1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

[Solved] Run DLL error

Discussion in 'Malware Removal Help' started by patszy, Feb 7, 2014.

  1. patszy

    patszy Registered Members

    Joined:
    Aug 1, 2010
    Messages:
    181
    Location:
    USA
    Operating System:
    Windows 8
    Oh yes.. Windows 8.1 is full of fun. Not as bad as I thought, however. I am getting used to it so that I can retire my Windows 7 (to hubby). HOWEVER....Windows 7 is MUCH faster much to my disimay.

    OK....I will do it and just hope all will be well. Kind of scary for me. I usually pay attention to WARNINGS!!!
     
  2. patszy

    patszy Registered Members

    Joined:
    Aug 1, 2010
    Messages:
    181
    Location:
    USA
    Operating System:
    Windows 8
    Whew....this is heavy stuff for this old 83 year old lady!!!!
    Here is the first one....I will look for the second one.
    I see Bonjour on there....I was going to ask someone if I could safely remove that but had not gotten around to it. I did not put that on the computer.

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-02-2014 02
    Ran by Patszy at 2014-02-10 14:04:15
    Running from C:\Users\Patszy\Pictures
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov)
    Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.44 - Adobe Systems Incorporated)
    AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden
    AMD Catalyst Install Manager (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
    AMD VISION Engine Control Center (x32 Version: 2013.0328.428.6129 - Advanced Micro Devices, Inc.) Hidden
    Bonjour (Version: 3.0.0.10 - Apple Inc.)
    Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0328.428.6129 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center InstallProxy (x32 Version: 2013.0328.428.6129 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Localization All (x32 Version: 2013.0328.428.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Chinese Standard (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Chinese Traditional (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Czech (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Danish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Dutch (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help English (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Finnish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help French (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help German (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Greek (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Hungarian (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Italian (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Japanese (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Korean (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Norwegian (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Polish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Portuguese (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Russian (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Spanish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Swedish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Thai (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Turkish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    ccc-utility64 (Version: 2013.0328.428.6129 - Advanced Micro Devices, Inc.) Hidden
    CCleaner (Version: 4.09 - Piriform)
    Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.)
    Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.)
    Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.)
    CyberLink LabelPrint (x32 Version: 2.5.4.6522 - CyberLink Corp.)
    CyberLink LabelPrint (x32 Version: 2.5.4.6522 - CyberLink Corp.) Hidden
    CyberLink Media Suite 10 (x32 Version: 10.0.4.3003 - CyberLink Corp.)
    CyberLink Media Suite 10 (x32 Version: 10.0.4.3003 - CyberLink Corp.) Hidden
    Cyberlink PhotoDirector (x32 Version: 3.0.2.4016 - CyberLink Corp.)
    Cyberlink PhotoDirector (x32 Version: 3.0.2.4016 - CyberLink Corp.) Hidden
    CyberLink Power2Go 8 (x32 Version: 8.0.4.2921 - CyberLink Corp.)
    CyberLink Power2Go 8 (x32 Version: 8.0.4.2921 - CyberLink Corp.) Hidden
    CyberLink PowerDirector 10 (x32 Version: 10.0.4.3007 - CyberLink Corp.)
    CyberLink PowerDirector 10 (x32 Version: 10.0.4.3007 - CyberLink Corp.) Hidden
    CyberLink PowerDVD 12 (x32 Version: 12.0.2.3324 - CyberLink Corp.)
    CyberLink PowerDVD 12 (x32 Version: 12.0.2.3324 - CyberLink Corp.) Hidden
    CyberLink YouCam (x32 Version: 3.5.6.6119 - CyberLink Corp.)
    CyberLink YouCam (x32 Version: 3.5.6.6119 - CyberLink Corp.) Hidden
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Energy Star (x32 Version: 1.0.9 - Hewlett-Packard Company)
    FastStone Capture 5.3 (x32 Version: 5.3 - FastStone Soft)
    FolderMagic (x32 Version: 2.0 - Cloudeight Internet, LLC.)
    Google Chrome (x32 Version: 32.0.1700.107 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
    Hallmark Card Studio 2013 (x32 Version: 14.0.0.28 - Creative Home)
    Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
    HitmanPro 3.7 (Version: 3.7.9.212 - SurfRight B.V.)
    HP Connected Music (Meridian - installer) (x32 Version: 1.0 - Meridian Audio Ltd)
    HP Connected Music (Meridian - player) (HKCU Version: 1.1 (build 88) hp - Meridian Audio Ltd)
    HP Customer Experience Enhancements (x32 Version: 6.0.1.8 - Hewlett-Packard) Hidden
    HP Postscript Converter (Version: 4.0.4100 - Hewlett-Packard) Hidden
    HP Quick Start (x32 Version: 1.0.4660.30220 - Hewlett-Packard)
    HP Registration Service (Version: 1.2.6668.4491 - Hewlett-Packard)
    HP Support Assistant (x32 Version: 7.4.45.4 - Hewlett-Packard Company)
    HP Support Information (x32 Version: 12.00.0000 - Hewlett-Packard)
    HP Support Solutions Framework (x32 Version: 11.50.0000 - Hewlett-Packard Company)
    HPDetect (x32 Version: 1.0.0.0 - HP)
    Jasc Animation Shop 3 (x32 Version: 3.11 - Jasc Software Inc)
    Jigs@w Puzzle 2 (x32 Version: - Tibo Software)
    Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    LastPass (uninstall only) (x32 Version: - LastPass)
    Malwarebytes Anti-Malware version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation)
    Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
    Microsoft PowerPoint Viewer (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
    Microsoft SkyDrive (HKCU Version: 16.4.6013.0910 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation)
    Microsoft SQL Server Compact 3.5 SP2 ENU (x32 Version: 3.5.8080.0 - Microsoft Corporation)
    Microsoft SQL Server Compact 3.5 SP2 x64 ENU (Version: 3.5.8080.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (x32 Version: 11.0.51106.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
    Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Mozilla Firefox 26.0 (x86 en-US) (x32 Version: 26.0 - Mozilla)
    Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla)
    MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
    MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
    MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
    MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
    Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Qualcomm Atheros Driver Installation Program (x32 Version: 10.0 - Qualcomm Atheros)
    Ralink RT2870 Wireless LAN Card (x32 Version: 1.5.6.0 - Ralink)
    Realtek Ethernet Controller Driver (x32 Version: 8.15.410.2013 - Realtek)
    Realtek High Definition Audio Driver (x32 Version: 6.0.1.7027 - Realtek Semiconductor Corp.)
    Realtek PCIE Card Reader (x32 Version: 6.2.9200.28140 - Realtek Semiconductor Corp.)
    Recovery Manager (x32 Version: 5.5.0.6208 - CyberLink Corp.) Hidden
    Revo Uninstaller 1.95 (x32 Version: 1.95 - VS Revo Group)
    SolSuite 2013 v13.11 (x32 Version: 13.11 - TreeCardGames)
    Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation)
    Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Mail (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Messenger (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live MIME IFilter (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Writer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Writer Resources (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    WordWeb (x32 Version: 7 - WordWeb Software)

