Computer not shutting down


I have been having a problem shutting down my computer and I do have a paid version of Malwarebytes . I have trouble logging out of the guest account and main account as well . Once logged out I shut down but can come back hours later, lift the cover of this Toshiba Laptop and it will still be shutting down. In other words it never did shut down.

Hi, whonew:


The forum experts will need some basic system info to start the troubleshooting process.


Please tell us:

What is the exact MODEL NUMBER of the Toshiba laptop?

Do you have some sort of "Service Tag" or unique service code or "serial number" for the computer (perhaps from a sticker on the bottom of the laptop) or from an invoice provided at the time of purchase?


Then please post back the logs from these scanners.


The experts will review them and work with you to find out what might be going on.







Please run the DDS scanner and send back both logs as attachments to your next reply.
If you are running Windows 8.1, please skip this step.

Download DDS from one of the locations below and save it to your Desktop:

Temporarily disable any script blocker if your Anti-Virus/Anti-Malware has it.
How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Once downloaded you can disconnect from the Internet and disable your Ant-Virus temporarily if needed.
Then double click dds.scr or dds.com to run the tool.
Click the Run button if prompted with an Open File - Security Warning dialog box.
A black DOS console should open and run for a moment.

  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop
  • Please include both of the following logs in your next reply as an attachment: DDS.txt and Attach.txt
  • You can ignore the note about zipping the Attach.txt file and just post it or attach it.

Please run the FRST tool and send back both logs as attachments to your next reply.

Download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system, download both of them and try to run them. The one that runs will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your next reply.
This is a Toshiba Satellite C655 and I am not sure why your asking for the tag number? I have not ever been asked that before . I am not sure what a sevice tag . There are two or three stickers on the bottom of this machine. Windows 7

For Dell computers it's called a "Service Tag Number".

Presumably, Toshiba uses a similar system, but they might call it something else.

Think of it as a unique "serial number" that applies to your specific computer.

Like a "Social Security Number".

It would be used to obtain information from Toshiba about the exact hardware and software specifications for your specific computer, if the need arose, in order to try to resolve your current issues.


Please post back with the requested logs when you are ready.





DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16866
Run by Judith at 22:30:08 on 2014-04-29
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.2663.1759 [GMT -7:00]
AV: Computer Security *Disabled/Updated* {15414183-282E-D62C-CA37-EF24860A2F17}
SP: Computer Security *Disabled/Updated* {AE20A067-0E14-D9A2-F087-D456FD8D65AA}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Frontier\fshoster32.exe
C:\Program Files (x86)\Frontier\apps\CCF_Reputation\fsorsp.exe
C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Anti-Virus\FSGK32.EXE
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Common\FSMA32.EXE
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Anti-Virus\fssm32.exe
C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Common\FSHDLL64.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\System32\svchost.exe -k LocalServicePeerNet
c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files (x86)\Frontier\fshoster32.exe
C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Common\FSM32.EXE
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
C:\windows\system32\svchost.exe -k imgsvc
============== Pseudo HJT Report ===============

BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
mRun: [F-Secure Hoster (53784)] "C:\Program Files (x86)\Frontier\fshoster32.exe" -app -hosterid:1
mRun: [F-Secure Manager] "C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Common\FSM32.EXE" /splash
mRun: [EEventManager] C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe
mRun: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
StartupFolder: C:\Users\Judith\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: EnableSecureUIAPath = dword:1
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

