DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 11.0.9600.18098
Run by [removed] at 18:19:48 on 2015-11-16
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2047.432 [GMT -6:00]
.
AV: AVG AntiVirus Free Edition *Enabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition *Enabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
.
============== Running Processes ================
.
c:\PROGRA~1\AVG\Av\avgrsx.exe
C:\Program Files\AVG\Av\avgcsrvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\AVG\Av\avgidsagent.exe
C:\Program Files\AVG\Framework\Common\avgsvcx.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\AVG\Av\avgwdsvcx.exe
C:\Windows\Explorer.EXE
C:\Program Files\TeamViewer\TeamViewer_Service.exe
C:\Program Files\BOINC\boincmgr.exe
C:\Program Files\BOINC\boinctray.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Dropbox\Client\Dropbox.exe
C:\Program Files\AVG\Av\avgui.exe
C:\Program Files\BOINC\boinc.exe
C:\Users\thom hp extra\AppData\Local\MalwareProtectionLive\MalwareProtectionClient.exe
C:\Windows\system32\conhost.exe
C:\Program Files\AVG\Framework\Common\avguix.exe
C:\Program Files\AVG\Av\avgnsx.exe
C:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
C:\Program Files\AVG\Av\avgemcx.exe
C:\Users\thom hp extra\AppData\Roaming\uTorrent\uTorrent.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Users\thom hp extra\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
C:\Users\thom hp extra\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcgrid_mcm1_7.35_windows_intelx86
C:\Windows\system32\conhost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
C:\Program Files\SeaMonkey\seamonkey.exe
C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcgrid_mcm1_7.35_windows_intelx86
C:\Windows\system32\conhost.exe
C:\Windows\ehome\ehRecvr.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LPDService
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.safesear.ch/?type=20151108-230-ie
uSearch Bar = hxxp://www.safesear.ch/web/?type=201511 ... e-ie-df&q={searchTerms}
uSearch Page = hxxp://www.safesear.ch/web/?type=201511 ... e-ie-df&q={searchTerms}
uDefault_Page_URL = hxxp://www.safesear.ch/?type=20151108-230-ie
mStart Page = hxxp://www.safesear.ch/?type=20151108-230-ie
mSearch Page = hxxp://www.safesear.ch/web/?type=201511 ... e-ie-df&q={searchTerms}
mDefault_Page_URL = hxxp://www.safesear.ch/?type=20151108-230-ie
uSearchAssistant = hxxp://www.safesear.ch/web/?type=201511 ... e-ie-df&q={searchTerms}
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: {95B7759C-8C7F-4BF1-B163-73684A933233} - <orphaned>
BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile: {D5233FCD-D258-4903-89B8-FB1568E7413D} -
EB: <No Name>: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - <no file>
EB: <No Name>: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - <no file>
uRun: [uTorrent] "c:\users\thom hp extra\appdata\roaming\utorrent\uTorrent.exe" /MINIMIZED
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
mRun: [boincmgr] "c:\program files\boinc\boincmgr.exe" /a /s
mRun: [boinctray] "c:\program files\boinc\boinctray.exe"
mRun: [Dropbox] "c:\program files\dropbox\client\Dropbox.exe" /systemstartup
mRun: [AVG_UI] "c:\program files\avg\av\avgui.exe" /TRAYONLY
mRun: [MalwareProtectionLive] c:\users\thom hp extra\appdata\local\malwareprotectionlive\MalwareProtectionClient.exe
mRun: [AvgUi] "c:\program files\avg\framework\common\avguix.exe" /fmw.trayonly
mRun: [iSkysoft Helper Compact.exe] c:\program files\common files\iskysoft\iskysoft helper compact\ISHelper.exe
dRun: [DevconDefaultDB] c:\windows\system32\READREG /SILENT /FAIL=1
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: Open Client to monitor &1 - c:\windows\web\AOpenClient.htm
IE: Open Client to monitor &2 - c:\windows\web\AOpenClient.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} -
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{0283995D-71A2-4368-B948-69DB3C45847A} : DHCPNameServer = 192.168.2.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\46.0.2490.80\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2015-8-20 231344]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2015-8-14 308656]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2015-10-21 192944]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2015-8-10 36784]
R1 anodlwf;ANOD Network Security Filter driver;c:\windows\system32\drivers\anodlwf.sys [2014-3-28 12800]
R1 Avgdiskx;AVG Disk Driver;c:\windows\system32\drivers\avgdiskx.sys [2015-8-10 156080]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2015-10-19 256432]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2015-8-14 31664]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2015-10-21 229296]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2015-10-8 231856]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2015-2-11 79872]
R3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\system32\drivers\hcw18bda.sys [2009-5-28 391296]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2011-4-11 62464]
S3 netr28u;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\Dnetr28u.sys [2014-3-28 750592]
.
=============== File Associations ===============
.
FileExt: .vbs: VBSFile="c:\windows\system32\WScript.exe" "%1" %* [UserChoice]
.
=============== Created Last 30 ================
.
