Well, I don't know if the problem my computer had last night is due to malware or to something else. I was only browsing some websites (daily online newspapers), when Eset blocked something and cleaned it. Then, Emsisoft warned me about a program which was trying to have access to the internet (something like that). I had a look and saw that the program was MCShield. I didn't worry about this, but I decided to make a full scan with Eset. It found one infected file and cleaned it. I search in the log, but I couldn't see what was the infected file about. Then, I restart the computer and the problem came: windows started, but when the desktop appeared, the computer stopped working. I could see that it was trying to connect to the internet, but I could do nothing. I turned it off and restart 2-3 times, but nothing changed. I then entered in safe mode, and decided to uninstall a new adobe program I installed a few days ago (photoshop). I was trying to check if the new software caused the problem, but I also decided to uninstall every adobe product I had in the computer. Some error messages appeared, and I was driven to adobe cleaner tool. I used it, and then restarted the computer. There was no problem anymore.
Although the computer is ok now, I will post the logs, and if there is something bad, I would ask for your help to fix it...
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16611 BrowserJavaVersion: 10.21.2
Run by MA RIA at 17:00:11 on 2013-06-18
Microsoft Windows 7 Home Premium 6.1.7601.1.1253.30.1033.18.6038.3811 [GMT 3:00]
.
AV: ESET Smart Security 6.0 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
AV: Emsisoft Anti-Malware *Enabled/Outdated* {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
SP: ESET Smart Security 6.0 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Emsisoft Anti-Malware *Enabled/Outdated* {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bing.com/
uSearch Bar = Preserve
uProxyServer = proxy.unic.ac.cy:8080
mWinlogon: Userinit = userinit.exe
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [MCShield Monitor] C:\Program Files (x86)\MCShield\mcshieldrtm.exe
mRun: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab
TCP: NameServer = 192.168.10.254
TCP: Interfaces\{F8010453-43D6-4BBC-9F0C-01DE21D23D1C} : DHCPNameServer = 192.168.10.254
TCP: Interfaces\{F8010453-43D6-4BBC-9F0C-01DE21D23D1C}\55E4963602055726C696360275966496 : DHCPNameServer = 195.14.130.220 195.14.130.170
TCP: Interfaces\{F8010453-43D6-4BBC-9F0C-01DE21D23D1C}\55E4963602D456469616A5F6E656023223 : DHCPNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= C:\Windows\SysWOW64\nvinit.dll acaptuser32.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
x64-Run: [BLEServicesCtrl] C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 epfwwfp;epfwwfp;C:\Windows\System32\drivers\epfwwfp.sys [2012-12-21 57904]
R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2012-10-8 30056]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-12-14 55856]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2011-12-14 21616]
R1 A2DDA;A2 Direct Disk Access Support Driver;C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [2013-6-15 26176]
R1 a2injectiondriver;a2injectiondriver;C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [2013-6-15 44688]
R1 a2util;a-squared Malware-IDS utility driver;C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [2013-6-15 17384]
R1 eamonm;eamonm;C:\Windows\System32\drivers\eamonm.sys [2012-12-21 213416]
R1 EpfwLWF;Epfw NDIS LightWeight Filter;C:\Windows\System32\drivers\EpfwLWF.sys [2012-12-21 59440]
R1 nvkflt;nvkflt;C:\Windows\System32\drivers\nvkflt.sys [2012-10-8 284008]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-13 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-8-12 140672]
R2 a2AntiMalware;Emsisoft Anti-Malware 7.0 - Service;C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [2013-6-15 2626880]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-12-14 98208]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2013-2-13 770528]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-12-13 1120784]
R2 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2012-12-3 1361856]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-12-3 1148864]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-9-12 135984]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2012-12-21 1333424]
R2 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2013-4-18 659992]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-12-14 1692480]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-2 382824]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2010-11-30 16120]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-12-14 2656280]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2013-2-8 3386608]
R3 a2acc;a2acc;C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys [2013-6-15 66320]
R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Accelern.sys [2011-12-14 27760]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2013-2-13 163808]
R3 btmaudio;Intel Bluetooth Audio Service;C:\Windows\System32\drivers\btmaud.sys [2012-10-22 87424]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2012-10-30 131968]
R3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2012-12-3 1342848]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2011-12-14 176096]
R3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2012-8-6 68136]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-12-14 317440]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-12-14 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-12-14 181760]
R3 qicflt;upper Device Filter Driver;C:\Windows\System32\drivers\qicflt.sys [2011-12-14 29288]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-12-14 428136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-6-3 162408]
S2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-3-13 4150112]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;C:\Windows\System32\drivers\AmpPal.sys [2013-2-13 163808]
S3 BthMtpEnum;Bluetooth MTP Device Enumerator;C:\Windows\System32\drivers\BthMtpEnum.sys [2009-7-14 64512]
S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-12-14 158976]
S3 JMCR;JMCR;C:\Windows\System32\drivers\jmcr.sys [2011-12-14 174168]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2013-2-8 273136]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\Windows\System32\drivers\nvstusb.sys [2011-12-14 121960]
S3 PSI;PSI;C:\Windows\System32\drivers\psi_mf_amd64.sys [2013-4-18 18456]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-2-3 19456]
S3 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2013-4-18 1227800]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-2-3 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-2-3 30208]
S3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-30 149504]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-2-18 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2013-06-18 11:46:39 76232 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{18AAFD52-8AFB-42B1-A584-1C086A1BC0FE}\offreg.dll
2013-06-18 11:10:47 9552976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{18AAFD52-8AFB-42B1-A584-1C086A1BC0FE}\mpengine.dll
2013-06-18 11:08:56 -------- d-----w- C:\Users\MA RIA\AppData\Local\{D7B90C11-0346-4452-8EDA-B8025F323C8B}
2013-06-17 11:51:49 -------- d-----w- C:\Users\MA RIA\AppData\Local\{87965383-A85B-4F68-9985-8F6AEC82134D}
2013-06-16 09:18:04 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-06-16 09:18:04 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-06-16 09:18:03 279040 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
2013-06-16 09:18:03 218112 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll
2013-06-16 09:16:46 -------- d-----w- C:\Users\MA RIA\AppData\Local\{2A7CA0E8-C52F-49CF-9932-3A7961E68CC5}
2013-06-15 19:49:58 -------- d-----w- C:\Users\MA RIA\AppData\Local\{6579746A-E84A-4005-89B0-B16360E7D4EF}
2013-06-15 18:48:15 -------- d-----w- C:\Program Files (x86)\Emsisoft Anti-Malware
2013-06-15 07:28:01 -------- d-----w- C:\Users\MA RIA\AppData\Local\{1F4E2673-B011-4A8B-A715-D0A5306EA96F}
2013-06-14 12:04:43 -------- d-----w- C:\Users\MA RIA\AppData\Local\{BF828F33-3470-4C8A-B659-659732EFDE9A}
2013-06-13 10:22:28 -------- d-----w- C:\Users\MA RIA\AppData\Local\{73041AE1-321B-41A1-A66F-4048506A418A}
2013-06-12 13:05:22 -------- d-----w- C:\Users\MA RIA\AppData\Roaming\NVIDIA
2013-06-12 12:58:42 -------- d-----w- C:\Users\MA RIA\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-06-12 12:54:54 -------- d-----w- C:\Users\MA RIA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2013-06-12 12:52:59 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
2013-06-12 11:21:46 -------- d-----w- C:\Users\MA RIA\AppData\Local\{7E22BD62-945A-45D7-99FD-34AF5A5A5880}
2013-06-11 14:43:31 -------- d-----w- C:\Users\MA RIA\AppData\Local\{353956B8-880C-49C4-8691-72FC2E5C764B}
2013-06-10 13:34:59 -------- d-----w- C:\Users\MA RIA\AppData\Local\{D3C867C4-D420-4413-8CF7-6EFCE2FA9D82}
2013-06-10 13:25:45 -------- d-----w- C:\Users\MA RIA\AppData\Local\{B9B2E820-F9BC-4F9A-A685-D0A61EA9B9C6}
2013-06-09 08:23:08 -------- d-----w- C:\Users\MA RIA\AppData\Local\{057A2028-C7B1-490F-A461-58AA7A631D72}
2013-06-08 09:32:03 -------- d-----w- C:\Users\MA RIA\AppData\Local\{BACD6180-8B96-4841-83F5-636EA5A4FD3A}
2013-06-07 13:15:43 -------- d-----w- C:\Users\MA RIA\AppData\Local\{B57B6C92-199F-4114-ACFB-52B20BA30719}
2013-06-06 18:30:24 -------- d-----w- C:\Users\MA RIA\AppData\Local\{CEBAFC8C-B8D8-4816-9F66-B29A037139DB}
2013-06-06 11:35:22 -------- d-----w- C:\Users\MA RIA\AppData\Local\{F86EF589-3286-40BF-9F96-0087D74840AC}
2013-06-05 16:55:15 -------- d-----w- C:\Users\MA RIA\AppData\Local\{C71272B2-98C3-4884-8C10-59CB4B78F6A4}
2013-06-04 10:34:58 -------- d-----w- C:\Users\MA RIA\AppData\Local\{07B1CAE1-0B02-49D0-B839-64D7F6FE9B14}
2013-06-03 12:06:31 -------- d-----w- C:\Users\MA RIA\AppData\Local\{C3F06F25-6083-4089-B87E-146BB70EC7E8}
2013-06-02 11:14:04 -------- d-----w- C:\Users\MA RIA\AppData\Local\{1ECAE951-A00E-4D50-BC42-C848AE3ACBBB}
2013-06-02 07:48:34 -------- d-----w- C:\Users\MA RIA\AppData\Local\{99058CC0-33A5-4874-896C-E8D58BA46898}
2013-06-01 08:04:12 -------- d-----w- C:\Users\MA RIA\AppData\Local\{BEF2A71D-4E6A-4F17-A70E-4E5D55B8019A}
2013-05-31 13:43:43 -------- d-----w- C:\Users\MA RIA\AppData\Local\{808EA86E-54A4-40D7-AFF2-2D6CDBDBE458}
2013-05-30 12:42:24 -------- d-----w- C:\Users\MA RIA\AppData\Local\{055139F1-DF0A-4061-985B-8750D6D1B96D}
2013-05-29 15:21:04 -------- d-----w- C:\Users\MA RIA\AppData\Local\{9D587B71-4A65-4517-BDCE-54D16E37E420}
2013-05-28 17:09:10 -------- d-----w- C:\Users\MA RIA\AppData\Local\{EBE3A8C7-6564-4FF2-9DD6-8B3BE4F604DF}
2013-05-27 19:49:10 -------- d-----w- C:\Users\MA RIA\AppData\Local\{4E0D6513-9368-43B6-ABF9-595CF3CFEEF3}
2013-05-27 14:30:30 -------- d-----w- C:\Users\MA RIA\AppData\Local\{F76838EA-A1BE-4B14-9C65-9BE6CDAC9455}
2013-05-26 14:57:02 1409 ----a-w- C:\Windows\QTFont.for
2013-05-26 14:55:04 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-05-26 14:47:46 -------- d-----w- C:\Users\MA RIA\AppData\Local\Secunia PSI
2013-05-26 14:47:41 -------- d-----w- C:\Program Files (x86)\Secunia
2013-05-26 14:11:51 -------- d-----w- C:\ProgramData\Intel.sav
2013-05-26 14:10:37 -------- d-----w- C:\ProgramData\Package Cache
2013-05-26 14:00:34 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab
2013-05-26 08:07:04 -------- d-----w- C:\Users\MA RIA\AppData\Local\{892B1B11-F680-4574-B256-69E2F261134A}
2013-05-25 15:07:48 -------- d-----w- C:\Users\MA RIA\AppData\Local\{26204FFA-1D44-4824-8EB5-CFD0E56CAD8B}
2013-05-24 17:45:12 -------- d-----w- C:\Program Files (x86)\Realtek
2013-05-24 17:23:25 -------- d--h--w- C:\Windows\System32\WLANProfiles
2013-05-23 15:28:28 -------- d-----w- C:\Users\MA RIA\New folder
2013-05-23 15:09:31 -------- d-----w- C:\Users\MA RIA\AppData\Local\{545D78C6-552D-432F-80F5-E1FB516E66EE}
2013-05-23 11:06:15 -------- d-----w- C:\Users\MA RIA\AppData\Local\{A16CC561-EF3E-43D7-B168-259ED4DFE2A0}
2013-05-22 19:02:40 -------- d-----w- C:\Windows\WindowsMobile
2013-05-22 16:04:12 -------- d-----w- C:\ProgramData\PC-Doctor for Windows
2013-05-22 16:03:19 -------- d-----w- C:\Program Files\My Dell
2013-05-22 14:10:51 -------- d-----w- C:\Users\MA RIA\AppData\Local\{A8F86FC2-9769-4D89-93B5-E871E7526ADD}
2013-05-21 11:40:02 -------- d-----w- C:\Users\MA RIA\AppData\Local\{D6F3A19D-B480-47E0-941D-79AAB2ACF888}
2013-05-20 11:26:23 -------- d-----w- C:\Users\MA RIA\AppData\Local\{CAEB4343-8041-4061-9F3E-EB026514DE59}
2013-05-19 15:44:51 -------- d-----w- C:\Users\MA RIA\AppData\Local\{FD5DE40D-0975-434E-A2EE-5DE0EF936CCF}
.
