Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Trovi After Removal
Message
<blockquote data-quote="Perryaire" data-source="post: 387866" data-attributes="member: 36568"><p>I need help to remove whatever is causing browsers to redirect to <a href="http://www.search.info" target="_blank">www.search.info</a></p><p></p><p>I followed all of the steps in the Trovi Removal instructions multiple times. The computer was too munged up to remove Trovi from the browsers until after I ran some of the tools. Once the tools were run I followed the instructions for removing Trovi from IE and Firefox and just removed Chrome altogether. After several repeats, things are close to being OK. It is just that whenever I start IE, it wants to redirect to <a href="http://www.search.info" target="_blank">www.search.info</a> instead of just sending me to google.com as set in the advanced internet options.</p><p></p><p>Further research on this site led to downloading and running Kaspersky's tdskiller to check for rootkits. The scan reported no infections.</p><p></p><p>Below are the FRST logs run after the clean up. Sorry I could not attach log files, they did not show in the list of files to be uploaded when I tried.</p><p></p><p>FRST.txt</p><p>Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-05-2015</p><p>Ran by jbremner (administrator) on IMG0001556 on 21-05-2015 15:47:25</p><p>Running from D:\</p><p>Loaded Profiles: jbremner (Available profiles: jbremner & user)</p><p>Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)</p><p>Internet Explorer Version 11 (Default browser: IE)</p><p>Boot Mode: Normal</p><p>Tutorial for Farbar Recovery Scan Tool: <a href="http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/" target="_blank">http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/</a></p><p></p><p>==================== Processes (Whitelisted) =================</p><p></p><p>(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)</p><p></p><p>(Lenovo.) C:\Windows\System32\ibmpmsvc.exe</p><p>(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe</p><p>(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe</p><p>(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe</p><p>(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe</p><p>(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe</p><p>(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe</p><p>(Intel Corporation) C:\Windows\System32\hkcmd.exe</p><p>(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe</p><p>(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe</p><p>(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe</p><p>(Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE</p><p>(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe</p><p>(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe</p><p>(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe</p><p>(Carbonite, Inc. (<a href="http://www.carbonite.com" target="_blank">www.carbonite.com</a>)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe</p><p>(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe</p><p>(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe</p><p>(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe</p><p>(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe</p><p>(Microsoft Corporation) C:\Windows\System32\dllhost.exe</p><p></p><p></p><p>==================== Registry (Whitelisted) ==================</p><p></p><p>(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)</p><p></p><p>HKLM-x32\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184112 2012-06-01] (Intel Corporation)</p><p>HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp</p><p>HKLM-x32\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)</p><p>HKLM-x32\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1260256 2013-01-04] (Realtek Semiconductor)</p><p>HKLM-x32\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [170304 2012-09-21] (Intel Corporation)</p><p>HKLM-x32\...\Run: [HotKeysCmds] => C:\Windows\system32\hkcmd.exe [398656 2012-09-21] (Intel Corporation)</p><p>HKLM-x32\...\Run: [Persistence] => C:\Windows\system32\igfxpers.exe [441152 2012-09-21] (Intel Corporation)</p><p>HKLM-x32\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3023600 2013-03-04] (Synaptics Incorporated)</p><p>HKLM-x32\...\Run: [LogMeIn GUI] => C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [57928 2013-04-30] (LogMeIn, Inc.)</p><p>HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)</p><p>HKLM\...\Run: [3D BubbleSound] => "C:\Program Files\BubbleSound\3D BubbleSound.exe"</p><p>HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134176 2012-10-22] (Intel Corporation)</p><p>HKLM-x32\...\Run: [Integrated Camera_Monitor] => C:\Program Files (x86)\Integrated Camera\monitor.exe [1699192 2012-12-25] ()</p><p>HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor</p><p>HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [290688 2012-10-23] (Intel Corporation)</p><p>HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)</p><p>HKLM-x32\...\Run: [NSCSysTrayUI_XEROX] => C:\Program Files (x86)\XEROX\NetworkScan\NSCSysUI_XEROX.exe [266240 2009-01-13] (XEROX)</p><p>HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2010-09-09] (CANON INC.)</p><p>HKLM-x32\...\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1056976 2014-06-27] (Carbonite, Inc.)</p><p>HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)</p><p>HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe</p><p>Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)</p><p>Winlogon\Notify\psfus: C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.)</p><p>HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [GoToMeeting] => C:\Users\jbremner\AppData\Local\Citrix\GoToMeeting\1350\g2mstart.exe [40304 2014-03-09] (Citrix Online, a division of Citrix Systems, Inc.)</p><p>HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)</p><p>HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)</p><p>HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-10-20] (Apple Inc.)</p><p>HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [GoogleChromeAutoLaunch_ED6964934F1BBF8145A329153CF6D8B3] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window</p><p>HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [BingSvc] => C:\Users\jbremner\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation)</p><p>HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\MountPoints2: {3e061047-e5f1-11e2-9914-806e6f6e6963} - Q:\LenovoQDrive.exe</p><p>AppInit_DLLs-x32: c:\programdata\flashbeat\flashbeat32.dll => "c:\programdata\flashbeat\flashbeat32.dll" File Not Found</p><p>Lsa: [Notification Packages] scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll</p><p>ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)</p><p>ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)</p><p>ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)</p><p>ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File</p><p>ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File</p><p>ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File</p><p>ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File</p><p>ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File</p><p>ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File</p><p>ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File</p><p>ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File</p><p>ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)</p><p>ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)</p><p>ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)</p><p>ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File</p><p>CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION</p><p></p><p>==================== Internet (Whitelisted) ====================</p><p></p><p>(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)</p><p></p><p>HKU\S-1-5-21-2037836387-1429457356-845570551-1180\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION</p><p>ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled</p><p>ProxyServer: [.DEFAULT] => http=127.0.0.1:53847;https=127.0.0.1:53847</p><p>HKU\S-1-5-21-2037836387-1429457356-845570551-1180\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = <a href="http://www.msn.com/?ocid=iehp" target="_blank">http://www.msn.com/?ocid=iehp</a></p><p>SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = </p><p>SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = </p><p>SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = </p><p>SearchScopes: HKU\S-1-5-21-2037836387-1429457356-845570551-1180 -> DefaultScope {08EDEB72-2C69-419C-A5D6-E62331429327} URL = <a href="https://www.google.com/search?q={searchTerms}" target="_blank">https://www.google.com/search?q={searchTerms}</a></p><p>SearchScopes: HKU\S-1-5-21-2037836387-1429457356-845570551-1180 -> {08EDEB72-2C69-419C-A5D6-E62331429327} URL = <a href="https://www.google.com/search?q={searchTerms}" target="_blank">https://www.google.com/search?q={searchTerms}</a></p><p>SearchScopes: HKU\S-1-5-21-2037836387-1429457356-845570551-1180 -> {D7C0A3C0-5F83-4D4F-9F59-707F33C6D3B6} URL = </p><p>BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)</p><p>BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)</p><p>BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)</p><p>BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)</p><p>BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)</p><p>BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)</p><p>BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-22] (Microsoft Corporation)</p><p>BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)</p><p>DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} <a href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab" target="_blank">http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a></p><p>Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-03-12] (Microsoft Corporation)</p><p>Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)</p><p>Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)</p><p>Tcpip\Parameters: [DhcpNameServer] 192.168.168.5</p><p></p><p>FireFox:</p><p>========</p><p>FF ProfilePath: C:\Users\jbremner\AppData\Roaming\Mozilla\Firefox\Profiles\3vm4j7wd.default-1432219147981</p><p>FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll [2013-07-29] (Oracle Corporation)</p><p>FF Plugin: @microsoft.com/GENUINE -> disabled No File</p><p>FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)</p><p>FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)</p><p>FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File</p><p>FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()</p><p>FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)</p><p>FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)</p><p>FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File</p><p>FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)</p><p>FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)</p><p>FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)</p><p>FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)</p><p>FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)</p><p>FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-04-06] (Apple Inc.)</p><p>FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-04-06] (Apple Inc.)</p><p>FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-04-06] (Apple Inc.)</p><p>FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-04-06] (Apple Inc.)</p><p>FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-04-06] (Apple Inc.)</p><p>FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14]</p><p></p><p>Chrome: </p><p>=======</p><p>CHR Profile: C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default</p><p>CHR Extension: (Google Slides) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-20]</p><p>CHR Extension: (Google Docs) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-20]</p><p>CHR Extension: (Google Drive) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-20]</p><p>CHR Extension: (YouTube) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-20]</p><p>CHR Extension: (Google Search) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-20]</p><p>CHR Extension: (Google Sheets) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-20]</p><p>CHR Extension: (Gmail) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-20]</p><p></p><p>==================== Services (Whitelisted) =================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)</p><p>R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)</p><p>R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)</p><p>R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1254400 2015-04-27] (Microsoft Corporation)</p><p>S3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [320576 2013-01-09] (Lenovo.)</p><p>S2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2015-05-20] (SurfRight B.V.)</p><p>S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166432 2012-10-22] (Intel Corporation)</p><p>S2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [136288 2012-08-10] (Lenovo Group Limited)</p><p>R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [417640 2015-02-26] (LogMeIn, Inc.)</p><p>S2 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [234344 2015-02-26] (LogMeIn, Inc.)</p><p>R2 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2013-04-30] (LogMeIn, Inc.)</p><p>R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)</p><p>R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)</p><p>S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272688 2012-08-23] ()</p><p>S2 OneTouch 4.0 Monitor; C:\Program Files (x86)\Visioneer\OneTouch 4.0\OtService.exe [221184 2010-11-02] (Visioneer Inc.) [File not signed]</p><p>R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)</p><p>S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3342640 2012-08-23] (Intel® Corporation)</p><p></p><p>==================== Drivers (Whitelisted) ====================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>R3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [111104 2012-05-21] (Motorola Solutions, Inc.)</p><p>R3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [849408 2012-06-09] (Motorola Solutions, Inc.)</p><p>S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [54072 2010-10-14] (Samsung Electronics)</p><p>R2 LMIInfo; C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [16056 2013-04-30] (LogMeIn, Inc.)</p><p>S4 LMIRfsClientNP; No ImagePath</p><p>R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)</p><p>R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-21] (Malwarebytes Corporation)</p><p>R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)</p><p>S2 risdxc; C:\Windows\System32\DRIVERS\risdxc64.sys [101888 2011-05-25] (REDC) [File not signed]</p><p>R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [31984 2013-03-04] (Synaptics Incorporated)</p><p>R2 smihlp2; C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [13128 2011-05-30] (Authentec Inc.)</p><p>R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1062520 2013-01-10] (Sunplus)</p><p>R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.)</p><p>S3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-08] (ThinkVantage Communications Utility)</p><p>R3 usb3Hub; C:\Windows\System32\DRIVERS\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider)</p><p>R3 XHCIPort; C:\Windows\System32\DRIVERS\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider)</p><p>S1 mmjimzv2yxmwbdd; system32\drivers\mmjimzv2yxmwbdd.sys [X]</p><p></p><p>==================== NetSvcs (Whitelisted) ===================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p></p><p>==================== One Month Created files and folders ========</p><p></p><p>(If an entry is included in the fixlist, the file/folder will be moved.)