I can't get rid of this nasty bugger. Picked up by Bitdefender, often says deleted, cleaned but it always comes back.
Any help would be huge-thanks!
Any help would be huge-thanks!
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-02-2017
Ran by Glen (administrator) on DESKTOP (20-02-2017 00:18:34)
Running from C:\Users\Glen\Desktop
Loaded Profiles: Glen (Available Profiles: Glen & UpdatusUser & Administrator)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Andrea Electronics Corporation) C:\Windows\System32\AERTSrv.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
() C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\FAX Utility\FUFAXSTM.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\FAX Utility\FUFAXRCV.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(WIBU-SYSTEMS AG) C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Akamai Technologies, Inc.) C:\Users\Glen\AppData\Local\Akamai\netsession_win.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe
() C:\Program Files\USB Sharing\usbshare.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Akamai Technologies, Inc.) C:\Users\Glen\AppData\Local\Akamai\netsession_win.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1980416 2013-12-18] (Wondershare)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4907008 2008-01-17] (Realtek Semiconductor)
HKLM\...\Run: [ISUSScheduler] => C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2006-10-03] (Macrovision Corporation)
HKLM\...\Run: [ISUSPM Startup] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2006-10-03] (Macrovision Corporation)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [174872 2007-03-21] (Intel Corporation)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM\...\Run: [FUFAXSTM] => C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [863848 2014-05-26] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [FUFAXRCV] => C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe [642664 2014-05-26] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1065024 2014-06-10] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1045720 2015-09-14] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe [1865664 2015-06-12] (Bitdefender)
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-3490785829-169181324-3712256341-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-3490785829-169181324-3712256341-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-3490785829-169181324-3712256341-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Glen\AppData\Local\Akamai\netsession_win.exe [4490200 2017-01-03] (Akamai Technologies, Inc.) <===== ATTENTION
HKU\S-1-5-21-3490785829-169181324-3712256341-1000\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe [687864 2017-01-31] (Bitdefender)
HKU\S-1-5-21-3490785829-169181324-3712256341-1000\...\Run: [*sneu<*>] => "C:\Users\Glen\AppData\Local\1e17e\9fab6.cc1c98" <===== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-21-3490785829-169181324-3712256341-1000\...\MountPoints2: F - F:\AutoRun\AutoRun.exe
HKU\S-1-5-21-3490785829-169181324-3712256341-1000\...\MountPoints2: {60deb600-6e3c-11e3-913b-001aa08d1be6} - O:\InnoTabSetup.exe
HKU\S-1-5-21-3490785829-169181324-3712256341-1000\...\MountPoints2: {ddc90d2f-8f2b-11de-9f2c-001aa08d1be6} - L:\ImageViewer4.exe -COPYFILE
HKU\S-1-5-21-3490785829-169181324-3712256341-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Aurora.scr [1370624 2008-01-19] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [__SafeBox1] -> {152C96EB-288E-4EDC-B7C6-D21F8250ADF3} => -> No File
ShellIconOverlayIdentifiers: [__SafeBox2] -> {342DAA0B-D796-460D-8566-901E08A1CCAD} => -> No File
ShellIconOverlayIdentifiers: [__SafeBox3] -> {57595DAE-1AE1-4D97-A49E-67CBB53B52DF} => -> No File
ShellIconOverlayIdentifiers: [__SafeBox4] -> {33816773-98AE-4723-ADE0-EBE54C8B5A67} => -> No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk [2008-09-04]
ShortcutTarget: APC UPS Status.lnk -> C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DataViz Inc Messenger.lnk [2008-07-18]
ShortcutTarget: DataViz Inc Messenger.lnk -> C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HotSync Manager.lnk [2008-07-18]
ShortcutTarget: HotSync Manager.lnk -> C:\Program Files\palmOne\Hotsync.exe (No File)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageMixer 3 SE Camera Monitor Ver.3.lnk [2011-05-29]
ShortcutTarget: ImageMixer 3 SE Camera Monitor Ver.3.lnk -> C:\Program Files\PIXELA\ImageMixer 3 SE Ver.3\CameraMonitor.exe (PIXELA CORPORATION)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\USB Sharing.lnk [2008-09-05]
ShortcutTarget: USB Sharing.lnk -> C:\Program Files\USB Sharing\usbshare.exe ()
BootExecute:
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{98C63B37-7ECC-43D4-AA4D-322215D7E7A2}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-3490785829-169181324-3712256341-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
URLSearchHook: HKU\S-1-5-21-3490785829-169181324-3712256341-1000 - (No Name) - {a94e8dc9-07aa-45a7-8af2-a0375473a5cd} - No File
URLSearchHook: HKU\S-1-5-21-3490785829-169181324-3712256341-1000 - (No Name) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - No File
URLSearchHook: HKU\S-1-5-21-3490785829-169181324-3712256341-1000 - (No Name) - {f897eb0e-a3a4-46c3-80eb-2729699d8892} - No File
URLSearchHook: HKU\S-1-5-21-3490785829-169181324-3712256341-1000 - (No Name) - {f4c28532-b9d0-4950-a2df-e83f9929242b} - C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll No File
SearchScopes: HKLM -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=756&hspart=avast&hsimp=yhs-corp&p={searchTerms}
SearchScopes: HKLM -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=756&hspart=avast&hsimp=yhs-corp&p={searchTerms}
SearchScopes: HKLM -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2925418
SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-3490785829-169181324-3712256341-1000 -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=756&hspart=avast&hsimp=yhs-corp&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3490785829-169181324-3712256341-1000 -> {4DFE95E1-324C-4BF8-BDE1-266927F9598A} URL = hxxps://search.yahoo.com/search?p={searchTerms}&intl=us&fr=yset_ie_syc_oracle&type=orcl_default&partnerexternal-oracle=external-oracle
SearchScopes: HKU\S-1-5-21-3490785829-169181324-3712256341-1000 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=756&hspart=avast&hsimp=yhs-corp&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3490785829-169181324-3712256341-1000 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.smilebox.com/?search={searchTerms}&loc=SB_IE_DS&a=6R8FRqYkDD
BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-04-03] (Bitdefender)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-01-21] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-01-21] (Oracle Corporation)
Toolbar: HKLM - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll [2015-04-03] (Bitdefender)
Toolbar: HKU\S-1-5-21-3490785829-169181324-3712256341-1000 -> No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
Toolbar: HKU\S-1-5-21-3490785829-169181324-3712256341-1000 -> No Name - {F897EB0E-A3A4-46C3-80EB-2729699D8892} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2006-06-05] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: pooixovy.default-1413691062373
FF ProfilePath: C:\Users\Glen\AppData\Roaming\Mozilla\Firefox\Profiles\pooixovy.default-1413691062373 [2017-02-20]
FF NewTab: Mozilla\Firefox\Profiles\pooixovy.default-1413691062373 -> about:newtab
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\pooixovy.default-1413691062373 -> Yahoo! (Avast)
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\pooixovy.default-1413691062373 -> DuckDuckGo
FF DefaultSearchUrl: Mozilla\Firefox\Profiles\pooixovy.default-1413691062373 -> hxxps://search.yahoo.com/yhs/search
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\pooixovy.default-1413691062373 -> Yahoo! (Avast)
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\pooixovy.default-1413691062373 -> Yahoo! (Avast)
FF Homepage: Mozilla\Firefox\Profiles\pooixovy.default-1413691062373 -> hxxps://duckduckgo.com/
FF SearchPlugin: C:\Users\Glen\AppData\Roaming\Mozilla\Firefox\Profiles\pooixovy.default-1413691062373\searchplugins\duckduckgo.xml [2014-10-18]
FF SearchPlugin: C:\Users\Glen\AppData\Roaming\Mozilla\Firefox\Profiles\pooixovy.default-1413691062373\searchplugins\yahoo-avast.xml [2017-01-22]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: (Microsoft .NET Framework Assistant) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-09-02] [not signed]
FF HKLM\...\Firefox\Extensions: [bdwteffv19@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\\bdwteff
FF Extension: (Bitdefender Wallet) - C:\Program Files\Bitdefender\Bitdefender 2015\\bdwteff [2017-01-31]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext
FF Extension: (Bitdefender Antispam Toolbar) - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext [2015-06-22] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-14] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin: @checkpoint.com/FFApi -> C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll [No File]
FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-21] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-21] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-01-18] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-01-18] (NVIDIA Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-09-09]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [fabcmochhfpldjekobfaaggijgohadih] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [phfmiknmhngmmlcppkpmbnopohlnfpbh] - C:\Users\Glen\AppData\Local\CRE\phfmiknmhngmmlcppkpmbnopohlnfpbh.crx [2012-09-09]
CHR HKU\S-1-5-21-3490785829-169181324-3712256341-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [phfmiknmhngmmlcppkpmbnopohlnfpbh] - C:\Users\Glen\AppData\Local\CRE\phfmiknmhngmmlcppkpmbnopohlnfpbh.crx [2012-09-09]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AERTFilters; C:\Windows\system32\AERTSrv.exe [77824 2007-12-05] (Andrea Electronics Corporation)
S4 Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [194240 2006-12-03] (Symantec Corporation)
S3 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2015\bdparentalservice.exe [69880 2014-12-09] (Bitdefender)
R2 CodeMeter.exe; C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe [3105144 2013-11-27] (WIBU-SYSTEMS AG)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc.exe [126128 2012-05-17] (Seiko Epson Corporation)
S3 getPlusHelper; C:\Program Files\NOS\bin\getPlus_Helper.dll [68000 2010-03-22] (NOS Microsystems Ltd.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
S4 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2011-03-04] (Hewlett-Packard Company) [File not signed]
S4 LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE [2541248 2006-12-03] (Symantec Corporation)
S4 LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [517768 2007-03-12] (Symantec Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S4 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [81704 2013-07-08] (Bitdefender)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe [54424 2014-10-27] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe [1335176 2017-01-31] (Bitdefender)
R2 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [185856 2012-07-12] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
S2 CLTNetCnService; "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [X]
S2 LiveUpdate Notice Ex; "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [X]
S4 stllssvr; "C:\Program Files\Common Files\SureThing Shared\stllssvr.exe" [X]
S2 ZAPrivacyService; "C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1258376 2017-01-26] (BitDefender)
R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [252184 2015-05-29] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [696632 2017-01-26] (BitDefender)
R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [77632 2014-12-15] (BitDefender LLC)
R1 bdftdif; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdftdif.sys [131432 2012-02-07] (BitDefender LLC)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [66832 2015-01-09] (BitDefender SRL)
R1 bdselfpr; C:\Program Files\Bitdefender\Bitdefender 2015\bdselfpr.sys [135600 2013-07-26] (BitDefender LLC)
R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [72704 2012-04-17] (BitDefender)
R1 CLBStor; C:\Windows\system32\Drivers\CLBStor.sys [16048 2007-06-04] (Cyberlink Co.,Ltd.)
R2 CLBUDF; C:\Windows\system32\Drivers\CLBUDF.sys [162096 2007-06-04] (CyberLink Corporation.)
S3 Dot4Scan; C:\Windows\System32\DRIVERS\Dot4Scan.sys [10752 2008-01-19] (Microsoft Corporation)
R1 ElRawDisk; C:\Windows\system32\drivers\elrawdsk.sys [12800 2007-09-20] (EldoS Corporation) [File not signed]
S3 FlyUsb; C:\Windows\System32\DRIVERS\FlyUsb.sys [19456 2008-04-01] (LeapFrog) [File not signed]
S3 grmnusb; C:\Windows\System32\drivers\grmnusb.sys [9344 2009-04-17] (GARMIN Corp.) [File not signed]
