Solved Malware ?? Having trouble removing

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by User (administrator) on YOUR-311D0C6927 on 17-03-2015 16:20:13
Running from C:\Documents and Settings\User\My Documents\Downloads
Loaded Profiles: User (Available profiles: User & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2015\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcsrvx.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Agere Systems) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehrecvr.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehSched.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgnsx.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgemcx.exe
(Oracle Corporation) C:\WINDOWS\system32\java.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Alcor Micro, Corp.) C:\Program Files\Digital Media Reader\readericon45G.exe
(Pure Networks, Inc.) C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
(Linksys LLC - A Division of Cisco Systems) C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe
(InstallShield Software Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Nikon Corporation) C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
(Sage) C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe
(CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
(cyberlink) C:\Program Files\CyberLink\Shared Files\brs.exe
(Sage) C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe
(SigmaTel, Inc.) C:\Program Files\SigmaTel\C-Major Audio\wdm\stacsv.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\WINDOWS\ehome\mcrdsvc.exe
() C:\Documents and Settings\All Users\Application Data\Clickfree\FullImagingBackup\FullImagingService.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehmsas.exe
(Pure Networks, Inc.) C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\dllhost.exe
(Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe
(Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Storage Appliance Corp.) C:\Documents and Settings\All Users\Application Data\Clickfree\cfagent.exe
(Storage Appliance Corp.) C:\Documents and Settings\All Users\Application Data\Clickfree\FullImagingBackup\FibReminder.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe
(Microsoft Corporation) C:\Program Files\Windows Desktop Search\WindowsSearch.exe
(Dropbox, Inc.) C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ehTray] => C:\WINDOWS\ehome\ehtray.exe [64512 2005-08-05] (Microsoft Corporation)
HKLM\...\Run: [readericon] => C:\Program Files\Digital Media Reader\readericon45G.exe [139264 2005-12-09] (Alcor Micro, Corp.)
HKLM\...\Run: [IntelAudioStudio] => C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe [8744960 2006-01-15] (Intel Corporation)
HKLM\...\Run: [nmctxth] => C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe [648504 2008-05-16] (Pure Networks, Inc.)
HKLM\...\Run: [LELA] => C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe [131072 2008-05-01] (Linksys LLC - A Division of Cisco Systems)
HKLM\...\Run: [ISUSPM Startup] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-14] (InstallShield Software Corporation)
HKLM\...\Run: [ISUSScheduler] => C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-06-14] (InstallShield Software Corporation)
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM\...\Run: [Google Desktop Search] => C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-24] (Google)
HKLM\...\Run: [Nikon Transfer Monitor] => C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe [479232 2009-09-15] (Nikon Corporation)
HKLM\...\Run: [ConnectionManager] => C:\Program Files\Winsim\ConnectionManager\Simply.SystemTrayIcon.exe [95560 2010-08-24] (Sage)
HKLM\...\Run: [UpdateLBPShortCut] => C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM\...\Run: [MDS_Menu] => C:\Program Files\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.)
HKLM\...\Run: [CLMLServer] => C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-12-15] (CyberLink)
HKLM\...\Run: [UpdateP2GoShortCut] => C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM\...\Run: [RemoteControl9] => C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2010-08-02] (CyberLink Corp.)
HKLM\...\Run: [BDRegion] => C:\Program Files\Cyberlink\Shared files\brs.exe [75048 2010-11-23] (cyberlink)
HKLM\...\Run: [UpdatePPShortCut] => C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM\...\Run: [UCam_Menu] => C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM\...\Run: [LGODDFU] => blrun
HKLM\...\Run: [UpdatePSTShortCut] => C:\Program Files\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe [222504 2010-12-23] (CyberLink Corp.)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3723728 2015-03-06] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-898855220-153585211-1186937704-1006\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [68856 2009-01-15] (Google Inc.)
HKU\S-1-5-21-898855220-153585211-1186937704-1006\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-13] (Microsoft Corporation)
HKU\S-1-5-21-898855220-153585211-1186937704-1006\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-08-16] (Hewlett-Packard Company)
HKU\S-1-5-21-898855220-153585211-1186937704-1006\...\Run: [ClickfreeMonitor] => c:\documents and settings\all users\application data\Clickfree\cfagent.exe [354632 2013-11-28] (Storage Appliance Corp.)
HKU\S-1-5-21-898855220-153585211-1186937704-1006\...\Run: [FibReminder] => c:\documents and settings\all users\application data\Clickfree\FullImagingBackup\FibReminder.exe [3634504 2013-11-28] (Storage Appliance Corp.)
HKU\S-1-5-21-898855220-153585211-1186937704-1006\...\Run: [HP Officejet 6600 (NET)] => C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe [1837672 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-898855220-153585211-1186937704-1006\...\MountPoints2: {54b03352-fe16-11dd-a60c-001676ae9e0e} - I:\LaunchU3.exe -a
HKU\S-1-5-21-898855220-153585211-1186937704-1006\...\MountPoints2: {62a02ca8-03bc-11e3-a32b-001676ae9e0e} - I:\FIBPGuard.exe
HKU\S-1-5-21-898855220-153585211-1186937704-1006\...\MountPoints2: {74108e3c-c3ac-11df-a670-001676ae9e0e} - K:\LaunchU3.exe -a
HKU\S-1-5-21-898855220-153585211-1186937704-1006\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\wpgldfsh.scr [4396544 2004-08-10] (Microsoft Corporation)
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-06-24] (Google)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [MOBK] -> {3c3f3c1a-9153-7c05-f938-622e7003894d} => No File
ShellIconOverlayIdentifiers: [MOBK2] -> {e6ea1d7d-144e-b977-98c4-84c53c1a69d0} => No File
ShellIconOverlayIdentifiers: [MOBK3] -> {b4caf489-1eec-c617-49ad-8d7088598c06} => No File
BootExecute: autocheck autochk * C:\PROGRA~1\AVG\AVG2015\avgrsx.exe /sync /restart

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
URLSearchHook: [S-1-5-21-898855220-153585211-1186937704-1006] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-898855220-153585211-1186937704-1006 -> DefaultScope {A7C98B7E-237D-4908-B432-C16522594744} URL = http://www.google.ca/search?q={sear...={outputEncoding}&sourceid=ie7&rlz=1I7GFRD_en
SearchScopes: HKU\S-1-5-21-898855220-153585211-1186937704-1006 -> {70D46D94-BF1E-45ED-B567-48701376298E} URL = http://localhost:4664/search&s=Su2iV9a950zjvqVPauNOvSEfF6Q?q={searchTerms}
SearchScopes: HKU\S-1-5-21-898855220-153585211-1186937704-1006 -> {A7C98B7E-237D-4908-B432-C16522594744} URL = http://www.google.ca/search?q={sear...={outputEncoding}&sourceid=ie7&rlz=1I7GFRD_en
SearchScopes: HKU\S-1-5-21-898855220-153585211-1186937704-1006 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://ca.search.yahoo.com/search?fr=mcafee&p={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-01-17] (Oracle Corporation)
BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-02] (Google Inc.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.10.11023.1534\swg.dll [2015-03-02] (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-01-17] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-02] (Google Inc.)
Toolbar: HKU\S-1-5-21-898855220-153585211-1186937704-1006 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-02] (Google Inc.)
Toolbar: HKU\S-1-5-21-898855220-153585211-1186937704-1006 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://support.gateway.com/support/profiler/PCPitStop.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231983037312
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll [2008-08-03] (Pure Networks, Inc.)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 64.59.144.91 64.59.150.137