TCP: NameServer =
TCP: Interfaces\{1C9F5782-6E1E-4B87-B6CE-A95F954BF38A} : DHCPNameServer =
TCP: Interfaces\{1C9F5782-6E1E-4B87-B6CE-A95F954BF38A}\6427F6E64796562733731353 : DHCPNameServer =
TCP: Interfaces\{1C9F5782-6E1E-4B87-B6CE-A95F954BF38A}\6716E602E475 : DHCPNameServer =
TCP: Interfaces\{1C9F5782-6E1E-4B87-B6CE-A95F954BF38A}\D61636B6D27457563747 : DHCPNameServer =
TCP: Interfaces\{1C9F5782-6E1E-4B87-B6CE-A95F954BF38A}\E43434 : DHCPNameServer =
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-TB: Easy Photo Print: {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
x64-Run: [smartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
x64-Run: [TPwrMain] C:\Program Files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
x64-Run: [smoothView] C:\Program Files (x86)\Toshiba\SmoothView\SmoothView.exe
x64-Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
x64-Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\cqjugvhh.default-1395345917665\
FF - prefs.js: browser.search.selectedEngine - Google
FF - plugin: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll
FF - plugin: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrlui.dll
FF - plugin: C:\windows\System32\Macromed\Flash\NPSWF64_13_0_0_206.dll
FF - plugin: C:\windows\System32\npDeployJava1.dll
FF - plugin: C:\windows\System32\npmproxy.dll
FF - plugin: C:\windows\System32\Wat\npWatWeb.dll
============= SERVICES / DRIVERS ===============
R0 amd_sata;amd_sata;C:\windows\System32\drivers\amd_sata.sys [2013-2-8 75904]
R0 amd_xata;amd_xata;C:\windows\System32\drivers\amd_xata.sys [2013-2-8 38016]
R0 fsbts;fsbts;C:\windows\System32\drivers\fsbts.sys [2013-10-16 56016]
R1 F-Secure HIPS;F-Secure HIPS Driver;C:\Program Files (x86)\Frontier\apps\ComputerSecurity\HIPS\drivers\fshs.sys [2014-4-23 69480]
R1 fsvista;F-Secure Vista Support Driver;C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [2013-10-16 13248]
R2 fshoster;F-Secure Dll Hoster;C:\Program Files (x86)\Frontier\fshoster32.exe [2013-5-15 191424]
R2 FSORSPClient;F-Secure ORSP Client;C:\Program Files (x86)\Frontier\apps\CCF_Reputation\fsorsp.exe [2012-8-6 60352]
R3 ETD;ELAN PS/2 Port Input Device;C:\windows\System32\drivers\ETD.sys [2010-11-11 137512]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [2013-10-16 203304]
R3 fsni;fsni;C:\Program Files (x86)\Frontier\apps\CCF_Scanning\fsni64.sys [2013-4-25 80832]
R3 FwLnk;FwLnk Driver;C:\windows\System32\drivers\FwLnk.sys [2013-2-8 9216]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\windows\System32\drivers\L1C62x64.sys [2011-4-20 169584]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\windows\System32\drivers\rtl8192ce.sys [2013-2-8 1109096]
R3 WSDScan;WSD Scan Support via UMB;C:\windows\System32\drivers\WSDScan.sys [2009-7-13 25088]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-4-23 1809720]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-4-23 857912]
S3 MBAMProtector;MBAMProtector;C:\windows\System32\drivers\mbam.sys [2013-12-7 25816]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\windows\System32\drivers\rdpvideominiport.sys [2013-2-8 19456]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\System32\drivers\RtsUStor.sys [2013-2-8 243712]
S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2013-2-8 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\System32\drivers\TsUsbGD.sys [2013-2-8 30208]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe [2013-2-9 1255736]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
S3 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
S4 AMD External Events Utility;AMD External Events Utility;C:\windows\System32\atiesrxx.exe [2013-2-8 203776]
S4 TMachInfo;TMachInfo;C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe [2013-2-8 54136]
S4 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-2-5 137560]
=============== Created Last 30 ================
2014-04-29 20:38:55    75888    ----a-w-    C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF61156B-7B58-4E84-8E05-07763D8B0D04}\offreg.dll
2014-04-29 06:03:43    10651704    ----a-w-    C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF61156B-7B58-4E84-8E05-07763D8B0D04}\mpengine.dll
2014-04-27 20:07:53    --------    d-s---w-    C:\windows\System32\CompatTel
2014-04-27 20:06:59    465408    ----a-w-    C:\windows\System32\aepdu.dll
2014-04-27 20:06:59    424448    ----a-w-    C:\windows\System32\aeinv.dll
2014-04-24 00:18:30    119512    ----a-w-    C:\windows\System32\drivers\MBAMSwissArmy.sys
2014-04-24 00:13:42    88280    ----a-w-    C:\windows\System32\drivers\mbamchameleon.sys
2014-04-24 00:13:42    63192    ----a-w-    C:\windows\System32\drivers\mwac.sys
2014-04-24 00:13:41    --------    d-----w-    C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-19 15:05:25    --------    d-----w-    C:\Users\Judith\AppData\Local\{9773292F-A589-44F7-BBF1-297635A09374}
2014-04-19 15:05:11    --------    d-----w-    C:\Users\Judith\AppData\Roaming\Windows Live Writer
2014-04-19 15:05:11    --------    d-----w-    C:\Users\Judith\AppData\Local\Windows Live Writer
2014-04-18 15:03:36    --------    d-----w-    C:\ProgramData\Sony Corporation
2014-04-18 05:54:37    --------    d-----w-    C:\epson
2014-04-18 04:06:01    77824    ----a-w-    C:\windows\SysWow64\EBAPI.dll
2014-04-18 04:06:01    65536    ----a-w-    C:\windows\SysWow64\EEBUtil.dll
2014-04-18 04:06:01    55808    ----a-w-    C:\windows\SysWow64\EEBSDKIF.dll
2014-04-18 04:06:01    135168    ----a-w-    C:\windows\SysWow64\EEBAPI.dll
2014-04-18 04:06:01    110592    ----a-w-    C:\windows\SysWow64\EEBDSCVR.dll
2014-04-18 04:03:56    --------    d-----w-    C:\Program Files (x86)\EpsonNet
2014-04-18 04:00:33    535552    ----a-w-    C:\windows\System32\ensppui.dll
2014-04-18 04:00:33    219648    ----a-w-    C:\windows\System32\enspres.dll
2014-04-18 04:00:31    558592    ----a-w-    C:\windows\System32\ensppmon.dll
2014-04-18 04:00:31    219648    ----a-w-    C:\windows\System32\enpres.dll
2014-04-18 04:00:30    558592    ----a-w-    C:\windows\System32\enppmon.dll
2014-04-18 04:00:30    535552    ----a-w-    C:\windows\System32\enppui.dll
2014-04-18 04:00:28    --------    d-----w-    C:\Program Files\EpsonNet
2014-04-18 03:56:00    --------    d-----w-    C:\Program Files (x86)\Common Files\EPSON
2014-04-18 03:27:26    --------    d-----w-    C:\Users\Judith\AppData\Local\{A6800D97-1746-49DF-9FE6-6E56ACAFB703}
2014-04-18 03:27:26    --------    d-----w-    C:\Users\Judith\AppData\Local\{82E3A1AD-4ED9-4F40-B279-936CE7770710}
2014-04-18 02:59:51    --------    d-----w-    C:\ProgramData\UDL
2014-04-17 21:46:33    --------    d-sh--w-    C:\$RECYCLE.BIN
2014-04-17 18:56:13    108032    ----a-w-    C:\windows\System32\E_ILMEMA.DLL
2014-04-17 18:56:09    81408    ----a-w-    C:\windows\System32\E_IBCBEMA.DLL
2014-04-17 18:03:04    282624    ----a-w-    C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe
2014-04-17 17:59:36    118784    ----a-w-    C:\windows\System32\E_ILMFRA.DLL
2014-04-17 17:59:34    81920    ----a-w-    C:\windows\System32\E_IBCBFRA.DLL
2014-04-17 17:59:16    --------    d-----w-    C:\ProgramData\EPSON
2014-04-17 17:58:52    459776    ----a-w-    C:\windows\System32\esxwiaud.dll
2014-04-17 17:58:52    17408    ----a-w-    C:\windows\System32\esxcdev.dll
2014-04-17 17:58:52    128392    ----a-w-    C:\windows\System32\esdevapp.exe
2014-04-17 17:58:50    --------    d-----w-    C:\Program Files (x86)\epson
2014-04-09 16:13:00    274880    ----a-w-    C:\windows\System32\drivers\msiscsi.sys
==================== Find3M  ====================
2014-04-29 21:26:34    70832    ----a-w-    C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-29 21:26:34    692400    ----a-w-    C:\windows\SysWow64\FlashPlayerApp.exe
2014-04-03 16:50:58    25816    ----a-w-    C:\windows\System32\drivers\mbam.sys
2014-03-31 16:35:08    270496    ------w-    C:\windows\System32\MpSigStub.exe
2014-03-13 06:33:30    2238976    ----a-w-    C:\windows\System32\wininet.dll
2014-03-13 06:32:03    3959808    ----a-w-    C:\windows\System32\jscript9.dll
2014-03-13 06:31:55    67072    ----a-w-    C:\windows\System32\iesetup.dll
2014-03-13 06:31:55    136704    ----a-w-    C:\windows\System32\iesysprep.dll
2014-03-13 05:10:47    1766400    ----a-w-    C:\windows\SysWow64\wininet.dll
2014-03-13 05:09:43    2877952    ----a-w-    C:\windows\SysWow64\jscript9.dll
2014-03-13 05:09:39    61440    ----a-w-    C:\windows\SysWow64\iesetup.dll
2014-03-13 05:09:39    109056    ----a-w-    C:\windows\SysWow64\iesysprep.dll
2014-03-13 04:57:03    2706432    ----a-w-    C:\windows\System32\mshtml.tlb
2014-03-13 04:47:33    2706432    ----a-w-    C:\windows\SysWow64\mshtml.tlb
2014-03-13 03:59:47    89600    ----a-w-    C:\windows\System32\RegisterIEPKEYs.exe
2014-03-13 03:51:45    71680    ----a-w-    C:\windows\SysWow64\RegisterIEPKEYs.exe
2014-03-04 09:44:21    362496    ----a-w-    C:\windows\System32\wow64win.dll
2014-03-04 09:44:21    243712    ----a-w-    C:\windows\System32\wow64.dll
2014-03-04 09:44:21    13312    ----a-w-    C:\windows\System32\wow64cpu.dll
2014-03-04 09:44:03    16384    ----a-w-    C:\windows\System32\ntvdm64.dll
2014-03-04 09:17:19    14336    ----a-w-    C:\windows\SysWow64\ntvdm64.dll
2014-03-04 09:17:05    44032    ----a-w-    C:\windows\apppatch\acwow64.dll
2014-03-04 09:16:54    25600    ----a-w-    C:\windows\SysWow64\setup16.exe
2014-03-04 09:16:18    5120    ----a-w-    C:\windows\SysWow64\wow32.dll
2014-03-04 08:09:30    7680    ----a-w-    C:\windows\SysWow64\instnm.exe
2014-03-04 08:09:29    2048    ----a-w-    C:\windows\SysWow64\user.exe
2014-02-07 01:23:30    3156480    ----a-w-    C:\windows\System32\win32k.sys
2014-02-04 02:35:56    190912    ----a-w-    C:\windows\System32\drivers\storport.sys
2014-02-04 02:35:35    27584    ----a-w-    C:\windows\System32\drivers\Diskdump.sys
2014-02-04 02:32:22    1424384    ----a-w-    C:\windows\System32\WindowsCodecs.dll
2014-02-04 02:32:12    624128    ----a-w-    C:\windows\System32\qedit.dll
2014-02-04 02:28:36    2048    ----a-w-    C:\windows\System32\iologmsg.dll
2014-02-04 02:04:22    1230336    ----a-w-    C:\windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04:11    509440    ----a-w-    C:\windows\SysWow64\qedit.dll
2014-02-04 02:00:39    2048    ----a-w-    C:\windows\SysWow64\iologmsg.dll
============= FINISH: 22:31:06.74 ===============

DDS (Ver_2012-11-20.01)
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 2/8/2013 5:32:58 PM
System Uptime: 4/29/2014 12:34:43 PM (10 hours ago)
Motherboard: TOSHIBA |  | Portable PC
Processor: AMD E-350 Processor | Socket FT1 | 800/100mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 285 GiB total, 242.76 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP144: 4/11/2014 1:47:15 PM - OTL Restore Point - 4/11/2014 1:47:11 PM
RP145: 4/15/2014 7:07:40 AM - Windows Update
RP146: 4/17/2014 11:00:47 AM - Installed Epson Event Manager
RP147: 4/17/2014 11:02:39 AM - Installed EPSON Scan Assistant
RP148: 4/17/2014 11:03:49 AM - Installed Attach To Email
RP149: 4/17/2014 11:07:51 AM - Installed Epson Print CD
RP150: 4/17/2014 8:54:07 PM - Installed FAX Utility
RP151: 4/17/2014 9:00:10 PM - Installed EpsonNet Print
RP152: 4/17/2014 9:02:58 PM - Configured EpsonNet Print
RP153: 4/17/2014 9:03:35 PM - Installed EpsonNet Setup
RP154: 4/17/2014 9:08:12 PM - Installed Epson Print CD
RP155: 4/18/2014 7:11:48 AM - Windows Update
RP156: 4/19/2014 5:28:09 PM - Removed Java 7 Update 51
RP157: 4/19/2014 5:29:24 PM - Removed Java 7 Update 51
RP158: 4/22/2014 6:41:57 AM - Windows Update
RP159: 4/27/2014 1:07:15 PM - Windows Update
==== Installed Programs ======================
Adobe Flash Player 13 ActiveX
Adobe Flash Player 13 Plugin
Adobe Reader XI (11.0.06)
Amazon Cloud Player
Amazon Music Importer
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
ATI Catalyst Install Manager
Best Buy pc app
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Computer Security (release)
Conexant HD Audio
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
EPSON Artisan 800 Series Printer Uninstall
EPSON Artisan 810 Series Printer Uninstall
Epson Easy Photo Print 2
Epson Event Manager
Epson FAX Utility
Epson Print CD
EpsonNet Print
EpsonNet Setup
ETDWare PS/2-X64
F-Secure CCF Reputation
F-Secure CCF Scanning (release)
F-Secure Network CCF 1.02.128
Frontier Secure
Junk Mail filter update
Label@Once 1.0
Malwarebytes Anti-Malware version
Mesh Runtime
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft Mouse and Keyboard Center
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Student 2010
Microsoft Office Office 64-bit Components 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared 64-bit MUI (English) 2010
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
Mozilla Firefox 28.0 (x86 en-US)
Mozilla Maintenance Service
Online Safety 2.83.1329.952
PlayReady PC Runtime amd64
PlayReady PC Runtime x86
Realtek USB 2.0 Card Reader
Realtek WLAN Driver
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Security Update for Microsoft Excel 2010 (KB2826033) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2826023) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2826035) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition
Security Update for Microsoft Word 2010 (KB2863926) 32-Bit Edition
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
TOSHIBA Application Installer
TOSHIBA Bulletin Board
TOSHIBA Disc Creator
TOSHIBA Hardware Setup
TOSHIBA Media Controller
TOSHIBA Quality Application
TOSHIBA Recovery Media Creator
TOSHIBA Service Station
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition
Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
Waterfox 27.0.2 (x64 en-US)
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WMV9/VC-1 Video Playback
==== Event Viewer Messages From Past Week ========
4/29/2014 12:37:12 PM, Error: Microsoft-Windows-DistributedCOM [10016]  - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID  {C97FCC79-E628-407D-AE68-A06AD6D8B4D1}  and APPID  {344ED43D-D086-4961-86A6-1106F4ACAD9B}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
4/26/2014 4:42:05 PM, Error: Microsoft-Windows-DistributedCOM [10016]  - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {8BC3F05E-D86B-11D0-A075-00C04FB68820}  and APPID  {8BC3F05E-D86B-11D0-A075-00C04FB68820}  to the user KIRK-PC\Guest SID (S-1-5-21-1596010243-3757955604-700281957-501) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
==== End Of File ===========================

