Hello! Some links don't work in websites when I click on them and not all things appear in websites when I browse to website. Chrome shows the missing things that Internet Explorer doesn't.
Also when browsing to different websites I get an invalid certificate errors.
Please help.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-07-2017
Ran by family (administrator) on FAMILY-PC (05-07-2017 12:49:57)
Running from C:\Users\family\Desktop
Loaded Profiles: family (Available Profiles: family)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Control Panel Client\nvcplui.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(CMedia) C:\Program Files\ASUS Xonar Essence STX Audio\Customapp\AsusAudioCenter.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_26_0_0_131_ActiveX.exe
(CrossWire Bible Society) C:\Program Files (x86)\CrossWire\The SWORD Project\sword.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
GroupPolicyScripts: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{2354B7A9-E94C-43D0-B33E-A9C5CE00E8A2}: [DhcpNameServer]
Internet Explorer:
HKU\S-1-5-21-3923717162-344275592-1238881661-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com.au/
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-05-05] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-05] (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll [2017-04-23] ()
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-05] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-05] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll [2017-04-23] ()
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version= -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2009-11-10] (Yahoo! Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
CHR Profile: C:\Users\family\AppData\Local\Google\Chrome\User Data\Default [2017-07-05]
CHR Extension: (Google Docs) - C:\Users\family\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-04-21]
CHR Extension: (Google Sheets) - C:\Users\family\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-04-21]
CHR Extension: (Google Docs Offline) - C:\Users\family\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-21]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [173344 2007-02-06] (Logitech Inc.)
S4 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [452152 2017-04-20] (NVIDIA Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2725376 2011-03-10] (C-Media Inc)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-05-14] ()
R0 mv64xx; C:\Windows\System32\DRIVERS\mv64xx.sys [322088 2009-01-29] (Marvell Semiconductor, Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-05 12:49 - 2017-07-05 12:49 - 00000000 ____D C:\Users\family\Desktop\FRST-OlderVersion
2017-07-04 12:55 - 2017-07-04 12:56 - 00000834 _____ C:\Users\family\Documents\Mine2.xml
2017-07-04 12:50 - 2017-07-04 12:50 - 00000834 _____ C:\Users\family\Documents\as.xml
2017-07-04 12:38 - 2017-07-04 12:39 - 00110740 _____ C:\Users\family\Downloads\pizza2_11249772.jar
2017-07-04 12:13 - 2017-07-04 12:13 - 00000000 ____D C:\Program Files (x86)\Launch4j
2017-07-03 23:39 - 2017-07-04 00:28 - 00000000 ____D C:\Users\family\AppData\Roaming\Paltalk
2017-07-03 23:39 - 2017-07-03 23:39 - 00000000 ____D C:\Users\family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paltalk Messenger
2017-07-03 23:39 - 2017-07-03 23:39 - 00000000 ____D C:\Program Files (x86)\Paltalk Messenger
2017-07-02 16:55 - 2017-07-02 16:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger
2017-07-02 11:31 - 2017-07-02 11:31 - 00000000 ____D C:\Users\family\AppData\Roaming\Yahoo!
2017-07-02 11:31 - 2017-07-02 11:31 - 00000000 ____D C:\Users\family\AppData\Local\Yahoo
2017-07-02 11:30 - 2017-07-02 11:30 - 00000000 ____D C:\ProgramData\Yahoo!
