LandzDown Forum

Security => Analysis and Malware Removal => Topic started by: DR M on December 11, 2014, 08:27:22 PM

Title: Something is wrong!
Post by: DR M on December 11, 2014, 08:27:22 PM
Hi, again. I am afraid that you will waste your time with me once more...

I don't know what's going on. My computer seems to be ok, but there are some things that make me suspect that it got infected. I don't know how.

All started a month (I think) ago, when suddenly Viber stopped working, saying that a problem occured, Windows are trying to find a solution, but I had to close the program to continue working. Meanwhile, Windows Media Player stopped ripping my cds, and VLC stopped convert my video and video files.  When the problem started, I ran Adware Cleaner two or three  but the computer was clean. Yesterday, I found the Viber error report, warning about an error 0xc000005 error, access violation, some strange numbers about memory. I found very strange the fact that the report identified my system as Windows Vista! I uninstalled and reinstalled Viber, and also ran ccleaner. Same results.

Today, I ran again Adware Cleaner and JRT. This time, Adware Cleaner was found some infected registry entries. I decided to ask for help here, and ran DDS and Security Check. The last one didn't run, and warned:   UNSUPPORTED OPERATING SYSTEM! ABORTED!



So, I post DDS logs (as well as Adware Cleaner's log), and please tell me if you see something bad...