The machine is a Satellite C655-95209 and the Serial # 7B1925470 ..I am using Waterfox web browser and do not know how to get the download to go to the desktop, it goes to a download folder, I moved the first one from within the download folder to the desktop ,  but would rather get it right the first time

for future reference (as you may need to download a number of items to the desktop) :


this is virtually the same as waterfox .


as a rule , i have mine set to always ask me where *I* want to download stuff to .

otherwise , things can get put where they don't belong or "get lost" .

also , WF and FF will "remember" the last folder/location you downloaded to , depending on how you set it up) .


(interestingly , i was not able to find a tutorial specific to WF)

Ok thank you I ran those and posted them but never got a black screen for DOS , I also did not take it off the internet should I run DDS again? I did go to Firefox and still did not get the option even though I had changed as shown. It downloaded in the download folder and I had to move it.

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-04-2014 01
Ran by Judith (administrator) on KIRK-PC on 30-04-2014 07:18:42
Running from C:\Users\Judith\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
(F-Secure Corporation) C:\Program Files (x86)\Frontier\fshoster32.exe
(F-Secure Corporation) C:\Program Files (x86)\Frontier\apps\CCF_Reputation\fsorsp.exe
(F-Secure Corporation) C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Anti-Virus\fsgk32.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(F-Secure Corporation) C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Common\FSMA32.EXE
(F-Secure Corporation) C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Anti-Virus\fssm32.exe
(F-Secure Corporation) C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Common\FSHDLL64.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(F-Secure Corporation) C:\Program Files (x86)\Frontier\fshoster32.exe
(F-Secure Corporation) C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Common\FSM32.EXE
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [smartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566184 2010-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [smoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [508216 2009-07-28] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKLM-x32\...\Run: [F-Secure Hoster (53784)] => C:\Program Files (x86)\Frontier\fshoster32.exe [191424 2013-05-15] (F-Secure Corporation)
HKLM-x32\...\Run: [F-Secure Manager] => C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Common\FSM32.EXE [310208 2013-08-14] (F-Secure Corporation)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [673616 2009-04-07] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [843776 2009-06-05] (SEIKO EPSON CORPORATION)
Startup: C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0F0AEC0E875ACF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.yahoo.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNJ
SearchScopes: HKLM-x32 - {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNJ
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\cqjugvhh.default-1395345917665
FF SelectedSearchEngine: Google
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @microsoft.com/GENUINE - C:\windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @TrendMicro.com/FFExtension - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [tmbepff-7.5@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1130\7.5.1130\firefoxextension
FF HKLM-x32\...\Firefox\Extensions: [tmbepff-7.5@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1130\7.5.1130\firefoxextension
FF HKLM-x32\...\Firefox\Extensions: [{22181a4d-af90-4ca3-a569-faed9118d6bc}] - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension
FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - C:\Program Files\Trend Micro\AMSP\module\20004\FxExt\firefoxextension\

