouTube) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-24]
    CHR Extension: (Google Search) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-24]
    CHR Extension: (Google Sheets) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-24]
    CHR Extension: (Google Wallet) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-24]
    CHR Extension: (Gmail) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-24]
     
    ==================== Services (Whitelisted) =================
     
    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
     
    R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
    R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [310912 2013-05-16] (Windows ® Win 7 DDK provider)
    R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3247120 2014-11-07] (AVG Technologies CZ, s.r.o.)
    R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-11-07] (AVG Technologies CZ, s.r.o.)
    R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
    R2 HPWMISVC; c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-10-08] (Hewlett-Packard Development Company, L.P.)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
    R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [239176 2013-03-04] (Realtek Semiconductor)
    R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2253112 2014-07-14] (AVG)
    S2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [42808 2014-07-14] (AVG)
    S2 UxTuneUp; C:\Windows\SysWOW64\uxtuneup.dll [35640 2014-07-14] (AVG)
    S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-11-04] (Microsoft Corporation)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
    R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-05-16] (Atheros) [File not signed]
     
    ==================== Drivers (Whitelisted) ====================
     
    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
     
    R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [94208 2013-02-14] (Advanced Micro Devices)
    S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
    R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
    R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.)
    R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
    R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [237848 2014-10-24] (AVG Technologies CZ, s.r.o.)
    R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
    R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-10-29] (AVG Technologies CZ, s.r.o.)
    R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
    R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-08-12] (AVG Technologies)
    R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [270104 2014-06-30] (AVG Technologies CZ, s.r.o.)
    R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-05-16] (Qualcomm Atheros)
    R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-09-24] (Microsoft Corporation)
    R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
    R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2014-11-26] (Malwarebytes Corporation)
    R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-10-01] (Malwarebytes Corporation)
    R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [288328 2013-01-24] (Realtek Semiconductor Corp.)
    S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [29424 2013-05-08] (Synaptics Incorporated)
    S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [33008 2013-05-08] (Synaptics Incorporated)
    R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-03-26] (TuneUp Software)
    S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
    R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
     
    ==================== NetSvcs (Whitelisted) ===================
     
    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
     
     
    ==================== One Month Created Files and Folders ========
     
    (If an entry is included in the fixlist, the file\folder will be moved.)
     
