Unwanted Search screen

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #16
    Sorry for the delay… Let’s do this…

    install (use the direct download) the Tweaking.com - Windows all in one repair tool. Then boot Windows into Safe Mode, (Make Certain To Run This Program As Administrator) then run through the Prescan on step 2 tab. Then skip to step 5 and create a system restore point. Then go to the repair tab…

    Notice create a registry backup is ticked by default, so no need to do so in step 5…[ATTACH]688[/ATTACH]

    Now run the program, with the boxes ticked in the picture below.

    Click Image Below For Better Resolution.

    [ATTACH]689[/ATTACH]

    May want to save picture or write down what boxes need ticked, since you will run this in Safe Mode.

    Important: Make certain to reboot twice after running this tool!!

    Comment

    • Kiredoryor
      PCHF Member
      • Oct 2016
      • 67

      #17
      Away for the weekend!
      I’m having problems following the instructions to the letter! Did a Direct Download from Tweaking.com Then restarted in Safe Mode. But then I had the same problems as before as I can’t run it from the Download folder.

      I click “Run as Administrator” but nothing happens.
      I’ve just checked it in Standard Mode and the Setup window has opened.

      Checking with you first to see if should run this but not in Safe Mode

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7041

        #18
        Alright, lets sort out a few more things…

        Defrag your machine with ToolWhiz Defrag. Also, give it a good cleaning with Privazer...

        HijackThis.

        1- Please click HERE to download HijackThis.
        2- Run the program.
        3- Click on the Main Menu button if not already there.
        4- Select Do a system scan and save a logfile.5- Copy & Paste Log in your next reply.

        Autoruns Scan


        [ul]
        [li]Download Autoruns and Autorunsc[/li][li]Unzip it to your desktop and then double click autoruns.exe[/li][li]After the scan is finished then click on File>>>>>>>>>>>Save[/li][li]The default name will be autoruns.arn[/li][li]Make sure to save it as Autoruns.txt under the file type option.[/li][li]In other words make sure it is a .txt file instead of .arn [/li][li]Attach the text in your next reply.[/li][/ul]


        Security Check Scan.


        [ul]
        [li]Download Security Check to your desktop.[/li][li]Right click it run as administrator.[/li][li]When the program completes, the tool will automatically open a log file.[/li][li]Please post that log here in your next post.[/li][/ul]

        Comment

        • Kiredoryor
          PCHF Member
          • Oct 2016
          • 67

          #19
          I posted a reply and it’s all vanished!!
          I think the Autoruns log is too big (4.47MB) as it refuses to attach and I think my attempt to copy and paste caused the whole operation to crash!
          I’ll do it in parts
          Ran the ToolWhiz Defrag and cleaned with Privazer
          HighJack & Security Check Logs attached.

          Logfile of Trend Micro HijackThis v2.0.4
          Scan saved at 18:18:35, on 05/11/2016
          Platform: Windows Vista SP2 (WinNT 6.00.1906)
          MSIE: Internet Explorer v9.00 (9.00.8112.16830)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Dell\DellDock\DellDock.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Windows\System32\WLTRAY.EXE
          C:\Program Files\Ruiware\WinPrivacy\WinPrivacyTrayApp.exe
          C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
          C:\Program Files\Dropbox\Client\Dropbox.exe
          C:\Program Files\Ruiware\WinPatrol\WinPatrol.exe
          C:\Windows\system32\wuauclt.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Users\Chinwe\Downloads\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Search - Microsoft Bing
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/USCON/2
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/2
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Search - Microsoft Bing
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Search - Microsoft Bing
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
          O4 - HKLM..\Run: [WinPrivacy] C:\Program Files\Ruiware\WinPrivacy\WinPrivacyTrayApp.exe
          O4 - HKLM..\Run: [QHSafeTray] “C:\Program Files\360\Total Security\safemon\QHSafeTray.exe” /start
          O4 - HKLM..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
          O4 - HKLM..\Run: [Dropbox] “C:\Program Files\Dropbox\Client\Dropbox.exe” /systemstartup
          O4 - HKLM..\Run: [Adobe ARM] “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
          O4 - HKCU..\Run: [WinPatrol] C:\Program Files\Ruiware\WinPatrol\winpatrol.exe
          O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User ‘Default user’)
          O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra ‘Tools’ menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra ‘Tools’ menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
          O10 - Broken Internet access because of LSP provider ‘c:\windows\system32\vsocklib.dll’ missing
          O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
          O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
          O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
          O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
          O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpda teService.exe
          O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
          O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files\Dropbox\Update\DropboxUpdate.exe
          O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files\Dropbox\Update\DropboxUpdate.exe
          O23 - Service: DbxSvc - Dropbox, Inc. - C:\Windows\system32\DbxSvc.exe
          O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
          O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
          O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
          O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
          O23 - Service: 360 Total Security (QHActiveDefense) - QIHU 360 SOFTWARE CO. LIMITED - C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe
          O23 - Service: Rapport Management Service (RapportMgmtService) - IBM Corp. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
          O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
          O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
          O23 - Service: WinPrivacySvc - WinPatrol - C:\Program Files\Ruiware\WinPrivacy\WinPrivacySvc.exe
          O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
          O23 - Service: Wondershare Application Framework Service (WsAppService) - Wondershare - C:\Program Files\Wondershare\WAF\2.1.5.6\WsAppService.exe


          End of file - 6717 bytes

          SecurityCheck by glax24 & Severnyj v.1.4.0.46 [22.09.16]

          WebSite: www.safezone.cc
          DateLog: 05.11.2016 18:31:06
          Path starting: C:\Users\Chinwe\AppData\Local\Temp\SecurityCheck\S ecurityCheck.exe
          Log directory: C:\SecurityCheck
          IsAdmin: True
          User: Chinwe
          VersionXML: 3.48is-30.10.2016