FireFox:
========
FF ProfilePath: C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\w5g6r5ya.default-1423587237125
FF DefaultSearchEngine.US: Google
FF Homepage: mozilla firefox home page
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-01-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-01-17] (Oracle Corporation)
FF Plugin: @mcafee.com/MVT -> C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-02-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-02-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-02-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-02-25] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-02-25] (Apple Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2013-10-09]
FF Extension: RightToClick - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\w5g6r5ya.default-1423587237125\Extensions\{cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi [2015-02-23]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-02-12]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2008-08-26] (Agere Systems)
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3416016 2015-03-06] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [309232 2015-03-06] (AVG Technologies CZ, s.r.o.)
S2 CLKMSVC10_E92D8507; C:\Program Files\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [240112 2010-11-23] (CyberLink)
R2 FullImagingService; c:\documents and settings\all users\application data\Clickfree\FullImagingBackup\FullImagingService.exe [235848 2013-11-28] ()
S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-24] (Google)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [106248 2015-03-14] (SurfRight B.V.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-01-17] (Oracle Corporation)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-08-16] (Hewlett-Packard Company) [File not signed]
R2 LinksysUpdater; C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [204800 2008-04-18] () [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 McrdSvc; C:\WINDOWS\ehome\mcrdsvc.exe [99328 2005-08-05] (Microsoft Corporation)
S2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [655936 2014-08-20] (McAfee, Inc.)
S3 MHN; C:\WINDOWS\System32\mhn.dll [85504 2004-08-10] (Microsoft Corporation) [File not signed]
S2 MOBCleanup; C:\Documents and Settings\Administrator\Local Settings\Temp\MOBCleanup.exe [238288 2013-09-09] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 nmservice; C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [648504 2008-05-16] (Pure Networks, Inc.)
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [244904 2009-07-02] () [File not signed]
S3 Sage Simply Accounting Transaction Manager 2011 - CDN; C:\Program Files\Winsim\TransactionManager2011 - CDN\Sage_SA.TransactionManager.exe [46440 2012-06-08] (Sage)
R2 Simply Accounting Database Connection Manager; C:\Program Files\Winsim\ConnectionManager\SimplyConnectionManager.exe [20808 2010-08-24] (Sage)
R2 STacSV; C:\Program Files\SigmaTel\C-Major Audio\WDM\Stacsv.exe [53248 2005-12-12] (SigmaTel, Inc.) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 abp480n5; C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS [23552 2004-08-10] (Microsoft Corporation)
R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [121624 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriverl; C:\WINDOWS\System32\DRIVERS\avgidsdriverlx.sys [209376 2015-02-24] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [154904 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\WINDOWS\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [192792 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [265184 2015-02-03] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [107488 2015-02-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [27416 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\WINDOWS\System32\DRIVERS\avgtdix.sys [210912 2015-02-25] (AVG Technologies CZ, s.r.o.)
S3 BVRPMPR5; C:\WINDOWS\system32\drivers\BVRPMPR5.SYS [49904 2010-06-21] (Avanquest Software) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2011-06-02] ()
R3 ELacpi; C:\WINDOWS\System32\DRIVERS\ELacpi.sys [7552 2005-10-12] (Intel Corporation)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-07-09] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-07-09] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-07-09] (HP)
S3 JL2005C; C:\WINDOWS\System32\Drivers\jl2005c.sys [68762 2008-03-11] (Windows (R) 2000 DDK provider) [File not signed]
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [54360 2015-03-17] () [File not signed]
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [114904 2015-03-17] (Malwarebytes Corporation)
R2 McPvDrv; C:\WINDOWS\system32\drivers\McPvDrv.sys [66296 2013-09-09] (McAfee, Inc.)
S3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [350240 2014-08-20] (McAfee, Inc.)
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [81296 2014-08-20] (McAfee, Inc.)
S3 mferkdk; C:\WINDOWS\System32\drivers\mferkdk.sys [34248 2009-09-16] (McAfee, Inc.)
S3 mfesmfk; C:\WINDOWS\System32\drivers\mfesmfk.sys [40552 2009-11-04] (McAfee, Inc.)
S3 MHNDRV; C:\WINDOWS\System32\DRIVERS\mhndrv.sys [11008 2004-08-10] (Microsoft Corporation) [File not signed]
R1 MOBKFilter; C:\WINDOWS\System32\DRIVERS\MOBK.sys [54776 2010-04-13] (Mozy, Inc.)
S3 mxnic; C:\WINDOWS\System32\DRIVERS\mxnic.sys [19968 2001-08-17] (Macronix International Co., Ltd. )
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
S1 P3; C:\WINDOWS\System32\DRIVERS\p3.sys [42752 2008-04-13] (Microsoft Corporation)
R2 pnarp; C:\WINDOWS\System32\DRIVERS\pnarp.sys [23992 2008-05-16] (Pure Networks, Inc.)
R2 purendis; C:\WINDOWS\System32\DRIVERS\purendis.sys [25272 2008-05-16] (Pure Networks, Inc.)
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [36560 2006-09-27] (Sonic Solutions) [File not signed]
S3 sfng32; C:\WINDOWS\System32\drivers\sfng32.sys [41728 2005-12-02] (Sonic Focus, Inc)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1271032 2008-04-10] (IDT, Inc.)
S1 bdftdif; \??\C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdftdif.sys [X]
S3 FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS [X]
S3 gzflt; \??\C:\Program Files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\3.0.0.56\gzflt.sys [X]
U0 mfewfpk; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U5 usbser; C:\Windows\System32\Drivers\usbser.sys [26240 2013-08-28] (Microsoft Corporation)
U1 WS2IFSL; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