    ==================== Restore Points =========================

    23-01-2014 16:14:47 Scheduled Checkpoint
    30-01-2014 15:47:11 Removed Bonjour
    05-02-2014 13:21:20 HPSF Restore Point

    ==================== Hosts content: ==========================

    2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

    ==================== Scheduled Tasks (whitelisted) =============

    Task: {04846BE4-86C0-407A-9CDF-844AF9E2E1CE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
    Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
    Task: {167F9A1A-6E0D-4FE5-A6BB-B002D137BB9F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
    Task: {26AC5145-9371-408D-8362-04DDA685EA55} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-01-15] (Microsoft Corporation)
    Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
    Task: {34E3146F-068A-47B4-892C-F4F97BBDEFE2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd)
    Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
    Task: {360CAAA7-E62A-4560-AD68-AA38120C1F2D} - System32\Tasks\CLMLSvc_P2G8 => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-03-12] (CyberLink)
    Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
    Task: {3D3A41D4-FF8F-45D7-9AF9-1DC377E0B062} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe
    Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
    Task: {5102A6E5-B510-4BB3-9859-AB13BFF5505E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {52759B28-1025-4E63-9A38-C125B95A3E89} - System32\Tasks\HPCeeScheduleForPatszy => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
    Task: {69A6CC67-2397-417C-B153-3A2E00A81DB0} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
    Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
    Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
    Task: {6FC109CB-2AFB-446C-938F-BBC3DED67FBF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-19] (Google Inc.)
    Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
    Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
    Task: {82F1C1F0-DD88-49B9-82BC-CC10A00C8DC5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-12-12] (Hewlett-Packard Company)
    Task: {84C9D834-9615-4C98-A365-D3646D5E8FA6} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe
    Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
    Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
    Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
    Task: {A2E2852E-B2A4-4C0A-8F3A-4812840A6442} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-04] (Adobe Systems Incorporated)
    Task: {A7967E63-9063-451A-960C-5EADB487B91D} - System32\Tasks\BackgroundContainer Startup Task => Rundll32.exe "C:\Users\Patszy\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
    Task: {AF72767F-7F2F-47E3-8786-C5D3EA31C319} - System32\Tasks\CLVDLauncher => c:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.)
    Task: {C80478D6-9871-48A7-BEDD-B51A0543C44D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard)
    Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
    Task: {D33F9668-2E0E-43CD-AD72-09B708FED0C8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-19] (Google Inc.)
    Task: {D42842F2-36F6-4890-AAD2-77A4C610DB92} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
    Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
    Task: {E49D94EB-6ABB-4F49-992F-F7EAC7F35CB2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard)
    Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
    Task: {F348113B-8418-4F39-96FC-5F919B03B3EC} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe
    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\HPCeeScheduleForPatszy.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

    ==================== Loaded Modules (whitelisted) =============

    2013-12-06 23:04 - 2013-12-06 23:05 - 00183808 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\ErrorReporting.dll
    2013-01-22 17:50 - 2013-01-22 17:50 - 00098304 _____ () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\BrandingNet4.dll
    2013-12-09 12:54 - 2009-12-10 11:16 - 00918816 _____ () C:\Program Files (x86)\Ralink\Common\RaWLAPI.dll
    2013-07-25 00:18 - 2013-03-12 09:51 - 00626240 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
    2013-03-13 00:53 - 2013-03-13 00:53 - 00015424 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll

    ==================== Alternate Data Streams (whitelisted) =========

    AlternateDataStreams: C:\Users\Patszy\SkyDrive:ms-properties
    AlternateDataStreams: C:\Users\Rod\SkyDrive:ms-properties

    ==================== Safe Mode (whitelisted) ===================


    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 1656

    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 1656

    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (02/09/2014 03:12:55 PM) (Source: Customer Experience Improvement Program) (User: )
    Description: 80070005

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 1484

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 1484

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second


    System errors:
    =============
    Error: (02/10/2014 00:55:01 PM) (Source: Service Control Manager) (User: )
    Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 3 time(s).

    Error: (02/10/2014 00:22:27 PM) (Source: Service Control Manager) (User: )
    Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 2 time(s).

    Error: (02/10/2014 10:13:43 AM) (Source: Service Control Manager) (User: )
    Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (02/10/2014 10:00:00 AM) (Source: DCOM) (User: NT AUTHORITY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable

    Error: (02/10/2014 07:57:31 AM) (Source: DCOM) (User: NT AUTHORITY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable

    Error: (02/09/2014 09:45:10 PM) (Source: Service Control Manager) (User: )
    Description: The Superfetch service terminated with the following error:
    %%1062

    Error: (02/09/2014 02:40:44 PM) (Source: Service Control Manager) (User: )
    Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (02/09/2014 02:24:08 PM) (Source: DCOM) (User: HP)
    Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

    Error: (02/09/2014 02:23:38 PM) (Source: DCOM) (User: HP)
    Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

    Error: (02/09/2014 02:12:28 PM) (Source: DCOM) (User: NT AUTHORITY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable


    Microsoft Office Sessions:
    =========================
    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 1656

    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 1656

    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (02/09/2014 03:12:55 PM) (Source: Customer Experience Improvement Program)(User: )
    Description: 80070005

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 1484

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 1484

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: Continuously busy for more than a second


    CodeIntegrity Errors:
    ===================================
    Date: 2014-02-07 11:46:24.370
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2014-02-07 11:46:24.292
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.


