Jump to content

Recommended Posts

I was told to post my problem into this portion of the forum since it did not belong where I originally posted it.

 

Im a bit troubled at the moment. I was going through my custom scan configuration on Malwarebytes Anti-Malware and I went through Windows(C:) and found an odd file that says $360Section and when I click on it, it says 360Safe. I went around on the internet to see what it might be and alot of sites say that its malicious and I should get rid of it but I scanned it using custom scan and it did not find anything. Is this a dangerous file and should I get rid of it? if If it is, how do I get rid of it? I have Malwarebytes Anti-Malware Premium as well as SUPERAntiSpyware Free Edition and they both did not find anything.

 

Here is the FRST.txt and Addition.txt from Farbar Recovery Scan Tool

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015
Ran by lfaas (administrator) on TVROOMPC on 17-07-2015 11:46:00
Running from C:\Users\lfaas\Downloads
Loaded Profiles: lfaas (Available Profiles: lfaas)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
(Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Hewlett-Packard ) C:\Program Files\IDT\WDM\Beats64.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\redirector.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [beatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2012-08-22] (Hewlett-Packard )
HKLM\...\Run: [sysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-06-04] (IDT, Inc.)
HKLM\...\Run: [simplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2793016 2013-09-05] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [154680 2013-09-05] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [154680 2013-09-05] (Hewlett-Packard)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\...\Run: [CitrixReceiver] => "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk"
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-1079287707-3710102426-1868348366-1001\...\Run: [itibiti.exe] => C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
HKU\S-1-5-21-1079287707-3710102426-1868348366-1001\...\Run: [sUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7800088 2015-07-06] (SUPERAntiSpyware)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK14/1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK14/1
HKU\S-1-5-21-1079287707-3710102426-1868348366-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://webtop.webmail.optimum.net/
HKU\S-1-5-21-1079287707-3710102426-1868348366-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://us-mg6.mail.yahoo.com/neo/launch?.rand=4vuec87oa2pmb
https://my.yahoo.com/?mkg=015
SearchScopes: HKLM -> {C72246A6-2BF1-4454-A311-144B4E0B9F76} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-154371-11896-2/4?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {C72246A6-2BF1-4454-A311-144B4E0B9F76} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-154371-11896-2/4?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-1079287707-3710102426-1868348366-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1079287707-3710102426-1868348366-1001 -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL =
SearchScopes: HKU\S-1-5-21-1079287707-3710102426-1868348366-1001 -> {C72246A6-2BF1-4454-A311-144B4E0B9F76} URL =
SearchScopes: HKU\S-1-5-21-1079287707-3710102426-1868348366-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
BHO: No Name -> {E6B04436-35EF-5FB2-753D-C7A7DCEA8E90} ->  No File
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2013-10-01] (Citrix Systems, Inc.)
Winsock: Catalog9 11 %windir%\system32\vsocklib.dll File Not ' & $found1 & '
Winsock: Catalog9 12 %windir%\system32\vsocklib.dll File Not ' & $found1 & '
Winsock: Catalog9-x64 11 %windir%\system32\vsocklib.dll File Not ' & $found1 & '
Winsock: Catalog9-x64 12 %windir%\system32\vsocklib.dll File Not ' & $found1 & '
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{037017A9-B184-4A23-A9DE-21D8B6A49136}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\lfaas\AppData\Roaming\Mozilla\Firefox\Profiles\9pyx3ark.default-1433187244150
FF DefaultSearchEngine.US: Google
FF Homepage: about:home
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2013-10-01] (Citrix Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-12] (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-06] (Microsoft Corporation)
FF Extension: Adblock Plus - C:\Users\lfaas\AppData\Roaming\Mozilla\Firefox\Profiles\9pyx3ark.default-1433187244150\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-07-14]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2014-06-04] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-09-05] () [File not signed]
R2 CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-08-12] (CyberLink)
R2 CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-08-12] (CyberLink)
R2 Intel® Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-08-12] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-08-12] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-09-05] (Softex Inc.) [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [333824 2013-06-04] (IDT, Inc.) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-08-24] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
S3 COMSysApp; No ImagePath