==================== Services (Whitelisted) =================

R2 fshoster; C:\Program Files (x86)\Frontier\fshoster32.exe [191424 2013-05-15] (F-Secure Corporation)
R3 FSMA; C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Common\FSMA32.EXE [216000 2013-08-14] (F-Secure Corporation)
R2 FSORSPClient; C:\Program Files (x86)\Frontier\apps\CCF_Reputation\fsorsp.exe [60352 2013-10-16] (F-Secure Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R3 F-Secure Gatekeeper; C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys [203304 2014-04-23] (F-Secure Corporation)
R1 F-Secure HIPS; C:\Program Files (x86)\Frontier\apps\ComputerSecurity\HIPS\drivers\fshs.sys [69480 2014-03-03] (F-Secure Corporation)
R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [56016 2013-10-16] ()
R3 fsni; C:\Program Files (x86)\Frontier\apps\CCF_Scanning\fsni64.sys [80832 2013-04-25] (F-Secure Corporation)
R1 fsvista; C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys [13248 2013-08-14] ()
S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-04-30 07:18 - 2014-04-30 07:19 - 00011108 _____ () C:\Users\Judith\Desktop\FRST.txt
2014-04-30 07:18 - 2014-04-30 07:18 - 00000000 ____D () C:\FRST
2014-04-30 07:11 - 2014-04-30 07:11 - 02060800 _____ (Farbar) C:\Users\Judith\Desktop\FRST64.exe
2014-04-29 22:25 - 2014-04-29 22:25 - 00688992 ____R (Swearware) C:\Users\Judith\Desktop\dds.scr
2014-04-29 15:28 - 2014-04-29 15:31 - 08584192 _____ () C:\Users\Guest\Downloads\EMET Setup.msi
2014-04-29 15:28 - 2014-04-29 15:28 - 00000000 ____D () C:\Users\Guest\AppData\Local\Adobe
2014-04-27 13:07 - 2014-04-27 13:07 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-04-27 13:06 - 2014-04-13 19:24 - 00465408 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-04-27 13:06 - 2014-04-13 19:19 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-04-26 15:40 - 2014-04-26 15:40 - 00000000 ____D () C:\Users\Guest\Desktop\Old Firefox Data
2014-04-25 21:11 - 2014-04-29 07:58 - 00000000 ____D () C:\Users\Guest\AppData\Local\CrashDumps
2014-04-23 17:18 - 2014-04-30 06:54 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-23 17:13 - 2014-04-23 17:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-23 17:13 - 2014-04-23 17:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-23 17:13 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-04-23 17:13 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-20 15:43 - 2014-04-20 15:43 - 00000000 ____D () C:\Users\Guest\AppData\Local\Conexant
2014-04-20 12:52 - 2014-04-20 12:52 - 00000000 ____D () C:\Users\Guest\AppData\Local\Macromedia
2014-04-20 07:30 - 2014-04-20 07:30 - 01071296 _____ (Solid State Networks) C:\Users\Guest\Downloads\install_flashplayer11x64_mssd_aih.exe
2014-04-19 08:05 - 2014-04-19 08:05 - 00000000 ____D () C:\Users\Judith\Documents\My Weblog Posts
2014-04-19 08:05 - 2014-04-19 08:05 - 00000000 ____D () C:\Users\Judith\AppData\Roaming\Windows Live Writer
2014-04-19 08:05 - 2014-04-19 08:05 - 00000000 ____D () C:\Users\Judith\AppData\Local\Windows Live Writer
2014-04-19 08:05 - 2014-04-19 08:05 - 00000000 ____D () C:\Users\Judith\AppData\Local\{9773292F-A589-44F7-BBF1-297635A09374}
2014-04-18 19:15 - 2014-04-18 19:15 - 00002962 _____ () C:\windows\System32\Tasks\{51BAB293-CAA6-4ED4-BEE7-EDE573C4C098}
2014-04-18 19:14 - 2014-04-18 19:14 - 00002962 _____ () C:\windows\System32\Tasks\{B15AF9A3-4973-4356-A12E-1AC4CC6851FA}
2014-04-18 08:03 - 2014-04-18 08:03 - 00002178 _____ () C:\Users\Public\Desktop\Epson Easy Photo Print.lnk
2014-04-18 08:03 - 2014-04-18 08:03 - 00000000 ____D () C:\ProgramData\Sony Corporation
2014-04-18 07:10 - 2014-04-18 07:10 - 00000000 _____ () C:\Users\Guest\Sti_Trace.log
2014-04-18 07:05 - 2014-04-18 07:08 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Epson
2014-04-17 22:54 - 2014-04-17 22:54 - 00000000 ____D () C:\epson
2014-04-17 21:11 - 2014-04-17 21:11 - 00001130 _____ () C:\Users\Judith\Desktop\MyEpson.lnk
2014-04-17 21:11 - 2014-04-17 21:11 - 00001130 _____ () C:\Users\Guest\Desktop\MyEpson.lnk
2014-04-17 21:09 - 2014-04-17 21:09 - 00000000 ____D () C:\Users\Judith\AppData\Roaming\Leadertech
2014-04-17 21:06 - 2007-09-07 17:33 - 00135168 _____ (SEIKO EPSON CORPORATION) C:\windows\SysWOW64\EEBAPI.dll
2014-04-17 21:06 - 2007-03-28 18:26 - 00065536 _____ (SEIKO EPSON CORPORATION) C:\windows\SysWOW64\EEBUtil.dll
2014-04-17 21:06 - 2006-12-19 18:31 - 00110592 _____ (SEIKO EPSON CORPORATION) C:\windows\SysWOW64\EEBDSCVR.dll
2014-04-17 21:06 - 2006-12-19 18:20 - 00077824 _____ (SEIKO EPSON CORPORATION) C:\windows\SysWOW64\EBAPI.dll
2014-04-17 21:06 - 2003-12-17 01:01 - 00055808 _____ (SEIKO EPSON CORPORATION) C:\windows\SysWOW64\EEBSDKIF.dll
2014-04-17 21:03 - 2014-04-17 21:03 - 00000000 ____D () C:\Program Files (x86)\EpsonNet
2014-04-17 21:00 - 2014-04-17 21:00 - 00000000 ____D () C:\Program Files\EpsonNet
2014-04-17 21:00 - 2012-11-12 20:41 - 00535552 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\ensppui.dll
2014-04-17 21:00 - 2012-11-12 20:41 - 00535552 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\enppui.dll
2014-04-17 21:00 - 2012-11-12 15:15 - 00558592 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\ensppmon.dll
2014-04-17 21:00 - 2012-11-12 15:15 - 00558592 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\enppmon.dll
2014-04-17 21:00 - 2012-10-22 17:19 - 00219648 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\enspres.dll
2014-04-17 21:00 - 2012-10-22 17:19 - 00219648 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\enpres.dll
2014-04-17 20:50 - 2014-04-17 21:11 - 00000090 _____ () C:\windows\EPART810.ini
2014-04-17 20:33 - 2014-04-17 21:09 - 00001176 _____ () C:\Users\Public\Desktop\Artisan 810 Info Center.lnk
2014-04-17 20:27 - 2014-04-17 20:29 - 00000000 ____D () C:\Users\Judith\AppData\Local\{82E3A1AD-4ED9-4F40-B279-936CE7770710}
2014-04-17 20:27 - 2014-04-17 20:27 - 00000000 ____D () C:\Users\Judith\AppData\Local\{A6800D97-1746-49DF-9FE6-6E56ACAFB703}
2014-04-17 19:59 - 2014-04-18 08:03 - 00000000 ____D () C:\ProgramData\UDL
2014-04-17 19:53 - 2014-04-17 19:58 - 35440928 _____ () C:\Users\Judith\Downloads\easyphotoprint_win.exe
2014-04-17 12:34 - 2014-04-17 12:51 - 00000000 ____D () C:\windows\erdnt
2014-04-17 11:56 - 2007-12-06 17:08 - 00108032 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\E_ILMEMA.DLL
2014-04-17 11:56 - 2007-12-06 17:01 - 00081408 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\E_IBCBEMA.DLL
2014-04-17 11:08 - 2014-04-17 21:08 - 00001090 _____ () C:\Users\Public\Desktop\Print CD.lnk
2014-04-17 11:07 - 2014-04-17 20:55 - 00000000 ____D () C:\Users\Judith\AppData\Roaming\EPSON
2014-04-17 11:07 - 2014-04-17 11:07 - 00000000 _____ () C:\Users\Judith\Sti_Trace.log
2014-04-17 11:04 - 2014-04-18 08:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software
2014-04-17 11:00 - 2014-04-18 08:03 - 00000000 ____D () C:\Program Files (x86)\Epson Software
2014-04-17 11:00 - 2006-10-31 00:10 - 00051360 _____ (SEIKO EPSON CORPORATION) C:\windows\SysWOW64\EpPicPrt.dll
2014-04-17 11:00 - 2006-10-31 00:10 - 00051360 _____ (SEIKO EPSON CORPORATION) C:\windows\SysWOW64\EpPicMgr.dll
2014-04-17 11:00 - 2006-10-31 00:10 - 00000097 _____ () C:\windows\SysWOW64\PICSDK.ini
2014-04-17 11:00 - 2006-10-20 00:10 - 00501912 _____ (SEIKO EPSON CORPORATION) C:\windows\SysWOW64\PICSDK2.dll
2014-04-17 11:00 - 2006-10-20 00:10 - 00108704 _____ (SEIKO EPSON CORPORATION) C:\windows\SysWOW64\PICEntry.dll
2014-04-17 11:00 - 2006-10-20 00:10 - 00080024 _____ (SEIKO EPSON CORPORATION) C:\windows\SysWOW64\PICSDK.dll