2017-06-29 14:53 - 2017-06-29 14:53 - 00000000 ____D C:\Users\family\AppData\Roaming\Yahoo Messenger
2017-06-27 22:25 - 2017-06-29 14:53 - 00000000 ____D C:\Users\family\AppData\Local\yahoomessenger
2017-06-27 22:25 - 2017-06-27 22:25 - 00000000 ____D C:\Users\family\AppData\Local\SquirrelTemp
2017-06-27 22:24 - 2017-06-27 22:24 - 00749404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-06-27 22:22 - 2017-07-02 11:30 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2017-06-26 15:15 - 2017-06-29 15:48 - 00000000 ____D C:\Users\family\AppData\Roaming\Skype
2017-06-26 15:15 - 2017-06-26 15:15 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-06-26 15:15 - 2017-06-26 15:15 - 00000000 ____D C:\ProgramData\Skype
2017-06-26 15:15 - 2017-06-26 15:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-06-23 17:39 - 2017-06-23 17:40 - 07649280 _____ C:\Program Files (x86)\GUTD0D6.tmp
2017-06-23 17:39 - 2017-06-23 17:39 - 00000000 ____D C:\Program Files (x86)\GUMD0D5.tmp
2017-06-23 12:22 - 2017-06-23 12:22 - 00000000 ____D C:\ProgramData\Emsisoft
2017-06-23 12:21 - 2017-06-23 17:34 - 00000000 ____D C:\EEK
2017-06-22 14:36 - 2017-06-24 00:01 - 00000000 ____D C:\Program Files\Google
2017-06-22 14:35 - 2017-06-22 14:35 - 00000000 ____D C:\Users\family\AppData\Local\CEF
2017-06-22 14:31 - 2017-06-23 17:37 - 00000000 ____D C:\ProgramData\AVAST Software
2017-06-21 12:35 - 2017-06-21 12:35 - 04110280 _____ C:\Users\family\Desktop\AdwCleaner.exe
2017-06-21 12:28 - 2017-06-21 12:28 - 00001879 _____ C:\Users\family\Desktop\JRT.txt
2017-06-21 12:19 - 2017-06-21 12:19 - 01663672 _____ (Malwarebytes) C:\Users\family\Desktop\JRT.exe
2017-06-21 11:54 - 2017-06-21 11:55 - 00008011 _____ C:\Users\family\Desktop\Fixlog.txt
2017-06-20 16:44 - 2017-06-20 16:44 - 00023659 _____ C:\Users\family\Desktop\Addition.txt
2017-06-20 16:43 - 2017-07-05 12:50 - 00006232 _____ C:\Users\family\Desktop\FRST.txt
2017-06-20 16:43 - 2017-07-05 12:49 - 00000000 ____D C:\FRST
2017-06-20 16:40 - 2017-07-05 12:49 - 02436608 _____ (Farbar) C:\Users\family\Desktop\FRST64.exe
2017-06-19 20:13 - 2017-06-19 20:13 - 00002064 _____ C:\Users\Public\Desktop\Logitech QuickCam.lnk
2017-06-19 20:13 - 2017-06-19 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2017-06-19 20:13 - 2017-06-19 20:13 - 00000000 ____D C:\ProgramData\Logitech
2017-06-19 20:13 - 2017-06-19 20:13 - 00000000 ____D C:\ProgramData\Logishrd
2017-06-19 20:04 - 2017-06-19 20:04 - 00220628 _____ C:\Windows\ntbtlog.txt
2017-06-19 19:55 - 2017-06-25 09:59 - 00000000 ____D C:\Windows\system32\appmgmt
2017-06-18 23:13 - 2017-06-18 23:13 - 00295721 _____ C:\Users\family\Downloads\repository.thgiliwt-1.0.3.zip
2017-06-09 17:14 - 2017-06-09 17:14 - 00121522 _____ C:\Users\family\Desktop\submission.jar
2017-06-08 22:39 - 2017-06-08 22:39 - 00000000 ____D C:\Users\family\AppData\Local\Barbary Software
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-05 11:16 - 2017-04-27 10:12 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-07-05 10:55 - 2017-05-17 23:19 - 00000000 ____D C:\Users\family\AppData\Local\PokerStars
2017-07-05 09:38 - 2009-07-14 15:13 - 00716598 _____ C:\Windows\system32\PerfStringBackup.INI
2017-07-05 09:38 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\inf
2017-07-05 09:34 - 2009-07-14 15:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-07-05 00:18 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\system32\NDF
2017-07-05 00:13 - 2017-04-17 01:45 - 00000000 ____D C:\Users\family\AppData\Local\ElevatedDiagnostics
2017-07-04 17:10 - 2017-05-10 20:35 - 00000000 ____D C:\Users\family\AppData\Local\CrashDumps
2017-07-04 16:10 - 2017-04-21 00:19 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2017-07-04 16:09 - 2017-04-21 00:19 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-07-04 16:08 - 2017-04-26 14:50 - 00000978 _____ C:\Users\family\AppData\Local\7F68A003.il
2017-07-04 16:08 - 2017-04-26 14:50 - 00000280 _____ C:\Users\family\AppData\Local\IndexIE_7F68A003.il
2017-07-04 12:13 - 2017-05-25 00:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Launch4j
2017-07-03 00:21 - 2017-04-17 02:00 - 00000000 ____D C:\Users\family\AppData\Local\QuickPar