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [173832 2015-04-29] (BitDefender LLC)
S3 PalmUSBD; C:\Windows\System32\drivers\PalmUSBD.sys [16640 2007-12-04] (PalmSource, Inc.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2013-10-08] (Kaspersky Lab ZAO)
S0 Lbd; system32\DRIVERS\Lbd.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 vsdatant7; System32\drivers\vsdatant.win7.sys [X]
S3 XE102Mp5; System32\Drivers\XE102Mp5.sys [X]
S3 XE102Sp5; System32\Drivers\XE102Sp5.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-20 00:18 - 2017-02-20 00:20 - 00021763 _____ C:\Users\Glen\Desktop\FRST.txt
2017-02-20 00:16 - 2017-02-20 00:18 - 00000000 ____D C:\FRST
2017-02-20 00:15 - 2017-02-20 00:15 - 01764864 _____ (Farbar) C:\Users\Glen\Desktop\FRST.exe
2017-02-20 00:01 - 2017-02-20 00:01 - 00000000 ____H C:\ProgramData\cm-lock
2017-02-19 23:54 - 2017-02-19 23:57 - 00002178 _____ C:\Users\Glen\Desktop\Rkill.txt
2017-02-19 21:44 - 2017-02-19 21:44 - 00001994 _____ C:\Users\Glen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Vista Upgrade Advisor.lnk
2017-02-19 11:54 - 2017-02-19 14:13 - 00000000 ____D C:\Users\Glen\Desktop\Old Files
2017-02-18 21:20 - 2017-02-18 21:20 - 00422664 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2017-02-03 00:19 - 2017-02-03 00:19 - 00000000 ____D C:\239deb8e4b0bd0ad0d434b4b
2017-02-03 00:17 - 2017-02-03 00:17 - 00000000 ____D C:\975cafc51b3f32eaa4bd77e09f6d1040
2017-02-02 15:51 - 2017-02-02 15:53 - 00000000 ____D C:\Users\Glen\AppData\Local\Roblox
2017-02-01 17:18 - 2017-02-01 17:18 - 00000000 ____D C:\ProgramData\Roblox
2017-02-01 17:17 - 2017-02-02 16:00 - 00000163 _____ C:\Users\Glen\AppData\LocalLow\rbxcsettings.rbx
2017-02-01 17:17 - 2017-02-01 17:17 - 00000000 ____D C:\Program Files\Roblox
2017-01-27 10:20 - 2017-01-27 10:21 - 00000000 ____D C:\Users\Glen\AppData\Local\AvgSetupLog
2017-01-26 11:30 - 2017-01-26 11:30 - 00000385 _____ C:\Windows\system32\user_gensett.xml
2017-01-26 09:22 - 2017-01-26 09:22 - 00935286 _____ C:\ProgramData\1485439235.bdinstall.bin
2017-01-26 09:19 - 2017-01-26 09:19 - 00000308 ____H C:\bdr-cf01
2017-01-26 09:18 - 2017-01-26 09:18 - 00001959 _____ C:\Users\Public\Desktop\Bitdefender Total Security 2015.lnk
2017-01-26 09:18 - 2017-01-26 09:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
2017-01-26 09:17 - 2015-01-09 11:58 - 00066832 _____ (BitDefender SRL) C:\Windows\system32\Drivers\bdsandbox.sys
2017-01-26 09:17 - 2015-01-09 11:44 - 00074000 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin.dll
2017-01-26 09:17 - 2015-01-09 11:44 - 00026624 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuh.dll
2017-01-26 09:17 - 2014-12-15 17:56 - 00077632 _____ (BitDefender LLC) C:\Windows\system32\Drivers\BdfNdisf6.sys
2017-01-26 09:17 - 2012-04-17 14:40 - 00072704 _____ (BitDefender) C:\Windows\system32\Drivers\bdvedisk.sys
2017-01-26 09:16 - 2017-01-26 09:47 - 01258376 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys
2017-01-26 09:16 - 2017-01-26 09:47 - 00696632 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys
2017-01-26 09:16 - 2015-05-29 09:50 - 00252184 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys
2017-01-26 09:06 - 2017-01-26 09:23 - 00000000 ____D C:\Users\Glen\AppData\Roaming\Bitdefender
2017-01-26 09:06 - 2017-01-26 09:19 - 00253404 ____H C:\bdr-ld01
2017-01-26 09:06 - 2017-01-26 09:19 - 00009216 ____H C:\bdr-ld01.mbr
2017-01-26 09:06 - 2015-05-19 15:52 - 39533906 ____H C:\bdr-im01.gz
2017-01-26 09:06 - 2012-08-15 15:28 - 02294848 ____H C:\bdr-bz01
2017-01-26 09:00 - 2017-01-26 09:21 - 00000000 ____D C:\ProgramData\Bitdefender
2017-01-26 09:00 - 2017-01-26 09:06 - 00000000 ____D C:\Program Files\Bitdefender
2017-01-26 09:00 - 2017-01-26 09:00 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2017-01-26 09:00 - 2015-04-29 13:31 - 00173832 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2017-01-26 08:56 - 2017-01-26 08:56 - 00000000 ____D C:\Users\Administrator\AppData\Local\CrashDumps
2017-01-26 08:53 - 2017-01-26 08:53 - 00084944 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2017-01-26 08:53 - 2017-01-26 08:53 - 00000000 ____D C:\Users\Administrator\AppData\Local\AvgSetupLog
2017-01-26 08:52 - 2017-01-26 08:52 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2017-01-26 08:51 - 2017-01-26 08:51 - 00000951 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-01-26 08:51 - 2017-01-26 08:51 - 00000946 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-01-26 08:51 - 2017-01-26 08:51 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Epson
2017-01-26 08:51 - 2017-01-26 08:51 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Apple Computer
2017-01-26 08:51 - 2017-01-26 08:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\Wondershare
2017-01-26 08:51 - 2017-01-26 08:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\Avg
2017-01-26 08:51 - 2017-01-26 08:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\Apple Computer
2017-01-26 08:50 - 2017-01-26 08:51 - 00000000 ____D C:\Users\Administrator
2017-01-26 08:50 - 2017-01-26 08:50 - 00000917 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2017-01-26 08:50 - 2017-01-26 08:50 - 00000020 ___SH C:\Users\Administrator\ntuser.ini
2017-01-26 08:50 - 2017-01-26 08:50 - 00000000 _SHDL C:\Users\Administrator\My Documents
2017-01-26 08:50 - 2017-01-26 08:50 - 00000000 _SHDL C:\Users\Administrator\Documents\My Videos
2017-01-26 08:50 - 2017-01-26 08:50 - 00000000 _SHDL C:\Users\Administrator\Documents\My Pictures
2017-01-26 08:50 - 2017-01-26 08:50 - 00000000 _SHDL C:\Users\Administrator\Documents\My Music
2017-01-26 08:50 - 2010-03-27 09:21 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia
2017-01-26 08:50 - 2006-11-02 07:37 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Media Center Programs
2017-01-25 23:16 - 2017-01-25 23:16 - 00000000 ____D C:\74b5dafec5ddf39806d5d11a11
2017-01-25 23:03 - 2017-01-25 23:03 - 00000000 ____D C:\a51f592706bbcae6374e3a720ddf
2017-01-25 22:35 - 2017-01-25 22:35 - 00000000 ____D C:\2e35ff875d9f9e874ec13ed34c92e8
2017-01-21 23:53 - 2017-01-21 23:53 - 00000000 ____D C:\Users\Glen\AppData\Local\CEF
2017-01-21 23:51 - 2017-01-27 10:39 - 00000000 ____D C:\ProgramData\Avg
2017-01-21 23:51 - 2017-01-21 23:51 - 00000000 ____D C:\Users\Glen\AppData\Local\Avg
2017-01-21 23:44 - 2017-01-21 23:44 - 00000000 ____D C:\Users\Glen\AppData\Roaming\Yahoo
2017-01-21 23:44 - 2017-01-21 23:44 - 00000000 ____D C:\Users\Glen\AppData\Local\YSearchUtil
2017-01-21 23:44 - 2017-01-21 23:44 - 00000000 ____D C:\Program Files\Yahoo!