    ==================== Memory info ===========================

    Percentage of memory in use: 16%
    Total physical RAM: 5717.25 MB
    Available physical RAM: 4786.74 MB
    Total Pagefile: 6677.25 MB
    Available Pagefile: 5387.2 MB
    Total Virtual: 131072 MB
    Available Virtual: 131071.77 MB

    ==================== Drives ================================

    Drive c: (Windows) (Fixed) (Total:446.17 GB) (Free:368.71 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive d: (Recovery Image) (Fixed) (Total:17.77 GB) (Free:2.17 GB) NTFS ==>[System with boot components (obtained from reading drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 466 GB) (Disk ID: 1F5A0FEE)

    Partition: GPT Partition Type
    ==================== End Of Log ============================
     
  3. patszy

    patszy Registered Members

    Joined:
    Aug 1, 2010
    Messages:
    181
    Location:
    USA
    Operating System:
    Windows 8
    Here is the Addition results.
    I do see that file listed, but it does not say it was deleted. It would seem to me I could go in there and delete it if it has the location listed. Guess not though. Looks like a lot of errors. Guess I had better run a Disk Check etc????
    I hope you can figure all this out and tell me what I need to do next.
    I do THANK you for all your time and expertise!!!!! Doesn't seem like I have any trouble as a result of the program. Of course, you knew that....
    P.

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-02-2014 02
    Ran by Patszy at 2014-02-10 14:04:15
    Running from C:\Users\Patszy\Pictures
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov)
    Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.44 - Adobe Systems Incorporated)
    AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden
    AMD Catalyst Install Manager (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
    AMD VISION Engine Control Center (x32 Version: 2013.0328.428.6129 - Advanced Micro Devices, Inc.) Hidden
    Bonjour (Version: 3.0.0.10 - Apple Inc.)
    Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0328.428.6129 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center InstallProxy (x32 Version: 2013.0328.428.6129 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Localization All (x32 Version: 2013.0328.428.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Chinese Standard (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Chinese Traditional (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Czech (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Danish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Dutch (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help English (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Finnish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help French (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help German (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Greek (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Hungarian (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Italian (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Japanese (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Korean (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Norwegian (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Polish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Portuguese (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Russian (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Spanish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Swedish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Thai (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Turkish (x32 Version: 2013.0328.0427.6129 - Advanced Micro Devices, Inc.) Hidden
    ccc-utility64 (Version: 2013.0328.428.6129 - Advanced Micro Devices, Inc.) Hidden
    CCleaner (Version: 4.09 - Piriform)
    Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.)
    Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.)
    Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.)
    CyberLink LabelPrint (x32 Version: 2.5.4.6522 - CyberLink Corp.)
    CyberLink LabelPrint (x32 Version: 2.5.4.6522 - CyberLink Corp.) Hidden
    CyberLink Media Suite 10 (x32 Version: 10.0.4.3003 - CyberLink Corp.)
    CyberLink Media Suite 10 (x32 Version: 10.0.4.3003 - CyberLink Corp.) Hidden
    Cyberlink PhotoDirector (x32 Version: 3.0.2.4016 - CyberLink Corp.)
    Cyberlink PhotoDirector (x32 Version: 3.0.2.4016 - CyberLink Corp.) Hidden
    CyberLink Power2Go 8 (x32 Version: 8.0.4.2921 - CyberLink Corp.)
    CyberLink Power2Go 8 (x32 Version: 8.0.4.2921 - CyberLink Corp.) Hidden
    CyberLink PowerDirector 10 (x32 Version: 10.0.4.3007 - CyberLink Corp.)
    CyberLink PowerDirector 10 (x32 Version: 10.0.4.3007 - CyberLink Corp.) Hidden
    CyberLink PowerDVD 12 (x32 Version: 12.0.2.3324 - CyberLink Corp.)
    CyberLink PowerDVD 12 (x32 Version: 12.0.2.3324 - CyberLink Corp.) Hidden
    CyberLink YouCam (x32 Version: 3.5.6.6119 - CyberLink Corp.)
    CyberLink YouCam (x32 Version: 3.5.6.6119 - CyberLink Corp.) Hidden
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Energy Star (x32 Version: 1.0.9 - Hewlett-Packard Company)
    FastStone Capture 5.3 (x32 Version: 5.3 - FastStone Soft)
    FolderMagic (x32 Version: 2.0 - Cloudeight Internet, LLC.)
    Google Chrome (x32 Version: 32.0.1700.107 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
    Hallmark Card Studio 2013 (x32 Version: 14.0.0.28 - Creative Home)
    Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
    HitmanPro 3.7 (Version: 3.7.9.212 - SurfRight B.V.)
    HP Connected Music (Meridian - installer) (x32 Version: 1.0 - Meridian Audio Ltd)
    HP Connected Music (Meridian - player) (HKCU Version: 1.1 (build 88) hp - Meridian Audio Ltd)
    HP Customer Experience Enhancements (x32 Version: 6.0.1.8 - Hewlett-Packard) Hidden
    HP Postscript Converter (Version: 4.0.4100 - Hewlett-Packard) Hidden
    HP Quick Start (x32 Version: 1.0.4660.30220 - Hewlett-Packard)
    HP Registration Service (Version: 1.2.6668.4491 - Hewlett-Packard)
    HP Support Assistant (x32 Version: 7.4.45.4 - Hewlett-Packard Company)
    HP Support Information (x32 Version: 12.00.0000 - Hewlett-Packard)
    HP Support Solutions Framework (x32 Version: 11.50.0000 - Hewlett-Packard Company)
    HPDetect (x32 Version: 1.0.0.0 - HP)
    Jasc Animation Shop 3 (x32 Version: 3.11 - Jasc Software Inc)
    Jigs@w Puzzle 2 (x32 Version: - Tibo Software)
    Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    LastPass (uninstall only) (x32 Version: - LastPass)
    Malwarebytes Anti-Malware version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation)
    Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
    Microsoft PowerPoint Viewer (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
    Microsoft SkyDrive (HKCU Version: 16.4.6013.0910 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation)
    Microsoft SQL Server Compact 3.5 SP2 ENU (x32 Version: 3.5.8080.0 - Microsoft Corporation)
    Microsoft SQL Server Compact 3.5 SP2 x64 ENU (Version: 3.5.8080.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (x32 Version: 11.0.51106.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
    Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Mozilla Firefox 26.0 (x86 en-US) (x32 Version: 26.0 - Mozilla)
    Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla)
    MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
    MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
    MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
    MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
    Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Qualcomm Atheros Driver Installation Program (x32 Version: 10.0 - Qualcomm Atheros)
    Ralink RT2870 Wireless LAN Card (x32 Version: 1.5.6.0 - Ralink)
    Realtek Ethernet Controller Driver (x32 Version: 8.15.410.2013 - Realtek)
    Realtek High Definition Audio Driver (x32 Version: 6.0.1.7027 - Realtek Semiconductor Corp.)
    Realtek PCIE Card Reader (x32 Version: 6.2.9200.28140 - Realtek Semiconductor Corp.)
    Recovery Manager (x32 Version: 5.5.0.6208 - CyberLink Corp.) Hidden
    Revo Uninstaller 1.95 (x32 Version: 1.95 - VS Revo Group)
    SolSuite 2013 v13.11 (x32 Version: 13.11 - TreeCardGames)
    Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation)
    Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Mail (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Messenger (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live MIME IFilter (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Writer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Windows Live Writer Resources (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    WordWeb (x32 Version: 7 - WordWeb Software)