          Windows Vista(6.0.6002) Service Pack 2 (x86) HomePremium Lang: English(0409)
          Installation date OS: 21.04.2009 19:50:03
          LicenseStatus: Windows™ Vista, HomePremium edition The machine is permanently activated.
          Boot Mode: Normal
          Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
          SystemDrive: C: FS: [NTFS] Capacity: [450.7 Gb] Used: [332.7 Gb] Free: [118 Gb]
          ------------------------------- [ Windows ] -------------------------------
          Internet Explorer 9.0.8112.16421 Warning! Download Update
          Online installation. Last version available when Windows update is enabled throught the Internet.
          Automatically download and schedule installation
          Date install updates: 2016-11-04 07:18:12
          Windows Update (wuauserv) - The service is running
          Security Center (wscsvc) - The service is running
          Remote Registry (RemoteRegistry) - The service has stopped
          Terminal Services (TermService) - The service is running
          Windows Remote Management (WS-Management) (WinRM) - The service has stopped
          SSDP Discovery (SSDPSRV) - The service is running
          ------------------------------ [ MS Office ] ------------------------------
          Microsoft Office 2003 v.11.0.8173.0
          Microsoft Office 2007 v.12.0.6612.1000
          ---------------------------- [ Antivirus_WMI ] ----------------------------
          360 Total Security (enabled)
          --------------------------- [ FirewallWindows ] ---------------------------
          Windows Firewall (MpsSvc) - The service is running
          --------------------------- [ AntiSpyware_WMI ] ---------------------------
          Windows Defender (enabled)
          360 Total Security (enabled)
          ---------------------- [ AntiVirusFirewallInstall ] -----------------------
          360 Total Security v.8.8.0.1080
          -------------------------- [ SecurityUtilities ] --------------------------
          Malwarebytes Anti-Malware version 2.2.1.1043 v.2.2.1.1043
          --------------------------- [ OtherUtilities ] ----------------------------
          Microsoft Silverlight v.5.1.50901.0
          --------------------------------- [ IM ] ----------------------------------
          Skype™ 7.27 v.7.27.101 Warning! Download Update
          ^Optional update.[1]
          -------------------------------- [ Java ] ---------------------------------
          Java™ 6 Update 11 v.6.0.110 Warning! This software is no longer supported. Please uninstall it and use Java SE 8 (jre-8u112-windows-i586.exe).
          --------------------------- [ AdobeProduction ] ---------------------------
          Adobe AIR v.23.0.0.257
          Adobe Flash Player 23 ActiveX v.23.0.0.162 Warning! Download Update
          Adobe Shockwave Player 12.2 v.12.2.4.194 Warning! Download Update
          Adobe Reader XI (11.0.17) v.11.0.17 Warning! Download Update
          ^Please run Adobe Reader XI and go Help - Check for updates…[2]
          ------------------------------- [ Browser ] -------------------------------
          Mozilla Firefox 49.0.2 (x86 en-GB) v.49.0.2
          ----------------------------- [ EmailClient ] -----------------------------
          Windows Live Mail v.14.0.8050.1202
          --------------------------- [ RunningProcess ] ----------------------------
          C:\Program Files\Mozilla Firefox\firefox.exe v.49.0.2.6136
          ------------------ [ AntivirusFirewallProcessServices ] -------------------
          C:\Program Files\Windows Defender\MSASCui.exe v.1.1.1600.0
          Windows Defender (WinDefend) - The service is running
          360 Total Security (QHActiveDefense) - The service is running
          C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe v.8.8.0.1008
          C:\Program Files\360\Total Security\safemon\QHWatchdog.exe v.8.2.0.1000
          C:\Program Files\360\Total Security\safemon\QHSafeTray.exe v.8.8.0.1014
          ----------------------------- [ End of Log ] ------------------------------

          1. /b ↩︎
          2. /b ↩︎

          Comment

          • Kiredoryor
            PCHF Member
            • Oct 2016
            • 67

            #20
            .

            Comment

            • Malnutrition
              PCHF Moderator
              • Jul 2016
              • 7041

              #21
              Please make sure that you change the default file type from .arn to .txt with Autoruns, then post the new log.
              Then go ahead and update all of your outdated programs with PatchMyPC
              Then Disable Windows Defender, as it is as useless as a 10 year old being a bouncer at a biker bar in Detroit…

              Remove these programs below with Geek Uninstaller.

              Dell Dock (HKLM...{F6CB42B9-F033-4152-8813-FF11DA8E6A78}) (Version: 1.0.0 - Dell)
              Dell Edoc Viewer (HKLM...{3138EAD3-700B-4A10-B617-B3F8096EE30D}) (Version: 1.0.0 - Dell Inc)
              Dell Getting Started Guide (HKLM...{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
              Dell Support Center (Support Software) (HKLM...{E3BFEE55-39E2-4BE0-B966-89FE583822C1}) (Version: 2.2.08335 - Dell)
              Dell-eBay (HKLM...{B935C985-A17F-484B-8470-09E4FC27DC26}) (Version: 1.00.0000 - Dell)

              Fix with HijackThis!

              Close all other programs!
              Right Click Hijack this, run as administrator.
              Click do a system scan only.
              Place a tick next to the items below.

              O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM..\Run: [Dropbox] “C:\Program Files\Dropbox\Client\Dropbox.exe” /systemstartup
              O4 - HKLM..\Run: [Adobe ARM] “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”
              O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User ‘Default user’)
              O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe

              Click fix checked.
              Accept the prompt.
              Reboot the machine after.