2015-11-16 03:18:37 -------- d-----w- c:\programdata\iSkysoft
2015-11-16 02:35:04 -------- d-----w- c:\users\thom hp extra\appdata\local\iSkysoft
2015-11-16 02:34:58 -------- d-----w- c:\program files\common files\iSkysoft
2015-11-16 02:34:10 531496 ----a-w- c:\windows\system32\mcmpeg2mux.ax
2015-11-16 02:34:10 375848 ----a-w- c:\windows\system32\mcm2ve.ax
2015-11-16 02:34:10 257064 ----a-w- c:\windows\system32\mcl2ae.ax
2015-11-16 02:34:10 244776 ----a-w- c:\windows\system32\mcmpgaout.dll
2015-11-16 02:34:10 2140712 ----a-w- c:\windows\system32\mcmpgvout.004
2015-11-16 02:34:10 20520 ----a-w- c:\windows\system32\mcmpgvout.dll
2015-11-16 02:33:40 -------- d-----w- c:\program files\iSkysoft
2015-11-16 02:26:43 -------- d-----w- c:\users\thom hp extra\appdata\local\Movavi
2015-11-16 02:26:37 -------- d-----w- c:\users\thom hp extra\appdata\local\VideoEditor
2015-11-16 02:25:04 -------- d-----w- c:\program files\Movavi Video Editor 11
2015-11-16 02:16:21 -------- d-----w- c:\programdata\Movavi Video Editor 11
2015-11-15 15:41:35 -------- d-----w- c:\users\thom hp extra\appdata\local\CEF
2015-11-15 15:27:02 -------- d-----w- c:\program files\SystemManager
2015-11-15 15:01:50 -------- d-----w- c:\users\thom hp extra\appdata\local\Tempfolder
2015-11-15 15:01:11 -------- d-----w- C:\uninst
2015-11-15 15:01:06 -------- d-----w- c:\program files\shopperz151120151549
2015-11-15 15:00:58 -------- d-----w- c:\users\thom hp extra\appdata\roaming\System Healer
2015-11-15 15:00:48 -------- d-----w- c:\programdata\MovieDeaConfig
2015-11-15 15:00:34 -------- d-----w- c:\program files\MovieDea
2015-11-15 14:58:06 -------- d-----w- c:\program files\SwiftSearch_1.10.0.25
2015-11-15 14:56:38 -------- d-----w- c:\program files\BubbleSound
2015-11-15 14:36:43 -------- d-----w- c:\users\thom hp extra\appdata\local\Opera Software
2015-11-15 14:36:17 -------- d-----w- c:\users\thom hp extra\appdata\roaming\Opera Software
2015-11-15 14:34:15 -------- d-----w- c:\users\thom hp extra\appdata\local\6061D900-1447576454-1012-BABF-809E7CA4452D
2015-11-15 14:29:54 -------- d-----w- c:\programdata\UWMiniProU
2015-11-15 14:29:52 -------- d-----w- c:\users\thom hp extra\appdata\roaming\mystartsearch
2015-11-15 14:25:37 -------- d-----w- c:\programdata\MegaBackup Corp
2015-11-15 14:25:12 -------- d-----w- c:\users\thom hp extra\appdata\local\Crossbrowse
2015-11-15 14:22:42 -------- d-----w- c:\program files\CinemaPlus_1.3dV13.11
2015-11-15 14:22:02 -------- d-----w- c:\program files\JZIP
2015-11-15 14:20:51 -------- d-----w- c:\program files\Crossbrowse
2015-11-15 14:16:31 -------- d-----w- c:\users\thom hp extra\appdata\local\globalUpdate
2015-11-15 14:16:31 -------- d-----w- c:\program files\globalUpdate
2015-11-15 14:16:05 -------- d-----w- c:\program files\CinePlus-1.44V09.11
2015-11-15 14:15:05 -------- d-----w- c:\users\thom hp extra\appdata\roaming\RunDir
2015-11-15 14:15:02 -------- d-----w- c:\users\thom hp extra\appdata\roaming\NetService
2015-11-15 14:14:53 -------- d-----w- c:\program files\jogotempo
2015-11-15 14:12:17 -------- d-----w- c:\users\thom hp extra\appdata\roaming\Note-UP
2015-11-15 14:11:25 -------- d-----w- c:\users\thom hp extra\appdata\local\6061D900-1447575085-1012-BABF-809E7CA4452D
2015-11-15 14:10:01 -------- d-----w- c:\users\thom hp extra\appdata\roaming\NUIns
2015-11-15 14:10:01 -------- d-----w- c:\program files\6061D900-1447596601-1012-BABF-809E7CA4452D
2015-11-15 14:04:07 -------- d-----w- c:\program files\winnetlog
2015-11-15 11:40:43 -------- d-----w- c:\users\thom hp extra\appdata\roaming\InstantSupport
2015-11-15 11:40:37 -------- d-----w- c:\programdata\PCAcceleratePro
2015-11-15 11:40:37 -------- d-----w- c:\program files\InstantSupport
2015-11-15 11:40:34 -------- d-----w- c:\users\thom hp extra\appdata\roaming\PCAcceleratePro
2015-11-15 11:40:29 -------- d-----w- c:\program files\PCAcceleratePro
2015-11-15 11:40:24 -------- d-----w- c:\program files\PCAPDownloader
2015-11-15 01:45:45 -------- d-----w- c:\program files\Nero
2015-11-15 01:45:21 -------- d-----w- c:\programdata\Nero
2015-11-13 20:25:44 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2015-11-13 20:22:06 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2015-11-13 20:18:58 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2015-11-13 02:18:27 87608 ----a-w- c:\users\thom hp extra\appdata\roaming\inst.exe
2015-11-13 02:18:27 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2015-11-13 02:18:27 47360 ----a-w- c:\users\thom hp extra\appdata\roaming\pcouffin.sys
2015-11-13 02:18:17 217127 ----a-w- c:\windows\system32\drv43260.dll
2015-11-13 02:18:17 208935 ----a-w- c:\windows\system32\drv33260.dll
2015-11-13 02:18:17 176165 ----a-w- c:\windows\system32\drv23260.dll
2015-11-13 02:18:15 -------- d-----w- c:\program files\VSO
2015-11-12 09:49:36 2386944 ----a-w- c:\windows\system32\win32k.sys
2015-11-11 14:02:24 62464 ----a-w- c:\windows\system32\aelupsvc.dll
2015-11-11 14:02:24 5120 ----a-w- c:\windows\system32\shimeng.dll
2015-11-11 14:02:24 295936 ----a-w- c:\windows\system32\apphelp.dll
2015-11-11 14:02:24 20992 ----a-w- c:\windows\system32\sdbinst.exe
2015-11-11 14:02:03 74752 ----a-w- c:\windows\system32\drivers\tdx.sys
2015-11-11 14:02:03 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2015-11-09 03:26:12 -------- d-----w- c:\users\thom hp extra\appdata\roaming\uTorrent
2015-11-09 02:58:35 -------- d-----w- c:\program files\.Npackd
2015-11-09 02:57:46 -------- d-----w- c:\program files\NpackdDetected
2015-11-09 02:54:16 -------- d-----w- c:\users\thom hp extra\appdata\local\Component
2015-11-09 02:53:54 -------- d-----w- c:\users\thom hp extra\appdata\local\intmanager
2015-11-09 02:53:46 -------- d-----w- c:\programdata\Npackd
2015-11-09 02:51:53 -------- d-----w- c:\users\thom hp extra\appdata\local\Fast Browser
2015-10-25 12:23:51 -------- d-----w- c:\users\thom hp extra\appdata\local\AvgSetupLog
2015-10-21 22:24:24 229296 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2015-10-19 14:06:02 256432 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
.