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2014-06-04] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7480496 2014-06-04] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-17] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverx64.sys [99288 2013-08-12] (Intel Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
S1 BAPIDRV; system32\DRIVERS\BAPIDRV64.sys [X]
S3 GENERICDRV; \??\c:\SWSetup\SP70148\samifldrv64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-17 11:46 - 2015-07-17 11:46 - 00017079 _____ C:\Users\lfaas\Downloads\FRST.txt
2015-07-17 11:45 - 2015-07-17 11:46 - 00000000 ____D C:\FRST
2015-07-17 11:45 - 2015-07-17 11:45 - 02133504 _____ (Farbar) C:\Users\lfaas\Downloads\FRST64.exe
2015-07-17 03:15 - 2015-07-17 03:15 - 00001039 _____ C:\Users\lfaas\Desktop\Scan.txt
2015-07-16 21:04 - 2015-07-16 21:04 - 00000000 ____D C:\Users\lfaas\AppData\Local\VS Revo Group
2015-07-16 20:55 - 2015-07-16 21:03 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-07-16 19:50 - 2015-07-17 09:15 - 00000528 _____ C:\windows\Tasks\SUPERAntiSpyware Scheduled Task b8a4fb5e-3cc1-402f-b6af-b2facb4e2c6f.job
2015-07-16 19:50 - 2015-07-16 19:50 - 00003584 _____ C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task b8a4fb5e-3cc1-402f-b6af-b2facb4e2c6f
2015-07-16 19:49 - 2015-07-17 09:15 - 00000528 _____ C:\windows\Tasks\SUPERAntiSpyware Scheduled Task d387eeef-bdb6-4d13-8f98-780b245d468c.job
2015-07-16 19:49 - 2015-07-16 19:49 - 00003584 _____ C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task d387eeef-bdb6-4d13-8f98-780b245d468c
2015-07-16 19:48 - 2015-07-17 03:30 - 00000528 _____ C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 8a105438-f4e3-4d87-a537-a6d9a2e4e206.job
2015-07-16 19:48 - 2015-07-16 19:48 - 00003584 _____ C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 8a105438-f4e3-4d87-a537-a6d9a2e4e206
2015-07-16 18:43 - 2015-07-16 18:43 - 00000000 ____D C:\SUPERDelete
2015-07-16 18:14 - 2015-07-17 10:14 - 00000528 _____ C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 8016cb28-f8a3-4284-a967-a3153875ca4b.job
2015-07-16 18:14 - 2015-07-16 18:14 - 00003500 _____ C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 8016cb28-f8a3-4284-a967-a3153875ca4b
2015-07-16 18:13 - 2015-07-16 18:13 - 00001827 _____ C:\Users\lfaas\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-07-16 18:13 - 2015-07-16 18:13 - 00000000 ____D C:\Users\lfaas\AppData\Roaming\SUPERAntiSpyware.com
2015-07-16 18:13 - 2015-07-16 18:13 - 00000000 ____D C:\Users\lfaas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-07-16 18:13 - 2015-07-16 18:13 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2015-07-16 18:13 - 2015-07-16 18:13 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-16 18:12 - 2015-07-16 18:12 - 22486640 _____ (SUPERAntiSpyware) C:\Users\lfaas\Downloads\SUPERAntiSpyware.exe
2015-07-15 06:46 - 2015-06-29 18:43 - 00026288 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-07-15 06:46 - 2015-06-29 11:07 - 01145856 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-07-15 06:46 - 2015-06-29 11:07 - 01084928 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-07-15 06:46 - 2015-06-29 11:07 - 00764928 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-07-15 06:46 - 2015-06-29 11:07 - 00433152 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-07-15 06:46 - 2015-06-29 11:07 - 00067584 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-07-15 06:46 - 2015-06-26 19:21 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-07-15 06:46 - 2015-06-26 19:21 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-07-15 06:46 - 2015-06-24 22:31 - 04177920 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-07-15 06:46 - 2015-06-15 18:41 - 00065024 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2015-07-15 06:46 - 2015-06-15 18:24 - 03320320 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-07-15 06:46 - 2015-06-15 17:16 - 00059904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2015-07-15 06:46 - 2015-06-15 17:09 - 03607552 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2015-07-15 06:46 - 2015-06-15 16:50 - 02774528 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-07-15 06:46 - 2015-06-15 15:57 - 02460160 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-07-15 06:46 - 2015-05-11 14:17 - 01201664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthport.sys
2015-07-15 06:46 - 2015-05-07 13:50 - 22292672 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-07-15 06:46 - 2015-05-07 13:00 - 03109376 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2015-07-15 06:46 - 2015-05-07 12:53 - 19734960 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-07-15 06:46 - 2015-05-07 12:12 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2015-07-15 06:46 - 2015-05-07 11:21 - 00522240 _____ (Microsoft Corporation) C:\windows\system32\GeofenceMonitorService.dll
2015-07-15 06:46 - 2015-05-07 11:05 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\GeofenceMonitorService.dll
2015-07-15 06:46 - 2015-05-03 11:09 - 00274944 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 06:46 - 2015-05-03 10:58 - 00210944 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 06:46 - 2015-05-03 10:55 - 00971776 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2015-07-15 06:46 - 2015-05-03 10:49 - 00811008 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2015-07-15 06:46 - 2015-05-02 20:39 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-07-15 06:46 - 2015-04-29 19:22 - 00130048 _____ (Microsoft Corporation) C:\windows\system32\WiFiDisplay.dll
2015-07-15 06:46 - 2015-04-24 22:25 - 00020992 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-07-15 06:46 - 2014-11-04 15:25 - 00059712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\kbdclass.sys
2015-07-15 06:46 - 2014-11-04 15:25 - 00051008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mouclass.sys
2015-07-15 06:46 - 2014-11-04 02:55 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\Drivers\sermouse.sys
2015-07-15 06:46 - 2014-11-04 02:54 - 00108544 _____ (Microsoft Corporation) C:\windows\system32\Drivers\i8042prt.sys
2015-07-15 06:46 - 2014-11-04 02:54 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\Drivers\kbdhid.sys
2015-07-15 06:46 - 2014-11-04 02:54 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mouhid.sys
2015-07-15 06:45 - 2015-07-09 15:51 - 00136904 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-07-15 06:45 - 2015-07-09 14:40 - 00359936 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-07-15 06:45 - 2015-07-09 12:03 - 03701760 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-07-15 06:45 - 2015-07-09 11:54 - 00035840 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-07-15 06:45 - 2015-07-09 11:53 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-07-15 06:45 - 2015-07-09 11:50 - 00409088 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2015-07-15 06:45 - 2015-07-09 11:50 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-07-15 06:45 - 2015-07-09 11:48 - 00891904 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-07-15 06:45 - 2015-07-09 11:46 - 02229248 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-07-15 06:45 - 2015-07-09 11:38 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-07-15 06:45 - 2015-07-09 11:37 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-07-15 06:45 - 2015-07-09 11:35 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-07-15 06:45 - 2015-07-09 11:34 - 00721920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-07-15 06:45 - 2015-07-03 09:52 - 00358912 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-07-15 06:45 - 2015-07-03 09:52 - 00044032 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-07-15 06:45 - 2015-07-03 09:50 - 00301056 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-07-15 06:45 - 2015-07-03 09:50 - 00035840 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-07-15 06:45 - 2015-07-01 18:08 - 05923840 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-07-15 06:45 - 2015-07-01 17:14 - 04520448 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-07-15 06:45 - 2015-06-28 01:07 - 00442712 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-07-15 06:45 - 2015-06-28 01:07 - 00178008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-07-15 06:45 - 2015-06-28 01:06 - 01311960 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-07-15 06:45 - 2015-06-28 01:06 - 00332120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-07-15 06:45 - 2015-06-27 12:42 - 00747520 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-07-15 06:45 - 2015-06-26 23:13 - 00202240 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-07-15 06:45 - 2015-06-26 23:12 - 00401408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-07-15 06:45 - 2015-06-26 23:12 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-07-15 06:45 - 2015-06-26 23:08 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-07-15 06:45 - 2015-06-26 23:08 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-07-15 06:45 - 2015-06-26 22:40 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2015-07-15 06:45 - 2015-06-26 22:14 - 00027136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-07-15 06:45 - 2015-06-26 22:05 - 01441792 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-07-15 06:45 - 2015-06-26 22:00 - 00989184 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-07-15 06:45 - 2015-06-26 21:53 - 00324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2015-07-15 06:45 - 2015-06-26 21:26 - 00802816 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-07-15 06:45 - 2015-05-30 17:18 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\werdiagcontroller.dll
2015-07-15 06:45 - 2015-05-30 15:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll
2015-07-15 06:45 - 2015-05-30 15:35 - 00911360 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-07-15 06:44 - 2015-07-02 17:21 - 19877376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-07-15 06:44 - 2015-07-02 16:50 - 02279424 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-07-15 06:44 - 2015-07-02 16:49 - 25193984 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-07-15 06:44 - 2015-07-02 16:23 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-07-15 06:44 - 2015-07-02 16:19 - 12855296 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-07-15 06:44 - 2015-07-02 15:55 - 01310720 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-07-15 06:44 - 2015-07-02 15:20 - 14453248 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-07-15 06:44 - 2015-07-02 14:59 - 01545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-07-15 06:44 - 2015-06-15 18:39 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-07-15 06:44 - 2015-06-15 18:38 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-07-15 06:44 - 2015-06-15 18:26 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-07-15 06:44 - 2015-06-15 18:02 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2015-07-15 06:44 - 2015-06-15 17:58 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-07-15 06:44 - 2015-06-15 17:57 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-07-15 06:44 - 2015-06-15 17:38 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-07-15 06:44 - 2015-06-15 17:36 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-07-15 06:44 - 2015-06-15 17:17 - 02880000 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll
2015-07-15 06:44 - 2015-06-15 17:16 - 02427392 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-07-15 06:44 - 2015-06-15 17:15 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-07-15 06:44 - 2015-06-15 17:13 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-07-15 06:44 - 2015-06-15 17:04 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-07-15 06:44 - 2015-06-15 16:52 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-07-15 06:44 - 2015-06-15 16:47 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2015-07-15 06:44 - 2015-06-15 16:44 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-07-15 06:44 - 2015-06-15 16:41 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-07-15 06:44 - 2015-06-15 16:37 - 00880128 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2015-07-15 06:44 - 2015-06-15 16:31 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-07-15 06:44 - 2015-06-15 16:30 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-07-15 06:44 - 2015-06-15 16:17 - 01048576 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll
2015-07-15 06:44 - 2015-06-15 16:07 - 01951232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-07-15 06:44 - 2015-06-15 16:02 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-07-15 06:43 - 2015-06-16 01:36 - 01661576 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2015-07-15 06:43 - 2015-06-16 01:36 - 01212248 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2015-07-15 06:43 - 2015-06-15 18:24 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-07-15 06:43 - 2015-06-15 17:56 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-07-15 06:43 - 2015-06-15 17:55 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-07-15 06:43 - 2015-06-15 17:49 - 01032704 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2015-07-15 06:43 - 2015-06-15 17:41 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-07-15 06:43 - 2015-06-15 17:03 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-07-15 06:43 - 2015-06-15 16:43 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-07-15 06:43 - 2015-06-15 16:42 - 00128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2015-07-15 06:43 - 2015-06-15 16:32 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-07-15 06:43 - 2015-06-15 16:30 - 00327168 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-07-15 06:43 - 2015-06-10 23:49 - 01380600 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-07-15 06:43 - 2015-06-10 12:13 - 01097216 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-07-15 06:43 - 2015-05-12 09:19 - 00294912 _____ (Microsoft Corporation) C:\windows\system32\SystemEventsBrokerServer.dll
2015-07-15 06:43 - 2015-05-11 12:34 - 00332800 _____ (Microsoft Corporation) C:\windows\system32\fhcpl.dll
2015-07-15 06:43 - 2015-05-07 12:47 - 00564224 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2015-07-15 06:43 - 2015-05-03 11:07 - 07784448 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2015-07-15 06:43 - 2015-05-03 10:57 - 05264384 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2015-07-15 06:43 - 2015-05-01 19:33 - 00410739 _____ C:\windows\system32\ApnDatabase.xml
2015-07-15 06:43 - 2015-04-28 09:13 - 00513480 _____ C:\windows\SysWOW64\locale.nls
2015-07-15 06:43 - 2015-04-28 09:13 - 00513480 _____ C:\windows\system32\locale.nls
2015-07-15 06:43 - 2015-04-23 11:47 - 03084288 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll
2015-07-15 06:43 - 2015-04-23 11:16 - 02471424 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll
2015-07-13 20:36 - 2015-07-13 20:36 - 00001772 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-07-13 20:36 - 2015-07-13 20:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-07-13 20:36 - 2015-07-13 20:36 - 00000000 ____D C:\Program Files\iTunes
2015-07-13 20:36 - 2015-07-13 20:36 - 00000000 ____D C:\Program Files\iPod
2015-07-13 20:36 - 2015-07-13 20:36 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-07-13 12:32 - 2015-07-17 11:36 - 00113880 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-13 12:32 - 2015-07-13 12:32 - 00001085 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-13 12:32 - 2015-07-13 12:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-13 12:32 - 2015-07-13 12:32 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-13 12:32 - 2015-07-13 12:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-07-13 12:32 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-07-13 12:32 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-07-13 12:32 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-07-13 12:31 - 2015-07-13 12:31 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\lfaas\Downloads\mbam-setup-2.1.8.1057.exe
2015-07-10 20:56 - 2015-07-11 08:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-01 15:11 - 2015-07-01 15:11 - 00003210 _____ C:\windows\System32\Tasks\{343610CA-AF9D-42A3-A441-7D9540706F47}
2015-06-25 18:02 - 2015-06-25 18:02 - 00000000 ____D C:\Users\lfaas\AppData\Roaming\IDT