              Comment

              • Kiredoryor
                PCHF Member
                • Oct 2016
                • 67

                #22
                Autoruns log. (I thought I had saved as a .txt file but now see I saved it twice!)
                “HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms” “” “” “” “02/11/2016 10:08” “”
                • “rdpclip” “” “” “File not found: rdpclip” “” “”
                  “HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru n” “” “” “” “02/11/2016 10:07” “”
                • “Adobe ARM” “Adobe Reader and Acrobat Manager” “Adobe Systems Incorporated” “c:\program files\common files\adobe\arm\1.0\adobearm.exe” “14/12/2015 07:38” “”
                • “Broadcom Wireless Manager UI” “Dell Wireless WLAN Card Wireless Network Tray Applet” “Dell Inc.” “c:\windows\system32\wltray.exe” “12/11/2008 03:15” “”
                • “Dropbox” “Dropbox” “Dropbox, Inc.” “c:\program files\dropbox\client\dropbox.exe” “10/10/2016 18:16” “”
                • “QHSafeTray” “360 Total Security” “QIHU 360 SOFTWARE CO. LIMITED” “c:\program files\360\total security\safemon\qhsafetray.exe” “19/10/2016 08:02” “”
                • “Windows Defender” “Windows Defender User Interface” “Microsoft Corporation” “c:\program files\windows defender\msascui.exe” “19/01/2008 05:42” “”
                • “WinPrivacy” “WinPrivacy” “WinPatrol” “c:\program files\ruiware\winprivacy\winprivacytrayapp.exe” “25/06/2015 04:16” “”
                  “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru n” “” “” “” “02/11/2016 10:05” “”
                • “WinPatrol” “WinPatrol Monitor” “Ruiware” “c:\program files\ruiware\winpatrol\winpatrol.exe” “26/07/2015 23:56” “”
                  “C:\Users\Chinwe\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Startup” “” “” “” “02/09/2015 07:18” “”
                • “Dell Dock.lnk” “Dell Dock” “Stardock Corporation” “c:\program files\dell\delldock\delldock.exe” “27/02/2009 20:09” “”
                  “HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components” “” “” “” “02/11/2016 10:07” “”
                • “Microsoft Windows Mail 7” “Windows Mail” “Microsoft Corporation” “c:\program files\windows mail\winmail.exe” “19/01/2008 05:47” “”
                  “HKLM\SOFTWARE\Classes\Protocols\Filter” “” “” “” “02/11/2016 10:07” “”
                • “text/xml” “Microsoft Office XML MIME Filter” “Microsoft Corporation” “c:\program files\common files\microsoft shared\office12\msoxmlmf.dll” “26/02/2009 16:00” “”
                  “HKLM\SOFTWARE\Classes\Protocols\Handler” “” “” “” “02/11/2016 10:35” “”
                • “livecall” “Windows Live Messenger Protocol Handler Module” “Microsoft Corporation” “c:\program files\windows live\messenger\msgrapp.14.0.8050.1202.dll” “03/12/2008 06:15” “”
                • “ms-help” “Microsoft® Help Data Services Module” “Microsoft Corporation” “c:\program files\common files\microsoft shared\help\hxds.dll” “07/11/2012 10:30” “”
                • “ms-itss” “Microsoft® InfoTech Storage System Library” “Microsoft Corporation” “c:\program files\common files\microsoft shared\information retrieval\msitss.dll” “20/06/2001 16:26” “”
                • “msnim” “Windows Live Messenger Protocol Handler Module” “Microsoft Corporation” “c:\program files\windows live\messenger\msgrapp.14.0.8050.1202.dll” “03/12/2008 06:15” “”
                • “wlmailhtml” “Windows Live Mail” “Microsoft Corporation” “c:\program files\windows live\mail\mailcomm.dll” “03/12/2008 06:15” “”
                  “HKLM\Software\Classes*\ShellEx\ContextMenuHandler s” “” “” “” “04/11/2016 18:17” “”
                • “DropboxExt” “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                • “PrivaZer” “” “” “c:\program files\privazer\privamenu5.dll” “15/02/2014 09:20” “”
                • “SD360” “360 Total Security” “” “c:\program files\360\total security\menuex.dll” “12/08/2016 10:24” “”
                  “HKLM\Software\Classes\Drive\ShellEx\ContextMenuHa ndlers” “” “” “” “04/11/2016 18:17” “”
                • “PrivaZer” “” “” “c:\program files\privazer\privamenu5.dll” “15/02/2014 09:20” “”
                  “HKLM\Software\Classes\AllFileSystemObjects\ShellE x\ContextMenuHandlers” “” “” “” “04/11/2016 18:17” “”
                • “MBAMShlExt” “Malwarebytes Anti-Malware” “Malwarebytes” “c:\program files\malwarebytes anti-malware\mbamext.dll” “24/02/2016 17:13” “”
                • “PrivaZer” “” “” “c:\program files\privazer\privamenu5.dll” “15/02/2014 09:20” “”
                  “HKLM\Software\Classes\Directory\ShellEx\ContextMe nuHandlers” “” “” “” “04/11/2016 18:17” “”
                • “DropboxExt” “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                • “PrivaZer” “” “” “c:\program files\privazer\privamenu5.dll” “15/02/2014 09:20” “”
                • “SD360” “360 Total Security” “” “c:\program files\360\total security\menuex.dll” “12/08/2016 10:24” “”
                  “HKLM\Software\Classes\Directory\Shellex\CopyHookH andlers” “” “” “” “02/11/2016 10:07” “”
                • “DropboxCopyHook” “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                  “HKLM\Software\Classes\Directory\Background\ShellE x\ContextMenuHandlers” “” “” “” “02/11/2016 10:07” “”
                • “ACE” “AMD Desktop Control Panel” “Advanced Micro Devices, Inc.” “c:\program files\ati technologies\ati.ace\core-static\atiacmxx.dll” “02/07/2008 14:56” “”
                • “DropboxExt” “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                  “HKLM\Software\Classes\Folder\Shellex\ColumnHandle rs” “” “” “” “02/11/2016 10:07” “”