==================== Find3M ====================
.
2015-10-30 22:58:29 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2015-10-30 22:58:18 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2015-10-30 22:47:08 504832 ----a-w- c:\windows\system32\vbscript.dll
2015-10-30 22:46:27 62464 ----a-w- c:\windows\system32\iesetup.dll
2015-10-30 22:45:51 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll
2015-10-30 22:45:42 341504 ----a-w- c:\windows\system32\html.iec
2015-10-30 22:44:57 64000 ----a-w- c:\windows\system32\MshtmlDac.dll
2015-10-30 22:36:30 102912 ----a-w- c:\windows\system32\ieetwcollector.exe
2015-10-30 22:36:25 115712 ----a-w- c:\windows\system32\ieUnatt.exe
2015-10-30 22:36:06 620032 ----a-w- c:\windows\system32\jscript9diag.dll
2015-10-30 22:31:22 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2015-10-30 22:23:51 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2015-10-30 22:16:43 4527616 ----a-w- c:\windows\system32\jscript9.dll
2015-10-30 22:09:23 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll
2015-10-30 22:09:15 2052608 ----a-w- c:\windows\system32\inetcpl.cpl
2015-10-30 21:51:28 2011136 ----a-w- c:\windows\system32\wininet.dll
2015-10-29 20:02:40 780488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-10-29 20:02:40 142536 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-10-29 17:49:57 562176 ----a-w- c:\windows\apppatch\AcLayers.dll
2015-10-29 17:49:57 470528 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2015-10-29 17:49:57 2178560 ----a-w- c:\windows\apppatch\AcGenral.dll
2015-10-29 17:49:57 211968 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2015-10-29 17:39:57 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2015-10-20 17:46:02 93696 ----a-w- c:\windows\system32\wudriver.dll
2015-10-20 17:46:02 2955776 ----a-w- c:\windows\system32\wucltux.dll
2015-10-20 17:46:02 174080 ----a-w- c:\windows\system32\wuwebv.dll
2015-10-20 17:45:27 73728 ----a-w- c:\windows\system32\WinSetupUI.dll
2015-10-20 17:45:12 11776 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2015-10-20 17:45:08 35328 ----a-w- c:\windows\system32\wuapp.exe
2015-10-20 00:52:02 3991488 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-10-20 00:52:02 3935680 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-10-20 00:52:00 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2015-10-20 00:52:00 138176 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2015-10-20 00:48:47 1308160 ----a-w- c:\windows\system32\ntdll.dll
2015-10-20 00:44:53 22528 ----a-w- c:\windows\system32\lsass.exe
2015-10-20 00:44:35 50176 ----a-w- c:\windows\system32\auditpol.exe
2015-10-20 00:39:32 60416 ----a-w- c:\windows\system32\msobjs.dll
2015-10-20 00:39:11 146432 ----a-w- c:\windows\system32\msaudite.dll
2015-10-20 00:35:03 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-10-20 00:35:00 686080 ----a-w- c:\windows\system32\adtschema.dll
2015-10-19 23:29:22 225792 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2015-10-19 23:28:57 98304 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2015-10-19 23:28:56 124416 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2015-10-13 10:24:00 4587520 ----a-w- c:\windows\system32\GPhotos.scr
2015-10-13 07:29:08 875720 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2015-10-13 04:50:31 712640 ----a-w- c:\windows\system32\drivers\ndis.sys
2015-10-08 13:48:58 231856 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2015-10-01 17:50:53 50176 ----a-w- c:\windows\system32\setbcdlocale.dll
2015-10-01 17:50:43 22528 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\jnwppr.dll
2015-10-01 17:50:43 216064 ----a-w- c:\windows\system32\InkEd.dll
2015-10-01 17:50:43 19968 ----a-w- c:\windows\system32\jnwmon.dll
2015-10-01 17:50:35 50688 ----a-w- c:\windows\system32\appidapi.dll
2015-10-01 17:50:35 28160 ----a-w- c:\windows\system32\appidsvc.dll
2015-10-01 17:50:00 96768 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2015-10-01 17:50:00 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2015-10-01 16:53:22 50176 ----a-w- c:\windows\system32\drivers\appid.sys
2015-09-23 13:09:58 371920 ----a-w- c:\windows\system32\drivers\cng.sys
2015-09-23 13:09:57 251000 ----a-w- c:\windows\system32\bcryptprimitives.dll
2015-09-18 17:47:06 23384 ----a-w- c:\windows\system32\CompatTelRunner.exe
2015-09-18 17:44:35 587776 ----a-w- c:\windows\system32\invagent.dll
2015-09-18 17:44:34 615936 ----a-w- c:\windows\system32\generaltel.dll
2015-09-18 17:44:30 423936 ----a-w- c:\windows\system32\devinv.dll
2015-09-18 17:44:27 1120768 ----a-w- c:\windows\system32\appraiser.dll
2015-09-18 17:44:26 62976 ----a-w- c:\windows\system32\acmigration.dll
2015-09-18 17:35:49 999936 ----a-w- c:\windows\system32\aeinv.dll
2015-09-02 02:48:35 26624 ----a-w- c:\windows\system32\lpk.dll
2015-09-02 02:48:31 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-09-02 02:48:28 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-09-02 02:48:25 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-09-02 01:33:48 299520 ----a-w- c:\windows\system32\atmfd.dll
2015-08-27 17:58:14 1391104 ----a-w- c:\windows\system32\msxml6.dll
2015-08-27 17:58:14 1241088 ----a-w- c:\windows\system32\msxml3.dll
2015-08-27 17:51:26 2048 ----a-w- c:\windows\system32\msxml6r.dll
2015-08-27 17:51:26 2048 ----a-w- c:\windows\system32\msxml3r.dll
2015-08-20 19:05:48 231344 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2015-08-20 16:14:30 130048 ----a-w- c:\windows\system32\SpoonUninstall.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: WDC_WD50 rev.01.0 -> Harddisk0\DR0 -> \Device\00000071
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll storport.sys nvstor32.sys
c:\windows\system32\drivers\nvstor32.sys NVIDIA Corporation NVIDIA nForce(TM) SATA Driver
1 ntkrnlpa!IofCallDriver[0x83053D19] -> \Device\Harddisk0\DR0[0x860B4030]
3 CLASSPNP[0x8919859E] -> ntkrnlpa!IofCallDriver[0x83053D19] -> [0x85030930]
5 ACPI[0x8378A3D4] -> ntkrnlpa!IofCallDriver[0x83053D19] -> \Device\00000070[0x859F0A28]
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
user != kernel MBR !!!