    2014-11-26 19:56 - 2014-11-26 19:56 - 00016811 _____ () C:\Users\Jack\Desktop\FRST.txt
    2014-11-26 19:55 - 2014-11-26 19:56 - 00000000 ____D () C:\FRST
    2014-11-26 19:54 - 2014-11-26 19:54 - 02117632 _____ (Farbar) C:\Users\Jack\Desktop\FRST64.exe
    2014-11-26 19:51 - 2014-11-26 19:51 - 00000613 _____ () C:\Users\Jack\Desktop\JRT.txt
    2014-11-26 19:35 - 2014-11-26 19:35 - 00000000 ____D () C:\WINDOWS\ERUNT
    2014-11-26 19:33 - 2014-11-26 19:33 - 01707532 _____ (Thisisu) C:\Users\Jack\Desktop\JRT.exe
    2014-11-26 19:31 - 2014-11-26 19:31 - 00007218 _____ () C:\Users\Jack\Desktop\AdwCleaner[S0].txt
    2014-11-26 19:31 - 2014-11-26 19:31 - 00000000 ___RD () C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
    2014-11-26 19:23 - 2014-11-26 19:27 - 00000000 ____D () C:\AdwCleaner
    2014-11-26 19:21 - 2014-11-26 19:21 - 02148864 _____ () C:\Users\Jack\Desktop\AdwCleaner.exe
    2014-11-25 19:55 - 2014-11-25 19:55 - 00078930 _____ () C:\Users\Jack\Desktop\Extras.Txt
    2014-11-25 19:54 - 2014-11-25 19:54 - 00131724 _____ () C:\Users\Jack\Desktop\OTL.Txt
    2014-11-25 19:53 - 2014-11-25 19:53 - 00078930 _____ () C:\Users\Jack\Downloads\Extras.Txt
    2014-11-25 19:51 - 2014-11-25 19:51 - 00131724 _____ () C:\Users\Jack\Downloads\OTL.Txt
    2014-11-25 19:20 - 2014-11-25 19:20 - 00602112 _____ (OldTimer Tools) C:\Users\Jack\Downloads\OTL.exe
    2014-11-25 18:39 - 2014-11-25 18:39 - 00001251 _____ () C:\Users\Jack\Desktop\Revo Uninstaller.lnk
    2014-11-25 18:39 - 2014-11-25 18:39 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
    2014-11-25 18:21 - 2014-11-26 19:30 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2014-11-25 18:21 - 2014-11-25 18:21 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\4F4061F6.sys
    2014-11-25 18:20 - 2014-11-25 18:20 - 00001085 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2014-11-25 18:20 - 2014-11-25 18:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2014-11-25 18:20 - 2014-11-25 18:20 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2014-11-25 18:20 - 2014-11-25 18:20 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-11-25 18:20 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2014-11-25 18:20 - 2014-10-01 11:11 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
    2014-11-25 18:20 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
    2014-11-25 18:18 - 2014-11-25 18:18 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Jack\Downloads\mbam-setup-2.0.3.1025.exe
    2014-11-24 23:06 - 2014-11-24 23:06 - 00000000 ____D () C:\ProgramData\Lavasoft
    2014-11-24 22:38 - 2014-11-24 22:41 - 00000000 ____D () C:\Users\Jack\Desktop\jacks stuff
    2014-11-24 21:20 - 2014-11-24 21:20 - 00002246 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2014-11-24 21:20 - 2014-11-24 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2014-11-24 21:12 - 2014-11-26 19:30 - 00000904 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2014-11-24 21:12 - 2014-11-25 21:17 - 00000908 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2014-11-24 21:12 - 2014-11-24 21:21 - 00000000 ____D () C:\Users\Jack\AppData\Local\Google
    2014-11-24 21:12 - 2014-11-24 21:20 - 00000000 ____D () C:\Program Files (x86)\Google
    2014-11-24 21:12 - 2014-11-24 21:12 - 00003880 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
    2014-11-24 21:12 - 2014-11-24 21:12 - 00003644 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
    2014-11-24 21:11 - 2014-11-24 21:12 - 00000000 ____D () C:\Users\Jack\AppData\Local\Deployment
    2014-11-24 21:11 - 2014-11-24 21:11 - 00000000 ____D () C:\Users\Jack\AppData\Local\Apps\2.0
    2014-11-24 20:28 - 2014-11-24 20:28 - 00000000 _____ () C:\autoexec.bat
    2014-11-24 20:20 - 2014-11-24 20:20 - 00000000 ____D () C:\Program Files\Enigma Software Group
    2014-11-24 12:06 - 2014-11-24 21:08 - 00000000 ____D () C:\WINDOWS\AutoKMS
    2014-11-24 12:06 - 2014-11-24 12:06 - 00003758 _____ () C:\WINDOWS\System32\Tasks\AutoKMS
    2014-11-24 12:05 - 2014-11-24 12:05 - 00000000 ____D () C:\ProgramData\Microsoft Toolkit
    2014-11-23 13:15 - 2014-11-24 19:15 - 00000069 _____ () C:\Users\Jack\AppData\Roaming\WB.CFG
    2014-11-23 12:12 - 2014-11-23 12:13 - 00762984 _____ ( ) C:\Users\Jack\Downloads\Malavida_Download_Manager.exe
    2014-11-23 12:04 - 2014-11-23 12:04 - 00000000 ___RD () C:\Users\Jack\Creative Cloud Files
    2014-11-23 12:02 - 2014-11-23 12:07 - 00000000 ____D () C:\ProgramData\Adobe
    2014-11-23 11:58 - 2014-11-24 07:22 - 00000000 ____D () C:\Program Files (x86)\Adobe
    2014-11-23 11:55 - 2014-11-24 07:16 - 00000000 ____D () C:\Users\Jack\AppData\Local\Adobe
    2014-11-23 11:54 - 2014-11-23 12:13 - 00672432 _____ (Adobe Systems Incorporated) C:\Users\Jack\Downloads\CreativeCloudSet-Up.exe
    2014-11-21 09:17 - 2014-11-21 09:17 - 00000000 ____D () C:\WINDOWS\PCHEALTH
    2014-11-21 09:11 - 2014-11-25 19:25 - 00000000 ____D () C:\ProgramData\Microsoft Help
    2014-11-21 09:11 - 2014-11-25 19:24 - 00000000 ____D () C:\Program Files\Microsoft Office
    2014-11-21 09:11 - 2014-11-21 09:11 - 00000000 ____D () C:\Users\Jack\AppData\Local\Microsoft Help
    2014-11-19 06:26 - 2014-11-09 23:19 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2014-11-19 06:26 - 2014-11-09 23:19 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2014-11-19 06:26 - 2014-11-09 23:18 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
    2014-11-19 06:26 - 2014-11-09 23:18 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
    2014-11-15 07:28 - 2014-11-21 09:21 - 00035840 ___SH () C:\Users\Jack\Desktop\Thumbs.db
    2014-11-13 07:31 - 2014-11-13 07:31 - 00000000 __SHD () C:\Users\Jack\AppData\Local\EmieBrowserModeList
    2014-11-12 09:08 - 2014-09-22 04:38 - 01519488 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
    2014-11-12 09:08 - 2014-09-22 03:06 - 00258368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
    2014-11-12 09:08 - 2014-09-22 03:06 - 00114496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
    2014-11-12 09:08 - 2014-09-22 02:49 - 00035320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
    2014-11-12 09:08 - 2014-09-19 00:16 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
    2014-11-12 09:08 - 2014-09-02 22:08 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
    2014-11-12 09:08 - 2014-09-02 22:08 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll
    2014-11-12 09:07 - 2014-11-04 23:38 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
    2014-11-12 09:07 - 2014-11-04 00:10 - 00304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
    2014-11-12 09:07 - 2014-10-31 04:53 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
    2014-11-12 09:07 - 2014-10-31 04:49 - 00537088 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
    2014-11-12 09:07 - 2014-10-31 04:24 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
    2014-11-12 09:07 - 2014-10-13 02:33 - 00116032 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
    2014-11-12 09:07 - 2014-10-11 00:58 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
    2014-11-12 09:07 - 2014-10-11 00:53 - 03607040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
    2014-11-12 09:07 - 2014-10-08 07:30 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
    2014-11-12 09:07 - 2014-10-08 07:09 - 00428032 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll
    2014-11-12 09:07 - 2014-10-08 06:27 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msihnd.dll
    2014-11-12 09:07 - 2014-10-08 05:32 - 02773504 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
    2014-11-12 09:07 - 2014-10-08 05:19 - 02459136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
    2014-11-12 07:41 - 2014-09-27 07:13 - 00104336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
    2014-11-12 07:41 - 2014-09-27 05:24 - 00088800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
    2014-11-12 07:41 - 2014-09-27 03:38 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
    2014-11-12 07:41 - 2014-09-27 03:30 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
    2014-11-12 07:41 - 2014-09-27 03:17 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
    2014-11-12 07:40 - 2014-10-10 01:58 - 00177472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
    2014-11-12 07:40 - 2014-10-10 01:58 - 00027456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
    2014-11-12 07:40 - 2014-10-10 01:44 - 00563976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2014-11-12 07:40 - 2014-10-08 07:37 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
    2014-11-12 07:40 - 2014-10-08 07:37 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
    2014-11-12 07:40 - 2014-10-08 07:34 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
    2014-11-12 07:40 - 2014-10-08 07:24 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
    2014-11-12 07:40 - 2014-10-08 06:56 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
    2014-11-12 07:40 - 2014-10-08 06:51 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
    2014-11-12 07:40 - 2014-10-08 06:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
    2014-11-12 07:40 - 2014-10-08 06:18 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
    2014-11-12 07:40 - 2014-10-08 06:17 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2014-11-12 07:40 - 2014-10-08 05:23 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
    2014-11-12 07:39 - 2014-10-18 09:55 - 00055776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
    2014-11-12 07:39 - 2014-10-18 08:09 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
    2014-11-12 07:39 - 2014-10-18 08:09 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
    2014-11-12 07:39 - 2014-10-18 07:25 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
    2014-11-12 07:39 - 2014-10-18 06:50 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaext.dll
    2014-11-12 07:39 - 2014-10-18 06:38 - 03557376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2014-11-12 07:39 - 2014-10-18 06:27 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
    2014-11-12 07:39 - 2014-10-18 06:26 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
    2014-11-12 07:39 - 2014-10-18 06:23 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
    2014-11-12 07:39 - 2014-10-18 06:23 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
    2014-11-12 07:39 - 2014-10-18 06:21 - 00894976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
    2014-11-12 07:39 - 2014-10-18 06:20 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
    2014-11-12 07:39 - 2014-10-18 06:14 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
    2014-11-12 07:39 - 2014-10-18 06:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
    2014-11-12 07:39 - 2014-10-18 06:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
    2014-11-12 07:39 - 2014-10-18 06:11 - 00723968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
    2014-11-12 07:39 - 2014-10-17 07:01 - 00789184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
    2014-11-12 07:39 - 2014-10-17 06:58 - 00602768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
    2014-11-12 07:38 - 2014-10-31 05:28 - 25110016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2014-11-12 07:38 - 2014-10-31 03:42 - 19781632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2014-11-12 07:34 - 2014-10-31 03:59 - 14390272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2014-11-12 07:33 - 2014-10-31 04:50 - 06040064 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2014-11-12 07:33 - 2014-10-31 02:46 - 04298240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2014-11-12 07:33 - 2014-10-31 02:30 - 12819456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2014-11-12 07:32 - 2014-10-31 05:12 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wextract.exe
    2014-11-12 07:32 - 2014-10-31 05:12 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshta.exe
    2014-11-12 07:32 - 2014-10-31 05:10 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iexpress.exe
    2014-11-12 07:32 - 2014-10-31 05:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pngfilt.dll
    2014-11-12 07:32 - 2014-10-31 05:08 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedssync.exe
    2014-11-12 07:32 - 2014-10-31 05:06 - 00580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2014-11-12 07:32 - 2014-10-31 05:06 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
    2014-11-12 07:32 - 2014-10-31 05:06 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
    2014-11-12 07:32 - 2014-10-31 05:06 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
    2014-11-12 07:32 - 2014-10-31 05:05 - 02884096 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2014-11-12 07:32 - 2014-10-31 05:05 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
    2014-11-12 07:32 - 2014-10-31 05:04 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
    2014-11-12 07:32 - 2014-10-31 04:57 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
