Hi dbreeze,
txs in advanced here is the frst.txt and addition.txt in my reply
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-01-2015
Ran by space_000 (administrator) on APP4 on 23-01-2015 21:47:24
Running from C:\Users\space_000\Downloads
Loaded Profiles: space_000 (Available profiles: space_000 & space_001 & kaya)
Platform: Microsoft Windows 8.1 Pro (X86) OS Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x86__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [spc1030] => C:\WINDOWS\vspc1030.exe [684032 2008-02-22] (Sonix)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS5ServiceManager] => C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated)
HKLM\...\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2012-06-28] (Nullsoft, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [kX Mixer] => C:\Program Files\kX Project\kxmixer.exe [418888 2010-12-18] (Eugene Gavrilov)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [1797064 2014-03-20] (NVIDIA Corporation)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-1392353723-3194137103-1205734640-1005\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1392353723-3194137103-1205734640-1005\...\RunOnce: [Application Restart #0] => C:\Program Files\Google\Chrome\Application\chrome.exe [843592 2015-01-21] (Google Inc.)
AppInit_DLLs: C:\PROGRA~1\NVIDIA~1\3DVISI~1\nvStInit.dll => C:\PROGRA~1\NVIDIA~1\3DVISI~1\nvStInit.dll File Not Found
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1392353723-3194137103-1205734640-1005\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://t.uk.msn.com/
SearchScopes: HKLM -> DefaultScope value is missing.
SearchScopes: HKU\S-1-5-21-1392353723-3194137103-1205734640-1005 -> {09C7CD9E-A87F-49F2-8F55-A3C83B809686} URL = http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10853
SearchScopes: HKU\S-1-5-21-1392353723-3194137103-1205734640-1005 -> {727502AC-766B-4DD7-8B98-5BFB6204DAE4} URL = http://search.findwide.com/serp?guid={9C873C8B-A9E3-42BA-8BE5-510E8B369DCD}&action=default_search&serpv=22&k={searchTerms}
BHO: ContributeBHO Class -> {074C1DC5-9320-4A9A-947D-C042949C6216} -> C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 212.54.40.25 212.54.44.54
FireFox:
========
FF ProfilePath: C:\Users\space_000\AppData\Roaming\Mozilla\Firefox\Profiles\5hw3tm02.default
FF NewTab:
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_287.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\space_000\AppData\Roaming\Mozilla\Firefox\Profiles\5hw3tm02.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF Extension: Freecorder - C:\Users\space_000\AppData\Roaming\Mozilla\Firefox\Profiles\5hw3tm02.default\Extensions\
[email protected] [2014-10-21]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-10-03]
FF HKLM\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
FF Extension: Adobe Contribute Toolbar - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2013-01-29]
Chrome:
=======
CHR Profile: C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-02-13]
CHR Extension: (Google Drive) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-06]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-23]
CHR Extension: (YouTube) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-06]
CHR Extension: (Firebug Lite for Google Chrome) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmagokdooijbeehmkpknfglimnifench [2013-03-06]
CHR Extension: (Adblock Plus) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-03-06]
CHR Extension: (Google Search) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-06]
CHR Extension: (Internet Radio Recorder) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\dakcgnkeibbhgbmjpneeaengmfndgimf [2014-10-21]
CHR Extension: (WAV Player for GMail™

- C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifjdgcbahemgdkfjihbcoidnmnjjnhoo [2014-08-19]
CHR Extension: (Drupal for Chrome) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\imlijcpfmhmifofiihbofoamohkdbblc [2013-03-06]
CHR Extension: (Media Player) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjhemcahlhoapagccjbikfkbdfnpjgie [2014-08-19]
CHR Extension: (SoundCloud Mix My Trip) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdndaifgbnhjefbblkjjneeaebocaf [2013-06-11]
CHR Extension: (Skype Click to Call) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-07-20]
CHR Extension: (Mixcloud Downloader - Technowise) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpegpbkoopngdajnepdppcbnahimaaf [2013-06-11]
CHR Extension: (Google Wallet) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (ScriptSafe) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiigbmnaadbkfbmpbfijlflahbdbdgdf [2013-03-06]
CHR Extension: (Gmail) - C:\Users\space_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-06]
CHR HKLM\...\Chrome\Extension: [gpicboiclhmnllnjdcfcffifpoaebgkm] - C:\Program Files\Freecorder extension\Freecorder.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 RapportMgmtService; C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe [1919256 2014-12-22] (IBM Corp.)