2017-07-01 16:16 - 2017-05-05 12:35 - 00000000 ____D C:\Users\family\Documents\NetBeansProjects
2017-07-01 00:55 - 2017-05-17 23:19 - 00000000 ____D C:\Program Files (x86)\PokerStars
2017-06-29 15:14 - 2017-04-23 11:37 - 00007605 _____ C:\Users\family\AppData\Local\Resmon.ResmonCfg
2017-06-29 11:52 - 2017-04-17 22:31 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-29 11:52 - 2017-04-17 22:31 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-06-25 10:21 - 2017-04-16 09:10 - 00000000 ____D C:\Users\family\AppData\Local\Adobe
2017-06-25 10:14 - 2017-04-23 09:23 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-06-25 10:14 - 2017-04-23 09:23 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-06-25 10:13 - 2017-04-23 09:23 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-06-25 10:13 - 2017-04-23 09:23 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-25 09:50 - 2017-05-04 09:54 - 00000000 ____D C:\ProgramData\Package Cache
2017-06-25 00:03 - 2009-07-14 14:45 - 00015696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-06-25 00:03 - 2009-07-14 14:45 - 00015696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-06-24 01:41 - 2017-05-25 19:49 - 00000000 ____D C:\Users\family\AppData\LocalLow\Temp
2017-06-24 00:01 - 2017-04-17 22:30 - 00000000 ____D C:\Program Files (x86)\Google
2017-06-23 17:40 - 2017-04-17 22:30 - 00000000 ____D C:\Users\family\AppData\Local\Google
2017-06-23 12:08 - 2009-07-14 13:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-06-21 12:43 - 2017-04-21 00:01 - 00000000 ____D C:\AdwCleaner
2017-06-19 20:13 - 2017-04-17 22:36 - 00000000 ____D C:\Program Files\Common Files\LogiShrd
2017-06-19 20:13 - 2017-04-17 22:35 - 00000000 ____D C:\Program Files (x86)\Logitech
2017-06-15 00:59 - 2017-04-17 09:20 - 00000000 ____D C:\Users\family\AppData\Roaming\Azureus
2017-06-15 00:59 - 2017-04-17 09:20 - 00000000 ____D C:\Program Files (x86)\Vuze
2017-06-14 14:36 - 2017-04-15 15:13 - 00000000 ____D C:\Windows\system32\SPReview
2017-06-08 09:16 - 2009-07-14 15:08 - 00032548 _____ C:\Windows\Tasks\SCHEDLGU.TXT
==================== Files in the root of some directories =======
2017-06-23 17:39 - 2017-06-23 17:40 - 7649280 _____ () C:\Program Files (x86)\GUTD0D6.tmp
2017-05-12 18:21 - 2017-06-03 14:24 - 0000600 _____ () C:\Users\family\AppData\Roaming\winscp.rnd
2017-04-26 14:50 - 2017-07-04 16:08 - 0000978 _____ () C:\Users\family\AppData\Local\7F68A003.il
2017-04-26 14:50 - 2017-07-04 16:08 - 0000280 _____ () C:\Users\family\AppData\Local\IndexIE_7F68A003.il
2017-05-12 18:21 - 2017-05-12 18:21 - 0000600 _____ () C:\Users\family\AppData\Local\PUTTY.RND
2017-04-23 11:37 - 2017-06-29 15:14 - 0007605 _____ () C:\Users\family\AppData\Local\Resmon.ResmonCfg
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-07-02 00:54
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-07-2017
Ran by family (05-07-2017 12:50:22)
Running from C:\Users\family\Desktop
Windows 7 Professional Service Pack 1 (X64) (2017-04-15 02:19:03)
Boot Mode: Normal
==================== Accounts: =============================
Administrator (S-1-5-21-3923717162-344275592-1238881661-500 - Administrator - Disabled)
family (S-1-5-21-3923717162-344275592-1238881661-1000 - Administrator - Enabled) => C:\Users\family
Guest (S-1-5-21-3923717162-344275592-1238881661-501 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 26 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Reader 9.5.5 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A95000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 381.89 - NVIDIA Corporation) Hidden
ASUS Xonar Essence STX Audio Driver (HKLM\...\C-Media Oxygen HD Audio Driver) (Version: - )
BlueJ (HKLM-x32\...\{7D66971C-652B-4065-A6B1-B3EE313C254B}) (Version: 3.1.7 - BlueJ Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: - Google Inc.) Hidden
Java 8 Update 131 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
Java SE Development Kit 8 Update 131 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180131}) (Version: 8.0.1310.11 - Oracle Corporation)
Launch4j 3.8 (HKLM-x32\...\Launch4j) (Version: 3.8 - Grzegorz Kowal)
Logitech QuickCam (HKLM\...\{192E85C6-2B8A-4217-AD30-ECA5CE19DB23}) (Version: 10.51.2029 - Logitech Inc.)