==================== Find3M ====================
.
2013-05-26 14:54:57 866720 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-05-26 14:54:57 788896 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-05-17 01:25:57 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-05-17 01:25:27 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-05-17 01:25:26 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-05-17 01:25:26 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-05-17 00:59:03 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-05-17 00:58:10 3958784 ----a-w- C:\Windows\System32\jscript9.dll
2013-05-17 00:58:08 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-05-17 00:58:08 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-05-14 12:23:25 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-05-14 08:40:13 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-05-13 05:51:01 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 ----a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 ----a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 ----a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2013-05-10 05:49:27 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2013-05-10 03:20:54 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-05-08 06:39:01 1910632 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-05-01 23:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-05-01 00:59:12 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2013-05-01 00:59:12 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2013-04-26 05:51:36 751104 ----a-w- C:\Windows\System32\win32spl.dll
2013-04-26 04:55:21 492544 ----a-w- C:\Windows\SysWow64\win32spl.dll
2013-04-25 23:30:32 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2013-04-18 13:55:50 18456 ----a-w- C:\Windows\System32\drivers\psi_mf_amd64.sys
2013-04-17 07:02:06 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-04-17 06:24:46 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-04-10 03:30:50 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-04-04 11:50:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-03-31 22:52:16 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2012-06-06 04:06:50 2174976 ----a-w- C:\Program Files (x86)\Common Files\atimpenc.dll
.
============= FINISH: 17:00:38,28 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 16/2/2012 2:31:11 μμ
System Uptime: 18/6/2013 3:47:56 μμ (2 hours ago)
.
Motherboard: Dell Inc. | | 0NJT03
Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz | CPU | 2201/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 679 GiB total, 568,825 GiB free.
D: is CDROM ()
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer:
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
.
Class GUID:
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0001
Manufacturer:
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0001
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0002
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0002
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0003
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0003
Service:
.
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0004
Manufacturer: HP
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0004
Service:
.
==== System Restore Points ===================
.
RP367: 11/6/2013 5:44:39 μμ - Windows Update
RP368: 12/6/2013 4:16:43 μμ - Windows Update
RP369: 13/6/2013 10:48:00 μμ - Windows Update
RP370: 16/6/2013 12:17:17 μμ - Windows Update
.
==== Installed Programs ======================
.
ΜΑΤΖΕΝΤΑ - Αγγλικό-Ελληνικό & Ελληνικό-Αγγλικό λεξικό
1500
1500_Help
1500Trb
64 Bit HP CIO Components Installer
AccelerometerP11
Adobe Acrobat 9 Pro Extended - English, Franηais, Deutsch
Adobe AIR
Adobe Help Manager
Advanced Audio FX Engine
AIO_CDB_ProductContext
AIO_CDB_Software
AIO_Scan
Allok Video Joiner 4.6.0422
Allok Video Splitter 3.0.1130
Any Video Converter 5 5.0.3
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ashampoo Burning Studio 9.21
Bonjour
BufferChm
Copy
D3DX10
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell Edoc Viewer
Dell Getting Started Guide
Dell MusicStage
Dell PhotoStage
Dell Stage
Dell Stage Remote
Dell VideoStage
Dell Webcam Central
DesignPro SE eMedia
Destinations
DeviceDiscovery
DjVuLibre+DjView
DocProc
Dropbox
DVDShrink 2008
eBay
Emsisoft Anti-Malware
ESET Smart Security
Fax
Finale 2011
FireArc Arcade
Free Studio version 2013
Google Chrome
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
GPBaseService2
High-Definition Video Playback
HP Customer Participation Program 13.0
HP Imaging Device Functions 13.0
HP Photo Creations
HP Photosmart 5510 series Basic Device Software
HP Photosmart 5510 series Help
HP Photosmart 5510 series Product Improvement Study
HP Photosmart Essential 3.5
HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B
HP Smart Web Printing 4.51
HP Solution Center 13.0
HP Update
HPPhotoGadget
HPPhotoSmartDiscLabelContent1
HPPhotosmartEssential
HPProductAssistant
HPSSupply
IBM SPSS Amos 19
IBM SPSS Statistics 19
ImTOO Audio Converter Pro
ImTOO Convert PowerPoint to Video Personal
ImTOO DVD Copy 2
ImTOO DVD Creator
ImTOO DVD Ripper Ultimate
ImTOO Video Converter Ultimate
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
Intel(R) PROSet/Wireless WiFi Software Driver
Intel(R) Turbo Boost Technology Monitor 2.0
Intel® PROSet/Wireless Software
Intel® PROSet/Wireless WiFi Software
iTunes
Java 7 Update 21
Junk Mail filter update
K-Lite Mega Codec Pack 8.3.2
MagicDisc 2.7.106
Malwarebytes Anti-Malware version 1.75.0.1300
MarketResearch
MCShield ::Anti-Malware Tool::
Mendeley Desktop 1.8.2
Mesh Runtime
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (Greek) 2010
Microsoft Office Excel MUI (Greek) 2010
Microsoft Office Groove MUI (Greek) 2010
Microsoft Office InfoPath MUI (Greek) 2010
Microsoft Office Office 64-bit Components 2010
Microsoft Office OneNote MUI (Greek) 2010
Microsoft Office Outlook MUI (Greek) 2010
Microsoft Office PowerPoint MUI (Greek) 2010
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (German) 2010
Microsoft Office Proof (Greek) 2010
Microsoft Office Proofing (Greek) 2010
Microsoft Office Publisher MUI (Greek) 2010
Microsoft Office Shared 64-bit MUI (Greek) 2010
Microsoft Office Shared MUI (Greek) 2010
Microsoft Office Word MUI (Greek) 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft_VC100_CRT_SP1_x64
Microsoft_VC100_CRT_SP1_x86
Microsoft_VC80_CRT_x86
Microsoft_VC90_CRT_x86
MSVC80_x64_v2
MSVC80_x86_v2
MSVC90_x64
MSVC90_x86
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2758694)
My Dell
Nero 10 Movie ThemePack Basic
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Network64
Nokia Connectivity Cable Driver
Nokia Suite
NVIDIA 3D Vision Driver 306.97
NVIDIA Control Panel 306.97
NVIDIA Graphics Driver 306.97
NVIDIA Install Application
NVIDIA Optimus 1.10.8
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.10.8
NVIDIA Update Components
OCR Software by I.R.I.S. 13.0
PC Connectivity Solution
PDF Settings CS6
PDF24 Creator 5.4.0
Photo Story 3 for Windows
Quickset64
QuickTime
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Scan
Secunia PSI (3.0.0.7009)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition
Security Update for Microsoft Filter Pack 2.0 (KB2553501) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687422) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2760406) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition
Security Update for Microsoft OneNote 2010 (KB2760600) 32-Bit Edition
Security Update for Microsoft Publisher 2010 (KB2553147) 32-Bit Edition
Security Update for Microsoft Visio 2010 (KB2810068) 32-Bit Edition
Security Update for Microsoft Visio Viewer 2010 (KB2687505) 32-Bit Edition
Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition
Shop for HP Supplies
Skype™ 6.5
SmartWebPrinting
SnowChristmasTree 1.6
SolutionCenter
Status
Subtitle Workshop 2.51
SumatraPDF
SUPERAntiSpyware
swMSM
Synaptics Pointing Device Driver
Syncios version 2.0.3
SyncUP
System Requirements Lab for Intel
TeamViewer 8
TinkerPlots
Toolbox
Total Uninstall 5.2.0
TrayApp
UnloadSupport
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
VLC media player 2.0.6
WaveLab 6
WebReg
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinRAR 4.10 (32-bit)
Wondershare DVD Slideshow Builder Deluxe(Build 6.1.0.41)
.
==== Event Viewer Messages From Past Week ========
.
18/6/2013 2:10:09 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
18/6/2013 2:10:09 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
18/6/2013 2:08:25 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
18/6/2013 2:07:55 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
18/6/2013 2:07:51 μμ, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the TeamViewer 8 service to connect.
18/6/2013 2:07:51 μμ, Error: Service Control Manager [7000] - The TeamViewer 8 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
18/6/2013 2:07:18 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 9:12:50 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
17/6/2013 9:12:50 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
17/6/2013 9:10:05 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:05:08 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:05:08 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:05:08 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:04:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:04:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:04:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:52 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:52 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:52 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:02 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
17/6/2013 8:52:51 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:52:51 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:52:51 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:52:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:52:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:52:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:45 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:45 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:45 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:32 μμ, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:32 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
17/6/2013 8:50:31 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
17/6/2013 8:50:30 μμ, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21
17/6/2013 8:50:28 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
17/6/2013 8:50:22 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
17/6/2013 8:50:13 μμ, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: a2injectiondriver discache eamonm ehdrv SASDIFSV SASKUTIL spldr Wanarpv6
17/6/2013 8:46:44 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 8:45:11 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:45:11 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:45:11 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:44:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:44:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:44:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:43:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:43:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:43:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:42:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:42:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:42:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:38:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:38:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:38:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:37:47 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:37:47 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:37:47 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:57 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:57 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:57 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:45 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:45 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service wh
==== Event Viewer Messages From Past Week ========
.
18/6/2013 2:10:09 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
18/6/2013 2:10:09 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
18/6/2013 2:08:25 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
18/6/2013 2:07:55 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
18/6/2013 2:07:51 μμ, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the TeamViewer 8 service to connect.