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17420  BrowserJavaVersion: 11.25.2
Run by DR WHO at 21:57:57 on 2014-12-11
Microsoft Windows 7 Home Premium   6.1.7601.1.1253.30.1033.18.6038.4020 [GMT 2:00]
.
AV: ESET Smart Security 8.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: ESET Smart Security 8.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personal firewall *Enabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
C:\Windows\System32\ctfmon.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files (x86)\MCShield\MCShieldRTM.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\CCleaner\CCleaner64.exe
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Bar = Preserve
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [MCShield Monitor] C:\Program Files (x86)\MCShield\mcshieldrtm.exe
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
uRun: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
uRun: [Viber] "C:\Users\DR WHO\AppData\Local\Viber\Viber.exe" StartMinimized
mRun: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.13.0.cab
TCP: NameServer = 192.168.10.254
TCP: Interfaces\{8D8A0C0D-EE47-4E27-A869-06980DCA98B5} : DHCPNameServer = 192.168.10.254
TCP: Interfaces\{F8010453-43D6-4BBC-9F0C-01DE21D23D1C} : DHCPNameServer = 192.168.10.254
TCP: Interfaces\{F8010453-43D6-4BBC-9F0C-01DE21D23D1C}\34954514244433531433 : DHCPNameServer = 192.168.10.254
TCP: Interfaces\{F8010453-43D6-4BBC-9F0C-01DE21D23D1C}\4505D2C494E4B4F5562776163747962796F6 : DHCPNameServer = 192.168.10.254
TCP: Interfaces\{F8010453-43D6-4BBC-9F0C-01DE21D23D1C}\751697E6563734F666665656 : DHCPNameServer = 195.14.130.170 195.14.130.220
TCP: Interfaces\{F8010453-43D6-4BBC-9F0C-01DE21D23D1C}\94E44554C4C494E45445F51405 : DHCPNameServer = 192.168.10.254
TCP: Interfaces\{F8010453-43D6-4BBC-9F0C-01DE21D23D1C}\C696E6B6379737 : DHCPNameServer = 192.168.10.254
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= C:\Windows\SysWOW64\nvinit.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
x64-Run: [BLEServicesCtrl] C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
x64-Run: [New Value #1] ctfmon = CTFMON.EXE
x64-Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 epfwwfp;epfwwfp;C:\Windows\System32\drivers\epfwwfp.sys [2014-9-18 63160]
R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2013-12-18 32544]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-12-14 55856]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2011-12-14 21616]
R1 A2DDA;A2 Direct Disk Access Support Driver;C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [2013-7-8 26176]
R1 a2injectiondriver;a2injectiondriver;C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [2013-7-8 44688]
R1 a2util;a-squared Malware-IDS utility driver;C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [2013-7-8 17384]
R1 eamonm;eamonm;C:\Windows\System32\drivers\eamonm.sys [2014-8-18 243440]
R1 EpfwLWF;Epfw NDIS LightWeight Filter;C:\Windows\System32\drivers\EpfwLWF.sys [2014-8-18 44632]
R1 nvkflt;nvkflt;C:\Windows\System32\drivers\nvkflt.sys [2013-12-18 300320]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2014-7-23 172344]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-12-14 98208]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2013-2-13 770528]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-12-13 1120784]
R2 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2012-12-3 1361856]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-12-3 1148864]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-9-12 135984]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2014-10-1 1349576]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-10-14 1871160]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-10-14 969016]
R2 TeamViewer9;TeamViewer 9;C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-7-29 4799760]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2010-11-29 16120]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-12-14 2656280]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2013-2-8 3386608]
R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Accelern.sys [2011-12-14 27760]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2013-2-13 163808]
R3 btmaudio;Intel Bluetooth Audio Service;C:\Windows\System32\drivers\btmaud.sys [2012-10-22 87424]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2012-10-30 131968]
R3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2012-12-3 1342848]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2011-12-14 176096]
R3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2012-8-6 68136]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-12-14 317440]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2014-10-14 25816]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2014-10-14 129752]