    ==================== Restore Points =========================

    23-01-2014 16:14:47 Scheduled Checkpoint
    30-01-2014 15:47:11 Removed Bonjour
    05-02-2014 13:21:20 HPSF Restore Point

    ==================== Hosts content: ==========================

    2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

    ==================== Scheduled Tasks (whitelisted) =============

    Task: {04846BE4-86C0-407A-9CDF-844AF9E2E1CE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
    Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
    Task: {167F9A1A-6E0D-4FE5-A6BB-B002D137BB9F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
    Task: {26AC5145-9371-408D-8362-04DDA685EA55} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-01-15] (Microsoft Corporation)
    Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
    Task: {34E3146F-068A-47B4-892C-F4F97BBDEFE2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd)
    Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
    Task: {360CAAA7-E62A-4560-AD68-AA38120C1F2D} - System32\Tasks\CLMLSvc_P2G8 => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-03-12] (CyberLink)
    Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
    Task: {3D3A41D4-FF8F-45D7-9AF9-1DC377E0B062} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe
    Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
    Task: {5102A6E5-B510-4BB3-9859-AB13BFF5505E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {52759B28-1025-4E63-9A38-C125B95A3E89} - System32\Tasks\HPCeeScheduleForPatszy => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
    Task: {69A6CC67-2397-417C-B153-3A2E00A81DB0} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
    Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
    Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
    Task: {6FC109CB-2AFB-446C-938F-BBC3DED67FBF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-19] (Google Inc.)
    Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
    Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
    Task: {82F1C1F0-DD88-49B9-82BC-CC10A00C8DC5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-12-12] (Hewlett-Packard Company)
    Task: {84C9D834-9615-4C98-A365-D3646D5E8FA6} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe
    Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
    Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
    Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
    Task: {A2E2852E-B2A4-4C0A-8F3A-4812840A6442} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-04] (Adobe Systems Incorporated)
    Task: {A7967E63-9063-451A-960C-5EADB487B91D} - System32\Tasks\BackgroundContainer Startup Task => Rundll32.exe "C:\Users\Patszy\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
    Task: {AF72767F-7F2F-47E3-8786-C5D3EA31C319} - System32\Tasks\CLVDLauncher => c:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.)
    Task: {C80478D6-9871-48A7-BEDD-B51A0543C44D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard)
    Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
    Task: {D33F9668-2E0E-43CD-AD72-09B708FED0C8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-19] (Google Inc.)
    Task: {D42842F2-36F6-4890-AAD2-77A4C610DB92} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
    Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
    Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
    Task: {E49D94EB-6ABB-4F49-992F-F7EAC7F35CB2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard)
    Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
    Task: {F348113B-8418-4F39-96FC-5F919B03B3EC} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe
    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\HPCeeScheduleForPatszy.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

    ==================== Loaded Modules (whitelisted) =============

    2013-12-06 23:04 - 2013-12-06 23:05 - 00183808 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\ErrorReporting.dll
    2013-01-22 17:50 - 2013-01-22 17:50 - 00098304 _____ () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\BrandingNet4.dll
    2013-12-09 12:54 - 2009-12-10 11:16 - 00918816 _____ () C:\Program Files (x86)\Ralink\Common\RaWLAPI.dll
    2013-07-25 00:18 - 2013-03-12 09:51 - 00626240 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
    2013-03-13 00:53 - 2013-03-13 00:53 - 00015424 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll

    ==================== Alternate Data Streams (whitelisted) =========

    AlternateDataStreams: C:\Users\Patszy\SkyDrive:ms-properties
    AlternateDataStreams: C:\Users\Rod\SkyDrive:ms-properties

    ==================== Safe Mode (whitelisted) ===================


    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 1656

    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 1656

    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (02/09/2014 03:12:55 PM) (Source: Customer Experience Improvement Program) (User: )
    Description: 80070005

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 1484

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 1484

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second


    System errors:
    =============
    Error: (02/10/2014 00:55:01 PM) (Source: Service Control Manager) (User: )
    Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 3 time(s).

    Error: (02/10/2014 00:22:27 PM) (Source: Service Control Manager) (User: )
    Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 2 time(s).

    Error: (02/10/2014 10:13:43 AM) (Source: Service Control Manager) (User: )
    Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (02/10/2014 10:00:00 AM) (Source: DCOM) (User: NT AUTHORITY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable

    Error: (02/10/2014 07:57:31 AM) (Source: DCOM) (User: NT AUTHORITY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable

    Error: (02/09/2014 09:45:10 PM) (Source: Service Control Manager) (User: )
    Description: The Superfetch service terminated with the following error:
    %%1062

    Error: (02/09/2014 02:40:44 PM) (Source: Service Control Manager) (User: )
    Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (02/09/2014 02:24:08 PM) (Source: DCOM) (User: HP)
    Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

    Error: (02/09/2014 02:23:38 PM) (Source: DCOM) (User: HP)
    Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

    Error: (02/09/2014 02:12:28 PM) (Source: DCOM) (User: NT AUTHORITY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable


    Microsoft Office Sessions:
    =========================
    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 1656

    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 1656

    Error: (02/10/2014 00:22:28 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (02/09/2014 03:12:55 PM) (Source: Customer Experience Improvement Program)(User: )
    Description: 80070005

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 1484

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 1484

    Error: (02/09/2014 02:40:46 PM) (Source: Bonjour Service)(User: )
    Description: Task Scheduling Error: Continuously busy for more than a second


    CodeIntegrity Errors:
    ===================================
    Date: 2014-02-07 11:46:24.370
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2014-02-07 11:46:24.292
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.