18/6/2013 2:07:51 μμ, Error: Service Control Manager [7000] - The TeamViewer 8 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
18/6/2013 2:07:18 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 9:12:50 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
17/6/2013 9:12:50 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
17/6/2013 9:10:05 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:07:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:05:08 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:05:08 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:05:08 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:04:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:04:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 9:04:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:58 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:59:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:52 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:52 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:52 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:40 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:35 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:57:02 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
17/6/2013 8:52:51 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:52:51 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:52:51 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:52:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:52:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:52:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:45 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:45 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:45 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:33 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:32 μμ, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:50:32 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
17/6/2013 8:50:31 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
17/6/2013 8:50:30 μμ, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21
17/6/2013 8:50:28 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
17/6/2013 8:50:22 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
17/6/2013 8:50:13 μμ, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: a2injectiondriver discache eamonm ehdrv SASDIFSV SASKUTIL spldr Wanarpv6
17/6/2013 8:46:44 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 8:45:11 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:45:11 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:45:11 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:44:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:44:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:44:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:43:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:43:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:43:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:42:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:42:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:42:41 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:38:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:38:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:38:05 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:37:47 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:37:47 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:37:47 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:57 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:57 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:57 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:45 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:45 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:45 μμ, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:44 μμ, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:35:43 μμ, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21
17/6/2013 8:35:42 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
17/6/2013 8:35:42 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
17/6/2013 8:35:39 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
17/6/2013 8:35:34 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
17/6/2013 8:35:25 μμ, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: a2injectiondriver discache eamonm ehdrv SASDIFSV SASKUTIL spldr Wanarpv6
17/6/2013 8:33:59 μμ, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:42 μμ, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:42 μμ, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:42 μμ, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:42 μμ, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:42 μμ, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:42 μμ, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:39 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
17/6/2013 8:33:39 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
17/6/2013 8:33:38 μμ, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:38 μμ, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:38 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
17/6/2013 8:33:38 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
17/6/2013 8:33:37 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
17/6/2013 8:33:32 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
17/6/2013 8:33:18 μμ, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: a2injectiondriver AFD DfsC discache eamonm ehdrv EpfwLWF NetBIOS NetBT nsiproxy Psched rdbss SASDIFSV SASKUTIL spldr tdx vwififlt Wanarpv6 WfpLwf
17/6/2013 8:33:17 μμ, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:17 μμ, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
17/6/2013 8:33:17 μμ, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
17/6/2013 8:33:17 μμ, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:17 μμ, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:17 μμ, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
17/6/2013 8:33:17 μμ, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:17 μμ, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
17/6/2013 8:33:17 μμ, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
17/6/2013 8:33:17 μμ, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
17/6/2013 8:30:46 μμ, Error: Service Control Manager [7022] - The ESET Service service hung on starting.
17/6/2013 8:29:04 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 8:23:50 μμ, Error: Service Control Manager [7022] - The ESET Service service hung on starting.
17/6/2013 8:22:08 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 6:20:50 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
17/6/2013 6:20:50 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
17/6/2013 6:17:54 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 5:09:11 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
17/6/2013 5:09:11 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
17/6/2013 5:07:47 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
17/6/2013 5:07:17 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
17/6/2013 5:06:40 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 5:05:56 μμ, Error: Service Control Manager [7038] - The upnphost service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The request is not supported. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
17/6/2013 5:05:56 μμ, Error: Service Control Manager [7000] - The UPnP Device Host service failed to start due to the following error: The service did not start due to a logon failure.
17/6/2013 5:05:56 μμ, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1069" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
17/6/2013 2:52:29 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
17/6/2013 2:52:29 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
17/6/2013 2:51:28 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
17/6/2013 2:50:58 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
17/6/2013 2:50:14 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 10:50:06 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
17/6/2013 10:49:36 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
17/6/2013 10:48:49 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 10:27:24 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
17/6/2013 10:27:24 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
17/6/2013 10:24:23 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
17/6/2013 10:22:22 μμ, Error: Service Control Manager [7031] - The Emsisoft Anti-Malware 7.0 - Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
16/6/2013 12:23:09 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
16/6/2013 12:23:09 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
16/6/2013 12:21:52 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
16/6/2013 12:20:41 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
16/6/2013 12:17:21 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
16/6/2013 12:17:21 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
16/6/2013 12:16:15 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
16/6/2013 12:15:45 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
16/6/2013 12:14:57 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
15/6/2013 10:29:12 πμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
15/6/2013 10:29:12 πμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
15/6/2013 10:27:50 πμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
15/6/2013 10:26:51 πμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
14/6/2013 7:02:51 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
14/6/2013 7:02:51 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
14/6/2013 7:01:43 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
14/6/2013 7:01:13 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
14/6/2013 7:00:30 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
14/6/2013 6:52:51 μμ, Error: Service Control Manager [7034] - The NVIDIA Stereoscopic 3D Driver Service service terminated unexpectedly. It has done this 1 time(s).
14/6/2013 6:19:50 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
14/6/2013 6:19:50 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
14/6/2013 6:18:39 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
14/6/2013 6:18:09 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
14/6/2013 6:17:26 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
14/6/2013 3:05:36 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
14/6/2013 3:05:36 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
14/6/2013 3:04:17 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
14/6/2013 3:03:47 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
14/6/2013 3:03:01 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
13/6/2013 6:27:04 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
13/6/2013 6:27:04 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
13/6/2013 6:26:01 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
13/6/2013 6:25:31 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
13/6/2013 6:24:46 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
13/6/2013 3:05:10 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
13/6/2013 3:05:10 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
13/6/2013 3:03:52 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
13/6/2013 3:03:22 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
13/6/2013 3:02:48 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
13/6/2013 12:27:35 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
13/6/2013 12:27:35 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
13/6/2013 12:26:32 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
13/6/2013 12:26:02 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
13/6/2013 12:25:13 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
12/6/2013 8:40:01 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
12/6/2013 8:40:01 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
12/6/2013 8:38:27 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
12/6/2013 8:37:57 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
12/6/2013 8:37:25 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
12/6/2013 5:05:52 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
12/6/2013 5:05:52 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
12/6/2013 5:04:51 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
12/6/2013 5:03:31 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
12/6/2013 4:12:48 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
12/6/2013 4:12:48 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
12/6/2013 4:11:40 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
12/6/2013 4:11:10 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
12/6/2013 4:10:27 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
12/6/2013 2:19:06 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
12/6/2013 2:19:06 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
12/6/2013 2:18:46 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
12/6/2013 2:16:47 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
12/6/2013 10:22:06 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR3.
12/6/2013 10:22:05 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR3.
12/6/2013 10:22:05 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR3.
12/6/2013 10:22:04 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR3.
12/6/2013 10:22:04 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR3.
12/6/2013 10:05:24 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR2.
12/6/2013 10:05:24 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR2.
12/6/2013 10:05:23 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR2.
12/6/2013 10:05:23 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR2.
12/6/2013 10:05:22 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR2.
11/6/2013 8:25:26 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
11/6/2013 8:25:26 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
11/6/2013 8:24:03 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
11/6/2013 8:23:05 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
11/6/2013 5:43:04 μμ, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
11/6/2013 5:43:04 μμ, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
11/6/2013 5:42:43 μμ, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
11/6/2013 5:40:44 μμ, Error: Service Control Manager [7000] - The GoToMyPC service failed to start due to the following error: The system cannot find the file specified.
11/6/2013 10:00:32 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
11/6/2013 10:00:31 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
11/6/2013 10:00:31 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
11/6/2013 10:00:30 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
11/6/2013 10:00:30 μμ, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
.
==== End Of File ===========================
Results of screen317's Security Check version 0.99.64
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````[/u]
Windows Firewall Enabled!
ESET Smart Security 6.0
Emsisoft Anti-Malware
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````[/u]
Secunia PSI (3.0.0.7009)
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 21
Google Chrome 27.0.1453.110
````````Process Check: objlist.exe by Laurent````````[/u]
ESET NOD32 Antivirus egui.exe
ESET NOD32 Antivirus ekrn.exe
Emsisoft Anti-Malware a2service.exe
`````````````````System Health check`````````````````[/u]
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````[/u]
Hi, Panos.
I agree that there is no problem with McShield (http://www.mcshield.net/). This is a program I suggested shortly after you joined LzD and were helping a friend with an infected computer. I am not seeing signs of malware on your computer, although, as you saw, there are a lot of event viewer errors listed in the log.
Based on the number of "The driver detected a controller error on \Device\Harddisk1\DR1", you may have a USB that is showing signs of wear and tear. You may want to check for errors: Check a drive for errors (http://windows.microsoft.com/en-us/windows7/Check-a-drive-for-errors).
Did you uninstall "GoToMyPC", http://www.gotomypc.com/remote_access/remote_access, another source of errors that may also be tied to several other errors?
It probably wouldn't hurt to run System File Checker. Instructions:
Please perform a SFC (System File Checker) scan which will check and fix any corrupted files on your system.
- Click Start, and then type cmd in the Start Search box.
- Right-click cmd in the Programs list, and then right-click Run as administrator.
- If you are prompted for an administrator password or confirmation, type your password or click Continue
- At the command prompt, type the following line, and then press ENTER: sfc /scannow (note the space before the slash)
- When the scan is complete, if no errors are found, restart your computer and post back
- If the message does not say "Windows resource protection did not find any integrity violations", restart your computer and run System File Checker again.
Note: You may need to run System File Checker
up to three times to resolve all corrupted files. Please advise if you still have corrupted files after a fourth run.
Hi, Corine. :hallo:
When I installed Emsisoft, I wanted to ask you if the software has a common link with MCShield; Em (M) Si (C), and the icons of the two programs are almost the same.
I uninstalled Go to my PC months ago, and I wonder why it appears so many times in the logs... I wanted something to help me have access in my pc from my tablet, but I found that team viewer is better.
The same is happening with Adobe Pro, Adobe Help, Adobe Air... I uninstalled all these. Why they are still in the computer?
And why my free C space is less now I uninstalled programs, than before I had them installed?
The logs are chinese for me, but what does this mean: Logon failure: the specified account password has expired. ?
I performed the SFC scan and there were no errors.
The time when the computer stopped working, I had only my tablet connected with usb cable. You think that this might caused the problem? It is not the first time, anyway...
I didn't check any drive for errors yet...
Really, sorry for "stealing" your time again...
Panos
Hi, Panos. You are
not "stealing" any of my time. I'm happy to do what I can to help you!
No, there is no connection between Emsisoft and McChield. Any similarity in the icons is coincidence.
Any chance GoToMyPC is still installed on the tablet? The Logon failures seem to be pointing to various services. Let's take a look.
Please download Farbar Service Scanner (http://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/) and run it on the computer with the issue.
- Make sure the following options are checked:
- Internet Services
- Windows Firewall
- System Restore
- Security Center/Action Center
- Windows Update
- Windows Defender
- Press "Scan".
- It will create a log (FSS.txt) in the same directory the tool is run.
- Please copy and paste the log to your reply.
Hello, Corine.
Another thing happened yesterday: After windows started, I accidentally entered my password with a mistake. When I tried to enter it again, I noticed that below the blank bar, there was the password hint, and below the hint there was a question about pass reset. This thing never happened again till now. I clicked reset pass, and an error window occured, saying that I need disc or usb to perform this action.
When the computer started, using the correct pass, the message about MCShield from EmSiSoft appeared again. I tried to entered MCShield controll center to disable it, but an error message saying that this is not a valid application occured. I uninstalled and reinstalled it, but I got the same error. Then I uninstalled EmSiSoft. MCShield worked again.
Perhaps all these have no matter, but I want you to know exactly what I am doing.
Now, the log from Farbar Scanner:
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
Other Services:
==============
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2013-06-12 14:26] - [2013-05-08 09:39] - 1910632 ____A (Microsoft Corporation) 9849EA3843A2ADBDD1497E97A85D8CAE
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll
[2013-06-12 14:26] - [2013-05-13 08:51] - 0184320 ____A (Microsoft Corporation) D8129C49798CBBFB2E4351D4B7B8EF9C
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
Since the MCShield Anti-Malware Tool is meant to protect USB drives, I wonder if there was a conflict between it and Emsisoft Anti-Malware 's real time protection ... you said you uninstalled Emsisoft, but perhaps the logs were left behind and would tell you something? If memory serves, you can set permissions within Emsisoft to allow MCShield to run unhindered.
Yes, I could set permissions within Emsisoft, but I prefered to uninstall it and maybe reinstall it later. Meanwhile, the site in where Eset blocked something, today says that although they received complaints about a virus, they assure that everything is ok within it.
Meanwhile, when I try to post in the forum I get this message:
This page can't be displayed
•Make sure the web address http://www.landzdown.com is correct.
•Look for the page with your search engine.
•Refresh the page in a few minutes.
Please, is there anything that I could do next? :sad:
DR M,
It could just be the server being a little slow as it some times happens to me.
But then I to use ESET can not say that it has blocked anything.