sectors 976773166 (+255): user != kernel
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/6/2014 5:06:24 PM
System Uptime: 11/16/2015 12:35:53 PM (6 hours ago)
.
Motherboard: ASUSTek Computer INC. | | NARRA
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3600+ | Socket AM2 | 988/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 448 GiB total, 344.446 GiB free.
D: is FIXED (NTFS) - 18 GiB total, 9.722 GiB free.
E: is FIXED (NTFS) - 932 GiB total, 456.821 GiB free.
F: is CDROM ()
G: is CDROM ()
H: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: FNetDevi
Device ID: ROOT\LEGACY_FNETDEVI\0000
Manufacturer:
Name: FNetDevi
PNP Device ID: ROOT\LEGACY_FNETDEVI\0000
Service: FNetDevi
.
==== System Restore Points ===================
.
RP166: 11/12/2015 8:18:44 PM - Device Driver Package Install: VSO Software
RP167: 11/13/2015 3:00:16 AM - Windows Update
RP169: 11/13/2015 2:17:26 PM - Installed DirectX
RP171: 11/13/2015 2:20:22 PM - Installed DirectX
RP173: 11/13/2015 2:24:16 PM - Installed DirectX
RP174: 11/14/2015 7:44:08 PM - Installed Nero 2016 Content Pack.
RP175: 11/15/2015 9:37:33 AM - Restore Operation
RP176: 11/15/2015 10:03:28 AM - Removed LightScribe System Software.
RP177: 11/15/2015 10:09:06 AM - Removed Citrix Online Launcher
.
==== Installed Programs ======================
.
µTorrent
32 Bit HP CIO Components Installer
ABBulkMailer
Adobe Flash Player 19 NPAPI
Adobe Reader XI (11.0.13)
Adobe Refresh Manager
AMD Catalyst Control Center
AMD Catalyst Install Manager
AMD Fuel
ASUS GPU Tweak
ASUS Product Register Program
AVG
AVG 2016
AVG Protection
Bing Rewards Client Installer
Catalyst Control Center - Branding
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Desktop
ccc-utility
CCC Help English
CDBurnerXP
ConvertXtoDVD 2.2.3.258
Dropbox
Dropbox Update Helper
Fitbit Connect
FMW 1
Google Chrome
Google Update Helper
GoToMeeting 7.5.1.3911
HP Customer Experience Enhancements
HP Officejet Pro 8600 Basic Device Software
HP Officejet Pro 8600 Help
HP Officejet Pro 8600 Product Improvement Study
HP Support Solutions Framework
HP Update
HPDiagnosticAlert
HydraVision
I.R.I.S. OCR
iSkysoft Video Editor(Build 4.7.2)
join.me
Kodi
Lead Tools Direct 297 Club
Malware Protection Live
Microsoft .NET Framework 4.5.2
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2008 R2 Native Client
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
Movavi Video Editor 11
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Net Extractor
NVIDIA Control Panel 307.83
NVIDIA Drivers
NVIDIA Graphics Driver 307.83
NVIDIA Install Application
NVIDIA Update 1.10.8
NVIDIA Update Components
Picasa 3
Quicken 2014
Revo Uninstaller 1.94
Sage ACT! Premium 2011
SeaMonkey 2.38 (x86 en-US)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4.5.2 (KB3097996)
Security Update for Microsoft .NET Framework 4.5.2 (KB3098781)
Security Update for Microsoft Office 2007 suites (KB2596650) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687409) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2817330) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2825645) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2837610) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2880507) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2880508) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2881069) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2920795) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB3085546) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB3085620) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB3101555) 32-Bit Edition
Security Update for Microsoft Office Access 2007 (KB2596614) 32-Bit Edition
Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3085551) 32-Bit Edition
Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3101558) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB3101554) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687406) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office OneNote 2007 (KB2889915) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB3085548) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2880506) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB3085552) 32-Bit Edition
Skype™ 7.12
SUPERAntiSpyware
TeamViewer 10
TurboTax 2014
TurboTax 2014 WinPerFedFormset
TurboTax 2014 WinPerReleaseEngine
TurboTax 2014 WinPerTaxSupport
TurboTax 2014 wrapper
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596787) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2965286) 32-Bit Edition
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB3101557) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Visual Studio 2012 x86 Redistributables
WinRAR 5.21 (32-bit)
World Community Grid
.
==== Event Viewer Messages From Past Week ========
.
11/16/2015 12:42:47 PM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
11/16/2015 12:37:16 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: FNetDevi
11/15/2015 9:22:28 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LanmanServer service.
11/15/2015 9:22:28 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgwd service.
11/15/2015 9:02:19 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Rebfueqeae service to connect.
11/15/2015 9:02:19 AM, Error: Service Control Manager [7000] - The Rebfueqeae service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================
.
============= FINISH: 18:21:57.19 ===============
Internet Explorer: 11.0.9600.18098
Run by [removed] at 18:19:48 on 2015-11-16
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2047.432 [GMT -6:00]
.