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-20 00:19 - 2016-11-16 17:24 - 00000000 ____D C:\Users\Glen\AppData\LocalLow\Mozilla
2017-02-20 00:07 - 2006-11-02 06:18 - 00000000 ____D C:\Windows\inf
2017-02-20 00:07 - 2006-11-02 05:33 - 00763670 _____ C:\Windows\system32\PerfStringBackup.INI
2017-02-20 00:02 - 2016-02-13 13:02 - 00000917 _____ C:\Windows\Tasks\EPSON WF-4630 Series Update {E3062EAB-2698-476F-8702-41D3C9FF90BE}.job
2017-02-20 00:02 - 2016-02-13 13:02 - 00000731 _____ C:\Windows\Tasks\EPSON WF-4630 Series Invitation {E3062EAB-2698-476F-8702-41D3C9FF90BE}.job
2017-02-20 00:01 - 2008-02-16 11:09 - 00000000 ____D C:\ProgramData\NVIDIA
2017-02-20 00:01 - 2006-11-02 08:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-20 00:01 - 2006-11-02 07:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2017-02-20 00:01 - 2006-11-02 07:47 - 00003568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2017-02-20 00:00 - 2015-03-28 14:50 - 00451022 _____ C:\bdlog.txt
2017-02-20 00:00 - 2006-11-02 08:01 - 00032564 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-02-19 23:57 - 2012-04-08 01:46 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-02-19 22:28 - 2016-12-28 10:30 - 00000000 ____D C:\Users\Glen\AppData\Local\CrashDumps
2017-02-19 12:44 - 2006-11-02 07:47 - 00337320 _____ C:\Windows\system32\FNTCACHE.DAT
2017-02-19 12:41 - 2010-05-18 22:51 - 00001356 _____ C:\Users\Glen\AppData\Local\d3d9caps.dat
2017-02-19 12:40 - 2007-08-13 19:41 - 00552296 _____ C:\Windows\ntbtlog.txt
2017-02-18 20:31 - 2007-12-10 09:05 - 00000000 ____D C:\ProgramData\Lavasoft
2017-02-14 20:57 - 2012-04-08 01:46 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-02-14 20:57 - 2011-05-19 02:27 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-02-14 20:57 - 2007-08-09 16:03 - 00000000 ____D C:\Windows\system32\Macromed
2017-01-28 12:42 - 2016-11-16 10:10 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-01-27 18:23 - 2014-06-28 10:20 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2017-01-26 09:19 - 2007-08-11 12:05 - 00000000 ____D C:\Users\Glen
2017-01-26 08:58 - 2007-08-11 12:06 - 00000946 _____ C:\Users\Glen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-01-25 22:13 - 2007-10-09 20:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fellowes NEATO MediaFACE II
2017-01-24 09:02 - 2011-11-03 21:24 - 00000000 ____D C:\Users\Glen\AppData\Local\Akamai
2017-01-22 13:21 - 2014-06-28 10:20 - 00000836 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-01-22 12:09 - 2008-09-20 22:24 - 00000000 ____D C:\Program Files\lg_fwupdate
2017-01-22 12:08 - 2008-09-20 22:25 - 00000289 _____ C:\Windows\lgfwup.ini
2017-01-21 23:43 - 2015-03-28 15:41 - 00000000 ____D C:\ProgramData\Oracle
2017-01-21 23:42 - 2015-03-28 15:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-01-21 23:42 - 2007-08-09 16:03 - 00000000 ____D C:\Program Files\Java
2017-01-21 23:42 - 2007-08-09 16:03 - 00000000 ____D C:\Program Files\Common Files\Java
2017-01-21 23:40 - 2015-03-28 15:42 - 00095808 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
==================== Files in the root of some directories =======
2015-07-16 09:17 - 2015-07-16 09:17 - 0001110 _____ () C:\Users\Glen\AppData\Roaming\ConvAPIPlugin.log
2009-02-21 21:23 - 2010-02-07 23:23 - 0000164 _____ () C:\Users\Glen\AppData\Roaming\default.rss
2010-10-03 00:30 - 2010-10-20 10:20 - 0087608 _____ () C:\Users\Glen\AppData\Roaming\inst.exe
2010-10-03 00:30 - 2010-10-20 10:20 - 0007887 _____ () C:\Users\Glen\AppData\Roaming\pcouffin.cat
2010-10-03 00:30 - 2010-10-20 10:20 - 0001144 _____ () C:\Users\Glen\AppData\Roaming\pcouffin.inf
2010-10-03 00:32 - 2010-10-20 10:20 - 0000033 _____ () C:\Users\Glen\AppData\Roaming\pcouffin.log
2010-10-03 00:30 - 2010-10-20 10:20 - 0047360 _____ (VSO Software) C:\Users\Glen\AppData\Roaming\pcouffin.sys
2008-02-06 17:21 - 2016-12-18 22:49 - 0000278 _____ () C:\Users\Glen\AppData\Roaming\wklnhst.dat
2013-12-26 10:06 - 2013-12-26 13:26 - 0000941 _____ () C:\Users\Glen\AppData\Local\cookies.ini
2010-05-18 22:51 - 2017-02-19 12:41 - 0001356 _____ () C:\Users\Glen\AppData\Local\d3d9caps.dat
2007-08-11 12:41 - 2014-08-12 12:40 - 0115200 _____ () C:\Users\Glen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-07-15 17:18 - 2009-07-15 17:18 - 0004096 _____ () C:\Users\Glen\AppData\Local\keyfile3.drm
2010-10-03 20:58 - 2010-10-03 21:18 - 0000040 ___SH () C:\ProgramData\.zreglib
2017-01-26 09:22 - 2017-01-26 09:22 - 0935286 _____ () C:\ProgramData\1485439235.bdinstall.bin
2017-02-20 00:01 - 2017-02-20 00:01 - 0000000 ____H () C:\ProgramData\cm-lock
2010-03-04 21:10 - 2016-02-12 18:31 - 0023445 _____ () C:\ProgramData\hpzinstall.log
2007-08-12 19:52 - 2016-12-26 11:01 - 0009134 _____ () C:\ProgramData\LUUnInstall.LiveUpdate
Files to move or delete:
====================
C:\Users\Glen\AppData\Local\Akamai\netsession_win.exe
Some files in TEMP:
====================
2017-01-21 23:38 - 2017-01-21 23:38 - 0739904 _____ (Oracle Corporation) C:\Users\Glen\AppData\Local\Temp\jre-8u121-windows-au.exe
2017-01-27 08:47 - 2017-01-27 08:47 - 0111936 _____ (Microsoft Corporation) C:\Users\Glen\AppData\Local\Temp\MsiZap.exe
2017-01-02 10:58 - 2010-05-04 12:46 - 0353112 _____ (Microsoft Corporation) C:\Users\Glen\AppData\Local\Temp\MSNF42D.exe
2016-12-26 19:56 - 2016-12-26 19:56 - 0075264 _____ () C:\Users\Glen\AppData\Local\Temp\upd.exE
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-02-20 00:10
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-02-2017
Ran by Glen (20-02-2017 00:20:55)
Running from C:\Users\Glen\Desktop
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) (2007-08-09 20:55:55)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3490785829-169181324-3712256341-500 - Administrator - Disabled) => C:\Users\Administrator
Glen (S-1-5-21-3490785829-169181324-3712256341-1000 - Administrator - Enabled) => C:\Users\Glen
Guest (S-1-5-21-3490785829-169181324-3712256341-501 - Limited - Disabled)
UpdatusUser (S-1-5-21-3490785829-169181324-3712256341-1003 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Bitdefender Antivirus (Enabled - Up to date) {3FB17364-4FCC-0FA7-6BBF-973897395371}
AS: Bitdefender Antispyware (Enabled - Up to date) {84D09280-69F6-0029-510F-AC4AECBE19CC}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Enabled) {078AF241-05A3-0EFF-40E0-3E0D69EA140A}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
Acrobat.com (HKLM\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
Acrobat.com (Version: 2.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM\...\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated)
Adobe Download Manager (HKLM\...\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}) (Version: 1.6.2.63 - NOS Microsystems Ltd.)