                • “PDF Shell Extension” “PDF Shell Extension” “Adobe Systems, Inc.” “c:\program files\common files\adobe\acrobat\activex\pdfshell.dll” “11/05/2013 09:34” “”
                  “HKLM\Software\Classes\Folder\ShellEx\ContextMenuH andlers” “” “” “” “04/11/2016 18:17” “”
                • “MBAMShlExt” “Malwarebytes Anti-Malware” “Malwarebytes” “c:\program files\malwarebytes anti-malware\mbamext.dll” “24/02/2016 17:13” “”
                • “PrivaZer” “” “” “c:\program files\privazer\privamenu5.dll” “15/02/2014 09:20” “”
                • “RUShellExt” “Revo Uninstaller Pro Extension” “VS Revo Group” “c:\program files\vs revo group\revo uninstaller pro\ruext.dll” “07/12/2012 11:55” “”
                • “SD360” “360 Total Security” “” “c:\program files\360\total security\menuex.dll” “12/08/2016 10:24” “”
                  “HKLM\Software\Microsoft\Windows\CurrentVersion\Ex plorer\ShellIconOverlayIdentifiers” “” “” “” “02/11/2016 10:07” “”
                • " DropboxExt1" “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                • " DropboxExt10" “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                • " DropboxExt2" “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                • " DropboxExt3" “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                • " DropboxExt4" “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                • " DropboxExt5" “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                • " DropboxExt6" “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                • " DropboxExt7" “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                • " DropboxExt8" “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                • " DropboxExt9" “Dropbox Shell Extension” “Dropbox, Inc.” “c:\program files\dropbox\client\dropboxext.1.0.dll” “24/10/2016 13:10” “”
                  “HKLM\Software\Microsoft\Windows\CurrentVersion\Ex plorer\Browser Helper Objects” “” “” “” “02/11/2016 10:07” “”
                • “Java™ Plug-In 2 SSV Helper” “Java™ Platform SE binary” “Sun Microsystems, Inc.” “c:\program files\java\jre6\bin\jp2ssv.dll” “10/11/2008 13:43” “”
                • “Java™ Plug-In SSV Helper” “Java™ Platform SE binary” “Sun Microsystems, Inc.” “c:\program files\java\jre6\bin\ssv.dll” “10/11/2008 13:43” “”
                • “Windows Live Sign-in Helper” “WindowsLiveLogin.dll” “Microsoft Corporation” “c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll” “18/02/2009 00:07” “”
                  “HKLM\Software\Microsoft\Internet Explorer\Extensions” “” “” “” “02/11/2016 10:07” “”
                • “&Blog This in Windows Live Writer” “Windows Live Writer Blog This Extension” “Microsoft Corporation” “c:\program files\windows live\writer\writerbrowserextension.dll” “03/12/2008 05:46” “”
                • “S&end to OneNote” “Microsoft Office OneNote Internet Explorer Add-in” “Microsoft Corporation” “c:\program files\microsoft office\office12\onbttnie.dll” “30/08/2011 06:40” “”
                  “Task Scheduler” “” “” “” “” “”
                • “\Microsoft\Windows Defender\MP Scheduled Scan” “Windows Defender Command Line Utility” “Microsoft Corporation” “c:\program files\windows defender\mpcmdrun.exe” “19/01/2008 05:42” “”
                • “\Microsoft\Windows\Wired\GatherWiredInfo” “” “” “c:\windows\system32\gatherwiredinfo.vbs” “21/01/2008 02:24” “”
                • “\Microsoft\Windows\Wireless\GatherWirelessInfo” “” “” “c:\windows\system32\gatherwirelessinfo.vbs” “21/01/2008 02:23” “”
                • “\PrivaZer_SkipUAC” “PrivaZer” “Goversoft LLC” “c:\program files\privazer\privazer.exe” “19/06/1992 22:22” “”
                • “\Tweaking.com - Windows Repair Tray Icon” “Tweaking.com - Windows Repair Tray Icon” “Tweaking.com” “c:\program files\tweaking.com\windows repair (all in one)\wr_tray_icon.exe” “12/03/2015 00:43” “”
                  “HKLM\System\CurrentControlSet\Services” “” “” “” “07/11/2016 07:07” “”
                • “AdobeARMservice” “Adobe Acrobat Updater keeps your Adobe software up to date.” “Adobe Systems Incorporated” “c:\program files\common files\adobe\arm\1.0\armsvc.exe” “14/12/2015 07:38” “”
                • “AdobeFlashPlayerUpdateSvc” “This service keeps your Adobe Flash Player installation up to date with the latest enhancements and security fixes.” “Adobe Systems Incorporated” “c:\windows\system32\macromed\flash\flashplayerupd ateservice.exe” “30/08/2016 00:01” “”
                • “AERTFilters” “Andrea filters APO access service (32-bit)” “Andrea Electronics Corporation” “c:\windows\system32\aertsrv.exe” “15/02/2008 17:33” “”
                • “Ati External Event Utility” “ATI External Event Utility EXE Module” “ATI Technologies Inc.” “c:\windows\system32\ati2evxx.exe” “29/07/2008 02:19” “”
                • “dbupdate” “Keeps your Dropbox software up to date. If this service is disabled or stopped, your Dropbox software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Dropbox software using it.” “Dropbox, Inc.” “c:\program files\dropbox\update\dropboxupdate.exe” “21/10/2015 18:52” “”
                • “dbupdatem” “Keeps your Dropbox software up to date. If this service is disabled or stopped, your Dropbox software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Dropbox software using it.” “Dropbox, Inc.” “c:\program files\dropbox\update\dropboxupdate.exe” “21/10/2015 18:52” “”