AV: AVG AntiVirus Free Edition *Enabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition *Enabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
.
============== Running Processes ================
.
c:\PROGRA~1\AVG\Av\avgrsx.exe
C:\Program Files\AVG\Av\avgcsrvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\AVG\Av\avgidsagent.exe
C:\Program Files\AVG\Framework\Common\avgsvcx.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\AVG\Av\avgwdsvcx.exe
C:\Windows\Explorer.EXE
C:\Program Files\TeamViewer\TeamViewer_Service.exe
C:\Program Files\BOINC\boincmgr.exe
C:\Program Files\BOINC\boinctray.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Dropbox\Client\Dropbox.exe
C:\Program Files\AVG\Av\avgui.exe
C:\Program Files\BOINC\boinc.exe
C:\Users\thom hp extra\AppData\Local\MalwareProtectionLive\MalwareProtectionClient.exe
C:\Windows\system32\conhost.exe
C:\Program Files\AVG\Framework\Common\avguix.exe
C:\Program Files\AVG\Av\avgnsx.exe
C:\Program Files\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
C:\Program Files\AVG\Av\avgemcx.exe
C:\Users\thom hp extra\AppData\Roaming\uTorrent\uTorrent.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Users\thom hp extra\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
C:\Users\thom hp extra\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcgrid_mcm1_7.35_windows_intelx86
C:\Windows\system32\conhost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
C:\Program Files\SeaMonkey\seamonkey.exe
C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcgrid_mcm1_7.35_windows_intelx86
C:\Windows\system32\conhost.exe
C:\Windows\ehome\ehRecvr.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LPDService
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.safesear.ch/?type=20151108-230-ie
uSearch Bar = hxxp://www.safesear.ch/web/?type=201511 ... e-ie-df&q={searchTerms}
uSearch Page = hxxp://www.safesear.ch/web/?type=201511 ... e-ie-df&q={searchTerms}
uDefault_Page_URL = hxxp://www.safesear.ch/?type=20151108-230-ie
mStart Page = hxxp://www.safesear.ch/?type=20151108-230-ie
mSearch Page = hxxp://www.safesear.ch/web/?type=201511 ... e-ie-df&q={searchTerms}
mDefault_Page_URL = hxxp://www.safesear.ch/?type=20151108-230-ie
uSearchAssistant = hxxp://www.safesear.ch/web/?type=201511 ... e-ie-df&q={searchTerms}
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: {95B7759C-8C7F-4BF1-B163-73684A933233} - <orphaned>
BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile: {D5233FCD-D258-4903-89B8-FB1568E7413D} -
EB: <No Name>: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - <no file>
EB: <No Name>: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - <no file>
uRun: [uTorrent] "c:\users\thom hp extra\appdata\roaming\utorrent\uTorrent.exe" /MINIMIZED
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
mRun: [boincmgr] "c:\program files\boinc\boincmgr.exe" /a /s
mRun: [boinctray] "c:\program files\boinc\boinctray.exe"
mRun: [Dropbox] "c:\program files\dropbox\client\Dropbox.exe" /systemstartup
mRun: [AVG_UI] "c:\program files\avg\av\avgui.exe" /TRAYONLY
mRun: [MalwareProtectionLive] c:\users\thom hp extra\appdata\local\malwareprotectionlive\MalwareProtectionClient.exe
mRun: [AvgUi] "c:\program files\avg\framework\common\avguix.exe" /fmw.trayonly
mRun: [iSkysoft Helper Compact.exe] c:\program files\common files\iskysoft\iskysoft helper compact\ISHelper.exe
dRun: [DevconDefaultDB] c:\windows\system32\READREG /SILENT /FAIL=1
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: Open Client to monitor &1 - c:\windows\web\AOpenClient.htm
IE: Open Client to monitor &2 - c:\windows\web\AOpenClient.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} -
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{0283995D-71A2-4368-B948-69DB3C45847A} : DHCPNameServer = 192.168.2.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\46.0.2490.80\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2015-8-20 231344]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2015-8-14 308656]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2015-10-21 192944]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2015-8-10 36784]
R1 anodlwf;ANOD Network Security Filter driver;c:\windows\system32\drivers\anodlwf.sys [2014-3-28 12800]
R1 Avgdiskx;AVG Disk Driver;c:\windows\system32\drivers\avgdiskx.sys [2015-8-10 156080]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2015-10-19 256432]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2015-8-14 31664]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2015-10-21 229296]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2015-10-8 231856]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2015-2-11 79872]
R3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\system32\drivers\hcw18bda.sys [2009-5-28 391296]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2011-4-11 62464]
S3 netr28u;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\Dnetr28u.sys [2014-3-28 750592]
.
=============== File Associations ===============
.
FileExt: .vbs: VBSFile="c:\windows\system32\WScript.exe" "%1" %* [UserChoice]
.
=============== Created Last 30 ================
.
