Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-12-2022
Ran by John (16-12-2022 10:13:40)
Running from C:\Users\John\Downloads
Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) (2008-05-28 22:18:41)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2314338359-2121603862-2684469121-500 - Administrator - Disabled)
Guest (S-1-5-21-2314338359-2121603862-2684469121-501 - Limited - Disabled)
John (S-1-5-21-2314338359-2121603862-2684469121-1000 - Administrator - Enabled) => C:\Users\John
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 32 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 32.0.0.465 - Adobe)
Adobe Flash Player 32 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 32.0.0.465 - Adobe)
Adobe Reader X (10.1.16) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)
AIM 7 (HKLM\...\AIM_7) (Version: - )
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 18.8.2356 - AVAST Software)
Avast Update Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.4.141.333 - AVAST Software) Hidden
Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
CyberLink DVD Suite Deluxe (HKLM\...\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 5.5.1019 - CyberLink Corp.)
Google Chrome (HKLM\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Hewlett-Packard Active Check (HKLM\...\{254C37AA-6B72-4300-84F6-98A82419187E}) (Version: 1.1.11.0 - Hewlett-Packard) Hidden
Hewlett-Packard Asset Agent for Health Check (HKLM\...\{669D4A35-146B-4314-89F1-1AC3D7B88367}) (Version: 2.0.62.5 - HP) Hidden
HP Advisor (HKLM\...\{73A43E42-3658-4DD9-8551-FACDA3632538}) (Version: 3.1.9152.3107 - Hewlett-Packard)
HP Customer Feedback (HKLM\...\{9DBA770F-BF73-4D39-B1DF-6035D95268FC}) (Version: 1.0.0 - Hewlett-Packard) Hidden
HP Easy Setup - Frontend (HKLM\...\{9885A11E-60E4-417C-B58B-8B31B21C0B8A}) (Version: 5.4.0.2430 - Hewlett-Packard)
HP On-Screen Cap/Num/Scroll Lock Indicator (HKLM\...\OsdMaestro) (Version: - Hewlett-Packard)
HP Photosmart Essential 2.5 (HKLM\...\HP Photosmart Essential) (Version: 2.5 - HP)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - )
Java 8 Update 91 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation)
K-Lite Codec Pack 10.6.5 Basic (HKLM\...\KLiteCodecPack_is1) (Version: 10.6.5 - )
LabelPrint (HKLM\...\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.2.2209 - CyberLink Corp.)
LightScribe System Software (HKLM\...\{7F10292C-A190-4176-A665-A1ED3478DF86}) (Version: 1.18.3.2 - LightScribe)
LightScribe Template Labeler (HKLM\...\{3EBA6E7C-3DF6-48AE-B87B-4CAFB2C1C3F7}) (Version: 1.10.13.1 - LightScribe)
Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}) (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\{3C3901C5-3455-3E0A-A214-0B093A5070A6}) (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Home and Student 60 day trial (HKLM\...\OfficeTrial) (Version: - )
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.363 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Works (HKLM\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 52.9.0 ESR (x86 en-US) (HKLM\...\Mozilla Firefox 52.9.0 ESR (x86 en-US)) (Version: 52.9.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 52.9.0.6746 - Mozilla)
MSN (HKLM\...\MSNINST) (Version: - )
muvee autoProducer 6.1 (HKLM\...\{E8C2622C-9FF1-4F60-8008-A0208154F9F3}) (Version: 6.10.050 - muvee Technologies)
Power2Go (HKLM\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.3417 - CyberLink Corp.)
PowerDirector (HKLM\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 6.5.2209 - CyberLink Corp.)
Python 2.5 (HKLM\...\{0A2C5854-557E-48C8-835A-3B9F074BDCAA}) (Version: 2.5.150 - Martin v. Löwis)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5548 - Realtek Semiconductor Corp.)