    2014-11-12 07:32 - 2014-10-31 04:56 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
    2014-11-12 07:32 - 2014-10-31 04:54 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\IEAdvpack.dll
    2014-11-12 07:32 - 2014-10-31 04:53 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
    2014-11-12 07:32 - 2014-10-31 04:52 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
    2014-11-12 07:32 - 2014-10-31 04:51 - 00812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2014-11-12 07:32 - 2014-10-31 04:51 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
    2014-11-12 07:32 - 2014-10-31 04:51 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
    2014-11-12 07:32 - 2014-10-31 04:50 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
    2014-11-12 07:32 - 2014-10-31 04:40 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
    2014-11-12 07:32 - 2014-10-31 04:38 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
    2014-11-12 07:32 - 2014-10-31 04:30 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
    2014-11-12 07:32 - 2014-10-31 04:29 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
    2014-11-12 07:32 - 2014-10-31 04:29 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
    2014-11-12 07:32 - 2014-10-31 04:28 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\inseng.dll
    2014-11-12 07:32 - 2014-10-31 04:25 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
    2014-11-12 07:32 - 2014-10-31 04:24 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
    2014-11-12 07:32 - 2014-10-31 04:24 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
    2014-11-12 07:32 - 2014-10-31 04:23 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
    2014-11-12 07:32 - 2014-10-31 04:21 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
    2014-11-12 07:32 - 2014-10-31 04:19 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
    2014-11-12 07:32 - 2014-10-31 04:15 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
    2014-11-12 07:32 - 2014-10-31 04:08 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
    2014-11-12 07:32 - 2014-10-31 04:06 - 00372736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2014-11-12 07:32 - 2014-10-31 04:05 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2014-11-12 07:32 - 2014-10-31 04:05 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2014-11-12 07:32 - 2014-10-31 04:03 - 02124288 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2014-11-12 07:32 - 2014-10-31 03:45 - 02365440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2014-11-12 07:32 - 2014-10-31 03:44 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
    2014-11-12 07:32 - 2014-10-31 03:42 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\imgutil.dll
    2014-11-12 07:32 - 2014-10-31 03:32 - 01550336 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2014-11-12 07:32 - 2014-10-31 03:28 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wextract.exe
    2014-11-12 07:32 - 2014-10-31 03:28 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshta.exe
    2014-11-12 07:32 - 2014-10-31 03:27 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iexpress.exe
    2014-11-12 07:32 - 2014-10-31 03:26 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pngfilt.dll
    2014-11-12 07:32 - 2014-10-31 03:25 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedssync.exe
    2014-11-12 07:32 - 2014-10-31 03:24 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2014-11-12 07:32 - 2014-10-31 03:24 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\url.dll
    2014-11-12 07:32 - 2014-10-31 03:24 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
    2014-11-12 07:32 - 2014-10-31 03:23 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
    2014-11-12 07:32 - 2014-10-31 03:23 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
    2014-11-12 07:32 - 2014-10-31 03:22 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
    2014-11-12 07:32 - 2014-10-31 03:20 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
    2014-11-12 07:32 - 2014-10-31 03:18 - 02277376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2014-11-12 07:32 - 2014-10-31 03:16 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
    2014-11-12 07:32 - 2014-10-31 03:15 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
    2014-11-12 07:32 - 2014-10-31 03:14 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IEAdvpack.dll
    2014-11-12 07:32 - 2014-10-31 03:13 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
    2014-11-12 07:32 - 2014-10-31 03:13 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
    2014-11-12 07:32 - 2014-10-31 03:12 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2014-11-12 07:32 - 2014-10-31 03:12 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
    2014-11-12 07:32 - 2014-10-31 03:11 - 00620032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
    2014-11-12 07:32 - 2014-10-31 03:03 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licmgr10.dll
    2014-11-12 07:32 - 2014-10-31 03:02 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
    2014-11-12 07:32 - 2014-10-31 02:57 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
    2014-11-12 07:32 - 2014-10-31 02:56 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inseng.dll
    2014-11-12 07:32 - 2014-10-31 02:56 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
    2014-11-12 07:32 - 2014-10-31 02:56 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
    2014-11-12 07:32 - 2014-10-31 02:53 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
    2014-11-12 07:32 - 2014-10-31 02:53 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedsbs.dll
    2014-11-12 07:32 - 2014-10-31 02:52 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
    2014-11-12 07:32 - 2014-10-31 02:51 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
    2014-11-12 07:32 - 2014-10-31 02:50 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
    2014-11-12 07:32 - 2014-10-31 02:48 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\occache.dll
    2014-11-12 07:32 - 2014-10-31 02:46 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
    2014-11-12 07:32 - 2014-10-31 02:42 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
    2014-11-12 07:32 - 2014-10-31 02:40 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2014-11-12 07:32 - 2014-10-31 02:40 - 00325632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2014-11-12 07:32 - 2014-10-31 02:39 - 02051072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2014-11-12 07:32 - 2014-10-31 02:26 - 01042944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
    2014-11-12 07:32 - 2014-10-31 02:24 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imgutil.dll
    2014-11-12 07:32 - 2014-10-31 02:17 - 01892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2014-11-12 07:32 - 2014-10-31 02:13 - 01310208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2014-11-12 07:32 - 2014-10-31 02:11 - 00708096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
    2014-11-12 07:32 - 2014-10-23 05:48 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll
    2014-11-12 07:32 - 2014-10-23 05:05 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll
    2014-11-12 07:32 - 2014-10-07 06:28 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2014-11-12 07:32 - 2014-10-07 06:27 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2014-11-12 07:32 - 2014-10-07 06:27 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2014-11-12 07:32 - 2014-10-07 06:27 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2014-11-12 07:32 - 2014-10-07 06:27 - 00108432 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
    2014-11-12 07:32 - 2014-10-07 03:34 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2014-11-12 07:32 - 2014-10-07 03:34 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
    2014-11-12 07:32 - 2014-10-07 03:33 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
    2014-11-12 07:32 - 2014-10-07 03:30 - 04182016 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2014-11-12 07:32 - 2014-10-07 01:54 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2014-11-12 07:32 - 2014-10-07 01:46 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2014-11-12 07:32 - 2014-08-23 05:18 - 02149376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
    2014-11-12 07:32 - 2014-08-23 05:03 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
    2014-11-12 07:31 - 2014-09-10 06:25 - 00474432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
    2014-11-12 07:31 - 2014-09-08 03:07 - 02497344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
    2014-11-12 07:31 - 2014-09-08 03:07 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
    2014-11-12 07:31 - 2014-09-07 22:08 - 00389176 _____ () C:\WINDOWS\system32\ApnDatabase.xml
    2014-11-12 07:31 - 2014-09-04 22:30 - 00822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
    2014-11-12 07:31 - 2014-09-04 22:21 - 01053184 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
    2014-11-12 07:31 - 2014-09-04 03:05 - 00836176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
    2014-11-12 07:31 - 2014-09-04 02:22 - 00670384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2014-11-12 07:31 - 2014-09-04 01:01 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
    2014-11-12 07:31 - 2014-09-04 00:32 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
    2014-11-12 07:31 - 2014-08-31 00:17 - 00148800 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
    2014-11-12 07:31 - 2014-08-31 00:15 - 21197152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2014-11-12 07:31 - 2014-08-30 22:59 - 18723112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2014-11-12 07:31 - 2014-08-30 22:05 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll
    2014-11-12 07:31 - 2014-08-30 21:58 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSAPI.dll
    2014-11-12 07:31 - 2014-08-30 21:04 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2014-11-12 07:31 - 2014-08-30 20:53 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSAPI.dll
    2014-11-12 07:31 - 2014-08-30 20:17 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2014-11-12 07:31 - 2014-08-28 02:55 - 07484224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2014-11-12 07:31 - 2014-08-28 00:21 - 02480128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
    2014-11-12 07:31 - 2014-08-28 00:06 - 02030592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
    2014-11-12 07:31 - 2014-08-23 05:14 - 13424128 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2014-11-12 07:31 - 2014-08-23 05:04 - 11820544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2014-11-12 07:31 - 2014-08-23 04:50 - 02714112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
    2014-11-12 07:31 - 2014-08-02 00:51 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
    2014-11-12 07:31 - 2014-08-02 00:35 - 00485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
    2014-11-11 20:33 - 2014-11-11 20:33 - 00003090 _____ () C:\WINDOWS\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-2762176236-1622541777-3508687700-1002
    2014-11-11 20:32 - 2014-11-11 20:32 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
    2014-11-11 20:28 - 2014-11-20 18:01 - 00004962 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for HomePC-Jack HomePC
    2014-11-11 19:49 - 2014-11-11 19:49 - 00000000 ___RD () C:\Users\Jack\SkyDrive
    2014-11-08 23:59 - 2013-08-22 06:57 - 00002143 ___RS () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser Choice.lnk
    2014-11-08 23:51 - 2014-11-08 23:59 - 00000000 ___RD () C:\WINDOWS\BrowserChoice
    2014-11-06 20:08 - 2014-11-06 20:08 - 00000000 ____D () C:\ProgramData\Avg_Update_1114tb
    2014-11-05 23:17 - 2014-08-15 00:36 - 00146752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
    2014-11-05 23:07 - 2014-07-15 18:16 - 03048880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
    2014-11-05 23:07 - 2014-07-15 08:29 - 03118080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
    2014-11-05 23:07 - 2014-07-15 08:22 - 02861056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
    2014-11-05 23:07 - 2014-07-15 08:03 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
    2014-11-05 23:04 - 2014-06-09 22:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
    2014-11-05 23:04 - 2014-06-09 22:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
    2014-11-05 23:02 - 2014-08-23 07:48 - 02374784 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
    2014-11-05 23:02 - 2014-08-23 07:13 - 02084520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
    2014-11-05 23:02 - 2014-08-23 06:10 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
    2014-11-05 23:02 - 2014-08-23 05:32 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
    2014-11-05 23:02 - 2014-08-23 04:33 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