    ==================== Memory info ===========================

    Percentage of memory in use: 16%
    Total physical RAM: 5717.25 MB
    Available physical RAM: 4786.74 MB
    Total Pagefile: 6677.25 MB
    Available Pagefile: 5387.2 MB
    Total Virtual: 131072 MB
    Available Virtual: 131071.77 MB

    ==================== Drives ================================

    Drive c: (Windows) (Fixed) (Total:446.17 GB) (Free:368.71 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive d: (Recovery Image) (Fixed) (Total:17.77 GB) (Free:2.17 GB) NTFS ==>[System with boot components (obtained from reading drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 466 GB) (Disk ID: 1F5A0FEE)

    Partition: GPT Partition Type
    ==================== End Of Log ============================
    n:
     
  4. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi patszy

    That makes you the same age as my mother. :)

    I understand what you are saying.
    This does happen from time to time with some of the tools we use.
    Usually it's because of how the tools work.... Windows and other security programs don't always like other programs delving into the depths.

    If you didn't install Bonjour for Windows manually, the most likely reason is that it was installed by an application that relies on Bonjour functionality.
    This is normally installed along with ITunes and Safari, but other programs do use it.
    If there are no installed programs reliant on it, it can be safely deleted.
    I see you already removed it.
    We can cleanup any leftovers later with a script.

    No not yet.
    A lot of those errors actually look a lot worse than they are.
    Some will be fixed later in the fix script.

    Did this come pre-installed on the system? and i take it you have subsequently removed it?

    Yes, the file causing the problem is showing in the report and is easily removed.

    Now before i can write a fix script for you, i need something else.......
    I need the main FRST report.
    Unfortunately you posted the additions report twice.
    You will find a copy here: ..... C:\Users\Patszy\Pictures ...(slap wrist for not downloading to the Desktop)
    The main FRST report will give a lot more information than the additions .txt ..... so i can't write a complete fix script without seeing that report.

    Any questions just shout out .... it's the best way of learning.

    Thanks
     
  5. patszy

    patszy Registered Members

    Joined:
    Aug 1, 2010
    Messages:
    181
    Location:
    USA
    Operating System:
    Windows 8
    Oh my....I don't know how that happened! But I guess it DID!!! That is the second mistake I made today. I FORGOT to disable my security!! Could not believe that, but don't think it hurt anything.

    Here is the report from the first scan:


    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-02-2014 02
    Ran by Patszy (administrator) on HP on 10-02-2014 14:02:37
    Running from C:\Users\Patszy\Pictures
    Windows 8.1 (X64) OS Language: English(US)
    Internet Explorer Version 11
    Boot Mode: Normal

    The only official download link for FRST:
    Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
    Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
    Download link from any site other than Bleeping Computer is unpermitted or outdated.
    See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (AMD) C:\WINDOWS\system32\atiesrxx.exe
    (AMD) C:\WINDOWS\system32\atieclxx.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
    (Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
    (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
    (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\LiveComm.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe
    (CyberLink) c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
    (Advanced Micro Devices Inc.) c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    (CyberLink) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
    (Microsoft Corporation) C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    (CyberLink) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe


    ==================== Registry (Whitelisted) ==================

    HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7198424 2013-08-29] (Realtek Semiconductor)
    HKLM-x32\...\Run: [StartCCC] - c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
    HKLM\...\RunOnce: [NCPluginUpdater] - "c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\NCPluginUpdater.exe" Update [21720 2014-01-28] (Hewlett-Packard)
    HKU\S-1-5-21-2805105478-1137937053-1898553863-1001\...\Run: [WordWeb] - C:\Program Files (x86)\WordWeb\wweb32.exe [77056 2013-05-17] (WordWeb Software)

    ==================== Internet (Whitelisted) ====================

    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK13/1
    SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS
    SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS
    SearchScopes: HKLM - {188DABF3-60D8-416A-B44E-B10870FB78BC} URL = http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}
    SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
    SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS
    SearchScopes: HKCU - {188DABF3-60D8-416A-B44E-B10870FB78BC} URL =
    SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
    BHO: LastPass Vault - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll (LastPass)
    BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
    BHO-x32: LastPass Vault - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll (LastPass)
    BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
    Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll (LastPass)
    Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll (LastPass)
    Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76

    FireFox:
    ========
    FF ProfilePath: C:\Users\Patszy\AppData\Roaming\Mozilla\Firefox\Profiles\0i4tzmm4.default
    FF Homepage: hxxp://thundercloud.net/start/
    FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
    FF Plugin: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass64.dll (LastPass)
    FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
    FF Plugin-x32: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass)
    FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin HKCU: hp.com/HPDetect - C:\Users\Patszy\AppData\Roaming\HewlettPackard\HPDetect\1.0.0.0\npHPDetect.dll (HP)
    FF Extension: LastPass - C:\Users\Patszy\AppData\Roaming\Mozilla\Firefox\Profiles\0i4tzmm4.default\Extensions\support@lastpass.com [2013-12-12]
    FF Extension: eCleaner - C:\Users\Patszy\AppData\Roaming\Mozilla\Firefox\Profiles\0i4tzmm4.default\Extensions\{c72c0c73-4eb0-4fb3-af0f-074e97326cfd}.xpi [2013-12-29]
    FF Extension: Adblock Plus - C:\Users\Patszy\AppData\Roaming\Mozilla\Firefox\Profiles\0i4tzmm4.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-13]
    FF HKCU\...\FIREFOX\Extensions: [wcapturex@deskperience.com] - C:\Program Files (x86)\WordWeb\WCaptureMoz
    FF Extension: WordWeb one-click lookup - C:\Program Files (x86)\WordWeb\WCaptureMoz [2013-12-05]