R3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2014-10-14 63704]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-12-14 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-12-14 181760]
R3 qicflt;upper Device Filter Driver;C:\Windows\System32\drivers\qicflt.sys [2011-12-14 29288]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-12-14 428136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-4-3 315008]
S3 a2acc;a2acc;C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys [2013-7-8 70960]
S3 a2AntiMalware;Emsisoft Anti-Malware 7.0 - Service;C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [2013-7-8 4159464]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;C:\Windows\System32\drivers\AmpPal.sys [2013-2-13 163808]
S3 BthMtpEnum;Bluetooth MTP Device Enumerator;C:\Windows\System32\drivers\BthMtpEnum.sys [2009-7-14 64512]
S3 cleanhlp;cleanhlp;C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [2013-7-8 57024]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2013-11-12 57840]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2014-3-31 1512640]
S3 hitmanpro37;HitmanPro 3.7 Support Driver;C:\Windows\System32\drivers\hitmanpro37.sys [2014-3-25 32512]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-11-13 114688]
S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-12-14 158976]
S3 JMCR;JMCR;C:\Windows\System32\drivers\jmcr.sys [2011-12-14 174168]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2013-2-8 273136]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\Windows\System32\drivers\nvstusb.sys [2011-12-14 121960]
S3 PSI;PSI;C:\Windows\System32\drivers\psi_mf_amd64.sys [2013-4-18 18456]
S3 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2013-4-18 1227800]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2014-7-28 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-2-17 1255736]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys [2014-4-15 29288]
S4 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2013-4-18 659992]
S4 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-12-14 1692480]
.
=============== File Associations ===============
.
FileExt: .js: Applications\notepad.exe=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2014-12-11 19:15:46   --------   d-----w-   C:\AdwCleaner
2014-12-10 20:00:59   --------   d-----w-   C:\Users\DR WHO\AppData\Roaming\ViberPC
2014-12-10 19:59:05   --------   d-----w-   C:\Users\DR WHO\AppData\Local\Viber
2014-12-09 12:36:06   11632448   ----a-w-   C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1A499917-3D37-43C1-A0E2-04205A0344D9}\mpengine.dll
2014-11-26 19:32:16   --------   d-----w-   C:\Program Files (x86)\Syncios
2014-11-25 12:31:52   --------   d-----w-   C:\Users\DR WHO\AppData\Roaming\EurekaLab s.a.s
2014-11-19 12:03:49   728064   ----a-w-   C:\Windows\System32\kerberos.dll
2014-11-19 12:03:49   550912   ----a-w-   C:\Windows\SysWow64\kerberos.dll
2014-11-19 12:03:49   241152   ----a-w-   C:\Windows\System32\pku2u.dll
2014-11-19 12:03:49   186880   ----a-w-   C:\Windows\SysWow64\pku2u.dll
2014-11-17 17:22:09   --------   d-sh--w-   C:\Users\DR WHO\AppData\Local\EmieBrowserModeList
2014-11-13 09:23:51   683520   ----a-w-   C:\Windows\System32\termsrv.dll
2014-11-13 09:23:50   96768   ----a-w-   C:\Windows\SysWow64\sspicli.dll
2014-11-13 09:23:50   681984   ----a-w-   C:\Windows\SysWow64\adtschema.dll
2014-11-13 09:23:50   681984   ----a-w-   C:\Windows\System32\adtschema.dll
2014-11-13 09:23:50   22016   ----a-w-   C:\Windows\SysWow64\secur32.dll
2014-11-13 09:23:50   155064   ----a-w-   C:\Windows\System32\drivers\ksecpkg.sys
2014-11-13 09:23:50   146432   ----a-w-   C:\Windows\SysWow64\msaudite.dll
2014-11-13 09:23:50   146432   ----a-w-   C:\Windows\System32\msaudite.dll
2014-11-13 09:23:50   1460736   ----a-w-   C:\Windows\System32\lsasrv.dll
2014-11-12 21:39:57   77824   ----a-w-   C:\Windows\System32\packager.dll
2014-11-12 21:39:57   67584   ----a-w-   C:\Windows\SysWow64\packager.dll
2014-11-12 21:39:54   3198976   ----a-w-   C:\Windows\System32\win32k.sys
2014-11-12 21:39:45   3241984   ----a-w-   C:\Windows\System32\msi.dll
2014-11-12 21:39:45   2363904   ----a-w-   C:\Windows\SysWow64\msi.dll
2014-11-12 21:39:38   861696   ----a-w-   C:\Windows\System32\oleaut32.dll
2014-11-12 21:39:38   571904   ----a-w-   C:\Windows\SysWow64\oleaut32.dll
.
==================== Find3M  ====================
.
2014-12-11 19:38:41   129752   ----a-w-   C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-12-10 19:18:11   71344   ----a-w-   C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-12-10 19:18:11   701616   ----a-w-   C:\Windows\SysWow64\FlashPlayerApp.exe