Logitech® Camera Driver (HKLM-x32\...\QcDrv) (Version: - )
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
MPC-HC 1.7.10 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.10 - MPC-HC Team)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NetBeans IDE 8.2 (HKLM\...\nbi-nb-base- (Version: 8.2 - NetBeans.org)
NewsLeecher v3.9 Final (HKLM-x32\...\NewsLeecher_is1) (Version: - )
NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NvTelemetry (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry) (Version: - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Paltalk Messenger 11.7 (HKLM-x32\...\Paltalk Messenger) (Version: 11.7.639.17814 - AVM Software Inc.)
PokerStars (HKLM-x32\...\PokerStars) (Version: - PokerStars)
QuickPar 0.9 (HKLM-x32\...\QuickPar) (Version: 0.9 - Peter B. Clements)
Skype™ 7.37 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.37.103 - Skype Technologies S.A.)
The SWORD Project (HKLM-x32\...\The SWORD Project) (Version: 1.5.9 - The Crosswire Bible Society)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: - Elaborate Bytes)
Vuze (HKLM-x32\...\8461-7759-5462-8226) (Version: 4.5 - Vuze Inc.)
Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc)
WinRAR 5.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
WinSCP 4.3.2 (HKLM-x32\...\winscp3_is1) (Version: 4.3.2 - Martin Prikryl)
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers01: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-15] (Elaborate Bytes AG)
ContextMenuHandlers01: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-08-27] (Alexander Roshal)
ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers01: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers02: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-15] (Elaborate Bytes AG)
ContextMenuHandlers03: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers04: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers05: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2014-07-03] (NVIDIA Corporation)
ContextMenuHandlers05: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
ContextMenuHandlers06: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-08-27] (Alexander Roshal)
ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File
ContextMenuHandlers06: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => -> No File
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {B7F1DEBC-C07C-4D87-B179-DF25CF821828} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-04-17] (Google Inc.)
Task: {DA9193C1-C921-41AA-AD09-3869AD04CE4C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-04-17] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2017-04-16 00:47 - 2014-07-03 04:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-04-16 01:37 - 2011-04-19 14:56 - 00143360 ____N () C:\Program Files\ASUS Xonar Essence STX Audio\Customapp\VmixP8.dll
2006-10-26 13:56 - 2006-10-26 13:56 - 00757008 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 12:34 - 2017-04-21 01:10 - 00454351 ____R C:\Windows\system32\Drivers\etc\hosts
There are 15592 more lines.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3923717162-344275592-1238881661-1000\Control Panel\Desktop\\Wallpaper ->
DNS Servers: -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: LVSrvLauncher => 2
MSCONFIG\Services: NVDisplay.ContainerLocalSystem => 2
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: NvTelemetryContainer => 2
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: Cmaudio8788 => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd
MSCONFIG\startupreg: Cmaudio8788GX => C:\Windows\syswow64\HsMgr.exe Envoke
MSCONFIG\startupreg: Cmaudio8788GX64 => C:\Windows\system\HsMgr64.exe Envoke
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: LogitechCommunicationsManager => "C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
MSCONFIG\startupreg: LogitechQuickCamRibbon => "C:\Program Files (x86)\Logitech\QuickCam10\QuickCam10.exe" /hide
MSCONFIG\startupreg: Messenger (Yahoo!) => "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Yahoo Messenger Updater => "C:\Users\family\AppData\Roaming\Yahoo Messenger\YMUpdater\YMUpdater.exe"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [TCP Query User{F5BE2AA9-9B78-451C-B2CE-50766396843A}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{26337FB3-857D-4853-9DF8-B29AAD12ECF7}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [{19BE65CA-8192-4EDC-9225-AE68991234D8}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{3CF1339C-4828-4D23-A0AD-1318042FBC36}] => (Allow) %SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
FirewallRules: [{5BC0BC7D-BF3C-4219-9C20-475478C8E718}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{18FE7F00-466B-4F8A-92A4-95A7C5856AAC}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{8E9CD088-3113-495C-8CF6-5C7D981AE408}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
==================== Restore Points =========================
ATTENTION: System Restore is disabled
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
Error: (07/05/2017 09:34:21 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x00000000.