Adobe Flash Player 24 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe Reader X (10.1.16) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-3490785829-169181324-3712256341-1000\...\Akamai) (Version: - Akamai Technologies, Inc)
Apple Application Support (32-bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{A75CA58D-DB9C-4D14-9428-E0C7B0F623DC}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
AviSynth 2.5 (HKLM\...\AviSynth) (Version: - )
BD/HD Advisor 1.0 (HKLM\...\{2D2D8FE2-605C-4D3C-B706-36E981E7EEF0}) (Version: - )
Bitdefender Total Security 2015 (HKLM\...\Bitdefender) (Version: 18.23.0.1604 - Bitdefender)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
bpd_scan (Version: 3.00.0000 - Hewlett-Packard) Hidden
Canon RAW Image Task for ZoomBrowser EX (HKLM\...\RAW Image Task) (Version: 0.9.3.9 - Canon Inc.)
Canon Utilities CameraWindow (HKLM\...\CameraWindowLauncher) (Version: 7.1.0.2 - Canon Inc.)
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (HKLM\...\CameraWindowDVC6) (Version: 6.4.2.16 - Canon Inc.)
Canon Utilities MyCamera (HKLM\...\MyCamera) (Version: 6.4.0.5 - Canon Inc.)
Canon Utilities RemoteCapture Task for ZoomBrowser EX (HKLM\...\RemoteCaptureTask) (Version: 1.7.1.9 - Canon Inc.)
Canon Utilities ZoomBrowser EX (HKLM\...\ZoomBrowser EX) (Version: 6.1.1.21 - Canon Inc.)
Canon ZoomBrowser EX Memory Card Utility (HKLM\...\ZoomBrowser EX Memory Card Utility) (Version: 1.1.0.8 - Canon Inc.)
Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CyberLink InstantBurn (HKLM\...\{19C64880-BBCA-11D4-9EEE-0004ACDDDB3B}) (Version: - )
Dell DataSafe (HKLM\...\{DF68383B-A940-4ABD-87FF-1D969F2B938B}) (Version: 2.00.0000 - Dell Inc.)
Dell System Customization Wizard (HKLM\...\{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}) (Version: 1.00.0000 - Dell Inc.)
Document Capture Pro (HKLM\...\{C75B4983-D3A7-4D0A-8B1A-7BC4F2044F37}) (Version: 1.06.0012 - Seiko Epson Corporation)
Documents To Go Desktop for iOS (HKLM\...\DTGDesktop) (Version: 5.0000.013 - DataViz, Inc.)
DVD Shrink 3.2 (HKLM\...\DVD Shrink_is1) (Version: - DVD Shrink)
Epson Event Manager (HKLM\...\{E4631929-CBD3-49A1-9BB7-F36E701F7C34}) (Version: 3.10.0040 - Seiko Epson Corporation)
Epson FAX Utility (HKLM\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.51.00 - SEIKO EPSON CORPORATION)
Epson PC-FAX Driver (HKLM\...\EPSON PC-FAX Driver 2) (Version: - )
EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EPSON Scan OCR Component (HKLM\...\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}) (Version: 2.30.00 - SEIKO EPSON Corp.)
EPSON Scan PDF Extensions (HKLM\...\{F9956472-6E16-4F83-BF9A-F887EF4A45B7}) (Version: 1.03.0001 - SEIKO EPSON Corp.)
EPSON WF-4630 Series Printer Uninstall (HKLM\...\EPSON WF-4630 Series) (Version: - SEIKO EPSON Corporation)
Epson WF-4630 User’s Guide version 1.0 (HKLM\...\UsersGuideEpson WF-4630 User’s Guide_is1) (Version: 1.0 - )
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
Hi-Def Suite (HKLM\...\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 5.0.1603 - CyberLink Corporation)
HPDiagnosticAlert (Version: 1.00.0000 - Microsoft) Hidden
ImageMixer 3 SE Ver.3 (HKLM\...\{3A95D49D-0076-4DB7-A91E-0E685DC6D6AD}) (Version: 3.01.020 - PIXELA)
ImagXpress (Version: 7.0.74.0 - Nero AG) Hidden
Intel(R) Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - )
Intel(R) PRO Network Connections 12.1.11.0 (HKLM\...\PROSetDX) (Version: - Intel)
iTunes (HKLM\...\{868B9974-4F23-494D-B6BC-4FAB92B2755D}) (Version: 12.1.3.6 - Apple Inc.)
Java 8 Update 121 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
Java 8 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Java(TM) SE Runtime Environment 6 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160000}) (Version: 1.6.0.0 - Sun Microsystems, Inc.)
LG ODD Auto Firmware Update (HKLM\...\{6179550A-3E7C-499E-BCC9-9E8113E0A285}) (Version: 5.01.0226.01 - )
LightScribe System Software (HKLM\...\{E0E55FC1-C53D-4F8D-B14B-B59C312747C8}) (Version: 1.18.22.2 - LightScribe)
LiveUpdate 3.2 (Symantec Corporation) (HKLM\...\LiveUpdate) (Version: 3.2.0.26 - Symantec Corporation)
LiveUpdate Notice (Symantec Corporation) (HKLM\...\{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}) (Version: 1.2.0 - Symantec Corporation)
MediaFACE II (HKLM\...\{DC1D7AD2-583A-4024-9041-387E8FFA5D8C}) (Version: - )
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM\...\{91E30409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Windows Vista Upgrade Advisor (HKLM\...\{E0EB8881-0CFE-4375-8782-8807D258CD7C}) (Version: 1.0.1 - Microsoft)
Microsoft Works (HKLM\...\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
MobileMe Control Panel (HKLM\...\{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}) (Version: 3.1.6.0 - Apple Inc.)
Mozilla Firefox 50.1.0 (x86 en-US) (HKLM\...\Mozilla Firefox 50.1.0 (x86 en-US)) (Version: 50.1.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla)
MSVCSetup (Version: 1.00.0000 - HP) Hidden
MSXML 4.0 SP2 (KB927978) (HKLM\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NVIDIA 3D Vision Controller Driver 296.10 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 296.10 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation)
NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.11.9745 - NVIDIA Corporation)
NVIDIA Graphics Driver 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0213 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0213 - NVIDIA Corporation)
NVIDIA Update 1.11.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation)
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0 - Microsoft Corporation) Hidden
Product Documentation Launcher (HKLM\...\{89CEAE14-DD0F-448E-9554-15781EC9DB24}) (Version: 1.00.0000 - Dell Inc.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - )
Recover My Files (HKLM\...\Recover My Files v5_is1) (Version: 5.2.1.1964 - GetData Pty Ltd)
Software Updater (HKLM\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION)
Sonic Activation Module (Version: 1.0 - Sonic Solutions) Hidden
Spelling Dictionaries Support For Adobe Reader 8 (HKLM\...\{AC76BA86-7AD7-5464-3428-800000000003}) (Version: 8.0.0 - Adobe Systems)
System Requirements Lab (HKLM\...\SystemRequirementsLab) (Version: - )
USB Sharing (HKLM\...\{25BDEE44-A62C-4DCE-9635-2D1646E2B663}) (Version: - )
User's Guides (HKLM\...\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}) (Version: - )
VC 9.0 Runtime (Version: 1.0.0 - Check Point Software Technologies Ltd) Hidden
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VTech Download Agent Library (Version: 1.00.0000 - VTech) Hidden
Windows Live ID Sign-in Assistant (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation)
WinRAR archiver (HKLM\...\WinRAR archiver) (Version: - )
Yahoo Search Set (HKLM\...\Yahoo! SearchSet) (Version: - Yahoo Inc.)