    2014-11-05 23:01 - 2014-08-16 04:01 - 01710184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2014-11-05 23:01 - 2014-08-16 03:58 - 01112512 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
    2014-11-05 23:01 - 2014-08-16 00:23 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
    2014-11-05 23:01 - 2014-08-16 00:18 - 04758528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
    2014-11-05 23:01 - 2014-08-16 00:17 - 08757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
    2014-11-05 23:01 - 2014-08-16 00:13 - 06649344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
    2014-11-05 23:01 - 2014-08-16 00:13 - 05902848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
    2014-11-05 23:01 - 2014-08-16 00:08 - 05777408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
    2014-11-05 23:00 - 2014-08-16 04:08 - 01507648 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
    2014-11-05 23:00 - 2014-08-16 03:16 - 01205976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
    2014-11-05 23:00 - 2014-08-16 03:03 - 01467384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2014-11-05 23:00 - 2014-08-16 01:31 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
    2014-11-05 23:00 - 2014-08-16 01:04 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll
    2014-11-05 23:00 - 2014-08-16 00:58 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
    2014-11-05 23:00 - 2014-08-16 00:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll
    2014-11-05 23:00 - 2014-08-16 00:46 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityService.dll
    2014-11-05 23:00 - 2014-08-16 00:45 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
    2014-11-05 23:00 - 2014-08-16 00:43 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll
    2014-11-05 23:00 - 2014-08-16 00:43 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll
    2014-11-05 23:00 - 2014-08-16 00:31 - 00914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
    2014-11-05 23:00 - 2014-08-16 00:31 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll
    2014-11-05 23:00 - 2014-08-16 00:29 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
    2014-11-05 23:00 - 2014-08-16 00:22 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
    2014-11-05 23:00 - 2014-08-16 00:22 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll
    2014-11-05 23:00 - 2014-08-16 00:19 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
    2014-11-05 23:00 - 2014-08-16 00:14 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll
    2014-11-05 23:00 - 2014-08-16 00:13 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
    2014-11-05 23:00 - 2014-08-16 00:11 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
    2014-11-05 23:00 - 2014-08-16 00:10 - 01120768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
    2014-11-05 23:00 - 2014-08-16 00:07 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
    2014-11-05 23:00 - 2014-08-02 00:18 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
    2014-11-05 22:59 - 2014-07-10 04:08 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\lockscreencn.dll
    2014-11-05 22:59 - 2014-05-03 05:36 - 00997888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
    2014-11-05 22:59 - 2014-05-03 05:19 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncobjapi.dll
    2014-11-05 22:59 - 2014-05-03 05:08 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedynos.dll
    2014-11-05 22:59 - 2014-05-03 05:07 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\framedyn.dll
    2014-11-05 22:59 - 2014-05-03 04:46 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncobjapi.dll
    2014-11-05 22:59 - 2014-05-03 04:37 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedynos.dll
    2014-11-05 22:59 - 2014-05-03 04:37 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\framedyn.dll
    2014-11-05 22:59 - 2014-05-02 23:26 - 00050745 _____ () C:\WINDOWS\system32\srms.dat
    2014-11-05 22:59 - 2014-04-30 06:43 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwififlt.sys
    2014-11-05 22:59 - 2014-04-30 06:41 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
    2014-11-05 22:59 - 2014-04-30 06:41 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
    2014-11-05 22:59 - 2014-04-30 06:41 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
    2014-11-05 22:59 - 2014-04-30 05:45 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Robocopy.exe
    2014-11-05 22:59 - 2014-04-30 04:48 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Robocopy.exe
    2014-11-05 22:59 - 2014-04-30 04:24 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll
    2014-11-05 22:59 - 2014-04-30 04:23 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
    2014-11-05 22:59 - 2014-04-30 04:23 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
    2014-11-05 22:59 - 2014-04-30 04:23 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll
    2014-11-05 22:59 - 2014-04-30 04:14 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
    2014-11-05 22:59 - 2014-04-30 03:59 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
    2014-11-05 22:59 - 2014-04-30 03:46 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
    2014-11-05 22:59 - 2014-04-30 03:46 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
    2014-11-05 22:59 - 2014-04-30 03:46 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll
    2014-11-05 22:59 - 2014-04-30 03:45 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll
    2014-11-05 22:59 - 2014-04-30 03:42 - 00403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
    2014-11-05 22:59 - 2014-04-28 22:40 - 00721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
    2014-11-05 22:59 - 2014-04-26 16:39 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
    2014-11-05 22:59 - 2014-04-14 09:37 - 02125344 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
    2014-11-05 22:59 - 2014-04-14 08:08 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
    2014-11-05 22:59 - 2014-04-14 05:18 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
    2014-11-05 22:58 - 2014-07-24 03:20 - 00875688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
    2014-11-05 22:58 - 2014-07-24 03:20 - 00869544 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
    2014-11-05 22:58 - 2014-07-12 04:17 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
    2014-11-05 22:58 - 2014-06-02 02:10 - 00423768 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
    2014-11-05 22:58 - 2014-05-31 06:27 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WUDFPf.sys
    2014-11-05 22:58 - 2014-05-31 06:26 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WUDFRd.sys
    2014-11-05 22:58 - 2014-05-31 04:01 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFHost.exe
    2014-11-05 22:58 - 2014-05-31 04:01 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll
    2014-11-05 22:58 - 2014-05-31 04:01 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFSvc.dll
    2014-11-05 22:58 - 2014-05-27 09:56 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\DaOtpCredentialProvider.dll
    2014-11-05 22:58 - 2014-05-27 09:53 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DaOtpCredentialProvider.dll
    2014-11-04 21:05 - 2014-11-04 21:05 - 00000000 __SHD () C:\Users\Jack\AppData\Local\EmieUserList
    2014-11-04 21:05 - 2014-11-04 21:05 - 00000000 __SHD () C:\Users\Jack\AppData\Local\EmieSiteList
    2014-11-04 21:02 - 2014-11-26 19:39 - 00003914 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{91E2A897-1A37-4A99-8E0B-FE146B59BA0B}
    2014-11-04 21:02 - 2014-11-04 21:02 - 00001453 _____ () C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2014-11-04 21:01 - 2014-11-04 21:01 - 00000020 ___SH () C:\Users\Jack\ntuser.ini
    2014-11-04 20:54 - 2014-11-04 20:54 - 00022744 _____ () C:\WINDOWS\system32\emptyregdb.dat
    2014-11-04 20:41 - 2014-11-04 20:41 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2014-11-04 20:41 - 2014-11-04 20:41 - 00000000 ____D () C:\Users\Default\Documents\hp.system.package.metadata
    2014-11-04 20:41 - 2014-11-04 20:41 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software
    2014-11-04 20:41 - 2014-11-04 20:41 - 00000000 ____D () C:\Users\Default User\Documents\hp.system.package.metadata
    2014-11-04 20:41 - 2014-11-04 20:41 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software
    2014-11-04 20:36 - 2014-11-04 20:36 - 00000000 ____D () C:\WINDOWS\system32\config\bbimigrate
    2014-11-04 20:34 - 2014-11-24 20:28 - 00000000 ____D () C:\Users\Jack
    2014-11-04 20:34 - 2014-11-04 20:54 - 00020958 _____ () C:\WINDOWS\diagwrn.xml
    2014-11-04 20:34 - 2014-11-04 20:54 - 00020958 _____ () C:\WINDOWS\diagerr.xml
    2014-11-04 20:34 - 2014-11-04 20:36 - 00000000 ___RD () C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2014-11-04 20:34 - 2014-11-04 20:36 - 00000000 ___RD () C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
    2014-11-04 20:34 - 2014-09-24 16:30 - 00000369 _____ () C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
    2014-11-04 20:34 - 2014-09-24 16:30 - 00000369 _____ () C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
    2014-11-04 20:34 - 2013-08-22 15:36 - 00000000 ___RD () C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2014-11-04 20:34 - 2013-08-22 15:36 - 00000000 ____D () C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2014-11-04 20:27 - 2014-11-04 20:36 - 00012096 _____ () C:\WINDOWS\iis.log
    2014-11-04 20:27 - 2014-11-04 20:27 - 00922144 _____ () C:\WINDOWS\SysWOW64\PerfStringBackup.INI
    2014-11-04 20:24 - 2014-11-04 20:24 - 00060601 _____ () C:\WINDOWS\SysWOW64\CCCInstall_201411042024360988.log
    2014-11-04 20:24 - 2014-11-04 20:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
    2014-11-04 20:24 - 2014-11-04 20:24 - 00000000 ____D () C:\ProgramData\AMD
    2014-11-04 20:24 - 2014-11-04 20:24 - 00000000 ____D () C:\Program Files\ATI Technologies
    2014-11-04 20:23 - 2014-11-26 19:39 - 01236274 _____ () C:\WINDOWS\WindowsUpdate.log
    2014-11-04 20:23 - 2014-11-23 12:01 - 00000000 ____D () C:\ProgramData\Package Cache
    2014-11-04 20:23 - 2014-11-04 20:39 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
    2014-11-04 20:22 - 2014-11-04 20:22 - 00000264 _____ () C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job
    2014-11-04 20:22 - 2014-11-04 20:22 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
    2014-11-04 20:22 - 2014-11-04 20:22 - 00000000 ____D () C:\WINDOWS\SysWOW64\RTCOM
    2014-11-04 20:22 - 2014-11-04 20:22 - 00000000 ____D () C:\WINDOWS\system32\SRSLabs
    2014-11-04 20:22 - 2014-11-04 20:22 - 00000000 ____D () C:\Program Files\Synaptics
    2014-11-04 20:22 - 2014-11-04 20:22 - 00000000 ____D () C:\Program Files\Realtek
    2014-11-04 20:22 - 2014-11-04 20:22 - 00000000 ____D () C:\Program Files\AMD
    2014-11-04 20:22 - 2014-11-04 20:22 - 00000000 _____ () C:\WINDOWS\ativpsrm.bin
    2014-11-04 20:19 - 2014-11-05 00:00 - 00000000 ___DC () C:\WINDOWS\Panther
    2014-11-04 20:19 - 2014-11-04 20:19 - 00000000 __SHD () C:\Recovery
    2014-11-04 20:17 - 2014-11-04 20:17 - 00921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
    2014-11-04 20:17 - 2014-11-04 20:17 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
    2014-11-04 20:17 - 2014-11-04 20:17 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
    2014-11-04 20:17 - 2014-11-04 20:17 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\BulkOperationHost.exe
    2014-11-04 20:15 - 2014-11-04 20:15 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
    2014-11-04 20:15 - 2014-11-04 20:15 - 00514048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
    2014-11-04 20:13 - 2014-11-04 20:13 - 00262144 _____ () C:\WINDOWS\system32\config\userdiff
    2014-11-04 20:10 - 2014-11-04 20:10 - 00000000 ____D () C:\Program Files\Reference Assemblies
    2014-11-04 20:10 - 2014-11-04 20:10 - 00000000 ____D () C:\Program Files\MSBuild
    2014-11-04 20:10 - 2014-11-04 20:10 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
    2014-11-04 20:10 - 2014-11-04 20:10 - 00000000 ____D () C:\Program Files (x86)\MSBuild
    2014-11-04 20:10 - 2014-11-04 20:10 - 00000000 ____D () C:\inetpub
    2014-11-04 20:09 - 2013-08-03 04:48 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
    2014-11-04 20:09 - 2013-08-03 04:48 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
    2014-11-04 20:09 - 2013-08-03 04:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
    2014-11-04 20:09 - 2013-08-03 04:41 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2014-11-04 18:43 - 2014-11-04 20:54 - 00006606 _____ () C:\WINDOWS\comsetup.log
    2014-10-30 08:16 - 2014-11-08 23:50 - 00000000 ____D () C:\WINDOWS\system32\AutoUpdateLicense
    2014-10-29 21:03 - 2014-10-29 21:03 - 00123672 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx64.sys
    2014-10-29 17:21 - 2014-10-22 03:34 - 00010777 ____N () C:\WINDOWS\system32\AutoconfigV2.cab
    2014-10-29 17:21 - 2014-10-22 03:33 - 00581016 ____N () C:\WINDOWS\system32\AutoUpdate.exe
     