</p><p></p><p>2015-05-21 15:47 - 2015-05-21 15:47 - 00000000 ____D () C:\FRST</p><p>2015-05-21 15:14 - 2015-05-21 15:14 - 00000811 _____ () C:\Users\jbremner\Desktop\JRT.txt</p><p>2015-05-21 15:12 - 2015-05-21 01:11 - 02720009 _____ (Thisisu) C:\Users\jbremner\Desktop\JRT_NEW.exe</p><p>2015-05-21 10:46 - 2015-05-21 10:46 - 02209792 _____ () C:\Users\jbremner\Downloads\adwcleaner_4.205.exe</p><p>2015-05-21 10:30 - 2015-05-21 10:30 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe</p><p>2015-05-21 10:15 - 2015-05-21 10:15 - 00000167 _____ () C:\Windows\pcfaxsetup.log</p><p>2015-05-21 09:39 - 2015-05-21 09:39 - 00000000 ____D () C:\Users\jbremner\Desktop\Old Firefox Data</p><p>2015-05-21 09:27 - 2015-05-21 09:27 - 00046606 _____ () C:\Windows\system32\.crusader</p><p>2015-05-20 16:16 - 2015-05-20 16:16 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER</p><p>2015-05-20 16:09 - 2015-05-20 16:17 - 00001904 _____ () C:\Users\Public\Desktop\HitmanPro.lnk</p><p>2015-05-20 16:09 - 2015-05-20 16:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro</p><p>2015-05-20 16:09 - 2015-05-20 16:09 - 00000000 ____D () C:\Program Files\HitmanPro</p><p>2015-05-20 16:08 - 2015-05-21 09:27 - 00000000 ____D () C:\ProgramData\HitmanPro</p><p>2015-05-20 15:57 - 2015-05-20 15:57 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk</p><p>2015-05-20 15:46 - 2015-05-20 15:46 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-IMG0001556-Windows-7-Professional-(64-bit).dat</p><p>2015-05-20 15:46 - 2015-05-20 15:46 - 00000000 ____D () C:\RegBackup</p><p>2015-05-20 15:36 - 2015-05-21 14:24 - 00000000 ____D () C:\AdwCleaner</p><p>2015-05-20 13:39 - 2015-05-20 13:39 - 00000000 ____D () C:\Users\jbremner\AppData\Local\Storm_Warnings,_LLC</p><p>2015-05-20 13:37 - 2015-05-20 13:37 - 00004320 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserM_1_7_22_478699874-4155726479-3780505679-3006UA__31313431363639352d344a414155342a2a236c6c5a</p><p>2015-05-20 13:25 - 2015-05-20 13:25 - 00000000 ____D () C:\Program Files (x86)\65389f70-5439-4eb5-8cbe-f5adb12c6561</p><p>2015-05-20 12:41 - 2015-05-20 12:41 - 00003624 _____ () C:\Windows\System32\Tasks\Norwood</p><p>2015-05-20 12:35 - 2015-05-20 12:35 - 00000024 _____ () C:\Users\jbremner\AppData\Roaming\appdataFr25.bin</p><p>2015-05-16 10:36 - 2015-05-16 10:36 - 00000000 ____D () C:\Users\jbremner\.cache</p><p>2015-05-14 22:46 - 2015-05-14 22:46 - 00000000 _____ () C:\Users\jbremner\AppData\Local\Temp.dat</p><p>2015-05-14 22:18 - 2015-05-14 22:18 - 00000942 _____ () C:\Windows\SysWOW64\${LOGFILE}</p><p>2015-05-14 21:47 - 2015-05-20 16:06 - 00000000 ____D () C:\Program Files (x86)\Panel View for Keep</p><p>2015-05-14 21:36 - 2015-05-21 15:08 - 00000336 _____ () C:\Windows\Tasks\IIXQMYFCO1.job</p><p>2015-05-14 21:36 - 2015-05-20 16:06 - 00000000 ____D () C:\ProgramData\06e78fe9f3fa4765b7830b8886163656</p><p>2015-05-14 21:36 - 2015-05-14 21:36 - 00003574 _____ () C:\Windows\System32\Tasks\YNZSM</p><p>2015-05-14 21:36 - 2015-05-14 21:36 - 00002858 _____ () C:\Windows\System32\Tasks\IIXQMYFCO1</p><p>2015-05-14 21:36 - 2015-05-14 21:36 - 00000000 ____D () C:\ProgramData\28341ff220e0446c9fff27c4493d622e</p><p>2015-05-14 21:32 - 2015-05-20 15:34 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7</p><p>2015-05-14 20:03 - 2015-05-14 20:03 - 00286208 _____ () C:\Windows\Minidump\051415-9874-01.dmp</p><p>2015-05-14 19:59 - 2015-05-20 13:41 - 00000112 _____ () C:\ProgramData\JbiLAXbd1.dat</p><p>2015-05-14 19:57 - 2015-05-14 19:57 - 00000064 _____ () C:\Users\jbremner\AppData\Local\fbaf540cdd3b561c80e7c0f9601a0598</p><p>2015-05-14 19:44 - 2009-06-10 16:00 - 00000824 _____ () C:\Windows\system32\Drivers\etc\hp.bak</p><p>2015-05-14 19:42 - 2015-05-14 19:42 - 00000000 ____D () C:\ProgramData\COMODO</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 ____D () C:\bca5ab1c-8a92-4430-b8df-55a46e0ace81</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9DF2.tmp</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9DD3.tmp</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9D66.tmp</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9D47.tmp</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9D18.tmp</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9D08.tmp</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9CBA.tmp</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9CAB.tmp</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9C7C.tmp</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9C4D.tmp</p><p>2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9C3D.tmp</p><p>2015-05-13 21:09 - 2015-05-01 08:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll</p><p>2015-05-13 21:09 - 2015-05-01 08:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll</p><p>2015-05-13 07:22 - 2015-05-04 20:29 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll</p><p>2015-05-13 07:22 - 2015-05-04 20:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll</p><p>2015-05-13 07:22 - 2015-04-21 21:28 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll</p><p>2015-05-13 07:22 - 2015-04-21 20:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll</p><p>2015-05-13 07:22 - 2015-04-21 12:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll</p><p>2015-05-13 07:22 - 2015-04-21 12:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb</p><p>2015-05-13 07:22 - 2015-04-21 12:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:51 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec</p><p>2015-05-13 07:22 - 2015-04-21 11:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe</p><p>2015-05-13 07:22 - 2015-04-21 11:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe</p><p>2015-05-13 07:22 - 2015-04-21 11:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe</p><p>2015-05-13 07:22 - 2015-04-21 11:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb</p><p>2015-05-13 07:22 - 2015-04-21 11:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec</p><p>2015-05-13 07:22 - 2015-04-21 11:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll</p><p>2015-05-13 07:22 - 2015-04-21 11:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe</p><p>2015-05-13 07:22 - 2015-04-21 10:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe</p><p>2015-05-13 07:22 - 2015-04-21 10:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl</p><p>2015-05-13 07:22 - 2015-04-21 10:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl</p><p>2015-05-13 07:22 - 2015-04-21 10:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll</p><p>2015-05-13 07:22 - 2015-04-21 10:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll</p><p>2015-05-13 07:22 - 2015-04-21 09:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll</p><p>2015-05-13 07:22 - 2015-04-21 09:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll</p><p>2015-05-13 07:22 - 2015-04-17 22:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll</p><p>2015-05-13 07:22 - 2015-04-17 21:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:28 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:28 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys</p><p>2015-05-13 07:21 - 2015-04-27 14:28 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys</p><p>2015-05-13 07:21 - 2015-04-27 14:26 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 01254400 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:23 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:22 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:22 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:22 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:22 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:22 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:22 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:22 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:22 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:21 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:08 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:05 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:04 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:03 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe</p><p>2015-05-13 07:21 - 2015-04-27 14:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll</p><p>2015-05-13 07:21 - 2015-04-27 14:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 13:06 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll</p><p>2015-05-13 07:21 - 2015-04-27 12:57 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe</p><p>2015-05-13 07:21 - 2015-04-27 12:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe</p><p>2015-05-13 07:21 - 2015-04-27 12:55 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 12:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 12:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-27 12:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll</p><p>2015-05-13 07:21 - 2015-04-19 22:17 - 01647104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll</p><p>2015-05-13 07:21 - 2015-04-19 22:17 - 01179136 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll</p><p>2015-05-13 07:21 - 2015-04-19 21:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll</p><p>2015-05-13 07:21 - 2015-04-19 21:11 - 03204608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys</p><p>2015-05-13 07:21 - 2015-04-12 22:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe</p><p>2015-05-13 07:21 - 2015-04-07 22:29 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll</p><p>2015-05-13 07:21 - 2015-04-07 22:29 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll</p><p>2015-05-13 07:21 - 2015-04-07 22:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll</p><p>2015-05-13 07:21 - 2015-03-03 23:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll</p><p>2015-05-13 07:21 - 2015-03-03 23:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll</p><p>2015-05-13 07:21 - 2015-03-03 23:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe</p><p>2015-05-13 07:21 - 2015-03-03 23:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll</p><p>2015-05-13 07:21 - 2015-03-03 23:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll</p><p>2015-05-13 07:21 - 2015-03-03 23:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll</p><p>2015-05-13 07:21 - 2015-03-03 23:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe</p><p>2015-05-13 07:21 - 2015-02-18 02:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe</p><p>2015-05-13 07:21 - 2015-02-18 02:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe</p><p>2015-05-13 07:21 - 2015-01-28 22:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll</p><p>2015-05-13 07:21 - 2015-01-28 22:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll</p><p>2015-05-12 15:07 - 2015-05-12 15:07 - 00003292 _____ () C:\Windows\System32\Tasks\{EDEE40D3-CF55-48AE-A662-1FF18EFE315D}</p><p></p><p>==================== One Month Modified files and folders ========</p><p></p><p>(If an entry is included in the fixlist, the file/folder will be moved.)</p><p></p><p>2015-05-21 15:15 - 2014-04-09 08:38 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys</p><p>2015-05-21 15:12 - 2009-07-14 00:13 - 00786578 _____ () C:\Windows\system32\PerfStringBackup.INI</p><p>2015-05-21 15:12 - 2009-07-13 23:45 - 00034432 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0</p><p>2015-05-21 15:12 - 2009-07-13 23:45 - 00034432 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0</p><p>2015-05-21 15:08 - 2014-10-21 05:59 - 00000000 ___RD () C:\Users\jbremner\iCloudDrive</p><p>2015-05-21 15:08 - 2014-02-27 13:43 - 00000580 _____ () C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-2037836387-1429457356-845570551-1180.job</p><p>2015-05-21 15:08 - 2013-07-05 23:17 - 01965741 _____ () C:\Windows\WindowsUpdate.log</p><p>2015-05-21 15:07 - 2014-01-24 14:44 - 00001015 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Client.lnk</p><p>2015-05-21 15:07 - 2014-01-24 14:44 - 00000999 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Control Panel.lnk</p><p>2015-05-21 15:07 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT</p><p>2015-05-21 15:07 - 2009-07-13 23:51 - 00077277 _____ () C:\Windows\setupact.log</p><p>2015-05-21 14:53 - 2014-02-18 10:16 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job</p><p>2015-05-21 10:39 - 2013-07-29 14:32 - 00000000 ____D () C:\Program Files (x86)\Google</p><p>2015-05-21 10:25 - 2013-10-30 14:40 - 00000000 ____D () C:\Program Files (x86)\Xerox</p><p>2015-05-21 10:12 - 2013-10-06 14:29 - 00000000 ____D () C:\Program Files\Google</p><p>2015-05-21 10:12 - 2010-11-20 22:47 - 00906488 _____ () C:\Windows\PFRO.log</p><p>2015-05-21 10:03 - 2014-02-17 15:10 - 00000000 ____D () C:\Users\jbremner\AppData\Local\Google</p><p>2015-05-21 09:28 - 2009-07-13 23:45 - 05098176 _____ () C:\Windows\system32\FNTCACHE.DAT</p><p>2015-05-21 09:15 - 2014-05-15 06:00 - 00000000 ____D () C:\Users\jbremner\AppData\Local\CrashDumps</p><p>2015-05-21 00:24 - 2013-07-29 11:34 - 00000000 ____D () C:\ProgramData\LogMeIn</p><p>2015-05-20 16:26 - 2014-10-21 06:00 - 00000000 ____D () C:\Users\jbremner\AppData\Local\566069BF-DE81-4744-831F-A1F7EC1547F1.aplzod</p><p>2015-05-20 16:17 - 2014-02-17 15:04 - 00111520 _____ () C:\Users\jbremner\AppData\Local\GDIPFONTCACHEV1.DAT</p><p>2015-05-20 16:16 - 2013-07-29 14:38 - 00000000 ____D () C:\ProgramData\Microsoft Help</p><p>2015-05-20 16:16 - 2009-07-13 22:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared</p><p>2015-05-20 15:57 - 2014-04-09 08:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware</p><p>2015-05-20 15:57 - 2014-04-09 08:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware</p><p>2015-05-20 15:40 - 2013-07-29 14:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox</p><p>2015-05-20 15:39 - 2014-02-17 15:04 - 00000000 ____D () C:\Users\jbremner</p><p>2015-05-20 15:38 - 2009-07-13 22:20 - 00000000 ____D () C:\Program Files\Common Files\System</p><p>2015-05-20 13:25 - 2013-07-05 23:16 - 00000000 ____D () C:\Program Files (x86)\Adobe</p><p>2015-05-20 12:09 - 2015-01-26 12:07 - 00000000 ____D () C:\Users\jbremner\Desktop\StressCount.com</p><p>2015-05-20 11:00 - 2015-04-05 03:00 - 00000000 ___SD () C:\Windows\SysWOW64\GWX</p><p>2015-05-20 11:00 - 2015-04-05 03:00 - 00000000 ___SD () C:\Windows\system32\GWX</p><p>2015-05-20 10:52 - 2014-02-17 15:04 - 00001584 _____ () C:\Users\jbremner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk</p><p>2015-05-20 10:52 - 2013-07-29 14:32 - 00001286 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk</p><p>2015-05-15 10:09 - 2015-03-27 15:19 - 00000000 ____D () C:\Users\jbremner\Desktop\Craigs List</p><p>2015-05-15 09:14 - 2014-11-07 20:58 - 00000000 ____D () C:\Users\jbremner\Desktop\Resume</p><p>2015-05-15 06:54 - 2009-07-14 00:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD</p><p>2015-05-14 22:22 - 2009-07-13 22:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy</p><p>2015-05-14 22:22 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy</p><p>2015-05-14 22:11 - 2009-07-13 21:34 - 00000580 _____ () C:\Windows\win.ini</p><p>2015-05-14 21:55 - 2014-03-25 14:27 - 00000000 ____D () C:\ProgramData\Package Cache</p><p>2015-05-14 21:32 - 2014-06-28 18:33 - 00000000 ____D () C:\Users\jbremner\AppData\Local\Adobe</p><p>2015-05-14 20:03 - 2014-01-21 11:43 - 663071910 _____ () C:\Windows\MEMORY.DMP</p><p>2015-05-14 20:03 - 2014-01-21 11:43 - 00000000 ____D () C:\Windows\Minidump</p><p>2015-05-14 19:58 - 2014-12-23 12:46 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task</p><p>2015-05-14 19:57 - 2014-03-25 15:02 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe</p><p>2015-05-14 19:42 - 2013-07-05 23:16 - 00000000 ____D () C:\ProgramData\Adobe</p><p>2015-05-14 13:16 - 2014-04-13 19:48 - 00000000 ____D () C:\Users\jbremner\Desktop\BREMNER</p><p>2015-05-14 07:42 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache</p><p>2015-05-14 06:08 - 2013-07-29 14:32 - 00000000 ____D () C:\Program Files\Microsoft Silverlight</p><p>2015-05-14 06:08 - 2013-07-29 14:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight</p><p>2015-05-14 06:08 - 2013-02-11 13:28 - 00000000 ____D () C:\Program Files\Windows Journal</p><p>2015-05-14 06:08 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers</p><p>2015-05-13 21:19 - 2013-07-29 14:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013</p><p>2015-05-13 21:17 - 2013-07-29 15:06 - 00000000 ____D () C:\Windows\system32\MRT</p><p>2015-05-13 21:12 - 2013-07-29 14:49 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe</p><p>2015-05-13 21:08 - 2013-07-29 14:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight</p><p>2015-05-12 15:21 - 2014-04-13 19:53 - 00000000 ____D () C:\Users\jbremner\Desktop\Photo and Videos2</p><p>2015-05-12 15:07 - 2013-11-21 05:57 - 00000000 ____D () C:\ProgramData\Oracle</p><p>2015-05-12 14:46 - 2014-02-18 10:06 - 00000000 ____D () C:\Program Files (x86)\Java</p><p>2015-05-11 14:04 - 2014-04-13 19:43 - 00000000 ____D () C:\Users\jbremner\Desktop\CLG</p><p>2015-05-11 09:20 - 2014-04-13 19:52 - 00000000 ____D () C:\Users\jbremner\Desktop\Grand Prix Tennis</p><p>2015-05-11 08:10 - 2014-11-07 18:06 - 00000000 ____D () C:\Users\jbremner\Desktop\Winners Cup</p><p>2015-04-24 11:21 - 2015-04-15 11:08 - 00000000 ____D () C:\Users\jbremner\AppData\Roaming\Skype</p><p>2015-04-23 06:43 - 2014-02-20 09:48 - 00000000 ____D () C:\Users\jbremner\AppData\Local\CutePDF Writer</p><p>2015-04-23 05:54 - 2014-02-18 10:16 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe</p><p>2015-04-23 05:54 - 2014-02-18 10:16 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl</p><p>2015-04-23 05:54 - 2014-02-18 10:16 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater</p><p>2015-04-22 09:45 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF</p><p></p><p>==================== Files in the root of some directories =======</p><p></p><p>2015-05-20 12:35 - 2015-05-20 12:35 - 0000024 _____ () C:\Users\jbremner\AppData\Roaming\appdataFr25.bin</p><p>2014-02-18 06:49 - 2014-02-18 06:49 - 0033193 _____ () C:\Users\jbremner\AppData\Roaming\UserTile.png</p><p>2015-05-14 19:57 - 2015-05-14 19:57 - 0000064 _____ () C:\Users\jbremner\AppData\Local\fbaf540cdd3b561c80e7c0f9601a0598</p><p>2015-05-14 22:46 - 2015-05-14 22:46 - 0000000 _____ () C:\Users\jbremner\AppData\Local\Temp.dat</p><p>2013-07-05 23:13 - 2013-07-05 23:13 - 0000000 ____H () C:\ProgramData\DP45977C.lfl</p><p>2015-05-14 19:59 - 2015-05-20 13:41 - 0000112 _____ () C:\ProgramData\JbiLAXbd1.dat</p><p></p><p>Files to move or delete:</p><p>====================</p><p>C:\ProgramData\JbiLAXbd1.dat</p><p></p><p></p><p>Some files in TEMP:</p><p>====================</p><p>C:\Users\jbremner\AppData\Local\Temp\APNSetup.exe</p><p>C:\Users\jbremner\AppData\Local\Temp\BSvcProcessor.exe</p><p>C:\Users\jbremner\AppData\Local\Temp\C4810D25-29C9-B176-8369-77630CBF9544.dll</p><p>C:\Users\jbremner\AppData\Local\Temp\cw.exe</p><p>C:\Users\jbremner\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpg1ud6r.dll</p><p>C:\Users\jbremner\AppData\Local\Temp\G2MInstallerExtractor.exe</p><p>C:\Users\jbremner\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe</p><p>C:\Users\jbremner\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe</p><p>C:\Users\jbremner\AppData\Local\Temp\MSETUP4.EXE</p><p>C:\Users\jbremner\AppData\Local\Temp\Quarantine.exe</p><p>C:\Users\jbremner\AppData\Local\Temp\sqlite3.dll</p><p>C:\Users\jbremner\AppData\Local\Temp\sqlite3.exe</p><p>C:\Users\jbremner\AppData\Local\Temp\supoptsetup.exe</p><p>C:\Users\user\AppData\Local\Temp\G2MInstallerExtractor.exe</p><p>C:\Users\user\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe</p><p>C:\Users\user\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe</p><p>C:\Users\user\AppData\Local\Temp\SkypeSetup.exe</p><p></p><p></p><p>==================== Bamital & volsnap Check =================</p><p></p><p>(There is no automatic fix for files that do not pass verification.)</p><p></p><p>C:\Windows\System32\winlogon.exe => File is digitally signed</p><p>C:\Windows\System32\wininit.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\wininit.exe => File is digitally signed</p><p>C:\Windows\explorer.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\explorer.exe => File is digitally signed</p><p>C:\Windows\System32\svchost.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\svchost.exe => File is digitally signed</p><p>C:\Windows\System32\services.exe => File is digitally signed</p><p>C:\Windows\System32\User32.dll => File is digitally signed</p><p>C:\Windows\SysWOW64\User32.dll => File is digitally signed</p><p>C:\Windows\System32\userinit.exe => File is digitally signed</p><p>C:\Windows\SysWOW64\userinit.exe => File is digitally signed</p><p>C:\Windows\System32\rpcss.dll => File is digitally signed</p><p>C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed</p><p></p><p></p><p>LastRegBack: 2015-05-14 07:35</p><p></p><p>==================== End of log ============================</p><p></p><p>Addition.txt</p><p></p><p>Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-05-2015</p><p>Ran by jbremner at 2015-05-21 15:47:48</p><p>Running from D:\</p><p>Boot Mode: Normal</p><p>==========================================================</p><p></p><p></p><p>==================== Accounts: =============================</p><p></p><p>Administrator (S-1-5-21-3125894905-1441278399-474381537-500 - Administrator - Disabled)</p><p>Guest (S-1-5-21-3125894905-1441278399-474381537-501 - Limited - Disabled)</p><p>user (S-1-5-21-3125894905-1441278399-474381537-1000 - Administrator - Enabled) => C:\Users\user</p><p></p><p>==================== Security Center ========================</p><p></p><p>(If an entry is included in the fixlist, it will be removed.)</p><p></p><p>AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}</p><p></p><p>==================== Installed Programs ======================</p><p></p><p>(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)</p><p></p><p>7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)</p><p>Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated)</p><p>Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)</p><p>Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)</p><p>Apple Application Support (32-bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)</p><p>Apple Application Support (64-bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)</p><p>Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)</p><p>Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)</p><p>Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)</p><p>Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - )</p><p>Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)</p><p>Canon MG3200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3200_series) (Version: - Canon Inc.)</p><p>Canon MG3200 series On-screen Manual (HKLM-x32\...\Canon MG3200 series On-screen Manual) (Version: 7.5.0 - Canon Inc.)</p><p>Canon MX410 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX410_series) (Version: - Canon Inc.)</p><p>Carbonite (HKLM-x32\...\Carbonite Backup) (Version: 5.5.5 build 4151 (Jun-27-2014) - Carbonite)</p><p>Citrix Online Launcher (HKLM-x32\...\{AC7E7905-8C59-4806-A96D-30936A2B1FC5}) (Version: 1.0.168 - Citrix)</p><p>Create Recovery Media (HKLM-x32\...\{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}) (Version: 1.20.0.00 - Lenovo Group Limited)</p><p>CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version: 3.0 - CutePDF.com)</p><p>Disable AMT Profile Synchronization Pop-up for Windows XP/Vista/7/8 (HKLM\...\DisableAMTPopup) (Version: 1.00 - )</p><p>globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION</p><p>GoToMeeting 7.1.8.2553 (HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\GoToMeeting) (Version: 7.1.8.2553 - CitrixOnline)</p><p>HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.241 - SurfRight B.V.)</p><p>iCloud (HKLM\...\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)</p><p>Integrated Camera (HKLM-x32\...\Sunplus SPUVCb) (Version: 3.4.7.19 - SunplusIT)</p><p>Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.20.1337 - Intel Corporation)</p><p>Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2857 - Intel Corporation)</p><p>Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{A10B1524-63B5-40F2-B272-D841CF671C16}) (Version: 2.2.0.0266 - Intel Corporation)</p><p>Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)</p><p>Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.6.245 - Intel Corporation)</p><p>Intel(R) WiDi (HKLM\...\{6097158B-0184-4140-BEC3-7885794D2571}) (Version: 3.5.40.0 - Intel Corporation)</p><p>Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - )</p><p>Intel® PROSet/Wireless WiFi Software (HKLM\...\{ECE5B218-A086-4E18-A362-D11181681457}) (Version: 15.03.1000.1637 - Intel Corporation)</p><p>Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden</p><p>iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)</p><p>Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)</p><p>join.me (HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\JoinMe) (Version: 1.14.0.141 - LogMeIn, Inc.)</p><p>Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 2.01 - )</p><p>Lenovo Patch Utility (HKLM-x32\...\{6E6E7725-C7BC-4C39-8B3F-14B67331A120}) (Version: 1.3.0.9 - Lenovo Group Limited)</p><p>Lenovo Patch Utility 64 bit (HKLM\...\{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}) (Version: 1.3.1.1 - Lenovo Group Limited)</p><p>Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.00.02 - )</p><p>LogMeIn (HKLM-x32\...\{CB7AF84A-1B7F-4C6B-8A58-EB7CDE48C23A}) (Version: 4.1.3268 - LogMeIn, Inc.)</p><p>Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)</p><p>Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)</p><p>Microsoft Office 365 ProPlus (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)</p><p>Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)</p><p>Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)</p><p>Mozilla Firefox 22.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 22.0 (x86 en-US)) (Version: 22.0 - Mozilla)</p><p>Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 22.0 - Mozilla)</p><p>MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)</p><p>MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)</p><p>Network Scan (HKLM-x32\...\{9C5725B7-2219-410C-A364-90767F71F00C}) (Version: - )</p><p>On Screen Display (HKLM\...\OnScreenDisplay) (Version: 7.11.20 - )</p><p>Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden</p><p>Power Manager (HKLM-x32\...\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}) (Version: 6.45 - )</p><p>QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)</p><p>Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6818 - Realtek Semiconductor Corp.)</p><p>Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 (HKLM\...\EnablePS) (Version: 1.00 - )</p><p>Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft)</p><p>Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden</p><p>Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)</p><p>Skype™ 7.3 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)</p><p>ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.3.15.2 - )</p><p>ThinkVantage Fingerprint Software (HKLM\...\{F58DA859-016E-492D-A588-317D9BB28002}) (Version: 5.9.9.7282 - Authentec Inc.)</p><p>Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\...\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{40930C8E-A677-414C-A72F-DFDEB10738FB}) (Version: - Microsoft)</p><p>Windows Driver Package - Intel (e1cexpress) Net (01/11/2012 11.15.16.0) (HKLM\...\EC2A0F2B229770EC589265FCF2B4839A0C221993) (Version: 01/11/2012 11.15.16.0 - Intel)</p><p>Windows Driver Package - Intel (iaStor) hdc (05/30/2012 11.2.0.1006) (HKLM\...\D92B2A049725011212996291E9BA2774FA43A3B0) (Version: 05/30/2012 11.2.0.1006 - Intel)</p><p>Windows Driver Package - Lenovo 1.66.00.22 (11/30/2012 1.66.00.22) (HKLM\...\16E722986C4293F5D6BF43595DFFD631398D5F21) (Version: 11/30/2012 1.66.00.22 - Lenovo)</p><p>Windows Driver Package - Synaptics (SmbDrv) System (03/04/2013 16.3.15.2) (HKLM\...\850C78BE3B5F0293BD5597737A6E95F45C18E8E1) (Version: 03/04/2013 16.3.15.2 - Synaptics)</p><p>Windows Driver Package - Synaptics (SynTP) Mouse (03/04/2013 16.3.15.2) (HKLM\...\A3D5941AC939C813D8A35AC7207BB60AD235AB5B) (Version: 03/04/2013 16.3.15.2 - Synaptics)</p><p>Xerox 7600 Driver (HKLM-x32\...\{4F7EE569-CF67-4054-82D2-8FF309489682}) (Version: 4.6.10306 - Visioneer Inc.)</p><p></p><p>==================== Custom CLSID (Whitelisted): ==========================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>CustomCLSID: HKU\S-1-5-21-2037836387-1429457356-845570551-1180_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\jbremner\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File</p><p>CustomCLSID: HKU\S-1-5-21-2037836387-1429457356-845570551-1180_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\jbremner\AppData\Local\Citrix\GoToMeeting\1350\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)</p><p></p><p>==================== Restore Points =========================</p><p></p><p>14-05-2015 22:44:25 Removed Microsoft Silverlight</p><p>14-05-2015 22:44:39 Removed Microsoft Silverlight</p><p>20-05-2015 10:57:31 Windows Update</p><p>20-05-2015 11:00:38 Windows Update</p><p>20-05-2015 16:10:43 Checkpoint by HitmanPro</p><p>20-05-2015 16:15:31 Configured Microsoft Office 365 ProPlus</p><p>20-05-2015 16:15:36 PROPLUSR</p><p>20-05-2015 16:19:21 Checkpoint by HitmanPro</p><p>21-05-2015 09:20:28 Checkpoint by HitmanPro</p><p>21-05-2015 09:27:34 Checkpoint by HitmanPro</p><p>21-05-2015 10:02:54 Removed Google Chrome</p><p>21-05-2015 10:15:22 Removed Xerox PC Fax</p><p>21-05-2015 10:30:24 Checkpoint by HitmanPro</p><p></p><p>==================== Hosts content: ===============================</p><p></p><p>(If needed Hosts: directive could be included in the fixlist to reset Hosts.)