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-17 11:01 - 2014-07-26 08:04 - 01137202 _____ C:\windows\WindowsUpdate.log
2015-07-17 11:00 - 2013-08-22 11:36 - 00000000 ____D C:\windows\system32\sru
2015-07-17 10:06 - 2014-07-26 08:11 - 00003926 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{DB4A9FEB-E1AC-4EED-9D3A-ACFB06310CB6}
2015-07-17 09:53 - 2014-07-26 08:15 - 00003600 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1079287707-3710102426-1868348366-1001
2015-07-17 09:20 - 2013-08-24 17:38 - 00891920 _____ C:\windows\system32\PerfStringBackup.INI
2015-07-17 09:16 - 2014-07-26 08:51 - 00000000 ___DO C:\Users\lfaas\SkyDrive
2015-07-17 09:15 - 2013-08-24 17:32 - 00058030 _____ C:\windows\PFRO.log
2015-07-17 09:15 - 2013-08-22 10:46 - 00025249 _____ C:\windows\setupact.log
2015-07-17 09:15 - 2013-08-22 10:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-07-17 09:15 - 2013-08-22 09:25 - 00262144 ___SH C:\windows\system32\config\BBI
2015-07-17 06:09 - 2013-08-22 11:36 - 00000000 ____D C:\windows\AppReadiness
2015-07-17 03:43 - 2013-08-22 11:20 - 00000000 ____D C:\windows\CbsTemp
2015-07-17 03:42 - 2015-04-04 09:45 - 00000000 ___SD C:\windows\SysWOW64\GWX
2015-07-17 03:42 - 2015-04-04 09:45 - 00000000 ___SD C:\windows\system32\GWX
2015-07-16 18:46 - 2014-08-27 06:51 - 00000000 __SHD C:\ProgramData\360Quarant
2015-07-15 15:17 - 2013-08-22 10:44 - 00346856 _____ C:\windows\system32\FNTCACHE.DAT
2015-07-15 15:14 - 2013-08-22 11:36 - 00000000 ___RD C:\windows\ToastData
2015-07-15 15:14 - 2013-08-22 11:36 - 00000000 ____D C:\windows\WinStore
2015-07-15 06:55 - 2014-12-12 17:00 - 00000000 ____D C:\windows\system32\appraiser
2015-07-15 06:55 - 2014-08-04 08:52 - 00000000 ___SD C:\windows\system32\CompatTel
2015-07-15 06:55 - 2014-07-29 04:03 - 00000000 ____D C:\windows\system32\MRT
2015-07-14 10:59 - 2014-08-04 10:23 - 00003164 _____ C:\windows\System32\Tasks\HPCeeScheduleForlfaas
2015-07-14 10:59 - 2014-08-04 10:23 - 00000350 _____ C:\windows\Tasks\HPCeeScheduleForlfaas.job
2015-07-13 20:36 - 2014-08-10 12:29 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-07-13 17:10 - 2014-08-04 08:59 - 00792568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-07-13 17:10 - 2014-08-04 08:59 - 00178168 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-13 12:41 - 2014-08-27 05:48 - 00000000 ____D C:\Users\lfaas\AppData\Roaming\Systweak
2015-07-13 11:23 - 2014-07-28 10:17 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2015-07-13 09:43 - 2014-08-27 05:46 - 00000000 ____D C:\Users\Public\Documents\GOOBZO
2015-07-11 08:49 - 2015-06-09 21:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-10 21:42 - 2014-07-26 08:10 - 00000000 ____D C:\Users\lfaas\AppData\Local\Packages
2015-07-10 11:20 - 2014-06-04 15:00 - 00000000 ____D C:\windows\Hewlett-Packard
2015-07-10 11:20 - 2013-09-03 00:57 - 00000000 ____D C:\SWSETUP
2015-07-05 06:08 - 2014-08-30 14:59 - 00300704 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2015-07-03 22:17 - 2015-04-11 13:27 - 00000000 ____D C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-07-03 08:43 - 2014-07-29 04:03 - 130333168 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-07-02 13:30 - 2014-06-04 14:17 - 00021122 _____ C:\windows\DPINST.LOG
2015-07-02 13:28 - 2014-06-04 14:48 - 00000000 ____D C:\ProgramData\Leap Motion
2015-07-02 13:26 - 2014-07-30 11:02 - 00000000 ____D C:\Users\lfaas\AppData\Local\Airspace
2015-07-02 13:26 - 2014-07-26 08:10 - 00000000 ____D C:\Users\lfaas
2015-06-28 00:50 - 2014-08-28 05:50 - 00000221 _____ C:\Users\lfaas\AppData\Roaming\WB.CFG