GR@PH;<'S (https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fi5.photobucket.com%2Falbums%2Fy197%2FANG-Graphics%2Fthcoffee_zpscf290df1.gif&hash=26239a18e133675e9031c0cf793388819e1fd6a1)
Hi, Panos.
Sorry for the delay. I wanted to spend some additional time looking at some of the entries in the log. Even though you used the Adobe cleanup tool, it seems that there are still remnants. Since ComboFix is so good at cleaning up orphans, please do the following:
Please follow these instructions carefully.Download ComboFix from
here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe).
!!! IMPORTANT !!! Save ComboFix.exe to your DesktopDisable your antivirus and anti-malware security applications. If not disabled, these programs will likely interfere with cleanup process. This can usually be accomplished by a right-click on the icon in the System Tray.
Note: If you are unsure how to disable your security software, see the instructions in this topic at Tech Support Forum: How to disable your security applications (http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/490111-how-disable-your-security-applications.html).
Now, please run ComboFix:
- Note: If infections are found, ComboFix will automatically reboot the machine to complete the removal process. Please ensure all opened windows are closed before proceeding.
- Double-click ComboFix.exe on your desktop and follow the prompts.
- As part of the process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it is strongly recommended to have this pre-installed on your machine before doing any malware removal. The Recovery Console will allow you to start up the computer in a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Please note: If the Microsoft Windows Recovery Console is already installed on the computer, ComboFix will continue the malware removal procedures.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console.
- When prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
(https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fsecuritygarden.googlepages.com%2FCF_RC1.png&hash=29e6fe1eb864e58b4b66611caa7d7b6be84a47f8)
- After the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
(https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fsecuritygarden.googlepages.com%2FCF_RC2.png&hash=e111f6aa2d657579d44cabc5fb4258fd1dce26eb)
- Click "Yes" to continue scanning for malware.
- When finished, a log will be produced. Please include the C:\ComboFix.txt in your next reply.
Sorry for my anxiety!
Combofix log:
ComboFix 13-06-21.02 - MA RIA 21/06/2013 13:23:39.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1253.30.1033.18.6038.3962 [GMT 3:00]
Running from: c:\users\MA RIA\Desktop\ComboFix.exe
AV: ESET Smart Security 6.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 6.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\MyWebFace_5aEI
c:\program files (x86)\MyWebFace_5aEI\Installr\1.bin\5aEIPlug.dll
c:\program files (x86)\MyWebFace_5aEI\Installr\1.bin\5aEZSETP.dll
c:\program files (x86)\MyWebFace_5aEI\Installr\1.bin\NP5aEISb.dll
c:\programdata\PCDr\6261\AddOnDownloaded\1f7e3200-2791-441e-8615-1258d84e5f61.dll
c:\programdata\PCDr\6261\AddOnDownloaded\27ada864-54d8-46c9-a6e3-8334fa39b525.dll
c:\programdata\PCDr\6261\AddOnDownloaded\2eccd5d6-e118-4f76-97b6-ba56fb6c597a.dll
c:\programdata\PCDr\6261\AddOnDownloaded\31274d4c-b2a5-4954-874c-18abd8e795fc.dll
c:\programdata\PCDr\6261\AddOnDownloaded\3820d79a-0389-4fd9-b10c-00d2774e8996.dll
c:\programdata\PCDr\6261\AddOnDownloaded\5e1499b7-780b-4b0e-8240-0221e699a647.dll
c:\programdata\PCDr\6261\AddOnDownloaded\7a273375-a427-45b1-8925-a4fd3312f55b.dll
c:\programdata\PCDr\6261\AddOnDownloaded\958decf6-f105-42b7-b2b8-ecb97b06448b.dll
c:\programdata\PCDr\6261\AddOnDownloaded\b3ef58a2-77e9-414a-b8f6-b8cbbf497383.dll
c:\programdata\Roaming
c:\users\MA RIA\AppData\Roaming\inst.exe
c:\users\MA RIA\AppData\Roaming\vso_ts_preview.xml
c:\windows\UA000011.DLL
.
.
((((((((((((((((((((((((( Files Created from 2013-05-21 to 2013-06-21 )))))))))))))))))))))))))))))))
.
.
2013-06-21 10:34 . 2013-06-21 10:34 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-06-21 10:34 . 2013-06-21 10:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-06-21 10:16 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F270FCA-46E0-4F92-AAEF-1E921D16D668}\mpengine.dll
2013-06-18 20:01 . 2013-06-18 20:01 -------- d-----w- c:\program files (x86)\MCShield
2013-06-16 09:18 . 2013-06-08 12:28 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-06-16 09:18 . 2013-06-08 11:13 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-06-16 09:18 . 2013-06-08 14:08 279040 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2013-06-16 09:18 . 2013-06-08 11:41 218112 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll
2013-06-16 09:18 . 2013-06-08 14:08 1365504 ----a-w- c:\windows\system32\urlmon.dll
2013-06-16 09:18 . 2013-06-08 14:06 2648064 ----a-w- c:\windows\system32\iertutil.dll
2013-06-16 09:17 . 2013-06-08 14:06 526336 ----a-w- c:\windows\system32\ieui.dll
2013-06-16 09:17 . 2013-06-08 14:06 15404544 ----a-w- c:\windows\system32\ieframe.dll
2013-06-16 09:17 . 2013-06-08 14:07 19233792 ----a-w- c:\windows\system32\mshtml.dll
2013-06-12 13:05 . 2013-06-12 13:05 -------- d-----w- c:\users\MA RIA\AppData\Roaming\NVIDIA
2013-06-12 12:58 . 2013-06-12 12:58 -------- d-----w- c:\users\MA RIA\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-06-12 12:54 . 2013-06-12 12:54 -------- d-----w- c:\users\MA RIA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2013-06-12 12:52 . 2013-06-12 13:04 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2013-05-26 14:57 . 2013-05-26 14:57 1409 ----a-w- c:\windows\QTFont.for
2013-05-26 14:55 . 2013-05-26 14:55 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-05-26 14:47 . 2013-05-26 14:47 -------- d-----w- c:\users\MA RIA\AppData\Local\Secunia PSI
2013-05-26 14:47 . 2013-05-26 14:47 -------- d-----w- c:\program files (x86)\Secunia
2013-05-26 14:10 . 2013-05-26 14:24 -------- d-----w- c:\programdata\Package Cache
2013-05-26 14:00 . 2013-05-26 14:00 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
2013-05-24 17:45 . 2013-05-24 17:54 -------- d-----w- c:\program files (x86)\Realtek
2013-05-24 17:25 . 2013-05-24 17:25 -------- d-----w- c:\programdata\Intel
2013-05-24 17:23 . 2013-05-24 17:23 -------- d--h--w- c:\windows\system32\WLANProfiles
2013-05-23 15:28 . 2013-05-23 15:28 -------- d-----w- c:\users\MA RIA\New folder
2013-05-22 19:02 . 2013-05-23 15:58 -------- d-----w- c:\windows\WindowsMobile
2013-05-22 16:04 . 2013-05-22 16:04 -------- d-----w- c:\programdata\PC-Doctor for Windows
2013-05-22 16:03 . 2013-05-22 16:04 -------- d-----w- c:\program files\My Dell
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 13:18 . 2012-02-17 13:02 75825640 ----a-w- c:\windows\system32\MRT.exe
2013-05-26 14:54 . 2012-11-15 18:56 866720 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-05-26 14:54 . 2012-11-15 18:56 788896 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-05-11 10:08 . 2010-06-24 17:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-01 23:06 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-05-01 00:59 . 2013-05-01 00:59 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2013-05-01 00:59 . 2013-05-01 00:59 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2013-04-18 13:55 . 2013-04-18 13:55 18456 ----a-w- c:\windows\system32\drivers\psi_mf_amd64.sys
2013-04-13 05:49 . 2013-05-15 13:50 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-15 13:50 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-15 13:50 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-15 13:50 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-15 13:50 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-15 13:50 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-04-12 14:45 . 2013-04-24 12:18 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-10 06:01 . 2013-05-15 13:50 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 06:01 . 2013-05-15 13:50 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 03:30 . 2013-05-15 13:49 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-04-04 11:50 . 2012-02-17 14:43 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-06 04:06 . 2012-06-06 04:06 2174976 ----a-w- c:\program files (x86)\Common Files\atimpenc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MCShield Monitor"="c:\program files (x86)\MCShield\mcshieldrtm.exe" [2013-04-04 607744]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-04-30 885760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R1 fxbiojph;fxbiojph;c:\windows\system32\drivers\fxbiojph.sys;c:\windows\SYSNATIVE\drivers\fxbiojph.sys
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys
R3 BthMtpEnum;Bluetooth MTP Device Enumerator;c:\windows\system32\DRIVERS\BthMtpEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthMtpEnum.sys
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys;c:\windows\SYSNATIVE\drivers\Impcd.sys
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys;c:\windows\SYSNATIVE\drivers\nvstusb.sys
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf_amd64.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf_amd64.sys
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys
R3 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys;c:\windows\SYSNATIVE\DRIVERS\stdcfltn.sys
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys
S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvkflt.sys
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe
S2 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe;c:\program files (x86)\Secunia\PSI\sua.exe
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys;c:\windows\SYSNATIVE\DRIVERS\Accelern.sys
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys
S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys;c:\windows\SYSNATIVE\drivers\btmaud.sys
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys
S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys;c:\windows\SYSNATIVE\DRIVERS\qicflt.sys
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-06-20 16:19 1165776 ----a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-28 15:35]
.
2013-06-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA1ce48d96f4bb08f.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-28 15:35]
.
2013-06-20 c:\windows\Tasks\HP Photo Creations Messager.job
- c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11]
.
2013-06-19 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task bf64327c-6b9e-43e4-b2d0-cf288408c881.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-18 6611048]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-05 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-05 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-05 416024]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-12-21 6326448]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshellex.dll" [2012-12-03 11733888]
"BLEServicesCtrl"="c:\program files (x86)\Intel\Bluetooth\BleServicesCtrl.exe" [2012-09-17 184112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.bing.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = proxy.unic.ac.cy:8080
uInternet Settings,ProxyOverride = *.local;<local>
IE: Send to Bluetooth - c:\program files (x86)\Intel\Bluetooth\btSendToObject.htm
TCP: DhcpNameServer = 192.168.10.254
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Wow6432Node\Adobe Acrobat\9.0]
@DACL=(02 0000)
.
[HKEY_USERS\LocalService\Software\Wow6432Node\Adobe Acrobat\9.0]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-20\Software\Wow6432Node\Adobe Acrobat\9.0]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1297263482-2230557874-2472846458-1001\Software\Wow6432Node\Adobe Acrobat\9.0]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-06-21 13:47:41
ComboFix-quarantined-files.txt 2013-06-21 10:47
.
Pre-Run: 607.996.981.248 bytes free
Post-Run: 607.460.687.872 bytes free
.
- - End Of File - - DCA9E64AEE6654E7D4F2FF39078B9FC5
D41D8CD98F00B204E9800998ECF8427E
Hi, Panos.
Again you needed to wait for my response. I was outside much of the day as well as running errands.
The purpose of the following ComboFix script is to clean up the leftovers after you ran the Adobe cleanup tool. I suspect the leftovers were due to Adobe's silly habit of locking registry keys so we'll let ComboFix unlock them and remove the indicated files. If you have decided to reinstall the programs you removed, let me know and don't run the script.
Custom CFScript
Note: The following instructions were created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
- Please open Notepad (Click Start -> Run -> type notepad in the Open field -> OK). Copy/Paste all of the text present inside the code box below:
RegLock::
[HKEY_USERS\.Default\Software\Wow6432Node\Adobe Acrobat\9.0]
[HKEY_USERS\LocalService\Software\Wow6432Node\Adobe Acrobat\9.0]
[HKEY_USERS\S-1-5-20\Software\Wow6432Node\Adobe Acrobat\9.0]
[HKEY_USERS\S-1-5-21-1297263482-2230557874-2472846458-1001\Software\Wow6432Node\Adobe Acrobat\9.0]
File::
c:\users\MA RIA\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
c:\users\MA RIA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
c:\programdata\regid.1986-12.com.adobe
- Save this as CFScript.txt and place it on your desktop.