2015-11-16 03:18:37 -------- d-----w- c:\programdata\iSkysoft
2015-11-16 02:35:04 -------- d-----w- c:\users\thom hp extra\appdata\local\iSkysoft
2015-11-16 02:34:58 -------- d-----w- c:\program files\common files\iSkysoft
2015-11-16 02:34:10 531496 ----a-w- c:\windows\system32\mcmpeg2mux.ax
2015-11-16 02:34:10 375848 ----a-w- c:\windows\system32\mcm2ve.ax
2015-11-16 02:34:10 257064 ----a-w- c:\windows\system32\mcl2ae.ax
2015-11-16 02:34:10 244776 ----a-w- c:\windows\system32\mcmpgaout.dll
2015-11-16 02:34:10 2140712 ----a-w- c:\windows\system32\mcmpgvout.004
2015-11-16 02:34:10 20520 ----a-w- c:\windows\system32\mcmpgvout.dll
2015-11-16 02:33:40 -------- d-----w- c:\program files\iSkysoft
2015-11-16 02:26:43 -------- d-----w- c:\users\thom hp extra\appdata\local\Movavi
2015-11-16 02:26:37 -------- d-----w- c:\users\thom hp extra\appdata\local\VideoEditor
2015-11-16 02:25:04 -------- d-----w- c:\program files\Movavi Video Editor 11
2015-11-16 02:16:21 -------- d-----w- c:\programdata\Movavi Video Editor 11
2015-11-15 15:41:35 -------- d-----w- c:\users\thom hp extra\appdata\local\CEF
2015-11-15 15:27:02 -------- d-----w- c:\program files\SystemManager
2015-11-15 15:01:50 -------- d-----w- c:\users\thom hp extra\appdata\local\Tempfolder
2015-11-15 15:01:11 -------- d-----w- C:\uninst
2015-11-15 15:01:06 -------- d-----w- c:\program files\shopperz151120151549
2015-11-15 15:00:58 -------- d-----w- c:\users\thom hp extra\appdata\roaming\System Healer
2015-11-15 15:00:48 -------- d-----w- c:\programdata\MovieDeaConfig
2015-11-15 15:00:34 -------- d-----w- c:\program files\MovieDea
2015-11-15 14:58:06 -------- d-----w- c:\program files\SwiftSearch_1.10.0.25
2015-11-15 14:56:38 -------- d-----w- c:\program files\BubbleSound
2015-11-15 14:36:43 -------- d-----w- c:\users\thom hp extra\appdata\local\Opera Software
2015-11-15 14:36:17 -------- d-----w- c:\users\thom hp extra\appdata\roaming\Opera Software
2015-11-15 14:34:15 -------- d-----w- c:\users\thom hp extra\appdata\local\6061D900-1447576454-1012-BABF-809E7CA4452D
2015-11-15 14:29:54 -------- d-----w- c:\programdata\UWMiniProU
2015-11-15 14:29:52 -------- d-----w- c:\users\thom hp extra\appdata\roaming\mystartsearch
2015-11-15 14:25:37 -------- d-----w- c:\programdata\MegaBackup Corp
2015-11-15 14:25:12 -------- d-----w- c:\users\thom hp extra\appdata\local\Crossbrowse
2015-11-15 14:22:42 -------- d-----w- c:\program files\CinemaPlus_1.3dV13.11
2015-11-15 14:22:02 -------- d-----w- c:\program files\JZIP
2015-11-15 14:20:51 -------- d-----w- c:\program files\Crossbrowse
2015-11-15 14:16:31 -------- d-----w- c:\users\thom hp extra\appdata\local\globalUpdate
2015-11-15 14:16:31 -------- d-----w- c:\program files\globalUpdate
2015-11-15 14:16:05 -------- d-----w- c:\program files\CinePlus-1.44V09.11
2015-11-15 14:15:05 -------- d-----w- c:\users\thom hp extra\appdata\roaming\RunDir
2015-11-15 14:15:02 -------- d-----w- c:\users\thom hp extra\appdata\roaming\NetService
2015-11-15 14:14:53 -------- d-----w- c:\program files\jogotempo
2015-11-15 14:12:17 -------- d-----w- c:\users\thom hp extra\appdata\roaming\Note-UP
2015-11-15 14:11:25 -------- d-----w- c:\users\thom hp extra\appdata\local\6061D900-1447575085-1012-BABF-809E7CA4452D
2015-11-15 14:10:01 -------- d-----w- c:\users\thom hp extra\appdata\roaming\NUIns
2015-11-15 14:10:01 -------- d-----w- c:\program files\6061D900-1447596601-1012-BABF-809E7CA4452D
2015-11-15 14:04:07 -------- d-----w- c:\program files\winnetlog
2015-11-15 11:40:43 -------- d-----w- c:\users\thom hp extra\appdata\roaming\InstantSupport
2015-11-15 11:40:37 -------- d-----w- c:\programdata\PCAcceleratePro
2015-11-15 11:40:37 -------- d-----w- c:\program files\InstantSupport
2015-11-15 11:40:34 -------- d-----w- c:\users\thom hp extra\appdata\roaming\PCAcceleratePro
2015-11-15 11:40:29 -------- d-----w- c:\program files\PCAcceleratePro
2015-11-15 11:40:24 -------- d-----w- c:\program files\PCAPDownloader
2015-11-15 01:45:45 -------- d-----w- c:\program files\Nero
2015-11-15 01:45:21 -------- d-----w- c:\programdata\Nero
2015-11-13 20:25:44 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2015-11-13 20:22:06 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2015-11-13 20:18:58 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2015-11-13 02:18:27 87608 ----a-w- c:\users\thom hp extra\appdata\roaming\inst.exe
2015-11-13 02:18:27 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2015-11-13 02:18:27 47360 ----a-w- c:\users\thom hp extra\appdata\roaming\pcouffin.sys
2015-11-13 02:18:17 217127 ----a-w- c:\windows\system32\drv43260.dll
2015-11-13 02:18:17 208935 ----a-w- c:\windows\system32\drv33260.dll
2015-11-13 02:18:17 176165 ----a-w- c:\windows\system32\drv23260.dll
2015-11-13 02:18:15 -------- d-----w- c:\program files\VSO
2015-11-12 09:49:36 2386944 ----a-w- c:\windows\system32\win32k.sys
2015-11-11 14:02:24 62464 ----a-w- c:\windows\system32\aelupsvc.dll
2015-11-11 14:02:24 5120 ----a-w- c:\windows\system32\shimeng.dll
2015-11-11 14:02:24 295936 ----a-w- c:\windows\system32\apphelp.dll
2015-11-11 14:02:24 20992 ----a-w- c:\windows\system32\sdbinst.exe
2015-11-11 14:02:03 74752 ----a-w- c:\windows\system32\drivers\tdx.sys
2015-11-11 14:02:03 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2015-11-09 03:26:12 -------- d-----w- c:\users\thom hp extra\appdata\roaming\uTorrent
2015-11-09 02:58:35 -------- d-----w- c:\program files\.Npackd
2015-11-09 02:57:46 -------- d-----w- c:\program files\NpackdDetected
2015-11-09 02:54:16 -------- d-----w- c:\users\thom hp extra\appdata\local\Component
2015-11-09 02:53:54 -------- d-----w- c:\users\thom hp extra\appdata\local\intmanager
2015-11-09 02:53:46 -------- d-----w- c:\programdata\Npackd
2015-11-09 02:51:53 -------- d-----w- c:\users\thom hp extra\appdata\local\Fast Browser
2015-10-25 12:23:51 -------- d-----w- c:\users\thom hp extra\appdata\local\AvgSetupLog
2015-10-21 22:24:24 229296 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2015-10-19 14:06:02 256432 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
.