2014-11-21 04:14:22   63704   ----a-w-   C:\Windows\System32\drivers\mwac.sys
2014-11-21 04:14:12   93400   ----a-w-   C:\Windows\System32\drivers\mbamchameleon.sys
2014-11-21 04:14:08   25816   ----a-w-   C:\Windows\System32\drivers\mbam.sys
2014-11-06 04:04:03   2724864   ----a-w-   C:\Windows\System32\mshtml.tlb
2014-11-06 04:03:50   4096   ----a-w-   C:\Windows\System32\ieetwcollectorres.dll
2014-11-06 03:47:03   66560   ----a-w-   C:\Windows\System32\iesetup.dll
2014-11-06 03:46:12   580096   ----a-w-   C:\Windows\System32\vbscript.dll
2014-11-06 03:46:12   48640   ----a-w-   C:\Windows\System32\ieetwproxystub.dll
2014-11-06 03:44:28   88064   ----a-w-   C:\Windows\System32\MshtmlDac.dll
2014-11-06 03:30:22   144384   ----a-w-   C:\Windows\System32\ieUnatt.exe
2014-11-06 03:30:08   114688   ----a-w-   C:\Windows\System32\ieetwcollector.exe
2014-11-06 03:29:18   814080   ----a-w-   C:\Windows\System32\jscript9diag.dll
2014-11-06 03:28:20   2724864   ----a-w-   C:\Windows\SysWow64\mshtml.tlb
2014-11-06 03:23:57   6040064   ----a-w-   C:\Windows\System32\jscript9.dll
2014-11-06 03:20:18   968704   ----a-w-   C:\Windows\System32\MsSpellCheckingFacility.exe
2014-11-06 03:13:43   501248   ----a-w-   C:\Windows\SysWow64\vbscript.dll
2014-11-06 03:13:36   62464   ----a-w-   C:\Windows\SysWow64\iesetup.dll
2014-11-06 03:12:44   47616   ----a-w-   C:\Windows\SysWow64\ieetwproxystub.dll
2014-11-06 03:10:58   64000   ----a-w-   C:\Windows\SysWow64\MshtmlDac.dll
2014-11-06 03:07:29   77824   ----a-w-   C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-11-06 02:59:36   115712   ----a-w-   C:\Windows\SysWow64\ieUnatt.exe
2014-11-06 02:58:38   620032   ----a-w-   C:\Windows\SysWow64\jscript9diag.dll
2014-11-06 02:42:36   60416   ----a-w-   C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-11-06 02:39:39   1359360   ----a-w-   C:\Windows\System32\mshtmlmedia.dll
2014-11-06 02:38:25   2124288   ----a-w-   C:\Windows\System32\inetcpl.cpl
2014-11-06 02:21:49   4298240   ----a-w-   C:\Windows\SysWow64\jscript9.dll
2014-11-06 02:21:25   2051072   ----a-w-   C:\Windows\SysWow64\inetcpl.cpl
2014-11-06 02:20:37   1155072   ----a-w-   C:\Windows\SysWow64\mshtmlmedia.dll
2014-11-06 02:17:24   2365440   ----a-w-   C:\Windows\System32\wininet.dll
2014-11-06 01:52:35   1892864   ----a-w-   C:\Windows\SysWow64\wininet.dll
2014-11-05 17:56:54   304640   ----a-w-   C:\Windows\System32\generaltel.dll
2014-11-05 17:56:36   228864   ----a-w-   C:\Windows\System32\aepdu.dll
2014-11-05 17:52:22   424448   ----a-w-   C:\Windows\System32\aeinv.dll
2014-11-04 12:30:58   275080   ------w-   C:\Windows\System32\MpSigStub.exe
2014-10-15 12:34:06   98216   ----a-w-   C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-10-03 02:12:00   500224   ----a-w-   C:\Windows\System32\AUDIOKSE.dll
2014-10-03 02:11:54   284672   ----a-w-   C:\Windows\System32\EncDump.dll
2014-10-03 02:11:51   680960   ----a-w-   C:\Windows\System32\audiosrv.dll
2014-10-03 02:11:51   440832   ----a-w-   C:\Windows\System32\AudioEng.dll
2014-10-03 02:11:51   296448   ----a-w-   C:\Windows\System32\AudioSes.dll
2014-10-03 01:44:42   442880   ----a-w-   C:\Windows\SysWow64\AUDIOKSE.dll
2014-10-03 01:44:26   374784   ----a-w-   C:\Windows\SysWow64\AudioEng.dll
2014-10-03 01:44:26   195584   ----a-w-   C:\Windows\SysWow64\AudioSes.dll
2014-09-25 02:08:38   371712   ----a-w-   C:\Windows\System32\qdvd.dll
2014-09-25 01:40:50   519680   ----a-w-   C:\Windows\SysWow64\qdvd.dll
2014-09-19 09:42:52   210944   ----a-w-   C:\Windows\System32\wdigest.dll
2014-09-19 09:42:51   86528   ----a-w-   C:\Windows\System32\TSpkg.dll
2014-09-19 09:42:49   342016   ----a-w-   C:\Windows\System32\schannel.dll
2014-09-19 09:42:47   314880   ----a-w-   C:\Windows\System32\msv1_0.dll
2014-09-19 09:42:47   309760   ----a-w-   C:\Windows\System32\ncrypt.dll
2014-09-19 09:42:41   22016   ----a-w-   C:\Windows\System32\credssp.dll
2014-09-19 09:23:55   172032   ----a-w-   C:\Windows\SysWow64\wdigest.dll
2014-09-19 09:23:52   65536   ----a-w-   C:\Windows\SysWow64\TSpkg.dll
2014-09-19 09:23:49   248832   ----a-w-   C:\Windows\SysWow64\schannel.dll
2014-09-19 09:23:46   221184   ----a-w-   C:\Windows\SysWow64\ncrypt.dll
2014-09-19 09:23:45   259584   ----a-w-   C:\Windows\SysWow64\msv1_0.dll
2014-09-19 09:23:36   17408   ----a-w-   C:\Windows\SysWow64\credssp.dll
2014-09-18 10:38:22   63160   ----a-w-   C:\Windows\System32\drivers\epfwwfp.sys
2012-06-06 04:06:50   2174976   ----a-w-   C:\Program Files (x86)\Common Files\atimpenc.dll
.
============= FINISH: 21:59:05,17 ===============