S3 ScDeviceEnum; C:\WINDOWS\System32\ScDeviceEnum.dll [105472 2013-08-22] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [288128 2014-09-22] (Microsoft Corporation)
S3 WEPHOSTSVC; C:\WINDOWS\system32\wephostsvc.dll [20992 2013-08-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22192 2014-09-22] (Microsoft Corporation)
S3 workfolderssvc; C:\WINDOWS\system32\workfolderssvc.dll [1222144 2014-07-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [25600 2014-02-22] (Microsoft Corporation)
S3 GPIO; C:\WINDOWS\System32\drivers\iaiogpio.sys [22016 2013-07-23] (Intel Corporation)
R3 kxwdmdrv; C:\WINDOWS\system32\drivers\kx.sys [445512 2010-12-18] (Eugene Gavrilov)
R1 MpKsldececaa4; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{95BC30DF-21FB-4745-B392-2BDC5F2C4098}\MpKsldececaa4.sys [39464 2015-01-23] (Microsoft Corporation)
S3 netr28u; C:\WINDOWS\system32\DRIVERS\netr28u.sys [1696528 2013-06-18] (Ralink Technology Corp.)
R3 phaudlwr; C:\WINDOWS\system32\DRIVERS\phaudlwr.sys [89648 2009-10-20] (Philips Applied Technologies)
R1 RapportCerberus_80120; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_80120.sys [472792 2015-01-15] (IBM Corp.)
R1 RapportEI; C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys [251640 2014-12-22] (IBM Corp.)
R0 RapportKELL; C:\WINDOWS\System32\Drivers\RapportKELL.sys [208856 2014-12-22] (IBM Corp.)
R1 RapportPG; C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys [332696 2014-12-22] (IBM Corp.)
R3 SPC1030; C:\WINDOWS\system32\DRIVERS\spc1030.sys [3035776 2008-06-11] ()
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [84800 2014-09-22] (Microsoft Corporation)
R0 Wof; C:\WINDOWS\system32\Drivers\Wof.sys [138584 2014-03-13] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [188416 2014-05-31] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-23 21:47 - 2015-01-23 21:48 - 00016247 _____ () C:\Users\space_000\Downloads\FRST.txt
2015-01-23 21:46 - 2015-01-23 21:47 - 00000000 ____D () C:\FRST
2015-01-23 21:46 - 2015-01-23 21:46 - 01118208 _____ (Farbar) C:\Users\space_000\Downloads\FRST.exe
2015-01-20 08:40 - 2015-01-20 08:40 - 00509440 _____ (Tech Support Guy System) C:\Users\space_000\Downloads\SysInfo.exe
2015-01-17 13:22 - 2015-01-12 13:10 - 96213031 ____N () C:\Users\space_000\Desktop\KiNK Boiler Room Moscow Live Set.wma
2015-01-14 12:13 - 2014-12-12 02:34 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2015-01-14 12:13 - 2014-12-12 01:46 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-01-14 12:13 - 2014-12-09 04:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-01-14 12:13 - 2014-12-08 20:46 - 00485544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-01-14 12:13 - 2014-12-08 20:46 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-01-14 12:13 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-01-14 12:13 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2015-01-14 12:13 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2015-01-14 12:13 - 2014-12-06 03:36 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-01-14 12:13 - 2014-12-06 02:28 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-01-14 12:13 - 2014-12-06 02:23 - 00194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-01-14 12:13 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2015-01-14 12:13 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2015-01-14 12:13 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-01-14 12:13 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-01-14 12:13 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-01-14 12:13 - 2014-10-29 04:07 - 00213336 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-01-14 12:13 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-01-14 12:13 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2015-01-14 12:13 - 2014-10-29 01:49 - 00694272 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-01-14 12:12 - 2014-12-19 06:46 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2015-01-13 19:42 - 2015-01-22 19:42 - 03353776 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2015-01-07 17:58 - 2015-01-07 18:00 - 656134330 _____ () C:\Users\space_000\Downloads\unbroken Dub.wav