                • “DbxSvc” “Dropbox Service” “Dropbox, Inc.” “c:\windows\system32\dbxsvc.exe” “05/10/2016 23:13” “”
                • “DockLoginService” “Dock Login Service” “Stardock Corporation” “c:\program files\dell\delldock\docklogin.exe” “21/08/2008 16:21” “”
                • “GoToAssist” “Citrix GoToAssist provides remote help to this PC.” “Citrix Online, a division of Citrix Systems, Inc.” “c:\program files\citrix\gotoassist\514\g2aservice.exe” “21/02/2008 20:46” “”
                • “IJPLMSVC” “Collects log data from the IJ printer and manages data transmission.” “” “c:\program files\canon\ijplm\ijplmsvc.exe” “05/04/2010 10:50” “”
                • “MozillaMaintenance” “The Mozilla Maintenance Service ensures that you have the latest and most secure version of Mozilla Firefox on your computer. Keeping Firefox up to date is very important for your online security, and Mozilla strongly recommends that you keep this service enabled.” “Mozilla Foundation” “c:\program files\mozilla maintenance service\maintenanceservice.exe” “19/10/2016 18:21” “”
                • “odserv” “Run portions of Microsoft Office Diagnostics.” “Microsoft Corporation” “c:\program files\common files\microsoft shared\office12\odserv.exe” “20/07/2011 05:12” “”
                • “ose” “Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports.” “Microsoft Corporation” “c:\program files\common files\microsoft shared\source engine\ose.exe” “26/10/2006 21:00” “”
                • “QHActiveDefense” “360 Total Security” “QIHU 360 SOFTWARE CO. LIMITED” “c:\program files\360\total security\safemon\qhactivedefense.exe” “25/08/2016 10:58” “”
                • “RapportMgmtService” “IBM Security Trusteer Endpoint Protection Central Management and Monitoring Service” “IBM Corp.” “c:\program files\trusteer\rapport\bin\rapportmgmtservice.exe” “06/10/2016 13:59” “”
                • “SkypeUpdate” “Enables the detection, download and installation of updates for Skype.” “Skype Technologies” “c:\program files\skype\updater\updater.exe” “25/07/2016 11:32” “”
                • “sprtsvc_DellSupportCenter” “SupportSoft Sprocket Service (DellSupportCenter)” “SupportSoft, Inc.” “c:\program files\dell support center\bin\sprtsvc.exe” “28/06/2008 09:47” “”
                • “stllssvr” “SureThing Labelflash Disc Printer Service Module” “MicroVision Development, Inc.” “c:\program files\common files\surething shared\stllssvr.exe” “12/03/2008 22:21” “”
                • “WinDefend” “Scan your computer for unwanted software, schedule scans, and get the latest unwanted software definitions.” “Microsoft Corporation” “c:\program files\windows defender\mpsvc.dll” “19/01/2008 07:26” “”
                • “WinPrivacySvc” “WinPrivacy background service. Taking back your Internet privacy!” “WinPatrol” “c:\program files\ruiware\winprivacy\winprivacysvc.exe” “25/06/2015 04:16” “”
                • “wltrysvc” “Provides automatic configuration for the 802.11 adapter using the Broadcom supplicant.” “” “c:\windows\system32\wltrysvc.exe” “12/11/2008 03:09” “”
                • “WMPNetworkSvc” “Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play” “Microsoft Corporation” “c:\program files\windows media player\wmpnetwk.exe” “19/01/2008 06:06” “”
                • “WsAppService” “Wondershare Application Framework Service” “Wondershare” “c:\program files\wondershare\waf\2.1.5.6\wsappservice.exe” “25/12/2015 09:19” “”
                  “HKLM\System\CurrentControlSet\Services” “” “” “” “07/11/2016 07:07” “”
                • “360AntiHacker” “360安全卫士 网络防黑模块” “360.cn” “c:\windows\system32\drivers\360antihacker.sys” “12/05/2016 02:18” “”
                • “360AvFlt” “360杀毒 文件监控驱动” “360.cn” “c:\windows\system32\drivers\360avflt.sys” “19/07/2016 08:43” “”
                • “360Box” “360Box” “360.cn” “c:\windows\system32\drivers\360box.sys” “12/05/2016 03:48” “”
                • “360Camera” “360安全卫士 木马防火墙模块” “360.cn” “c:\windows\system32\drivers\360camera.sys” “07/03/2014 10:28” “”
                • “360SelfProtection” “360安全卫士 - SelfProtection” “360安全中心” “c:\windows\system32\drivers\360selfprotection.sys ” “30/07/2016 15:14” “”
                • “atikmdag” “ATI Radeon Kernel Mode Driver” “ATI Technologies Inc.” “c:\windows\system32\drivers\atikmdag.sys” “29/07/2008 02:35” “”
                • “BAPIDRV” “BAPIDRV” “360.cn” “c:\windows\system32\drivers\bapidrv.sys” “24/08/2016 09:08” “”
                • “BCM42RLY” “Broadcom iLine10™ PCI Network Adapter Proxy Protocol Driver” “Broadcom Corporation” “c:\windows\system32\drivers\bcm42rly.sys” “12/11/2008 03:07” “”
                • “BCM43XX” “Broadcom 802.11 Network Adapter wireless driver” “Broadcom Corporation” “c:\windows\system32\drivers\bcmwl6.sys” “23/10/2008 00:41” “”
                • “BrFiltLo” “Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver” “Brother Industries, Ltd.” “c:\windows\system32\drivers\brfiltlo.sys” “06/08/2006 21:33” “”
                • “BrFiltUp” “Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver” “Brother Industries, Ltd.” “c:\windows\system32\drivers\brfiltup.sys” “06/08/2006 21:33” “”
                • “BrUsbSer” “Brother USB Serial Driver” “Brother Industries Ltd.” “c:\windows\system32\drivers\brusbser.sys” “09/08/2006 12:02” “”
                • “dbx” “Dropbox Mini-Filter Driver” “” “File not found: system32\DRIVERS\dbx.sys” “” “”
                • “e1express” “Intel(R) PRO/1000 Adapter NDIS 6 deserialized driver” “Intel Corporation” “c:\windows\system32\drivers\e1e6032.sys” “29/10/2007 21:43” “”