NETSVC: MHN -> C:\Windows\System32\mhn.dll (Microsoft Corporation)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-17 16:20 - 2015-03-17 16:20 - 00000000 ____D () C:\FRST
2015-03-17 13:55 - 2015-03-17 13:55 - 00090112 _____ () C:\WINDOWS\Minidump\Mini031715-01.dmp
2015-03-17 12:55 - 2015-03-17 12:55 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\793D590E.sys
2015-03-17 12:55 - 2015-03-17 12:55 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\212E591B.sys
2015-03-16 12:55 - 2015-03-16 12:56 - 00000637 _____ () C:\Documents and Settings\User\Desktop\Start Emsisoft Emergency Kit.lnk
2015-03-16 12:54 - 2015-03-16 12:56 - 00000000 ____D () C:\EEK
2015-03-15 22:03 - 2015-03-17 15:41 - 00000000 ____D () C:\Documents and Settings\User\My Documents\COMPUTER
2015-03-14 19:02 - 2015-03-14 19:22 - 00000000 ____D () C:\AdwCleaner
2015-03-14 18:48 - 2015-03-14 18:48 - 00001610 _____ () C:\Documents and Settings\All Users\Desktop\HitmanPro.lnk
2015-03-14 18:48 - 2015-03-14 18:48 - 00000000 ____D () C:\Program Files\HitmanPro
2015-03-14 18:48 - 2015-03-14 18:48 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\HitmanPro
2015-03-14 18:47 - 2015-03-15 22:01 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\HitmanPro
2015-03-14 17:38 - 2015-03-17 15:43 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-03-14 17:38 - 2015-03-17 13:54 - 00054360 _____ () C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-03-14 17:38 - 2015-03-14 17:38 - 00000777 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-14 17:38 - 2015-03-14 17:38 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-03-14 17:38 - 2015-03-14 17:38 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-14 17:38 - 2015-03-14 17:38 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2015-03-14 17:38 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-03-14 16:57 - 2004-01-01 02:12 - 00004000 _____ () C:\Documents and Settings\User\Desktop\Rkill.txt
2015-03-14 14:30 - 2015-03-14 15:41 - 00006688 _____ () C:\Documents and Settings\Administrator\Desktop\avgrep.txt
2015-03-14 14:25 - 2015-03-14 14:25 - 00000000 ____D () C:\Documents and Settings\Administrator\My Documents\CyberLink
2015-03-14 14:05 - 2015-03-14 14:05 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\AVG2015
2015-03-14 14:04 - 2015-03-14 16:37 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\AVG
2015-03-14 14:04 - 2015-03-14 14:04 - 00000702 _____ () C:\Documents and Settings\All Users\Desktop\AVG 2015.lnk
2015-03-11 11:59 - 2015-03-11 11:59 - 00000000 __SHD () C:\Documents and Settings\Administrator\IECompatCache
2015-03-11 11:59 - 2015-03-11 11:59 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Macromedia
2015-03-11 11:39 - 2015-03-11 11:39 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2015-03-11 11:36 - 2015-03-11 11:36 - 00000000 __SHD () C:\Documents and Settings\Administrator\PrivacIE
2015-03-11 11:33 - 2015-03-11 11:33 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Yahoo!
2015-03-11 11:30 - 2015-03-11 11:30 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\Avg
2015-03-11 11:30 - 2015-03-11 11:30 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\AVG
2015-03-11 11:29 - 2015-03-14 14:31 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\Avg2015
2015-03-11 11:29 - 2015-03-11 11:29 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\MFAData
2015-03-11 11:01 - 2015-03-11 11:01 - 00000265 ____N () C:\Documents and Settings\User\debug.log
2015-03-11 10:52 - 2015-03-11 10:52 - 00000168 _____ () C:\WINDOWS\system32\debug.log
2015-03-11 10:52 - 2015-03-11 10:52 - 00000000 ____D () C:\Documents and Settings\User\Application Data\AVG Web TuneUp
2015-03-10 21:07 - 2015-03-10 21:07 - 00000000 ____D () C:\Documents and Settings\LocalService\Local Settings\Application Data\AVG
2015-03-10 21:07 - 2015-03-10 21:07 - 00000000 ____D () C:\Documents and Settings\LocalService\Application Data\AVG
2015-03-10 21:06 - 2015-03-11 03:20 - 00065536 _____ () C:\WINDOWS\system32\config\TuneUp.evt
2015-03-10 21:05 - 2015-03-10 21:05 - 00000000 ____D () C:\Documents and Settings\User\Application Data\AVG
2015-03-10 21:04 - 2015-03-10 21:04 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Application Data\Avg
2015-03-10 21:02 - 2015-03-10 21:06 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\AVG
2015-03-10 20:24 - 2015-03-10 20:24 - 00000000 ____D () C:\Documents and Settings\User\Application Data\AVG2015
2015-03-10 20:23 - 2015-03-10 20:23 - 00000000 ____D () C:\Documents and Settings\User\Application Data\TuneUp Software
2015-03-10 20:20 - 2015-03-14 14:04 - 00000000 ___HD () C:\$AVG
2015-03-10 20:20 - 2015-03-14 14:04 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\AVG2015
2015-03-10 20:18 - 2015-03-14 14:03 - 00000000 ____D () C:\Program Files\AVG
2015-03-10 20:14 - 2015-03-17 11:04 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\MFAData
2015-03-10 20:14 - 2015-03-11 10:47 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Application Data\Avg2015
2015-03-10 20:14 - 2015-03-10 20:14 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Application Data\MFAData
2015-03-10 17:13 - 2015-03-14 17:01 - 00000000 __RSD () C:\Documents and Settings\User\My Documents\McAfee Vaults
2015-03-10 17:04 - 2015-03-14 14:29 - 00000000 __RSD () C:\Documents and Settings\Administrator\My Documents\McAfee Vaults
2015-03-10 17:04 - 2015-03-10 17:04 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\McAfee File Lock
2015-03-10 16:55 - 2015-03-10 16:55 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Adobe
2015-03-10 16:11 - 2015-03-10 16:11 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
2015-03-10 16:10 - 2015-03-10 16:10 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Mozilla
2015-03-10 16:09 - 2015-03-10 16:09 - 00000000 __SHD () C:\Documents and Settings\Administrator\IETldCache
2015-03-05 14:53 - 2015-03-11 10:51 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-02-25 17:28 - 2015-02-25 17:28 - 00210912 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgtdix.sys
2015-02-24 16:47 - 2015-02-24 16:47 - 00209376 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdriverlx.sys