</p><p></p><p>2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts</p><p></p><p>==================== Scheduled Tasks (Whitelisted) =============</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>Task: {00C7830E-4ACF-42EF-9029-0F04F36CCEB4} - \avaavaevy No Task File <==== ATTENTION</p><p>Task: {16C03C5F-1E81-4DC8-BCBD-69E3DCB1D48D} - System32\Tasks\YNZSM => C:\ProgramData\06e78fe9f3fa4765b7830b8886163656\06e78fe9f3fa4765b7830b8886163656.exe</p><p>Task: {261B5FB7-1F5A-4F7A-BD1B-AAF57A70E12F} - System32\Tasks\IIXQMYFCO1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION</p><p>Task: {263BB5B4-1F78-42DB-A341-41452840484C} - System32\Tasks\PMTask => C:\Program Files (x86)\ThinkPad\Utilities\PWMIDTSV.EXE [2013-01-09] (Lenovo Group Limited)</p><p>Task: {2BFA7B1C-9A40-4489-8A3C-F7565E419CB6} - \avabvbxvh No Task File <==== ATTENTION</p><p>Task: {2F1A3417-4A34-4BAC-A2C5-8BF858590602} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)</p><p>Task: {39A262AF-D8BB-4994-842E-68AEA7FB00AE} - System32\Tasks\{D5FA6611-36C5-4C47-B77C-4A74B32D5862} => Iexplore.exe <a href="http://ui.skype.com/ui/0/6.6.0.106/en/abandoninstall?page=tsMain" target="_blank">http://ui.skype.com/ui/0/6.6.0.106/en/abandoninstall?page=tsMain</a></p><p>Task: {51976E3D-564A-4E1B-AF14-FD89F600D92C} - System32\Tasks\Microsoft Office 15 Sync Maintenance for ITMAXGROUP-jbremner IMG0001556.itmaxgroup.local => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2015-04-14] (Microsoft Corporation)</p><p>Task: {532247B7-AF01-4149-A4F1-BC855D192C85} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-23] (Adobe Systems Incorporated)</p><p>Task: {60FE4DBD-F2A7-4B82-9028-9FA47781BCA1} - System32\Tasks\DiskUpdate => C:\SWTOOLS\OSFIXES\DISKUPDT\DiskUpdate.exe [2009-02-09] ()</p><p>Task: {67A67FDB-055D-4FEF-995A-7D77CBA52447} - System32\Tasks\{EDEE40D3-CF55-48AE-A662-1FF18EFE315D} => pcalua.exe -a "C:\Users\jbremner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C9VLFZGV\JavaSetup8u45.exe" -d C:\Users\jbremner\Desktop</p><p>Task: {7259A915-19A1-4976-88DB-E05C3E0A7331} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)</p><p>Task: {843F0FE6-CF5A-4B67-A622-4BA48D1FBF26} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-03-07] (Adobe Systems Incorporated)</p><p>Task: {8B52CC4D-8554-4EFF-BD5C-91BD0BE6F1E8} - System32\Tasks\G2MUpdateTask-S-1-5-21-2037836387-1429457356-845570551-1180 => C:\Users\jbremner\AppData\Local\Citrix\GoToMeeting\2553\g2mupdate.exe [2015-04-13] (Citrix Online, a division of Citrix Systems, Inc.)</p><p>Task: {98CD9C28-BA2E-4028-99DF-373042012A7B} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2014-12-01] (Apple Inc.)</p><p>Task: {9F86584F-1522-4C11-8DD7-75DF317FD505} - System32\Tasks\Norwood => C:\Program Files\shopperz\Cote.bat</p><p>Task: {ACB1C182-EE82-433D-8839-EE55F4EEA83A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)</p><p>Task: {ADF05F1A-BB9F-4C72-AB2F-0B503432D09D} - System32\Tasks\Intel\Intel Service Manager => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe</p><p>Task: {AE5C3F82-DAAC-4EF4-868C-0138779DCF95} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)</p><p>Task: {CBE89A5D-126F-47F6-A833-F8C742D67391} - \ProPCCleaner_Start No Task File <==== ATTENTION</p><p>Task: {D53D9D8B-9FD8-46EB-95E5-67BC8B4C5DCB} - \ProPCCleaner_Popup No Task File <==== ATTENTION</p><p>Task: {EE8AF48E-2ED8-4A06-874A-9DB8AC8EFE4C} - System32\Tasks\GoogleUpdateTaskUserM_1_7_22_478699874-4155726479-3780505679-3006UA__31313431363639352d344a414155342a2a236c6c5a => Wscript.exe //B "C:\ProgramData\PastaLeadsAgent\startprocess.js" pastaleadss.exe /invoke /f:check_services /l:0</p><p>Task: {EE921805-FF18-4EA2-8C0C-93F9CD5E1433} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)</p><p>Task: {F70B3427-51FE-4218-8C44-588CAC32B5D9} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-07] (Microsoft Corporation)</p><p>Task: {FDF8BAFA-DC68-4BD4-81D8-E262130743F7} - System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} => C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe</p><p>Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe</p><p>Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-2037836387-1429457356-845570551-1180.job => C:\Users\jbremner\AppData\Local\Citrix\GoToMeeting\2553\g2mupdate.exe</p><p>Task: C:\Windows\Tasks\IIXQMYFCO1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION</p><p></p><p>==================== Loaded Modules (Whitelisted) ==============</p><p></p><p>2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll</p><p>2015-01-20 23:35 - 2015-01-20 23:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll</p><p>2013-07-05 23:15 - 2013-01-09 17:45 - 00094208 ____N () C:\Program Files (x86)\ThinkPad\Utilities\US\PWMRT64V.DLL</p><p>2013-07-29 14:33 - 2012-10-04 19:49 - 00087152 _____ () C:\Windows\System32\cpwmon64.dll</p><p>2013-07-29 14:36 - 2008-09-08 18:57 - 00022016 _____ () C:\Windows\System32\sxs2ml6.dll</p><p>2015-01-20 23:35 - 2015-01-20 23:35 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll</p><p>2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll</p><p></p><p>==================== Alternate Data Streams (Whitelisted) =========</p><p></p><p>(If an entry is included in the fixlist, only the ADS will be removed.)</p><p></p><p></p><p>==================== Safe Mode (Whitelisted) ===================</p><p></p><p>(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)</p><p></p><p></p><p>==================== EXE Association (Whitelisted) ===============</p><p></p><p>(If an entry is included in the fixlist, the registry item will be restored to default or removed.)</p><p></p><p></p><p>==================== Internet Explorer trusted/restricted ===============</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry.)</p><p></p><p></p><p>==================== Other Areas ============================</p><p></p><p>(Currently there is no automatic fix for this section.)</p><p></p><p>HKU\S-1-5-21-2037836387-1429457356-845570551-1180\Control Panel\Desktop\\Wallpaper -> C:\Users\jbremner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg</p><p>DNS Servers: 192.168.168.5</p><p></p><p>==================== MSCONFIG/TASK MANAGER Error getting ==</p><p></p><p>(Currently there is no automatic fix for this section.)</p><p></p><p></p><p>==================== FirewallRules (Whitelisted) ===============</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe</p><p>FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe</p><p>FirewallRules: [{5BC08E3C-63A4-41CA-95ED-9FC11191EDEE}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe</p><p>FirewallRules: [{A747BE03-9A8A-4DF4-887C-5683657E0DA7}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe</p><p>FirewallRules: [{8622BC69-4DDE-4302-9B9D-84C6039586D3}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe</p><p>FirewallRules: [{7A60F9C4-F561-4A1A-95C6-3CB139B5FAA7}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe</p><p>FirewallRules: [{96D89F78-4BC4-4EB0-BA2C-F73722874C5F}] => (Allow) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe</p><p>FirewallRules: [{907F9C35-8858-4B6D-9278-8C4AD61972E7}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe</p><p>FirewallRules: [{F4D32FD2-16AA-4FB6-A864-996AEAEB2810}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe</p><p>FirewallRules: [{0772165F-F184-4DC5-B9C9-C17A6FF67BAB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe</p><p>FirewallRules: [{4C9DD39A-74BC-48E1-B64D-5078A4F228AD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe</p><p>FirewallRules: [{DBEC3747-E0D0-4C8B-B1C5-6E4A5D0EF9C1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe</p><p>FirewallRules: [{0A137A7F-5AE9-4482-A003-F10E9F500083}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe</p><p>FirewallRules: [{BC0CB494-8421-4DA7-8403-0AF9EAEAC92F}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe</p><p>FirewallRules: [{A8A945DD-5FC9-47BA-9389-EC47A7816CB1}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe</p><p>FirewallRules: [{761794EB-834E-4DFB-90C3-676BF766AD40}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe</p><p>FirewallRules: [{822316CF-1A84-42C6-A893-57E15689875B}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe</p><p>FirewallRules: [{08D4784E-A83E-4DBA-9C80-512DCBC880A8}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe</p><p>FirewallRules: [{7FBBA375-2E7D-4E37-A477-3C44B6565F79}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe</p><p>FirewallRules: [{28B18022-4738-4281-9F07-04BC851AD7E0}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe</p><p>FirewallRules: [{19D967A0-90D2-479A-976C-E75253469C5E}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe</p><p>FirewallRules: [{9419526F-CDEC-4567-8B10-0FA2BC1B3E85}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe</p><p>FirewallRules: [{90D58FDD-94C2-4959-94C0-1552BFF7ED0C}] => (Allow) C:\Windows\twain_32\Xerox\WC3220\Sscan2io.exe</p><p>FirewallRules: [{7AEEAB18-AD97-4C8C-B39B-846F88F3E5D0}] => (Allow) C:\Windows\twain_32\Xerox\WC3220\Sscan2io.exe</p><p>FirewallRules: [TCP Query User{E6398012-0E7D-4A64-9BA2-CB25AF0254EC}C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe] => (Allow) C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe</p><p>FirewallRules: [UDP Query User{E9377D72-FF17-424F-9B8A-C49B61970B9B}C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe] => (Allow) C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe</p><p>FirewallRules: [TCP Query User{BF577325-4BDF-4817-8E58-3215D97D70A2}C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe] => (Block) C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe</p><p>FirewallRules: [UDP Query User{DA06EFF4-EB85-431A-B03E-89501CD57C24}C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe] => (Block) C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe</p><p>FirewallRules: [{7045EE2E-AD3B-4137-AAF4-36B12899A77F}] => (Allow) C:\Users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe</p><p>FirewallRules: [{CD01EFF0-79C7-4507-AC7C-C9C51A0A9D94}] => (Allow) C:\Users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe</p><p>FirewallRules: [TCP Query User{6C77C019-1434-4DF7-8626-8B0F53CBD521}C:\users\jbremner\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\jbremner\appdata\roaming\dropbox\bin\dropbox.exe</p><p>FirewallRules: [UDP Query User{B3098D33-A459-4BBB-ADFC-C2C624B53F50}C:\users\jbremner\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\jbremner\appdata\roaming\dropbox\bin\dropbox.exe</p><p>FirewallRules: [{A28759A7-A1F5-4674-9536-C2DA106829DE}] => (Allow) C:\Users\jbremner\AppData\Roaming\Dropbox\bin\Dropbox.exe</p><p>FirewallRules: [{9BFC6D01-A12B-43A7-AA07-955F9479C952}] => (Allow) C:\Users\jbremner\AppData\Roaming\Dropbox\bin\Dropbox.exe</p><p>FirewallRules: [{54AC4155-C674-4FA4-984A-3005DE527F7C}] => (Allow) C:\Program Files\iTunes\iTunes.exe</p><p></p><p>==================== Faulty Device Manager Devices =============</p><p></p><p>Name: mmjimzv2yxmwbdd</p><p>Description: mmjimzv2yxmwbdd</p><p>Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}</p><p>Manufacturer: </p><p>Service: mmjimzv2yxmwbdd</p><p>Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)</p><p>Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.</p><p>Devices stay in this state if they have been prepared for removal.</p><p>After you remove the device, this error disappears.Remove the device, and this error should be resolved.</p><p></p><p>Name: </p><p>Description: </p><p>Class Guid: </p><p>Manufacturer: </p><p>Service: </p><p>Problem: : The drivers for this device are not installed. (Code 28)</p><p>Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.</p><p></p><p>Name: Teredo Tunneling Pseudo-Interface</p><p>Description: Microsoft Teredo Tunneling Adapter</p><p>Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}</p><p>Manufacturer: Microsoft</p><p>Service: tunnel</p><p>Problem: : This device cannot start. (Code10)</p><p>Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.</p><p>On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.</p><p></p><p></p><p>==================== Event log errors: =========================</p><p></p><p>Application errors:</p><p>==================</p><p>Error: (05/21/2015 03:07:54 PM) (Source: WinMgmt) (EventID: 10) (User: )</p><p>Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003</p><p></p><p>Error: (05/21/2015 02:43:05 PM) (Source: WinMgmt) (EventID: 10) (User: )</p><p>Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003</p><p></p><p>Error: (05/21/2015 02:24:50 PM) (Source: WinMgmt) (EventID: 10) (User: )</p><p>Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000200,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,00000000019BEE60.72). hr = 0x80070005, Access is denied.</p><p>.</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000006cc,(null),0,REG_BINARY,0000000001F2E0B0.72). hr = 0x80070005, Access is denied.</p><p>.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}</p><p> Writer Name: WMI Writer</p><p> Writer Instance ID: {4b746811-d3ee-47f6-a94a-bbcb1cb21fae}</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000c8c,(null),0,REG_BINARY,0000000005EBE100.72). hr = 0x80070005, Access is denied.</p><p>.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2}</p><p> Writer Name: MSSearch Service Writer</p><p> Writer Instance ID: {2bed8e4b-10b7-4d6a-9bf9-36b36ac5d772}</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001b4,SYSTEM\CurrentControlSet\Services\VSS\Diag\Registry Writer,0,REG_BINARY,00000000028EE8C0.72). hr = 0x80070005, Access is denied.</p><p>.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {afbab4a2-367d-4d15-a586-71dbb18f8485}</p><p> Writer Name: Registry Writer</p><p> Writer Instance ID: {35a93998-fed9-4f63-93ab-313faf85bce1}</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001c0,SYSTEM\CurrentControlSet\Services\VSS\Diag\COM+ REGDB Writer,0,REG_BINARY,0000000002BAF2A0.72). hr = 0x80070005, Access is denied.</p><p>.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {542da469-d3e1-473c-9f4f-7847f01fc64f}</p><p> Writer Name: COM+ REGDB Writer</p><p> Writer Instance ID: {61a6dcae-ec28-4782-9030-37e277730327}</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000002e8,(null),0,REG_BINARY,00000000029AE0B0.72). hr = 0x80070005, Access is denied.</p><p>.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}</p><p> Writer Name: System Writer</p><p> Writer Instance ID: {f8bb262e-2489-458a-ac59-398fb25c4dd4}</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\Shadow Copy Optimization Writer,0,REG_BINARY,0000000002ADEA40.72). hr = 0x80070005, Access is denied.</p><p>.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}</p><p> Writer Name: Shadow Copy Optimization Writer</p><p> Writer Instance ID: {30634271-3245-47d0-89c8-e79bb1f8d106}</p><p></p><p></p><p>System errors:</p><p>=============</p><p>Error: (05/21/2015 03:14:06 PM) (Source: Service Control Manager) (EventID: 7032) (User: )</p><p>Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the CarboniteService service, but this action failed with the following error: </p><p>%%1056</p><p></p><p>Error: (05/21/2015 03:13:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The Intel(R) Management and Security Application User Notification Service service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p>Error: (05/21/2015 03:13:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The iPod Service service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p>Error: (05/21/2015 03:13:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The Bluetooth Media Service service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p>Error: (05/21/2015 03:13:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The Bluetooth OBEX Service service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p>Error: (05/21/2015 03:13:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )</p><p>Description: The Windows Modules Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.