- Close any open browsers.
- Close/disable all antivirus and anti-malware programs so they do not interfere with the running of ComboFix.
(https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fsecuritygarden.googlepages.com%2FCF_CFScript.gif&hash=19cdd291c9ded999b7ed69b7a82ebed7c9d0ab01)
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hi, Corine.
No need to apologise! The time diference makes the communication difficult, but we will overcome the situation as always! I wish I could reciprocate the help you offer to me! :rose:
After I ran Combofix, every time I entered a website I got the message that I was leaving secure internet connection and it would be possible for others to view information I send. I clicked not to get this message again.
As for the adobe programs, I would like to reinstall the Adobe flash player (many sites asks for its installation) and the free Adobe reader. Although Sumatra is now my default pdf reader, the problem I refered to in a previous topic, with some images formated in Word, makes me think that it should be good having Adobe reader installed as well. No other reason for wanting Adobe. Surely, I don't want Acrobat 9 Pro, Bridge, Air, Help anymore, but maybe I will need Adobe Photoshop one day.
So, I will wait for your reply before I run the script.
P.S.
What is your opinion about the password hint given after entering a wrong password, when windows start? Does this have to do with an update?
I scan my computer with Eset yesterday. Many many errors were found, but no malware. I have also taken a look in some old Eset scan logs. The files found and deleted as a thread were java files. Some of my programs need Java to run, so what can I do?
Hi, Panos.
The password hint after entering a wrong password is a feature of Windows 7. See Create or change a password hint (http://windows.microsoft.com/en-US/Windows7/Create-or-change-a-password-hint).
The items included in the ComboFix script do not apply to Adobe Flash Player or Adobe Reader. If you do decide to reinstall Adobe Reader, you will need to remember to keep it updated. Since installing Sumatra PDF, I have yet to run into any situation that has required Adobe Reader.
Regarding the programs that require Java, are they locally installed programs so no Internet connection is required?
I ran Combofix, but forgot disable Windows Defender... Combofix asked for installing a new version and I clicked no. Should I run it again? Although, here is the log:
ComboFix 13-06-21.02 - MA RIA 22/06/2013 22:25:36.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1253.30.1033.18.6038.3752 [GMT 3:00]
Running from: c:\users\MA RIA\Desktop\ComboFix.exe
Command switches used :: c:\users\MA RIA\Desktop\CFScript.txt
AV: ESET Smart Security 6.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 6.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\programdata\regid.1986-12.com.adobe"
"c:\users\MA RIA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1"
"c:\users\MA RIA\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\PCDr\6261\AddOnDownloaded\1f7e3200-2791-441e-8615-1258d84e5f61.dll
c:\programdata\PCDr\6261\AddOnDownloaded\27ada864-54d8-46c9-a6e3-8334fa39b525.dll
c:\programdata\PCDr\6261\AddOnDownloaded\2eccd5d6-e118-4f76-97b6-ba56fb6c597a.dll
c:\programdata\PCDr\6261\AddOnDownloaded\31274d4c-b2a5-4954-874c-18abd8e795fc.dll
c:\programdata\PCDr\6261\AddOnDownloaded\3820d79a-0389-4fd9-b10c-00d2774e8996.dll
c:\programdata\PCDr\6261\AddOnDownloaded\5e1499b7-780b-4b0e-8240-0221e699a647.dll
c:\programdata\PCDr\6261\AddOnDownloaded\7a273375-a427-45b1-8925-a4fd3312f55b.dll
c:\programdata\PCDr\6261\AddOnDownloaded\958decf6-f105-42b7-b2b8-ecb97b06448b.dll
c:\programdata\PCDr\6261\AddOnDownloaded\b3ef58a2-77e9-414a-b8f6-b8cbbf497383.dll
c:\programdata\PCDr\6261\AddOnDownloaded\ba005e12-3139-4327-9f7a-9f2ea6a6c841.dll
.
.
((((((((((((((((((((((((( Files Created from 2013-05-22 to 2013-06-22 )))))))))))))))))))))))))))))))
.
.
2013-06-22 19:34 . 2013-06-22 19:34 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-06-22 19:34 . 2013-06-22 19:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-06-22 19:34 . 2013-06-22 19:34 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F270FCA-46E0-4F92-AAEF-1E921D16D668}\offreg.dll
2013-06-21 10:16 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F270FCA-46E0-4F92-AAEF-1E921D16D668}\mpengine.dll
2013-06-18 20:01 . 2013-06-18 20:01 -------- d-----w- c:\program files (x86)\MCShield
2013-06-16 09:18 . 2013-06-08 12:28 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-06-16 09:18 . 2013-06-08 11:13 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-06-16 09:18 . 2013-06-08 14:08 279040 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2013-06-16 09:18 . 2013-06-08 11:41 218112 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll
2013-06-16 09:18 . 2013-06-08 14:08 1365504 ----a-w- c:\windows\system32\urlmon.dll
2013-06-16 09:18 . 2013-06-08 14:06 2648064 ----a-w- c:\windows\system32\iertutil.dll
2013-06-16 09:17 . 2013-06-08 14:06 526336 ----a-w- c:\windows\system32\ieui.dll
2013-06-16 09:17 . 2013-06-08 14:06 15404544 ----a-w- c:\windows\system32\ieframe.dll
2013-06-16 09:17 . 2013-06-08 14:07 19233792 ----a-w- c:\windows\system32\mshtml.dll
2013-06-12 13:05 . 2013-06-12 13:05 -------- d-----w- c:\users\MA RIA\AppData\Roaming\NVIDIA
2013-06-12 12:58 . 2013-06-12 12:58 -------- d-----w- c:\users\MA RIA\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-06-12 12:54 . 2013-06-12 12:54 -------- d-----w- c:\users\MA RIA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2013-06-12 12:52 . 2013-06-12 13:04 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2013-05-26 14:57 . 2013-05-26 14:57 1409 ----a-w- c:\windows\QTFont.for
2013-05-26 14:55 . 2013-05-26 14:55 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-05-26 14:47 . 2013-05-26 14:47 -------- d-----w- c:\users\MA RIA\AppData\Local\Secunia PSI
2013-05-26 14:47 . 2013-05-26 14:47 -------- d-----w- c:\program files (x86)\Secunia
2013-05-26 14:10 . 2013-05-26 14:24 -------- d-----w- c:\programdata\Package Cache
2013-05-26 14:00 . 2013-05-26 14:00 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
2013-05-24 17:45 . 2013-05-24 17:54 -------- d-----w- c:\program files (x86)\Realtek
2013-05-24 17:25 . 2013-05-24 17:25 -------- d-----w- c:\programdata\Intel
2013-05-24 17:23 . 2013-05-24 17:23 -------- d--h--w- c:\windows\system32\WLANProfiles
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 13:18 . 2012-02-17 13:02 75825640 ----a-w- c:\windows\system32\MRT.exe
2013-05-26 14:54 . 2012-11-15 18:56 866720 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-05-26 14:54 . 2012-11-15 18:56 788896 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-05-11 10:08 . 2010-06-24 17:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-01 23:06 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-05-01 00:59 . 2013-05-01 00:59 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2013-05-01 00:59 . 2013-05-01 00:59 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2013-04-18 13:55 . 2013-04-18 13:55 18456 ----a-w- c:\windows\system32\drivers\psi_mf_amd64.sys
2013-04-13 05:49 . 2013-05-15 13:50 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-15 13:50 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-15 13:50 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-15 13:50 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-15 13:50 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-15 13:50 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-04-12 14:45 . 2013-04-24 12:18 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-10 06:01 . 2013-05-15 13:50 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 06:01 . 2013-05-15 13:50 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 03:30 . 2013-05-15 13:49 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-04-04 11:50 . 2012-02-17 14:43 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-06 04:06 . 2012-06-06 04:06 2174976 ----a-w- c:\program files (x86)\Common Files\atimpenc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MCShield Monitor"="c:\program files (x86)\MCShield\mcshieldrtm.exe" [2013-04-04 607744]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-04-30 885760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R1 fxbiojph;fxbiojph;c:\windows\system32\drivers\fxbiojph.sys;c:\windows\SYSNATIVE\drivers\fxbiojph.sys
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys
R3 BthMtpEnum;Bluetooth MTP Device Enumerator;c:\windows\system32\DRIVERS\BthMtpEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthMtpEnum.sys
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys;c:\windows\SYSNATIVE\drivers\Impcd.sys
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys;c:\windows\SYSNATIVE\drivers\nvstusb.sys
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf_amd64.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf_amd64.sys
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys
R3 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys;c:\windows\SYSNATIVE\DRIVERS\stdcfltn.sys
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys
S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvkflt.sys
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe
S2 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe;c:\program files (x86)\Secunia\PSI\sua.exe
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys;c:\windows\SYSNATIVE\DRIVERS\Accelern.sys
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys
S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys;c:\windows\SYSNATIVE\drivers\btmaud.sys
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys
S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys;c:\windows\SYSNATIVE\DRIVERS\qicflt.sys
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-06-20 16:19 1165776 ----a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-28 15:35]
.
2013-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA1ce48d96f4bb08f.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-28 15:35]
.
2013-06-22 c:\windows\Tasks\HP Photo Creations Messager.job
- c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11]
.
2013-06-22 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task bf64327c-6b9e-43e4-b2d0-cf288408c881.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-18 6611048]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-05 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-05 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-05 416024]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-12-21 6326448]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshellex.dll" [2012-12-03 11733888]
"BLEServicesCtrl"="c:\program files (x86)\Intel\Bluetooth\BleServicesCtrl.exe" [2012-09-17 184112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = proxy.unic.ac.cy:8080
uInternet Settings,ProxyOverride = *.local;<local>
IE: Send to Bluetooth - c:\program files (x86)\Intel\Bluetooth\btSendToObject.htm
TCP: DhcpNameServer = 192.168.10.254
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\LocalService\Software\Wow6432Node\Adobe Acrobat\9.0]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-06-22 22:48:34
ComboFix-quarantined-files.txt 2013-06-22 19:48
ComboFix2.txt 2013-06-21 10:47
.
Pre-Run: 606.955.831.296 bytes free
Post-Run: 606.645.002.240 bytes free
.
- - End Of File - - 71457D94F45C491EE9C6E9848BD05933
D41D8CD98F00B204E9800998ECF8427E
P.S. :)
1. Programs that need java run without internet connection.
2. Password hint when enter a wrong pass from the first time was not an option before. Well, I think so! :huh:
3. Unfortunately Sumatra changes the original image edited in Word (e.g. http://www.landzdown.com/computer-problems-questions-and-solutions!/problem-with-adobe-reader/ ). If there is a solution for this issue, I don't need Adobe Reader.
4. THANK YOU! :mitch:
Yes, sUBs updates ComboFix every few days so it is always best to install the new version when prompted, besides the script didn't work because I should have used "folder" instead of "file". :smash: It isn't critical to remove them but worth trying again if you don't mind.
Custom CFScript
Note: The following instructions were created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
- Please open Notepad (Click Start -> Run -> type notepad in the Open field -> OK). Copy/Paste all of the text present inside the code box below:
RegLock::
[HKEY_USERS\.Default\Software\Wow6432Node\Adobe Acrobat\9.0]
[HKEY_USERS\LocalService\Software\Wow6432Node\Adobe Acrobat\9.0]
[HKEY_USERS\S-1-5-20\Software\Wow6432Node\Adobe Acrobat\9.0]
[HKEY_USERS\S-1-5-21-1297263482-2230557874-2472846458-1001\Software\Wow6432Node\Adobe Acrobat\9.0]
Folder::
c:\users\MA RIA\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
c:\users\MA RIA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
c:\programdata\regid.1986-12.com.adobe
- Save this as CFScript.txt and place it on your desktop.