ZoneAlarm DataLock (Version: 10.1.065.000 - Check Point Software Technologies Ltd.) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3490785829-169181324-3712256341-1000_Classes\CLSID\{188047CE-0F0A-11D7-8331-00C04FA03755}\localserver32 -> C:\PROGRA~1\palmOne\QUICKI~1.EXE => No File
CustomCLSID: HKU\S-1-5-21-3490785829-169181324-3712256341-1000_Classes\CLSID\{209DAEB8-0F02-11D7-8331-00C04FA03755}\localserver32 -> C:\PROGRA~1\palmOne\QUICKI~1.EXE => No File
CustomCLSID: HKU\S-1-5-21-3490785829-169181324-3712256341-1000_Classes\CLSID\{382C9F93-9BA4-4FC6-88DC-AD52F5812FF8}\localserver32 -> "C:\Users\Glen\AppData\Roaming\Smilebox\OzDesktopImporter.exe" => No File
CustomCLSID: HKU\S-1-5-21-3490785829-169181324-3712256341-1000_Classes\CLSID\{693566bc-21f8-401e-8d42-e2c5ce50dacc}\localserver32 -> C:\Users\Glen\AppData\Local\Temp\{d5641912-e47a-429c-879e-cfe13eac7a13}\IDriver.NonElevated.exe => N (the data entry has 6 more characters).
CustomCLSID: HKU\S-1-5-21-3490785829-169181324-3712256341-1000_Classes\CLSID\{763F9014-A89C-11D6-82E7-00C04FA03755}\localserver32 -> C:\PROGRA~1\palmOne\QUICKI~1.EXE => No File
CustomCLSID: HKU\S-1-5-21-3490785829-169181324-3712256341-1000_Classes\CLSID\{BE1B5231-A3E2-11D6-82E3-00C04FA03755}\localserver32 -> C:\PROGRA~1\palmOne\QUICKI~1.EXE => No File
CustomCLSID: HKU\S-1-5-21-3490785829-169181324-3712256341-1000_Classes\CLSID\{C42B23DF-334C-4AD0-9AB4-91FF53D04239}\localserver32 -> "C:\Users\Glen\AppData\Roaming\Smilebox\OzDesktopImporter.exe" => No File
CustomCLSID: HKU\S-1-5-21-3490785829-169181324-3712256341-1000_Classes\CLSID\{DFD4C164-AE18-11D6-82EC-00C04FA03755}\localserver32 -> C:\PROGRA~1\palmOne\QUICKI~1.EXE => No File
CustomCLSID: HKU\S-1-5-21-3490785829-169181324-3712256341-1000_Classes\CLSID\{f4c28532-b9d0-4950-a2df-e83f9929242b}\InprocServer32 -> C:\Program Files\MyFunCards_5m\bar\1.bin\5mSrcAs.dll => No File
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {17C3711D-7E21-4D2A-8FD4-80ECB19BB36C} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: {1C2BFEBB-C9B8-40EF-BA7B-D5201E63806B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)
Task: {220D309F-59EE-44D4-99C7-A4063687102B} - System32\Tasks\{2028ABC9-32ED-4C06-91E9-053878041268} => pcalua.exe -a F:\SETUP.EXE -d F:\ -c /AUTORUN
Task: {3EBAC6B0-0E01-48FE-B28F-5994609B6EA9} - System32\Tasks\{D9AF9D65-BB9E-4F69-A722-44379F8B0934} => pcalua.exe -a "C:\Program Files\GetData\Recover My Files\RecoverMyFiles.exe" -d "C:\Program Files\GetData\Recover My Files"
Task: {423C1562-2B26-44D9-9E6A-D02D256A28FF} - System32\Tasks\{C1FCE3D9-EAB2-4CA3-AE11-663AAD4DFC16} => pcalua.exe -a F:\autorun.exe -d F:\
Task: {62F6A621-F6AE-464E-BE66-74793BFF7AAD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-14] (Adobe Systems Incorporated)
Task: {80603F12-8AF1-4B9A-982B-EBA598909069} - System32\Tasks\EPSON WF-4630 Series Invitation {E3062EAB-2698-476F-8702-41D3C9FF90BE} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TTSKLE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {A84A6B12-A206-4D22-9AD6-89B0AF492116} - System32\Tasks\{82C6B9FC-0BA2-4CBF-9D00-3128DBE5866A} => pcalua.exe -a "C:\Users\Glen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N137I7QO\USBDrivers_221[1].exe" -d C:\Users\Glen
Task: {AF06B840-555F-46B4-93DC-5D1C64A78890} - System32\Tasks\{8E1D13D6-A0B1-4413-ADE5-58072754FAAA} => pcalua.exe -a F:\setup.exe -d F:\
Task: {AFAE7C3D-6E97-4942-84D4-B3F4874AB1EB} - System32\Tasks\EPSON WF-4630 Series Update {E3062EAB-2698-476F-8702-41D3C9FF90BE} => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TTSKLE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {B5BC98B8-08C6-42D2-A44C-2FB0A629D4BD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-09-14] (Adobe Systems Incorporated)
Task: {FED34180-25B7-4EAD-BB57-DC18F9037D18} - System32\Tasks\{12BA5604-D8C7-4859-A9A9-72D73BACEE54} => pcalua.exe -a "C:\Program Files\palmOne\QuickInstall.exe" -d C:\Users\Glen\Desktop
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\EPSON WF-4630 Series Invitation {E3062EAB-2698-476F-8702-41D3C9FF90BE}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TTSKLE.EXE
Task: C:\Windows\Tasks\EPSON WF-4630 Series Update {E3062EAB-2698-476F-8702-41D3C9FF90BE}.job => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TTSKLE.EXE :/EXE:{E3062EAB-2698-476F-8702-41D3C9FF90BE} /F:Update SYSTEM ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2017-01-26 09:17 - 2014-08-27 16:30 - 00204280 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\txmlutil.dll
2017-01-26 09:16 - 2013-09-03 14:29 - 00095088 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdmetrics.dll
2017-01-26 09:17 - 2015-06-22 16:22 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\UI\accessl.ui
2017-01-26 09:17 - 2012-10-29 14:22 - 00130656 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdfwcore.dll
2017-02-08 00:29 - 2017-02-08 00:29 - 00859344 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_02643_003\ashttpbr.mdl
2017-02-08 00:29 - 2017-02-08 00:29 - 00466568 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_02643_003\ashttpdsp.mdl
2017-02-08 00:29 - 2017-02-08 00:29 - 02660936 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_02643_003\ashttpph.mdl
2017-02-08 00:29 - 2017-02-08 00:30 - 01303008 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_02643_003\ashttprbl.mdl
2007-10-09 19:58 - 2007-09-20 17:34 - 00129024 _____ () C:\Program Files\WinRAR\rarext.dll
2014-10-11 14:48 - 2013-07-24 08:24 - 00137728 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2012-09-21 12:04 - 2012-07-12 10:48 - 00185856 _____ () C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
2009-09-17 09:55 - 2009-04-11 01:28 - 00368640 _____ () C:\Windows\system32\msjetoledb40.dll
2008-09-05 18:48 - 2003-05-23 11:04 - 00139264 _____ () C:\Program Files\USB Sharing\usbshare.exe
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4 [268]
AlternateDataStreams: C:\ProgramData\TEMP:0CE7F3C9 [312]
AlternateDataStreams: C:\ProgramData\TEMP:A8ADE5D8 [232]
AlternateDataStreams: C:\ProgramData\TEMPFC5A2B2 [244]
AlternateDataStreams: C:\Users\Glen\Desktop\FRST.exe:BDU [0]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\KL1 => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\kl2 => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 05:23 - 2008-09-15 14:18 - 00001077 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3490785829-169181324-3712256341-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Glen\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 0)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: Automatic LiveUpdate Scheduler => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: Lavasoft Ad-Aware Service => 2
MSCONFIG\Services: LightScribeService => 2
MSCONFIG\Services: LiveUpdate => 3
MSCONFIG\Services: LiveUpdate Notice Service => 2
MSCONFIG\startupreg: Ad-Watch =>
MSCONFIG\startupreg: Adobe Reader Speed Launcher =>
MSCONFIG\startupreg: AppleSyncNotifier => C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Bdagent => "C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe"
MSCONFIG\startupreg: BDRegion =>
MSCONFIG\startupreg: Bitdefender Wallet Agent => "C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe"
MSCONFIG\startupreg: Dell PC TuneUp Startup =>
MSCONFIG\startupreg: EPLTarget =>
MSCONFIG\startupreg: InstantBurn => C:\PROGRA~1\CYBERL~1\INSTAN~1\Win2K\IBurn.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LanguageShortcut =>
MSCONFIG\startupreg: LGODDFU => "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