</p><p></p><p>Error: (05/21/2015 03:13:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The Lenovo Hotkey Client Loader service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p>Error: (05/21/2015 03:13:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The Lenovo Microphone Mute service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p>Error: (05/21/2015 03:13:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The Intel(R) PROSet/Wireless Zero Configuration Service service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p>Error: (05/21/2015 03:13:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The On Screen Display service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p></p><p>Microsoft Office:</p><p>=========================</p><p>Error: (05/21/2015 03:07:54 PM) (Source: WinMgmt) (EventID: 10) (User: )</p><p>Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003</p><p></p><p>Error: (05/21/2015 02:43:05 PM) (Source: WinMgmt) (EventID: 10) (User: )</p><p>Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003</p><p></p><p>Error: (05/21/2015 02:24:50 PM) (Source: WinMgmt) (EventID: 10) (User: )</p><p>Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: RegSetValueExW(0x00000200,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,00000000019BEE60.72)0x80070005, Access is denied.</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: RegSetValueExW(0x000006cc,(null),0,REG_BINARY,0000000001F2E0B0.72)0x80070005, Access is denied.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}</p><p> Writer Name: WMI Writer</p><p> Writer Instance ID: {4b746811-d3ee-47f6-a94a-bbcb1cb21fae}</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: RegSetValueExW(0x00000c8c,(null),0,REG_BINARY,0000000005EBE100.72)0x80070005, Access is denied.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2}</p><p> Writer Name: MSSearch Service Writer</p><p> Writer Instance ID: {2bed8e4b-10b7-4d6a-9bf9-36b36ac5d772}</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: RegSetValueExW(0x000001b4,SYSTEM\CurrentControlSet\Services\VSS\Diag\Registry Writer,0,REG_BINARY,00000000028EE8C0.72)0x80070005, Access is denied.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {afbab4a2-367d-4d15-a586-71dbb18f8485}</p><p> Writer Name: Registry Writer</p><p> Writer Instance ID: {35a93998-fed9-4f63-93ab-313faf85bce1}</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: RegSetValueExW(0x000001c0,SYSTEM\CurrentControlSet\Services\VSS\Diag\COM+ REGDB Writer,0,REG_BINARY,0000000002BAF2A0.72)0x80070005, Access is denied.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {542da469-d3e1-473c-9f4f-7847f01fc64f}</p><p> Writer Name: COM+ REGDB Writer</p><p> Writer Instance ID: {61a6dcae-ec28-4782-9030-37e277730327}</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: RegSetValueExW(0x000002e8,(null),0,REG_BINARY,00000000029AE0B0.72)0x80070005, Access is denied.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}</p><p> Writer Name: System Writer</p><p> Writer Instance ID: {f8bb262e-2489-458a-ac59-398fb25c4dd4}</p><p></p><p>Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: )</p><p>Description: RegSetValueExW(0x000001f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\Shadow Copy Optimization Writer,0,REG_BINARY,0000000002ADEA40.72)0x80070005, Access is denied.</p><p></p><p></p><p>Operation:</p><p> BackupShutdown Event</p><p></p><p>Context:</p><p> Execution Context: Writer</p><p> Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}</p><p> Writer Name: Shadow Copy Optimization Writer</p><p> Writer Instance ID: {30634271-3245-47d0-89c8-e79bb1f8d106}</p><p></p><p></p><p>CodeIntegrity Errors:</p><p>===================================</p><p> Date: 2015-05-21 15:07:53.048</p><p> Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.</p><p></p><p> Date: 2015-05-21 15:07:52.998</p><p> Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.</p><p></p><p> Date: 2015-05-21 14:43:04.055</p><p> Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.</p><p></p><p> Date: 2015-05-21 14:43:04.005</p><p> Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.</p><p></p><p> Date: 2015-05-21 14:24:49.425</p><p> Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.</p><p></p><p> Date: 2015-05-21 14:24:49.365</p><p> Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.</p><p></p><p> Date: 2015-05-21 10:53:32.602</p><p> Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.</p><p></p><p> Date: 2015-05-21 10:53:32.555</p><p> Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.</p><p></p><p> Date: 2015-05-21 10:12:39.604</p><p> Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.</p><p></p><p> Date: 2015-05-21 10:12:39.554</p><p> Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.</p><p></p><p></p><p>==================== Memory info =========================== </p><p></p><p>Processor: Intel(R) Core(TM) i5-3437U CPU @ 1.90GHz</p><p>Percentage of memory in use: 45%</p><p>Total physical RAM: 3793.41 MB</p><p>Available physical RAM: 2079.82 MB</p><p>Total Pagefile: 7585.04 MB</p><p>Available Pagefile: 5726 MB</p><p>Total Virtual: 8192 MB</p><p>Available Virtual: 8191.8 MB</p><p></p><p>==================== Drives ================================</p><p></p><p>Drive c: (Windows7_OS) (Fixed) (Total:145.54 GB) (Free:14.38 GB) NTFS ==>[System with boot components (obtained from reading drive)]</p><p>Drive d: () (Removable) (Total:7.19 GB) (Free:7.15 GB) FAT32</p><p>Drive q: (Lenovo_Recovery) (Fixed) (Total:13.67 GB) (Free:3.63 GB) NTFS</p><p></p><p>==================== MBR & Partition Table ==================</p><p></p><p>========================================================</p><p>Disk: 0 (Size: 167.7 GB) (Disk ID: 640D7EA8)</p><p>Partition 1: (Active) - (Size=1.5 GB) - (Type=07 NTFS)</p><p>Partition 2: (Not Active) - (Size=145.5 GB) - (Type=07 NTFS)</p><p>Partition 3: (Not Active) - (Size=13.7 GB) - (Type=07 NTFS)</p><p>Partition 4: (Not Active) - (Size=7 GB) - (Type=84)</p><p></p><p>========================================================</p><p>Disk: 1 (Size: 7.2 GB) (Disk ID: 54CC1D44)</p><p>Partition 1: (Not Active) - (Size=7.2 GB) - (Type=0B)</p><p></p><p>==================== End of log ============================</p><p></p><p>There was no FIX list.</p><p></p><p>I will provide logs from the other scan tools if needed. They are all partial because the tools have been run repeatedly with fixing done until there is nothing to fix.</p></blockquote><p></p>
[QUOTE="Perryaire, post: 387866, member: 36568"] I need help to remove whatever is causing browsers to redirect to [URL="http://www.search.info"]www.search.info[/URL] I followed all of the steps in the Trovi Removal instructions multiple times. The computer was too munged up to remove Trovi from the browsers until after I ran some of the tools. Once the tools were run I followed the instructions for removing Trovi from IE and Firefox and just removed Chrome altogether. After several repeats, things are close to being OK. It is just that whenever I start IE, it wants to redirect to [URL="http://www.search.info"]www.search.info[/URL] instead of just sending me to google.com as set in the advanced internet options. Further research on this site led to downloading and running Kaspersky's tdskiller to check for rootkits. The scan reported no infections. Below are the FRST logs run after the clean up. Sorry I could not attach log files, they did not show in the list of files to be uploaded when I tried. FRST.txt Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-05-2015 Ran by jbremner (administrator) on IMG0001556 on 21-05-2015 15:47:25 Running from D:\ Loaded Profiles: jbremner (Available profiles: jbremner & user) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: [URL]http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/[/URL] ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Carbonite, Inc. ([URL="http://www.carbonite.com"]www.carbonite.com[/URL])) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184112 2012-06-01] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp HKLM-x32\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor) HKLM-x32\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1260256 2013-01-04] (Realtek Semiconductor) HKLM-x32\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [170304 2012-09-21] (Intel Corporation) HKLM-x32\...\Run: [HotKeysCmds] => C:\Windows\system32\hkcmd.exe [398656 2012-09-21] (Intel Corporation) HKLM-x32\...\Run: [Persistence] => C:\Windows\system32\igfxpers.exe [441152 2012-09-21] (Intel Corporation) HKLM-x32\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3023600 2013-03-04] (Synaptics Incorporated) HKLM-x32\...\Run: [LogMeIn GUI] => C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [57928 2013-04-30] (LogMeIn, Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.) HKLM\...\Run: [3D BubbleSound] => "C:\Program Files\BubbleSound\3D BubbleSound.exe" HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134176 2012-10-22] (Intel Corporation) HKLM-x32\...\Run: [Integrated Camera_Monitor] => C:\Program Files (x86)\Integrated Camera\monitor.exe [1699192 2012-12-25] () HKLM-x32\...\Run: [PWMTRV] => rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [290688 2012-10-23] (Intel Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.) HKLM-x32\...\Run: [NSCSysTrayUI_XEROX] => C:\Program Files (x86)\XEROX\NetworkScan\NSCSysUI_XEROX.exe [266240 2009-01-13] (XEROX) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2010-09-09] (CANON INC.) HKLM-x32\...\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1056976 2014-06-27] (Carbonite, Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\psfus: C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.) HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [GoToMeeting] => C:\Users\jbremner\AppData\Local\Citrix\GoToMeeting\1350\g2mstart.exe [40304 2014-03-09] (Citrix Online, a division of Citrix Systems, Inc.) HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.) HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.) HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-10-20] (Apple Inc.) HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [GoogleChromeAutoLaunch_ED6964934F1BBF8145A329153CF6D8B3] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\Run: [BingSvc] => C:\Users\jbremner\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation) HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\MountPoints2: {3e061047-e5f1-11e2-9914-806e6f6e6963} - Q:\LenovoQDrive.exe AppInit_DLLs-x32: c:\programdata\flashbeat\flashbeat32.dll => "c:\programdata\flashbeat\flashbeat32.dll" File Not Found Lsa: [Notification Packages] scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.) ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.) ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.) ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.) ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2037836387-1429457356-845570551-1180\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled ProxyServer: [.DEFAULT] => http=127.0.0.1:53847;https=127.0.0.1:53847 HKU\S-1-5-21-2037836387-1429457356-845570551-1180\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = [URL]http://www.msn.com/?ocid=iehp[/URL] SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2037836387-1429457356-845570551-1180 -> DefaultScope {08EDEB72-2C69-419C-A5D6-E62331429327} URL = [URL]https://www.google.com/search?q={searchTerms}[/URL] SearchScopes: HKU\S-1-5-21-2037836387-1429457356-845570551-1180 -> {08EDEB72-2C69-419C-A5D6-E62331429327} URL = [URL]https://www.google.com/search?q={searchTerms}[/URL] SearchScopes: HKU\S-1-5-21-2037836387-1429457356-845570551-1180 -> {D7C0A3C0-5F83-4D4F-9F59-707F33C6D3B6} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-22] (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} [URL]http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab[/URL] Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-03-12] (Microsoft Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.168.5 FireFox: ======== FF ProfilePath: C:\Users\jbremner\AppData\Roaming\Mozilla\Firefox\Profiles\3vm4j7wd.default-1432219147981 FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\system32\npDeployJava1.dll [2013-07-29] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-04-06] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-04-06] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-04-06] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-04-06] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-04-06] (Apple Inc.) FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] Chrome: ======= CHR Profile: C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-20] CHR Extension: (Google Docs) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-20] CHR Extension: (Google Drive) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-20] CHR Extension: (YouTube) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-20] CHR Extension: (Google Search) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-20] CHR Extension: (Google Sheets) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-20] CHR Extension: (Gmail) - C:\Users\jbremner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-20] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1254400 2015-04-27] (Microsoft Corporation) S3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [320576 2013-01-09] (Lenovo.) S2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2015-05-20] (SurfRight B.V.) S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166432 2012-10-22] (Intel Corporation) S2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [136288 2012-08-10] (Lenovo Group Limited) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [417640 2015-02-26] (LogMeIn, Inc.) S2 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [234344 2015-02-26] (LogMeIn, Inc.) R2 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2013-04-30] (LogMeIn, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272688 2012-08-23] () S2 OneTouch 4.0 Monitor; C:\Program Files (x86)\Visioneer\OneTouch 4.0\OtService.exe [221184 2010-11-02] (Visioneer Inc.) [File not signed] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3342640 2012-08-23] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [111104 2012-05-21] (Motorola Solutions, Inc.) R3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [849408 2012-06-09] (Motorola Solutions, Inc.) S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [54072 2010-10-14] (Samsung Electronics) R2 LMIInfo; C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [16056 2013-04-30] (LogMeIn, Inc.) S4 LMIRfsClientNP; No ImagePath R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-21] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation) S2 risdxc; C:\Windows\System32\DRIVERS\risdxc64.sys [101888 2011-05-25] (REDC) [File not signed] R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [31984 2013-03-04] (Synaptics Incorporated) R2 smihlp2; C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [13128 2011-05-30] (Authentec Inc.) R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1062520 2013-01-10] (Sunplus) R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.) S3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-08] (ThinkVantage Communications Utility) R3 usb3Hub; C:\Windows\System32\DRIVERS\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider) R3 XHCIPort; C:\Windows\System32\DRIVERS\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider) S1 mmjimzv2yxmwbdd; system32\drivers\mmjimzv2yxmwbdd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-05-21 15:47 - 2015-05-21 15:47 - 00000000 ____D () C:\FRST 2015-05-21 15:14 - 2015-05-21 15:14 - 00000811 _____ () C:\Users\jbremner\Desktop\JRT.txt 2015-05-21 15:12 - 2015-05-21 01:11 - 02720009 _____ (Thisisu) C:\Users\jbremner\Desktop\JRT_NEW.exe 2015-05-21 10:46 - 2015-05-21 10:46 - 02209792 _____ () C:\Users\jbremner\Downloads\adwcleaner_4.205.exe 2015-05-21 10:30 - 2015-05-21 10:30 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe 2015-05-21 10:15 - 2015-05-21 10:15 - 00000167 _____ () C:\Windows\pcfaxsetup.log 2015-05-21 09:39 - 2015-05-21 09:39 - 00000000 ____D () C:\Users\jbremner\Desktop\Old