- Close any open browsers.
- Close/disable all antivirus and anti-malware programs so they do not interfere with the running of ComboFix.
(https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fsecuritygarden.googlepages.com%2FCF_CFScript.gif&hash=19cdd291c9ded999b7ed69b7a82ebed7c9d0ab01)
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
1. Java: Microsoft released a Fix it solution so that people who need Java for programs on their computer but not the internet can disable Java in Internet Explorer. I provided the instructions in this blog post: Microsoft Fix it to Disable Java in Internet Explorer (http://securitygarden.blogspot.com/2013/06/microsoft-fix-it-to-disable-java-in.html).
Instructions for disabling Java in other browsers is in section 3 of Java, The Never-Ending Saga (http://securitygarden.blogspot.com/p/blog-page_18.html). Since you have Chrome installed, you'd need to make the change in both browsers.
2. Password Hint: Perhaps you haven't made enough mistakes with your password before to result in getting the password hint. There is also the option to Create a password reset disk (http://windows.microsoft.com/en-us/windows7/create-a-password-reset-disk).
3. Sumatra & Word images -- I remember that topic. In a search of the Sumatra PDF Forum (a bit awkward), the closest I came is here: LINKS AND IMAGES IN PDF FORMAT (http://forums.fofou.org/sumatrapdf/topic?id=3183756&comments=1), but that is related to converting to eBook format. This much older item is a bit closer: How is the conversion? (http://forums.fofou.org/sumatrapdf/topic?id=2336).
I was beginning to wonder if the "border" is the grey background leaking through and then came across this: smoothing does not work in 1.4 (http://forums.fofou.org/sumatrapdf/topic?id=2013354). Not being knowledgeable in graphics, I wonder if that is related. Also see http://code.google.com/p/sumatrapdf/issues/detail?id=1297
4. You are welcome!!!
Good morning, Corrine!
I will handle with Java and Sumatra later.
Meanwhile, here is the new Combofix log:
ComboFix 13-06-22.01 - MA RIA 23/06/2013 7:26.3.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1253.30.1033.18.6038.4057 [GMT 3:00]
Running from: c:\users\MA RIA\Desktop\ComboFix.exe
Command switches used :: c:\users\MA RIA\Desktop\CFScript.txt
AV: ESET Smart Security 6.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 6.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\regid.1986-12.com.adobe
c:\programdata\regid.1986-12.com.adobe\regid.1986-12.com.adobe_Illustrator-CS6-Win-GM.swidtag
c:\programdata\regid.1986-12.com.adobe\regid.1986-12.com.adobe_Photoshop-CS6-Win-GM.swidtag
c:\users\MA RIA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
c:\users\MA RIA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1\Local Store\#ApplicationUpdater\state.xml
c:\users\MA RIA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1\Local Store\#SharedObjects\s_br.sol
c:\users\MA RIA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1\Local Store\appDB.db
c:\users\MA RIA\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1\Local Store\chc-pref.xml
c:\users\MA RIA\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
.
.
((((((((((((((((((((((((( Files Created from 2013-05-23 to 2013-06-23 )))))))))))))))))))))))))))))))
.
.
2013-06-23 04:35 . 2013-06-23 04:35 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-06-23 04:35 . 2013-06-23 04:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-06-21 10:16 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0F270FCA-46E0-4F92-AAEF-1E921D16D668}\mpengine.dll
2013-06-18 20:01 . 2013-06-18 20:01 -------- d-----w- c:\program files (x86)\MCShield
2013-06-16 09:18 . 2013-06-08 12:28 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-06-16 09:18 . 2013-06-08 11:13 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb
2013-06-16 09:18 . 2013-06-08 14:08 279040 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2013-06-16 09:18 . 2013-06-08 11:41 218112 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll
2013-06-16 09:18 . 2013-06-08 14:08 1365504 ----a-w- c:\windows\system32\urlmon.dll
2013-06-16 09:18 . 2013-06-08 14:06 2648064 ----a-w- c:\windows\system32\iertutil.dll
2013-06-16 09:17 . 2013-06-08 14:06 526336 ----a-w- c:\windows\system32\ieui.dll
2013-06-16 09:17 . 2013-06-08 14:06 15404544 ----a-w- c:\windows\system32\ieframe.dll
2013-06-16 09:17 . 2013-06-08 14:07 19233792 ----a-w- c:\windows\system32\mshtml.dll
2013-06-12 13:05 . 2013-06-12 13:05 -------- d-----w- c:\users\MA RIA\AppData\Roaming\NVIDIA
2013-05-26 14:57 . 2013-05-26 14:57 1409 ----a-w- c:\windows\QTFont.for
2013-05-26 14:55 . 2013-05-26 14:55 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-05-26 14:47 . 2013-05-26 14:47 -------- d-----w- c:\users\MA RIA\AppData\Local\Secunia PSI
2013-05-26 14:47 . 2013-05-26 14:47 -------- d-----w- c:\program files (x86)\Secunia
2013-05-26 14:10 . 2013-05-26 14:24 -------- d-----w- c:\programdata\Package Cache
2013-05-26 14:00 . 2013-05-26 14:00 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
2013-05-24 17:45 . 2013-05-24 17:54 -------- d-----w- c:\program files (x86)\Realtek
2013-05-24 17:25 . 2013-05-24 17:25 -------- d-----w- c:\programdata\Intel
2013-05-24 17:23 . 2013-05-24 17:23 -------- d--h--w- c:\windows\system32\WLANProfiles
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 13:18 . 2012-02-17 13:02 75825640 ----a-w- c:\windows\system32\MRT.exe
2013-05-26 14:54 . 2012-11-15 18:56 866720 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-05-26 14:54 . 2012-11-15 18:56 788896 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-05-11 10:08 . 2010-06-24 17:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-01 23:06 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-05-01 00:59 . 2013-05-01 00:59 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2013-05-01 00:59 . 2013-05-01 00:59 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2013-04-18 13:55 . 2013-04-18 13:55 18456 ----a-w- c:\windows\system32\drivers\psi_mf_amd64.sys
2013-04-13 05:49 . 2013-05-15 13:50 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-15 13:50 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-15 13:50 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-15 13:50 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-15 13:50 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-15 13:50 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-04-12 14:45 . 2013-04-24 12:18 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-10 06:01 . 2013-05-15 13:50 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 06:01 . 2013-05-15 13:50 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 03:30 . 2013-05-15 13:49 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-04-04 11:50 . 2012-02-17 14:43 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-06 04:06 . 2012-06-06 04:06 2174976 ----a-w- c:\program files (x86)\Common Files\atimpenc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MCShield Monitor"="c:\program files (x86)\MCShield\mcshieldrtm.exe" [2013-04-04 607744]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-04-30 885760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R1 fxbiojph;fxbiojph;c:\windows\system32\drivers\fxbiojph.sys;c:\windows\SYSNATIVE\drivers\fxbiojph.sys
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys
R3 BthMtpEnum;Bluetooth MTP Device Enumerator;c:\windows\system32\DRIVERS\BthMtpEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthMtpEnum.sys
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys;c:\windows\SYSNATIVE\drivers\Impcd.sys
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\drivers\nvstusb.sys;c:\windows\SYSNATIVE\drivers\nvstusb.sys
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys;c:\windows\SYSNATIVE\Drivers\pcouffin.sys
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf_amd64.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf_amd64.sys
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys
R3 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys;c:\windows\SYSNATIVE\DRIVERS\stdcfltn.sys
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys
S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvkflt.sys
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe
S2 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe;c:\program files (x86)\Secunia\PSI\sua.exe
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys;c:\windows\SYSNATIVE\DRIVERS\Accelern.sys
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys
S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys;c:\windows\SYSNATIVE\drivers\btmaud.sys
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys
S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys;c:\windows\SYSNATIVE\DRIVERS\qicflt.sys
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-06-20 16:19 1165776 ----a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-28 15:35]
.
2013-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA1ce48d96f4bb08f.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-28 15:35]
.
2013-06-22 c:\windows\Tasks\HP Photo Creations Messager.job
- c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11]
.
2013-06-22 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task bf64327c-6b9e-43e4-b2d0-cf288408c881.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\MA RIA\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-18 6611048]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-05 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-05 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-05 416024]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2012-12-21 6326448]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshellex.dll" [2012-12-03 11733888]
"BLEServicesCtrl"="c:\program files (x86)\Intel\Bluetooth\BleServicesCtrl.exe" [2012-09-17 184112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = proxy.unic.ac.cy:8080
uInternet Settings,ProxyOverride = *.local;<local>
IE: Send to Bluetooth - c:\program files (x86)\Intel\Bluetooth\btSendToObject.htm
TCP: DhcpNameServer = 192.168.10.254
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\LocalService\Software\Wow6432Node\Adobe Acrobat\9.0]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-06-23 07:50:01
ComboFix-quarantined-files.txt 2013-06-23 04:49
ComboFix2.txt 2013-06-22 19:48
ComboFix3.txt 2013-06-21 10:47
.
Pre-Run: 607.555.629.056 bytes free
Post-Run: 608.949.809.152 bytes free
.
- - End Of File - - 99530F3C732F6DA602C6B557FE908F92
D41D8CD98F00B204E9800998ECF8427E
OK Corrine, I have some news:
1. I installed Adobe Flash Player 11.
2. I disable Java from IE and Chrome. YES!
3. There is an update of Sumatra, version 2.3.2, which SOLVED the problem with formated images in Word!
4. I am waiting for your reply, to solve the other issues.
4. ... I love you! :flowers:
:dance:
What are the remaining issues?
Quote from: Corrine on June 23, 2013, 01:22:53 PM
:dance:
What are the remaining issues?
Well, did Combofix finish the job? Is now the computer free of all those error events etc? :smiley:
Hi, Panos.
From what I can tell, it appears that we've covered everything, although there is one more tool I'd like to run. In the meantime, we can clean up the other tools that we used.
1. You can delete the following from your desktop: Farbar Service Scanner and SecurityCheck.
2. Please do the following to implement cleanup procedures and also to reset System Restore points:
Click Start > Run and copy/paste the following bold text into the Run box and click OK:
ComboFix /Uninstall Note: In the event you wish to contribute to the ongoing development of ComboFix, the developer is accepting donations via PayPal (https://www.paypal.com/cgi-bin/webscr?cmd=_donations&business=combofix%40live%2ecom&item_name=ComboFix&no_shipping=0&no_note=1&tax=0¤cy_code=USD&bn=PP%2dDonationsBF&charset=UTF%2d8).
3. Please download
AdwCleaner (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner) by Xplode to your Desktop.
- Double-click AdwCleaner.exe to run the tool.
- Click Delete.
- Everything that was found will be deleted.
- Save any open files and approve the reboot. A text file will open after the restart.
- Please post the contents of that logfile with your next reply.
Note: The log can also be found at C:\AdwCleaner[XX].txt where XX denotes the number of times the application has been run, i.e., S1
# AdwCleaner v2.303 - Logfile created 06/23/2013 at 21:56:26
# Updated 08/06/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : MA RIA - DR-M
# Boot Mode : Normal
# Running from : C:\Users\MA RIA\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\END
File Deleted : C:\user.js
Folder Deleted : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\Wondershare
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
Folder Deleted : C:\ProgramData\ParetoLogic
Folder Deleted : C:\ProgramData\Wondershare
Folder Deleted : C:\Users\MA RIA\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\MA RIA\AppData\LocalLow\PriceGong
***** [Registry] *****
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YourFileDownloader
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\Software\YourFileDownloader
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
***** [Internet Browsers] *****
-\\ Internet Explorer v10.0.9200.16611
[OK] Registry is clean.