2014-04-17 11:00 - 2004-03-03 06:10 - 00073220 _____ () C:\windows\SysWOW64\EPPICPrinterDB.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00031053 _____ () C:\windows\SysWOW64\EPPICPattern131.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00029114 _____ () C:\windows\SysWOW64\EPPICPattern1.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00027417 _____ () C:\windows\SysWOW64\EPPICPattern121.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00021021 _____ () C:\windows\SysWOW64\EPPICPattern3.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00015670 _____ () C:\windows\SysWOW64\EPPICPattern5.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00013280 _____ () C:\windows\SysWOW64\EPPICPattern2.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00012669 _____ () C:\windows\SysWOW64\EPPICLocal_EN.cfg
2014-04-17 11:00 - 2004-03-03 06:10 - 00010673 _____ () C:\windows\SysWOW64\EPPICPattern4.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00006478 _____ () C:\windows\SysWOW64\EPPICLocal_PT.cfg
2014-04-17 11:00 - 2004-03-03 06:10 - 00006478 _____ () C:\windows\SysWOW64\EPPICLocal_BP.cfg
2014-04-17 11:00 - 2004-03-03 06:10 - 00006366 _____ () C:\windows\SysWOW64\EPPICLocal_FR.cfg
2014-04-17 11:00 - 2004-03-03 06:10 - 00006366 _____ () C:\windows\SysWOW64\EPPICLocal_CF.cfg
2014-04-17 11:00 - 2004-03-03 06:10 - 00006226 _____ () C:\windows\SysWOW64\EPPICLocal_ES.cfg
2014-04-17 11:00 - 2004-03-03 06:10 - 00004943 _____ () C:\windows\SysWOW64\EPPICPattern6.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00001140 _____ () C:\windows\SysWOW64\EPPICPresetData_PT.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00001140 _____ () C:\windows\SysWOW64\EPPICPresetData_BP.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00001137 _____ () C:\windows\SysWOW64\EPPICPresetData_ES.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00001130 _____ () C:\windows\SysWOW64\EPPICPresetData_FR.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00001130 _____ () C:\windows\SysWOW64\EPPICPresetData_CF.dat
2014-04-17 11:00 - 2004-03-03 06:10 - 00001104 _____ () C:\windows\SysWOW64\EPPICPresetData_EN.dat
2014-04-17 10:59 - 2014-04-17 20:52 - 00000000 ____D () C:\ProgramData\EPSON
2014-04-17 10:59 - 2008-11-12 03:00 - 00118784 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\E_ILMFRA.DLL
2014-04-17 10:59 - 2008-11-12 03:00 - 00081920 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\E_IBCBFRA.DLL
2014-04-17 10:58 - 2014-04-17 21:11 - 00000000 ____D () C:\Program Files (x86)\epson
2014-04-17 10:58 - 2014-04-17 21:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2014-04-17 10:58 - 2014-04-17 20:51 - 00000941 _____ () C:\Users\Public\Desktop\EPSON Scan.lnk
2014-04-17 10:58 - 2009-05-01 00:00 - 00128392 _____ (Seiko Epson Corporation) C:\windows\system32\esdevapp.exe
2014-04-17 10:58 - 2009-05-01 00:00 - 00017408 _____ (SEIKO EPSON CORP.) C:\windows\system32\esxcdev.dll
2014-04-17 10:58 - 2008-11-17 00:00 - 00459776 _____ (Seiko Epson Corporation) C:\windows\system32\esxwiaud.dll
2014-04-17 10:43 - 2014-04-17 10:43 - 01423224 _____ (Adobe Systems Incorporated) C:\Users\Judith\Downloads\AcroRd32.exe
2014-04-17 09:58 - 2014-04-17 10:45 - 71125280 _____ () C:\Users\Judith\Downloads\epson13157.exe
2014-04-17 09:18 - 2014-04-17 09:18 - 00000000 ____D () C:\Users\Judith\Documents\Fax
2014-04-14 17:09 - 2014-04-15 15:55 - 00000515 _____ () C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\MSN.com.website
2014-04-12 19:56 - 2014-04-12 19:56 - 00522240 _____ (OldTimer Tools) C:\Users\Guest\Desktop\OTM.exe
2014-04-12 09:54 - 2014-04-12 09:57 - 00033816 _____ () C:\Users\Guest\Desktop\SystemLook.txt
2014-04-12 09:45 - 2014-04-12 09:45 - 00165376 _____ () C:\Users\Guest\Desktop\SystemLook_x64.exe
2014-04-11 12:34 - 2014-04-11 18:55 - 00000184 _____ () C:\Users\Guest\Desktop\toshiba page.txt
2014-04-09 09:15 - 2014-03-12 23:33 - 02238976 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-04-09 09:15 - 2014-03-12 23:33 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-04-09 09:15 - 2014-03-12 23:33 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-04-09 09:15 - 2014-03-12 23:32 - 19273728 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-04-09 09:15 - 2014-03-12 23:32 - 03959808 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-04-09 09:15 - 2014-03-12 23:32 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-04-09 09:15 - 2014-03-12 23:32 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-04-09 09:15 - 2014-03-12 23:32 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-04-09 09:15 - 2014-03-12 23:32 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-04-09 09:15 - 2014-03-12 23:31 - 15404544 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-04-09 09:15 - 2014-03-12 23:31 - 02648576 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-04-09 09:15 - 2014-03-12 23:31 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-04-09 09:15 - 2014-03-12 23:31 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2014-04-09 09:15 - 2014-03-12 23:31 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-04-09 09:15 - 2014-03-12 23:31 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-04-09 09:15 - 2014-03-12 22:10 - 01766400 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-04-09 09:15 - 2014-03-12 22:10 - 01140736 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 14358016 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 02877952 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 02049536 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 00391168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 00039936 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-04-09 09:15 - 2014-03-12 22:09 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-04-09 09:15 - 2014-03-12 21:57 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-04-09 09:15 - 2014-03-12 21:47 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-04-09 09:15 - 2014-03-12 20:59 - 00089600 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2014-04-09 09:15 - 2014-03-12 20:51 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2014-04-09 09:13 - 2014-02-03 19:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2014-04-09 09:12 - 2014-03-04 02:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2014-04-09 09:12 - 2014-03-04 02:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2014-04-09 09:12 - 2014-03-04 02:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2014-04-09 09:12 - 2014-03-04 02:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2014-04-09 09:12 - 2014-03-04 02:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2014-04-09 09:12 - 2014-03-04 02:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2014-04-09 09:12 - 2014-03-04 02:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2014-04-09 09:12 - 2014-03-04 02:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2014-04-09 09:12 - 2014-03-04 02:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2014-04-09 09:12 - 2014-03-04 01:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2014-04-09 09:12 - 2014-03-04 01:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2014-04-09 09:12 - 2014-02-03 19:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2014-04-09 09:12 - 2014-02-03 19:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2014-04-09 09:12 - 2014-02-03 19:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2014-04-09 09:12 - 2014-02-03 19:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll
2014-04-09 09:12 - 2014-01-23 19:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2014-04-08 09:22 - 2014-04-08 09:22 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Malwarebytes
2014-04-08 08:10 - 2014-04-08 08:11 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Mozilla
2014-04-08 08:10 - 2014-04-08 08:11 - 00000000 ____D () C:\Users\Guest\AppData\Local\Mozilla
2014-04-07 10:37 - 2014-04-07 10:39 - 00001714 _____ () C:\DelFix.txt
2014-04-03 16:34 - 2014-04-29 22:31 - 00008796 _____ () C:\Users\Judith\Desktop\attach.txt