==================== Files in the root of some directories =======

2014-08-28 05:50 - 2015-06-28 00:50 - 0000221 _____ () C:\Users\lfaas\AppData\Roaming\WB.CFG
2014-12-01 19:50 - 2014-12-17 01:50 - 0000010 _____ () C:\Users\lfaas\AppData\Local\DSI.DAT

Some files in TEMP:
====================
C:\Users\lfaas\AppData\Local\Temp\6_Offer_17.exe
C:\Users\lfaas\AppData\Local\Temp\cabex.dll
C:\Users\lfaas\AppData\Local\Temp\Extract.exe
C:\Users\lfaas\AppData\Local\Temp\LeapUpdate.exe
C:\Users\lfaas\AppData\Local\Temp\post2.dll
C:\Users\lfaas\AppData\Local\Temp\sp64126.exe
C:\Users\lfaas\AppData\Local\Temp\SP69313.exe
C:\Users\lfaas\AppData\Local\Temp\SP70148.exe
C:\Users\lfaas\AppData\Local\Temp\SP70869.exe
C:\Users\lfaas\AppData\Local\Temp\SP71319.exe
C:\Users\lfaas\AppData\Local\Temp\UninstallHPSA.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-07-14 03:04

==================== End of log ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:13-07-2015
Ran by lfaas at 2015-07-17 11:46:20
Running from C:\Users\lfaas\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1079287707-3710102426-1868348366-500 - Administrator - Disabled)
Guest (S-1-5-21-1079287707-3710102426-1868348366-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1079287707-3710102426-1868348366-1003 - Limited - Enabled)
lfaas (S-1-5-21-1079287707-3710102426-1868348366-1001 - Administrator - Enabled) => C:\Users\lfaas