                • “E1G60” “Intel(R) PRO/1000 Adapter NDIS 6 deserialized driver” “Intel Corporation” “c:\windows\system32\drivers\e1g60i32.sys” “07/08/2007 16:14” “”
                • “EfiMon” “360Efimon Driver” “360.cn” “c:\windows\system32\drivers\efimon.sys” “11/11/2015 03:45” “”
                • “HookPort” “360安全卫士 - HookPort” “360安全中心” “c:\windows\system32\drivers\hookport.sys” “30/07/2016 15:16” “”
                • “IntcAzAudAddService” “Realtek(r) High Definition Audio Function Driver” “Realtek Semiconductor Corp.” “c:\windows\system32\drivers\rtkvhda.sys” “11/07/2008 07:50” “”
                • “PxHelp20” “Px Engine Device Driver for Windows 2000/XP” “Sonic Solutions” “c:\windows\system32\drivers\pxhelp20.sys” “17/10/2007 18:24” “”
                • “qutmdserv” “360安全卫士 木马防火墙模块” “360.cn” “c:\windows\system32\drivers\qutmdrv.sys” “28/07/2016 07:46” “”
                • “qutmipc” “360安全卫士 木马防火墙模块” “360.cn” “c:\windows\system32\drivers\qutmipc.sys” “19/07/2016 06:18” “”
                • “R300” “ATI Radeon Kernel Mode Driver” “ATI Technologies Inc.” “c:\windows\system32\drivers\atikmdag.sys” “29/07/2008 02:35” “”
                • “RapportCerberus_1609053” “RapportCerberus” “IBM Corp.” “c:\programdata\trusteer\rapport\store\exts\rappor tcerberus\baseline\rapportcerberus32_1609053.sys” “01/09/2016 14:44” “”
                • “RapportEI” “RapportEI” “IBM Corp.” “c:\program files\trusteer\rapport\bin\rapportei.sys” “06/10/2016 14:06” “”
                • “RapportHades” “RapportHades64” “IBM Corp.” “c:\windows\system32\drivers\rapporthades.sys” “06/10/2016 14:06” “”
                • “RapportKELL” “RapportKE” “IBM Corp.” “c:\windows\system32\drivers\rapportkell.sys” “06/10/2016 14:06” “”
                • “RapportPG” “RapportPG” “IBM Corp.” “c:\program files\trusteer\rapport\bin\rapportpg.sys” “06/10/2016 14:06” “”
                • “Revoflt” “Revo Uninstaller Filter driver” “VS Revo Group” “c:\windows\system32\drivers\revoflt.sys” “30/12/2009 09:18” “”
                • “RTL8169” "Realtek 8101E/8168/8169 NDIS6 32-bit Driver " "Realtek Corporation " “c:\windows\system32\drivers\rtlh86.sys” “10/06/2008 10:54” “”
                • “RtNdPt60” “Realtek NDIS Protocol Driver” “Windows (R) Codename Longhorn DDK provider” “c:\windows\system32\drivers\rtndpt60.sys” “11/12/2007 02:50” “”
                • “ruinetf” “” “” “File not found: system32\drivers\ruinetf.sys” “” “”
                • “WsAudioDevice_383” “Wondershare Virtual Audio Device” “Wondershare” “c:\windows\system32\drivers\wsaudiodevice_383.sys ” “18/11/2008 09:14” “”
                  “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers” “” “” “” “02/11/2016 10:08” “”
                • “Adobe Type Manager” “Windows NT OpenType/Type 1 Font Driver” “Adobe Systems Incorporated” “c:\windows\system32\atmfd.dll” “14/05/2016 14:21” “”
                  “HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32” “” “” “” “02/11/2016 10:08” “”
                • “msacm.l3acm” “MPEG Layer-3 Audio Codec for MSACM” “Fraunhofer Institut Integrierte Schaltungen IIS” “c:\windows\system32\l3codeca.acm” “21/01/2010 15:05” “”
                • “vidc.cvid” “Cinepak® Codec” “Radius Inc.” “c:\windows\system32\iccvid.dll” “27/05/2010 20:08” “”
                • “vidc.iv50” “Intel Indeo® video 5.10” “Intel Corporation” “c:\windows\system32\ir50_32.dll” “02/11/2006 09:41” “”
                  “HKLM\Software\Classes\CLSID{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance” “” “” “” “02/11/2016 10:31” “”
                • “9x8Resize” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “Allocator Fix” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “ATI Ticker” “” “” “c:\program files\ati technologies\ati.ace\graphics-previews-common\ticker.ax” “18/12/2006 20:57” “”
                • “Bitmap” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “Capture ASF Writer” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “Capture File Writer” “Windows Live Video Acquisition Filters” “Microsoft Corporation” “c:\program files\windows live\photo gallery\wlxvafilt.dll” “05/12/2008 06:46” “”
                • “Frame Eater” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “Indeo® video 5.10 Compression Filter” “Intel Indeo® video 5.10” “Intel Corporation” “c:\windows\system32\ir50_32.dll” “02/11/2006 09:41” “”
                • “Indeo® video 5.10 Decompression Filter” “Intel Indeo® video 5.10” “Intel Corporation” “c:\windows\system32\ir50_32.dll” “02/11/2006 09:41” “”
                • “MMACE Deinterlace” “” “” “c:\program files\ati technologies\ati.ace\graphics-previews-common\mmacefilters.dll” “07/05/2008 22:55” “”
                • “MMACE ProcAmp” “” “” “c:\program files\ati technologies\ati.ace\graphics-previews-common\mmacefilters.dll” “07/05/2008 22:55” “”
                • “MMACE SoftEmu” “” “” “c:\program files\ati technologies\ati.ace\graphics-previews-common\mmacefilters.dll” “07/05/2008 22:55” “”
                • “Multiple File Output” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “NewSoft Audio Encoder Filter” “Auido Encoder Filter” "NewSoft " “c:\program files\common files\newsoft\nsm2aenc.ax” “12/07/2005 07:49” “”
                • “NewSoft DeInterlace” “” “Newsoft” “c:\program files\common files\newsoft\nsdeinterlace.ax” “07/07/2005 03:14” “”
                • “NewSoft MPEG Video Decoder Filter” “NewSoft MPEG Video Decoder Filter” “NewSoft Corporation” “c:\program files\common files\newsoft\nsm2vdec.ax” “10/08/2005 09:32” “”
                • “NewSoft MPEG Video Encoder Filter” “MPEG Video Encoder Filter” "NewSoft " “c:\program files\common files\newsoft\nsm2venc.ax” “30/08/2005 10:09” “”