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-17 16:20 - 2009-01-14 20:06 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Temp
2015-03-17 15:56 - 2010-02-11 11:15 - 00000886 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-17 15:40 - 2012-07-04 19:53 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-03-17 15:40 - 2005-01-09 18:10 - 01718282 _____ () C:\WINDOWS\WindowsUpdate.log
2015-03-17 15:35 - 2012-09-16 19:26 - 00000000 ___RD () C:\Documents and Settings\User\My Documents\Dropbox
2015-03-17 15:35 - 2012-09-16 19:22 - 00000000 ____D () C:\Documents and Settings\User\Application Data\Dropbox
2015-03-17 15:33 - 2005-01-09 18:07 - 00000000 ____D () C:\WINDOWS\Registration
2015-03-17 15:32 - 2005-01-09 10:03 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-03-17 15:32 - 2005-01-09 10:03 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2015-03-17 15:31 - 2014-03-27 10:57 - 00000220 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-03-17 15:31 - 2010-02-11 11:15 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-17 15:31 - 2005-01-09 18:19 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-03-17 13:55 - 2009-01-16 10:27 - 00000000 ____D () C:\WINDOWS\Minidump
2015-03-17 01:32 - 2012-03-04 17:28 - 00000000 ____D () C:\Documents and Settings\User\Application Data\uTorrent
2015-03-17 01:32 - 2009-01-14 20:06 - 00000278 ___SH () C:\Documents and Settings\User\ntuser.ini
2015-03-17 01:32 - 2005-01-09 18:19 - 00032608 _____ () C:\WINDOWS\SchedLgU.Txt
2015-03-16 22:37 - 2010-02-11 11:22 - 00000420 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{3552F3B9-DB86-4E99-8F02-60E5380687AC}.job
2015-03-16 12:11 - 2012-01-22 20:57 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Samsung
2015-03-16 12:10 - 2009-01-14 20:09 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-03-16 12:02 - 2013-11-22 00:07 - 00396531 _____ () C:\WINDOWS\setupapi.log
2015-03-16 11:03 - 2005-01-09 10:00 - 00107714 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-03-16 10:56 - 2005-01-09 16:48 - 00001170 _____ () C:\WINDOWS\system32\wpa.dbl
2015-03-16 00:08 - 2012-08-19 11:38 - 00000447 _____ () C:\WINDOWS\nsw.log
2015-03-15 22:37 - 2014-04-12 16:33 - 00000000 ____D () C:\Program Files\Lavasoft
2015-03-14 20:27 - 2009-02-06 15:09 - 00002521 _____ () C:\Documents and Settings\User\Desktop\Microsoft Office Outlook 2003.lnk
2015-03-14 20:22 - 2009-12-19 15:50 - 00000000 ____D () C:\Program Files\McAfee
2015-03-14 20:22 - 2009-01-15 21:42 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\McAfee
2015-03-14 20:21 - 2009-12-19 15:50 - 00000000 ____D () C:\Program Files\Common Files\McAfee
2015-03-14 18:11 - 2010-08-13 16:01 - 00000000 __HDC () C:\WINDOWS\$NtUninstallKB978542$
2015-03-14 18:01 - 2012-09-16 19:26 - 00001003 _____ () C:\Documents and Settings\User\Desktop\Dropbox.lnk
2015-03-14 18:01 - 2012-09-16 19:22 - 00000000 ____D () C:\Documents and Settings\User\Start Menu\Programs\Dropbox
2015-03-14 17:33 - 2009-04-13 09:53 - 00000000 ____D () C:\Program Files\ArcSoft
2015-03-14 17:02 - 2009-04-13 09:54 - 00000000 ____D () C:\Documents and Settings\User\Application Data\ArcSoft
2015-03-14 15:51 - 2005-01-09 18:19 - 00000178 ___SH () C:\Documents and Settings\Administrator\ntuser.ini
2015-03-14 14:34 - 2005-01-09 18:19 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Temp
2015-03-14 13:32 - 2014-08-20 13:46 - 00000000 ____D () C:\Documents and Settings\User\Local Settings\Application Data\Adobe
2015-03-14 11:49 - 2009-04-26 02:20 - 00001324 _____ () C:\WINDOWS\system32\d3d9caps.dat
2015-03-11 11:59 - 2005-01-09 18:19 - 00000000 ____D () C:\Documents and Settings\Administrator
2015-03-11 11:33 - 2009-07-10 00:39 - 00000000 ____D () C:\Program Files\Yahoo!
2015-03-11 03:12 - 2013-07-19 12:32 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-03-11 03:12 - 2009-01-14 18:20 - 119837696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-03-11 03:06 - 2009-08-16 20:12 - 00000000 ____D () C:\Documents and Settings\User\Application Data\HpUpdate
2015-03-11 03:06 - 2009-01-17 14:03 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\TEMP
2015-03-11 03:04 - 2010-08-13 16:46 - 00000000 ____D () C:\Documents and Settings\User\Desktop\Unused Desktop Shortcuts
2015-03-11 03:04 - 2009-01-24 12:06 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\DVD Shrink
2015-03-10 20:19 - 2013-05-16 11:38 - 00000284 _____ () C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2015-03-08 15:00 - 2014-03-27 10:57 - 00000214 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2015-03-06 10:38 - 2012-04-27 16:05 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-03-06 00:46 - 2015-01-26 15:35 - 00000000 ____D () C:\Program Files\Mozilla Firefox.bak
2015-03-04 18:55 - 2014-05-07 20:21 - 00000000 ____D () C:\Documents and Settings\User\Desktop\BUDGET M O N T H L Y E X P
2015-03-03 16:27 - 2005-01-09 09:59 - 00370840 _____ () C:\WINDOWS\setupact.log
2015-03-02 22:04 - 2014-05-07 17:23 - 00000000 ____D () C:\Documents and Settings\User\My Documents\P E R S O N A L
2015-02-26 13:51 - 2014-05-02 17:04 - 00000000 ____D () C:\Documents and Settings\User\My Documents\iTunes
2015-02-24 14:02 - 2009-02-07 09:46 - 00002497 _____ () C:\Documents and Settings\User\Desktop\Microsoft Office Word 2003 (2).lnk
2015-02-16 17:08 - 2014-08-12 15:33 - 00090624 _____ () C:\Documents and Settings\User\Desktop\DONS WITHDRAWLS.xls

==================== Files in the root of some directories =======

2012-01-22 21:01 - 2012-01-22 21:01 - 0002528 ____N () C:\Documents and Settings\User\Application Data\$_hpcst$.hpc
2009-03-13 21:53 - 2009-03-13 21:53 - 0038490 ____N () C:\Documents and Settings\User\Application Data\Comma Separated Values (DOS).ADR
2009-03-18 11:29 - 2009-03-18 11:29 - 0036433 ____N () C:\Documents and Settings\User\Application Data\Comma Separated Values (Windows).ADR
2010-07-22 09:38 - 2010-07-22 09:38 - 0000268 ___RH () C:\Documents and Settings\User\Application Data\Super Strings
2010-07-22 09:41 - 2010-07-22 09:41 - 0000268 ___RH () C:\Documents and Settings\User\Application Data\Sync Schema
2009-07-24 08:34 - 2014-12-15 03:21 - 0052224 _____ () C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-01-15 21:52 - 2009-01-15 21:52 - 0000127 ____N () C:\Documents and Settings\User\Local Settings\Application Data\fusioncache.dat

Some content of TEMP:
====================
C:\Documents and Settings\Administrator\Local Settings\Temp\DseShExt-x86.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\MOBCleanup.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\SDShelEx-win32.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\UNINSTALL.EXE
C:\Documents and Settings\User\Local Settings\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpssryy3.dll
C:\Documents and Settings\User\Local Settings\Temp\InstallerMessageBox.exe
C:\Documents and Settings\User\Local Settings\Temp\klfrfb1q.dll
C:\Documents and Settings\User\Local Settings\Temp\mlide0ty.dll
C:\Documents and Settings\User\Local Settings\Temp\NPSInstallerProxy.exe
C:\Documents and Settings\User\Local Settings\Temp\NPSInstallerProxyMessageBoxHookDll.dll
C:\Documents and Settings\User\Local Settings\Temp\owtovvcn.dll
C:\Documents and Settings\User\Local Settings\Temp\PrintCreations_2.6.255.207_2.8.255.384.exe
C:\Documents and Settings\User\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\User\Local Settings\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================



Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by User at 2015-03-17 16:21:38
Running from C:\Documents and Settings\User\My Documents\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-898855220-153585211-1186937704-1006\...\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
Acrobat.com (HKLM\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated)
Acrobat.com (Version: 0.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM\...\Adobe AIR) (Version: 2.0.2.12610 - Adobe Systems Inc.)
Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Apple Application Support (HKLM\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C0CC75CD-F5B7-46AD-B016-17C0F5171718}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft Print Creations - Album Page (HKLM\...\{E6B4117F-AC59-4B13-9274-EB136E8897EE}) (Version: - ArcSoft)
ArcSoft Print Creations - Funhouse (HKLM\...\{9591C049-5CAE-4E89-A8D9-191F1899628B}) (Version: - ArcSoft)
ArcSoft Print Creations - Greeting Card (HKLM\...\{F04F9557-81A9-4293-BC49-2C216FA325A7}) (Version: - ArcSoft)
ArcSoft Print Creations - Photo Book (HKLM\...\{56589DFE-0C29-4DFE-8E42-887B771ECD23}) (Version: - ArcSoft)
ArcSoft Print Creations - Photo Calendar (HKLM\...\{CA9ED5E4-1548-485B-A293-417840060158}) (Version: - ArcSoft)
ArcSoft Print Creations - Scrapbook (HKLM\...\{B0D83FCD-9D42-43ED-8315-250326AADA02}) (Version: - ArcSoft)
ArcSoft Print Creations - Slimline Card (HKLM\...\{007B37D9-0C45-4202-834B-DD5FAAE99D63}) (Version: - ArcSoft)
ArcSoft Print Creations (HKLM\...\{CAE8A0F1-B498-4C23-95FA-55047E730C8F}) (Version: 2.6.255.207 - ArcSoft)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.5856 - AVG Technologies)
AVG 2015 (Version: 15.0.4306 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.5856 - AVG Technologies) Hidden
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CCScore (Version: 7.00.0000.0001 - EASTMAN KODAK Company) Hidden
Clickfree Easy Image (HKLM\...\Clickfree Easy Image) (Version: - Storage Appliance Corp.)
Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Critical Update for Windows Media Player 11 (KB959772) (HKLM\...\KB959772_WM11) (Version: - Microsoft Corporation)
CyberLink BD Advisor 2.0 (HKLM\...\{2D2D8FE2-605C-4D3C-B706-36E981E7EEF0}) (Version: - )
CyberLink Blu-ray Disc Suite (HKLM\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 6.0.4703 - CyberLink Corp.)
CyberLink LabelPrint (HKLM\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1916 - CyberLink Corp.)
CyberLink LG Burning Tool (HKLM\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.2.4619 - CyberLink Corp.)
CyberLink MediaShow (HKLM\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 4.1.3402 - CyberLink Corp.)
CyberLink PowerDVD 9 (HKLM\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.3530.52 - CyberLink Corp.)
CyberLink PowerProducer (HKLM\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0.2.2512 - CyberLink Corp.)
CyberLink YouCam (HKLM\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.3718 - CyberLink Corp.)
Data Lifeguard Diagnostic for Windows (HKLM\...\{E40CE517-0D42-4198-96B4-C8232B257EB5}) (Version: 1.13 - Western Digital Corporation)
Digital Media Reader (HKLM\...\InstallShield_{4AC55A61-BA20-4DF5-ABFF-8F4819E0C875}) (Version: 2.01.00.02 - AlcorMicro)
Digital Media Reader (Version: 2.01.00.02 - AlcorMicro) Hidden
DocProc (Version: 12.0.0.0 - Hewlett-Packard) Hidden
Dropbox (HKU\S-1-5-21-898855220-153585211-1186937704-1006\...\Dropbox) (Version: 3.2.9 - Dropbox, Inc.)
DVD Shrink 3.2 (HKLM\...\DVD Shrink_is1) (Version: - DVD Shrink)
ESSBrwr (Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
ESSCDBK (Version: 7.01.0000.0002 - EASTMAN KODAK Company) Hidden
ESScore (Version: 7.01.0000.0012 - EASTMAN KODAK Company) Hidden
ESSgui (Version: 7.01.0000.0002 - EASTMAN KODAK Company) Hidden
ESSini (Version: 7.01.0000.0002 - EASTMAN KODAK Company) Hidden
ESSPCD (Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
ESSPDock (Version: 6.03.0001.0004 - EASTMAN KODAK Company) Hidden
ESSTOOLS (Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
essvatgt (Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
fflink (Version: 6.02.1001.0001 - EASTMAN KODAK Company) Hidden
File Uploader (HKLM\...\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}) (Version: 1.2.5 - Nikon)
Gateway Download Assistant (HKLM\...\{A2A73632-BBAA-43EB-A337-ADF43F905A1C}) (Version: 1.0.0 - Gateway)
Google Desktop (HKLM\...\Google Desktop) (Version: 5.9.1005.12335 - Google)
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.1.0.0 (Version: 1.00.0000 - Hewlett-Packard) Hidden
High Definition Audio Driver Package - KB835221 (HKLM\...\KB835221WXP) (Version: 20040219.000000 - Microsoft Corporation)
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.238 - SurfRight B.V.)
HP FWUpdateEDO2 (HKLM\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Officejet 6600 Basic Device Software (HKLM\...\{C4C4BECF-764C-406D-A1AD-F73611B0F668}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Officejet 6600 Help (HKLM\...\{2FA81482-5570-4CF0-9A10-D61D2F164916}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.9572 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (Version: 1.00.0000 - Microsoft) Hidden
I.R.I.S. OCR (HKLM\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Intel Audio Studio 2.0 (HKLM\...\{3D1B20A6-E31D-4BB5-BC5C-DDD3B0D91728}) (Version: 2.00.00093 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - )
Intel(R) PRO Network Connections Drivers (HKLM\...\PROSet) (Version: - )
Intel® Viiv™ (HKLM\...\{FCFEC0B9-6999-4BD2-85D1-4ED21070704E}) (Version: 1.0.0.2008 - Intel Corporation)
iTunes (HKLM\...\{F32DC846-4457-40A8-BECA-BCC0E960BC53}) (Version: 11.4.0.18 - Apple Inc.)
Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
kgcbaby (Version: 5.03.0000.0002 - EASTMAN KODAK Company) Hidden
kgchday (Version: 5.03.0000.0002 - EASTMAN KODAK Company) Hidden
kgchlwn (Version: 5.03.0000.0002 - EASTMAN KODAK Company) Hidden
kgcinvt (Version: 5.03.0000.0003 - EASTMAN KODAK Company) Hidden
kgckids (Version: 6.03.0001.0001 - EASTMAN KODAK Company) Hidden
kgcmove (Version: 6.03.0001.0001 - EASTMAN KODAK Company) Hidden
kgcvday (Version: 5.03.0000.0002 - EASTMAN KODAK Company) Hidden
Kodak EasyShare software (HKLM\...\{D32470A1-B10C-4059-BA53-CF0486F68EBC}) (Version: - Eastman Kodak Company)
LG Tool Kit (HKLM\...\{6179550A-3E7C-499E-BCC9-9E8113E0A285}) (Version: 10.01.0712.01 - )
LightScribe System Software (HKLM\...\{705B639E-FAAF-40D7-AD58-C445321C7C3F}) (Version: 1.18.18.1 - LightScribe)
Linksys EasyLink Advisor (HKLM\...\InstallShield_{7FE3214C-283E-40C6-A8D5-CB773110090C}) (Version: 3.0.8122.29 - Linksys, Cisco System.)
Linksys EasyLink Advisor (Version: 3.0.8122.29 - Linksys, Cisco System.) Hidden
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
McAfee Online Backup (Version: - McAfee, Inc.) Hidden
McAfee Online Backup (Version: 1.16.4.0 - McAfee, Inc.) Hidden
Microsoft .NET Framework 1.0 Hotfix (KB2572066) (HKLM\...\KB2572066) (Version: - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB2604042) (HKLM\...\KB2604042) (Version: - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB2656378) (HKLM\...\KB2656378) (Version: - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB953295) (HKLM\...\KB953295) (Version: - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB979904) (HKLM\...\KB979904) (Version: - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2698035) (HKLM\...\KB2698035) (Version: - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2742607) (HKLM\...\KB2742607) (Version: - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2833951) (HKLM\...\KB2833951) (Version: - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2904878) (HKLM\...\KB2904878) (Version: - Microsoft Corporation)