Firefox Data 2015-05-21 09:27 - 2015-05-21 09:27 - 00046606 _____ () C:\Windows\system32\.crusader 2015-05-20 16:16 - 2015-05-20 16:16 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2015-05-20 16:09 - 2015-05-20 16:17 - 00001904 _____ () C:\Users\Public\Desktop\HitmanPro.lnk 2015-05-20 16:09 - 2015-05-20 16:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro 2015-05-20 16:09 - 2015-05-20 16:09 - 00000000 ____D () C:\Program Files\HitmanPro 2015-05-20 16:08 - 2015-05-21 09:27 - 00000000 ____D () C:\ProgramData\HitmanPro 2015-05-20 15:57 - 2015-05-20 15:57 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-05-20 15:46 - 2015-05-20 15:46 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-IMG0001556-Windows-7-Professional-(64-bit).dat 2015-05-20 15:46 - 2015-05-20 15:46 - 00000000 ____D () C:\RegBackup 2015-05-20 15:36 - 2015-05-21 14:24 - 00000000 ____D () C:\AdwCleaner 2015-05-20 13:39 - 2015-05-20 13:39 - 00000000 ____D () C:\Users\jbremner\AppData\Local\Storm_Warnings,_LLC 2015-05-20 13:37 - 2015-05-20 13:37 - 00004320 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserM_1_7_22_478699874-4155726479-3780505679-3006UA__31313431363639352d344a414155342a2a236c6c5a 2015-05-20 13:25 - 2015-05-20 13:25 - 00000000 ____D () C:\Program Files (x86)\65389f70-5439-4eb5-8cbe-f5adb12c6561 2015-05-20 12:41 - 2015-05-20 12:41 - 00003624 _____ () C:\Windows\System32\Tasks\Norwood 2015-05-20 12:35 - 2015-05-20 12:35 - 00000024 _____ () C:\Users\jbremner\AppData\Roaming\appdataFr25.bin 2015-05-16 10:36 - 2015-05-16 10:36 - 00000000 ____D () C:\Users\jbremner\.cache 2015-05-14 22:46 - 2015-05-14 22:46 - 00000000 _____ () C:\Users\jbremner\AppData\Local\Temp.dat 2015-05-14 22:18 - 2015-05-14 22:18 - 00000942 _____ () C:\Windows\SysWOW64\${LOGFILE} 2015-05-14 21:47 - 2015-05-20 16:06 - 00000000 ____D () C:\Program Files (x86)\Panel View for Keep 2015-05-14 21:36 - 2015-05-21 15:08 - 00000336 _____ () C:\Windows\Tasks\IIXQMYFCO1.job 2015-05-14 21:36 - 2015-05-20 16:06 - 00000000 ____D () C:\ProgramData\06e78fe9f3fa4765b7830b8886163656 2015-05-14 21:36 - 2015-05-14 21:36 - 00003574 _____ () C:\Windows\System32\Tasks\YNZSM 2015-05-14 21:36 - 2015-05-14 21:36 - 00002858 _____ () C:\Windows\System32\Tasks\IIXQMYFCO1 2015-05-14 21:36 - 2015-05-14 21:36 - 00000000 ____D () C:\ProgramData\28341ff220e0446c9fff27c4493d622e 2015-05-14 21:32 - 2015-05-20 15:34 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 2015-05-14 20:03 - 2015-05-14 20:03 - 00286208 _____ () C:\Windows\Minidump\051415-9874-01.dmp 2015-05-14 19:59 - 2015-05-20 13:41 - 00000112 _____ () C:\ProgramData\JbiLAXbd1.dat 2015-05-14 19:57 - 2015-05-14 19:57 - 00000064 _____ () C:\Users\jbremner\AppData\Local\fbaf540cdd3b561c80e7c0f9601a0598 2015-05-14 19:44 - 2009-06-10 16:00 - 00000824 _____ () C:\Windows\system32\Drivers\etc\hp.bak 2015-05-14 19:42 - 2015-05-14 19:42 - 00000000 ____D () C:\ProgramData\COMODO 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 ____D () C:\bca5ab1c-8a92-4430-b8df-55a46e0ace81 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9DF2.tmp 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9DD3.tmp 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9D66.tmp 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9D47.tmp 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9D18.tmp 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9D08.tmp 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9CBA.tmp 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9CAB.tmp 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9C7C.tmp 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9C4D.tmp 2015-05-14 19:41 - 2015-05-14 19:41 - 00000000 _____ () C:\LIL9C3D.tmp 2015-05-13 21:09 - 2015-05-01 08:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-05-13 21:09 - 2015-05-01 08:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2015-05-13 07:22 - 2015-05-04 20:29 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-05-13 07:22 - 2015-05-04 20:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-05-13 07:22 - 2015-04-21 21:28 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-05-13 07:22 - 2015-04-21 20:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-05-13 07:22 - 2015-04-21 12:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-05-13 07:22 - 2015-04-21 12:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-05-13 07:22 - 2015-04-21 12:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-05-13 07:22 - 2015-04-21 11:51 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-05-13 07:22 - 2015-04-21 11:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-05-13 07:22 - 2015-04-21 11:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-05-13 07:22 - 2015-04-21 11:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-05-13 07:22 - 2015-04-21 11:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-05-13 07:22 - 2015-04-21 11:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-05-13 07:22 - 2015-04-21 11:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-05-13 07:22 - 2015-04-21 11:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-05-13 07:22 - 2015-04-21 11:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-05-13 07:22 - 2015-04-21 11:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-05-13 07:22 - 2015-04-21 11:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-05-13 07:22 - 2015-04-21 11:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-05-13 07:22 - 2015-04-21 11:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-05-13 07:22 - 2015-04-21 11:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-05-13 07:22 - 2015-04-21 11:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-05-13 07:22 - 2015-04-21 11:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-05-13 07:22 - 2015-04-21 11:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-05-13 07:22 - 2015-04-21 11:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-05-13 07:22 - 2015-04-21 11:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-05-13 07:22 - 2015-04-21 11:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-05-13 07:22 - 2015-04-21 11:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-05-13 07:22 - 2015-04-21 11:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-05-13 07:22 - 2015-04-21 11:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-05-13 07:22 - 2015-04-21 11:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-05-13 07:22 - 2015-04-21 11:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-05-13 07:22 - 2015-04-21 11:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-05-13 07:22 - 2015-04-21 11:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-05-13 07:22 - 2015-04-21 11:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-05-13 07:22 - 2015-04-21 11:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-05-13 07:22 - 2015-04-21 11:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-05-13 07:22 - 2015-04-21 11:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-05-13 07:22 - 2015-04-21 10:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-05-13 07:22 - 2015-04-21 10:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-05-13 07:22 - 2015-04-21 10:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-05-13 07:22 - 2015-04-21 10:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-05-13 07:22 - 2015-04-21 10:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-05-13 07:22 - 2015-04-21 10:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-05-13 07:22 - 2015-04-21 10:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-05-13 07:22 - 2015-04-21 10:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-05-13 07:22 - 2015-04-21 10:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-05-13 07:22 - 2015-04-21 10:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-05-13 07:22 - 2015-04-21 10:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-05-13 07:22 - 2015-04-21 10:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-05-13 07:22 - 2015-04-21 10:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-05-13 07:22 - 2015-04-21 10:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-05-13 07:22 - 2015-04-21 10:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-05-13 07:22 - 2015-04-21 10:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-05-13 07:22 - 2015-04-21 10:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-05-13 07:22 - 2015-04-21 10:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-05-13 07:22 - 2015-04-21 10:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-05-13 07:22 - 2015-04-21 10:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-05-13 07:22 - 2015-04-21 10:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-05-13 07:22 - 2015-04-21 10:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-05-13 07:22 - 2015-04-21 09:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-05-13 07:22 - 2015-04-21 09:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-05-13 07:22 - 2015-04-17 22:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2015-05-13 07:22 - 2015-04-17 21:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2015-05-13 07:21 - 2015-04-27 14:28 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-05-13 07:21 - 2015-04-27 14:28 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-05-13 07:21 - 2015-04-27 14:28 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-05-13 07:21 - 2015-04-27 14:26 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 01254400 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-05-13 07:21 - 2015-04-27 14:23 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-05-13 07:21 - 2015-04-27 14:22 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe 2015-05-13 07:21 - 2015-04-27 14:22 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-05-13 07:21 - 2015-04-27 14:22 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-05-13 07:21 - 2015-04-27 14:22 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-05-13 07:21 - 2015-04-27 14:22 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2015-05-13 07:21 - 2015-04-27 14:22 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe 2015-05-13 07:21 - 2015-04-27 14:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe 2015-05-13 07:21 - 2015-04-27 14:22 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-05-13 07:21 - 2015-04-27 14:22 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe 2015-05-13 07:21 - 2015-04-27 14:21 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-05-13 07:21 - 2015-04-27 14:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-05-13 07:21 - 2015-04-27 14:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 14:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-05-13 07:21 - 2015-04-27 14:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-05-13 07:21 - 2015-04-27 14:08 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-05-13 07:21 - 2015-04-27 14:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2015-05-13 07:21 - 2015-04-27 14:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-05-13 07:21 - 2015-04-27 14:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-05-13 07:21 - 2015-04-27 14:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-05-13 07:21 - 2015-04-27 14:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll 2015-05-13 07:21 - 2015-04-27 14:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-05-13 07:21 - 2015-04-27 14:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-05-13 07:21 - 2015-04-27 14:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-05-13 07:21 - 2015-04-27 14:05 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-05-13 07:21 - 2015-04-27 14:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2015-05-13 07:21 - 2015-04-27 14:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-05-13 07:21 - 2015-04-27 14:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe 2015-05-13 07:21 - 2015-04-27 14:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe 2015-05-13 07:21 - 2015-04-27 14:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe 2015-05-13 07:21 - 2015-04-27 14:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe 2015-05-13 07:21 - 2015-04-27 14:04 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-05-13 07:21 - 2015-04-27 14:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-05-13 07:21 - 2015-04-27 14:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-05-13 07:21 - 2015-04-27 14:03 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-05-13 07:21 - 2015-04-27 14:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-05-13 07:21 - 2015-04-27 14:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-05-13 07:21 - 2015-04-27 14:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe 2015-05-13 07:21 - 2015-04-27 14:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-05-13 07:21 - 2015-04-27 14:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-05-13 07:21 - 2015-04-27 14:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 13:06 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll 2015-05-13 07:21 - 2015-04-27 12:57 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-05-13 07:21 - 2015-04-27 12:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-05-13 07:21 - 2015-04-27 12:55 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 12:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 12:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-05-13 07:21 - 2015-04-27 12:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-05-13 07:21 - 2015-04-19 22:17 - 01647104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2015-05-13 07:21 - 2015-04-19 22:17 - 01179136 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2015-05-13 07:21 - 2015-04-19 21:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2015-05-13 07:21 - 2015-04-19 21:11 - 03204608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-05-13 07:21 - 2015-04-12 22:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe 2015-05-13 07:21 - 2015-04-07 22:29 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2015-05-13 07:21 - 2015-04-07 22:29 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll 2015-05-13 07:21 - 2015-04-07 22:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2015-05-13 07:21 - 2015-03-03 23:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-05-13 07:21 - 2015-03-03 23:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll 2015-05-13 07:21 - 2015-03-03 23:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe 2015-05-13 07:21 - 2015-03-03 23:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll 2015-05-13 07:21 - 2015-03-03 23:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll 2015-05-13 07:21 - 2015-03-03 23:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll 2015-05-13 07:21 - 2015-03-03 23:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe 2015-05-13 07:21 - 2015-02-18 02:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2015-05-13 07:21 - 2015-02-18 02:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2015-05-13 07:21 - 2015-01-28 22:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll 2015-05-13 07:21 - 2015-01-28 22:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll 2015-05-12 15:07 - 2015-05-12 15:07 - 00003292 _____ () C:\Windows\System32\Tasks\{EDEE40D3-CF55-48AE-A662-1FF18EFE315D} ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-05-21 15:15 - 2014-04-09 08:38 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-05-21 15:12 - 2009-07-14 00:13 - 00786578 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-05-21 15:12 - 2009-07-13 23:45 - 00034432 