    Chrome:
    =======
    CHR HomePage: https://www.google.com/
    CHR Extension: (Mahjong Words 2) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\akoaibgodkfmengiiainfdbjmmamfall [2013-12-05]
    CHR Extension: (Docs) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-05]
    CHR Extension: (Google Drive) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-05]
    CHR Extension: (YouTube) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-05]
    CHR Extension: (Adblock Plus) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-01-17]
    CHR Extension: (Google Search) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-05]
    CHR Extension: (Email this page (by Google)) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbeoemfhkdniadbojeencpkgmobndpai [2013-12-05]
    CHR Extension: (AdBlock) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-05]
    CHR Extension: (LastPass) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2013-12-05]
    CHR Extension: (Mahjong Words) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmefkohhpkdnaieghlijadogfapogebe [2013-12-05]
    CHR Extension: (Mahjong Solitaire) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\neojceinbonpjjcokpokpeobkhcpiloc [2013-12-05]
    CHR Extension: (Google Wallet) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-05]
    CHR Extension: (Gmail) - C:\Users\Patszy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-05]
    CHR HKCU\...\Chrome\Extension: [gahpidfnpjlikfplofgcckpplbhopgpp] - C:\Users\Patszy\AppData\Local\CRE\gahpidfnpjlikfplofgcckpplbhopgpp.crx [2013-12-05]
    CHR HKLM-x32\...\Chrome\Extension: [gahpidfnpjlikfplofgcckpplbhopgpp] - C:\Users\Patszy\AppData\Local\CRE\gahpidfnpjlikfplofgcckpplbhopgpp.crx [2013-12-05]
    CHR HKLM-x32\...\Chrome\Extension: [mjdepfkicdcciagbigfcmdhknnoaaegf] - C:\Program Files (x86)\WordWeb\wcxChrome.crx [2013-12-05]

    ==================== Services (Whitelisted) =================

    R2 CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-09-26] (CyberLink)
    R2 CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-09-26] (CyberLink)
    R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [46904 2013-12-17] (Hewlett-Packard Company)
    R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [289496 2013-08-29] (Realtek Semiconductor)
    S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-12-05] (Microsoft Corporation)
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
    S2 BingDesktopUpdate; "C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe" [X]

    ==================== Drivers (Whitelisted) ====================

    S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
    S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Windows (R) Win 7 DDK provider)
    R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-15] (CyberLink)
    S3 CpqDfw; C:\Windows\System32\drivers\CpqDfw.sys [27456 2012-05-29] (Windows (R) Codename Longhorn DDK provider)
    S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
    S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
    S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-09] (Intel Corporation)
    R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-10] (Microsoft Corporation)
    S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
    R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
    S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
    S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
    R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [1975000 2013-07-31] (Realtek Semiconductor Corporation )
    S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-25] (Microsoft Corporation)
    S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-12-05] (Microsoft Corporation)
    S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)

    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2014-02-10 14:02 - 2014-02-10 14:02 - 00000000 ____D () C:\FRST
    2014-02-09 13:46 - 2014-02-09 13:46 - 00000000 ____D () C:\WINDOWS\ERUNT
    2014-02-08 19:28 - 2014-02-08 19:28 - 00005704 _____ () C:\WINDOWS\PFRO.log
    2014-02-08 19:17 - 2014-02-08 19:26 - 00000000 ____D () C:\AdwCleaner
    2014-02-07 11:45 - 2014-02-07 11:45 - 00001916 _____ () C:\Users\Patszy\Desktop\FolderMagic.lnk
    2014-02-07 11:44 - 2014-02-07 11:44 - 02830799 _____ (Cloudeight Internet, LLC. ) C:\Users\Patszy\Downloads\foldermagic20.exe
    2014-02-06 12:02 - 2014-02-10 13:55 - 00543156 _____ () C:\WINDOWS\WindowsUpdate.log
    2014-02-05 11:22 - 2014-02-05 11:22 - 00000000 ____D () C:\Users\Patszy\Documents\Avatar
    2014-02-05 08:32 - 2014-02-05 08:58 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp
    2014-01-30 14:17 - 2014-01-30 14:17 - 00000000 ____D () C:\Users\Patszy\AppData\Roaming\HewlettPackard
    2014-01-30 14:12 - 2014-01-30 14:12 - 00000000 ____D () C:\Program Files (x86)\Hp
    2014-01-30 08:36 - 2014-02-01 18:48 - 00167936 ___SH () C:\Users\Patszy\Desktop\Thumbs.db
    2014-01-17 11:41 - 2014-01-17 11:41 - 04230093 _____ () C:\Users\Patszy\Downloads\lpchrome_win.crx
    2014-01-17 10:46 - 2014-01-17 10:49 - 00000000 ____D () C:\Program Files (x86)\LastPass
    2014-01-17 10:46 - 2014-01-17 10:46 - 00000000 ____D () C:\Users\Patszy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
    2014-01-16 16:48 - 2014-01-16 16:49 - 04645232 _____ (Piriform Ltd) C:\Users\Patszy\Downloads\ccsetup409.exe
    2014-01-16 10:15 - 2014-01-16 10:15 - 00000000 ____D () C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
    2014-01-15 17:57 - 2013-11-27 10:36 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
    2014-01-15 17:57 - 2013-11-27 03:48 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
    2014-01-15 17:57 - 2013-11-27 03:45 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll
    2014-01-15 17:57 - 2013-11-27 03:40 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
    2014-01-15 17:57 - 2013-11-27 03:17 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
    2014-01-15 17:57 - 2013-11-27 03:12 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
    2014-01-15 17:56 - 2013-12-08 19:15 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
    2014-01-15 17:56 - 2013-11-27 06:41 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe
    2014-01-15 17:56 - 2013-11-27 05:34 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll
    2014-01-15 17:56 - 2013-11-27 04:54 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll
    2014-01-15 17:56 - 2013-11-27 03:38 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll

    ==================== One Month Modified Files and Folders =======

    2014-02-10 14:02 - 2014-02-10 14:02 - 00000000 ____D () C:\FRST
    2014-02-10 14:02 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\system32\sru
    2014-02-10 13:55 - 2014-02-06 12:02 - 00543156 _____ () C:\WINDOWS\WindowsUpdate.log
    2014-02-10 12:20 - 2013-12-14 21:22 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
    2014-02-10 11:24 - 2013-12-19 20:13 - 00000916 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2014-02-10 08:02 - 2013-12-04 11:45 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2805105478-1137937053-1898553863-1001
    2014-02-10 07:59 - 2013-12-15 08:28 - 00003158 _____ () C:\WINDOWS\System32\Tasks\HPCeeScheduleForPatszy
    2014-02-10 07:59 - 2013-12-15 08:28 - 00000342 _____ () C:\WINDOWS\Tasks\HPCeeScheduleForPatszy.job
    2014-02-10 07:59 - 2013-12-10 09:19 - 00000052 _____ () C:\WINDOWS\SysWOW64\DOErrors.log
    2014-02-10 07:58 - 2013-12-10 09:30 - 00000000 _____ () C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
    2014-02-10 07:56 - 2013-09-29 23:04 - 00956476 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
    2014-02-10 07:51 - 2013-12-19 20:13 - 00000912 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2014-02-10 07:51 - 2013-08-22 09:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
    2014-02-09 21:45 - 2013-08-22 08:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
    2014-02-09 13:46 - 2014-02-09 13:46 - 00000000 ____D () C:\WINDOWS\ERUNT
    2014-02-08 19:28 - 2014-02-08 19:28 - 00005704 _____ () C:\WINDOWS\PFRO.log
    2014-02-08 19:26 - 2014-02-08 19:17 - 00000000 ____D () C:\AdwCleaner
    2014-02-08 11:44 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
    2014-02-08 11:37 - 2013-12-04 11:39 - 00003930 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{1E0BDA28-4994-4194-829E-3F8248959726}
    2014-02-08 10:00 - 2013-12-04 16:31 - 00000000 ____D () C:\Users\Patszy\Documents\Youcam
    2014-02-08 08:21 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
    2014-02-07 11:48 - 2013-12-09 07:46 - 00000000 ____D () C:\Program Files (x86)\FolderMagic
    2014-02-07 11:45 - 2014-02-07 11:45 - 00001916 _____ () C:\Users\Patszy\Desktop\FolderMagic.lnk
    2014-02-07 11:44 - 2014-02-07 11:44 - 02830799 _____ (Cloudeight Internet, LLC. ) C:\Users\Patszy\Downloads\foldermagic20.exe
    2014-02-05 11:22 - 2014-02-05 11:22 - 00000000 ____D () C:\Users\Patszy\Documents\Avatar
    2014-02-05 11:17 - 2013-07-25 00:36 - 00000000 ____D () C:\Users\Public\CyberLink
    2014-02-05 09:45 - 2013-12-08 15:04 - 00000000 ____D () C:\Users\Patszy\AppData\Roaming\SolSuite
    2014-02-05 08:58 - 2014-02-05 08:32 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp
    2014-02-05 08:57 - 2013-12-05 12:51 - 00000000 ____D () C:\WINDOWS\SysWOW64\RTCOM
    2014-02-04 14:21 - 2013-12-14 21:22 - 00003718 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
    2014-02-01 18:48 - 2014-01-30 08:36 - 00167936 ___SH () C:\Users\Patszy\Desktop\Thumbs.db
    2014-02-01 10:07 - 2013-12-05 18:43 - 00000000 ____D () C:\Users\Patszy\AppData\Local\Windows Live
    2014-01-31 14:03 - 2013-12-13 10:30 - 00000000 ___RD () C:\Users\Patszy\My DocumentsNew folder
    2014-01-31 12:54 - 2013-12-05 12:57 - 00000000 ____D () C:\Users\Patszy
    2014-01-30 19:00 - 2013-08-22 09:44 - 00428672 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
    2014-01-30 15:47 - 2013-08-22 10:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2014-01-30 15:47 - 2013-08-22 10:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2014-01-30 14:17 - 2014-01-30 14:17 - 00000000 ____D () C:\Users\Patszy\AppData\Roaming\HewlettPackard
    2014-01-30 14:12 - 2014-01-30 14:12 - 00000000 ____D () C:\Program Files (x86)\Hp
    2014-01-30 10:52 - 2013-12-11 21:33 - 00000000 ____D () C:\ProgramData\HitmanPro
    2014-01-25 21:21 - 2013-12-04 11:36 - 00000000 ____D () C:\Users\Patszy\AppData\Local\Packages
    2014-01-23 11:08 - 2013-12-04 16:33 - 00000000 ____D () C:\Users\Patszy\AppData\Local\HP Quick Start
    2014-01-19 02:38 - 2013-12-11 22:32 - 00270496 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
    2014-01-17 11:41 - 2014-01-17 11:41 - 04230093 _____ () C:\Users\Patszy\Downloads\lpchrome_win.crx
    2014-01-17 10:49 - 2014-01-17 10:46 - 00000000 ____D () C:\Program Files (x86)\LastPass
    2014-01-17 10:46 - 2014-01-17 10:46 - 00000000 ____D () C:\Users\Patszy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
    2014-01-16 16:51 - 2013-12-11 22:43 - 00000000 ____D () C:\Program Files\CCleaner
    2014-01-16 16:49 - 2014-01-16 16:48 - 04645232 _____ (Piriform Ltd) C:\Users\Patszy\Downloads\ccsetup409.exe
    2014-01-16 16:43 - 2013-12-06 08:00 - 00000000 __RDO () C:\Users\Patszy\SkyDrive
    2014-01-16 10:18 - 2013-07-25 00:04 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
    2014-01-16 10:17 - 2013-07-25 00:02 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
    2014-01-16 10:15 - 2014-01-16 10:15 - 00000000 ____D () C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
    2014-01-16 10:14 - 2013-12-04 15:45 - 00000000 ____D () C:\Users\Patszy\AppData\Roaming\hpqlog
    2014-01-16 10:14 - 2013-07-25 00:04 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
    2014-01-16 10:14 - 2013-04-10 14:20 - 00000000 ____D () C:\SWSETUP
    2014-01-15 20:12 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\WinStore
    2014-01-15 18:22 - 2013-12-07 06:10 - 00000000 ____D () C:\WINDOWS\system32\MRT
    2014-01-15 18:18 - 2013-12-07 06:10 - 86054176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

    ==================== Bamital & volsnap Check =================

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


    LastRegBack: 2014-02-10 09:05

    ==================== End Of Log ==========================

    Thank you so very much for all your valuable time. I feel terrible taking so much of it though.
    Do things look BAD on my computer?
     
  6. patszy

    patszy Registered Members

    Joined:
    Aug 1, 2010
    Messages:
    181
    Location:
    USA
    Operating System:
    Windows 8
    Yes, Norton came preinstalled and I uninstalled it very soon after I got the computer. Have never wanted it or McAfee.
     
  7. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi patszy

    No things don't look too bad at all.
    Just a few things to tidy up.

    It's no problem at all, just glad i can be of service.

    That doesn't matter too much when running FRST.
    JRT does require security programs to be stopped ..... but not all of our tools do.


    Step 1
    Please click on the attached fixlist.txt file (bottom of this post) click Save and save it to ....C:\Users\Patszy\Pictures.
    NOTE.
    It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine.
    Running this on another machine may cause damage to your operating system


    Re-run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post this in your next reply.


    Step 2
    Download TFC by OldTimer to your desktop
    • Please double-click TFC.exe to run it. (Note: If you are running on Vista/Win7 or Win8, right-click on the file and choose Run As Administrator).
    • It will close all programs when run, so make sure you have saved all your work before you begin.
    • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
    • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.