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Alcor Micro USB Card Reader Driver  (HKLM-x32\...\AmUStor) (Version: 20.21.3317.03861 - Alcor Micro Corp.)
Alcor Micro USB Card Reader Driver  (x32 Version: 20.21.3317.03861 - Alcor Micro Corp.) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 6.30.223.170 - Broadcom Corporation)
Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 14.1.0.0 - Citrix Systems, Inc.)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6805 - CyberLink Corp.)
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.5.3103 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.3.4323 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.5.3215 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.5.3215 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3212 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: 1.0 - Meridian Audio Ltd)
HP Documentation (HKLM-x32\...\{06600E94-1C34-40E2-AB09-D30AECF78172}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7127.4628 - Hewlett-Packard)
HP SimplePass (HKLM-x32\...\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.51 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6482.0 - IDT)
Inst5675 (Version: 8.00.51 - Softex Inc.) Hidden
Inst5676 (Version: 8.00.51 - Softex Inc.) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3262 - Intel Corporation)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\...\{6CF1A7E2-8001-4870-9F18-3C6CDD6FE9E3}) (Version: 12.2.1.16 - Apple Inc.)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 39.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 38.0.5 - Mozilla)
Online Plug-in (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 5.5.0.7001 - CyberLink Corp.) Hidden
Self-service Plug-in (x32 Version: 4.1.0.41738 - Citrix Systems, Inc.) Hidden
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1200 - SUPERAntiSpyware.com)
Windows Driver Package - Broadcom Corporation (bcbtums) Bluetooth  (08/09/2013 12.0.0.7620) (HKLM\...\7C5445C0C158E0500C2E0AD361C4CBF4BAB2476C) (Version: 08/09/2013 12.0.0.7620 - Broadcom Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

29-06-2015 04:49:57 Scheduled Checkpoint
02-07-2015 13:28:21 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
02-07-2015 13:28:38 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
09-07-2015 09:49:49 Windows Update
10-07-2015 11:20:09 HPSF Applying updates
15-07-2015 06:52:05 Windows Update

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 09:25 - 2013-08-22 09:25 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {14772947-85CA-43A7-9EAF-C93763A541EF} - System32\Tasks\SUPERAntiSpyware Scheduled Task d387eeef-bdb6-4d13-8f98-780b245d468c => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {19427FA0-7238-4CD7-9409-00702EDC25B0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {1AFD03E6-6575-4682-9FA9-D63FF98D11A0} - System32\Tasks\YTAUpdate => C:\PROGRA~2\YOUTUB~1\Updater.exe <==== ATTENTION
Task: {216CFE63-3ADC-46D8-96A2-5FC663859332} - System32\Tasks\HPCeeScheduleForlfaas => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {40733FE3-05BD-478C-A0B2-8638C51AC088} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {6DBB4460-A1BC-4CDA-A3FF-A174D713588C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2015-06-16] (Hewlett-Packard)
Task: {94D0C712-BD6F-4E78-A144-496A00A71467} - System32\Tasks\CLVDLauncher => c:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.)
Task: {96D32B67-6887-496B-8F46-7F846B5F41F5} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {9A052BEB-C4B3-4335-8F28-8E6746D4EBA1} - System32\Tasks\{343610CA-AF9D-42A3-A441-7D9540706F47} => pcalua.exe -a C:\Users\lfaas\AppData\Local\Roblox\Versions\version-75334a80f0a9470d\RobloxPlayerLauncher.exe -c -uninstall
Task: {D1EAE44D-C98C-4D85-8133-27F6495FB0A0} - System32\Tasks\CLMLSvc_P2G8 => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05] (CyberLink)
Task: {D23719E9-F99E-4287-9842-6D0BF8CE26CF} - System32\Tasks\SUPERAntiSpyware Scheduled Task 8016cb28-f8a3-4284-a967-a3153875ca4b => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {DF98FDB7-F5EF-4E82-979B-11FB5606B841} - System32\Tasks\SUPERAntiSpyware Scheduled Task b8a4fb5e-3cc1-402f-b6af-b2facb4e2c6f => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {E85B5B60-4DB3-48B4-8216-6C556CC7E304} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2015-07-03] (Microsoft Corporation)
Task: {EAE8337B-86C6-43EE-BA2D-0D268D17CA6A} - System32\Tasks\YTAUpdate_logon => C:\PROGRA~2\YOUTUB~1\Updater.exe <==== ATTENTION
Task: {F8892FFE-9411-4FB4-A427-D73E72AD1CB7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {FA6D0C27-0FCF-4209-849E-79053EC2BAB5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2015-06-16] (Hewlett-Packard)
Task: {FB4E7A86-9166-4C7D-AEA9-F5E4438EDC36} - System32\Tasks\SUPERAntiSpyware Scheduled Task 8a105438-f4e3-4d87-a537-a6d9a2e4e206 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {FC0970A1-8F83-47B8-A6B6-ACE0710C19FB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\HPCeeScheduleForlfaas.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 8016cb28-f8a3-4284-a967-a3153875ca4b.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 8a105438-f4e3-4d87-a537-a6d9a2e4e206.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task b8a4fb5e-3cc1-402f-b6af-b2facb4e2c6f.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task d387eeef-bdb6-4d13-8f98-780b245d468c.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

==================== Loaded Modules (Whitelisted) ==============

2013-09-05 06:22 - 2013-09-05 06:22 - 00109568 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
2013-09-05 06:24 - 2013-09-05 06:24 - 00627200 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachedrv.dll
2013-09-05 06:24 - 2013-09-05 06:24 - 02540544 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
2013-09-05 06:21 - 2013-09-05 06:21 - 00035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
2013-09-05 06:21 - 2013-09-05 06:21 - 00055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
2013-09-05 06:21 - 2013-09-05 06:21 - 00021504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll
2013-09-05 06:36 - 2013-09-05 06:36 - 00306064 _____ () C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll
2013-09-05 06:36 - 2013-09-05 06:36 - 01298832 _____ () C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 16:26 - 2015-05-15 16:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-09-05 06:31 - 2013-09-05 06:31 - 00064000 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
2014-06-04 14:19 - 2013-08-05 03:49 - 00627672 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2013-08-05 18:48 - 2013-08-05 18:48 - 00016856 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2014-06-04 14:16 - 2013-08-12 05:53 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:56E2E879
AlternateDataStreams: C:\Users\lfaas\SkyDrive:ms-properties