    ==================== One Month Modified Files and Folders =======
     
    (If an entry is included in the fixlist, the file\folder will be moved.)
     
    2014-11-26 19:40 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\sru
    2014-11-26 19:35 - 2014-09-24 16:21 - 00956476 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
    2014-11-26 19:29 - 2014-09-24 08:08 - 00098580 _____ () C:\WINDOWS\PFRO.log
    2014-11-26 19:29 - 2014-06-03 15:48 - 00000000 ____D () C:\Users\Jack\AppData\Local\AVG SafeGuard toolbar
    2014-11-26 19:29 - 2013-08-22 14:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
    2014-11-26 19:29 - 2013-08-22 14:44 - 00478080 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
    2014-11-26 19:28 - 2013-08-22 13:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
    2014-11-26 19:02 - 2014-06-02 05:33 - 00000000 ____D () C:\ProgramData\MFAData
    2014-11-26 19:01 - 2013-08-22 13:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
    2014-11-26 18:58 - 2012-07-26 07:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
    2014-11-25 19:27 - 2014-03-13 20:45 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2762176236-1622541777-3508687700-1002
    2014-11-25 19:24 - 2013-08-22 15:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
    2014-11-25 19:23 - 2014-09-24 15:57 - 00000000 ____D () C:\WINDOWS\ShellNew
    2014-11-25 19:20 - 2013-08-22 15:36 - 00000000 ____D () C:\Program Files\Common Files\System
    2014-11-25 19:20 - 2013-08-22 13:25 - 00000076 _____ () C:\WINDOWS\win.ini
    2014-11-25 07:02 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
    2014-11-24 22:39 - 2014-03-13 14:12 - 00000000 ____D () C:\Users\Jack\AppData\Local\Packages
    2014-11-24 22:37 - 2014-03-13 16:59 - 00000000 ____D () C:\Users\Jack\Documents\Youcam
    2014-11-24 21:09 - 2014-06-02 05:38 - 00000000 ____D () C:\ProgramData\AVG2014
    2014-11-24 07:24 - 2013-06-11 16:42 - 00000000 ____D () C:\ProgramData\WildTangent
    2014-11-24 07:24 - 2013-06-11 16:42 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
    2014-11-24 07:21 - 2014-03-13 14:16 - 00000000 ____D () C:\Users\Jack\AppData\Roaming\Adobe
    2014-11-23 15:38 - 2014-06-03 17:57 - 00000000 ____D () C:\Users\Jack\AppData\Roaming\Skype
    2014-11-21 10:35 - 2013-08-22 14:46 - 00295451 _____ () C:\WINDOWS\setupact.log
    2014-11-18 17:27 - 2014-06-02 05:38 - 00000988 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
    2014-11-18 17:27 - 2014-06-02 05:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    2014-11-13 17:14 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\rescache
    2014-11-13 08:53 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
    2014-11-13 07:25 - 2014-09-24 18:55 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
    2014-11-13 07:25 - 2013-08-22 15:36 - 00000000 ___RD () C:\WINDOWS\ToastData
    2014-11-13 07:25 - 2013-08-22 15:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
    2014-11-13 07:25 - 2013-08-22 15:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2014-11-13 07:25 - 2013-08-22 15:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2014-11-13 07:25 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\en-GB
    2014-11-13 07:25 - 2013-08-22 15:36 - 00000000 ____D () C:\Program Files\Windows Defender
    2014-11-13 07:25 - 2013-08-22 15:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
    2014-11-13 07:22 - 2014-03-18 23:12 - 00000000 ____D () C:\WINDOWS\system32\MRT
    2014-11-13 07:19 - 2014-03-18 23:12 - 103374192 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2014-11-11 19:43 - 2014-03-13 14:12 - 00000000 ____D () C:\Users\Jack\AppData\Local\VirtualStore
    2014-11-11 19:36 - 2014-08-03 18:21 - 00000000 ____D () C:\Users\Jack\AppData\Local\Windows Live
    2014-11-08 23:59 - 2014-03-19 15:06 - 00003544 _____ () C:\WINDOWS\System32\Tasks\CreateChoiceProcessTask
    2014-11-08 23:52 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\WinStore
    2014-11-05 23:36 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\en-GB
    2014-11-05 23:30 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\restore
    2014-11-04 21:04 - 2014-03-13 14:16 - 00000000 ____D () C:\Users\Jack\Documents\Bluetooth Folder
    2014-11-04 20:54 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\Registration
    2014-11-04 20:51 - 2013-08-22 15:36 - 00000000 __RSD () C:\WINDOWS\Media
    2014-11-04 20:50 - 2013-08-22 15:36 - 00000000 __RHD () C:\Users\Public\Libraries
    2014-11-04 20:49 - 2012-07-26 08:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
    2014-11-04 20:43 - 2014-09-24 15:35 - 00000000 ____D () C:\WINDOWS\en-GB
    2014-11-04 20:43 - 2014-06-03 17:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2014-11-04 20:43 - 2014-03-13 14:15 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services
    2014-11-04 20:43 - 2013-11-18 22:41 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat
    2014-11-04 20:43 - 2013-11-18 22:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
    2014-11-04 20:43 - 2013-08-22 13:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep
    2014-11-04 20:43 - 2013-06-11 16:43 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
    2014-11-04 20:43 - 2013-06-11 16:39 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
    2014-11-04 20:43 - 2013-06-11 16:22 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
    2014-11-04 20:41 - 2014-09-24 15:35 - 00000000 ____D () C:\WINDOWS\SysWOW64\WCN
    2014-11-04 20:41 - 2014-09-24 15:35 - 00000000 ____D () C:\WINDOWS\SysWOW64\sysprep
    2014-11-04 20:41 - 2014-09-24 15:35 - 00000000 ____D () C:\WINDOWS\system32\WCN
    2014-11-04 20:41 - 2013-11-18 22:21 - 00000000 ____D () C:\WINDOWS\SysWOW64\sda
    2014-11-04 20:41 - 2013-08-22 15:37 - 00004893 _____ () C:\WINDOWS\DtcInstall.log
    2014-11-04 20:41 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\MUI
    2014-11-04 20:41 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\migwiz
    2014-11-04 20:41 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\IME
    2014-11-04 20:41 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\spool
    2014-11-04 20:41 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\MUI
    2014-11-04 20:41 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\IME
    2014-11-04 20:41 - 2013-08-22 13:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\SMI
    2014-11-04 20:41 - 2013-08-22 13:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
    2014-11-04 20:41 - 2013-06-11 16:27 - 00000000 ____D () C:\WINDOWS\SysWOW64\Adobe
    2014-11-04 20:41 - 2012-07-26 05:37 - 00000000 ____D () C:\Users\Default.migrated
    2014-11-04 20:39 - 2013-11-18 22:24 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Program
    2014-11-04 20:39 - 2013-11-18 22:14 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
    2014-11-04 20:39 - 2013-08-22 15:43 - 00000000 ____D () C:\WINDOWS\DigitalLocker
    2014-11-04 20:39 - 2013-08-22 15:36 - 00000000 __SHD () C:\Program Files\Windows Sidebar
    2014-11-04 20:39 - 2013-08-22 15:36 - 00000000 __SHD () C:\Program Files (x86)\Windows Sidebar
    2014-11-04 20:39 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\Help
    2014-11-04 20:39 - 2013-06-11 16:24 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
    2014-11-04 20:39 - 2012-08-03 22:29 - 00000000 ____D () C:\ProgramData\PRICache
    2014-11-04 20:36 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\Recovery
    2014-11-04 20:22 - 2013-08-22 14:46 - 00000084 _____ () C:\WINDOWS\setuperr.log
    2014-11-04 20:20 - 2013-08-22 13:36 - 00000000 __RHD () C:\Users\Default
    2014-11-04 20:18 - 2013-08-22 15:36 - 00262144 _____ () C:\WINDOWS\system32\config\BCD-Template
    2014-11-04 20:17 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
    2014-11-04 20:17 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\FileManager
    2014-11-04 20:17 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\Camera
    2014-11-04 20:16 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
    2014-11-04 20:10 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\inetsrv
    2014-11-04 20:10 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\inetsrv
    2014-11-04 20:10 - 2013-08-22 11:25 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
    2014-11-04 20:10 - 2013-08-22 11:22 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
    2014-11-04 20:10 - 2013-08-22 11:19 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
    2014-11-04 20:10 - 2013-08-22 11:19 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
    2014-11-04 20:10 - 2013-08-22 11:18 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
    2014-11-04 20:10 - 2013-08-22 10:03 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
    2014-11-04 20:10 - 2013-08-22 03:58 - 00016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
    2014-11-04 20:10 - 2013-08-22 03:56 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
    2014-11-04 20:10 - 2013-08-22 03:53 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
    2014-11-04 20:10 - 2013-08-22 03:53 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
    2014-11-04 20:10 - 2013-08-22 03:51 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
    2014-11-04 20:10 - 2013-08-22 02:54 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
    2014-11-04 19:58 - 2014-03-13 14:11 - 01877408 _____ () C:\WINDOWS\WindowsUpdate (1).log
    2014-11-04 18:13 - 2012-07-26 08:12 - 00000000 ____D () C:\WINDOWS\AUInstallAgent
    2014-11-04 00:06 - 2014-04-02 23:47 - 00000000 ____D () C:\Users\Jack\AppData\Local\CrashDumps
    2014-10-30 00:55 - 2014-09-24 19:00 - 00714208 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2014-10-30 00:55 - 2014-09-24 19:00 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
     
    Some content of TEMP:
    ====================
    C:\Users\Jack\AppData\Local\Temp\70407uninstall.exe
    C:\Users\Jack\AppData\Local\Temp\94433uninstall.exe
    C:\Users\Jack\AppData\Local\Temp\ose00000.exe
    C:\Users\Jack\AppData\Local\Temp\Quarantine.exe
    C:\Users\Jack\AppData\Local\Temp\SppExtComObjHook.dll
    C:\Users\Jack\AppData\Local\Temp\sqlite3.dll
     
     
    ==================== Bamital & volsnap Check =================
     
    (There is no automatic fix for files that do not pass verification.)
     
    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
     
     
    LastRegBack: 2014-11-25 19:27
     
    ==================== End Of Log ============================
     
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-11-2014 01
    Ran by Jack at 2014-11-26 19:58:25
    Running from C:\Users\Jack\Desktop
    Boot Mode: Normal
    ==========================================================
     
     
    ==================== Security Center ========================
     
    (If an entry is included in the fixlist, it will be removed.)
     
    AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}
    FW: AVG update module (Disabled) {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
     
    ==================== Installed Programs ======================
     
    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
     
    7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
    Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.)
    AMD Catalyst Install Manager (HKLM\...\{CB4C08E3-800F-65F6-9C00-06814A6B7CE7}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
    AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4794 - AVG Technologies)
    AVG 2014 (Version: 14.0.4189 - AVG Technologies) Hidden
    AVG 2014 (Version: 14.0.4794 - AVG Technologies) Hidden
    AVG PC TuneUp 2014 (en-GB) (x32 Version: 14.0.1001.519 - AVG) Hidden
    AVG PC TuneUp 2014 (HKLM-x32\...\AVG PC TuneUp) (Version: 14.0.1001.519 - AVG)
    AVG PC TuneUp 2014 (x32 Version: 14.0.1001.519 - AVG) Hidden
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3.6326 - CyberLink Corp.)
    CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.3.2608 - CyberLink Corp.)
    CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.3.2527 - CyberLink Corp.)
    CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.6.4319 - CyberLink Corp.)
    CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.6.6119 - CyberLink Corp.)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.65 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    HP Documentation (HKLM-x32\...\{8C1ADF61-4F87-44BC-804C-C20FC70D98BB}) (Version: 1.4.0.0 - Hewlett-Packard)
    HP Quick Start (HKLM-x32\...\{574F0207-8E98-46CD-8F79-318348C98C46}) (Version: 1.0.4660.30220 - Hewlett-Packard)
    HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.6317.4309 - Hewlett-Packard)
    HP System Event Utility (HKLM-x32\...\{C78E8F51-3EAD-4F0C-83F0-EF371075E0B4}) (Version: 1.0.10 - Hewlett-Packard Company)
    HP Utility Center (HKLM\...\{73237EBB-B26F-4628-8754-4EFE563D72E9}) (Version: 2.1.5 - Hewlett-Packard Company)
    HP Wireless Button Driver (HKLM-x32\...\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company)
    Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-2762176236-1622541777-3508687700-1002\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
    OEM Application Profile (HKLM-x32\...\{C89A97B6-F991-EBB5-77B7-927BCF420EBE}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
    Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.226 - Qualcomm Atheros Communications)
    Qualcomm Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Qualcomm Atheros)
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.10.1226.2012 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6937 - Realtek Semiconductor Corp.)
    Realtek PCIE Card Reader (HKLM-x32\...\{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}) (Version: 6.2.9200.29053 - Realtek Semiconductor Corp.)
    Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
    Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
    Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
    swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
    Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.6.1.3 - Synaptics Incorporated)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
     
    ==================== Custom CLSID (selected items): ==========================
     
    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
     
    CustomCLSID: HKU\S-1-5-21-2762176236-1622541777-3508687700-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Jack\AppData\Local\Microsoft\SkyDrive\17.3.1229.0918\amd64\FileSyncApi64.dll (Microsoft Corporation)
     
    ==================== Restore Points  =========================
     
    19-11-2014 06:57:25 Windows Update
    21-11-2014 09:09:22 Installed Microsoft Office Professional Plus 2013
    21-11-2014 09:10:20 PROPLUS
    23-11-2014 11:59:51 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
    24-11-2014 23:06:28 AA11
     
    ==================== Hosts content: ==========================
     
    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
     
    2013-08-22 13:25 - 2013-08-22 13:25 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts
     