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 16/2/2012 2:31:11 μμ
System Uptime: 11/12/2014 9:19:57 μμ (0 hours ago)
.
Motherboard: Dell Inc. |  | 0NJT03
Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz | CPU | 2201/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 679 GiB total, 506,324 GiB free.
D: is CDROM ()
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0048
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0048
Service:
.
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0009
Manufacturer: HP
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0009
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0068
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0068
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0029
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0029
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0049
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0049
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0010
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0010
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0069
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0069
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0030
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0030
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0050
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0050
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0011
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0011
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0070
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0070
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0031
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0031
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0051
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0051
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0012
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0012
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0071
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0071
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0032
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0032
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0052
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0052
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0013
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0013
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0072
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0072
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0033
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0033
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0053
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0053
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0014
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0014
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0073
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0073
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0034
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0034
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0054
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0054
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0015
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0015
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0074
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0074
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0035
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0035
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0055
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0055
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0016
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0016
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0075
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0075
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0036
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0036
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0056
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0056
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0017
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0017
Service:
.
Class GUID:
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0076
Manufacturer:
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0076
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0037
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0037
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0057
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0057
Service:
.
Class GUID:
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0018
Manufacturer:
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0018
Service:
.
Class GUID:
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0077
Manufacturer:
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0077
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0038
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0038
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0058
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0058
Service:
.
Class GUID:
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0019
Manufacturer:
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0019
Service:
.
Class GUID:
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0039
Manufacturer:
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0039
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0059
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0059
Service:
.
Class GUID:
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0020
Manufacturer:
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0020
Service:
.
Class GUID:
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0040
Manufacturer:
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0040
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0001
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0001
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0060
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0060
Service:
.
Class GUID:
Description: HP Color LaserJet MFP M476dw
Device ID: ROOT\MULTIFUNCTION\0021
Manufacturer:
Name: HP Color LaserJet MFP M476dw
PNP Device ID: ROOT\MULTIFUNCTION\0021
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0041
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0041
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0002
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0002
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0061
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0061
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0022
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0022
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0042
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0042
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0003
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0003
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0062
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0062
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0023
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0023
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0043
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0043
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0004
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0004
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0063
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0063
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0024
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0024
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0044
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0044
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0005
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0005
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0064
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0064
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0025
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0025
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0045
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0045
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0006
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0006
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0065
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0065
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0026
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0026
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0046
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0046
Service:
.
Class GUID:
Description: Photosmart 5510 series
Device ID: ROOT\MULTIFUNCTION\0007
Manufacturer:
Name: Photosmart 5510 series
PNP Device ID: ROOT\MULTIFUNCTION\0007
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0066
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0066
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0027
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0027
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0047
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0047
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0008
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0008
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0067
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0067
Service:
.
Class GUID:
Description: HP Color LaserJet CP4005
Device ID: ROOT\MULTIFUNCTION\0028
Manufacturer:
Name: HP Color LaserJet CP4005
PNP Device ID: ROOT\MULTIFUNCTION\0028
Service:
.
==== System Restore Points ===================
.
RP660: 25/11/2014 2:33:09 μμ - Windows Update
RP661: 2/12/2014 2:28:15 μμ - Windows Update
RP662: 3/12/2014 6:29:30 μμ - Απεγκαταστήθηκε με το Total Uninstall "Viber"
RP663: 5/12/2014 2:42:45 μμ - Windows Update
RP664: 5/12/2014 3:41:14 μμ - Installed ESET Smart Security
RP665: 9/12/2014 2:35:18 μμ - Windows Update
RP666: 10/12/2014 9:53:41 μμ - Απεγκαταστήθηκε με το Total Uninstall "Viber"
.
==== Installed Programs ======================
.
Συλλογή φωτογραφιών
ΜΑΤΖΕΝΤΑ - Αγγλικό-Ελληνικό & Ελληνικό-Αγγλικό λεξικό
64 Bit HP CIO Components Installer
A-PDF Number freeware 1.3
AccelerometerP11
Adobe Flash Player 16 ActiveX
Adobe Flash Player 16 NPAPI
Advanced Audio FX Engine
Allok Video Joiner 4.6.0422
Allok Video Splitter 3.0.1130
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ashampoo Burning Studio 9.12
Audacity 2.0.5
Bonjour
CCleaner
Cobian Backup 11 Gravity
D3DX10
Definition Update for Microsoft Office 2010 (KB2899521) 32-Bit Edition
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell Edoc Viewer
Dell Getting Started Guide
Dell MusicStage
Dell PhotoStage
Dell Stage
Dell Stage Remote
Dell VideoStage
Dell Webcam Central
DesignPro SE eMedia
DjVuLibre+DjView
Dropbox
eBay
Emsisoft Anti-Malware
Eraser 6.0.10.2620
ESET Smart Security
Finale 2011
FireArc Arcade
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
High-Definition Video Playback
HP Customer Participation Program 13.0
HP Imaging Device Functions 13.0
HP Photo Creations
HP Photosmart 5510 series Basic Device Software
HP Photosmart 5510 series Help
HP Photosmart 5510 series Product Improvement Study
HP Photosmart Essential 3.5
HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B
HP Smart Web Printing 4.51
HP Solution Center 13.0
HP Update
IBM SPSS Amos 19
IBM SPSS Statistics 19
iCloud
IDBAnalyzerV3
IE Java Block 32bit Shim
IE Java Block 64bit Shim
ImTOO Audio Converter Pro
ImTOO Convert PowerPoint to Video Personal
ImTOO DVD Copy 2
ImTOO DVD Creator
ImTOO DVD Ripper Ultimate
ImTOO Video Converter Ultimate
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed
Intel(R) Turbo Boost Technology Monitor 2.0
Intel® PROSet/Wireless Software
Intel® PROSet/Wireless WiFi Software
iTunes
Java 8 Update 25
Java Auto Updater
Junk Mail filter update
K-Lite Mega Codec Pack 10.6.0
LAME v3.99.3 (for Windows)
LibreOffice 4.2.2.1
MagicDisc 2.7.106
Malwarebytes Anti-Malware version 2.0.4.1028
MCShield ::Anti-Malware Tool::
Mendeley Desktop 1.8.2
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft Office Access MUI (Greek) 2010
Microsoft Office Excel MUI (Greek) 2010
Microsoft Office Groove MUI (Greek) 2010
Microsoft Office InfoPath MUI (Greek) 2010
Microsoft Office Office 64-bit Components 2010
Microsoft Office OneNote MUI (Greek) 2010
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (Greek) 2010
Microsoft Office PowerPoint MUI (Greek) 2010
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (German) 2010
Microsoft Office Proof (Greek) 2010
Microsoft Office Proofing (Greek) 2010
Microsoft Office Publisher MUI (Greek) 2010
Microsoft Office Shared 64-bit MUI (Greek) 2010
Microsoft Office Shared MUI (Greek) 2010
Microsoft Office Word MUI (Greek) 2010
Microsoft OneDrive
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Microsoft_VC100_CRT_SP1_x64
Microsoft_VC100_CRT_SP1_x86
Microsoft_VC80_CRT_x86
Microsoft_VC90_CRT_x86
Movie Maker
MSVC80_x64_v2
MSVC80_x86_v2
MSVC90_x64
MSVC90_x86
MSVCRT
MSVCRT_amd64
MSVCRT110
MSVCRT110_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2758694)
My Dell
Nero 10 Movie ThemePack Basic
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nokia Connectivity Cable Driver
Nokia Suite
NVIDIA Control Panel 331.65
NVIDIA Graphics Driver 331.65
NVIDIA Install Application
OCR Software by I.R.I.S. 13.0
paint.net
Pale Moon 25.1.0 (x86 en-US)
PC Connectivity Solution
PDF Settings CS6
PDF24 Creator 6.7.0
Photo Common
Photo Gallery
Photo Story 3 for Windows
Quickset64
QuickTime 7
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Recuva
Secunia PSI (3.0.0.7009)
Security Update for Microsoft .NET Framework 4.5.1 (KB2894854v2)
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Security Update for Microsoft .NET Framework 4.5.1 (KB2931368)
Security Update for Microsoft .NET Framework 4.5.1 (KB2972107)
Security Update for Microsoft .NET Framework 4.5.1 (KB2972216)
Security Update for Microsoft .NET Framework 4.5.1 (KB2978128)
Security Update for Microsoft .NET Framework 4.5.1 (KB2979578v2)
Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2810073) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2880971) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2881071) 32-Bit Edition
Security Update for Microsoft Word 2010 (KB2883013) 32-Bit Edition
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
Shop for HP Supplies
Skype Click to Call
Skype™ 6.21
SnowChristmasTree 1.6
Subtitle Workshop 6.0b
SumatraPDF
SUPERAntiSpyware
swMSM
Synaptics Pointing Device Driver
Syncios version 4.1.6
SyncUP
System Requirements Lab for Intel
TeamViewer 9
TinkerPlots
Total Uninstall 5.2.0
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Excel 2010 (KB2889935) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition
Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589386) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687275) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition
Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition
Update for Microsoft Office 2010 (KB2837602) 32-Bit Edition
Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition
Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition
Update for Microsoft Office 2010 (KB2889828) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2878251) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition
Viber
VLC media player
Windows Driver Package - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live MIME IFilter
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinRAR 4.10 (32-bit)
.
==== End Of File ===========================