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM\...\{91110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Works 6-9 Converter (HKLM\...\{172423F9-522A-483A-AD65-03600CE4CA4F}) (Version: 9.7.0621 - Microsoft Corporation)
Microsoft Works 6-9 Converter (HKLM\...\{95140000-0137-0409-0000-0000000FF1CE}) (Version: 14.0.6120.5002 - Microsoft Corporation)
Motorola Phone Tools (Version: 4.30 - BVRP Software) Hidden
Motorola Phone Tools (Version: 5.00 - BVRP Software) Hidden
Mozilla Firefox 36.0.1 (x86 en-US) (HKLM\...\Mozilla Firefox 36.0.1 (x86 en-US)) (Version: 36.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSVCSetup (Version: 1.00.0000 - HP) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 6.0 Parser (KB925673) (HKLM\...\{FE9126DB-5F84-495A-BB46-3C724F1C2D08}) (Version: 6.00.3888.0 - Microsoft Corporation)
MySQL Connector/ODBC 3.51 (HKLM\...\{F929096B-54A0-4C5C-B125-1E7EB1917412}) (Version: 3.51.19 - MySQL AB)
netbrdg (Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
Nikon Message Center (HKLM\...\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}) (Version: 0.92.000 - Nikon)
Nikon Transfer (HKLM\...\{E9757890-7EC5-46C8-99AB-B00F07B6525C}) (Version: 1.5.3 - Nikon)
OCR Software by I.R.I.S. 12.0 (HKLM\...\HPOCR) (Version: 12.0 - HP)
OfotoXMI (Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
Picture Control Utility (HKLM\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.1.9 - Nikon)
PowerDVD (HKLM\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: - CyberLink Corporation)
PRS-500 USB driver (HKLM\...\{A212E6C2-20F7-4A8E-BD8E-DC3EE7483FA2}) (Version: 1.0.00.08110 - Sony)
Pure Networks Platform (Version: 10.2.8216.0 - Pure Networks) Hidden
QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Sage Simply Accounting 2011 (HKLM\...\InstallShield_{53AB83B3-9908-44DF-97B5-C107140F26AD}) (Version: 18.10.2002 - Sage Software)
Sage Simply Accounting 2011 (Version: 18.10.2002 - Sage Software) Hidden
Sage Simply Accounting 2011 (Version: 18.10.30 - Sage Software) Hidden
Sage Simply Accounting 2011 (Version: 18.10.40 - Sage Software) Hidden
SFR (Version: 7.01.0000.0003 - Eastman Kodak Company) Hidden
Shared C Run-time for x86 (Version: 10.0.0 - McAfee) Hidden
SHASTA (Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
SigmaTel Audio (HKLM\...\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}) (Version: 5.10.4610.0 - SigmaTel)
Simply Accounting 2004 Basic (HKLM\...\{39B82ED4-D8AE-11D7-A9ED-00B0D0627A8E}) (Version: - )
skin0001 (Version: 7.01.0000.0003 - EASTMAN KODAK Company) Hidden
SKINXSDK (Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
Sonic Encoders (HKLM\...\{9941F0AA-B903-4AF4-A055-83A9815CC011}) (Version: 1.00 - Sonic Solutions)
Spelling Dictionaries Support For Adobe Reader 9 (HKLM\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
staticcr (Version: 7.01.0000.0005 - EASTMAN KODAK Company) Hidden
System Requirements Lab for Intel (HKLM\...\{EFE3D683-903C-4B58-AB8F-C68C69F33758}) (Version: 4.5.3.0 - Husdawg, LLC)
TeamViewer 9 (HKLM\...\TeamViewer 9) (Version: 9.0.27614 - TeamViewer)
tooltips (Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
Uninstall Dual Mode Camera (HKLM\...\Dual Mode Camera_is1) (Version: - )
Update Rollup 2 for Windows XP Media Center Edition 2005 (HKLM\...\KB900325) (Version: - Microsoft Corporation)
ViewNX (HKLM\...\{F007CBCE-D714-4C0B-8CE9-9B0D78116468}) (Version: 1.5.2 - Nikon)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VPRINTOL (Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
WebEx Support Manager for Internet Explorer (HKLM\...\{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}) (Version: 6.5.47 - WebEx Communications Inc.)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Backup Utility (HKLM\...\{76EFFC7C-17A6-479D-9E47-8E658C1695AE}) (Version: 5.1 - Microsoft Corporation)
Windows Driver Package - Sony Corporation (PRSUSB) USB (08/08/2006 1.0.03.08080) (HKLM\...\75070B1806113224B16C70296B90DD1AD8A53479) (Version: 08/08/2006 1.0.03.08080 - Sony Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM\...\{9422C8EA-B0C6-4197-B8FC-DC797658CA00}) (Version: 5.000.818.6 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - )
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version: - )
Windows Search 4.0 (HKLM\...\KB940157) (Version: 04.00.6001.503 - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB2502898 (HKLM\...\KB2502898) (Version: - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB2619340 (HKLM\...\KB2619340) (Version: - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB2628259 (HKLM\...\KB2628259) (Version: - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB925766 (HKLM\...\KB925766) (Version: - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB973768 (HKLM\...\KB973768) (Version: - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
WIRELESS (Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
XML Paper Specification Shared Components Pack 1.0 (Version: - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{1F4C752B-FEBD-4FA5-B343-C24A695FB0FB}\InprocServer32 -> C:\WINDOWS\system32\mscoree.DLL (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{2837E0FE-686B-4CB0-BE53-0EA097EAF71B}\InprocServer32 -> C:\WINDOWS\Downloaded Program Files\isusweb.dll (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{49BBAA3C-C574-419E-8378-783C362E9C15}\InprocServer32 -> C:\Program Files\HP\Common\FWUpdateEDO2.dll (Hewlett-Packard Co.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{5B7524C8-2446-40E9-9474-94A779DBA224}\InprocServer32 -> C:\WINDOWS\Downloaded Program Files\isusweb.dll (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{621D3650-F1D3-414C-97F9-03A02B211261}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{623E415A-22EF-4DAA-A2FF-E68E77A673C9}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{78392DA3-CFD8-342C-9C84-2B8B16C623EF}\InprocServer32 -> C:\WINDOWS\system32\mscoree.DLL (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}\InprocServer32 -> C:\WINDOWS\Downloaded Program Files\dwusplay.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}\localserver32 -> C:\WINDOWS\Downloaded Program Files\dwusplay.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{915C2CEB-216B-4B7C-89E4-9ED3512D58D9}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{92C5E738-7372-4CD6-BE57-15833624EBF3}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{97090E2F-3062-4459-855B-014F0D3CDBB1}\InprocServer32 -> C:\Program Files\Windows Desktop Search\deskbar.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{9CAAD2EA-177B-4D07-871F-47255B5D30F3}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{B391A1DB-28C8-4506-A43C-5BD6051F16BA}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{E50C953D-311A-481B-8F8D-C55E65AF7417}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{E69341A3-E6D2-4175-B60C-C9D3D6FA40F6}\localserver32 -> C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{E9880553-B8A7-4960-A668-95C68BED571E}\InprocServer32 -> C:\WINDOWS\Downloaded Program Files\isusweb.dll (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{E9A93328-79D4-4AED-A778-146E7191F8BC}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Documents and Settings\User\Application Data\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-898855220-153585211-1186937704-1006_Classes\CLSID\{FFF2D28F-E4EE-44D9-8104-8E71556757F6}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (InstallShield Software Corporation)