                • “Proxy Sink” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “Proxy Source” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “Record Queue” “Windows Live Video Acquisition Filters” “Microsoft Corporation” “c:\program files\windows live\photo gallery\wlxvafilt.dll” “05/12/2008 06:46” “”
                • “Record Queue” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “ShotDetect” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “Stetch” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WM VIH2 Fix” “Windows Live Video Acquisition Filters” “Microsoft Corporation” “c:\program files\windows live\photo gallery\wlxvafilt.dll” “05/12/2008 06:46” “”
                • “WM VIH2 Fix” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT Audio Analyzer” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT Black Frame Generator” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT DV Extract Filter” “Windows Live Video Acquisition Filters” “Microsoft Corporation” “c:\program files\windows live\photo gallery\wlxvafilt.dll” “05/12/2008 06:46” “”
                • “WMT DV Extract Filter” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT FormatConversion” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT Import Filter” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT Interlacer” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT Log Filter” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT MuxDeMux Filter” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT Sample Info Filter” “Windows Live Video Acquisition Filters” “Microsoft Corporation” “c:\program files\windows live\photo gallery\wlxvafilt.dll” “05/12/2008 06:46” “”
                • “WMT Sample Info Filter” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT Switch Filter” “Windows Live Video Acquisition Filters” “Microsoft Corporation” “c:\program files\windows live\photo gallery\wlxvafilt.dll” “05/12/2008 06:46” “”
                • “WMT Switch Filter” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT Virtual Renderer” “Windows Live Video Acquisition Filters” “Microsoft Corporation” “c:\program files\windows live\photo gallery\wlxvafilt.dll” “05/12/2008 06:46” “”
                • “WMT Virtual Renderer” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT Virtual Source” “Windows Live Video Acquisition Filters” “Microsoft Corporation” “c:\program files\windows live\photo gallery\wlxvafilt.dll” “05/12/2008 06:46” “”
                • “WMT Virtual Source” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                • “WMT Volume” “Windows Movie Maker Filters” “Microsoft Corporation” “c:\program files\movie maker\wmm2filt.dll” “11/04/2009 06:28” “”
                  “HKLM\SOFTWARE\Classes\Htmlfile\Shell\Open\Command (Default)” “” “” “” “02/11/2016 10:07” “”
                • “C:\Program Files\Internet Explorer\iexplore.exe” “Internet Explorer” “Microsoft Corporation” “c:\program files\internet explorer\iexplore.exe” “30/09/2016 03:36” “”
                  “HKLM\System\CurrentControlSet\Services\WinSock2\P arameters\Protocol_Catalog9\Catalog_Entries” “” “” “” “02/11/2016 10:37” “”
                • “vSockets DGRAM” “” “” “File not found: C:\Windows\system32\vsocklib.dll.exe” “” “”
                • “vSockets STREAM” “” “” “File not found: C:\Windows\system32\vsocklib.dll.exe” “” “”
                  “HKLM\System\CurrentControlSet\Services\WinSock2\P arameters\Protocol_Catalog9\Catalog_Entries64” “” “” “” “02/11/2016 10:37” “”
                • “vSockets DGRAM” “” “” “File not found: C:\Windows\system32\vsocklib.dll.exe” “” “”
                • “vSockets STREAM” “” “” “File not found: C:\Windows\system32\vsocklib.dll.exe” “” “”
                  “HKLM\SYSTEM\CurrentControlSet\Control\Print\Monit ors” “” “” “” “02/11/2016 10:08” “”
                • “BJ Language Monitor3_3” “Canon Inkjet Printer Driver” “CANON INC.” “c:\windows\system32\cnblm3_3.dll” “02/11/2006 09:39” “”
                  “HKLM\SYSTEM\CurrentControlSet\Control\NetworkProv ider\Order” “” “” “” “02/11/2016 10:08” “”
                • “BCMLogon” “Dell Wireless WLAN Card Logon Provider” “Dell Inc.” “c:\windows\system32\bcmlogon.dll” “12/11/2008 03:12” “”
                  “HKLM\Software\Microsoft\Office\Outlook\Addins” “” “” “” “02/11/2016 10:07” “”
                • “Microsoft VBA for Outlook Addin” “Outlook VBA Integration Add-In” “Microsoft Corporation” “c:\program files\microsoft office\office12\addins\outlvba.dll” “18/11/2014 15:48” “”
                  X “OMS Connect class” “Microsoft Outlook Mobile Service” “Microsoft Corporation” “c:\program files\microsoft office\office12\omsmain.dll” “18/11/2014 15:54” “”
                • “OneNote Notes about Outlook Items” “Microsoft Office OneNote Outlook Add-in” “Microsoft Corporation” “c:\program files\microsoft office\office12\onbttnol.dll” “30/08/2011 06:40” “”
                  “HKCU\Software\Microsoft\Office\Outlook\Addins” “” “” “” “02/11/2016 10:05” “”
                • “ColleagueImportAddIn Class” “” “” “c:\program files\microsoft office\office12\addins\colleagueimport.dll” “26/02/2009 13:31” “”
                • “FormRegionAddin Class” “” “” “c:\program files\microsoft office\office12\addins\umoutlookaddin.dll” “22/06/2011 11:40” “”
                • “{D614B4AF-F5E6-4A03-AE81-37BA64372538}” “Microsoft Office Outlook Calendar Gadget for Windows SideShow” “Microsoft Corporation” “c:\program files\microsoft office\office12\olsideshow.dll” “27/10/2006 03:31” “”

                Comment

                • Kiredoryor
                  PCHF Member
                  • Oct 2016
                  • 67

                  #23
                  Have done all of above.
                  but:
                  couldn’t find “Dell Edoc Viewer” in Geek Uninstaller
                  Couldn’t find 04 - DEFAULT or 04 - Startup: Dell Dock.Ink
                  all the 04s were HKLM, HKCU or HKUS

                  K

                  Comment

                  • Malnutrition
                    PCHF Moderator
                    • Jul 2016
                    • 7041

                    #24
                    You never did complete the Zemana Scan from post number 12 of this thread. Please do that, and perform a check disk on this machine, and tell me how things are running.

                    Run chkdsk /f /r from elevated command prompt. Open the Start Menu, click on All Programs and Accessories, right click on Command Prompt, and click on Run as administrator.

                    [MEDIA=youtube]4feZG3LebOg[/MEDIA]

                    Comment

                    • Kiredoryor
                      PCHF Member
                      • Oct 2016
                      • 67

                      #25
                      I was unable to login yesterday, even when typing the www in first - eventually gave up!
                      I still have the same problem that I had when you first suggested Zemana Scan. i can download the programme but cannot open it. I try double clicking from the download folder, then try running as administrator. I’ve also tried both from the containing folder but nothing happens. I have found that this is also happening to the Whatsapp for PC prog that I used to use on the PC.

                      I have run CheckDisk. I don’t know how long it took but it was over 5 hours - is that expected? The computer had rebooted when I came back to it so I don’t know if there was any status report at the end of it. Should there be one and, if so, would it be saved somewhere? Although I haven’t really had much time to test it properly my first impression is the the machine is operating much quicker now.

                      I’m having a little difficulty with Gimp. When I try to open it I soon get a window stating “C:\Program files\GIMP2\bix\icui18n56.dll is either not designed to run on windows or it contains an error. Try installing again …etc” I click OK then get “Check for a Solution…” I do that & it carries on loading. I have to repeat that process 5 or 6 times and then it loads OK. I did delete it and download again but am having the same problem. I’m wondering if during all this processing it has been updated and now contains a version that isn’t compatible with Vista?

                      Comment

                      • Malnutrition
                        PCHF Moderator
                        • Jul 2016
                        • 7041

                        #26
                        Alright, considering the age of this install. If it were my machine, I would look into setting up a new profile and migrating your settings to it. Before we get into that, how about enabling the admin account, and let me know if any issues are to speak of from within it.

                        Comment

                        • Kiredoryor
                          PCHF Member
                          • Oct 2016
                          • 67

                          #27
                          I’m really going to display my ignorance now!
                          1. Clicked the ‘enabling the admin account’ link and started following instructions but didn’t get far! I ckicked ‘Start’ typed cmd & pressed enter and got a Notepad window with a C:\Users\Chinwe> prompt. There was nothing to click on that window so typed cmd again into search box, didn’t click enter but right clicked ‘cmd’ at the top of the search results list and clicked run as administrator - that opened another Notepad window this time with C:\Windows\system32> prompt (there seemed to be no further requirement for the first window so not sure what the point was of opening it?) At next stage got stuck as no idea who or what “net user administrator” is. tried typing in that phrase, the main user name “Chinwe” with and without spacing before the / and as many combination of things as I could think of. I got either "Chinwe is not recognised … or just nothing.
                            So my ignorance got me stuck at that point!
                          2. I do have other ‘users’ on this machine is that the same thing as a ‘profile’ if not how do I set up a new one?

                          Comment

                          • Malnutrition
                            PCHF Moderator
                            • Jul 2016
                            • 7041

                            #28
                            Originally posted by Kiredoryor
                            . I do have other ‘users’ on this machine is that the same thing as a ‘profile’
                            Yes, same thing. Just use this guide if there is any question.

                            To setup new user.
                            To enable admin account. Instructions are the same for windows 7.

                            Comment

                            • Malnutrition
                              PCHF Moderator
                              • Jul 2016
                              • 7041

                              #29
                              Hello, how about an update?

                              Comment

                              • Kiredoryor
                                PCHF Member
                                • Oct 2016
                                • 67

                                #30
                                Been away! Got a bit of catching up to do then back to this!

                                Comment

                                Working...