==================== One Month Modified Files and Folders =======

2014-04-30 07:19 - 2014-04-30 07:18 - 00011108 _____ () C:\Users\Judith\Desktop\FRST.txt
2014-04-30 07:18 - 2014-04-30 07:18 - 00000000 ____D () C:\FRST
2014-04-30 07:14 - 2013-03-31 23:57 - 00003926 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{D4940CF2-687B-4072-9529-E1ACB9C40F93}
2014-04-30 07:11 - 2014-04-30 07:11 - 02060800 _____ (Farbar) C:\Users\Judith\Desktop\FRST64.exe
2014-04-30 07:00 - 2009-07-13 21:45 - 00024608 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-30 07:00 - 2009-07-13 21:45 - 00024608 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-30 06:56 - 2014-01-25 10:24 - 01719932 _____ () C:\windows\WindowsUpdate.log
2014-04-30 06:54 - 2014-04-23 17:18 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-30 06:52 - 2014-02-20 04:11 - 00005198 _____ () C:\windows\setupact.log
2014-04-30 06:52 - 2009-07-13 22:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-29 23:52 - 2009-07-13 22:13 - 00782470 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-29 23:24 - 2014-03-25 14:34 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-29 22:31 - 2014-04-03 16:34 - 00008796 _____ () C:\Users\Judith\Desktop\attach.txt
2014-04-29 22:25 - 2014-04-29 22:25 - 00688992 ____R (Swearware) C:\Users\Judith\Desktop\dds.scr
2014-04-29 15:31 - 2014-04-29 15:28 - 08584192 _____ () C:\Users\Guest\Downloads\EMET Setup.msi
2014-04-29 15:28 - 2014-04-29 15:28 - 00000000 ____D () C:\Users\Guest\AppData\Local\Adobe
2014-04-29 15:28 - 2013-07-23 20:31 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Adobe
2014-04-29 14:26 - 2014-03-25 14:34 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-04-29 14:26 - 2014-03-25 14:34 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-29 14:26 - 2014-03-25 14:34 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-04-29 07:58 - 2014-04-25 21:11 - 00000000 ____D () C:\Users\Guest\AppData\Local\CrashDumps
2014-04-27 13:07 - 2014-04-27 13:07 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-04-26 15:41 - 2013-04-12 19:50 - 00000000 ____D () C:\Users\Judith\AppData\Local\Adobe
2014-04-26 15:40 - 2014-04-26 15:40 - 00000000 ____D () C:\Users\Guest\Desktop\Old Firefox Data
2014-04-23 17:13 - 2014-04-23 17:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-23 17:13 - 2014-04-23 17:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-23 17:13 - 2013-12-07 11:58 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-23 17:13 - 2013-12-07 11:58 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-04-23 17:13 - 2013-09-18 20:41 - 00000000 ____D () C:\Users\Judith\AppData\Roaming\Malwarebytes
2014-04-23 17:13 - 2013-09-18 20:41 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-20 15:43 - 2014-04-20 15:43 - 00000000 ____D () C:\Users\Guest\AppData\Local\Conexant
2014-04-20 12:52 - 2014-04-20 12:52 - 00000000 ____D () C:\Users\Guest\AppData\Local\Macromedia
2014-04-20 07:30 - 2014-04-20 07:30 - 01071296 _____ (Solid State Networks) C:\Users\Guest\Downloads\install_flashplayer11x64_mssd_aih.exe
2014-04-19 14:19 - 2013-02-08 18:33 - 00000000 ___RD () C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-19 08:05 - 2014-04-19 08:05 - 00000000 ____D () C:\Users\Judith\Documents\My Weblog Posts
2014-04-19 08:05 - 2014-04-19 08:05 - 00000000 ____D () C:\Users\Judith\AppData\Roaming\Windows Live Writer
2014-04-19 08:05 - 2014-04-19 08:05 - 00000000 ____D () C:\Users\Judith\AppData\Local\Windows Live Writer
2014-04-19 08:05 - 2014-04-19 08:05 - 00000000 ____D () C:\Users\Judith\AppData\Local\{9773292F-A589-44F7-BBF1-297635A09374}
2014-04-18 19:15 - 2014-04-18 19:15 - 00002962 _____ () C:\windows\System32\Tasks\{51BAB293-CAA6-4ED4-BEE7-EDE573C4C098}
2014-04-18 19:14 - 2014-04-18 19:14 - 00002962 _____ () C:\windows\System32\Tasks\{B15AF9A3-4973-4356-A12E-1AC4CC6851FA}
2014-04-18 08:21 - 2013-11-27 12:46 - 00002074 _____ () C:\Users\Judith\Desktop\Dorkas.txt
2014-04-18 08:03 - 2014-04-18 08:03 - 00002178 _____ () C:\Users\Public\Desktop\Epson Easy Photo Print.lnk
2014-04-18 08:03 - 2014-04-18 08:03 - 00000000 ____D () C:\ProgramData\Sony Corporation
2014-04-18 08:03 - 2014-04-17 19:59 - 00000000 ____D () C:\ProgramData\UDL
2014-04-18 08:03 - 2014-04-17 11:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software
2014-04-18 08:03 - 2014-04-17 11:00 - 00000000 ____D () C:\Program Files (x86)\Epson Software
2014-04-18 08:03 - 2011-03-29 19:48 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-18 07:10 - 2014-04-18 07:10 - 00000000 _____ () C:\Users\Guest\Sti_Trace.log
2014-04-18 07:10 - 2013-02-09 16:13 - 00000000 ____D () C:\Users\Guest
2014-04-18 07:08 - 2014-04-18 07:05 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Epson
2014-04-17 22:54 - 2014-04-17 22:54 - 00000000 ____D () C:\epson
2014-04-17 21:11 - 2014-04-17 21:11 - 00001130 _____ () C:\Users\Judith\Desktop\MyEpson.lnk
2014-04-17 21:11 - 2014-04-17 21:11 - 00001130 _____ () C:\Users\Guest\Desktop\MyEpson.lnk
2014-04-17 21:11 - 2014-04-17 20:50 - 00000090 _____ () C:\windows\EPART810.ini
2014-04-17 21:11 - 2014-04-17 10:58 - 00000000 ____D () C:\Program Files (x86)\epson
2014-04-17 21:11 - 2009-07-13 22:32 - 00000000 ____D () C:\windows\system32\FxsTmp
2014-04-17 21:09 - 2014-04-17 21:09 - 00000000 ____D () C:\Users\Judith\AppData\Roaming\Leadertech
2014-04-17 21:09 - 2014-04-17 20:33 - 00001176 _____ () C:\Users\Public\Desktop\Artisan 810 Info Center.lnk
2014-04-17 21:08 - 2014-04-17 11:08 - 00001090 _____ () C:\Users\Public\Desktop\Print CD.lnk
2014-04-17 21:04 - 2014-04-17 10:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2014-04-17 21:03 - 2014-04-17 21:03 - 00000000 ____D () C:\Program Files (x86)\EpsonNet
2014-04-17 21:00 - 2014-04-17 21:00 - 00000000 ____D () C:\Program Files\EpsonNet
2014-04-17 20:55 - 2014-04-17 11:07 - 00000000 ____D () C:\Users\Judith\AppData\Roaming\EPSON
2014-04-17 20:52 - 2014-04-17 10:59 - 00000000 ____D () C:\ProgramData\EPSON
2014-04-17 20:51 - 2014-04-17 10:58 - 00000941 _____ () C:\Users\Public\Desktop\EPSON Scan.lnk
2014-04-17 20:29 - 2014-04-17 20:27 - 00000000 ____D () C:\Users\Judith\AppData\Local\{82E3A1AD-4ED9-4F40-B279-936CE7770710}
2014-04-17 20:27 - 2014-04-17 20:27 - 00000000 ____D () C:\Users\Judith\AppData\Local\{A6800D97-1746-49DF-9FE6-6E56ACAFB703}
2014-04-17 19:58 - 2014-04-17 19:53 - 35440928 _____ () C:\Users\Judith\Downloads\easyphotoprint_win.exe
2014-04-17 19:43 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\system32\NDF
2014-04-17 19:14 - 2014-02-20 04:11 - 00123550 _____ () C:\windows\PFRO.log
2014-04-17 14:42 - 2009-07-13 19:34 - 00000215 _____ () C:\windows\system.ini
2014-04-17 12:54 - 2009-07-13 20:20 - 00000000 __RHD () C:\Users\Default
2014-04-17 12:51 - 2014-04-17 12:34 - 00000000 ____D () C:\windows\erdnt
2014-04-17 12:51 - 2013-02-08 17:19 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-17 12:51 - 2013-02-08 17:19 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-17 11:07 - 2014-04-17 11:07 - 00000000 _____ () C:\Users\Judith\Sti_Trace.log
2014-04-17 11:07 - 2013-02-08 18:33 - 00000000 ____D () C:\Users\Judith
2014-04-17 10:45 - 2014-04-17 09:58 - 71125280 _____ () C:\Users\Judith\Downloads\epson13157.exe
2014-04-17 10:43 - 2014-04-17 10:43 - 01423224 _____ (Adobe Systems Incorporated) C:\Users\Judith\Downloads\AcroRd32.exe
2014-04-17 09:18 - 2014-04-17 09:18 - 00000000 ____D () C:\Users\Judith\Documents\Fax
2014-04-15 15:55 - 2014-04-14 17:09 - 00000515 _____ () C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\MSN.com.website
2014-04-13 19:24 - 2014-04-27 13:06 - 00465408 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-04-13 19:19 - 2014-04-27 13:06 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-04-12 20:53 - 2009-07-13 22:08 - 00032588 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-04-12 19:56 - 2014-04-12 19:56 - 00522240 _____ (OldTimer Tools) C:\Users\Guest\Desktop\OTM.exe
2014-04-12 12:29 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\rescache
2014-04-12 09:57 - 2014-04-12 09:54 - 00033816 _____ () C:\Users\Guest\Desktop\SystemLook.txt
2014-04-12 09:45 - 2014-04-12 09:45 - 00165376 _____ () C:\Users\Guest\Desktop\SystemLook_x64.exe
2014-04-11 18:55 - 2014-04-11 12:34 - 00000184 _____ () C:\Users\Guest\Desktop\toshiba page.txt
2014-04-11 08:44 - 2014-02-24 22:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-10 08:25 - 2014-02-14 22:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-09 16:53 - 2013-02-27 10:41 - 00000000 ____D () C:\Users\Judith\AppData\Local\CrashDumps
2014-04-09 09:26 - 2013-02-23 11:58 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-09 09:23 - 2013-07-12 21:30 - 00000000 ____D () C:\windows\system32\MRT
2014-04-09 09:20 - 2013-02-08 19:40 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-04-08 22:22 - 2013-02-09 16:17 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Toshiba
2014-04-08 22:21 - 2013-02-09 16:17 - 00109688 _____ () C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-08 09:22 - 2014-04-08 09:22 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Malwarebytes
2014-04-08 08:11 - 2014-04-08 08:10 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Mozilla
2014-04-08 08:11 - 2014-04-08 08:10 - 00000000 ____D () C:\Users\Guest\AppData\Local\Mozilla
2014-04-08 08:08 - 2013-02-09 16:14 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-08 08:08 - 2013-02-09 16:13 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-08 08:07 - 2013-02-09 16:14 - 00001424 _____ () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-08 08:07 - 2009-07-13 20:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-04-07 10:39 - 2014-04-07 10:37 - 00001714 _____ () C:\DelFix.txt
2014-04-05 15:25 - 2013-09-07 22:54 - 00000000 ____D () C:\Users\Judith\AppData\Local\Macromedia
2014-04-04 22:54 - 2013-02-23 11:58 - 00000000 ____D () C:\Users\Judith\AppData\Local\Microsoft Help
2014-04-03 09:51 - 2014-04-23 17:13 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-23 17:13 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2013-12-07 11:58 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-03-31 09:35 - 2010-11-20 20:27 - 00270496 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2014-04-29 22:08

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-04-2014 01
Ran by Judith at 2014-04-30 07:19:53
Running from C:\Users\Judith\Desktop
Boot Mode: Normal