2015-01-07 15:12 - 2015-01-07 15:12 - 97501528 _____ () C:\Users\space_000\Downloads\KiNK Boiler Room Moscow Live Set.aac
2015-01-04 20:58 - 2015-01-04 21:04 - 00000000 ____D () C:\Users\space_000\Documents\passwords
2015-01-04 09:44 - 2015-01-04 09:44 - 00003108 _____ () C:\Users\space_000\Downloads\nebnvnf.htm
2014-12-26 10:31 - 2014-12-26 10:32 - 109829936 _____ (Apple Inc.) C:\Users\space_000\Downloads\iTunesSetup.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-23 21:42 - 2013-02-04 00:06 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-01-23 21:41 - 2013-08-22 08:23 - 00400463 _____ () C:\WINDOWS\setupact.log
2015-01-23 21:28 - 2013-10-27 01:41 - 01104825 _____ () C:\WINDOWS\WindowsUpdate.log
2015-01-23 21:02 - 2013-01-29 18:58 - 00000904 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-23 21:00 - 2013-08-22 09:17 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-01-23 06:34 - 2012-07-26 07:43 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-01-23 06:33 - 2013-08-22 09:17 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2015-01-23 04:04 - 2013-01-29 19:00 - 00002149 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-22 07:52 - 2013-08-22 09:17 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-01-22 07:44 - 2013-10-27 10:24 - 00000000 ___DO () C:\Users\space_000\SkyDrive
2015-01-22 07:42 - 2013-08-22 08:23 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-01-22 07:41 - 2013-11-16 08:29 - 00000000 ____D () C:\WINDOWS\Minidump
2015-01-22 07:41 - 2013-10-27 01:42 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-01-22 07:41 - 2013-01-23 08:27 - 00064000 ____N () C:\WINDOWS\Minidump\012215-27281-01.dmp
2015-01-21 21:47 - 2013-10-27 01:47 - 00000000 ____D () C:\Users\space_000
2015-01-20 21:56 - 2013-02-17 21:00 - 02803712 ___SH () C:\Users\space_000\Downloads\Thumbs.db
2015-01-20 10:28 - 2013-03-01 11:26 - 00000000 ____D () C:\Users\space_000\AppData\Roaming\Skype
2015-01-20 07:26 - 2014-10-03 19:58 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-01-20 07:16 - 2013-01-23 08:27 - 00064512 ____N () C:\WINDOWS\Minidump\012015-36968-01.dmp
2015-01-19 22:32 - 2014-12-12 00:10 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-01-19 22:32 - 2014-12-12 00:10 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-01-18 05:19 - 2013-08-13 20:20 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-01-18 05:03 - 2013-01-29 22:54 - 110348472 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-01-15 07:28 - 2013-09-15 02:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection
2015-01-14 23:07 - 2013-08-22 07:13 - 00786432 ___SH () C:\WINDOWS\system32\config\BBI
2015-01-07 11:06 - 2014-12-22 19:53 - 00000000 ____D () C:\Users\space_000\Desktop\BRITT
2015-01-07 10:14 - 2013-12-17 21:09 - 00000000 ____D () C:\Users\space_000\AppData\Roaming\Apple Computer
2015-01-06 01:03 - 2013-02-12 09:50 - 00000000 ____D () C:\Users\space_000\AppData\Local\PokerStars.EU
2015-01-03 16:39 - 2013-02-03 22:30 - 00000000 ____D () C:\Program Files\PokerStars.EU
2014-12-31 12:13 - 2013-01-29 22:56 - 00249488 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2014-12-31 08:37 - 2014-08-20 06:16 - 00000000 ____D () C:\Users\space_000\AppData\Local\Adobe
Some content of TEMP:
====================
C:\Users\space_000\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\space_000\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\space_000\AppData\Local\Temp\nvStInst.exe
C:\Users\space_000\AppData\Local\Temp\Quarantine.exe
C:\Users\space_000\AppData\Local\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-22 08:33
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-01-2015
Ran by space_000 at 2015-01-23 21:48:36
Running from C:\Users\space_000\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 2.7.1.19610 - Adobe Systems Incorporated)