MSCONFIG\startupreg: Monitor =>
MSCONFIG\startupreg: QuickTime Task =>
MSCONFIG\startupreg: RemoteControl =>
MSCONFIG\startupreg: Symantec PIF AlertEng => "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{52487D41-E3F1-4EF6-A850-AE75DAB5FD37}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{5157DDDC-B9DF-4B1F-A40F-0E2A063AF17F}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{E8208C00-15E0-4EC7-93BA-4040582D8CC2}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{8E3C4D3F-3943-474E-9E01-83C044E02880}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{B4541D54-F33F-4FFE-A5B9-885FF16DAC9A}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{15A7338F-F041-4FDD-9A18-5067200B1110}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{1EDC6A38-B229-4A0A-9054-03C480D967F8}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{9ECC0299-5E11-493E-BF26-614DF0711D39}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{C82C6C4A-1284-4C7A-8519-C27E392B8617}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{047EC2CA-1ED7-43C9-B362-40E7D87C7B1A}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{76D0149D-C3B7-476B-82FB-1EFDE857E498}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{B2BC89BE-BB3B-46C5-AE15-15B06724BC23}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{A9626A92-2E46-42F5-9E4A-4516ACA719DD}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{A5CB1C6C-1749-4D1D-9D54-4247868E95F2}] => (Allow) LPort=80
FirewallRules: [{8601B18A-1F64-4AC7-8656-43C941D30155}] => (Allow) LPort=80
FirewallRules: [{81B2CB85-C95E-42F0-A772-E419995B3DCC}] => (Allow) LPort=80
FirewallRules: [{02C5A18A-A5AE-4D22-9EDA-1447AF434C0F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{5FE9330D-6243-4F11-AA9C-D14E8558EEB6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{EA2BB518-26DA-4B33-9F31-0FFFD4E756CF}C:\users\glen\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\glen\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{42758F7A-2433-4873-A96C-7FC15ED308C6}C:\users\glen\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\glen\appdata\local\akamai\netsession_win.exe
FirewallRules: [{3406EAF9-9BEA-4C12-A641-48D5D21ABC3F}] => (Allow) C:\Users\Glen\AppData\Roaming\Smilebox\sbtb_install.exe
FirewallRules: [{47B94913-B1CF-4FCC-9513-C6ED761178F5}] => (Allow) C:\Users\Glen\AppData\Roaming\Smilebox\sbtb_install.exe
FirewallRules: [{19A6674F-B218-4482-8DCA-B509C9554BEC}] => (Allow) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{E8B702D1-8C8A-458F-B899-B496CD03149E}] => (Allow) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{891E5A19-FDE6-42CA-BE6F-13C6663ACD95}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{97065B30-F847-48EF-9609-FBEAAB247650}] => (Allow) C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{3EDA8036-BC40-4092-B930-71CEF04A2B98}] => (Allow) C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{DE480A04-09F9-4760-A21E-A96725FF1BE7}] => (Allow) C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{22AD5023-36BA-4FD8-B513-4A7B81A9862B}] => (Allow) C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
FirewallRules: [{7C831FD3-1C1A-48A2-8B78-7D39723F5029}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{47F533B1-C8F1-44E2-AA57-E3683421FF8E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{F964E030-FC1A-4BCA-8745-BDE961C72FF4}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{4EF6A342-B655-4C70-AD64-99D5AB9A62CB}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{06BC1296-E664-429D-882F-780CECCEDF87}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{B61F74FA-B878-4D94-9B09-FACA6097B014}] => (Allow) C:\Program Files\HP\hp software update\hpwucli.exe
FirewallRules: [{E0020F70-AA63-4521-9FCE-8EE7AECC2427}] => (Allow) C:\Program Files\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{51C9D544-C00A-40CA-99D1-01CD2D173363}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{BE8EE55C-5A1E-41C5-8B11-21268C2064E3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{C78ED4D8-EC48-4290-9E36-2BBE618BE4E8}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{B20CD4FA-78C6-48B0-B8E5-6258D980E0BA}] => (Allow) C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe
FirewallRules: [{2F4D69E1-0B2D-4746-8955-B15962A68A58}] => (Allow) C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe
FirewallRules: [{52122FB5-B1DE-486B-A851-604E292C684A}] => (Allow) C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe
FirewallRules: [{9F25BEBA-C0C3-4C7D-9CF5-EFDE1B2FDF53}] => (Allow) C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe
FirewallRules: [TCP Query User{0D3CEA84-0F80-409B-B844-9FE66B9BC166}C:\users\glen\appdata\local\temp\rarsfx0\x32\pcsftool.exe] => (Block) C:\users\glen\appdata\local\temp\rarsfx0\x32\pcsftool.exe
FirewallRules: [UDP Query User{E0B6F099-84EF-4D55-962B-246F8685949D}C:\users\glen\appdata\local\temp\rarsfx0\x32\pcsftool.exe] => (Block) C:\users\glen\appdata\local\temp\rarsfx0\x32\pcsftool.exe
FirewallRules: [TCP Query User{94CECE24-A8DA-44CA-8F3F-913169E36D82}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{DC703B94-A20B-4CE3-8105-091E7D343834}C:\program files\epson software\event manager\eeventmanager.exe] => (Block) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [TCP Query User{1DAD6339-7599-49FD-841E-D3EEAC1260C0}C:\program files\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{86601BFA-9F3E-45D3-8517-F3FEF7DFDFF1}C:\program files\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files\epson software\event manager\eeventmanager.exe
FirewallRules: [TCP Query User{7B8523F7-3639-4A14-863D-7F1A572A877E}C:\users\glen\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\glen\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{53FFF5B3-493F-4563-8BA1-F9AC1CAB1FB2}C:\users\glen\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\glen\appdata\local\akamai\netsession_win.exe
FirewallRules: [{6EE273F5-714D-4C29-87F5-532F39349A13}] => (Allow) LPort=49357
FirewallRules: [{84C79808-A714-40A1-A235-CC822DEBCB67}] => (Allow) LPort=5000
==================== Restore Points =========================
ATTENTION: System Restore is disabled
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Microsoft WPD FileSystem Volume Driver
Description: Microsoft WPD FileSystem Volume Driver
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: (WPD file system device)
Service: WUDFRd
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
Name: USB HS-CF Card
Description: USB HS-CF Card
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: TEAC
Service: WUDFRd
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
Name: USB HS-MS Card
Description: USB HS-MS Card
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: TEAC
Service: WUDFRd
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
Name: USB HS-SD Card
Description: USB HS-SD Card
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: TEAC
Service: WUDFRd
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
Name: USB HS-xD/SM
Description: USB HS-xD/SM
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: TEAC
Service: WUDFRd
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
==================== Event log errors: =========================
Application errors:
==================
Error: (02/19/2017 10:28:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application nvtray.exe, version 7.17.13.1106, time stamp 0x50f950f4, faulting module nvtray.exe, version 7.17.13.1106, time stamp 0x50f950f4, exception code 0x40000015, fault offset 0x0010333f,
process id 0x16fc, application start time 0x01d28b2953c65f79.