==================== Restore Points =========================

14-03-2015 20:32:50 Removed Panorama Maker
15-03-2015 22:01:21 Checkpoint by HitmanPro
15-03-2015 22:07:45 AA11
16-03-2015 11:54:09 Checkpoint by HitmanPro
16-03-2015 12:07:18 Removed Samsung New PC Studio

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-01-14 18:44 - 2004-08-10 12:00 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
Task: C:\WINDOWS\Tasks\EasyShare Registration Task.job => C:\WINDOWS\system32\rundll32.exelC:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registration_7.9.20.1.sxt
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{3552F3B9-DB86-4E99-8F02-60E5380687AC}.job => C:\WINDOWS\system32\msfeedssync.exe

==================== Loaded Modules (whitelisted) ==============

2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2005-01-09 16:48 - 2011-02-04 18:48 - 00291840 _____ () C:\WINDOWS\system32\sbe.dll
2005-01-09 16:48 - 2013-01-01 23:49 - 01292288 _____ () C:\WINDOWS\system32\quartz.dll
2009-01-14 18:43 - 2008-04-13 17:11 - 00059904 _____ () C:\WINDOWS\system32\devenum.dll
2009-01-14 18:45 - 2008-04-13 17:11 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll
2008-04-18 02:30 - 2008-04-18 02:30 - 00204800 _____ () C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
2008-04-18 02:30 - 2008-04-18 02:30 - 00081920 _____ () C:\Program Files\Linksys\Linksys Updater\lib\wrapper.dll
2009-12-15 14:46 - 2009-12-15 14:46 - 00619816 _____ () C:\Program Files\CyberLink\Power2Go\CLMediaLibrary.dll
2009-12-15 14:49 - 2009-12-15 14:49 - 00013096 _____ () C:\Program Files\CyberLink\Power2Go\CLMLSvcPS.dll
2012-02-25 18:10 - 2009-07-02 07:02 - 00244904 ____N () C:\Program Files\CyberLink\Shared Files\RichVideo.exe
2013-08-12 19:05 - 2013-11-28 08:36 - 00235848 ____R () c:\documents and settings\all users\application data\Clickfree\FullImagingBackup\FullImagingService.exe
2013-08-12 19:05 - 2013-11-28 08:36 - 00137544 ____R () c:\documents and settings\all users\application data\Clickfree\FullImagingBackup\VssClientDll.dll
2010-08-16 14:21 - 2010-08-16 14:21 - 02121728 _____ () C:\Program Files\Common Files\LightScribe\QtCore4.dll
2010-08-16 14:21 - 2010-08-16 14:21 - 07745536 _____ () C:\Program Files\Common Files\LightScribe\QtGui4.dll
2010-08-16 14:21 - 2010-08-16 14:21 - 00135168 _____ () C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2015-03-04 15:08 - 2015-03-04 15:08 - 00750080 _____ () C:\Documents and Settings\User\Application Data\Dropbox\bin\libGLESv2.dll
2015-03-17 15:34 - 2015-03-17 15:34 - 00043008 _____ () c:\Documents and Settings\User\Local Settings\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpssryy3.dll
2015-03-04 15:08 - 2015-03-04 15:08 - 00047616 _____ () C:\Documents and Settings\User\Application Data\Dropbox\bin\libEGL.dll
2015-03-04 15:08 - 2015-03-04 15:08 - 00865280 _____ () C:\Documents and Settings\User\Application Data\Dropbox\bin\plugins\platforms\qwindows.dll
2015-03-04 15:07 - 2015-03-04 15:07 - 00200704 _____ () C:\Documents and Settings\User\Application Data\Dropbox\bin\plugins\imageformats\qjpeg.dll
2015-02-05 02:40 - 2015-02-05 02:40 - 16852144 _____ () C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:8C35AEA7

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-898855220-153585211-1186937704-1006\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: 64.59.144.91 - 64.59.150.137

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== Accounts: =============================

Administrator (S-1-5-21-898855220-153585211-1186937704-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
ASPNET (S-1-5-21-898855220-153585211-1186937704-1003 - Limited - Enabled)
Guest (S-1-5-21-898855220-153585211-1186937704-501 - Limited - Enabled)
HelpAssistant (S-1-5-21-898855220-153585211-1186937704-1005 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-898855220-153585211-1186937704-1002 - Limited - Disabled)
User (S-1-5-21-898855220-153585211-1186937704-1006 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\User

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (03/16/2015 11:03:42 AM) (Source: LoadPerf) (EventID: 3011) (User: )
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The
Error code is the first DWORD in Data section.

Error: (03/16/2015 11:03:42 AM) (Source: LoadPerf) (EventID: 3012) (User: )
Description: The performance strings in the Performance registry value is corrupted when
process Performance extension counter provider. BaseIndex value from Performance
registry is the first DWORD in Data section, LastCounter value is the second
DWORD in Data section, and LastHelp value is the third DWORD in Data section.

Error: (03/15/2015 09:54:20 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.

Error: (03/14/2015 10:58:55 AM) (Source: LoadPerf) (EventID: 3011) (User: )
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The
Error code is the first DWORD in Data section.

Error: (03/14/2015 10:58:55 AM) (Source: LoadPerf) (EventID: 3012) (User: )
Description: The performance strings in the Performance registry value is corrupted when
process Performance extension counter provider. BaseIndex value from Performance
registry is the first DWORD in Data section, LastCounter value is the second
DWORD in Data section, and LastHelp value is the third DWORD in Data section.

Error: (03/14/2015 08:40:34 PM) (Source: FullImagingService) (EventID: 0) (User: )
Description: Service cannot be started. The service process could not connect to the service controller

Error: (03/14/2015 05:10:59 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry <C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\START MENU\PROGRAMS> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (03/14/2015 05:10:59 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry <C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\START MENU\PROGRAMS> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (03/14/2015 05:10:21 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry <C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\START MENU\PROGRAMS> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (03/14/2015 05:10:21 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry <C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\START MENU\PROGRAMS> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog


Details:
A device attached to the system is not functioning. (0x8007001f)


System errors:
=============
Error: (03/17/2015 03:33:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
bdftdif

Error: (03/17/2015 03:32:46 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The McAfee Anti-Malware Core service depends on the following nonexistent service: mfevtp

Error: (03/17/2015 03:25:48 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generate Activation Context failed for c:\Program Files\AVG\AVG2015\avgcmlx.dll.
Reference error message: Error Message is unavailable
.

Error: (03/17/2015 03:25:48 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generate Activation Context failed for C:\Program Files\AVG\AVG2015\avgcmlx.dll.
Reference error message: The operation completed successfully.
.

Error: (03/17/2015 03:25:48 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generate Activation Context failed for C:\Program Files\AVG\AVG2015\avgkrnlapix.dll.
Reference error message: The operation completed successfully.
.

Error: (03/17/2015 03:25:48 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generate Activation Context failed for c:\Program Files\AVG\AVG2015\avgcmlx.dll.
Reference error message: The operation completed successfully.
.