-\\ Google Chrome v27.0.1453.116
File : C:\Users\MA RIA\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[S1].txt - [2636 octets] - [23/06/2013 21:56:26]
########## EOF - C:\AdwCleaner[S1].txt - [2696 octets] ##########
Excellent! Now I think I know where those files came from that came up in the ComboFix log.
Let's run one final tool that I've noticed will sometimes find additional files that AdwCleaner doesn't see.
Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/dl/131/) to your desktop.
- Disable ESET and Emsisoft to avoid potential conflicts.
- Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select "Run as Administrator".
- The tool will open and start scanning your system.
- Please be patient as this can take a while to complete depending on your system's specifications.
- On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
- Post the contents of JRT.txt into your next message.
Hi, Corrine. Here is the log:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by MA RIA on ‰¬¨ 23/06/2013 at 22:53:51,66
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{01CB1C89-4FDD-4F61-8339-5B5A48927CAB}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{029023AD-65B6-44BF-967A-4C431C14AAB7}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{02F2690F-7A5C-46E0-87C1-EEFCAEC7FC04}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{031D5677-05B6-451B-B69E-87108C70CC3E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{03766248-B4CB-4D4A-ACA0-1C173526AC4D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{0469A0DD-D389-4CE6-AAF8-E0D65C6F7D76}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{04B04090-481D-4B64-9F1A-F54C5BB60B89}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{050D0EB2-3D6B-4752-889B-06BF7B4E53A0}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{055139F1-DF0A-4061-985B-8750D6D1B96D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{057A2028-C7B1-490F-A461-58AA7A631D72}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{0587B723-B91B-48AD-9A15-E2C65E7DFAEC}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{05C071C0-DB2E-4B5C-9DCD-66E9640DF977}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{05D69201-55E6-459B-8C7B-5ACFE5D0370A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{07B1CAE1-0B02-49D0-B839-64D7F6FE9B14}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{08CC942C-341E-4D06-9A54-333279644918}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{09908CCE-791C-4A83-AE01-80D0217BD26C}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{0A27A451-FA0B-49C8-91DE-7980B614F9A9}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{0AEF47D4-4E60-4018-8148-A87C4690046E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{0B2B4084-00A9-418A-B22F-AF4BA9775EFD}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{0BADEFA9-2606-4EC2-BD5F-B4337E40A9C2}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{0C18975D-468B-4EED-B203-D7DF5B155473}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{0E016916-63AF-4563-9D33-3F96BA4A03B0}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{0FDB72B7-BF5B-4A4D-98BC-DE50AA0B79A5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{10899CAF-370B-47DB-8885-AFD08FB294B2}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{12F852BD-6846-41CD-851F-3BE07C5CD992}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{12FCFE00-7B18-42C4-B04A-D1BC8BB7763F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{130316EF-06B9-4481-8B35-579ABB70B396}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{130EBE63-6757-4F81-9BF0-D4DD47B9DD35}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{149BB3AB-C06A-4CAD-9314-2BD3516255C8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{161112FF-EAFF-4D29-842A-8F54B0517265}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{17DF1DFB-BC88-40E4-92D8-63DF9C45C16B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{191B355F-83F6-486B-B389-9E58EF2E4DDA}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{1A178E57-52C7-4C3F-944F-3A0B562C9D12}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{1B429360-F34F-4D12-BEE8-E59A0B39FDA4}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{1BD45D52-C4AA-4754-88CE-6FD7E491FFA5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{1D59A4E9-5D7B-4E7F-BB81-10F86C6914CA}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{1D867FDF-7DDC-418E-A6AA-6D4CA6BD9E28}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{1E7A2AE5-907E-4A33-8D69-E8F1CF86304B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{1EAE4EED-ACC4-4C40-AAA4-D85DD549650E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{1ECAE951-A00E-4D50-BC42-C848AE3ACBBB}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{1F4E2673-B011-4A8B-A715-D0A5306EA96F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{20D8857B-3B3B-4778-AF97-AA6C5CC66227}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{22F2E789-53EB-46C0-A6BB-1D36FA98775E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{23B92E2C-68A4-4566-8CC7-88E3BE4A4E8B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{244C6310-7FA4-4A70-BFC1-8FAD11523E4B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{2498462A-3BC4-41E3-A6BA-21A9472890FE}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{26204FFA-1D44-4824-8EB5-CFD0E56CAD8B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{27A62AB0-0946-4B94-A9C2-21F6AEC5EA15}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{2825F506-28A3-4267-8CA0-3527065AB98F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{2845E306-BFF9-410E-B75A-837503C286E8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{28590F8F-F873-4C69-A239-5D60345D06B1}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{28F0850B-DA36-4C0C-8DB5-D54839144F1E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{2A5F9270-2B91-4743-B659-EE70EC35CA1A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{2A7CA0E8-C52F-49CF-9932-3A7961E68CC5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{2AC2CFF5-2F09-4A9E-B855-240566BD2B45}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{2AFE8E88-10DF-4678-88E2-B2243772D6B7}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{2C2F9ED1-83B0-49BC-B2D0-AB3582692486}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{2CE05572-17B1-449D-A335-3FDB468623CE}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{2D1CD4F3-7C98-4B9C-A34B-16D8883BF792}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{2DC74577-AC81-45DC-A93D-5E45C140D84D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{30DFFD42-8226-4D29-BE56-57BA9C81C095}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{30F909BD-F106-41C0-9870-18FEB81D8CE7}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{31A65EDC-B897-45A5-ADD3-0EB7FED294E0}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{34C13C3B-7097-4DC4-A26D-B158CDA8B7AE}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{353956B8-880C-49C4-8691-72FC2E5C764B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{357C5812-0DC0-4F6E-96FE-37DA8442FB08}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{357D212E-6175-4BBC-86B7-5CFB7DCF358F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{35CA8507-05F3-4EC5-9FC6-02F500B8DB61}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{36E66D92-058B-40E2-BABF-4C9ACDFCD3D9}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{373D0326-5020-475B-AC2B-B6396EDEAD40}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{3752D099-FBD9-4C1B-98AF-098274839530}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{3A16A468-9C57-41A7-A0D5-43E33DFF7D77}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{3BA19D55-A2CD-4F7E-8010-3903860903A2}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{3BAF9655-E588-470F-96E8-719938B635C1}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{3C68567F-A611-4AF0-82B3-672DD8E32EFF}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{3D02586C-BF23-430F-A43B-7E360DC0A6AB}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{3E36E44A-9D6F-4ADF-995D-F6E876C019A1}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{3F691B6F-EB1E-4E0B-B419-FB5F9FFC95D5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{4166DDCF-DEF8-44C7-8A46-751831EC3BF9}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{41EA56AA-2BC1-48AB-953F-D31B6B810C1C}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{42F25462-66BC-4278-8C30-33CC231461A5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{44931FF6-FAEF-4252-8CF6-5B42EC9215D5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{44B71110-3513-4C80-8E23-24CD4CAE6FC0}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{454263BF-6FB8-42BF-937A-C84042937065}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{46B896B4-B0A5-496B-9CB4-23B8F02D6BF8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{4742FF73-70FC-4780-87C1-140770BCFCFD}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{4B4CF9F4-7AD2-4659-9D96-3C419F095003}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{4B6C5160-F460-4F7B-ACF8-5AD5DE17DA36}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{4C08F015-9D46-43A7-B70B-9A0977647278}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{4DB0C53C-A3AB-4226-989D-4D8C45C1332E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{4E0D6513-9368-43B6-ABF9-595CF3CFEEF3}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{4E7A5F32-6803-4E5C-9FEB-D97D82706581}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{4E7E0B68-E008-417F-AF0F-0F8AD88FA72A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{4F8FCD94-A608-4DE5-A757-B62EB8F0BFDE}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{4FBE4364-99DD-44F5-8EFC-327523064897}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{501C039F-83B3-4450-B035-A4A370A18E39}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{5097032A-153E-4189-9E64-B10DAF8DFCB8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{5100DF4D-0D5C-48C7-8B31-566CB3FE7811}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{511462C2-D87F-45D6-80A8-E306C1800984}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{52CE1063-2C96-4BC7-8D79-DB42FF1277E8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{53F4BA9A-9B15-4DAE-A51F-9BA83049C932}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{545D78C6-552D-432F-80F5-E1FB516E66EE}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{55860643-6EE0-4A3B-8CD2-495A89E199C3}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{55EBFB37-2FD0-4A69-8178-F657A852A261}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{568A8EB5-DED4-4FAD-B4E9-6C9C45B6D30B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{5A150E99-BC55-43CF-A35C-C0822FDA04E5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{5B2B14A4-E20E-4B0D-9874-CB3AE3F266F8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{5B5E3275-4C71-49E5-986C-3DB19E5214DD}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{5DD341B1-8D3F-4897-B5BF-92F4871EB186}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{5E1FBB4D-304C-4AEE-A697-FEBBA10E2298}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{5E2AC6FD-D8E6-4214-AC5C-A0C956367373}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{5F52D872-EFE0-49FD-B05F-6F941E9C4A41}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{5FCFC965-5E00-49E6-A74A-28E95E4CBEE1}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{6092A99C-C22C-44CF-994E-031C505B5C56}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{62F8576D-3872-49D7-9242-F238EF1E8BCF}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{63BBAFCC-DA59-4291-AC09-FDBDF0336A58}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{644FA70C-58B3-44CF-9C5B-18A63EEBF48B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{6579746A-E84A-4005-89B0-B16360E7D4EF}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{66FF0431-F40F-4329-BCE5-F70552711467}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{68BD3E7C-F592-4BFD-9EBE-A40D6F975E9C}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{68F33DD9-A53B-4165-A25C-2C13D396EFC2}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{6A91A946-6CEB-4122-8DA4-DB98C0D8C4F2}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{6B4CA93B-4A40-49E9-A7EF-EEC1D9BBFB99}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{6B7A7EC7-9797-46DC-9D4C-35EBE50B51B9}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{6C28C51C-98F4-46E1-9A62-5A2A3BA39B4C}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{6CD1BDE3-C0D6-4A05-960C-7FCF08827F4B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{6CFF2DB6-76B2-46D9-8B4E-E3C23CC627EC}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{6E01CF81-AAC8-4E74-BEE9-AFFD3A0D9D7F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{6E2450C6-3630-423D-8351-8B621C21A547}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{6FE3B186-5334-47DA-9600-7F01EC0700A1}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{709F7E1B-95C1-466F-A41D-AC52E8939370}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{73041AE1-321B-41A1-A66F-4048506A418A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{75CACC4D-D1C1-4E57-93C1-46516162DAD2}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{7772586A-CB11-4253-BBAA-3935B7425DC2}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{7877D538-56C2-489C-8262-B869D9D775A0}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{78BC7052-53BF-4784-AC9D-1E6FC770C42D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{78D65A57-0AB1-4FE1-86B3-1654192A2979}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{78DFB4E1-BB0A-4D46-8955-B02F72C695B3}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{79409984-0F02-471B-B0AC-C6D2C5D8D38B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{79AAC9EA-AF7C-480D-804B-3CCC890905B5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{7C9DEECE-FCE8-41A5-AC07-FF16E9647531}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{7CCA16B6-DB52-4322-8901-2B3B0F257D81}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{7E22BD62-945A-45D7-99FD-34AF5A5A5880}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{7EE35A3E-99F6-4FBE-9744-8F4E55A6267B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{7F91E932-E675-4382-A685-B8AB76DA00C6}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{8038CF2F-3449-4FA3-8899-297E1150AE0C}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{808EA86E-54A4-40D7-AFF2-2D6CDBDBE458}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{80A72B9B-CF20-43F7-8628-45201EFE866F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{81032D3A-8AF8-4FDC-8454-81DFA2692B69}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{814DCA88-0991-44C2-B022-0BCF0AC3C07D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{817EF532-0D0A-4274-8F69-3F57A7B6F27E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{81F8EF08-2F50-42A3-AECC-CF01BE0F5D5E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{84AE6C97