Adobe Community Help (HKLM\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Creative Suite 5 Master Collection (HKLM\...\{FBB02B04-C034-4382-A3F6-57416E2752C4}) (Version: 5.0 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (HKLM\...\{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}) (Version: 10.1.52.14 - Adobe Systems, Inc.)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.287 - Adobe Systems Incorporated)
Adobe Media Player (HKLM\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Nederlands (HKLM\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{0592EF96-69D8-4E4B-9CC9-88F58EA86F01}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Cartes du Ciel (HKLM\...\Cartes du Ciel) (Version: - )
Data Lifeguard Diagnostic for Windows 1.27 (HKLM\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version: - Western Digital Corporation)
eMule (HKLM\...\eMule) (Version: - )
Full Tilt Poker.Eu (HKLM\...\{127BEFB3-24B2-4B44-8E99-AD22C2A5A8ED}) (Version: 4.55.4.WIN.FullTilt.EU - )
Google Chrome (HKLM\...\Google Chrome) (Version: 40.0.2214.91 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
iCloud (HKLM\...\{00A61104-74B5-4056-AD00-4397EF4FB141}) (Version: 3.1.0.40 - Apple Inc.)
iTunes (HKLM\...\{C197BC08-3D82-4651-8886-E68C21578A38}) (Version: 11.1.3.8 - Apple Inc.)
Java 7 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle)
Microsoft Flight Simulator X Demo (HKLM\...\InstallShield_{B98A34C0-A6A2-4087-B272-557C1C6D0A07}) (Version: 10.0.60905 - Microsoft Game Studios)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.1.177.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Monkey's Audio (HKLM\...\Monkey's Audio_is1) (Version: - )
Mozilla Firefox 32.0.2 (x86 nl) (HKLM\...\Mozilla Firefox 32.0.2 (x86 nl)) (Version: 32.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 Parser and SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Nero 12 (HKLM\...\{560FC78C-A4B2-461D-9B47-820C1EEF87B8}) (Version: 12.0.02000 - Nero AG)
NVIDIA 3D Vision Driver 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation)
NVIDIA Graphics Driver 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
PDF Settings CS5 (Version: 10.0 - Adobe Systems Incorporated) Hidden
Philips SPC1030NC Webcam (HKLM\...\{26216D96-B03D-4B8A-9979-D91C71241B70}) (Version: 1.00.000 - Philips)
PokerStars.eu (HKLM\...\PokerStars.eu) (Version: - PokerStars.eu)
Prerequisite installer (Version: 12.0.0002 - Nero AG) Hidden
PxMergeModule (Version: 1.00.0000 - Your Company Name) Hidden
QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Rapport (Version: 3.5.1404.61 - Trusteer) Hidden
SketchUp 2014 (HKLM\...\{A608A8D3-E77C-4BEE-8F2A-F8124F5F0FE2}) (Version: 14.0.4900 - Trimble Navigation Limited)
Skype Click to Call (HKLM\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Stellar Phoenix Windows Data Recovery - Home (HKLM\...\Stellar Phoenix Windows Data Recovery - Home_is1) (Version: 6.0.0.1 - Stellar Information Technology Pvt Ltd.)
Trusteer Endpoint Protection (HKLM\...\Rapport_msi) (Version: 3.5.1404.61 - Trusteer)
Welcome App (Start-up experience) (Version: 12.0.14000 - Nero AG) Hidden
Win32DiskImager version 0.9.5 (HKLM\...\{D074CE74-912A-4AD3-A0BF-3937D9D01F17}_is1) (Version: 0.9.5 - ImageWriter Developers)
Winamp (HKLM\...\Winamp) (Version: 5.63 - Nullsoft, Inc)
Windows Driver Package - Philips CL (phaudlwr) MEDIA (06/02/2008 1.0.5.12) (HKLM\...\10F7630C78CC9B1F315B5FA216ECB493C3ACD3E5) (Version: 06/02/2008 1.0.5.12 - Philips CL)
WinRAR 4.20 (32-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
06-01-2015 04:09:11 Scheduled Checkpoint
14-01-2015 12:43:42 Windows Update
18-01-2015 05:00:57 Windows Update
23-01-2015 06:31:34 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2012-07-26 05:17 - 2013-01-29 21:57 - 00000922 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {1A2E6441-2600-4B19-93B2-2E4E13C6CD16} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-01-18] (Microsoft Corporation)
Task: {262CCF92-24F8-4E66-9E28-DC42A79AD580} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-1392353723-3194137103-1205734640-1005
Task: {483C3109-95DD-41C3-8273-64F41DE9B593} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-29] (Google Inc.)