    ==================== Scheduled Tasks (whitelisted) =============
     
    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
     
    Task: {0122D7C9-4205-462A-81D5-79A77BEDE208} - System32\Tasks\Microsoft Office 15 Sync Maintenance for HomePC-Jack HomePC => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe
    Task: {198B7B46-9986-4CB8-8492-A09DA4BEAE1C} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe [2014-07-14] (AVG)
    Task: {24D2D561-C742-481A-922D-E521AFB4662B} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-08] (CyberLink)
    Task: {3E921D5A-64DE-443E-BF08-EA8DE4663FE5} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2012-07-24] (CyberLink Corp.)
    Task: {806CCD0C-547A-48F3-8401-1066B359F68E} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-05-16] (Synaptics Incorporated)
    Task: {8B9D850C-97C3-443D-A36A-135D072872BE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-24] (Google Inc.)
    Task: {8F1BF23D-3B00-4419-BE2C-80E920F011F9} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-03-21] (Realtek Semiconductor)
    Task: {BAA8E766-1960-41FB-8479-A305FF10A6C9} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-2762176236-1622541777-3508687700-1002 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe
    Task: {BB68E2F2-210E-44A1-BB86-BD85BE400B92} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe
    Task: {BCC611BD-14AA-45DC-903B-1C254FA26E4F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-11-13] (Microsoft Corporation)
    Task: {F56BC71D-E9D6-41EF-A02C-5AE1EE857518} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
    Task: {F9213195-6E04-418F-9D8B-CFD4481DF16D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-24] (Google Inc.)
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
     
    ==================== Loaded Modules (whitelisted) =============
     
    2014-07-04 21:33 - 2014-07-04 21:33 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
    2014-07-14 10:26 - 2014-07-14 10:26 - 00699704 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\avgrepliba.dll
    2014-07-14 10:26 - 2014-07-14 10:26 - 00407864 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\tuavga.dll
    2013-05-16 02:46 - 2013-05-16 02:46 - 00011264 _____ () C:\Program Files (x86)\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
    2013-05-16 02:43 - 2013-05-16 02:43 - 00086016 _____ () C:\Program Files (x86)\Bluetooth Suite\Modules\Map\MAP.dll
    2013-05-16 03:09 - 2013-05-16 03:09 - 00012928 _____ () C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
    2013-05-16 03:15 - 2013-05-16 03:15 - 00384128 _____ () C:\Program Files (x86)\Bluetooth Suite\ContactsApi.dll
    2013-11-18 22:44 - 2012-06-08 03:34 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
    2012-06-08 11:34 - 2012-06-08 11:34 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
    2014-11-24 21:20 - 2014-11-14 21:15 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libglesv2.dll
    2014-11-24 21:20 - 2014-11-14 21:15 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libegl.dll
    2014-11-24 21:20 - 2014-11-14 21:15 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\pdf.dll
    2014-11-24 21:20 - 2014-11-14 21:15 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\ffmpegsumo.dll
     
    ==================== Alternate Data Streams (whitelisted) =========
     
    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
     
     
    ==================== Safe Mode (whitelisted) ===================
     
    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
     
     
    ==================== EXE Association (whitelisted) =============
     
    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
     
     
    ==================== MSCONFIG/TASK MANAGER disabled items =========
     
    (Currently there is no automatic fix for this section.)
     
    HKLM\...\StartupApproved\Run32: => "AVG_UI"
    HKU\S-1-5-21-2762176236-1622541777-3508687700-1002\...\StartupApproved\Run: => "Skype"
     
    ========================= Accounts: ==========================
     
    Administrator (S-1-5-21-2762176236-1622541777-3508687700-500 - Administrator - Disabled)
    Guest (S-1-5-21-2762176236-1622541777-3508687700-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-2762176236-1622541777-3508687700-1004 - Limited - Enabled)
    Jack (S-1-5-21-2762176236-1622541777-3508687700-1002 - Administrator - Enabled) => C:\Users\Jack
     
    ==================== Faulty Device Manager Devices =============
     
     
    ==================== Event log errors: =========================
     
    Application errors:
    ==================
     
    System errors:
    =============
    Error: (11/26/2014 07:56:52 PM) (Source: DCOM) (EventID: 10010) (User: HomePC)
    Description: {9AA46009-3CE0-458A-A354-715610A075E6}
     
    Error: (11/26/2014 07:56:22 PM) (Source: DCOM) (EventID: 10010) (User: HomePC)
    Description: {9AA46009-3CE0-458A-A354-715610A075E6}
     
    Error: (11/26/2014 07:55:51 PM) (Source: DCOM) (EventID: 10010) (User: HomePC)
    Description: {9AA46009-3CE0-458A-A354-715610A075E6}
     
    Error: (11/26/2014 07:55:21 PM) (Source: DCOM) (EventID: 10010) (User: HomePC)
    Description: {9AA46009-3CE0-458A-A354-715610A075E6}
     
     
    Microsoft Office Sessions:
    =========================
     
    ==================== Memory info =========================== 
     
    Processor: AMD E2-1800 APU with Radeon™ HD Graphics
    Percentage of memory in use: 39%
    Total physical RAM: 3682.26 MB
    Available physical RAM: 2218.19 MB
    Total Pagefile: 4322.26 MB
    Available Pagefile: 2605.04 MB
    Total Virtual: 131072 MB
    Available Virtual: 131071.8 MB
     
    ==================== Drives ================================
     
    Drive c: (Windows) (Fixed) (Total:445.03 GB) (Free:412.56 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive d: (RECOVERY) (Fixed) (Total:19.52 GB) (Free:1.98 GB) NTFS ==>[System with boot components (obtained from reading drive)]
     
    ==================== MBR & Partition Table ==================
     
    ========================================================
    Disk: 0 (Size: 465.8 GB) (Disk ID: 1E1F4777)
     
    Partition: GPT Partition Type.
     
    ==================== End Of Log ============================

    • 0

    #4
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 24,625 posts
    • MVP

    Looks like we got it.  Let's clean up a little deadwood:

     

    Download the attached fixlist.txt to the same location as FRST
    Run FRST and press Fix
    A fix log will be generated please post that.
     
    How is it running now?  Is Vosteran gone?
     
    Ron

    • 0

    #5
    Steviep

    Steviep

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 338 posts

    Hi Ron,

     

    Here is the log - Its not my laptop but I've used it for past 5 hours with no redirects and although slower than my PC it seems fine

     

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-11-2014 01
    Ran by Jack at 2014-11-26 22:30:54 Run:1
    Running from C:\Users\Jack\Desktop
    Loaded Profile: Jack (Available profiles: Jack)
    Boot Mode: Normal
    ==============================================
     
    Content of fixlist:
    *****************
    ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
    ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
    ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
    C:\Users\Jack\AppData\Local\Temp\70407uninstall.exe
    C:\Users\Jack\AppData\Local\Temp\94433uninstall.exe
    C:\Users\Jack\AppData\Local\Temp\ose00000.exe
    C:\Users\Jack\AppData\Local\Temp\Quarantine.exe
    C:\Users\Jack\AppData\Local\Temp\SppExtComObjHook.dll
    C:\Users\Jack\AppData\Local\Temp\sqlite3.dll
    *****************
     
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Key deleted successfully.
    "HKCR\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => Key not found.
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Key deleted successfully.
    "HKCR\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => Key not found.
    "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Key deleted successfully.
    "HKCR\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => Key not found.
    "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Key deleted successfully.
    "HKCR\Wow6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => Key not found.
    "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Key deleted successfully.
    "HKCR\Wow6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => Key not found.
    "HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Key deleted successfully.
    "HKCR\Wow6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => Key not found.
    C:\Users\Jack\AppData\Local\Temp\70407uninstall.exe => Moved successfully.
    C:\Users\Jack\AppData\Local\Temp\94433uninstall.exe => Moved successfully.
    C:\Users\Jack\AppData\Local\Temp\ose00000.exe => Moved successfully.
    C:\Users\Jack\AppData\Local\Temp\Quarantine.exe => Moved successfully.
    C:\Users\Jack\AppData\Local\Temp\SppExtComObjHook.dll => Moved successfully.
    C:\Users\Jack\AppData\Local\Temp\sqlite3.dll => Moved successfully.
     
    ==== End of Fixlog ====

    • 0

    #6
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 24,625 posts
    • MVP
    Let's check if there is a reason for running slow:
     
    Get Process Explorer
     
    Save it to your desktop then run it (Vista or Win7 - right click and Run As Administrator).  
    Close all programs but your browser.
    View, Select Column, check Verified Signer, OK
    Options, Verify Image Signatures
     
     
    Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  
     
    Wait a full minute then:
     
    File, Save As, Save.  Open the file Procexp.txt on your desktop and copy and paste the text to a reply.
     
     
    Get the free version of Speccy:
     
    http://www.filehippo...download_speccy  (Look in the upper right for the Download
    Latest Version button  - Do NOT press the large Start Download button on the upper left!)  Download, Save and Install it.  Run Speccy.  When it finishes (the little icon in the bottom left will stop moving), File, Save as Text File,  (to your desktop) note the name it gives. OK.  Open the file in notepad and delete the line that gives the serial number of your Operating System.  (It will be near the top about 10 lines down.) Attach the file to your next post.
     
     
     
    Right click on (My) Computer and select Manage (Continue) Then click on the arrow in front of Event Viewer. Next Click on the arrow in front of Windows Logs Right click on System and Clear Log, Clear. Repeat for Application.
     
    Reboot. 
     
    Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator.  Then type (with an Enter after each line).
    sfc  /scannow
     
    (This will check your critical system files. Does this finish without complaint?  IF it says it couldn't fix everything then:
     
    Copy the next two lines:
     
    findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log  >  \windows\logs\cbs\junk.txt 
    notepad \windows\logs\cbs\junk.txt 
     
    Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue.  Right click and Paste or Edit then Paste and the copied line should appear.
    Hit Enter. Copy and paste the text from notepad or if it is too big, just attach the file.)
     
     
    1. Please download the Event Viewer Tool by Vino Rosso
    and save it to your Desktop:
    2. Right-click VEW.exe and Run AS Administrator
    3. Under 'Select log to query', select:
     
    * System
    4. Under 'Select type to list', select:
    * Error
    * Warning
     
     
    Then use the 'Number of events' as follows:
     
     
    1. Click the radio button for 'Number of events'
    Type 20 in the 1 to 20 box
    Then click the Run button.
    Notepad will open with the output log.
     
     
    Please post the Output log in your next reply then repeat but select Application.
     