==================== Find3M ====================
.
2015-10-30 22:58:29 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2015-10-30 22:58:18 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2015-10-30 22:47:08 504832 ----a-w- c:\windows\system32\vbscript.dll
2015-10-30 22:46:27 62464 ----a-w- c:\windows\system32\iesetup.dll
2015-10-30 22:45:51 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll
2015-10-30 22:45:42 341504 ----a-w- c:\windows\system32\html.iec
2015-10-30 22:44:57 64000 ----a-w- c:\windows\system32\MshtmlDac.dll
2015-10-30 22:36:30 102912 ----a-w- c:\windows\system32\ieetwcollector.exe
2015-10-30 22:36:25 115712 ----a-w- c:\windows\system32\ieUnatt.exe
2015-10-30 22:36:06 620032 ----a-w- c:\windows\system32\jscript9diag.dll
2015-10-30 22:31:22 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2015-10-30 22:23:51 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2015-10-30 22:16:43 4527616 ----a-w- c:\windows\system32\jscript9.dll
2015-10-30 22:09:23 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll
2015-10-30 22:09:15 2052608 ----a-w- c:\windows\system32\inetcpl.cpl
2015-10-30 21:51:28 2011136 ----a-w- c:\windows\system32\wininet.dll
2015-10-29 20:02:40 780488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-10-29 20:02:40 142536 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-10-29 17:49:57 562176 ----a-w- c:\windows\apppatch\AcLayers.dll
2015-10-29 17:49:57 470528 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2015-10-29 17:49:57 2178560 ----a-w- c:\windows\apppatch\AcGenral.dll
2015-10-29 17:49:57 211968 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2015-10-29 17:39:57 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2015-10-20 17:46:02 93696 ----a-w- c:\windows\system32\wudriver.dll
2015-10-20 17:46:02 2955776 ----a-w- c:\windows\system32\wucltux.dll
2015-10-20 17:46:02 174080 ----a-w- c:\windows\system32\wuwebv.dll
2015-10-20 17:45:27 73728 ----a-w- c:\windows\system32\WinSetupUI.dll
2015-10-20 17:45:12 11776 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2015-10-20 17:45:08 35328 ----a-w- c:\windows\system32\wuapp.exe
2015-10-20 00:52:02 3991488 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-10-20 00:52:02 3935680 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-10-20 00:52:00 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2015-10-20 00:52:00 138176 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2015-10-20 00:48:47 1308160 ----a-w- c:\windows\system32\ntdll.dll
2015-10-20 00:44:53 22528 ----a-w- c:\windows\system32\lsass.exe
2015-10-20 00:44:35 50176 ----a-w- c:\windows\system32\auditpol.exe
2015-10-20 00:39:32 60416 ----a-w- c:\windows\system32\msobjs.dll
2015-10-20 00:39:11 146432 ----a-w- c:\windows\system32\msaudite.dll
2015-10-20 00:35:03 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-10-20 00:35:00 686080 ----a-w- c:\windows\system32\adtschema.dll
2015-10-19 23:29:22 225792 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2015-10-19 23:28:57 98304 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2015-10-19 23:28:56 124416 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2015-10-13 10:24:00 4587520 ----a-w- c:\windows\system32\GPhotos.scr
2015-10-13 07:29:08 875720 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2015-10-13 04:50:31 712640 ----a-w- c:\windows\system32\drivers\ndis.sys
2015-10-08 13:48:58 231856 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2015-10-01 17:50:53 50176 ----a-w- c:\windows\system32\setbcdlocale.dll
2015-10-01 17:50:43 22528 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\jnwppr.dll
2015-10-01 17:50:43 216064 ----a-w- c:\windows\system32\InkEd.dll
2015-10-01 17:50:43 19968 ----a-w- c:\windows\system32\jnwmon.dll
2015-10-01 17:50:35 50688 ----a-w- c:\windows\system32\appidapi.dll
2015-10-01 17:50:35 28160 ----a-w- c:\windows\system32\appidsvc.dll
2015-10-01 17:50:00 96768 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2015-10-01 17:50:00 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2015-10-01 16:53:22 50176 ----a-w- c:\windows\system32\drivers\appid.sys
2015-09-23 13:09:58 371920 ----a-w- c:\windows\system32\drivers\cng.sys
2015-09-23 13:09:57 251000 ----a-w- c:\windows\system32\bcryptprimitives.dll
2015-09-18 17:47:06 23384 ----a-w- c:\windows\system32\CompatTelRunner.exe
2015-09-18 17:44:35 587776 ----a-w- c:\windows\system32\invagent.dll
2015-09-18 17:44:34 615936 ----a-w- c:\windows\system32\generaltel.dll
2015-09-18 17:44:30 423936 ----a-w- c:\windows\system32\devinv.dll
2015-09-18 17:44:27 1120768 ----a-w- c:\windows\system32\appraiser.dll
2015-09-18 17:44:26 62976 ----a-w- c:\windows\system32\acmigration.dll
2015-09-18 17:35:49 999936 ----a-w- c:\windows\system32\aeinv.dll
2015-09-02 02:48:35 26624 ----a-w- c:\windows\system32\lpk.dll
2015-09-02 02:48:31 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-09-02 02:48:28 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-09-02 02:48:25 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-09-02 01:33:48 299520 ----a-w- c:\windows\system32\atmfd.dll
2015-08-27 17:58:14 1391104 ----a-w- c:\windows\system32\msxml6.dll
2015-08-27 17:58:14 1241088 ----a-w- c:\windows\system32\msxml3.dll
2015-08-27 17:51:26 2048 ----a-w- c:\windows\system32\msxml6r.dll
2015-08-27 17:51:26 2048 ----a-w- c:\windows\system32\msxml3r.dll
2015-08-20 19:05:48 231344 ----a-w- c:\windows\system32\drivers\avgidshx.sys
2015-08-20 16:14:30 130048 ----a-w- c:\windows\system32\SpoonUninstall.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: WDC_WD50 rev.01.0 -> Harddisk0\DR0 -> \Device\00000071
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll storport.sys nvstor32.sys
c:\windows\system32\drivers\nvstor32.sys NVIDIA Corporation NVIDIA nForce(TM) SATA Driver
1 ntkrnlpa!IofCallDriver[0x83053D19] -> \Device\Harddisk0\DR0[0x860B4030]
3 CLASSPNP[0x8919859E] -> ntkrnlpa!IofCallDriver[0x83053D19] -> [0x85030930]
5 ACPI[0x8378A3D4] -> ntkrnlpa!IofCallDriver[0x83053D19] -> \Device\00000070[0x859F0A28]
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
user != kernel MBR !!!