    In your next reply, please submit:
    Fixlog.txt
    and let me know how the system is running now.


    Thanks
     

    Attached Files:

  8. patszy

    patszy Registered Members

    Joined:
    Aug 1, 2010
    Messages:
    181
    Location:
    USA
    Operating System:
    Windows 8
    Hello....
    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-02-2014 01
    Ran by Patszy at 2014-02-10 21:12:17 Run:1
    Running from C:\Users\Patszy\Pictures
    Boot Mode: Normal
    ==============================================

    Content of fixlist:
    *****************
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    SearchScopes: HKCU - {188DABF3-60D8-416A-B44E-B10870FB78BC} URL =
    SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
    Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    Task: {3D3A41D4-FF8F-45D7-9AF9-1DC377E0B062} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe
    Task: {84C9D834-9615-4C98-A365-D3646D5E8FA6} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe
    Task: {A7967E63-9063-451A-960C-5EADB487B91D} - System32\Tasks\BackgroundContainer Startup Task => Rundll32.exe "C:\Users\Patszy\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
    Task: {F348113B-8418-4F39-96FC-5F919B03B3EC} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe
    C:\Program Files (x86)\Norton Internet Security
    C:\Users\Patszy\AppData\Local\Conduit
    C:\Program Files\Bonjour

    *****************

    [1604] C:\Program Files\Bonjour\mDNSResponder.exe => Process closed successfully.
    HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{188DABF3-60D8-416A-B44E-B10870FB78BC} => Key deleted successfully.
    HKCR\CLSID\{188DABF3-60D8-416A-B44E-B10870FB78BC} => Key not found.
    HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => Key deleted successfully.
    HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => Key not found.
    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value deleted successfully.
    HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3D3A41D4-FF8F-45D7-9AF9-1DC377E0B062} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D3A41D4-FF8F-45D7-9AF9-1DC377E0B062} => Error deleting key
    C:\Windows\System32\Tasks\Norton Internet Security\Norton Error Processor => Moved successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security\Norton Error Processor => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{84C9D834-9615-4C98-A365-D3646D5E8FA6} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{84C9D834-9615-4C98-A365-D3646D5E8FA6} => Error deleting key
    C:\Windows\System32\Tasks\Norton WSC Integration => Moved successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton WSC Integration => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A7967E63-9063-451A-960C-5EADB487B91D} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7967E63-9063-451A-960C-5EADB487B91D} => Error deleting key
    C:\Windows\System32\Tasks\BackgroundContainer Startup Task => Moved successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BackgroundContainer Startup Task => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F348113B-8418-4F39-96FC-5F919B03B3EC} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F348113B-8418-4F39-96FC-5F919B03B3EC} => Error deleting key
    C:\Windows\System32\Tasks\Norton Internet Security\Norton Error Analyzer => Moved successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security\Norton Error Analyzer => Error deleting key
    "C:\Program Files (x86)\Norton Internet Security" => File/Directory not found.
    "C:\Users\Patszy\AppData\Local\Conduit" => File/Directory not found.
    C:\Program Files\Bonjour => Moved successfully.

    ==== End of Fixlog ====
     
  9. patszy

    patszy Registered Members

    Joined:
    Aug 1, 2010
    Messages:
    181
    Location:
    USA
    Operating System:
    Windows 8
    Wow!! You are a genius!!
    When I rebooted, that nasty Run DLL was GONE!!!!
    When I saw above, there at the end, it said File/Directory not found I thought maybe it was still hidden in there somewhere.

    Well, again I thank you so VERY MUCH for all your time and expertise. I was beginning to think I would never get rid of that window when I turn the computer on. I really really appreciate all your efforts.

    30ec590365eed2fc45e4200f1f23f299.gif
    Pat
     
  10. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi patszy

    Glad we managed to get the problem sorted for you.

    What was missing was the.dll file that the startup task was trying to run.
    This was the task that was trying to start it...... the problem was that because the .dll file was missing the task couldn't start it.
    So we removed the task and double checked that the folder that the file was in, was also removed.
    If all that makes sense. :)

    We should really cleanup the tools we used now.

    Step 1
    Restart MalwareBytes AntiMalware.
    Click on the Quarantine tab

    b98d8f9bf07306db6b7853c64ae04fae.png

    If there are items in quarantine.....
    Make sure everything is selected and then click Delete All.
    Close MBAM.


    Step 2
    Click on AdwCleaner.exe to run the tool again.
    • Click on the Uninstall button.
    • Click Yes when asked are you sure you want to uninstall.
    • Both AdwCleaner.exe, its folder and all logs will be removed.

    JRT and FRST can now be removed also. (right click on each program and the report files and select delete.)

    Hitman Pro
    If you are going to use the 'paid for' version then by all means leave it on the system.
    If you are only using it as the free version i recommend that you uninstall the program.
    It's only a 30 day trial and shouldn't be needed again.

    You may find this an interesting read:
    How Malware Spreads

    Glad I was able to help.
    Take care and keep enjoying the computer.

    Safe surfing. 200636f9a90a19cb85ecf0ba93831af6.gif
     
  11. patszy

    patszy Registered Members

    Joined:
    Aug 1, 2010
    Messages:
    181
    Location:
    USA
    Operating System:
    Windows 8
    THANK YOU!!!
    It was a joy to boot up this morning and NOT see that file.
    I immediately did a scan with Malwarebytes. It found nothing.
    Have followed your very clear directions and have cleaned up everything.
    Concerning Hit Man Pro....I bought it when the free time was up. The person who originally helped me when I had the infection said that was the only program she buys....she thinks it is that good. So, I bought it. I could have Norton free with my Comcast subscription but have been under the impression that it was to be avoided. I don't usually buy programs. I have SuperAntiSpyware and Spyware Blaster on other computer, and husbands,
    I will continue to read on this forum and follow your suggestions.
    I don't like to trust anyone to fix my computers, so it was great to do it with your help!!
     
  12. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    :woohooo:

    It's certainly not a program that i would recommend.

    Having a go yourself ( under supervision) is always a great way to learn things.
     
  13. patszy

    patszy Registered Members

    Joined:
    Aug 1, 2010
    Messages:
    181
    Location:
    USA
    Operating System:
    Windows 8
    Glad to hear that you agree about Norton.

    Thanks for all....a great forum....a great service!!
     

Share This Page