    Ron
     

    • 0

    #7
    Steviep

    Steviep

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 338 posts
    Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
    System Idle Process 83.48 0 K 4 K 0
    procexp64.exe 6.73 23,760 K 46,036 K 2684 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Sysinternals
    Interrupts 3.21 0 K 0 K n/a Hardware Interrupts and DPCs
    SynTPEnh.exe 2.55 3,744 K 2,564 K 3448 Synaptics TouchPad Enhancements Synaptics Incorporated (Verified) Microsoft Windows Hardware Compatibility Publisher
    dwm.exe 1.35 17,460 K 21,348 K 1068 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows
    System 0.79 12,224 K 11,728 K 4
    csrss.exe 0.66 2,184 K 2,904 K 956 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows
    explorer.exe 0.36 77,612 K 96,564 K 1752 Windows Explorer Microsoft Corporation (Verified) Microsoft Windows
    mbam.exe 0.30 39,592 K 43,128 K 2936 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
    avgwdsvc.exe 0.24 10,636 K 12,764 K 1596 AVG Watchdog Service AVG Technologies CZ, s.r.o. (Verified) AVG Technologies CZ
    TuneUpUtilitiesApp64.exe 0.11 2,032 K 3,484 K 2876 AVG PC TuneUp AVG (Verified) AVG Netherlands B.V.
    CLMLSvc_P2G8.exe 0.04 2,076 K 896 K 5328 CyberLink MediaLibray Service CyberLink (Verified) CyberLink
    chrome.exe 0.04 33,876 K 66,512 K 7156 Google Chrome Google Inc. (Verified) Google Inc
    chrome.exe 0.04 20,960 K 46,804 K 4668 Google Chrome Google Inc. (Verified) Google Inc
    BtTray.exe 0.03 41,448 K 16,412 K 5256 BtTray Qualcomm Atheros (Verified) Qualcomm Atheros
    RIconMan.exe 0.02 1,552 K 1,744 K 2216 Realtek Card Reader Patch Tool. Realsil Microelectronics Inc. (Verified) Realtek Semiconductor Corp
    svchost.exe 0.02 60,240 K 61,424 K 1324 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    avgidsagent.exe 0.01 16,552 K 19,988 K 2028 AVG Identity Protection Service AVG Technologies CZ, s.r.o. (Verified) AVG Technologies CZ
    avgrsa.exe < 0.01 21,236 K 24,240 K 560 AVG Resident Shield Service AVG Technologies CZ, s.r.o. (Verified) AVG Technologies CZ
    svchost.exe < 0.01 4,920 K 6,832 K 824 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    TuneUpUtilitiesService64.exe < 0.01 13,040 K 15,048 K 2732 AVG PC TuneUp Service AVG (Verified) AVG Netherlands B.V.
    csrss.exe < 0.01 1,924 K 1,972 K 856 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe < 0.01 22,220 K 28,208 K 1204 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    BtvStack.exe < 0.01 18,352 K 8,284 K 4700 Extension Core Qualcomm Atheros Commnucations (Verified) Qualcomm Atheros
    wmpnetwk.exe 5,824 K 5,244 K 3508 Windows Media Player Network Sharing Service Microsoft Corporation (Verified) Microsoft Windows
    WmiPrvSE.exe 1,740 K 5,540 K 7160 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
    winlogon.exe 1,860 K 1,392 K 1000 Windows Log-on Application Microsoft Corporation (Verified) Microsoft Windows
    wininit.exe 740 K 504 K 948 Windows Start-Up Application Microsoft Corporation (Verified) Microsoft Windows
    taskhostex.exe 8,584 K 9,872 K 3440 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
    SynTPHelper.exe 688 K 240 K 5292 Synaptics Pointing Device Helper Synaptics Incorporated (Verified) Microsoft Windows Hardware Compatibility Publisher
    svchost.exe 3,576 K 5,744 K 3748 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 19,084 K 17,604 K 1788 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 3,876 K 4,792 K 812 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 15,108 K 13,984 K 1172 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 3,184 K 2,968 K 1944 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 6,512 K 9,208 K 1556 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 7,976 K 9,016 K 1240 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 1,204 K 888 K 3908 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 10,076 K 13,176 K 2956 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    spoolsv.exe 3,764 K 3,060 K 1740 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows
    smss.exe 280 K 324 K 320 Windows Session Manager Microsoft Corporation (Verified) Microsoft Windows
    SkypeC2CPNRSvc.exe 1,736 K 1,144 K 2112 Phone Number Recognition (PNR) module Microsoft Corporation (Verified) Skype Software Sarl
    SkypeC2CAutoUpdateSvc.exe 1,792 K 1,348 K 2052 Updates Skype Click to Call Microsoft Corporation (Verified) Skype Software Sarl
    setup.exe 2,504 K 2,300 K 2108 Google Chrome Installer Google Inc. (Verified) Google Inc
    services.exe 2,852 K 3,888 K 504 Services and Controller app Microsoft Corporation (Verified) Microsoft Windows
    SearchIndexer.exe 24,000 K 20,452 K 4060 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
    RuntimeBroker.exe 3,456 K 2,820 K 4324 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
    RtkNGUI64.exe 3,844 K 884 K 5368 Realtek HD Audio Manager Realtek Semiconductor (Verified) Microsoft Windows Hardware Compatibility Publisher
    RTKAUDIOSERVICE64.EXE 1,264 K 1,424 K 1444 Realtek Audio Service Realtek Semiconductor (Verified) Microsoft Windows Hardware Compatibility Publisher
    RAVBg64.exe 5,376 K 4,240 K 1472 HD Audio Background Process Realtek Semiconductor (Verified) Microsoft Windows Hardware Compatibility Publisher
    procexp.exe 2,316 K 6,980 K 3792 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
    mDNSResponder.exe 1,308 K 1,612 K 2012 Bonjour Service Apple Inc. (Verified) Apple Inc.
    mbamservice.exe 197,812 K 85,180 K 2376 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
    mbamscheduler.exe 3,992 K 5,196 K 2244 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
    lsass.exe 4,612 K 7,188 K 516 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows
    HPWMISVC.exe 928 K 1,348 K 2164 HP WMI Service Hewlett-Packard Development Company, L.P. (Verified) Hewlett-Packard Company
    glcnd.exe Suspended 27,592 K 22,844 K 1632 Windows Reader Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    Fuel.Service.exe 1,272 K 1,652 K 1924 AMD Fuel Service Advanced Micro Devices, Inc. (No signature was present in the subject) Advanced Micro Devices, Inc.
    dasHost.exe 828 K 644 K 2188 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
    chrome.exe 56,672 K 66,064 K 4360 Google Chrome Google Inc. (Verified) Google Inc
    avgnsa.exe 6,984 K 7,384 K 2412 AVG Online Shield Service AVG Technologies CZ, s.r.o. (Verified) AVG Technologies CZ
    avgemca.exe 1,720 K 1,448 K 2420 AVG E-mail Scanner AVG Technologies CZ, s.r.o. (Verified) AVG Technologies CZ
    avgcsrva.exe 15,776 K 42,108 K 604 AVG Scanning Core Module - Server Part AVG Technologies CZ, s.r.o. (Verified) AVG Technologies CZ
    atiesrxx.exe 704 K 508 K 1124 AMD External Events Service Module AMD (Verified) Microsoft Windows Hardware Compatibility Publisher
    atieclxx.exe 2,016 K 2,136 K 1268 AMD External Events Client Module AMD (Verified) Microsoft Windows Hardware Compatibility Publisher
    Ath_CoexAgent.exe 1,560 K 1,600 K 2860 Atheros Coex Service Application Atheros (No signature was present in the subject) Atheros
    AERTSr64.exe 472 K 356 K 1900 Andrea filters APO access service (64-bit) Andrea Electronics Corporation (Verified) Microsoft Windows Hardware Compatibility Publisher
    AdminService.exe 1,352 K 1,660 K 1960 Windows Setup API Windows ® Win 7 DDK provider (Verified) Qualcomm Atheros
    ActivateDesktop.exe 1,140 K 820 K 5288 (Verified) Qualcomm Atheros
    39.0.2171.71_39.0.2171.65_chrome_updater.exe 812 K 504 K 4992 (Verified) Google Inc

    • 0

    #8
    Steviep

    Steviep

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 338 posts

    Attached File  HOMEPC.txt   103.4KB   558 downloadsHere is the Speccy text file and running the sfc /scannow however it is only 55% done on the verification stage after 40 mins


    Edited by Steviep, 26 November 2014 - 05:41 PM.

    • 0

    #9
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 24,625 posts
    • MVP

    In Process Explorer we see:

     

    Interrupts 3.21 0 K 0 K n/a Hardware Interrupts and DPCs

     

    This is very high.  Normally we get around .75 to 1.5. This is from my HP All in one:

     

    Interrupts n/a 1.29 0 K 0 K Hardware Interrupts and DPCs

     

    A higher number is more important than you would think.  So far I have found this to be caused by bad drivers or on a laptop by a bad battery.  To test for a bad battery, just shut it down, remove the big battery and plug it into the wall plug and boot up.  Run Process Explorer again and see if the number drops to a better value.  Since this is a win 8 I would think it is fairly new so not likely but you never know.

     

    Finding a bad driver is a bit harder.  I would start by going to the maker's website and see if there are any new drivers especially Synaptics TouchPad Enhancements.   If not then, boot into Safe Mode without networking and run Process Explorer again and see if the Interrupts value is normal.  

    Then try Safe Mode with Networking.  Then go in to MSCONFIG and do a diagnostic boot.  See http://www.computerp...fig-utility.htm

     

     

    Speccy says it is running a bit hot but not enough to slow it down.  Since it appears to be an HP, it's probably a real bear to open it to clean the heatsink so I'd just check the temps every 6  months or so to make sure it doesn't go over 65C.  (Make sure you are running it on a hard surface as a soft surface can block the air vents.)

     

    Hard drive appears to be in good shape and it has adequate RAM.

     

    I guess since you are in the UK, it's way past bedtime so won't expect to see the results of SFC until tomorrow.


    • 0

    #10
    Steviep

    Steviep

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 338 posts

    Morning Ron,

     

    Awoke to find on the command prompt window "windows Resource Protection found corrupt files but was unable to fix some of them. Details are included in the CBS.log windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.Log."