Error: (02/19/2017 10:12:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application nvtray.exe, version 7.17.13.1106, time stamp 0x50f950f4, faulting module nvtray.exe, version 7.17.13.1106, time stamp 0x50f950f4, exception code 0x40000015, fault offset 0x0010333f,
process id 0xba0, application start time 0x01d28b1647b852a9.
Error: (02/19/2017 09:01:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application usbshare.exe, version 0.0.0.0, time stamp 0x3ecd9dd7, faulting module usbshare.exe, version 0.0.0.0, time stamp 0x3ecd9dd7, exception code 0xc0000005, fault offset 0x000039dd,
process id 0xd54, application start time 0x01d28b164b695489.
Error: (02/19/2017 06:18:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application mcupdate.EXE, version 6.0.6002.18005, time stamp 0x49e02324, faulting module KERNEL32.dll, version 6.0.6002.19623, time stamp 0x56ec36ff, exception code 0xe0434f4d, fault offset 0x0003fdb6,
process id 0x1124, application start time 0x01d28b0679ab390d.
Error: (02/19/2017 12:39:45 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007043c from line 45 of d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.
Error: (02/19/2017 12:38:18 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007043c from line 45 of d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.
Error: (02/18/2017 06:18:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application mcupdate.EXE, version 6.0.6002.18005, time stamp 0x49e02324, faulting module KERNEL32.dll, version 6.0.6002.19623, time stamp 0x56ec36ff, exception code 0xe0434f4d, fault offset 0x0003fdb6,
process id 0x10d4, application start time 0x01d28a3d4e091195.
Error: (02/18/2017 03:46:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application firefox.exe, version 51.0.1.6234, time stamp 0x5888f28c, faulting module mozglue.dll, version 51.0.1.6234, time stamp 0x5888f27e, exception code 0x80000003, fault offset 0x0000ec83,
process id 0xdf4, application start time 0x01d28a087724e9d5.
Error: (02/17/2017 06:22:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application mcupdate.EXE, version 6.0.6002.18005, time stamp 0x49e02324, faulting module KERNEL32.dll, version 6.0.6002.19623, time stamp 0x56ec36ff, exception code 0xe0434f4d, fault offset 0x0003fdb6,
process id 0x1424, application start time 0x01d2897423ceaead.
Error: (02/16/2017 06:18:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application mcupdate.EXE, version 6.0.6002.18005, time stamp 0x49e02324, faulting module KERNEL32.dll, version 6.0.6002.19623, time stamp 0x56ec36ff, exception code 0xe0434f4d, fault offset 0x0003fdb6,
process id 0x12a4, application start time 0x01d288aaf9817f1c.
System errors:
=============
Error: (02/20/2017 12:04:02 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error:
The service did not start due to a logon failure.
Error: (02/20/2017 12:04:02 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error:
Logon failure: the specified account password has expired.
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
Error: (02/20/2017 12:02:42 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd
Error: (02/20/2017 12:02:42 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The ZoneAlarm Privacy Service service failed to start due to the following error:
The system cannot find the path specified.
Error: (02/20/2017 12:02:42 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Diagnostic Policy Service service terminated with the following error:
Access is denied.
Error: (02/19/2017 11:59:18 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
Error: (02/19/2017 10:51:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error:
The service did not start due to a logon failure.
Error: (02/19/2017 10:51:29 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error:
Logon failure: the specified account password has expired.
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
Error: (02/19/2017 10:49:26 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Lbd
Error: (02/19/2017 10:49:19 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The ZoneAlarm Privacy Service service failed to start due to the following error:
The system cannot find the path specified.
CodeIntegrity:
===================================
Date: 2017-02-20 00:20:15.353
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\klflt.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-02-20 00:20:14.901
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\klflt.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-02-20 00:20:14.464
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\klflt.sys because the set of per-page image hashes could not be found on the system.
Date: 2017-02-20 00:20:14.011
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\klflt.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-03-09 23:24:01.537
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\klflt.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-03-09 23:24:01.150
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\klflt.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-03-09 23:24:00.733
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\klflt.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-03-09 23:24:00.315
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\klflt.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-11-19 08:06:47.598
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\klflt.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-11-19 08:06:47.175
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\klflt.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU E6550 @ 2.33GHz
Percentage of memory in use: 65%
Total physical RAM: 3325.45 MB
Available physical RAM: 1146.65 MB
Total Virtual: 6869.7 MB
Available Virtual: 4763.19 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:167.25 GB) (Free:9.87 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (DELL BACKUP) (Fixed) (Total:55.52 GB) (Free:28.52 GB) NTFS
Drive e: (RECOVERY) (Fixed) (Total:10 GB) (Free:6.14 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.8 GB) (Disk ID: 48000000)
Partition 1: (Not Active) - (Size=55 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=167.3 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=55.5 GB) - (Type=OF Extended)
==================== End of Addition.txt ============================
Attachments
-
42.1 KB Views: 15
-
598 bytes Views: 14
-
34.2 KB Views: 16