Task: {49D56676-8C1E-40EF-AB85-8A898632DF26} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-01-29] (Microsoft)
Task: {5846F25A-E302-4F47-A521-005F736E9B94} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation)
Task: {9CC40F64-FEF3-4B98-B60B-A19628775B2C} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-01-29] (Microsoft Corporation)
Task: {A2AC1CA4-450E-439A-889F-3D0F7752C68B} - System32\Tasks\{EEED71EE-9280-4909-808C-3453DF5A4082} => pcalua.exe -a D:\Autorun.exe -d D:\
Task: {AA2ADF7C-4959-43AE-B8B6-0B0106122466} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation)
Task: {B8890498-3346-4804-A4E3-E9AB2D357DCE} - System32\Tasks\YourFile DownloaderUpdate => C:\Program Files\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION
Task: {C499D60A-81C7-4B16-A425-55AF0CEB919B} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-22] (Adobe Systems Incorporated)
Task: {CBBAFB2C-0B8C-4894-9388-03765FEA0295} - System32\Tasks\{7F35B292-FE62-406C-8A09-F95F8B561997} => pcalua.exe -a C:\Users\space_000\AppData\Local\TNT2\2.0.0.1868\TNT2User.exe -c /UNINSTALL PARTNER=10853
Task: {E613D8AD-1BBA-4FDC-A975-4FF51F4D433F} - System32\Tasks\
[email protected] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)
Task: {EA44D983-85E0-443C-A45F-F33B568BB511} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-01-29] (Microsoft Corporation)
Task: {EE2E1016-4C70-431C-971A-9A67DE21C1AB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-29] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-10-27 01:41 - 2014-03-04 13:34 - 00109000 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2013-09-13 19:51 - 2013-09-13 19:51 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-09-13 19:51 - 2013-09-13 19:51 - 01242952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-23 04:03 - 2015-01-21 04:50 - 01117512 _____ () C:\Program Files\Google\Chrome\Application\40.0.2214.91\libglesv2.dll
2015-01-23 04:03 - 2015-01-21 04:50 - 00211272 _____ () C:\Program Files\Google\Chrome\Application\40.0.2214.91\libegl.dll
2015-01-23 04:03 - 2015-01-21 04:50 - 09171272 _____ () C:\Program Files\Google\Chrome\Application\40.0.2214.91\pdf.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Users\space_000\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\space_001.APP4.004\SkyDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\Run: => "AdobeCS5ServiceManager"
HKLM\...\StartupApproved\Run: => "Adobe ARM"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run: => "SwitchBoard"
HKLM\...\StartupApproved\Run: => "WinampAgent"
HKLM\...\StartupApproved\Run: => "APSDaemon"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run: => "QuickTime Task"
HKU\S-1-5-21-1392353723-3194137103-1205734640-1005\...\StartupApproved\Run: => "ApplePhotoStreams"
========================= Accounts: ==========================
Administrator (S-1-5-21-1392353723-3194137103-1205734640-500 - Administrator - Disabled)
Guest (S-1-5-21-1392353723-3194137103-1205734640-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1392353723-3194137103-1205734640-1007 - Limited - Enabled)
kaya (S-1-5-21-1392353723-3194137103-1205734640-1009 - Limited - Enabled) => C:\Users\kaya
space_000 (S-1-5-21-1392353723-3194137103-1205734640-1005 - Administrator - Enabled) => C:\Users\space_000
space_001 (S-1-5-21-1392353723-3194137103-1205734640-1008 - Administrator - Enabled) => C:\Users\space_001.APP4.004
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/23/2015 06:39:30 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/23/2015 06:39:30 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/23/2015 06:39:30 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/23/2015 06:39:30 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/23/2015 06:39:30 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/23/2015 06:39:29 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/23/2015 06:39:29 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/23/2015 06:39:29 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/23/2015 06:39:28 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/23/2015 06:39:28 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.