RTC Client API v1.2 (HKLM\...\{44CDBD1B-89FB-4E02-8319-2A4C550F664A}) (Version: 1.2.0000 - Microsoft)
Snapfish Picture Mover (HKLM\...\{029B5901-1F27-4347-9923-E8ACC8F54E15}) (Version: 1.9.0.16 - HP Snapfish)
Soft Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1) (Version: 7.74.00 - Conexant Systems)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WeatherBug Gadget (HKLM\...\{209CDA54-D390-46A2-A97C-7BF61734418D}) (Version: 1.0.0.6 - AWS Convergence Technologies) Hidden
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Windows -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2022-12-15] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2022-12-15] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2022-12-15] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2008-03-25] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2022-12-15] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes Corporation -> Malwarebytes)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2022-12-15 23:08 - 2022-12-15 23:08 - 048936448 _____ () [File not signed] C:\Program Files\AVAST Software\Avast\libcef.dll
2017-08-09 23:28 - 2016-09-06 11:00 - 000147456 _____ () [File not signed] C:\Users\John\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libegl.dll
2017-08-09 23:28 - 2016-09-06 11:00 - 005197312 _____ () [File not signed] C:\Users\John\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libglesv2.dll
2017-02-23 16:47 - 2017-02-23 16:47 - 000752128 _____ (AOL Inc.) [File not signed] [File is in use] C:\Program Files\AIM\acccore.dll
2017-02-23 16:47 - 2017-02-23 16:47 - 001208320 _____ (AOL Inc.) [File not signed] C:\Program Files\AIM\coolcore61.dll
2017-02-23 16:47 - 2017-02-23 16:47 - 000252928 _____ (AOL Inc.) [File not signed] C:\Program Files\AIM\xprt6.dll
2010-01-06 01:03 - 2010-01-06 01:03 - 000163840 _____ (AOL Inc.) [File not signed] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 000477592 _____ (Avast Software s.r.o. -> Avast Software) [File not signed] [File is in use] C:\Program Files\AVAST Software\Avast\defs\22121604\arPot.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 000378264 _____ (Avast Software s.r.o. -> Avast Software) [File not signed] [File is in use] C:\Program Files\AVAST Software\Avast\defs\22121604\aswArray.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 000566680 _____ (Avast Software s.r.o. -> Avast Software) [File not signed] [File is in use] C:\Program Files\AVAST Software\Avast\defs\22121604\aswCmnBS.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 000440728 _____ (Avast Software s.r.o. -> Avast Software) [File not signed] [File is in use] C:\Program Files\AVAST Software\Avast\defs\22121604\aswCmnIS.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 000172952 _____ (Avast Software s.r.o. -> Avast Software) [File not signed] [File is in use] C:\Program Files\AVAST Software\Avast\defs\22121604\aswCmnOS.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 001753496 _____ (Avast Software s.r.o. -> Avast Software) [File not signed] [File is in use] C:\Program Files\AVAST Software\Avast\defs\22121604\aswEngin.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 000613784 _____ (Avast Software s.r.o. -> Avast Software) [File not signed] [File is in use] C:\Program Files\AVAST Software\Avast\defs\22121604\aswFiDb.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 000741272 _____ (Avast Software s.r.o. -> Avast Software) [File not signed] [File is in use] C:\Program Files\AVAST Software\Avast\defs\22121604\aswRep.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 000066456 _____ (Avast Software s.r.o. -> Avast Software) [File not signed] [File is in use] C:\Program Files\AVAST Software\Avast\defs\22121604\uiExt.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 000559000 _____ (Avast Software s.r.o. -> Avast Software) [File not signed] C:\Program Files\AVAST Software\Avast\defs\22121604\aswCleanerDLL.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 005220056 _____ (Avast Software s.r.o. -> AVAST Software) [File not signed] C:\Program Files\AVAST Software\Avast\defs\22121604\bcuengine.dll
2022-12-16 07:57 - 2022-12-16 07:57 - 002467224 _____ (Avast Software s.r.o. -> AVAST Software) [File not signed] C:\Program Files\AVAST Software\Avast\defs\22121604\swhealthex2.dll
2022-12-15 22:44 - 2022-12-15 22:44 - 002387776 _____ (AVAST Software s.r.o. -> The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\AVAST Software\Avast\libcrypto-1_1.dll
2022-12-15 22:44 - 2022-12-15 22:44 - 000512832 _____ (AVAST Software s.r.o. -> The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\AVAST Software\Avast\libssl-1_1.dll
2009-03-17 12:25 - 2009-03-17 12:25 - 000033792 _____ (Hewlett-Packard Company) [File not signed] C:\Program Files\Common Files\LightScribe\LSLog.dll
2009-03-17 12:25 - 2009-03-17 12:25 - 000110592 _____ (Hewlett-Packard Company) [File not signed] C:\Program Files\Common Files\LightScribe\LSSProxy.dll
2022-12-15 16:37 - 2018-05-01 11:10 - 001137152 _____ (Igor Pavlov) [File not signed] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\7z.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Version 8) (Whitelisted) ==========
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=hp-avast&type=avastbcl