==================== Security Center ========================

AV: Computer Security (Disabled - Up to date) {15414183-282E-D62C-CA37-EF24860A2F17}
AS: Computer Security (Disabled - Up to date) {AE20A067-0E14-D9A2-F087-D456FD8D65AA}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: - Amazon Services LLC)
Amazon Music Importer (HKLM-x32\...\com.amazon.music.uploader) (Version: 2.1.0 - Amazon Services LLC)
Amazon Music Importer (x32 Version: 2.1.0 - Amazon Services LLC) Hidden
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: - Atheros Communications Inc.)
ATI Catalyst Install Manager (HKLM\...\{1D27E8CF-7546-F200-4CA3-CD2F39909F5A}) (Version: 3.0.808.0 - ATI Technologies, Inc.)
Best Buy pc app (Version: - Best Buy) Hidden
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0216.726.13233 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2011.0216.726.13233 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2011.0216.726.13233 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Czech (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Danish (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Dutch (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help English (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Finnish (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help French (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help German (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Greek (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Italian (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Japanese (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Korean (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Polish (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Russian (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Spanish (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Swedish (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Thai (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
CCC Help Turkish (x32 Version: 2011.0216.0725.13233 - ATI) Hidden
ccc-core-static (x32 Version: 2011.0216.726.13233 - ATI) Hidden
ccc-utility64 (Version: 2011.0216.726.13233 - ATI) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform)
Computer Security (release) (x32 Version: - F-Secure Corporation) Hidden
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: - Conexant)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5971CA1F-6BDE-498F-952C-9F2BF94070A4}) (Version:  - Microsoft)
EPSON Artisan 800 Series Printer Uninstall (HKLM\...\EPSON Artisan 800 Series) (Version:  - SEIKO EPSON Corporation)
EPSON Artisan 810 Series Printer Uninstall (HKLM\...\EPSON Artisan 810 Series) (Version:  - SEIKO EPSON Corporation)
Epson Easy Photo Print 2 (HKLM-x32\...\{674E262F-72EA-41C1-AF16-9727311A4553}) (Version: - SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM-x32\...\{48F22622-1CC2-4A83-9C1E-644DD96F832D}) (Version: 2.30.01 - SEIKO EPSON Corporation)
Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.00.01 - SEIKO EPSON CORPORATION)
Epson Print CD (HKLM-x32\...\{D16A31F9-276D-4968-A753-FFEAC56995D0}) (Version: 2.00.00 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION)
EpsonNet Setup (HKLM-x32\...\{FFFAE01B-466F-4C07-9821-A94FD753BDDA}) (Version: 3.1c - SEIKO EPSON CORPORATION)
ETDWare PS/2-X64 (HKLM\...\Elantech) (Version: - ELAN Microelectronic Corp.)
Frontier Secure (HKLM-x32\...\F-Secure ServiceEnabler 53784) (Version: 1.83.311.0 - F-Secure Corporation)
Frontier Secure (x32 Version: 1.83.311.0 - F-Secure Corporation) Hidden
F-Secure CCF Reputation (x32 Version: - F-Secure) Hidden
F-Secure CCF Scanning (release) (x32 Version: - F-Secure Corporation) Hidden
F-Secure Network CCF 1.02.128 (x32 Version: - F-Secure Corporation) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Label@Once 1.0 (HKLM-x32\...\{0D795777-9D60-4692-8386-F2B3F2B5E5BF}) (Version: 1.0 - Corel)
Malwarebytes Anti-Malware version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (Version: - Microsoft Corporation) Hidden
Microsoft Office Access MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 28.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 en-US)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
Online Safety 2.83.1329.952 (x32 Version: 2.83.1329.952 - F-Secure Corporation) Hidden
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30124 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0016 - REALTEK Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
swMSM (x32 Version: - Adobe Systems, Inc) Hidden
TOSHIBA Application Installer (HKLM-x32\...\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: - TOSHIBA)
TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.02.02 - TOSHIBA CORPORATION)
TOSHIBA Bulletin Board (HKLM-x32\...\InstallShield_{C14518AF-1A0F-4D39-8011-69BAA01CD380}) (Version: - TOSHIBA Corporation)
TOSHIBA Bulletin Board (Version: - TOSHIBA Corporation) Hidden
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: for x64 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\...\{8E9CEA3B-EBD1-439C-A01D-830CB39613C6}) (Version: 2.00.14 - TOSHIBA Corporation)
TOSHIBA HDD/SSD Alert (HKLM-x32\...\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: - TOSHIBA Corporation)
TOSHIBA HDD/SSD Alert (Version: - TOSHIBA Corporation) Hidden
TOSHIBA HDD/SSD Alert (x32 Version: - TOSHIBA Corporation) Hidden
TOSHIBA Media Controller (HKLM-x32\...\{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}) (Version: - TOSHIBA CORPORATION)
TOSHIBA Quality Application (HKLM-x32\...\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.3 - TOSHIBA)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: - TOSHIBA CORPORATION)
TOSHIBA ReelTime (HKLM-x32\...\InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}) (Version: - TOSHIBA Corporation)
TOSHIBA ReelTime (Version: - TOSHIBA Corporation) Hidden
TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.9 - TOSHIBA)
TOSHIBA Supervisor Password (HKLM-x32\...\{073B89C3-BA88-41B5-965F-B35A88EAE838}) (Version: 2.00.07 - TOSHIBA Corporation)
TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: - TOSHIBA Corporation)
TOSHIBA Value Added Package (Version: - TOSHIBA Corporation) Hidden
TOSHIBA Value Added Package (x32 Version: - TOSHIBA Corporation) Hidden
ToshibaRegistration (HKLM-x32\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.0.4 - Toshiba)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{5E8EB600-8B94-429E-873E-98369C6DC1BC}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{DCE104A1-1875-4469-A83D-A5BFA6C4640F}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{334AA0A1-2BB1-4D74-B66A-2B2C4D9C2C87}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{799005D3-9B70-4219-AFE0-BC479614CC4D}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version:  - Microsoft)
Waterfox 27.0.2 (x64 en-US) (HKLM\...\Waterfox 27.0.2 (x64 en-US)) (Version: 27.0.2 - Mozilla)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
WMV9/VC-1 Video Playback (Version: 1.00.0000 - ATI Technologies Inc.) Hidden

==================== Restore Points  =========================

11-04-2014 20:47:15 OTL Restore Point - 4/11/2014 1:47:11 PM
15-04-2014 14:07:40 Windows Update
17-04-2014 18:00:47 Installed Epson Event Manager
17-04-2014 18:02:39 Installed EPSON Scan Assistant
17-04-2014 18:03:49 Installed Attach To Email
17-04-2014 18:07:51 Installed Epson Print CD
18-04-2014 03:54:07 Installed FAX Utility
18-04-2014 04:00:10 Installed EpsonNet Print
18-04-2014 04:02:58 Configured EpsonNet Print
18-04-2014 04:03:35 Installed EpsonNet Setup
18-04-2014 04:08:12 Installed Epson Print CD
18-04-2014 14:11:48 Windows Update
20-04-2014 00:28:09 Removed Java 7 Update 51
20-04-2014 00:29:24 Removed Java 7 Update 51
22-04-2014 13:41:57 Windows Update
27-04-2014 20:07:15 Windows Update

==================== Hosts content: ==========================

2009-07-13 19:34 - 2014-04-17 12:50 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0FE80366-8A82-4B97-86F4-7DD0582BE800} - System32\Tasks\{C61D0DB7-19E8-42FC-8186-E8023D65E8B8} => Firefox.exe
Task: {270CA8DD-E40C-4512-B522-0BF8FEFF8483} - System32\Tasks\{B4705F96-9088-4C7F-8B6C-A4F7DC5EABEC} => Firefox.exe
Task: {2DA53F4C-F384-4EEC-9D83-B0A848006CC1} - System32\Tasks\{B15AF9A3-4973-4356-A12E-1AC4CC6851FA} => C:\Program Files (x86)\Java\jre7\bin\javacpl.exe
Task: {3A27E351-E84C-42CB-B96E-CEBF66929C01} - System32\Tasks\{DA0BDAC5-032C-4A4F-8326-EEBE5440CD16} => Firefox.exe
Task: {3B758073-CCF7-4A02-9B3A-8ABE6D5189BB} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-29] (Adobe Systems Incorporated)
Task: {40912EF1-A8FC-43C5-A6C4-4ADCE81A9D34} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {5E50B421-C175-41B1-A0E9-447DCCC32701} - System32\Tasks\{0AEDA49D-1493-4E9D-A001-669FA5192D02} => Firefox.exe
Task: {61BFBB2C-8654-48A2-A18A-19F1298DA793} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {6873988D-2DE7-42A5-A68A-730699C43F31} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {B10D70BE-CD32-43A0-A386-4B9720E45D54} - System32\Tasks\{A36C11B9-6838-429F-8CC4-8FCC92D14C39} => C:\Users\Judith\Downloads\Silverlight_x64.exe [2013-10-15] (Microsoft Corporation)
Task: {C0000956-1C41-44CB-9243-442D7CC44B3B} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft)
Task: {C1756598-09F4-4E15-9143-DAB0317A521E} - System32\Tasks\{6F88532B-D144-4717-AE5F-28A0F751BAAB} => C:\Users\Judith\Desktop\ccsetup404.exe
Task: {C7F9E654-9593-4933-BA50-37C42B20D81C} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {E1796917-C4D3-4DB6-926D-EA7EE98CD435} - System32\Tasks\{2B8CE091-096B-4BE4-A871-8371B0BD267C} => C:\Users\Judith\Downloads\Silverlight_x64.exe [2013-10-15] (Microsoft Corporation)
Task: {E80F36D5-A4A4-42E3-A239-1A5BBDE9C0C4} - System32\Tasks\{51BAB293-CAA6-4ED4-BEE7-EDE573C4C098} => C:\Program Files (x86)\Java\jre7\bin\javacpl.exe
Task: {F148F8C2-0F40-4376-8E77-E0B66BD1293B} - System32\Tasks\{D6316FFE-752C-4829-A453-86D7913742E7} => C:\Users\Judith\Desktop\ccsetup404.exe
Task: {F47827AD-3218-4D8B-AC45-4399CB9C7F05} - System32\Tasks\{48CF2A02-6F72-486B-A626-6565BF054CB7} => C:\Program Files\Waterfox\plugin-container.exe [2014-02-26] (Mozilla Corporation)
Task: {FF4A12EC-10D4-4399-B67D-F554F250B13E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2013-10-16 16:18 - 2013-08-14 05:22 - 00045504 _____ () C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Anti-Virus\FSAVHRES.ENG
2013-05-15 16:06 - 2013-05-15 16:06 - 00183232 _____ () C:\Program Files (x86)\Frontier\zlib_32.dll
2013-05-15 16:05 - 2013-05-15 16:05 - 00220096 _____ () C:\Program Files (x86)\Frontier\daas2.dll
2013-10-16 16:23 - 2013-10-16 16:23 - 00030888 _____ () C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Anti-Virus\minifilter\hashlib_x86.dll
2013-10-16 16:19 - 2013-12-10 19:38 - 00212008 _____ () C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Spam Control\fsas.dll
2013-10-16 16:18 - 2014-04-23 08:24 - 00949288 _____ () C:\Program Files (x86)\Frontier\apps\ComputerSecurity\Anti-Virus\fm4av.dll
2013-10-16 16:13 - 2013-10-16 16:13 - 00593464 _____ () C:\windows\WinSxS\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.482.65_none_b59e1e0911fd55ab\QtMultimediaKit1.dll
2013-10-16 16:18 - 2013-08-14 05:22 - 00056256 _____ () C:\Program Files (x86)\Frontier\apps\ComputerSecurity\FSGUI\fsavures.ENG
2014-04-17 11:03 - 2009-03-12 15:45 - 00135168 ____N () C:\Program Files (x86)\Epson Software\Event Manager\Assistants\Scan Assistant\ScanEngine.dll
2014-04-17 11:03 - 2008-11-21 13:58 - 00057344 ____N () C:\Program Files (x86)\Epson Software\Event Manager\Assistants\Scan Assistant\Satwain.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\MSN.com.website:TASKICON_0favicon1129903636
AlternateDataStreams: C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\MSN.com.website:TASKICON_1favicon-298702541
AlternateDataStreams: C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\MSN.com.website:TASKICON_2favicon-1464078272
AlternateDataStreams: C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\MSN.com.website:TASKICON_3favicon-860043155
AlternateDataStreams: C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\MSN.com.website:TASKICON_4favicon640180837