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1079287707-3710102426-1868348366-1001\Control Panel\Desktop\\Wallpaper -> C:\windows\web\wallpaper\HP\HP_Svinoya_Norway_Sunset.jpg
DNS Servers: 192.168.1.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{6176A2D8-4291-470A-95C3-12213002FDF5}] => (Allow) C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe
FirewallRules: [{2F2ED864-93C8-4B65-8275-29B00ACFA0AE}] => (Allow) C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe
FirewallRules: [{4326BCDD-3C1A-4D7C-B6CA-5F718C9A66A6}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\HPConnectedMusic.exe
FirewallRules: [{643F4967-7034-496A-ACFB-61DB15CF9B6B}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\HPConnectedMusic.exe
FirewallRules: [{C7578C41-F43D-4D5B-B28D-4F69ABCBD39B}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\spotify_helper.exe
FirewallRules: [{5473BF13-E0F2-4C4D-8A1A-996016868D2C}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\spotify_helper.exe
FirewallRules: [{6520CB73-D1C2-415C-90A9-DEBCF1A8F858}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{3630B429-935B-46D4-BBD6-231E193DFC73}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{E8B97834-1EF2-4ABD-86EE-7A0FBCF9135D}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{24CBEB38-3F2A-483A-BCFF-425261B50A1C}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{A7C5FE2F-6FB2-4AF8-8546-E9DB58EE16DA}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{C4CF12C6-77D8-4FAC-B344-25E5D933A5E3}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{0032BE96-7252-4238-ABC7-985C18CCC6C0}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{0CE53175-59E8-4647-A0C6-BA5EB71E557E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1EC83694-85AE-42D5-92E5-EBD2000FED9F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{54205793-D93D-45ED-A1DB-F287E807C0FE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{53549F48-00E0-44C8-9E1B-1A17D993754E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{4E73CB1A-88BE-4C4E-95FD-9FD61D286418}C:\program files (x86)\leap motion\core services\leapsvc.exe] => (Block) C:\program files (x86)\leap motion\core services\leapsvc.exe
FirewallRules: [uDP Query User{39BA25F0-5C82-4716-8821-DFAB3243497F}C:\program files (x86)\leap motion\core services\leapsvc.exe] => (Block) C:\program files (x86)\leap motion\core services\leapsvc.exe
FirewallRules: [{406FE29E-8804-472A-9DAB-724634C34C7A}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{8B467F06-ED7E-457B-9130-3B32E97F9636}] => (Allow) LPort=2869
FirewallRules: [{6FC2C225-36BA-4E6F-9D8E-FA47DE21641D}] => (Allow) LPort=1900
FirewallRules: [{E74D221A-D64F-4E14-AEC6-B169F82DBDB6}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{E99F06B2-7E4B-4004-BF66-AE47FE4F7E6E}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{B3F7C7E7-BC60-4B48-887E-F90A87829605}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{397DF08F-BF41-4CBE-8E27-2D2F0A3D759E}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{EE46C57B-09F9-43EB-B30C-10C453531004}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{43C02D44-0EB8-4E06-B9AD-4CF8D1BB7A44}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{0A342CDD-9964-4DBF-AE9C-2B5816CE6946}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{23725E67-4091-48D3-8E9C-92EFECD7CFDD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FF13D58E-C3C7-4B7B-A7B5-52EC82C71EC5}C:\program files (x86)\leap motion\core services\leapsvc.exe] => (Block) C:\program files (x86)\leap motion\core services\leapsvc.exe
FirewallRules: [uDP Query User{0E9B6431-0921-4363-80A1-274AEEBCF772}C:\program files (x86)\leap motion\core services\leapsvc.exe] => (Block) C:\program files (x86)\leap motion\core services\leapsvc.exe
FirewallRules: [{ABAF8E00-F288-4CE7-8032-8C34537F0950}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [{421FC54E-4736-4583-BF0E-BAD0B48F9912}] => (Allow) C:\Program Files\iTunes\iTunes.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/15/2015 06:55:04 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: .NETFrameworkC:\windows\system32\mscoree.dll8

Error: (07/13/2015 11:29:43 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: .NETFrameworkC:\windows\system32\mscoree.dll8

Error: (07/12/2015 11:29:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: OPBHOBrokerDsktop.exe, version: 8.0.0.51, time stamp: 0x5228424c
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000000000000000
Faulting process id: 0x1274
Faulting application start time: 0xOPBHOBrokerDsktop.exe0
Faulting application path: OPBHOBrokerDsktop.exe1
Faulting module path: OPBHOBrokerDsktop.exe2
Report Id: OPBHOBrokerDsktop.exe3
Faulting package full name: OPBHOBrokerDsktop.exe4
Faulting package-relative application ID: OPBHOBrokerDsktop.exe5

Error: (07/12/2015 11:19:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17840, time stamp: 0x555fe1bb
Faulting module name: Flash.ocx, version: 18.0.0.203, time stamp: 0x55971b05
Exception code: 0xc0000005
Fault offset: 0x0036ce35
Faulting process id: 0x17d4
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3
Faulting package full name: IEXPLORE.EXE4
Faulting package-relative application ID: IEXPLORE.EXE5

Error: (07/06/2015 10:02:57 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: .NETFrameworkC:\windows\system32\mscoree.dll8

Error: (07/02/2015 01:32:05 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: There was an error with the Windows Location Provider database

Error: (07/02/2015 01:30:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: LeapSvc64.exe, version: 2.2.6.0, time stamp: 0x555e7ece
Faulting module name: MSVCP120.dll, version: 6.3.9600.17736, time stamp: 0x550f4336
Exception code: 0xc0000135
Fault offset: 0x00000000000ec180
Faulting process id: 0xb58
Faulting application start time: 0xLeapSvc64.exe0
Faulting application path: LeapSvc64.exe1
Faulting module path: LeapSvc64.exe2
Report Id: LeapSvc64.exe3
Faulting package full name: LeapSvc64.exe4
Faulting package-relative application ID: LeapSvc64.exe5