     

    I will do the things in you last post when I return from work this evening. Thanks again for your assistance


    • 0

    #11
    Steviep

    Steviep

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 338 posts

    Hi Ron,

     

    I've updated some of the drivers including the touchpad one and ran procexp again here is the log

     

    Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
    System Idle Process 86.46 0 K 4 K 0
    procexp64.exe 6.22 21,676 K 42,768 K 496 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Sysinternals
    Interrupts 3.23 0 K 0 K n/a Hardware Interrupts and DPCs
    dwm.exe 1.40 14,668 K 24,204 K 6328
    System 0.78 19,732 K 35,656 K 4
    csrss.exe 0.56 2,224 K 6,780 K 1592
    SynTPEnh.exe 0.47 3,548 K 12,044 K 1128
    mbam.exe 0.28 36,904 K 51,484 K 4336
    explorer.exe 0.25 62,660 K 95,172 K 3648 Windows Explorer Microsoft Corporation (Verified) Microsoft Windows
    TuneUpUtilitiesService64.exe 0.18 11,024 K 14,700 K 2944 AVG PC TuneUp Service AVG (Verified) AVG Netherlands B.V.
    CLMLSvc_P2G8.exe 0.04 2,060 K 700 K 868 CyberLink MediaLibray Service CyberLink (Verified) CyberLink
    BtTray.exe 0.02 42,100 K 48,052 K 4916 BtTray Qualcomm Atheros (Verified) Qualcomm Atheros
    RIconMan.exe 0.02 1,564 K 2,420 K 2284 Realtek Card Reader Patch Tool. Realsil Microelectronics Inc. (Verified) Realtek Semiconductor Corp
    avgwdsvc.exe 0.02 11,364 K 17,780 K 1420 AVG Watchdog Service AVG Technologies CZ, s.r.o. (Verified) AVG Technologies CZ
    svchost.exe 0.02 5,480 K 10,104 K 860 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 0.01 3,968 K 8,772 K 3272 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    avgidsagent.exe 0.01 14,472 K 22,428 K 2040 AVG Identity Protection Service AVG Technologies CZ, s.r.o. (Verified) AVG Technologies CZ
    TuneUpUtilitiesApp64.exe < 0.01 1,956 K 9,468 K 6108 AVG PC TuneUp AVG (Verified) AVG Netherlands B.V.
    svchost.exe < 0.01 65,352 K 72,240 K 1324 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    avgrsa.exe < 0.01 22,384 K 41,388 K 532
    csrss.exe < 0.01 1,836 K 3,124 K 852
    BtvStack.exe < 0.01 18,252 K 22,056 K 4568 Extension Core Qualcomm Atheros Commnucations (Verified) Qualcomm Atheros
    wmpnetwk.exe 5,536 K 4,076 K 5052 Windows Media Player Network Sharing Service Microsoft Corporation (Verified) Microsoft Windows
    WmiPrvSE.exe 1,588 K 5,656 K 4996
    winlogon.exe 1,312 K 11,088 K 4952
    wininit.exe 856 K 2,644 K 944
    taskhostex.exe 8,132 K 14,416 K 3448 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
    taskhost.exe 7,820 K 10,452 K 4372
    SynTPHelper.exe 736 K 3,752 K 3680
    svchost.exe 4,044 K 5,568 K 808 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 13,152 K 19,228 K 1564 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 31,808 K 41,932 K 1208 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 8,928 K 11,636 K 1264 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 16,784 K 15,872 K 1780 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 16,520 K 17,512 K 1188 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 3,224 K 4,240 K 1960 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 1,232 K 2,720 K 3468 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    spoolsv.exe 4,020 K 5,148 K 1732 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows
    smss.exe 276 K 1,000 K 312
    SkypeC2CPNRSvc.exe 1,732 K 2,264 K 2072 Phone Number Recognition (PNR) module Microsoft Corporation (Verified) Skype Software Sarl
    SkypeC2CAutoUpdateSvc.exe 1,064 K 1,920 K 1804 Updates Skype Click to Call Microsoft Corporation (Verified) Skype Software Sarl
    setup.exe 2,384 K 2,216 K 5140
    services.exe 2,680 K 4,708 K 276
    SearchProtocolHost.exe 1,700 K 7,240 K 1968
    SearchIndexer.exe 29,108 K 29,568 K 4196 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
    SearchFilterHost.exe 1,104 K 4,220 K 5380
    RuntimeBroker.exe 4,244 K 15,336 K 6248 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
    RtkNGUI64.exe 3,840 K 596 K 4644 Realtek HD Audio Manager Realtek Semiconductor (Verified) Microsoft Windows Hardware Compatibility Publisher
    RTKAUDIOSERVICE64.EXE 1,264 K 2,692 K 1444 Realtek Audio Service Realtek Semiconductor (Verified) Microsoft Windows Hardware Compatibility Publisher
    RAVBg64.exe 5,368 K 10,728 K 6952
    procexp.exe 2,228 K 6,980 K 488 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
    msiexec.exe 7,312 K 12,112 K 3948 Windows® installer Microsoft Corporation (Verified) Microsoft Windows
    mDNSResponder.exe 1,328 K 2,980 K 1604 Bonjour Service Apple Inc. (Verified) Apple Inc.
    mbamservice.exe 198,504 K 91,264 K 2628 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
    mbamscheduler.exe 4,064 K 6,428 K 2328 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
    lsass.exe 4,844 K 8,752 K 280 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows
    HPWMISVC.exe 924 K 2,136 K 2140 HP WMI Service Hewlett-Packard Development Company, L.P. (Verified) Hewlett-Packard Company
    HPSupportSolutionsFrameworkService.exe 15,024 K 22,768 K 3572 SolutionsFrameworkService Hewlett-Packard Company (Verified) Hewlett-Packard Company
    glcnd.exe Suspended 27,464 K 6,676 K 4848 Windows Reader Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    Fuel.Service.exe 1,252 K 2,592 K 1932 AMD Fuel Service Advanced Micro Devices, Inc. (No signature was present in the subject) Advanced Micro Devices, Inc.
    dasHost.exe 796 K 1,468 K 2264
    avgnsa.exe 7,452 K 11,248 K 2416
    avgemca.exe 1,784 K 4,184 K 2436
    avgcsrva.exe 17,956 K 114,036 K 600
    atiesrxx.exe 708 K 1,852 K 1152 AMD External Events Service Module AMD (Verified) Microsoft Windows Hardware Compatibility Publisher
    atieclxx.exe 1,992 K 7,540 K 5592
    Ath_CoexAgent.exe 1,640 K 3,176 K 2096 Atheros Coex Service Application Atheros (No signature was present in the subject) Atheros
    AERTSr64.exe 464 K 1,084 K 1916 Andrea filters APO access service (64-bit) Andrea Electronics Corporation (Verified) Microsoft Windows Hardware Compatibility Publisher
    AdminService.exe 1,380 K 2,568 K 1980 Windows Setup API Windows ® Win 7 DDK provider (Verified) Qualcomm Atheros
    ActivateDesktop.exe 1,132 K 4,724 K 4204 (Verified) Qualcomm Atheros
    39.0.2171.71_chrome_installer.exe 884 K 960 K 5352

    • 0

    #12
    Steviep

    Steviep

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 338 posts
    Vino's Event Viewer v01c run on Windows 7 in English
    Report run at 27/11/2014 18:18:43
     
    Note: All dates below are in the format dd/mm/yyyy
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Critical Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Error Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 27/11/2014 06:15:38
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 27/11/2014 06:14:54
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 27/11/2014 05:55:54
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 27/11/2014 05:55:24
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 26/11/2014 23:00:49
    Type: Error Category: 0
    Event: 7000 Source: Service Control Manager
    The AVG Theme Extension service failed to start due to the following error:  The executable program that this service is configured to run in does not implement the service.
     
    Log: 'System' Date/Time: 26/11/2014 22:58:53
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {4545DEA0-2DFC-4906-A728-6D986BA399A9} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 26/11/2014 22:58:52
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {4545DEA0-2DFC-4906-A728-6D986BA399A9} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 26/11/2014 22:58:47
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {4545DEA0-2DFC-4906-A728-6D986BA399A9} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 26/11/2014 22:58:46
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {4545DEA0-2DFC-4906-A728-6D986BA399A9} did not register with DCOM within the required timeout.
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Warning Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 27/11/2014 06:15:50
    Type: Warning Category: 212
    Event: 219 Source: Microsoft-Windows-Kernel-PnP
    The driver \Driver\WudfRd failed to load for the device SWD\SensorsAndLocationEnum\LPSensorSWDevice.

    • 0

    #13
    Steviep

    Steviep

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 338 posts
    Vino's Event Viewer v01c run on Windows 7 in English
    Report run at 27/11/2014 18:18:43
     
    Note: All dates below are in the format dd/mm/yyyy
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Critical Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Error Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 27/11/2014 06:15:38
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 27/11/2014 06:14:54
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 27/11/2014 05:55:54
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 27/11/2014 05:55:24
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 26/11/2014 23:00:49
    Type: Error Category: 0
    Event: 7000 Source: Service Control Manager
    The AVG Theme Extension service failed to start due to the following error:  The executable program that this service is configured to run in does not implement the service.
     
    Log: 'System' Date/Time: 26/11/2014 22:58:53
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {4545DEA0-2DFC-4906-A728-6D986BA399A9} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 26/11/2014 22:58:52
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {4545DEA0-2DFC-4906-A728-6D986BA399A9} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 26/11/2014 22:58:47
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {4545DEA0-2DFC-4906-A728-6D986BA399A9} did not register with DCOM within the required timeout.
     
    Log: 'System' Date/Time: 26/11/2014 22:58:46
    Type: Error Category: 0
    Event: 10010 Source: Microsoft-Windows-DistributedCOM
    The server {4545DEA0-2DFC-4906-A728-6D986BA399A9} did not register with DCOM within the required timeout.
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    'System' Log - Warning Type
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Log: 'System' Date/Time: 27/11/2014 06:15:50
    Type: Warning Category: 212
    Event: 219 Source: Microsoft-Windows-Kernel-PnP
    The driver \Driver\WudfRd failed to load for the device SWD\SensorsAndLocationEnum\LPSensorSWDevice.

    • 0

    #14
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 24,625 posts
    • MVP
     
    Log: 'System' Date/Time: 26/11/2014 23:00:49
    Type: Error Category: 0
    Event: 7000 Source: Service Control Manager

    The AVG Theme Extension service failed to start due to the following error:  The executable program that this service is configured to run in does not implement the service.

     

     

     

    Appears AVG has a problem.  Perhaps an uninstall and then a reinstall with a fresh download might help.

     

    The Interrupts % doesn't seem to be any better after the updates.  


    • 0






    Similar Topics

    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users

    As Featured On:

    Microsoft Yahoo BBC MSN PC Magazine Washington Post HP