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-05-21 15:12 - 2009-07-13 23:45 - 00034432 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-05-21 15:08 - 2014-10-21 05:59 - 00000000 ___RD () C:\Users\jbremner\iCloudDrive 2015-05-21 15:08 - 2014-02-27 13:43 - 00000580 _____ () C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-2037836387-1429457356-845570551-1180.job 2015-05-21 15:08 - 2013-07-05 23:17 - 01965741 _____ () C:\Windows\WindowsUpdate.log 2015-05-21 15:07 - 2014-01-24 14:44 - 00001015 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Client.lnk 2015-05-21 15:07 - 2014-01-24 14:44 - 00000999 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Control Panel.lnk 2015-05-21 15:07 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-05-21 15:07 - 2009-07-13 23:51 - 00077277 _____ () C:\Windows\setupact.log 2015-05-21 14:53 - 2014-02-18 10:16 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-05-21 10:39 - 2013-07-29 14:32 - 00000000 ____D () C:\Program Files (x86)\Google 2015-05-21 10:25 - 2013-10-30 14:40 - 00000000 ____D () C:\Program Files (x86)\Xerox 2015-05-21 10:12 - 2013-10-06 14:29 - 00000000 ____D () C:\Program Files\Google 2015-05-21 10:12 - 2010-11-20 22:47 - 00906488 _____ () C:\Windows\PFRO.log 2015-05-21 10:03 - 2014-02-17 15:10 - 00000000 ____D () C:\Users\jbremner\AppData\Local\Google 2015-05-21 09:28 - 2009-07-13 23:45 - 05098176 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-05-21 09:15 - 2014-05-15 06:00 - 00000000 ____D () C:\Users\jbremner\AppData\Local\CrashDumps 2015-05-21 00:24 - 2013-07-29 11:34 - 00000000 ____D () C:\ProgramData\LogMeIn 2015-05-20 16:26 - 2014-10-21 06:00 - 00000000 ____D () C:\Users\jbremner\AppData\Local\566069BF-DE81-4744-831F-A1F7EC1547F1.aplzod 2015-05-20 16:17 - 2014-02-17 15:04 - 00111520 _____ () C:\Users\jbremner\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-20 16:16 - 2013-07-29 14:38 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-05-20 16:16 - 2009-07-13 22:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2015-05-20 15:57 - 2014-04-09 08:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-05-20 15:57 - 2014-04-09 08:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-05-20 15:40 - 2013-07-29 14:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-05-20 15:39 - 2014-02-17 15:04 - 00000000 ____D () C:\Users\jbremner 2015-05-20 15:38 - 2009-07-13 22:20 - 00000000 ____D () C:\Program Files\Common Files\System 2015-05-20 13:25 - 2013-07-05 23:16 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-05-20 12:09 - 2015-01-26 12:07 - 00000000 ____D () C:\Users\jbremner\Desktop\StressCount.com 2015-05-20 11:00 - 2015-04-05 03:00 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-05-20 11:00 - 2015-04-05 03:00 - 00000000 ___SD () C:\Windows\system32\GWX 2015-05-20 10:52 - 2014-02-17 15:04 - 00001584 _____ () C:\Users\jbremner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-05-20 10:52 - 2013-07-29 14:32 - 00001286 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-05-15 10:09 - 2015-03-27 15:19 - 00000000 ____D () C:\Users\jbremner\Desktop\Craigs List 2015-05-15 09:14 - 2014-11-07 20:58 - 00000000 ____D () C:\Users\jbremner\Desktop\Resume 2015-05-15 06:54 - 2009-07-14 00:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2015-05-14 22:22 - 2009-07-13 22:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2015-05-14 22:22 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2015-05-14 22:11 - 2009-07-13 21:34 - 00000580 _____ () C:\Windows\win.ini 2015-05-14 21:55 - 2014-03-25 14:27 - 00000000 ____D () C:\ProgramData\Package Cache 2015-05-14 21:32 - 2014-06-28 18:33 - 00000000 ____D () C:\Users\jbremner\AppData\Local\Adobe 2015-05-14 20:03 - 2014-01-21 11:43 - 663071910 _____ () C:\Windows\MEMORY.DMP 2015-05-14 20:03 - 2014-01-21 11:43 - 00000000 ____D () C:\Windows\Minidump 2015-05-14 19:58 - 2014-12-23 12:46 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-05-14 19:57 - 2014-03-25 15:02 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2015-05-14 19:42 - 2013-07-05 23:16 - 00000000 ____D () C:\ProgramData\Adobe 2015-05-14 13:16 - 2014-04-13 19:48 - 00000000 ____D () C:\Users\jbremner\Desktop\BREMNER 2015-05-14 07:42 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache 2015-05-14 06:08 - 2013-07-29 14:32 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2015-05-14 06:08 - 2013-07-29 14:32 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2015-05-14 06:08 - 2013-02-11 13:28 - 00000000 ____D () C:\Program Files\Windows Journal 2015-05-14 06:08 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers 2015-05-13 21:19 - 2013-07-29 14:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2015-05-13 21:17 - 2013-07-29 15:06 - 00000000 ____D () C:\Windows\system32\MRT 2015-05-13 21:12 - 2013-07-29 14:49 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-05-13 21:08 - 2013-07-29 14:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-05-12 15:21 - 2014-04-13 19:53 - 00000000 ____D () C:\Users\jbremner\Desktop\Photo and Videos2 2015-05-12 15:07 - 2013-11-21 05:57 - 00000000 ____D () C:\ProgramData\Oracle 2015-05-12 14:46 - 2014-02-18 10:06 - 00000000 ____D () C:\Program Files (x86)\Java 2015-05-11 14:04 - 2014-04-13 19:43 - 00000000 ____D () C:\Users\jbremner\Desktop\CLG 2015-05-11 09:20 - 2014-04-13 19:52 - 00000000 ____D () C:\Users\jbremner\Desktop\Grand Prix Tennis 2015-05-11 08:10 - 2014-11-07 18:06 - 00000000 ____D () C:\Users\jbremner\Desktop\Winners Cup 2015-04-24 11:21 - 2015-04-15 11:08 - 00000000 ____D () C:\Users\jbremner\AppData\Roaming\Skype 2015-04-23 06:43 - 2014-02-20 09:48 - 00000000 ____D () C:\Users\jbremner\AppData\Local\CutePDF Writer 2015-04-23 05:54 - 2014-02-18 10:16 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-04-23 05:54 - 2014-02-18 10:16 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-04-23 05:54 - 2014-02-18 10:16 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-04-22 09:45 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF ==================== Files in the root of some directories ======= 2015-05-20 12:35 - 2015-05-20 12:35 - 0000024 _____ () C:\Users\jbremner\AppData\Roaming\appdataFr25.bin 2014-02-18 06:49 - 2014-02-18 06:49 - 0033193 _____ () C:\Users\jbremner\AppData\Roaming\UserTile.png 2015-05-14 19:57 - 2015-05-14 19:57 - 0000064 _____ () C:\Users\jbremner\AppData\Local\fbaf540cdd3b561c80e7c0f9601a0598 2015-05-14 22:46 - 2015-05-14 22:46 - 0000000 _____ () C:\Users\jbremner\AppData\Local\Temp.dat 2013-07-05 23:13 - 2013-07-05 23:13 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2015-05-14 19:59 - 2015-05-20 13:41 - 0000112 _____ () C:\ProgramData\JbiLAXbd1.dat Files to move or delete: ==================== C:\ProgramData\JbiLAXbd1.dat Some files in TEMP: ==================== C:\Users\jbremner\AppData\Local\Temp\APNSetup.exe C:\Users\jbremner\AppData\Local\Temp\BSvcProcessor.exe C:\Users\jbremner\AppData\Local\Temp\C4810D25-29C9-B176-8369-77630CBF9544.dll C:\Users\jbremner\AppData\Local\Temp\cw.exe C:\Users\jbremner\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpg1ud6r.dll C:\Users\jbremner\AppData\Local\Temp\G2MInstallerExtractor.exe C:\Users\jbremner\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\jbremner\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe C:\Users\jbremner\AppData\Local\Temp\MSETUP4.EXE C:\Users\jbremner\AppData\Local\Temp\Quarantine.exe C:\Users\jbremner\AppData\Local\Temp\sqlite3.dll C:\Users\jbremner\AppData\Local\Temp\sqlite3.exe C:\Users\jbremner\AppData\Local\Temp\supoptsetup.exe C:\Users\user\AppData\Local\Temp\G2MInstallerExtractor.exe C:\Users\user\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\user\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\user\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-14 07:35 ==================== End of log ============================ Addition.txt Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-05-2015 Ran by jbremner at 2015-05-21 15:47:48 Running from D:\ Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3125894905-1441278399-474381537-500 - Administrator - Disabled) Guest (S-1-5-21-3125894905-1441278399-474381537-501 - Limited - Disabled) user (S-1-5-21-3125894905-1441278399-474381537-1000 - Administrator - Enabled) => C:\Users\user ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated) Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - ) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.) Canon MG3200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3200_series) (Version: - Canon Inc.) Canon MG3200 series On-screen Manual (HKLM-x32\...\Canon MG3200 series On-screen Manual) (Version: 7.5.0 - Canon Inc.) Canon MX410 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX410_series) (Version: - Canon Inc.) Carbonite (HKLM-x32\...\Carbonite Backup) (Version: 5.5.5 build 4151 (Jun-27-2014) - Carbonite) Citrix Online Launcher (HKLM-x32\...\{AC7E7905-8C59-4806-A96D-30936A2B1FC5}) (Version: 1.0.168 - Citrix) Create Recovery Media (HKLM-x32\...\{50DC5136-21E8-48BC-97E5-1AD055F6B0B6}) (Version: 1.20.0.00 - Lenovo Group Limited) CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version: 3.0 - CutePDF.com) Disable AMT Profile Synchronization Pop-up for Windows XP/Vista/7/8 (HKLM\...\DisableAMTPopup) (Version: 1.00 - ) globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION GoToMeeting 7.1.8.2553 (HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\GoToMeeting) (Version: 7.1.8.2553 - CitrixOnline) HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.241 - SurfRight B.V.) iCloud (HKLM\...\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.) Integrated Camera (HKLM-x32\...\Sunplus SPUVCb) (Version: 3.4.7.19 - SunplusIT) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.20.1337 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2857 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{A10B1524-63B5-40F2-B272-D841CF671C16}) (Version: 2.2.0.0266 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.6.245 - Intel Corporation) Intel(R) WiDi (HKLM\...\{6097158B-0184-4140-BEC3-7885794D2571}) (Version: 3.5.40.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel® PROSet/Wireless WiFi Software (HKLM\...\{ECE5B218-A086-4E18-A362-D11181681457}) (Version: 15.03.1000.1637 - Intel Corporation) Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.) Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation) join.me (HKU\S-1-5-21-2037836387-1429457356-845570551-1180\...\JoinMe) (Version: 1.14.0.141 - LogMeIn, Inc.) Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 2.01 - ) Lenovo Patch Utility (HKLM-x32\...\{6E6E7725-C7BC-4C39-8B3F-14B67331A120}) (Version: 1.3.0.9 - Lenovo Group Limited) Lenovo Patch Utility 64 bit (HKLM\...\{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}) (Version: 1.3.1.1 - Lenovo Group Limited) Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.00.02 - ) LogMeIn (HKLM-x32\...\{CB7AF84A-1B7F-4C6B-8A58-EB7CDE48C23A}) (Version: 4.1.3268 - LogMeIn, Inc.) Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 365 ProPlus (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Firefox 22.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 22.0 (x86 en-US)) (Version: 22.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 22.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Network Scan (HKLM-x32\...\{9C5725B7-2219-410C-A364-90767F71F00C}) (Version: - ) On Screen Display (HKLM\...\OnScreenDisplay) (Version: 7.11.20 - ) Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Power Manager (HKLM-x32\...\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}) (Version: 6.45 - ) QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6818 - Realtek Semiconductor Corp.) Registry Patch to Enable Maximum Power Saving on WiFi Adapters for Windows 7 (HKLM\...\EnablePS) (Version: 1.00 - ) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation) Skype™ 7.3 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.) ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.3.15.2 - ) ThinkVantage Fingerprint Software (HKLM\...\{F58DA859-016E-492D-A588-317D9BB28002}) (Version: 5.9.9.7282 - Authentec Inc.) Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\...\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{40930C8E-A677-414C-A72F-DFDEB10738FB}) (Version: - Microsoft) Windows Driver Package - Intel (e1cexpress) Net (01/11/2012 11.15.16.0) (HKLM\...\EC2A0F2B229770EC589265FCF2B4839A0C221993) (Version: 01/11/2012 11.15.16.0 - Intel) Windows Driver Package - Intel (iaStor) hdc (05/30/2012 11.2.0.1006) (HKLM\...\D92B2A049725011212996291E9BA2774FA43A3B0) (Version: 05/30/2012 11.2.0.1006 - Intel) Windows Driver Package - Lenovo 1.66.00.22 (11/30/2012 1.66.00.22) (HKLM\...\16E722986C4293F5D6BF43595DFFD631398D5F21) (Version: 11/30/2012 1.66.00.22 - Lenovo) Windows Driver Package - Synaptics (SmbDrv) System (03/04/2013 16.3.15.2) (HKLM\...\850C78BE3B5F0293BD5597737A6E95F45C18E8E1) (Version: 03/04/2013 16.3.15.2 - Synaptics) Windows Driver Package - Synaptics (SynTP) Mouse (03/04/2013 16.3.15.2) (HKLM\...\A3D5941AC939C813D8A35AC7207BB60AD235AB5B) (Version: 03/04/2013 16.3.15.2 - Synaptics) Xerox 7600 Driver (HKLM-x32\...\{4F7EE569-CF67-4054-82D2-8FF309489682}) (Version: 4.6.10306 - Visioneer Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2037836387-1429457356-845570551-1180_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\jbremner\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File CustomCLSID: HKU\S-1-5-21-2037836387-1429457356-845570551-1180_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\jbremner\AppData\Local\Citrix\GoToMeeting\1350\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.) ==================== Restore Points ========================= 14-05-2015 22:44:25 Removed Microsoft Silverlight 14-05-2015 22:44:39 Removed Microsoft Silverlight 20-05-2015 10:57:31 Windows Update 20-05-2015 11:00:38 Windows Update 20-05-2015 16:10:43 Checkpoint by HitmanPro 20-05-2015 16:15:31 Configured Microsoft Office 365 ProPlus 20-05-2015 16:15:36 PROPLUSR 20-05-2015 16:19:21 Checkpoint by HitmanPro 21-05-2015 09:20:28 Checkpoint by HitmanPro 21-05-2015 09:27:34 Checkpoint by HitmanPro 21-05-2015 10:02:54 Removed Google Chrome 21-05-2015 10:15:22 Removed Xerox PC Fax 21-05-2015 10:30:24 Checkpoint by HitmanPro ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {00C7830E-4ACF-42EF-9029-0F04F36CCEB4} - \avaavaevy No Task File <==== ATTENTION Task: {16C03C5F-1E81-4DC8-BCBD-69E3DCB1D48D} - System32\Tasks\YNZSM => C:\ProgramData\06e78fe9f3fa4765b7830b8886163656\06e78fe9f3fa4765b7830b8886163656.exe Task: {261B5FB7-1F5A-4F7A-BD1B-AAF57A70E12F} - System32\Tasks\IIXQMYFCO1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION Task: {263BB5B4-1F78-42DB-A341-41452840484C} - System32\Tasks\PMTask => C:\Program Files (x86)\ThinkPad\Utilities\PWMIDTSV.EXE [2013-01-09] (Lenovo Group Limited) Task: {2BFA7B1C-9A40-4489-8A3C-F7565E419CB6} - \avabvbxvh No Task File <==== ATTENTION Task: {2F1A3417-4A34-4BAC-A2C5-8BF858590602} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {39A262AF-D8BB-4994-842E-68AEA7FB00AE} - System32\Tasks\{D5FA6611-36C5-4C47-B77C-4A74B32D5862} => Iexplore.exe [URL]http://ui.skype.com/ui/0/6.6.0.106/en/abandoninstall?page=tsMain[/URL] Task: {51976E3D-564A-4E1B-AF14-FD89F600D92C} - System32\Tasks\Microsoft Office 15 Sync Maintenance for ITMAXGROUP-jbremner IMG0001556.itmaxgroup.local => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2015-04-14] (Microsoft Corporation) Task: {532247B7-AF01-4149-A4F1-BC855D192C85} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-23] (Adobe Systems Incorporated) Task: {60FE4DBD-F2A7-4B82-9028-9FA47781BCA1} - System32\Tasks\DiskUpdate => C:\SWTOOLS\OSFIXES\DISKUPDT\DiskUpdate.exe [2009-02-09] () Task: {67A67FDB-055D-4FEF-995A-7D77CBA52447} - System32\Tasks\{EDEE40D3-CF55-48AE-A662-1FF18EFE315D} => pcalua.exe -a "C:\Users\jbremner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C9VLFZGV\JavaSetup8u45.exe" -d C:\Users\jbremner\Desktop Task: {7259A915-19A1-4976-88DB-E05C3E0A7331} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation) Task: {843F0FE6-CF5A-4B67-A622-4BA48D1FBF26} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-03-07] (Adobe Systems Incorporated) Task: {8B52CC4D-8554-4EFF-BD5C-91BD0BE6F1E8} - System32\Tasks\G2MUpdateTask-S-1-5-21-2037836387-1429457356-845570551-1180 => C:\Users\jbremner\AppData\Local\Citrix\GoToMeeting\2553\g2mupdate.exe [2015-04-13] (Citrix Online, a division of Citrix Systems, Inc.) Task: {98CD9C28-BA2E-4028-99DF-373042012A7B} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2014-12-01] (Apple Inc.) Task: {9F86584F-1522-4C11-8DD7-75DF317FD505} - System32\Tasks\Norwood => C:\Program Files\shopperz\Cote.bat Task: {ACB1C182-EE82-433D-8839-EE55F4EEA83A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {ADF05F1A-BB9F-4C72-AB2F-0B503432D09D} - System32\Tasks\Intel\Intel Service Manager => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe Task: {AE5C3F82-DAAC-4EF4-868C-0138779DCF95} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {CBE89A5D-126F-47F6-A833-F8C742D67391} - \ProPCCleaner_Start No Task File <==== ATTENTION Task: {D53D9D8B-9FD8-46EB-95E5-67BC8B4C5DCB} - \ProPCCleaner_Popup No Task File <==== ATTENTION Task: {EE8AF48E-2ED8-4A06-874A-9DB8AC8EFE4C} - System32\Tasks\GoogleUpdateTaskUserM_1_7_22_478699874-4155726479-3780505679-3006UA__31313431363639352d344a414155342a2a236c6c5a => Wscript.exe //B "C:\ProgramData\PastaLeadsAgent\startprocess.js" pastaleadss.exe /invoke /f:check_services /l:0 Task: {EE921805-FF18-4EA2-8C0C-93F9CD5E1433} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {F70B3427-51FE-4218-8C44-588CAC32B5D9} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-07] (Microsoft Corporation) Task: {FDF8BAFA-DC68-4BD4-81D8-E262130743F7} - System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} => C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-2037836387-1429457356-845570551-1180.job => C:\Users\jbremner\AppData\Local\Citrix\GoToMeeting\2553\g2mupdate.exe Task: C:\Windows\Tasks\IIXQMYFCO1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION ==================== Loaded Modules (Whitelisted) ============== 2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-01-20 23:35 - 2015-01-20 23:35 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-07-05 23:15 - 2013-01-09 17:45 - 00094208 ____N () C:\Program Files (x86)\ThinkPad\Utilities\US\PWMRT64V.DLL 2013-07-29 14:33 - 2012-10-04 19:49 - 00087152 _____ () C:\Windows\System32\cpwmon64.dll 2013-07-29 14:36 - 2008-09-08 18:57 - 00022016 _____ () C:\Windows\System32\sxs2ml6.dll 2015-01-20 23:35 - 2015-01-20 23:35 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2037836387-1429457356-845570551-1180\Control Panel\Desktop\\Wallpaper -> C:\Users\jbremner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.168.5 ==================== MSCONFIG/TASK MANAGER Error getting == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{5BC08E3C-63A4-41CA-95ED-9FC11191EDEE}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{A747BE03-9A8A-4DF4-887C-5683657E0DA7}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe FirewallRules: [{8622BC69-4DDE-4302-9B9D-84C6039586D3}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe FirewallRules: [{7A60F9C4-F561-4A1A-95C6-3CB139B5FAA7}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe FirewallRules: [{96D89F78-4BC4-4EB0-BA2C-F73722874C5F}] => (Allow) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe FirewallRules: [{907F9C35-8858-4B6D-9278-8C4AD61972E7}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe FirewallRules: [{F4D32FD2-16AA-4FB6-A864-996AEAEB2810}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe FirewallRules: [{0772165F-F184-4DC5-B9C9-C17A6FF67BAB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{4C9DD39A-74BC-48E1-B64D-5078A4F228AD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{DBEC3747-E0D0-4C8B-B1C5-6E4A5D0EF9C1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{0A137A7F-5AE9-4482-A003-F10E9F500083}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{BC0CB494-8421-4DA7-8403-0AF9EAEAC92F}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{A8A945DD-5FC9-47BA-9389-EC47A7816CB1}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{761794EB-834E-4DFB-90C3-676BF766AD40}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{822316CF-1A84-42C6-A893-57E15689875B}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{08D4784E-A83E-4DBA-9C80-512DCBC880A8}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{7FBBA375-2E7D-4E37-A477-3C44B6565F79}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{28B18022-4738-4281-9F07-04BC851AD7E0}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{19D967A0-90D2-479A-976C-E75253469C5E}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{9419526F-CDEC-4567-8B10-0FA2BC1B3E85}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{90D58FDD-94C2-4959-94C0-1552BFF7ED0C}] => (Allow) C:\Windows\twain_32\Xerox\WC3220\Sscan2io.exe FirewallRules: [{7AEEAB18-AD97-4C8C-B39B-846F88F3E5D0}] => (Allow) C:\Windows\twain_32\Xerox\WC3220\Sscan2io.exe FirewallRules: [TCP Query User{E6398012-0E7D-4A64-9BA2-CB25AF0254EC}C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe] => (Allow) C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe FirewallRules: [UDP Query User{E9377D72-FF17-424F-9B8A-C49B61970B9B}C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe] => (Allow) C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe FirewallRules: [TCP Query User{BF577325-4BDF-4817-8E58-3215D97D70A2}C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe] => (Block) C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe FirewallRules: [UDP Query User{DA06EFF4-EB85-431A-B03E-89501CD57C24}C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe] => (Block) C:\program files (x86)\xerox\networkscan\nscsysui_xerox.exe FirewallRules: [{7045EE2E-AD3B-4137-AAF4-36B12899A77F}] => (Allow) C:\Users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{CD01EFF0-79C7-4507-AC7C-C9C51A0A9D94}] => (Allow) C:\Users\user\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{6C77C019-1434-4DF7-8626-8B0F53CBD521}C:\users\jbremner\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\jbremner\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{B3098D33-A459-4BBB-ADFC-C2C624B53F50}C:\users\jbremner\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\jbremner\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{A28759A7-A1F5-4674-9536-C2DA106829DE}] => (Allow) C:\Users\jbremner\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{9BFC6D01-A12B-43A7-AA07-955F9479C952}] => (Allow) C:\Users\jbremner\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{54AC4155-C674-4FA4-984A-3005DE527F7C}] => (Allow) C:\Program Files\iTunes\iTunes.exe ==================== Faulty Device Manager Devices ============= Name: mmjimzv2yxmwbdd Description: mmjimzv2yxmwbdd Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: mmjimzv2yxmwbdd Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Teredo Tunneling Pseudo-Interface Description: Microsoft Teredo Tunneling Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (05/21/2015 03:07:54 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/21/2015 02:43:05 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/21/2015 02:24:50 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000200,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,00000000019BEE60.72). hr = 0x80070005, Access is denied. . Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000006cc,(null),0,REG_BINARY,0000000001F2E0B0.72). hr = 0x80070005, Access is denied. . Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Writer Name: WMI Writer Writer Instance ID: {4b746811-d3ee-47f6-a94a-bbcb1cb21fae} Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000c8c,(null),0,REG_BINARY,0000000005EBE100.72). hr = 0x80070005, Access is denied. . Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2} Writer Name: MSSearch Service Writer Writer Instance ID: {2bed8e4b-10b7-4d6a-9bf9-36b36ac5d772} Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001b4,SYSTEM\CurrentControlSet\Services\VSS\Diag\Registry Writer,0,REG_BINARY,00000000028EE8C0.72). hr = 0x80070005, Access is denied. . Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {afbab4a2-367d-4d15-a586-71dbb18f8485} Writer Name: Registry Writer Writer Instance ID: {35a93998-fed9-4f63-93ab-313faf85bce1} Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001c0,SYSTEM\CurrentControlSet\Services\VSS\Diag\COM+ REGDB Writer,0,REG_BINARY,0000000002BAF2A0.72). hr = 0x80070005, Access is denied. . Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {542da469-d3e1-473c-9f4f-7847f01fc64f} Writer Name: COM+ REGDB Writer Writer Instance ID: {61a6dcae-ec28-4782-9030-37e277730327} Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000002e8,(null),0,REG_BINARY,00000000029AE0B0.72). hr = 0x80070005, Access is denied. . Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {f8bb262e-2489-458a-ac59-398fb25c4dd4} Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\Shadow Copy Optimization Writer,0,REG_BINARY,0000000002ADEA40.72). hr = 0x80070005, Access is denied. . Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {30634271-3245-47d0-89c8-e79bb1f8d106} System errors: ============= Error: (05/21/2015 03:14:06 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the CarboniteService service, but this action failed with the following error: %%1056 Error: (05/21/2015 03:13:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Intel(R) Management and Security Application User Notification Service service terminated unexpectedly. It has done this 1 time(s). Error: (05/21/2015 03:13:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The iPod Service service terminated unexpectedly. It has done this 1 time(s). Error: (05/21/2015 03:13:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Bluetooth Media Service service terminated unexpectedly. It has done this 1 time(s). Error: (05/21/2015 03:13:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Bluetooth OBEX Service service terminated unexpectedly. It has done this 1 time(s). Error: (05/21/2015 03:13:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Modules Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. Error: (05/21/2015 03:13:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Lenovo Hotkey Client Loader service terminated unexpectedly. It has done this 1 time(s). Error: (05/21/2015 03:13:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Lenovo Microphone Mute service terminated unexpectedly. It has done this 1 time(s). Error: (05/21/2015 03:13:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Intel(R) PROSet/Wireless Zero Configuration Service service terminated unexpectedly. It has done this 1 time(s). Error: (05/21/2015 03:13:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The On Screen Display service terminated unexpectedly. It has done this 1 time(s). Microsoft Office: ========================= Error: (05/21/2015 03:07:54 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/21/2015 02:43:05 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/21/2015 02:24:50 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x00000200,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,00000000019BEE60.72)0x80070005, Access is denied. Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x000006cc,(null),0,REG_BINARY,0000000001F2E0B0.72)0x80070005, Access is denied. Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Writer Name: WMI Writer Writer Instance ID: {4b746811-d3ee-47f6-a94a-bbcb1cb21fae} Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x00000c8c,(null),0,REG_BINARY,0000000005EBE100.72)0x80070005, Access is denied. Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2} Writer Name: MSSearch Service Writer Writer Instance ID: {2bed8e4b-10b7-4d6a-9bf9-36b36ac5d772} Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x000001b4,SYSTEM\CurrentControlSet\Services\VSS\Diag\Registry Writer,0,REG_BINARY,00000000028EE8C0.72)0x80070005, Access is denied. Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {afbab4a2-367d-4d15-a586-71dbb18f8485} Writer Name: Registry Writer Writer Instance ID: {35a93998-fed9-4f63-93ab-313faf85bce1} Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x000001c0,SYSTEM\CurrentControlSet\Services\VSS\Diag\COM+ REGDB Writer,0,REG_BINARY,0000000002BAF2A0.72)0x80070005, Access is denied. Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {542da469-d3e1-473c-9f4f-7847f01fc64f} Writer Name: COM+ REGDB Writer Writer Instance ID: {61a6dcae-ec28-4782-9030-37e277730327} Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x000002e8,(null),0,REG_BINARY,00000000029AE0B0.72)0x80070005, Access is denied. Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {f8bb262e-2489-458a-ac59-398fb25c4dd4} Error: (05/21/2015 10:30:32 AM) (Source: VSS) (EventID: 8193) (User: ) Description: RegSetValueExW(0x000001f0,SYSTEM\CurrentControlSet\Services\VSS\Diag\Shadow Copy Optimization Writer,0,REG_BINARY,0000000002ADEA40.72)0x80070005, Access is denied. Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {30634271-3245-47d0-89c8-e79bb1f8d106} CodeIntegrity Errors: =================================== Date: 2015-05-21 15:07:53.048 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 15:07:52.998 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 14:43:04.055 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 14:43:04.005 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 14:24:49.425 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 14:24:49.365 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 10:53:32.602 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 10:53:32.555 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 10:12:39.604 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-05-21 10:12:39.554 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\risdxc64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3437U CPU @ 1.90GHz Percentage of memory in use: 45% Total physical RAM: 3793.41 MB Available physical RAM: 2079.82 MB Total Pagefile: 7585.04 MB Available Pagefile: 5726 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (Windows7_OS) (Fixed) (Total:145.54 GB) (Free:14.38 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: () (Removable) (Total:7.19 GB) (Free:7.15 GB) FAT32 Drive q: (Lenovo_Recovery) (Fixed) (Total:13.67 GB) (Free:3.63 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 167.7 GB) (Disk ID: 640D7EA8) Partition 1: (Active) - (Size=1.5 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=145.5 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=13.7 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=7 GB) - (Type=84) ======================================================== Disk: 1 (Size: 7.2 GB) (Disk ID: 54CC1D44) Partition 1: (Not Active) - (Size=7.2 GB) - (Type=0B) ==================== End of log ============================ There was no FIX list. I will provide logs from the other scan tools if needed. They are all partial because the tools have been run repeatedly with fixing done until there is nothing to fix. [/QUOTE]
Insert quotes…
Verification
Post reply
Top