System errors:
=============
Error: (01/22/2015 07:56:55 AM) (Source: DCOM) (EventID: 10010) (User: APP4)
Description: Windows.Store
Error: (01/22/2015 07:41:10 AM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
Description: 32212254735864588865492316
Error: (01/22/2015 07:41:52 AM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x000000a0 (0x00000107, 0x0000000a, 0x8a3c8ee0, 0x00000000)C:\WINDOWS\Minidump\012215-27281-01.dmp012215-27281-01
Error: (01/22/2015 07:41:51 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 21:16:46 on ‎21/‎01/‎2015 was unexpected.
Error: (01/21/2015 09:47:53 PM) (Source: DCOM) (EventID: 10010) (User: APP4)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (01/21/2015 09:47:53 PM) (Source: DCOM) (EventID: 10010) (User: APP4)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (01/21/2015 09:47:53 PM) (Source: DCOM) (EventID: 10010) (User: APP4)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (01/21/2015 09:47:53 PM) (Source: DCOM) (EventID: 10010) (User: APP4)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (01/21/2015 09:47:53 PM) (Source: DCOM) (EventID: 10010) (User: APP4)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (01/21/2015 09:47:53 PM) (Source: DCOM) (EventID: 10010) (User: APP4)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Microsoft Office Sessions:
=========================
Error: (01/23/2015 06:39:30 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe soundbooth cs5\Setup\resources\libraries\ARKEngine.dll
Error: (01/23/2015 06:39:30 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Adobe\adobe soundbooth cs5\Setup\resources\libraries\Adobe_Helperx64.exe
Error: (01/23/2015 06:39:30 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe soundbooth cs5\Setup\resources\libraries\ARKCmdDefrag.dll
Error: (01/23/2015 06:39:30 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe soundbooth cs5\setuproyalty\resources\libraries\ARKCmdFS.dll
Error: (01/23/2015 06:39:30 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe soundbooth cs5\setuproyalty\resources\libraries\ARKCmdCaps.dll
Error: (01/23/2015 06:39:29 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe soundbooth cs5\Setup\resources\libraries\ARKCmdFS.dll
Error: (01/23/2015 06:39:29 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe soundbooth cs5\Setup\resources\libraries\ARKCmdCaps.dll
Error: (01/23/2015 06:39:29 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Adobe\adobe soundbooth cs5\setuproyalty\resources\libraries\Adobe_Helperx64.exe
Error: (01/23/2015 06:39:28 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe soundbooth cs5\setuproyalty\resources\libraries\ARKEngine.dll
Error: (01/23/2015 06:39:28 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"c:\program files\Adobe\adobe soundbooth cs5\setuproyalty\resources\libraries\ARKCmdDefrag.dll
CodeIntegrity Errors:
===================================
Date: 2015-01-15 13:11:38.254
Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2015-01-15 13:11:38.237
Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-12-16 07:50:27.007
Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-12-16 07:50:26.945
Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-12-16 07:50:26.747
Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-12-16 07:50:26.682
Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-12-16 07:50:26.502
Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-12-16 07:50:26.423
Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-12-16 07:50:26.237
Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2014-12-16 07:50:26.164
Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU E7500 @ 2.93GHz
Percentage of memory in use: 67%
Total physical RAM: 2045.96 MB
Available physical RAM: 674.36 MB
Total Pagefile: 4093.96 MB
Available Pagefile: 1686.13 MB
Total Virtual: 2047.88 MB
Available Virtual: 1867.2 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:1863.01 GB) (Free:1341.67 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 1863 GB) (Disk ID: 31AA4FA6)
Partition 1: (Active) - (Size=1863 GB) - (Type=07 NTFS)
==================== End Of Log ============================