Error: (07/02/2015 01:29:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: LeapControlPanel.exe, version: 2.2.6.0, time stamp: 0x555e7e58
Faulting module name: MSVCP120.dll, version: 6.3.9600.17736, time stamp: 0x550f42c2
Exception code: 0xc0000135
Fault offset: 0x0009d4f2
Faulting process id: 0x1098
Faulting application start time: 0xLeapControlPanel.exe0
Faulting application path: LeapControlPanel.exe1
Faulting module path: LeapControlPanel.exe2
Report Id: LeapControlPanel.exe3
Faulting package full name: LeapControlPanel.exe4
Faulting package-relative application ID: LeapControlPanel.exe5

Error: (07/02/2015 01:29:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: LeapSvc64.exe, version: 2.2.6.0, time stamp: 0x555e7ece
Faulting module name: MSVCP120.dll, version: 6.3.9600.17736, time stamp: 0x550f4336
Exception code: 0xc0000135
Fault offset: 0x00000000000ec180
Faulting process id: 0x110c
Faulting application start time: 0xLeapSvc64.exe0
Faulting application path: LeapSvc64.exe1
Faulting module path: LeapSvc64.exe2
Report Id: LeapSvc64.exe3
Faulting package full name: LeapSvc64.exe4
Faulting package-relative application ID: LeapSvc64.exe5

Error: (07/02/2015 01:25:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Airspace.exe, version: 1.0.0.0, time stamp: 0x51edd2fb
Faulting module name: Airspace.exe, version: 1.0.0.0, time stamp: 0x51edd2fb
Exception code: 0x80000003
Fault offset: 0x001ace90
Faulting process id: 0x484
Faulting application start time: 0xAirspace.exe0
Faulting application path: Airspace.exe1
Faulting module path: Airspace.exe2
Report Id: Airspace.exe3
Faulting package full name: Airspace.exe4
Faulting package-relative application ID: Airspace.exe5


System errors:
=============
Error: (07/17/2015 03:49:38 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly.  It has done this 3 time(s).

Error: (07/16/2015 10:23:41 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly.  It has done this 2 time(s).

Error: (07/16/2015 08:19:00 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (07/16/2015 07:41:10 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 106.

Error: (07/16/2015 07:41:10 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 106.

Error: (07/16/2015 07:39:56 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 106.

Error: (07/16/2015 07:39:56 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 106.

Error: (07/16/2015 02:32:53 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume Windows.

The exact nature of the corruption is unknown.  The file system structures need to be scanned online.

Error: (07/16/2015 02:32:52 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume Windows.

The exact nature of the corruption is unknown.  The file system structures need to be scanned online.

Error: (07/16/2015 02:32:51 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: A corruption was discovered in the file system structure on volume Windows.

The exact nature of the corruption is unknown.  The file system structures need to be scanned online.


Microsoft Office:
=========================
Error: (07/15/2015 06:55:04 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: .NETFrameworkC:\windows\system32\mscoree.dll8

Error: (07/13/2015 11:29:43 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: .NETFrameworkC:\windows\system32\mscoree.dll8

Error: (07/12/2015 11:29:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: OPBHOBrokerDsktop.exe8.0.0.515228424cunknown0.0.0.000000000c00000050000000000000000127401d0bd1a917bbd7bC:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exeunknown58197ca5-290f-11e5-8285-54271ef48dba

Error: (07/12/2015 11:19:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: IEXPLORE.EXE11.0.9600.17840555fe1bbFlash.ocx18.0.0.20355971b05c00000050036ce3517d401d0bd1aa3da1565C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SYSTEM32\Macromed\Flash\Flash.ocx01f3e6b0-290e-11e5-8285-54271ef48dba

Error: (07/06/2015 10:02:57 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: .NETFrameworkC:\windows\system32\mscoree.dll8

Error: (07/02/2015 01:32:05 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: -2147024883

Error: (07/02/2015 01:30:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: LeapSvc64.exe2.2.6.0555e7eceMSVCP120.dll6.3.9600.17736550f4336c000013500000000000ec180b5801d0b4ecd56e2ccaC:\Program Files (x86)\Leap Motion\Core Services\LeapSvc64.exeMSVCP120.dll1321de8c-20e0-11e5-827f-54271ef48dba

Error: (07/02/2015 01:29:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: LeapControlPanel.exe2.2.6.0555e7e58MSVCP120.dll6.3.9600.17736550f42c2c00001350009d4f2109801d0b4ecae6491a7C:\Program Files (x86)\Leap Motion\Core Services\LeapControlPanel.exeMSVCP120.dlledce5de7-20df-11e5-827f-54271ef48dba

Error: (07/02/2015 01:29:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: LeapSvc64.exe2.2.6.0555e7eceMSVCP120.dll6.3.9600.17736550f4336c000013500000000000ec180110c01d0b4ecab1f9197C:\Program Files (x86)\Leap Motion\Core Services\LeapSvc64.exeMSVCP120.dlle8d80fc8-20df-11e5-827f-54271ef48dba

Error: (07/02/2015 01:25:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Airspace.exe1.0.0.051edd2fbAirspace.exe1.0.0.051edd2fb80000003001ace9048401d0b4eb8017d60eC:\Program Files (x86)\Leap Motion\Airspace\Airspace.exeC:\Program Files (x86)\Leap Motion\Airspace\Airspace.exe54a1ee59-20df-11e5-827f-54271ef48dba


CodeIntegrity Errors:
===================================
  Date: 2015-04-04 15:14:42.886
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-04-04 15:14:42.730
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-12-06 13:31:36.315
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-12-06 13:31:36.225
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-12-05 06:01:49.013
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-12-05 06:01:48.944
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-12-04 22:02:58.794
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-12-04 22:02:58.718
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-10-16 21:43:16.306
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2014-10-16 21:43:16.238
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel® Core i5-4440 CPU @ 3.10GHz
Percentage of memory in use: 30%
Total physical RAM: 8097.09 MB
Available physical RAM: 5649.78 MB
Total Virtual: 9377.09 MB
Available Virtual: 7018.44 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:1844.72 GB) (Free:1797.08 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: (Recovery Image) (Fixed) (Total:16.82 GB) (Free:2.1 GB) NTFS ==>[system with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 1863 GB) (Disk ID: AC004271)

Partition: GPT Partition Type.