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2314338359-2121603862-2684469121-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=hp-avast&type=avastbcl
HKU\S-1-5-21-2314338359-2121603862-2684469121-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKLM -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKLM -> {0B4A10D1-FBD6-451d-BFDA-F03252B05984} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&query={searchTerms}&invocationType=tb50trie7
SearchScopes: HKLM -> {55C1D719-5274-4281-A484-D799AE2BA7E5} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-psdt
SearchScopes: HKLM -> {6FFC5051-438A-4405-9F3C-54DFE9532F52} URL = hxxp://www.ask.com/web?q={searchTerms}&l=dis&o=uscqd
SearchScopes: HKLM -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2314338359-2121603862-2684469121-1000 -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2314338359-2121603862-2684469121-1000 -> {0B4A10D1-FBD6-451d-BFDA-F03252B05984} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&query={searchTerms}&invocationType=tb50trie7
SearchScopes: HKU\S-1-5-21-2314338359-2121603862-2684469121-1000 -> {55C1D719-5274-4281-A484-D799AE2BA7E5} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-psdt
SearchScopes: HKU\S-1-5-21-2314338359-2121603862-2684469121-1000 -> {8f6ecace-7280-4a70-834a-38c6fca77ee7} URL = hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=2706&query={searchTerms}&invocationType=bu10aiminstabie7
SearchScopes: HKU\S-1-5-21-2314338359-2121603862-2684469121-1000 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-05-10] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-10] (Oracle America, Inc. -> Oracle Corporation)
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-06-07] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 05:23 - 2022-12-16 07:55 - 000000028 _____ C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\hp\bin\Python;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
HKU\S-1-5-21-2314338359-2121603862-2684469121-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\Wallpaper\img24.jpg
DNS Servers: 68.105.28.11 - 68.105.29.11
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk => C:\Windows\pss\Snapfish Media Detector.lnk.CommonStartup
MSCONFIG\startupreg: HP Health Check Scheduler => [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
MSCONFIG\startupreg: HPADVISOR => C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW,SYSTRAY
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) C:\Windows\system32\dfsr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) C:\Windows\system32\dfsr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [WinCollab-In-TCP] => (Allow) C:\Program Files\Windows Collaboration\WinCollab.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [WinCollab-Out-TCP] => (Allow) C:\Program Files\Windows Collaboration\WinCollab.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [WinCollab-In-UDP] => (Allow) C:\Program Files\Windows Collaboration\WinCollab.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [WinCollab-Out-UDP] => (Allow) C:\Program Files\Windows Collaboration\WinCollab.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{E8483AA0-B6A2-4E65-8E1A-487AF1D60F96}] => (Allow) c:\Program Files\Cyberlink\PowerDirector\PDR.EXE (CyberLink -> CyberLink Corp.)
FirewallRules: [{FF70F5DB-A77F-4995-82F4-F392FE088383}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe (EarthLink -> EarthLink, Inc.)
FirewallRules: [{7CA489F2-040E-4A14-B3CE-841374A39D14}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe (EarthLink -> EarthLink, Inc.)
FirewallRules: [{6C9B8201-7929-4920-92D0-FBF369AB8F02}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe (EarthLink -> EarthLink, Inc.)
FirewallRules: [{793C14E1-E9F1-43A0-81E3-5990CECA9272}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe (EarthLink -> EarthLink, Inc.)
FirewallRules: [{409E208E-3A8E-4C91-A4EA-CF32EC792BE1}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe (EarthLink -> EarthLink, Inc.)
FirewallRules: [{32E8602A-B424-4804-8652-6DD5FCE87884}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe (EarthLink -> EarthLink, Inc.)
FirewallRules: [{D2DFA983-1E8D-460E-89CB-0352F1AB2BA8}] => (Allow) C:\Program Files\Common Files\aol\Loader\aolload.exe (AOL Inc. -> AOL Inc.)
FirewallRules: [{32AFA6F4-899C-4C3C-9130-749E79257543}] => (Allow) C:\Program Files\Common Files\aol\Loader\aolload.exe (AOL Inc. -> AOL Inc.)
FirewallRules: [{B862DD3D-630A-478D-9901-8D589C31EB1C}] => (Allow) C:\Program Files\Common Files\aol\Loader\aolload.exe (AOL Inc. -> AOL Inc.)
FirewallRules: [{18954565-0C09-4879-942F-5DD029B03AB8}] => (Allow) C:\Program Files\Common Files\aol\Loader\aolload.exe (AOL Inc. -> AOL Inc.)
FirewallRules: [TCP Query User{33B25B29-68F1-4854-89D9-99CBA08971B1}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{B4C7D4F5-239B-43BA-9A0E-231DD5044C73}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{60D32775-8659-4D06-B54C-3B6171048679}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe => No File
FirewallRules: [{8B1743DE-136A-4409-90EC-8BBACEFEAF0A}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe => No File
FirewallRules: [{4F87DBE6-6356-42F1-824B-BDCF6BDFBB9F}] => (Allow) C:\Program Files\AIM\aim.exe (AOL Inc. -> AOL Inc.)