And this:

# AdwCleaner v4.105 - Report created 11/12/2014 at 21:15:48
# Updated 08/12/2014 by Xplode
# Database : 2014-12-08.2 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : DR WHO - DR-WHO
# Running from : C:\Users\DR WHO\Desktop\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : c2cautoupdatesvc
Service Found : c2cpnrsvc

***** [ Files / Folders ] *****


***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17420


-\\ Pale Moon v25.1.0 (en-US)


*************************

AdwCleaner[R0].txt - [1312 octets] - [11/12/2014 21:15:48]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1372 octets] ##########

Title: Re: Something is wrong!
Post by: Corrine on December 11, 2014, 09:15:28 PM
Hi, Panos.

I saw your thread about Viber and hadn't come up with any suggestions yet.  Note that All AdwCleaner removed was the Skype toolbar and the accompanying Phone Number Recognition Service: 

http://www.systemlookup.com/CLSID/66064-skypeieplugin_dll_skypeieplugin4_dll.html
http://www.systemlookup.com/Drivers/10185-SkypeC2CPNRSvc_exe.html

As to the "unsupported operating system" error message you received from SecurityCheck, are you receiving any other "Windows is not Genuine" messages?  A fellow MVP posted in a private venue that he is seeing quite a few of these since the last update.  Posting the instructions he has provided so I don't need to track them down again if needed. I do NOT want you to follow his instructions at this time.
Looks like faulty Intel Rapid Storage driver.  Download and install the latest version from Intel:  https://downloadcenter.intel.com/Detail_Desc.aspx?DwnldID=22194

I know your operating system is valid.  However, to see what errors are shown, please run the Microsoft Genuine Diagnostics Tool then copy and paste the results in a reply here for further analysis:  http://go.microsoft.com/fwlink/?linkid=52012


Title: Re: Something is wrong!
Post by: Corrine on December 12, 2014, 02:29:27 AM
Panos, also, please check installed updates and see if you have KB3004394 (an update for Windows Root Certificate Program) installed. 
Title: Re: Something is wrong!
Post by: DR M on December 12, 2014, 01:05:16 PM
Hi, Corrine.

I never got messages about not genuine Windows.

Also, I haven't got the KB3004394 update installed.

I would feel better if I sent you the results of the Diagnostics Tool in a personal message, as there are many keys in there. If you think that everything is ok, then I will paste them here too.




Title: Re: Something is wrong!
Post by: Corrine on December 12, 2014, 11:00:55 PM
Hi, Panos.

I'm having some tree removal done so was occupied with that most of the day.  The pertinent information in the WGA log is X'd out but it isn't necessary to post the log here.  I misunderstood what you meant by "unsupported operating system" and was concerned because, as I indicated, there were a number of people who ran into a problem after installing updates on Tuesday.