==================== Safe Mode (whitelisted) ===================

==================== Disabled items from MSCONFIG ==============

MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: TMachInfo => 3
MSCONFIG\Services: TOSHIBA HDD SSD Alert Service => 3
MSCONFIG\startupfolder: C:^Users^Judith^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: 00TCrdMain => %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Amazon Cloud Player => "C:\Users\Judith\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe"
MSCONFIG\startupreg: ETDCtrl => %ProgramFiles%\Elantech\ETDCtrl.exe
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: ToshibaServiceStation => "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
MSCONFIG\startupreg: TosNC => %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
MSCONFIG\startupreg: TosReelTimeMonitor => %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
Error: (04/30/2014 06:54:30 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/29/2014 00:36:41 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/28/2014 00:46:19 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/28/2014 08:28:11 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/28/2014 03:34:04 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/27/2014 06:58:40 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/26/2014 10:30:25 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/26/2014 08:54:47 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/26/2014 08:21:19 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/24/2014 07:35:31 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

System errors:
Error: (04/30/2014 06:54:31 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (04/29/2014 00:37:12 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (04/29/2014 00:35:10 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 9:13:43 AM on ‎4/‎29/‎2014 was unexpected.

Error: (04/28/2014 00:46:06 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (04/28/2014 08:28:19 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (04/28/2014 03:34:07 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (04/27/2014 06:58:24 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (04/26/2014 04:42:05 PM) (Source: DCOM) (User: KIRK-PC)
Description: application-specificLocalActivation{8BC3F05E-D86B-11D0-A075-00C04FB68820}{8BC3F05E-D86B-11D0-A075-00C04FB68820}KIRK-PCGuestS-1-5-21-1596010243-3757955604-700281957-501LocalHost (Using LRPC)

Error: (04/26/2014 03:40:28 PM) (Source: DCOM) (User: KIRK-PC)
Description: application-specificLocalActivation{8BC3F05E-D86B-11D0-A075-00C04FB68820}{8BC3F05E-D86B-11D0-A075-00C04FB68820}KIRK-PCGuestS-1-5-21-1596010243-3757955604-700281957-501LocalHost (Using LRPC)

Error: (04/26/2014 03:20:15 PM) (Source: DCOM) (User: KIRK-PC)
Description: application-specificLocalActivation{8BC3F05E-D86B-11D0-A075-00C04FB68820}{8BC3F05E-D86B-11D0-A075-00C04FB68820}KIRK-PCGuestS-1-5-21-1596010243-3757955604-700281957-501LocalHost (Using LRPC)

Microsoft Office Sessions:
Error: (04/30/2014 06:54:30 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/29/2014 00:36:41 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/28/2014 00:46:19 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/28/2014 08:28:11 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/28/2014 03:34:04 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/27/2014 06:58:40 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/26/2014 10:30:25 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/26/2014 08:54:47 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/26/2014 08:21:19 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/24/2014 07:35:31 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

CodeIntegrity Errors:
  Date: 2014-04-17 12:49:03.168
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-04-17 12:49:03.012
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Percentage of memory in use: 34%
Total physical RAM: 2662.87 MB
Available physical RAM: 1731.97 MB
Total Pagefile: 5323.91 MB
Available Pagefile: 3948.07 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (TI106147W0C) (Fixed) (Total:285.29 GB) (Free:242.93 GB) NTFS ==>[system with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: A9AEA8CE)
Partition 1: (Active) - (Size=1 GB) - (Type=27)
Partition 2: (Not Active) - (Size=285 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=11 GB) - (Type=17)

==================== End Of Log ============================

Hi, whonew:


Sorry, it looks as if the staff and forum experts haven't had a chance to review your logs and respond.


Alas, that task is above my pay-grade.


So, we'll need to wait to see if anyone has suggestions for you.


I apologize for the wait -- hopefully someone will be along soon to assist you with your issue.


Thanks for your patience,



One question before everyone disappears on me, could this have anything to do with my back up called " My Passport" That tech was suppose to fix the typing issue and for a few days seemed he had it fixed that was about the 23 or March . Is it possible ? I am asking because now it also has a problem shutting down Malwarebyts along with that other program that seems to keep running when I shut down.

Mine happen too, and it's windows 7, what can i do to prevent this.

It keeps on shutting down more than an hour

Somebody help me....


Each computer is unique and requires a custom solution for problems.


Please follow the instructions in post #2 >>HERE<< and then please start a NEW, separate post.

That way, both you and whonew can receive full attention for your issue, perhaps with less confusion. :)





until someone more knowledgeable has some input on this topic ...


"...lift the cover of this Toshiba Laptop and it will still be shutting down ..."

this is a little ambiguous .

have you tried shutting the machine down while leaving the screen "up" ?

(it may be something to do with the "sleep" or suspend" mode settings)

Link to post
Share on other sites

that is a step in the right direction .


what is the make/model of the printer ?

about your printer and compatibility issues ...

it is pretty much up to the various manufacturers if they want to write software to run their old equipment on a more modern OS .

if they do not write a software package then one is relegated to purchasing a more up to date printer .


i have two old printers that still work very well ...

the software is good for XP and vista (i never have owned/wanted to use vista) .

currently , they are being driven by a linux box and they are about to get stripped down for parts .

something strange ...

at the epson site there is software for the artisan 810 ... and it is written for W7 .

i would suggest looking closely at the messages that pop up ... and writing down exactly what they say .

as an option ...

do you have the original epson printer disk for W7 ?

if so , then try removing the program using "revo uninstaller" , and then re-install either from the disk or (a better way as it has updated drivers and such) download the software from here :


mind you , this is for W7 64 bit if you have a 32 bit machine you will have to select that from the drop-down list of available OS types (on the same page .

you want the "drivers and utilities combo package-network" .

do not select anything else .

save this file to your desktop and run it as "administrator" .

Thank you , will locate CD and see but doubt that had Window 7


If it is an older, discontinued printer model, then it's possible/likely that the drivers on the CD that came with the printer are NOT Win7-compatible.

That's why CWB suggested that you download the latest driver package for your model directly from the Epson site > uninstall the current version > reboot > install the new version > reboot.

It's important to follow instructions -- I know that for my HP printers, it's important NOT to connect the printer to the computer until the install wizard prompts to do so at the correct point in the installation process.

But the software installer should walk you through the steps.


I'm no expert and don't have any Epson products, but that's the general procedure for all peripherals, regardless of the brand.


Here is probably the page you want.


NOTE: It's important to select the driver package that applies to your particular version of Windows. As you can see from my attached screenshot, the web page detected (correctly) that I am running Win7(64-bit).  You would want to make sure to select the correct one for YOUR computer from the dropdown menu, if needed.


There are also links to other helpful resources (FAQ, troubleshooting guides, etc) on that same page.