Error: (03/17/2015 03:25:34 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (03/17/2015 03:08:32 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
bdftdif

Error: (03/17/2015 03:08:04 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The McAfee Anti-Malware Core service depends on the following nonexistent service: mfevtp

Error: (03/17/2015 03:02:07 PM) (Source: DCOM) (EventID: 10005) (User: YOUR-311D0C6927)
Description: DCOM got error "%%1058" attempting to start the service ntmssvc with arguments "-Service"
in order to run the server:
{D61A27C6-8F53-11D0-BFA0-00A024151983}


Microsoft Office Sessions:
=========================
Error: (02/05/2009 09:44:40 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: 6Microsoft Office Outlook12.0.6316.500012.0.6215.100010960

Error: (02/05/2009 09:42:46 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: 6Microsoft Office Outlook12.0.6316.500012.0.6215.1000260


==================== Memory info ===========================

Processor: Intel(R) Pentium(R) D CPU 2.80GHz
Percentage of memory in use: 61%
Total physical RAM: 2037.64 MB
Available physical RAM: 792.94 MB
Total Pagefile: 3405.96 MB
Available Pagefile: 2189.29 MB
Total Virtual: 2047.88 MB
Available Virtual: 1916.47 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.88 GB) (Free:94.02 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive j: (My Book) (Fixed) (Total:596.02 GB) (Free:367.61 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: 14CB14CB)
Partition 1: (Active) - (Size=232.9 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 596.2 GB) (Disk ID: ACDD9B22)
Partition 1: (Not Active) - (Size=596.2 GB) - (Type=0C)

==================== End Of Log ============================
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,



They call me TwinHeadedEagle around here, and I'll be working with you.



Before we start please read and note the following:
  • At the top of your post, please click on the "Watch thread" button and make sure to check Watch this thread...and receive email notifications. This will send an email to you as soon as I reply to your topic, allowing me to solve your problem faster.
  • Please do not install any new software during the cleaning process other than the tools I provide for you. This can hinder the cleaning process. Please do not perform System Restore or any other restore.
  • Instructions I give to you are very simple and made for complete beginner to follow. That's why you need to read through my instructions carefully and completely before executing them.
  • Please do not run any tools other than the ones I ask you to, when I ask you to. Some of these tools can be very dangerous if used improperly. Also, if you use a tool that I have not requested you use, it can cause false positives, thereby delaying the complete cleaning of your machine.
  • All tools we use here are completely clean and do not contain any malware. If your antivirus detects them as malicious, please disable your antivirus and then continue.
  • If during the process you run across anything that is not in my instructions, please stop and ask. If any tool is running too much time (few hours), please stop and inform me.
  • I visit forum several times at day, making sure to respond to everyone's topic as fast as possible. But bear in mind that I have private life like everyone and I cannot be here 24/7. So please be patient with me. Also, some infections require less, and some more time to be removed completely, so bear this in mind and be patient.
  • Please stay with me until the end of all steps and procedures and I declare your system clean. Just because there is a lack of symptoms does not indicate a clean machine. If you solved your problem yourself, set aside two minutes to let me know.
  • Please attach all report using
    fjqb1h.png
    button below. Doing this, you make it easier for me to analyze and fix your problem.

  • Do not ask for help for your business PC. Companies are making revenue via computers, so it is good thing to pay someone to repair it.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.




Download
51a5f31352b88-icon_MBAR.png
Malwarebytes Anti-Rootkit to your desktop.
  • Double-click the icon to start the tool.
  • It will ask you where to extract it, then it will start.
  • Warning! Malwarebytes Anti-Rootkit needs to be run from an account with administrator rights.
  • Click in the introduction screen "next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
  • When the scan is finished and no malware has been found select "Exit".
  • If malware was detected, make sure to check all the items and click "Cleanup". Reboot your computer.
  • Open the MBAR folder and paste the content of the following files in your next reply:
    • "mbar-log-{date} (xx-xx-xx).txt"
    • "system-log.txt"




FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.
 

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
Thank you TwinHeadedEagle, shall do as requested and report back and await your reply before doing any more rooting around for things to help!
 

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
In the Malwarebytes Antirootkit scan, no malware was found. I am attaching ( I hope) the Farbar recovery scan results from the notepad! Thanks for your help, appreciate it!
 

Attachments

  • mbar-log-2015-03-17 (17-39-36).txt
    2.1 KB · Views: 28
  • system-log.txt
    23.4 KB · Views: 28

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
OK done! Will attach! Thanks!
 

Attachments

  • FRST 3-18-15.txt
    43.2 KB · Views: 26
  • FRST Addition 3-18-15.txt
    37.3 KB · Views: 25

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
Not really sure! I am afraid to turn it off, I have left it on so I would not lose you. I guess it is time to see if all is good, wish me luck! Here goes!
 

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
Hey TwinHeadedEagle, opened up great! No multiple windows opened! Chdsk started up (??) and deleted a file (??) then my "System 32" file folder opened (??) My email (Outlook) is broken still, can now open without multiples but seems innards are gone (??)! So is this it?? Am I now fixed?? Do you know what was wrong? How was it fixed? The scans didn't seem to find anything? Should I delete all the program scans I downloaded from your Malwarebyte tutorial? Thanks for any advice for this Newbie! Very much appreciated!!
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Glad I could help. We will delete all used tools and I'll give you some tips to harden your security and learn how to protect yourself :)


Recommended reading:
icon_exclaim.gif
MUST READ - security tips:

icon_exclaim.gif
MUST READ - general maintenance:


The Importance of Software Updating:

In order to stay protected it is
very important that you regularly update all of your software. Cybercriminals depend on the apathy of users around software updates to keep their malicious endeavor running.

Operating systems, such as Windows, and applications, such as Adobe Reader or JAVA, are used by tens of millions of computers and devices around the world, making them a huge target for cybercriminals. Downloading updates and installing them can sometimes be tedious, but the advantages you get from the updates are certainly worth it.




Recommended additional software:
icon_arrow.gif
TFC - to clean unneeded temporary files.
icon_arrow.gif
Malwarebytes' Anti-Malware - to scan your system from time to time in search for malware.
icon_arrow.gif
Malwarebytes' Anti-Exploit - to prevent plenty of mostly exploited vulnerabilities.
icon_arrow.gif
McShield - to prevent infections spread by removable media.
icon_arrow.gif
Unchecky - to prevent from installing additional foistware, implemented in legitimate installations.
icon_arrow.gif
Adblock - to surf the web without annoying ads!



Post-cleanup procedures:


Download DelFix by Xplode and save it to your desktop.
  • Run the tool by right click on the
    51a5ce45263de-delfix.png
    icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run and wait until the tool completes his work.
  • All tools we used should be gone. Tool will create an report for you (C:\DelFix.txt)
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.



My help is free for everybody.
If you're happy with the help provided and/or wish to buy me a beer for the assistance you received, then you can consider a donation:
Thank you!​




Stay safe,
TwinHeadedEagle :)
 

Crash

New Member
Thread author
Verified
Mar 17, 2015
28
Thanks so much TwinHeadedEagle! I have read through it all and added the programs, have never downloaded so much stuff before, than I have in the last couple of days....scary!! I have also done the cleanup part too! Will I be able to access this info again ^^^^ I think I will need to read again, or bookmark?? Thanks again! You are a Saint!
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top