Why is Viber starting from "C:\Users\DR WHO\AppData\Local\Viber\Viber.exe" instead of C:\Program Files\Viber\Viber.exe".  That seems rather abnormal.  You said here (http://www.landzdown.com/computer-problems-questions-and-solutions!/destop-viber-stopped-working/msg171694/#new) that you installed Viber on another computer and it is working fine. Where is the Viber.exe file located on the other computer?
Title: Re: Something is wrong!
Post by: DR M on December 13, 2014, 05:22:29 PM
Hi, Corrine. I would like to be occupied with jobs like tree removal these days! Instead I have a lot of reading. Let's hope that this will be the last year!   :mitch:

As for the Viber, I have no Viber folder in Program Files. I don't know if there was ever such a file there. The only Viber file is in AppData, and it is in there I found the error report. When I double click the exe file in the folder, nothing happens. The other computer I installed Viber is in the Computer Lab, so when I tried the program and saw that it was ok, I uninstalled it. So I can't see now where the exe file is. I can do this again on Monday, if I don't find the opportunity to try it on a friend's computer tomorrow.

Title: Re: Something is wrong!
Post by: Corrine on December 13, 2014, 09:05:37 PM
With the reinstall of Viber Desktop, did you need to get a new activation code as described here, Viber | Viber setup for Windows desktop (https://support.viber.com/customer/portal/articles/1340184-getting-started-viber-setup-for-windows-desktop#.VIyp-Z7iKUk)?
Title: Re: Something is wrong!
Post by: DR M on December 14, 2014, 12:22:55 PM
Quote from: Corrine on December 13, 2014, 09:05:37 PM
With the reinstall of Viber Desktop, did you need to get a new activation code as described here, Viber | Viber setup for Windows desktop (https://support.viber.com/customer/portal/articles/1340184-getting-started-viber-setup-for-windows-desktop#.VIyp-Z7iKUk)?

Yes, I did. Every time you reinstall Viber, you have to get a new activation code and enter your phone number.
Title: Re: Something is wrong!
Post by: DR M on December 15, 2014, 02:00:32 PM
I didn't have the opportunity to check Viber's location today.

Do you think that the problem is due to a malware?

P.S. Not relevant, but just wanted to tell you: two of my friends installed Sumatra. The default color is not yellow, but grey.  :smiley:
Title: Re: Something is wrong!
Post by: plodr on December 15, 2014, 02:44:56 PM
The default color can be changed easily. I have it changed to blue, tan, pink and green depending on the computer.
Right click Sumatra and select properties.
Look at the Target line and append after the last " by the exe a space then the following
-bg-color #??????
The ?'s are replaced by numbers and letters. Here is the chart
http://html-color-codes.com/

So along the top line FF3300 would be a shade of orange.

F0DDD5 is beige
CCFFCC is pale green

Here's my opening screen on the computer I'm currently using
(https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fwww.walagata.com%2Fw%2Fperk%2FSumatra_blue.jpg&hash=7ce779c14f58bddbbdebf6c112abeafed81b4e46)
Title: Re: Something is wrong!
Post by: Corrine on December 15, 2014, 03:41:40 PM
Also see http://www.sumatrapdfreader.org/settings3.0.html.  Using the menu item Settings -> Advanced Settings... to open the settings file with Notepad, the "MainWindowBackground" can be changed.  Why your friends had gray is a mystery since bright yellow is the default. 
Title: Re: Something is wrong!
Post by: DR M on December 15, 2014, 05:08:08 PM
Hi, Corrine.

I have tried some things I found here and there, but I didn't find a solution... When I go to Viber's properties, change the compatibility to Windows XP and click run as administrator, Viber starts to work. If I unchecked these options and make them as before, the program still works. But if I make a computer restart, again, I get the error that the program needs to close and so on...


P.S. It seems that yellow color was the default in Sumatra. Now it's gray. I just found this to confirm: http://blog.kowalczyk.info/article/b/SumatraPDF-30-released.html  (please see the last line).
Title: Re: Something is wrong!
Post by: Corrine on December 15, 2014, 08:47:59 PM
:dance:  Thank you!  Until I have some spare time and correct/write a not blog post, I've added the information as a comment, including "h/t" (hat tip) to you:  http://securitygarden.blogspot.com/2013/02/replacing-adobe-reader-with-sumatra-pdf.html

Title: Re: Something is wrong!
Post by: DR M on December 16, 2014, 12:24:20 PM
Quote from: Corrine on December 15, 2014, 08:47:59 PM
:dance:  Thank you!  Until I have some spare time and correct/write a not blog post, I've added the information as a comment, including "h/t" (hat tip) to you:  http://securitygarden.blogspot.com/2013/02/replacing-adobe-reader-with-sumatra-pdf.html

Corrine, of course you hadn't got to refer to anyone for that! I just realized that yellow became gray, when my friends didn't notice much difference from Adobe. Yesterday I found the link I posted here.  :mitch:

Now, Viber's location is in Users/username/AppData/Local/Viber in all computers. I don't know if we can do something with this or leave it as it is. My only concern is about my computer, to be safe, with no malware.
Title: Re: Something is wrong!
Post by: Corrine on December 16, 2014, 06:04:08 PM
I'm not seeing any malware in the logs, Panos.