sectors 976773166 (+255): user != kernel
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/6/2014 5:06:24 PM
System Uptime: 11/16/2015 12:35:53 PM (6 hours ago)
.
Motherboard: ASUSTek Computer INC. | | NARRA
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3600+ | Socket AM2 | 988/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 448 GiB total, 344.446 GiB free.
D: is FIXED (NTFS) - 18 GiB total, 9.722 GiB free.
E: is FIXED (NTFS) - 932 GiB total, 456.821 GiB free.
F: is CDROM ()
G: is CDROM ()
H: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: FNetDevi
Device ID: ROOT\LEGACY_FNETDEVI\0000
Manufacturer:
Name: FNetDevi
PNP Device ID: ROOT\LEGACY_FNETDEVI\0000
Service: FNetDevi
.
==== System Restore Points ===================
.
RP166: 11/12/2015 8:18:44 PM - Device Driver Package Install: VSO Software
RP167: 11/13/2015 3:00:16 AM - Windows Update
RP169: 11/13/2015 2:17:26 PM - Installed DirectX
RP171: 11/13/2015 2:20:22 PM - Installed DirectX
RP173: 11/13/2015 2:24:16 PM - Installed DirectX
RP174: 11/14/2015 7:44:08 PM - Installed Nero 2016 Content Pack.
RP175: 11/15/2015 9:37:33 AM - Restore Operation
RP176: 11/15/2015 10:03:28 AM - Removed LightScribe System Software.
RP177: 11/15/2015 10:09:06 AM - Removed Citrix Online Launcher
.
==== Installed Programs ======================
.
µTorrent
32 Bit HP CIO Components Installer
ABBulkMailer
Adobe Flash Player 19 NPAPI
Adobe Reader XI (11.0.13)
Adobe Refresh Manager
AMD Catalyst Control Center
AMD Catalyst Install Manager
AMD Fuel
ASUS GPU Tweak
ASUS Product Register Program
AVG
AVG 2016
AVG Protection
Bing Rewards Client Installer
Catalyst Control Center - Branding
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Desktop
ccc-utility
CCC Help English
CDBurnerXP
ConvertXtoDVD 2.2.3.258
Dropbox
Dropbox Update Helper
Fitbit Connect
FMW 1
Google Chrome
Google Update Helper
GoToMeeting 7.5.1.3911
HP Customer Experience Enhancements
HP Officejet Pro 8600 Basic Device Software
HP Officejet Pro 8600 Help
HP Officejet Pro 8600 Product Improvement Study
HP Support Solutions Framework
HP Update
HPDiagnosticAlert
HydraVision
I.R.I.S. OCR
iSkysoft Video Editor(Build 4.7.2)
join.me
Kodi
Lead Tools Direct 297 Club
Malware Protection Live
Microsoft .NET Framework 4.5.2
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2008 R2 Native Client
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
Movavi Video Editor 11
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Net Extractor
NVIDIA Control Panel 307.83
NVIDIA Drivers
NVIDIA Graphics Driver 307.83
NVIDIA Install Application
NVIDIA Update 1.10.8
NVIDIA Update Components
Picasa 3
Quicken 2014
Revo Uninstaller 1.94
Sage ACT! Premium 2011
SeaMonkey 2.38 (x86 en-US)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4.5.2 (KB3097996)
Security Update for Microsoft .NET Framework 4.5.2 (KB3098781)
Security Update for Microsoft Office 2007 suites (KB2596650) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687409) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2817330) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2825645) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2837610) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2880507) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2880508) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2881069) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2920795) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB3085546) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB3085620) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB3101555) 32-Bit Edition
Security Update for Microsoft Office Access 2007 (KB2596614) 32-Bit Edition
Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3085551) 32-Bit Edition
Security Update for Microsoft Office Compatibility Pack Service Pack 3 (KB3101558) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB3101554) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687406) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office OneNote 2007 (KB2889915) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB3085548) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2880506) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB3085552) 32-Bit Edition
Skype™ 7.12
SUPERAntiSpyware
TeamViewer 10
TurboTax 2014
TurboTax 2014 WinPerFedFormset
TurboTax 2014 WinPerReleaseEngine
TurboTax 2014 WinPerTaxSupport
TurboTax 2014 wrapper
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596787) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2965286) 32-Bit Edition
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB3101557) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Visual Studio 2012 x86 Redistributables
WinRAR 5.21 (32-bit)
World Community Grid
.
==== Event Viewer Messages From Past Week ========
.
11/16/2015 12:42:47 PM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
11/16/2015 12:37:16 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: FNetDevi
11/15/2015 9:22:28 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LanmanServer service.
11/15/2015 9:22:28 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgwd service.
11/15/2015 9:02:19 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Rebfueqeae service to connect.
11/15/2015 9:02:19 AM, Error: Service Control Manager [7000] - The Rebfueqeae service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================
.
============= FINISH: 18:21:57.19 ===============