Error: (07/05/2017 09:34:21 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
Error: (07/05/2017 09:28:23 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x00000000.
Error: (07/05/2017 09:28:23 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
Error: (07/04/2017 10:59:06 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Windows license activation failed. Error 0x00000000.
Error: (07/04/2017 10:59:06 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
Error: (07/04/2017 05:23:07 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.18639 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 1330
Start Time: 01d2f496410cdd29
Termination Time: 46
Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Report Id:
Error: (07/04/2017 05:10:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18639, time stamp: 0x58d6bb0d
Faulting module name: Flash32_26_0_0_131.ocx, version:, time stamp: 0x5941bb71
Exception code: 0x40000015
Fault offset: 0x007f2941
Faulting process id: 0x154c
Faulting application start time: 0x01d2f493bc6f37da
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: C:\Windows\SysWOW64\Macromed\Flash\Flash32_26_0_0_131.ocx
Report Id: e671a267-6087-11e7-b311-485b3917444d
Error: (07/04/2017 05:04:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18639, time stamp: 0x58d6bb0d
Faulting module name: jscript9.dll, version: 11.0.9600.18639, time stamp: 0x58d6bfcf
Exception code: 0xc0000005
Fault offset: 0x000adf1f
Faulting process id: 0x9d4
Faulting application start time: 0x01d2f49307376791
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: C:\Windows\SysWOW64\jscript9.dll
Report Id: f9a84e62-6086-11e7-b311-485b3917444d
Error: (07/04/2017 04:59:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18639, time stamp: 0x58d6bb0d
Faulting module name: Flash32_26_0_0_131.ocx, version:, time stamp: 0x5941bb71
Exception code: 0xc0000005
Fault offset: 0x007f9de0
Faulting process id: 0x7ec
Faulting application start time: 0x01d2f491d9f69976
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: C:\Windows\SysWOW64\Macromed\Flash\Flash32_26_0_0_131.ocx
Report Id: 43439271-6086-11e7-b311-485b3917444d
System errors:
Error: (07/05/2017 09:34:16 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: The default transaction resource manager on volume G: encountered a non-retryable error and could not start. The data contains the error code.
Error: (07/05/2017 09:34:16 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (07/05/2017 09:34:14 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (07/05/2017 09:34:11 AM) (Source: volmgr) (EventID: 46) (User: )
Description: Crash dump initialization failed!
Error: (07/05/2017 09:29:47 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Diagnostic System Host service hung on starting.
Error: (07/05/2017 09:29:45 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Diagnostic Service Host service hung on starting.
Error: (07/05/2017 09:28:18 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: The default transaction resource manager on volume G: encountered a non-retryable error and could not start. The data contains the error code.
Error: (07/05/2017 09:28:18 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (07/05/2017 09:28:16 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
Error: (07/05/2017 09:28:13 AM) (Source: volmgr) (EventID: 46) (User: )
Description: Crash dump initialization failed!
==================== Memory info ===========================
Processor: Intel® Core i7 CPU 975 @ 3.33GHz
Percentage of memory in use: 55%
Total physical RAM: 6135.11 MB
Available physical RAM: 2720.52 MB
Total Virtual: 6133.29 MB
Available Virtual: 1726.79 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:219.87 GB) (Free:186.87 GB) NTFS
Drive d: () (Fixed) (Total:199.22 GB) (Free:29.55 GB) NTFS
Drive f: () (Fixed) (Total:931.51 GB) (Free:7.19 GB) NTFS
Drive g: (Local Disk) (Fixed) (Total:1863.01 GB) (Free:53.43 GB) NTFS
==================== MBR & Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: D4AEE926)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A5A370FC)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 419.2 GB) (Disk ID: 34352478)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=219.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=199.2 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================