FirewallRules: [{98E15AFD-DED9-4FE8-B9CF-D50DE8A89A1E}] => (Allow) C:\Program Files\AIM\aim.exe (AOL Inc. -> AOL Inc.)
FirewallRules: [TCP Query User{370899B0-DC0F-4C66-A99D-862E3F33507D}C:\windows\system32\wuauclt.exe] => (Block) C:\windows\system32\wuauclt.exe (Microsoft Windows Component Publisher -> Microsoft Corporation)
FirewallRules: [UDP Query User{6B4D3CD6-142F-42B2-80D9-BCFCF612DE37}C:\windows\system32\wuauclt.exe] => (Block) C:\windows\system32\wuauclt.exe (Microsoft Windows Component Publisher -> Microsoft Corporation)
FirewallRules: [{2F1C4541-2B64-4B4A-8EA8-0F3ED7B890C0}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6D78CD1A-7F6A-4A87-A8AE-46A55023C5E5}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{A5E60A3B-4561-424E-8A18-174F42E21003}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{EB8C3515-5A35-4A71-A72B-F5E61F7E2008}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{2F134E04-97DC-49A8-B255-2B36AE9A218C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{65921389-A4FF-4AF2-B28E-9A38485FE263}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{9DCEE7C7-A0AC-48AD-83A9-C1055C5ABA0D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc -> Google Inc.)
FirewallRules: [{7CFFBEFF-43DB-4A1C-8833-27560307053A}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe (AVAST Software s.r.o. -> AVAST Software)
FirewallRules: [{2F3596B0-FED9-43BD-A9A0-AD47A640FA32}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe (AVAST Software s.r.o. -> AVAST Software)
StandardProfile\AuthorizedApplications: [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe] => Enabled:Earthlink
==================== Restore Points =========================
09-12-2022 13:16:18 Scheduled Checkpoint
10-12-2022 16:41:37 Scheduled Checkpoint
12-12-2022 04:01:08 Scheduled Checkpoint
14-12-2022 00:34:53 Scheduled Checkpoint
14-12-2022 12:26:41 Restore Point Created by FRST
14-12-2022 21:11:56 Restore Point Created by FRST
15-12-2022 12:19:37 Scheduled Checkpoint
15-12-2022 21:23:05 Removed HP Advisor.
15-12-2022 21:28:47 Removed HP Update.
15-12-2022 21:39:32 Removed HP Customer Experience Enhancements
15-12-2022 21:56:35 Installed Crystal Security
==================== Faulty Device Manager Devices ============
Name: 6TO4 Adapter
Description: Microsoft 6to4 Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
Name: 6TO4 Adapter
Description: Microsoft 6to4 Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
Name: Microsoft 6to4 Adapter #3
Description: Microsoft 6to4 Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
Name: isatap.{F05BCA3E-C3F5-4180-9854-C7D45E1D1F7F}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
Name: isatap.{51C707ED-47E5-4CD2-9358-696DFB65C052}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
Name: isatap.{D198F27B-6061-4FB6-BF4D-9C66D7E0C0D3}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
==================== Event log errors: ========================
Application errors:
==================
Error: (12/16/2022 09:50:03 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 11) (User: )
Description: Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
Error: (12/16/2022 09:50:03 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 11) (User: )
Description: Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
Error: (12/16/2022 09:50:03 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 11) (User: )
Description: Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
Error: (12/16/2022 09:50:03 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 11) (User: )
Description: Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
Error: (12/16/2022 09:50:03 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 11) (User: )
Description: Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
Error: (12/16/2022 09:50:03 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 11) (User: )
Description: Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
Error: (12/16/2022 09:50:03 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 11) (User: )
Description: Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
Error: (12/16/2022 09:50:03 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 11) (User: )
Description: Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
System errors:
=============
==================== Memory info ===========================
BIOS: American Megatrends Inc. 5.16 10/01/2007
Motherboard: ASUSTeK Computer INC. Lancaster8
Processor: Intel(R) Pentium(R) Dual CPU E2180 @ 2.00GHz
Percentage of memory in use: 94%
Total physical RAM: 2038.64 MB
Available physical RAM: 105.24 MB
Total Virtual: 4322.56 MB
Available Virtual: 1080.38 MB
==================== Drives ================================
Drive c: (COMPAQ) (Fixed) (Total:326.01 GB) (Free:245.57 GB) (Model: ST3360320AS ATA Device) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (FACTORY_IMAGE) (Fixed) (Total:9.34 GB) (Free:1.26 GB) (Model: ST3360320AS ATA Device) NTFS ==>[system with boot components (obtained from drive)]
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 335.4 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=326 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=9.3 GB) - (Type=07 NTFS)
==================== End of Addition.txt =======================