-3BC7-4B42-9D98-56D1CD3C4A6F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{85155AB6-AF75-4BB0-AA9B-477CEB571F17}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{8557F157-2DB5-4E5F-A5E3-1F552362E291}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{85AC72DC-3BDA-4813-A1D4-3A60BB578175}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{8693721F-BE6A-476A-9E36-588E637A8B2A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{87965383-A85B-4F68-9985-8F6AEC82134D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{884D8783-2079-44CB-84C2-5556D3664019}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{8898784E-4C84-4441-A584-E6767F36F5D3}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{889E9853-08C6-431F-A7E1-C98CE3262A88}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{892B1B11-F680-4574-B256-69E2F261134A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{89823114-9D6A-49CE-B69C-44ED07826DEC}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{89D0AFE7-2B74-4D2E-B724-5692F4E40C7F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{89E056C9-81E7-45F2-BFF2-1CDCCE38551E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{8B39AFA3-EEA3-488F-BB0B-C86AAE6B2FE2}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{8B3BC930-4D9B-4886-A590-6127BB47B521}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{8B8CB5A1-2019-43BE-9BC0-969333058FB4}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{8BA6E3C6-DC5D-414F-988A-07D6FF61BF72}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{8D670160-E855-4465-A71E-190C7265E12A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{8EAC813B-43FF-4852-ACB6-6ADDE14FC649}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{91759230-AC62-47BA-BC7A-6785448925F5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{91DC3CFA-BE24-4CA8-B720-9F396C17916A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9244BF10-216C-4B46-B3D0-55745F90135D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{930FB3C8-4C82-4253-845F-F15204D77F2E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{93521A19-4F97-4129-99D8-F53802B84A7D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{935B6606-3681-476A-A4A6-7AD7B76DD7AD}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{93B8F613-1C2D-46CA-AB15-854D0DCE43F8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{94721367-E6C1-471E-B210-0DAB88DB3703}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{94AF3A4A-B77D-404E-B66C-BAC819BBB0FE}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{96BB97D8-0BF0-4F62-834E-621055C26879}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{97BCD0BE-CEF0-443E-A974-1E6506894E17}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{988137DD-4691-4AD3-A89E-0C66DC91BDB5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{98F51261-9CAE-4170-B999-DB90CF8E5F95}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{99058CC0-33A5-4874-896C-E8D58BA46898}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9ACBF113-09EF-4952-BC3D-B1670E8485C9}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9B55203B-D45C-4778-BFA3-0DD1FED9FFE4}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9B5D8204-8B91-4D52-9F42-85F89EECF7F4}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9C0429C0-42EB-478E-B693-DFE7106A7F18}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9CB6607A-474B-40EE-A3E6-E7E5D24D83D5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9D587B71-4A65-4517-BDCE-54D16E37E420}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9D6933E6-6286-474D-A685-D204EB527F92}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9DB0024F-8F87-417F-BA9E-1D4AC5F72077}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9DF12EDF-65D7-4976-8991-8ACDDE7FCC75}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9EF72B7C-2B17-45C7-9553-ACB2B39174AE}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{9F862332-5636-4640-9593-7FEB305254D9}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A16CC561-EF3E-43D7-B168-259ED4DFE2A0}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A19F6F5C-C590-4493-8294-87DC1F4027C7}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A1EF0CD6-141E-40B4-899A-1F7266880FF3}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A224C0B8-A7D9-4956-B79B-B24246069204}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A23A0442-211E-4B98-BFE6-6F8E40EC926C}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A242CDC8-2AC2-41DD-87C8-DAD377065A29}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A3250A47-4635-42B5-9500-2A8A093A5B78}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A3F37258-4480-4F04-917B-F90065B60E46}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A41CD61C-0A99-4CAA-81B0-90A7EFB288A7}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A475354F-A618-4A13-8149-49DC84BE28C5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A6A61665-4A89-4483-BE76-0EBA6DD22FDE}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A8F86FC2-9769-4D89-93B5-E871E7526ADD}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{A920E76D-3488-477E-BEE7-961E1EDE24CE}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{AAC3A253-DD48-4DB5-B100-5CE2EB80044E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{AB93D39B-8D03-415E-BD8E-CDA079CF3404}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{ABB4211E-0020-4FC7-A2B3-1F3EC552A48D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{ABE129C2-A46B-42BC-9B21-3B94C2678318}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{AC1A40A6-B968-4E97-BF95-C2E4F772A1A8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{AE850079-551F-463C-B705-B537DB040832}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{B2936296-880A-4708-ADDD-76A47C197866}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{B2B4C9F3-7398-4C04-8F54-E519D8A90F16}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{B393EB68-EF84-4C6B-8618-80B4DC7083F8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{B3E60D2B-95C0-4CF3-9C3A-3F09E28BD247}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{B4D5F28A-D3AC-4156-8B81-E68B3E86AE09}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{B5035979-295C-4A14-AB21-0AE2BECCA30E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{B57B6C92-199F-4114-ACFB-52B20BA30719}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{B80F5DC5-65FB-43CB-BB7E-885919F3AF3D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{B95A4B7E-1A8A-486E-9C57-E9650A476E81}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{B96BB0DF-485E-436E-9495-88B0DBF6BA5A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{B9B2E820-F9BC-4F9A-A685-D0A61EA9B9C6}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{BA1C7E3B-57D6-4CB4-8A99-B9B1E5D18E2F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{BA43E78D-7725-4ABD-8DC4-62D6DF5800DB}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{BACD6180-8B96-4841-83F5-636EA5A4FD3A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{BB9CF8DB-2361-4C70-96FB-971F149DA6BB}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{BBCB44FC-8D45-445D-824F-025DF36B954D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{BC43A311-D4C2-447E-871C-F61EA569CB42}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{BDC93E6A-46E2-4562-94A4-2A9DD699DB3C}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{BDDE0807-88A4-4B9D-B6A2-991366F16EE1}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{BEF2A71D-4E6A-4F17-A70E-4E5D55B8019A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{BF78D8D3-504C-4C9F-AE8B-70B8AF289721}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{BF828F33-3470-4C8A-B659-659732EFDE9A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C0B5C11F-748B-44AB-8913-861313E8D0CF}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C0EC541F-8077-49F2-A1C3-271986B5F8D3}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C0F44CBC-64DB-4217-AA6F-A9482346AD9F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C17531D6-DDA0-4283-9A97-7721EEF4E8CF}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C1B80DED-CA65-4483-8B48-51BD60981DE8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C3DFCF0A-82E6-4DE9-B280-7BC9731EF78F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C3F06F25-6083-4089-B87E-146BB70EC7E8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C4860DD1-E7B0-4856-ABA1-C5B0D12997B0}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C56E9667-782C-4C95-BDF1-152F82906B3A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C5BF2FA0-5285-487D-A918-FCF837EBF532}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C5D7F136-7559-435A-A1D7-AD960E08B8B2}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C5F9F61C-2281-4BC7-8F0F-46973663A9D2}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C609CF29-F0A8-448D-8AA3-167ED5F945CA}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C6A66F36-5BD0-4F00-ABD3-802B57DC3C5B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C71272B2-98C3-4884-8C10-59CB4B78F6A4}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C7BDB769-F230-44D7-867A-F0827BC91FD6}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C7CF7B39-2BCA-4996-A0DF-9BD323C68C92}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C837F161-D2CA-4260-A638-AEF5FEA59AC0}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{C86A6B7C-4D00-4096-9B11-6E342C1406D5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{CAEB4343-8041-4061-9F3E-EB026514DE59}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{CCA74979-A739-44BF-BD01-46FB7F87674A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{CD68F98E-B2C9-449A-92B5-E9A94386A6B6}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{CEBAFC8C-B8D8-4816-9F66-B29A037139DB}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D0C510C5-8A51-4344-9B54-52DF1EE90B04}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D207431E-1E34-4D9E-93C1-5E598A9006A7}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D3C867C4-D420-4413-8CF7-6EFCE2FA9D82}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D4AFCEB0-B4B0-432B-915A-F14AA8648927}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D6F2EE81-0316-47E0-AE6B-21C9702A5844}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D6F3A19D-B480-47E0-941D-79AAB2ACF888}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D7348155-67C3-42F4-AC3E-6455900987CC}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D7B90C11-0346-4452-8EDA-B8025F323C8B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D82F8710-0074-4040-BCD3-C767A570CBA8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D88FDD13-E4ED-460B-8A49-78A7DA455721}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D8F63422-DFE6-46DD-A04F-0BEF946479AF}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{D9FE8FF9-96DF-460F-9033-4FD19F5E9216}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{DC6B996E-8A53-48DD-8A1C-5C793727D1CA}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{DDDB01AC-ACB1-44FF-A9AE-14753A7C2BEA}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{DE351A5D-8AE2-4125-B2CB-C41663A98766}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{DEBB9BA6-233D-45C9-8B9C-D3792A133E6F}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{DF47AE11-4C3B-41DD-8B4A-864E310E645C}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{E141CE55-5D1D-43C7-8863-AE0491BC515D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{E17B9A54-1F68-41E1-801D-DF3E48D32C73}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{E20C4235-1507-483B-A920-605A45B29B24}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{E2161BCD-7AA0-47B5-B5DD-E0DE54E432EC}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{E5614854-8471-4034-8082-032093B30641}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{E63BE6DC-042D-4813-9A6C-37CEABCD0D3B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{E63E2901-787E-4D2B-B5E3-D5D7D867F618}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{E80CC1D3-0409-4F55-A9AA-751A343621EF}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{E846948F-496D-45FB-9E9C-689F4B63ACBA}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{E8F1DE8A-261C-41F3-A831-110729566358}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{E915D293-6D46-43C8-8E98-5976B3D6060D}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{EBE3A8C7-6564-4FF2-9DD6-8B3BE4F604DF}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{EC48E4AD-43C4-4733-B37C-5087C37D53AB}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{ED3438DF-92BA-4888-BF31-0C8FB1484B8B}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{EECD9B93-57C3-4696-83C7-EA71C1A6CDFC}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{EEFE65B7-78A9-4363-BFC8-7D066EA909AC}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{EF2A619B-4CC5-4A3C-B106-62FEB0B59015}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{F0A5CB09-EF81-441B-A00C-AC7AB8108359}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{F6195438-D0BE-488B-A092-F56103119445}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{F759768E-EC7F-47FF-9B8C-35BB93C2509E}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{F76838EA-A1BE-4B14-9C65-9BE6CDAC9455}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{F779DD87-DD76-41C0-B187-4810649FA836}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{F8029F98-1FAF-41DD-BB0E-81A917FAA6BC}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{F86EF589-3286-40BF-9F96-0087D74840AC}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{F8FD66D7-EFAD-4004-BBCD-D8C63E67E2C5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{FA437060-B5A0-48C7-9787-92BCB2DA3DC5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{FAA31AE1-5812-41E8-89AD-DC9CC1D0A0E5}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{FC76D89E-3454-4B15-8B3C-CE605CB6B46A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{FD34AA0F-E307-4155-999B-FA8744349A1A}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{FD5DE40D-0975-434E-A2EE-5DE0EF936CCF}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{FE8CA3D2-1140-449B-B495-81AD217D02D8}
Successfully deleted: [Empty Folder] C:\Users\MA RIA\appdata\local\{FF593722-D5EB-4FA8-9698-1EDBE50A649C}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ‰¬¨ 23/06/2013 at 22:58:48,67
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fantastic! You can delete Junkware Removal Tool from your desktop and do the following to uninstall AdwCleaner. (Yes, both are great tools but they do have updates so no sense keeping an old copy around.)
Please do the following to uninstall AdwCleaner.
- Double-click AdwCleaner.exe to run the tool.
- Click Uninstall
- Confirm with yes
Even though you've heard my "words of wisdom" ;) in the past, feel free to refer to the Safe Computing Practices and other recommendations in this updated copy of "So how did I get infected in the first place?" (http://securitygarden.blogspot.com/p/blog-page.html).