==================== End of log ============================

 

Link to post
Share on other sites

Hello,
    
 
They call me TwinHeadedEagle around here, and I'll try to help your with your issue.
 
     
    
Before we start please read and note the following:

  • We're primarily oriented on malware removal here, so you must know that some issues just cannot be solved and you must be prepared for this. Some tools we use here will remove your browser search history, so backup your important links and all the files whose loss is unacceptable.
  • Limit your internet access to posting here, some infections just wait to steal typed-in passwords.
  • Please be patient. I know it is frustrating when your PC isn't working properly, but malware removal takes time. Keep in mind that private life gets in the way too. Note that we may live in totally different time zones, what may cause some delays between answers.
  • Don't run any scripts or tools on your own, unsupervised usage may cause more harm than good.
  • Do not paste the logs in your posts, attachments make my work easier. There is a More reply options button, that gives you Upload Files option below which you can use to attach your reports. Always attach reports from all tools.
  • Always execute my instructions in given order. If for some reason you cannot completely follow one instruction, inform me about that.
  • I volunteer to help you, so please, do not ask for help for your company/business PC. Companies are making revenue via computers, so it is good thing to pay someone to repair it.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.

:excl: I can't foresee everything, so if anything not covered in my instructions happens, please stop and inform me!
:excl: There are no silly questions. Never be afraid to ask if in doubt!
 
 
 
  warning.gif Rules and policies
 
We won't support any piracy.
That being told, if any evidence of illegal OS, software, cracks/keygens or any other will be revealed, any further assistance will be suspended. If you are aware that there is this kind of stuff on your machine, remove it before proceeding!
The same applies to any use of P2P software: uTorrent, BitTorrent, Vuze, Kazaa, Ares... We don't provide any help for P2P, except for their removal. All P2P software has to be uninstalled or at least fully disabled before proceeding!
 
Failure to follow these guidelines will result with closing your topic and withdrawning any assistance.
 
 



 
FRST.gif Scan with Farbar Recovery Scan Tool
 
Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please upload them into your next reply.

Link to post
Share on other sites

Hello,

    

 

They call me TwinHeadedEagle around here, and I'll try to help your with your issue.

 

     

    

Before we start please read and note the following:

  • We're primarily oriented on malware removal here, so you must know that some issues just cannot be solved and you must be prepared for this. Some tools we use here will remove your browser search history, so backup your important links and all the files whose loss is unacceptable.
  • Limit your internet access to posting here, some infections just wait to steal typed-in passwords.
  • Please be patient. I know it is frustrating when your PC isn't working properly, but malware removal takes time. Keep in mind that private life gets in the way too. Note that we may live in totally different time zones, what may cause some delays between answers.
  • Don't run any scripts or tools on your own, unsupervised usage may cause more harm than good.
  • Do not paste the logs in your posts, attachments make my work easier. There is a More reply options button, that gives you Upload Files option below which you can use to attach your reports. Always attach reports from all tools.
  • Always execute my instructions in given order. If for some reason you cannot completely follow one instruction, inform me about that.
  • I volunteer to help you, so please, do not ask for help for your company/business PC. Companies are making revenue via computers, so it is good thing to pay someone to repair it.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.

:excl: I can't foresee everything, so if anything not covered in my instructions happens, please stop and inform me!

:excl: There are no silly questions. Never be afraid to ask if in doubt!

 

 

 

  warning.gif Rules and policies

 

We won't support any piracy.

That being told, if any evidence of illegal OS, software, cracks/keygens or any other will be revealed, any further assistance will be suspended. If you are aware that there is this kind of stuff on your machine, remove it before proceeding!

The same applies to any use of P2P software: uTorrent, BitTorrent, Vuze, Kazaa, Ares... We don't provide any help for P2P, except for their removal. All P2P software has to be uninstalled or at least fully disabled before proceeding!

 

Failure to follow these guidelines will result with closing your topic and withdrawning any assistance.

 

 


 

FRST.gif Scan with Farbar Recovery Scan Tool

 

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.

    (XP users click run after receipt of Windows Security Warning - Open File).

  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please upload them into your next reply.

Hi TwinHeadedEagle

 

Here they are.

FRST.txt

Addition.txt

Link to post
Share on other sites

FRST.gif Fix with Farbar Recovery Scan Tool
 


icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif
icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

 
Download attached fixlist.txt file and save it to the Desktop:
 
Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.

fixlist.txt

Link to post
Share on other sites

Yes. I said in my first post in this thread that I noticed a weird file in my Custom Scan Configuration settings on Malwarebytes by the file name $360Section in my Windows (C:). I just checked to see if it was still there and it still is. I do not know if it is malicious, I scanned it and nothing was detected. I try to go into Programs and Features and type in 360safe and all of these things pop up as a result. When i click on them, a notepad pops up with triggering words like Trojan and virus. I never downloaded 360 Total Security. I want to see if all of these things can be removed. I will attach a screenshot of what the $360Secion looks like in Malwarebytes Custom Scan Configuration settings. The files are checked. I also have screenshots of what the search results are when I type in 360safe in Programs and Features, Should I attach those as well?

post-190159-0-46005000-1437231093_thumb.

Link to post
Share on other sites

FRST.gif Scan with Farbar Recovery Scan Tool

 

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.

    (XP users click run after receipt of Windows Security Warning - Open File).

  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please upload them into your next reply.
Link to post
Share on other sites

FRST.gif Fix with Farbar Recovery Scan Tool

icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif

icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.

    (XP users click run after receipt of Windows Security Warning - Open File).

  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please upload it to your reply.

fixlist.txt

Link to post
Share on other sites

I've made one mistake:

FRST.gif Fix with Farbar Recovery Scan Tool

icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif

icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.

    (XP users click run after receipt of Windows Security Warning - Open File).

  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.

fixlist.txt

Link to post
Share on other sites

FRST.gif Fix with Farbar Recovery Scan Tool

icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif

icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.

    (XP users click run after receipt of Windows Security Warning - Open File).

  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.

fixlist.txt

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.