Knowing absolutely nothing about Viber, since you installed it in the Computer Lab, I gather it works with your connection there.  If that was not the case, I would have suggested reinstalling on your mobile device.  Unless someone else is familiar with Viber, I suggest you submit a ticket to Viber Support:  https://support.viber.com/customer/portal/emails/new
Title: Re: Something is wrong!
Post by: DR M on December 16, 2014, 08:30:39 PM
Ok, Corrine. Thank you for your help so far. :rose:

I will post here the whole error report in Viber, in case someone can help. Otherwise I will completely uninstall Viber from both, the computer and the phone.

The error report:

Viber caused a (0xc0000005)
in module libViber.dll at 0023:56e6ee4e.

Exception handler called.
Error occurred at 12/16/2014 22:26:08.
C:\Users\DR WHO\AppData\Local\Viber\Viber.exe, run by DR WHO.
Operating system:  Windows Vista (6.1.7601).
8 processor(s), type 586.
38% memory in use.
0 MBytes physical memory.
3710 MBytes physical memory free.
0 MBytes paging file.
0 MBytes paging file free.
2048 MBytes user address space.
1663 MBytes user address space free.
Read from location 00000000 caused an access violation.

Context:
EDI:    0x00000000  ESI: 0x00000000  EAX:   0x0031d1e4
EBX:    0x00000000  ECX: 0x00000000  EDX:   0x006c006e
EIP:    0x56e6ee4e  EBP: 0x0031d20c  SegCs: 0x00000023
EFlags: 0x00010246  ESP: 0x0031d1d8  SegSs: 0x0000002b

Bytes at CS:EIP:
8b 16 50 8b 42 14 8b ce c6 45 fc 02 ff d0 8d 4d
0: 0023:56E6EE4E (0x0031D230 0x00000000 0x56DA8F7B 0x00000000), viberAppMain()+850206 byte(s)
1: 0023:56E6E91B (0x00000000 0x00000000 0x0031D618 0x00000000), viberAppMain()+848875 byte(s)
2: 0023:56DA8F7B (0x62C2A04D 0x00000000 0x0031D618 0x00000000), viberAppMain()+39499 byte(s)
3: 0023:56DAC65C (0x0031D618 0x00000000 0x0108AFE8 0x00000000), viberAppMain()+53548 byte(s)
4: 0023:63510BB9 (0x0110D808 0x00000000 0x0031D618 0x00000000), QApplicationPrivate::notify_helper()+0185 byte(s)
5: 0023:65C8346F (0x01037F60 0x00000000 0x0031D618 0x00000000), QCoreApplication::notifyInternal()+0127 byte(s)

===== [end of ERROR.LOG] =====
Title: Re: Something is wrong!
Post by: Corrine on December 19, 2014, 02:43:54 AM
Found out the source of the problem!  ESET is blocking Viber.  See ESET Rebuffs Viber's #esetsucks Hashtag with Proof of Application's Silent Activity - Softpedia (http://news.softpedia.com/news/ESET-Rebuffs-Viber-s-esetsucks-Hashtag-with-Proof-of-Application-s-Silent-Activity-467866.shtml).

Read the article carefully and decide what you want to do.  Having read the article a second time myself, I wanted to draw your attention to a couple of key points:

QuoteNOD32 is not the only antivirus product that flags the desktop version of Viber as a potentially unwanted application. Clam AntiVirus and Dr. Web also mark it as a similar threat.

The reason the desktop version of Viber was identified by ESET and other vendors as a potentially unwanted application is because of the silent downloading and sending of statistics, as illustrated in the image in this Tweet by ESET:  https://twitter.com/esetglobal/status/545273531089817600
Title: Re: Something is wrong!
Post by: DR M on December 19, 2014, 02:16:49 PM
Quote from: Corrine on December 19, 2014, 02:43:54 AM
Found out the source of the problem!

I was sure about this!!!!   :dance:

Anyway, I already uninstalled Viber from both, the computer and the phone. But today I read that I should reinstalled it to deactivate my account. So I did. Before, I turned off Eset's protection, to see what is going to happen. I got again the same error. So, I changed the compatibility mode (run for Windows XP), to enter the program and deactivate the account. I deactivated it and uninstalled it. Now I don't have Viber installed in any of my devices. I don't know what really caused the problem, but I can do my job with Skype.

Thanks, as always! :rose: