Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

RunDLL Error loading SysMenu.dll


  • Please log in to reply
13 replies to this topic

#1 davlinford

davlinford

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:27 PM

Posted 21 January 2016 - 02:34 PM

Hi,

 

I have an HP Pavilion P6120F desktop with Windows Vista home premium. About 3 to 5 minutes after I boot up I get a RunDLL message that says

 

Error Loading C;\PROGRA~1\COMMON~1\system\SysMenu.dll

The specified module could not be found.

 

I have checked the above location and the dll does not exist as far as I can tell. I have also checked my start up file to try and locate what is calling that dll and I dont see it anywhere. I have tried autoruns as well and cannot find it there either. Cn you please help me resolve this error message.

 

Thanks,
David Linford


Edited by hamluis, 22 January 2016 - 11:34 AM.
Moved from Vista to Am I Infected - Hamluis.


BC AdBot (Login to Remove)

 


#2 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:06:27 PM

Posted 21 January 2016 - 03:29 PM

In Autoruns, did you look under the Scheduled Tasks tab? Something like SMupdate.job?



#3 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:06:27 PM

Posted 21 January 2016 - 03:48 PM

Can you please do the following?

 

Click Start > Run > copy/paste the following command:


cmd /k schtasks /query > 0 & notepad 0

Press Enter.

 

A Notepad window will open. Please copy/paste the entire content into your next reply.


Edited by Phantom010, 21 January 2016 - 03:48 PM.


#4 davlinford

davlinford
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:27 PM

Posted 21 January 2016 - 03:52 PM

Hi Phantom010,

 

thanks for the reply. I did not see it there. attached is a jpg of all things that show up under scheduled tasks.

 

David



#5 davlinford

davlinford
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:27 PM

Posted 21 January 2016 - 03:55 PM

Hi Phantom010,

 

Here is the output that you requested:

 

 
Folder: \
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Adobe Acrobat Update Task                N/A                    Unknown        
HP Health Check                          1/26/2016 1:05:00 PM   Ready          
User_Feed_Synchronization-{BC2CAFAF-8197 1/21/2016 8:10:52 PM   Ready          
{17E0E9C3-8002-47DB-9A2A-BAB9FF466B36}   N/A                    Ready          
{70D4CBB0-F4FC-4A3C-9900-C349D02247F8}   N/A                    Ready          
{ADB73644-F877-4105-BB27-28FC9676D164}   N/A                    Could not start
{CD6B2B2A-BB8F-4E5C-A367-42DC17DB4120}   N/A                    Ready          
 
Folder: \Apple
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
AppleSoftwareUpdate                      1/24/2016 7:54:00 PM   Ready          
 
Folder: \Microsoft
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
 
Folder: \Microsoft\Windows
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
 
Folder: \Microsoft\Windows\Active Directory Rights Management Services Client
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
AD RMS Rights Policy Template Management Disabled                              
AD RMS Rights Policy Template Management N/A                    Ready          
 
Folder: \Microsoft\Windows\Bluetooth
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
UninstallDeviceTask                      N/A                    Ready          
 
Folder: \Microsoft\Windows\CertificateServicesClient
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
UserTask                                 N/A                    Running        
UserTask-Roam                            N/A                    Ready          
 
Folder: \Microsoft\Windows\Customer Experience Improvement Program
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Consolidator                             1/22/2016 6:00:00 AM   Could not start
OptinNotification                        N/A                    Ready          
 
Folder: \Microsoft\Windows\Defrag
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
ManualDefrag                             N/A                    Ready          
ScheduledDefrag                          Disabled                              
 
Folder: \Microsoft\Windows\DiskDiagnostic
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Microsoft-Windows-DiskDiagnosticResolver Disabled                              
 
Folder: \Microsoft\Windows\Maintenance
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
SMupdate2                                1/21/2016 1:53:41 PM   Running        
 
Folder: \Microsoft\Windows\Media Center
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
ehDRMInit                                N/A                    Ready          
mcupdate                                 1/21/2016 6:12:36 PM   Ready          
OCURActivate                             N/A                    Ready          
OCURDiscovery                            N/A                    Ready          
UpdateRecordPath                         N/A                    Ready          
 
Folder: \Microsoft\Windows\MobilePC
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
HotStart                                 N/A                    Ready          
TMM                                      N/A                    Running        
 
Folder: \Microsoft\Windows\MUI
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
LPRemove                                 N/A                    Ready          
 
Folder: \Microsoft\Windows\Multimedia
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
SMupdate3                                1/21/2016 3:53:43 PM   Ready          
SystemSoundsService                      N/A                    Running        
 
Folder: \Microsoft\Windows\NetworkAccessProtection
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
NAPStatus UI                             N/A                    Ready          
 
Folder: \Microsoft\Windows\PLA
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
 
Folder: \Microsoft\Windows\RAC
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
RACAgent                                 N/A                    Unknown        
 
Folder: \Microsoft\Windows\Shell
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
CrawlStartPages                          N/A                    Ready          
 
Folder: \Microsoft\Windows\SideShow
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
AutoWake                                 Disabled                              
GadgetManager                            N/A                    Ready          
SessionAgent                             Disabled               Could not start
SystemDataProviders                      Disabled               Could not start
 
Folder: \Microsoft\Windows\SystemRestore
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
SR                                       1/22/2016 12:00:00 AM  Unknown        
 
Folder: \Microsoft\Windows\Tcpip
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
IpAddressConflict1                       N/A                    Ready          
IpAddressConflict2                       N/A                    Ready          
 
Folder: \Microsoft\Windows\TextServicesFramework
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
MsCtfMonitor                             N/A                    Running        
 
Folder: \Microsoft\Windows\UPnP
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
UPnPHostConfig                           N/A                    Ready          
 
Folder: \Microsoft\Windows\WDI
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
ResolutionHost                           N/A                    Ready          
 
Folder: \Microsoft\Windows\Windows Error Reporting
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
QueueReporting                           N/A                    Unknown        
 
Folder: \Microsoft\Windows\WindowsCalendar
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Reminders - Cindy Garside                N/A                    Ready          
 
Folder: \Microsoft\Windows\Wired
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
GatherWiredInfo                          N/A                    Ready          
 
Folder: \Microsoft\Windows\Wireless
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
GatherWirelessInfo                       N/A                    Ready          
 
Folder: \Microsoft\Windows Live
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
 
Folder: \Microsoft\Windows Live\SOXE
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Extractor Definitions Update Task        1/29/2016 8:27:09 AM   Ready          
 
Folder: \Norton Internet Security
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
Norton Error Analyzer                    N/A                    Ready          
 
Folder: \WPD
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
SqmUpload_S-1-5-21-2891162650-2295746832 N/A                    Ready          
 

Attached Files



#6 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:06:27 PM

Posted 21 January 2016 - 04:01 PM

It's not that I don't believe you, but in case I can spot something related to it, please do the following:

 

Run Autoruns again.

Select File in the upper left corner.

Click Save...

Change the File Type to: Text (*.txt)

Save the file to your desktop.

 

Open the file, copy the whole content and paste it into your next reply here.



#7 davlinford

davlinford
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:27 PM

Posted 21 January 2016 - 04:09 PM

Hi Phamtom010,

 

Here ya go:

 

"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" "" "" "" "1/21/2016 9:06 AM" ""
+ "HotKeysCmds" "hkcmd Module" "Intel Corporation" "c:\windows\system32\hkcmd.exe" "2/26/2009 11:09 AM" ""
+ "HP Remote Software" "Core functionality module for HP Remote software" "" "c:\program files\hewlett-packard\hp remote\hp remote v1.0.5.exe" "2/6/2009 3:11 AM" ""
+ "IAAnotif" "Event Monitor User Notification Tool" "Intel Corporation" "c:\program files (x86)\intel\intel matrix storage manager\iaanotif.exe" "12/4/2008 12:57 PM" ""
+ "IgfxTray" "igfxTray Module" "Intel Corporation" "c:\windows\system32\igfxtray.exe" "2/26/2009 11:09 AM" ""
+ "Persistence" "persistence Module" "Intel Corporation" "c:\windows\system32\igfxpers.exe" "2/26/2009 11:09 AM" ""
+ "SmartMenu" "HP MediaSmart SmartMenu" "Hewlett-Packard" "c:\program files\hewlett-packard\hp mediasmart\smartmenu.exe" "3/5/2009 2:25 AM" ""
+ "Windows Defender" "Windows Defender User Interface" "Microsoft Corporation" "c:\program files\windows defender\msascui.exe" "1/18/2008 10:19 PM" ""
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run" "" "" "" "1/21/2016 12:30 PM" ""
+ "CLMLServer for HP TouchSmart" "CyberLink MediaLibray Service" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe" "1/7/2009 5:51 AM" ""
+ "ControlCenter4" "ControlCenter Launcher" "Brother Industries, Ltd." "c:\program files (x86)\controlcenter4\brccboot.exe" "1/29/2013 10:32 PM" ""
+ "DVDAgent" "HP DVDSmart Resident Program" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\media\dvd\dvdagent.exe" "3/12/2009 11:29 PM" ""
+ "HP Health Check Scheduler" "HP Health Check Scheduler" "Hewlett-Packard" "c:\program files (x86)\hewlett-packard\hp health check\hphc_scheduler.exe" "12/4/2008 6:12 AM" ""
+ "HP Software Update" "hpwuSchd Application" "Hewlett-Packard" "c:\program files (x86)\hp\hp software update\hpwuschd2.exe" "7/10/2007 1:32 AM" ""
+ "hpsysdrv" "hpsysdrv" "Hewlett-Packard" "c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe" "11/20/2008 10:46 AM" ""
+ "Microsoft Default Manager" "Microsoft Default Manager" "Microsoft Corp." "c:\program files (x86)\microsoft\search enhancement pack\default manager\defmgr.exe" "2/6/2009 4:02 PM" ""
+ "UpdateLBPShortCut" "MUI StartMenu Application" "CyberLink Corp." "c:\program files (x86)\cyberlink\labelprint\muitransfer\muistartmenu.exe" "12/3/2008 5:40 AM" ""
+ "UpdateP2GoShortCut" "MUI StartMenu Application" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\muitransfer\muistartmenu.exe" "12/3/2008 5:40 AM" ""
+ "UpdatePDIRShortCut" "MUI StartMenu Application" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "12/3/2008 5:40 AM" ""
+ "UpdatePSTShortCut" "MUI StartMenu Application" "CyberLink Corp." "c:\program files (x86)\cyberlink\cyberlink dvd suite deluxe\muitransfer\muistartmenu.exe" "9/23/2008 7:05 PM" ""
"HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" "" "" "" "1/21/2016 9:06 AM" ""
+ "Sidebar" "Windows Sidebar" "Microsoft Corporation" "c:\program files\windows sidebar\sidebar.exe" "4/10/2009 10:16 PM" ""
+ "swg" "GoogleToolbarNotifier" "Google Inc." "c:\program files (x86)\google\googletoolbarnotifier\googletoolbarnotifier.exe" "5/12/2008 10:14 AM" ""
"HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" "" "" "" "1/16/2015 6:16 PM" ""
+ "Microsoft Windows Mail 7" "Windows Mail" "Microsoft Corporation" "c:\program files\windows mail\winmail.exe" "1/18/2008 10:25 PM" ""
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components" "" "" "" "10/8/2015 9:11 PM" ""
+ "Google Chrome" "Google Chrome Installer" "Google Inc." "c:\program files (x86)\google\chrome\application\47.0.2526.111\installer\chrmstp.exe" "1/11/2016 9:27 PM" ""
+ "Microsoft Windows Mail 7" "Windows Mail" "Microsoft Corporation" "c:\program files (x86)\windows mail\winmail.exe" "1/18/2008 9:47 PM" ""
"HKLM\SOFTWARE\Classes\Protocols\Filter" "" "" "" "12/9/2011 10:54 PM" ""
+ "text/xml" "Microsoft Office XML MIME Filter" "Microsoft Corporation" "c:\program files\common files\microsoft shared\office12\msoxmlmf.dll" "2/26/2009 3:28 AM" ""
"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers" "" "" "" "7/8/2015 8:44 AM" ""
+ "BUContextMenu" "Backup Shell" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine64\22.5.5.15\bushell.dll" "11/5/2015 2:34 AM" ""
+ "Symantec.Norton.Antivirus.IEContextMenu" "Norton Security Shell Extension Module" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine64\22.5.5.15\navshext.dll" "11/20/2015 5:06 AM" ""
"HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers" "" "" "" "1/7/2011 5:56 AM" ""
+ "Symantec.Norton.Antivirus.IEContextMenu" "Norton Security Shell Extension Module" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine64\22.5.5.15\navshext.dll" "11/20/2015 5:06 AM" ""
"HKLM\Software\Classes\*\ShellEx\PropertySheetHandlers" "" "" "" "7/8/2015 8:44 AM" ""
+ "BuPropertySheet" "Backup Shell" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine64\22.5.5.15\bushell.dll" "11/5/2015 2:34 AM" ""
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers" "" "" "" "5/4/2009 1:19 PM" ""
+ "igfxcui" "igfxpph Module" "Intel Corporation" "c:\windows\system32\igfxpph.dll" "2/26/2009 11:09 AM" ""
"HKLM\Software\Wow6432Node\Classes\Folder\Shellex\ColumnHandlers" "" "" "" "10/20/2014 11:13 PM" ""
+ "PDF Shell Extension" "PDF Shell Extension" "Adobe Systems, Inc." "c:\program files (x86)\common files\adobe\acrobat\activex\pdfshell.dll" "9/24/2015 5:42 AM" ""
"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers" "" "" "" "7/8/2015 8:44 AM" ""
+ "BUContextMenu" "Backup Shell" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine64\22.5.5.15\bushell.dll" "11/5/2015 2:34 AM" ""
+ "Symantec.Norton.Antivirus.IEContextMenu" "Norton Security Shell Extension Module" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine64\22.5.5.15\navshext.dll" "11/20/2015 5:06 AM" ""
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers" "" "" "" "7/8/2015 8:44 AM" ""
+ "  OverlayExcluded" "Backup Shell" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine64\22.5.5.15\bushell.dll" "11/5/2015 2:34 AM" ""
+ "  OverlayPending" "Backup Shell" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine64\22.5.5.15\bushell.dll" "11/5/2015 2:34 AM" ""
+ "  OverlayProtected" "Backup Shell" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine64\22.5.5.15\bushell.dll" "11/5/2015 2:34 AM" ""
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" "" "" "" "12/18/2015 1:51 PM" ""
+ "Google Toolbar Helper" "Google Toolbar" "Google Inc." "c:\program files (x86)\google\google toolbar\googletoolbar_64.dll" "12/10/2015 7:38 AM" ""
+ "Windows Live ID Sign-in Helper" "Microsoft® Windows Live ID Login Helper" "Microsoft Corp." "c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll" "9/21/2010 1:47 PM" ""
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" "" "" "" "1/21/2016 8:26 AM" ""
+ "Google Toolbar Helper" "Google Toolbar" "Google Inc." "c:\program files (x86)\google\google toolbar\googletoolbar_32.dll" "12/10/2015 7:44 AM" ""
+ "Java™ Plug-In 2 SSV Helper" "Java™ Platform SE binary" "Sun Microsystems, Inc." "c:\program files (x86)\java\jre6\bin\jp2ssv.dll" "10/3/2011 5:05 AM" ""
+ "Microsoft Live Search Toolbar Helper" "MSN® Shell Extender" "Microsoft Corp." "c:\program files (x86)\msn\toolbar\3.0.0552.0\msneshellx.dll" "1/22/2009 10:36 AM" ""
+ "Norton Identity Protection" "coIEPlugIn" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine\22.5.5.15\coieplg.dll" "11/5/2015 1:54 PM" ""
+ "Search Helper" "Search Helper for Internet Explorer" "Microsoft Corporation" "c:\program files (x86)\microsoft\search enhancement pack\search helper\sepsearchhelperie.dll" "5/19/2009 10:35 AM" ""
+ "Windows Live ID Sign-in Helper" "Microsoft® Windows Live ID Login Helper" "Microsoft Corp." "c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll" "9/21/2010 1:01 PM" ""
"HKLM\Software\Microsoft\Internet Explorer\Toolbar" "" "" "" "12/18/2015 1:51 PM" ""
+ "Google Toolbar" "Google Toolbar" "Google Inc." "c:\program files (x86)\google\google toolbar\googletoolbar_64.dll" "12/10/2015 7:38 AM" ""
"HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar" "" "" "" "12/18/2015 1:51 PM" ""
+ "Google Toolbar" "Google Toolbar" "Google Inc." "c:\program files (x86)\google\google toolbar\googletoolbar_32.dll" "12/10/2015 7:44 AM" ""
+ "Microsoft Live Search Toolbar" "MSN® Shell Extender" "Microsoft Corp." "c:\program files (x86)\msn\toolbar\3.0.0552.0\msneshellx.dll" "1/22/2009 10:36 AM" ""
+ "Norton Toolbar" "coIEPlugIn" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine\22.5.5.15\coieplg.dll" "11/5/2015 1:54 PM" ""
"HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions" "" "" "" "12/10/2011 12:42 AM" ""
+ "S&end to OneNote" "Microsoft Office OneNote Internet Explorer Add-in" "Microsoft Corporation" "c:\program files (x86)\microsoft office\office12\onbttnie.dll" "8/29/2011 10:40 PM" ""
+ "SmartPrint" "HP Smart Print Setup" "Hewlett-Packard" "c:\program files (x86)\hewlett-packard\smartprint\smartprintsetup.exe" "4/15/2011 5:20 AM" ""
"Task Scheduler" "" "" "" "" ""
+ "\Adobe Acrobat Update Task" "Adobe Reader and Acrobat Manager" "Adobe Systems Incorporated" "c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe" "9/14/2015 8:19 AM" ""
+ "\Adobe Flash Player Updater" "Adobe® Flash® Player Update Service 20.0 r0" "Adobe Systems Incorporated" "c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe" "1/11/2016 5:03 PM" ""
+ "\Apple\AppleSoftwareUpdate" "Apple Software Update" "Apple Inc." "c:\program files (x86)\apple software update\softwareupdate.exe" "8/26/2015 11:14 PM" ""
+ "\GoogleUpdateTaskMachineCore" "Google Installer" "Google Inc." "c:\program files (x86)\google\update\googleupdate.exe" "8/21/2015 6:13 PM" ""
+ "\GoogleUpdateTaskMachineUA" "Google Installer" "Google Inc." "c:\program files (x86)\google\update\googleupdate.exe" "8/21/2015 6:13 PM" ""
+ "\HP Health Check" "HP Health Check Scheduler" "Hewlett-Packard" "c:\program files (x86)\hewlett-packard\hp health check\hphc_scheduler.exe" "12/4/2008 6:12 AM" ""
+ "\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task" "Windows Live Social Object Extractor Engine" "Microsoft Corporation" "c:\program files (x86)\windows live\soxe\wlsoxe.dll" "9/22/2010 11:12 PM" ""
+ "\Microsoft\Windows\WindowsCalendar\Reminders - Cindy Garside" "Windows Calendar" "Microsoft Corporation" "c:\program files\windows calendar\wincal.exe" "1/18/2008 10:26 PM" ""
+ "\Microsoft\Windows\WindowsCalendar\Reminders - Emily" "Windows Calendar" "Microsoft Corporation" "c:\program files\windows calendar\wincal.exe" "1/18/2008 10:26 PM" ""
+ "\Microsoft\Windows\WindowsCalendar\Reminders - Gigi" "Windows Calendar" "Microsoft Corporation" "c:\program files\windows calendar\wincal.exe" "1/18/2008 10:26 PM" ""
+ "\Microsoft\Windows\Wired\GatherWiredInfo" "" "" "c:\windows\system32\gatherwiredinfo.vbs" "1/20/2008 6:48 PM" ""
+ "\Microsoft\Windows\Wireless\GatherWirelessInfo" "" "" "c:\windows\system32\gatherwirelessinfo.vbs" "1/20/2008 6:47 PM" ""
+ "\Norton Internet Security\Norton Error Analyzer" "Symantec Error Reporting" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine\22.5.5.15\symerr.exe" "11/5/2015 4:36 AM" ""
+ "\Norton Internet Security\Norton Error Processor" "Symantec Error Reporting" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine\22.5.5.15\symerr.exe" "11/5/2015 4:36 AM" ""
+ "\Norton WSC Integration" "WSCStub" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine\22.5.5.15\wscstub.exe" "11/20/2015 4:41 AM" ""
"HKLM\System\CurrentControlSet\Services" "" "" "" "1/21/2016 11:32 AM" ""
+ "AdobeARMservice" "Adobe Acrobat Updater keeps your Adobe software up to date." "Adobe Systems Incorporated" "c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe" "9/14/2015 8:19 AM" ""
+ "AdobeFlashPlayerUpdateSvc" "This service keeps your Adobe Flash Player installation up to date with the latest enhancements and security fixes." "Adobe Systems Incorporated" "c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe" "1/11/2016 5:03 PM" ""
+ "Apple Mobile Device Service" "Provides the interface to Apple mobile devices." "Apple Inc." "c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe" "2/12/2015 7:18 PM" ""
+ "Bonjour Service" "Enables hardware devices and software services to automatically configure themselves on the network and advertise their presence." "Apple Inc." "c:\program files\bonjour\mdnsresponder.exe" "8/30/2011 9:52 PM" ""
+ "BrYNSvc" "BrYNCSvc" "Brother Industries, Ltd." "c:\program files (x86)\browny02\brynsvc.exe" "10/25/2012 5:40 PM" ""
+ "fsssvc" "This service enables Family Safety on the computer. If this service is not running, Family Safety will not work." "Microsoft Corporation" "c:\program files (x86)\windows live\family safety\fsssvc.exe" "9/22/2010 11:16 PM" ""
+ "gupdate" "Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "Google Inc." "c:\program files (x86)\google\update\googleupdate.exe" "8/21/2015 6:13 PM" ""
+ "gupdatem" "Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it." "Google Inc." "c:\program files (x86)\google\update\googleupdate.exe" "8/21/2015 6:13 PM" ""
+ "gusvc" "Google Updater keeps your Google software up to date. If Google Updater Service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work." "Google" "c:\program files (x86)\google\common\google updater\googleupdaterservice.exe" "3/2/2012 1:13 PM" ""
+ "HP Health Check Service" "HP Health Check Service" "Hewlett-Packard" "c:\program files (x86)\hewlett-packard\hp health check\hphc_service.exe" "12/4/2008 6:12 AM" ""
+ "IAANTMON" "RAID Monitor" "Intel Corporation" "c:\program files (x86)\intel\intel matrix storage manager\iaantmon.exe" "12/4/2008 12:57 PM" ""
+ "LightScribeService" "Used by the LightScribe software components to support 3rd party disc labeling applications using the LightScribe COM Application Programming Interface (LSCAPI). This service needs to run for LightScribe direct disc labeling to work." "Hewlett-Packard Company" "c:\program files (x86)\common files\lightscribe\lssrvc.exe" "3/17/2009 12:12 PM" ""
+ "MBAMService" "Malwarebytes Anti-Malware service" "Malwarebytes Corporation" "c:\program files (x86)\malwarebytes anti-malware\mbamservice.exe" "6/17/2015 3:21 PM" ""
+ "MozillaMaintenance" "The Mozilla Maintenance Service ensures that you have the latest and most secure version of Mozilla Firefox on your computer. Keeping Firefox up to date is very important for your online security, and Mozilla strongly recommends that you keep this service enabled." "Mozilla Foundation" "c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe" "1/5/2016 6:25 PM" ""
+ "Net Driver HPZ12" "Dot4Net Module" "Hewlett-Packard" "c:\windows\system32\hpzinw12.dll" "8/5/2010 9:45 PM" ""
+ "NIS" "Norton Internet Security" "Symantec Corporation" "c:\program files (x86)\norton internet security\engine\22.5.5.15\nis.exe" "6/9/2015 9:57 AM" ""
+ "odserv" "Run portions of Microsoft Office Diagnostics." "Microsoft Corporation" "c:\program files (x86)\common files\microsoft shared\office12\odserv.exe" "7/19/2011 9:12 PM" ""
+ "ose" "Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports." "Microsoft Corporation" "c:\program files (x86)\common files\microsoft shared\source engine\ose.exe" "10/26/2006 1:00 PM" ""
+ "Pml Driver HPZ12" "PmlDrv Module" "Hewlett-Packard" "c:\windows\system32\hpzipm12.dll" "8/5/2010 9:45 PM" ""
+ "SeaPort" "Enables the detection, download and installation of up-to-date configuration files for Microsoft Search Enhancement applications. Also provides server communication for the customer experience improvement program. If this service is disabled, search enhancement features such as search history may not work correctly." "Microsoft Corporation" "c:\program files (x86)\microsoft\search enhancement pack\seaport\seaport.exe" "5/19/2009 10:35 AM" ""
+ "WinDefend" "Scan your computer for unwanted software, schedule scans, and get the latest unwanted software definitions." "Microsoft Corporation" "c:\program files\windows defender\mpsvc.dll" "1/18/2008 11:53 PM" ""
+ "wlidsvc" "Enables Windows Live ID authentication." "Microsoft Corp." "c:\program files\common files\microsoft shared\windows live\wlidsvc.exe" "9/21/2010 1:46 PM" ""
+ "WMPNetworkSvc" "Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play" "Microsoft Corporation" "c:\program files\windows media player\wmpnetwk.exe" "1/18/2008 10:51 PM" ""
"HKLM\System\CurrentControlSet\Services" "" "" "" "1/21/2016 11:32 AM" ""
+ "athr" "Atheros Extensible Wireless LAN device driver" "Atheros Communications, Inc." "c:\windows\system32\drivers\athrx.sys" "9/18/2008 4:39 PM" ""
+ "BHDrvx64" "SONAR Engine Driver" "Symantec Corporation" "c:\program files (x86)\norton internet security\nortondata\22.5.0.124\definitions\bashdefs\20160119.001\bhdrvx64.sys" "9/25/2015 5:17 PM" ""
+ "BrFiltLo" "Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver" "Brother Industries, Ltd." "c:\windows\system32\drivers\brfiltlo.sys" "8/6/2006 5:51 PM" ""
+ "BrFiltUp" "Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver" "Brother Industries, Ltd." "c:\windows\system32\drivers\brfiltup.sys" "8/6/2006 5:51 PM" ""
+ "BrUsbSer" "Brother USB Serial Driver" "Brother Industries Ltd." "c:\windows\system32\drivers\brusbser.sys" "8/9/2006 4:11 AM" ""
+ "BVRPMPR5a64" "BVRP NDIS 5.0 MPR Protocol Driver" "Avanquest Software" "c:\windows\system32\drivers\bvrpmpr5a64.sys" "2/21/2007 9:56 AM" ""
+ "ccSet_NIS" "Common Client Settings Driver" "Symantec Corporation" "c:\windows\system32\drivers\nisx64\1605050.00f\ccsetx64.sys" "8/18/2014 11:33 AM" ""
+ "E1G60" "Intel® PRO/1000 Adapter NDIS 6 deserialized driver" "Intel Corporation" "c:\windows\system32\drivers\e1g6032e.sys" "8/7/2007 8:15 AM" ""
+ "eeCtrl" "Symantec Eraser Control Driver" "Symantec Corporation" "c:\program files (x86)\common files\symantec shared\eengine\eectrl64.sys" "11/6/2015 6:29 PM" ""
+ "EraserUtilRebootDrv" "Symantec Eraser Utility Driver" "Symantec Corporation" "c:\program files (x86)\common files\symantec shared\eengine\eraserutilrebootdrv.sys" "11/6/2015 6:29 PM" ""
+ "GEARAspiWDM" "CD DVD Filter" "GEAR Software Inc." "c:\windows\system32\drivers\gearaspiwdm.sys" "5/3/2012 11:56 AM" ""
+ "iaStor" "Intel Matrix Storage Manager driver - x64" "Intel Corporation" "c:\windows\system32\drivers\iastor.sys" "12/4/2008 12:47 PM" ""
+ "IDSVia64" "Symantec Intrusion Prevention Driver" "Symantec Corporation" "c:\program files (x86)\norton internet security\nortondata\22.5.0.124\definitions\ipsdefs\20160120.001\idsvia64.sys" "10/12/2015 6:00 PM" ""
+ "igfx" "Intel Graphics Kernel Mode Driver" "Intel Corporation" "c:\windows\system32\drivers\igdkmd64.sys" "2/26/2009 11:46 AM" ""
+ "IntcAzAudAddService" "Realtek® High Definition Audio Function Driver" "Realtek Semiconductor Corp." "c:\windows\system32\drivers\rtkvhd64.sys" "2/11/2009 4:39 AM" ""
+ "MBAMProtector" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\windows\system32\drivers\mbam.sys" "9/3/2014 9:50 AM" ""
+ "MBAMSwissArmy" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\windows\system32\drivers\mbamswissarmy.sys" "4/13/2015 11:29 AM" ""
+ "MBAMWebAccessControl" "Malwarebytes Web Access Control" "Malwarebytes Corporation" "c:\windows\system32\drivers\mwac.sys" "6/17/2014 6:06 PM" ""
+ "NAVENG" "AV Engine" "Symantec Corporation" "c:\program files (x86)\norton internet security\nortondata\22.5.0.124\definitions\virusdefs\20160121.001\eng64.sys" "10/13/2015 6:06 PM" ""
+ "NAVEX15" "AV Engine" "Symantec Corporation" "c:\program files (x86)\norton internet security\nortondata\22.5.0.124\definitions\virusdefs\20160121.001\ex64.sys" "10/13/2015 6:01 PM" ""
+ "RTL8169" "Realtek 8101E/8168/8169 NDIS6 64-bit Driver                    " "Realtek Corporation                                            " "c:\windows\system32\drivers\rtlh64.sys" "1/19/2009 10:49 PM" ""
+ "SRTSP" "Symantec AutoProtect" "Symantec Corporation" "c:\windows\system32\drivers\nisx64\1605050.00f\srtsp64.sys" "10/9/2015 4:11 PM" ""
+ "SRTSPX" "Symantec AutoProtect" "Symantec Corporation" "c:\windows\system32\drivers\nisx64\1605050.00f\srtspx64.sys" "8/25/2014 10:36 PM" ""
+ "SymEFASI" "Symantec Extended File Attributes" "Symantec Corporation" "c:\windows\system32\drivers\nisx64\1605050.00f\symefasi64.sys" "10/19/2015 3:48 PM" ""
+ "SymEvent" "Symantec Event Library" "Symantec Corporation" "c:\windows\system32\drivers\symevent64x86.sys" "1/19/2015 2:43 PM" ""
+ "SymIRON" "Iron Driver" "Symantec Corporation" "c:\windows\system32\drivers\nisx64\1605050.00f\ironx64.sys" "5/4/2015 3:51 PM" ""
+ "SYMTDIv" "Network Dispatch Driver" "Symantec Corporation" "c:\windows\system32\drivers\nisx64\1605050.00f\symtdiv.sys" "8/24/2015 12:08 PM" ""
+ "USBAAPL64" "Apple Mobile Device USB Driver" "Apple, Inc." "c:\windows\system32\drivers\usbaapl64.sys" "7/15/2014 9:30 AM" ""
+ "WDC_SAM" "Manages WD external storage products." "Western Digital Technologies" "c:\windows\system32\drivers\wdcsam64.sys" "4/16/2008 12:39 AM" ""
+ "WsAudio_DeviceS(1)" "Wondershare Virtual Audio Device" "Wondershare" "c:\windows\system32\drivers\wsaudio_devices(1).sys" "7/23/2009 4:04 AM" ""
+ "WsAudio_DeviceS(2)" "Wondershare Virtual Audio Device" "Wondershare" "c:\windows\system32\drivers\wsaudio_devices(2).sys" "7/23/2009 4:04 AM" ""
+ "WsAudio_DeviceS(3)" "Wondershare Virtual Audio Device" "Wondershare" "c:\windows\system32\drivers\wsaudio_devices(3).sys" "7/23/2009 4:04 AM" ""
+ "WsAudio_DeviceS(4)" "Wondershare Virtual Audio Device" "Wondershare" "c:\windows\system32\drivers\wsaudio_devices(4).sys" "7/23/2009 4:04 AM" ""
+ "WsAudio_DeviceS(5)" "Wondershare Virtual Audio Device" "Wondershare" "c:\windows\system32\drivers\wsaudio_devices(5).sys" "7/23/2009 4:04 AM" ""
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Font Drivers" "" "" "" "11/2/2006 7:28 AM" ""
+ "Adobe Type Manager" "Windows NT OpenType/Type 1 Font Driver" "Adobe Systems Incorporated" "c:\windows\system32\atmfd.dll" "9/2/2015 12:16 PM" ""
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" "" "" "" "1/20/2016 2:47 PM" ""
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "Fraunhofer Institut Integrierte Schaltungen IIS" "c:\windows\system32\l3codeca.acm" "1/21/2010 7:37 AM" ""
"HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32" "" "" "" "1/20/2016 2:47 PM" ""
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "Fraunhofer Institut Integrierte Schaltungen IIS" "c:\windows\syswow64\l3codeca.acm" "1/21/2010 7:05 AM" ""
+ "msacm.l3codecp" "MPEG Audio Layer-3 Codec for MSACM" "Fraunhofer Institut Integrierte Schaltungen IIS" "c:\windows\syswow64\l3codecp.acm" "4/10/2009 10:22 PM" ""
+ "vidc.cvid" "Cinepak® Codec" "Radius Inc." "c:\windows\syswow64\iccvid.dll" "5/27/2010 12:08 PM" ""
"HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance" "" "" "" "11/2/2006 7:29 AM" ""
+ "9x8Resize" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "Allocator Fix" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "Bitmap" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "Capture ASF Writer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "Frame Eater" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "Multiple File Output" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "Proxy Sink" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "Proxy Source" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "Record Queue" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "ShotDetect" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "Stetch" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WM VIH2 Fix" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT Audio Analyzer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT Black Frame Generator" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT DV Extract Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT FormatConversion" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT Import Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT Interlacer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT Log Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT MuxDeMux Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT Sample Info Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT Switch Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT Virtual Renderer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT Virtual Source" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
+ "WMT Volume" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll" "4/10/2009 11:11 PM" ""
"HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance" "" "" "" "6/27/2015 8:31 AM" ""
+ "AC3Filter" "ac3filter" "" "c:\windows\syswow64\ac3filter.ax" "7/9/2008 12:06 AM" ""
+ "Audio Destination" "WAVDest Filter (Sample)" "Microsoft Corporation" "c:\program files (x86)\google\google earth\plugin\wavdest.ax" "5/20/2015 3:07 PM" ""
+ "Bouncing Ball" "Bouncing Ball Filter (Sample)" "Microsoft Corporation" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\copptestfilter.ax" "6/27/2005 7:40 AM" ""
+ "CL Dvb Subtitle Decoder" "CLDvbSub" "CyberLink_DE" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrdvbsub.ax" "3/27/2008 12:52 AM" ""
+ "CL_EVRWindow" "CLEvr" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrevr.dll" "11/15/2007 12:37 AM" ""
+ "CL_EVRWindow" "CLEvr" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\clevr.dll" "5/17/2007 4:33 AM" ""
+ "CyberLink Audio Decoder" "CyberLink Audio Decoder Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\claud61.ax" "7/3/2008 3:45 AM" ""
+ "CyberLink Audio Decoder (HP)" "CyberLink Audio Decoder Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\claud.ax" "11/24/2008 1:57 AM" ""
+ "CyberLink Audio Decoder (HP)" "CyberLink Audio Decoder Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\claud.ax" "12/5/2008 12:44 AM" ""
+ "CyberLink Audio Effect" "CyberLink Audio Effect Filter" "CyberLink Corporation" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmraudfx.ax" "8/5/2004 5:25 AM" ""
+ "CyberLink Audio Effect (HP)" "CyberLink Audio Effect Filter" "CyberLink Corporation" "c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\claudfx.ax" "3/3/2008 1:14 AM" ""
+ "CyberLink Audio Effect (HP)" "CyberLink Audio Effect Filter" "CyberLink Corporation" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\claudfx.ax" "12/22/2004 7:16 PM" ""
+ "CyberLink Audio Noise Reduction" "CLAuNR" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmraunrwrapper.ax" "1/10/2005 1:38 AM" ""
+ "CyberLink Audio Noise Reduction" "CLAuNR" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gaunrwrapper.ax" "10/16/2005 6:34 PM" ""
+ "CyberLink Audio Resampler" "CLAuRsmpl.ax" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gaursmpl.ax" "2/24/2005 6:41 PM" ""
+ "CyberLink Audio Spectrum Analyzer (HomeNetwork)" "CLAudSpa.ax" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\claudspa.ax" "9/24/2004 3:08 AM" ""
+ "CyberLink Audio Spectrum Analyzer (HP)" "CLAudSpa.ax" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\claudspa.ax" "9/24/2004 3:08 AM" ""
+ "CyberLink Audio VolumeBooster" "CyberLink Audio Volume Booster Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gvb.ax" "10/8/2004 12:36 AM" ""
+ "CyberLink AudioCD Filter" "CyberLink AudioCD Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gaudiocd.ax" "1/21/2008 2:35 AM" ""
+ "CyberLink AudioCD Filter (HP)" "CyberLink AudioCD Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\claudiocd.ax" "8/2/2006 3:37 PM" ""
+ "CyberLink Demultiplexer" "MPEG-2 Dempltiplexer" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrdemuxer.ax" "3/27/2008 3:04 AM" ""
+ "CyberLink Demultiplexer (HP)" "MPEG-2 Dempltiplexer" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\cldemuxer.ax" "6/5/2007 6:44 AM" ""
+ "CyberLink Demultiplexer(Scramble)" "MPEG-2 Dempltiplexer" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\cldemuxer.ax" "8/7/2008 4:09 AM" ""
+ "Cyberlink Dump Dispatch Filter" "Cyberlink File Dump Dispatch Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gdumpdispatch.ax" "12/11/2003 11:01 PM" ""
+ "Cyberlink Dump Filter" "Cyberlink File Dump Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gdump.ax" "11/22/2006 4:15 AM" ""
+ "CyberLink DVD Navigator (HP)" "CyberLink DVD Navigation Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\clnavx.ax" "2/22/2009 2:03 AM" ""
+ "CyberLink DVD Navigator (HP)" "CyberLink DVD Navigation Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\clnavx.ax" "2/2/2009 3:54 AM" ""
+ "CyberLink Editing Service 3.0 (Source)" "CES Kernel" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gedtkrn.dll" "5/2/2007 10:18 PM" ""
+ "CyberLink EPG Decoder" "EPGDec" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrepgdec.ax" "5/16/2006 8:37 AM" ""
+ "CyberLink File Map Sink" "CyberLink File Map Sink" "Cyberlink Corporation." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrfmsnk.ax" "8/9/2005 9:52 PM" ""
+ "CyberLink File Map Source" "CyberLink File Map Source" "CyberLink File Map Source" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrfmsrc.ax" "8/9/2005 9:52 PM" ""
+ "Cyberlink File Reader (Async.)" "Cyberlink MPEG File Reader" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2greader.ax" "6/15/2003 7:35 PM" ""
+ "CyberLink Line21 Decoder Filter (HP)" "CyberLink Line21 Decoder Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\clline21.ax" "12/25/2008 7:30 AM" ""
+ "CyberLink Line21 Decoder Filter (HP)" "CyberLink Line21 Decoder Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\clline21.ax" "3/27/2007 5:05 AM" ""
+ "CyberLink Load Image Filter" "CLImage" "CyberLink" "c:\program files (x86)\cyberlink\shared files\climage.ax" "11/6/2006 8:16 PM" ""
+ "CyberLink M2V Writer" "CLM2VWriter" "CyberLink" "c:\program files (x86)\cyberlink\power2go\p2gm2vwriter.ax" "8/17/2005 6:45 AM" ""
+ "CyberLink MP3 Wrapper-PCM" "CyberLink MP3 Wrapper" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrmp3wrap.ax" "11/11/2007 5:53 PM" ""
+ "CyberLink MP3/WAV Wrapper" "CyberLink MP3 Wrapper" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gmp3wrap.ax" "1/13/2008 6:30 PM" ""
+ "CyberLink MPEG Decoder" "CyberLink Video/SP Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gmvd.ax" "9/29/2003 5:50 AM" ""
+ "CyberLink MPEG Muxer" "MpgMux" "CyberLink" "c:\program files (x86)\cyberlink\power2go\p2gmpgmux.ax" "5/22/2008 11:27 PM" ""
+ "CyberLink MPEG Splitter" "CyberLink MPEG Splitter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\clsplter.ax" "10/23/2007 5:13 AM" ""
+ "CyberLink MPEG Splitter(Scramble)" "CyberLink MPEG Splitter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\clsplter.ax" "5/19/2008 2:05 AM" ""
+ "CyberLink MPEG Video Encoder" "CyberLink MPEG Video Encoder                               " "CyberLink Corp.                                            " "c:\program files (x86)\cyberlink\power2go\p2gvidenc.ax" "10/26/2005 3:41 AM" ""
+ "CyberLink MPEG Video Encoder" "CyberLink MPEG Video Encoder                               " "CyberLink Corp.                                            " "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrmpgvenc.ax" "12/10/2007 6:39 PM" ""
+ "CyberLink MPEG-1 Splitter" "CyberLink MPEG Splitter" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gm1spliter.ax" "12/3/2007 7:11 PM" ""
+ "CyberLink MPEG-2 Splitter" "CyberLink MPEG Splitter" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gm2spliter.ax" "12/3/2007 7:10 PM" ""
+ "CyberLink MPEG-4 Splitter" "CyberLink MPEG-4 Splitter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\clm4splt.ax" "1/24/2008 1:28 AM" ""
+ "CyberLink MPEGV Analyzer" "CLMPEGAnalysis" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrmpegvanalyzer.ax" "2/20/2008 6:03 AM" ""
+ "CyberLink PCM Wrapper" "CyberLink PCM Wrapper" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gpcmenc.ax" "3/20/2002 9:54 PM" ""
+ "CyberLink Pipe Switch" "CyberLink Pipe Switch" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrpipswch.ax" "8/15/2007 4:53 AM" ""
+ "CyberLink PTS Regulator" "CyberLink PTS Regulator " "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmptsreg.ax" "12/9/2005 5:40 AM" ""
+ "CyberLink Push-Mode CLStream" "CLStream" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\clstream(pushmode).ax" "11/5/2008 2:05 AM" ""
+ "CyberLink Push-Mode CLStream (cURL)" "CLStream" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\clstream(multilib).ax" "8/25/2008 1:08 AM" ""
+ "CyberLink SAC Video Decoder" "CyberLink Video/SP Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\clvsd.ax" "10/17/2008 2:56 AM" ""
+ "CyberLink SBE Filter" "CLSBE" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrsbe.ax" "2/20/2008 6:03 AM" ""
+ "CyberLink SBE Source Filter" "CLSBESrc" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrsbesrc.ax" "2/20/2008 6:03 AM" ""
+ "Cyberlink Streamming Filter" "Cyberlink Streaming Source Filter(Scramble)" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\clstream.ax" "10/23/2008 9:37 PM" ""
+ "Cyberlink SubTitle Importor (HP)" "CLSubTitle.ax" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\clsubtitle.ax" "4/3/2005 11:48 PM" ""
+ "Cyberlink SubTitle(HP)" "CLSubTitle.ax" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\clsubtitle.ax" "11/16/2007 12:18 AM" ""
+ "CyberLink Teletext Decoder Filter" "Teletext Renderer Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrttxdec.ax" "8/28/2007 7:47 AM" ""
+ "CyberLink TimeStretch Filter" "CLAuTS.ax" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrauts.ax" "9/7/2004 11:15 PM" ""
+ "CyberLink TimeStretch Filter (CES)" "CLAuTS.ax" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gauts.ax" "10/12/2004 6:32 AM" ""
+ "CyberLink TimeStretch Filter (HP)" "CLAuTS.ax" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\clauts.ax" "6/22/2007 7:28 PM" ""
+ "CyberLink TimeStretch Filter (HP)" "CLAuTS.ax" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\clauts.ax" "6/22/2007 7:28 PM" ""
+ "CyberLink TimeStretch Filter(HomeNetwork)" "CLAuTS.ax" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\clauts.ax" "6/22/2007 7:28 PM" ""
+ "CyberLink TL MPEG Splitter" "CyberLink MPEG Splitter" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gtlmsplter.ax" "10/18/2006 9:33 PM" ""
+ "Cyberlink TS Filter Filter" "TSFF" "Cyberlink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrtsff.ax" "3/18/2008 6:10 AM" ""
+ "Cyberlink TS Information" "CLTSInfo" "Cyberlink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrtsinfo.ax" "3/18/2008 6:09 AM" ""
+ "CyberLink Tzan Filter" "Cyberlink Tzan Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\cltzan.ax" "10/15/2008 5:17 AM" ""
+ "CyberLink Video Effect" "CLVidFx" "CyberLink" "c:\program files (x86)\cyberlink\power2go\p2gvidfx.ax" "8/29/2005 8:01 PM" ""
+ "CyberLink Video Effect (HP)" "CLVidFx" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\clvidfx.ax" "3/23/2005 12:15 AM" ""
+ "CyberLink Video Effect (HP)" "CLVidFx" "CyberLink" "c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\clvidfx.ax" "8/23/2005 10:26 PM" ""
+ "CyberLink Video Regulator" "CLRGL" "Cyberlink" "c:\program files (x86)\cyberlink\power2go\p2grgl.ax" "9/28/2005 2:42 AM" ""
+ "CyberLink Video Stabilizer" "CLVideoDeShaking" "CyberLink" "c:\program files (x86)\cyberlink\power2go\p2gvideostabilizer.ax" "10/16/2005 10:28 PM" ""
+ "CyberLink Video/SP Decoder (HP)" "CyberLink Video/SP Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\video\clvsd.ax" "6/29/2008 11:53 PM" ""
+ "CyberLink Video/SP Decoder (HP)" "CyberLink Video/SP Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\clvsd.ax" "12/30/2008 6:34 PM" ""
+ "CyberLink Volume Meter" "CLVolumeMeter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\hpvolumemeter.ax" "10/27/2008 6:51 AM" ""
+ "CyberLink WMV Dumper(HP)" "CLWMVDum Dynamic Link Library" "" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmwmvdump.ax" "3/25/2008 7:00 PM" ""
+ "CyberLink WMV/WMA Demultiplexer" "WMV/WMA Demux" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\clwmfdemux.ax" "7/23/2008 1:09 AM" ""
+ "CyberLink XDS Codec" "CLXDSCodec" "Cyberlink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrxdscodec.ax" "3/22/2005 5:33 AM" ""
+ "MSDVD Audio Wizard (HP)" "CyberLink Audio Wizard Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\claudwizard.ax" "12/16/2008 1:39 AM" ""
+ "P2G Audio Decoder" "CyberLink Audio Decoder Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gaud.ax" "11/30/2006 9:59 PM" ""
+ "P2G Audio Encoder" "CyberLink Audio Encoder Filter" "Cyberlink Corp." "c:\program files (x86)\cyberlink\power2go\p2gaudenc.ax" "12/20/2006 1:20 AM" ""
+ "P2G Video Decoder" "CyberLink Video/SP Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\power2go\p2gvsd.ax" "11/10/2005 4:36 AM" ""
+ "P2G Video Regulator" "CyberLink Video Regulator" "CyberLink" "c:\program files (x86)\cyberlink\power2go\p2gresample.ax" "6/17/2002 7:32 PM" ""
+ "PCM Audio Decoder" "CyberLink Audio Decoder Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmraud.ax" "5/4/2007 12:14 AM" ""
+ "PCM Audio Encoder" "CyberLink Audio Encoder Filter" "Cyberlink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmraudenc.ax" "8/30/2007 10:16 PM" ""
+ "PCM Audio Resampler" "CLAuRsmpl.ax" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmraursmpl.ax" "11/3/2004 11:24 PM" ""
+ "PCM Dump Filter" "Cyberlink File Dump Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrdump.ax" "10/31/2007 12:30 AM" ""
+ "PCM MPEG Muxer" "MpgMux" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrmpgmux.ax" "12/17/2007 2:47 AM" ""
+ "PCM MPEG Video Encoder" "CyberLink MPEG Video Encoder                               " "CyberLink Corp.                                            " "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrmpgvenc2.ax" "12/6/2004 5:32 AM" ""
+ "PCM MPEG-2 Splitter" "CyberLink MPEG Splitter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrm2splter.ax" "7/28/2006 1:23 AM" ""
+ "PCM RTP Source Filter" "RTP Source Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrrtpsrc.ax" "6/25/2007 6:19 PM" ""
+ "PCM SnapShotTIP Filter" "CLSShot" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrsshot.ax" "1/4/2008 4:32 AM" ""
+ "PCM Video Effect" "CLVidFx" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrvidfx.ax" "11/11/2006 8:54 AM" ""
+ "PCM Video Regulator" "CyberLink Video Regulator" "CyberLink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrresample.ax" "1/26/2005 2:25 AM" ""
+ "PCM Video/SP Decoder" "CyberLink Video/SP Filter" "CyberLink Corp." "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmrvsd.ax" "3/21/2007 9:21 AM" ""
+ "Sample File Source (Async.)" "Async sample Filter (Sample)" "Microsoft Corporation" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\dmp\clasyreader.ax" "2/17/2008 6:48 PM" ""
+ "Time Regulator" "TimeRegulator" "cyberlink" "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\tv\pcmravi_audtr.ax" "2/12/2003 6:42 PM" ""
+ "WS ScreenCapture" "ScreenCa Dynamic Link Library" "" "c:\program files (x86)\aimersoft\drm media converter\screencapturefilter.ax" "12/6/2011 10:02 PM" ""
+ "Xvid MPEG-4 Video Decoder" "" "" "c:\windows\syswow64\xvid.ax" "9/25/2008 7:23 PM" ""
"HKLM\SOFTWARE\Classes\Htmlfile\Shell\Open\Command\(Default)" "" "" "" "11/19/2014 3:55 PM" ""
+ "C:\Program Files (x86)\Internet Explorer\iexplore.exe" "Internet Explorer" "Microsoft Corporation" "c:\program files (x86)\internet explorer\iexplore.exe" "12/15/2015 1:44 PM" ""
"HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries" "" "" "" "11/22/2011 6:15 PM" ""
+ "mdnsNSP" "Bonjour Namespace Provider" "Apple Inc." "c:\program files (x86)\bonjour\mdnsnsp.dll" "8/30/2011 9:44 PM" ""
"HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64" "" "" "" "11/22/2011 6:15 PM" ""
+ "mdnsNSP" "Bonjour Namespace Provider" "Apple Inc." "c:\program files\bonjour\mdnsnsp.dll" "8/30/2011 9:53 PM" ""
"HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors" "" "" "" "6/27/2015 8:26 AM" ""
+ "HP b411 Status Monitor" "Print Status Language Monitor" "Hewlett-Packard Co." "c:\windows\system32\hpinkstsb411lm.dll" "5/19/2011 2:40 PM" ""
+ "PCL hpz3l5ha" "LanguageMonitor" "Hewlett-Packard Company" "c:\windows\system32\hpz3l5ha.dll" "3/15/2007 2:17 AM" ""
"HKLM\Software\Microsoft\Office\Outlook\Addins" "" "" "" "9/11/2014 3:41 PM" ""
X "Connect Class" "OutlookChangeNotifier" "Apple Inc." "c:\program files\common files\apple\mobile device support\outlookchangenotifieraddin.dll" "8/4/2015 1:54 PM" ""
"HKCU\Software\Microsoft\Office\Outlook\Addins" "" "" "" "9/26/2014 9:18 PM" ""
+ "CalendarHelper Class" "iTunes Outlook Add-in" "Apple Inc." "c:\program files\itunes\itunesoutlookaddin.dll" "10/15/2014 3:21 AM" ""
"HKLM\Software\Wow6432Node\Microsoft\Office\Outlook\Addins" "" "" "" "2/20/2015 8:19 PM" ""
+ "MobileMe Outlook Add-in" "MobileMe Outlook Addin" "Apple Inc." "c:\program files (x86)\common files\apple\mobile device support\outmme32.dll" "4/20/2011 5:37 PM" ""
+ "OneNote Notes about Outlook Items" "Microsoft Office OneNote Outlook Add-in" "Microsoft Corporation" "c:\program files (x86)\microsoft office\office12\onbttnol.dll" "8/29/2011 10:40 PM" ""
"HKLM\Software\Wow6432Node\Microsoft\Office\Excel\Addins" "" "" "" "8/18/2012 12:12 PM" ""
+ "Connect Class" "Microsoft Office Live Add-in" "Microsoft Corp." "c:\program files (x86)\microsoft\office live\olconnector.dll" "4/24/2010 9:05 AM" ""
"HKLM\Software\Wow6432Node\Microsoft\Office\PowerPoint\Addins" "" "" "" "8/18/2012 12:12 PM" ""
+ "Connect Class" "Microsoft Office Live Add-in" "Microsoft Corp." "c:\program files (x86)\microsoft\office live\olconnector.dll" "4/24/2010 9:05 AM" ""
"HKLM\Software\Wow6432Node\Microsoft\Office\Word\Addins" "" "" "" "8/18/2012 12:12 PM" ""
+ "Connect Class" "Microsoft Office Live Add-in" "Microsoft Corp." "c:\program files (x86)\microsoft\office live\olconnector.dll" "4/24/2010 9:05 AM" ""
 


#8 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:06:27 PM

Posted 21 January 2016 - 04:30 PM

Did you run a scan with Malwarebytes' Anti-Malware?

 

Ever tried AdwCleaner? If not,

 

 

Please download AdwCleaner.

  • Double-click the adwcleaner.exe to run the tool.
  • Click Scan.
  • When the scan is finished, click Cleaning.
  • When the cleaning process is over, click Logfile and a Notepad window will be opened.
  • Please post the contents into your next reply.

Edited by Phantom010, 21 January 2016 - 04:50 PM.


#9 davlinford

davlinford
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:27 PM

Posted 21 January 2016 - 05:20 PM

Hi Phantom010,

 

I tried malwarebytes a few days ago and it came up clean. I just ran the program you asked me to and will paste the log below. After the scan ran it rebooted and the error message still came up.

 

# AdwCleaner v5.030 - Logfile created 21/01/2016 at 14:05:35
# Updated 17/01/2016 by Xplode
# Database : 2016-01-19.2 [Server]
# Operating system : Windows ™ Vista Home Premium Service Pack 2 (x64)
# Username : Cindy Garside - GARSIDE-PC
# Running from : C:\Users\Cindy Garside\Downloads\adwcleaner_5.030.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[#] Folder Deleted : C:\Program Files (x86)\BearShare Applications
[#] Folder Deleted : C:\Program Files (x86)\globalUpdate
[#] Folder Deleted : C:\Program Files (x86)\iMesh Applications
[#] Folder Deleted : C:\Program Files (x86)\Object
[#] Folder Deleted : C:\Program Files (x86)\predm
[#] Folder Deleted : C:\Program Files (x86)\EliteUnzip
[#] Folder Deleted : C:\ProgramData\Premium
[#] Folder Deleted : C:\ProgramData\Trymedia
[#] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iwin games
[#] Folder Deleted : C:\Users\Cindy Garside\AppData\Local\emaze
[#] Folder Deleted : C:\Users\Cindy Garside\AppData\Local\globalUpdate
[#] Folder Deleted : C:\Users\Cindy Garside\AppData\Local\Installer\Install_26800
[#] Folder Deleted : C:\Users\Cindy Garside\AppData\Local\Installer\Install_9909
[#] Folder Deleted : C:\Users\Cindy Garside\AppData\LocalLow\ShoppingReport
[#] Folder Deleted : C:\Users\Cindy Garside\AppData\Roaming\UpdaterEX
[#] Folder Deleted : C:\Users\Cindy Garside\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Elite Unzip
[#] Folder Deleted : C:\Users\Gigi\AppData\Local\Object Browser
[#] Folder Deleted : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\wol76vpk.default\Extensions\staged\{ad7ce998-a77b-4062-9ffb-1d0b7cb23183}

***** [ Files ] *****

[-] File Deleted : C:\END
[-] File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
[-] File Deleted : C:\Users\Cindy Garside\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ffjcmnpnoopgilmnfhloocdcbnimmmea_0.localstorage
[-] File Deleted : C:\Users\Cindy Garside\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ffjcmnpnoopgilmnfhloocdcbnimmmea_0.localstorage-journal
[-] File Deleted : C:\Users\Cindy Garside\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_paint-net.en.softonic.com_0.localstorage
[-] File Deleted : C:\Users\Cindy Garside\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_paint-net.en.softonic.com_0.localstorage-journal
[-] File Deleted : C:\Users\Cindy Garside\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.shopathome.com_0.localstorage
[-] File Deleted : C:\Users\Cindy Garside\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.shopathome.com_0.localstorage-journal
[-] File Deleted : C:\Users\Cindy Garside\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_iblenkmcolcdonmlfknbpbgjebabcoae_0.localstorage
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_iblenkmcolcdonmlfknbpbgjebabcoae_0.localstorage-journal
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_cdn.adbabylon.com_0.localstorage
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_cdn.adbabylon.com_0.localstorage-journal
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
[-] File Deleted : C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal
[-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
[-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
[-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_answers.ask.com_0.localstorage
[-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_translation.babylon.com_0.localstorage
[-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
[-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal
[-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
[-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
[-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
[-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal
[-] File Deleted : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\wol76vpk.default\searchplugins\mywebsearch.xml
[-] File Deleted : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\wol76vpk.default\searchplugins\safesearch.xml
[-] File Deleted : C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\wol76vpk.default\user.js
[-] File Deleted : C:\Users\Public\Desktop\eBay.lnk

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : YTDownloader
[-] Task Deleted : Microsoft\Windows\Multimedia\SMupdate3
[-] Task Deleted : Microsoft\Windows\Maintenance\SMupdate2

***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Search
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\BHO.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [C:\Program Files (x86)\iWebar\iWebar-nova.exe]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [C:\Program Files (x86)\Object Browser\Object Browser-nova.exe]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [Object Browser-bg.exe]
[-] Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{EB132DB0-A4CA-11DF-9732-0E29E0D72085}]
[-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{EB132DB0-A4CA-11DF-9732-0E29E0D72085}]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415C-8A37-763AE183E7E4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A07E5BFF-B16C-4ABA-A30F-514213A945E6}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EBB289A-2D7B-465B-825F-1530B813E95A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B37B4BA6-334E-72C1-B57E-6AFE8F8A5AF3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B77AD4AC-C1C2-B293-7737-71E13A11FFEA}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CD5C92AE-97B0-4BC3-BA65-BA0308D543BF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E773F2CF-5E6E-FF2B-81A1-AC581A26B2B2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{596BB86E-F1E5-A1DE-3363-41AB634E77EF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A3492A3A-6715-9371-F8DB-1C48CC4DAAA1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D15809AA-50CF-4EE0-BCC9-E91A681BEFD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{96F7FABC-5789-EFA4-B6ED-1272F4C1D27B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9863E762-BACC-46E4-8CAA-2A6ADA06B65B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A147AA03-820F-4A0F-9F34-D6CB4004A2F9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AA2E16F2-387A-415F-BA95-B89BAF3AF109}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{474597C5-AB09-49D6-A4D5-2E8D7341384E}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{91C18ED5-5E1C-4AE5-A148-A861DE8C8E16}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{0974BA1E-64EC-11DE-B2A5-E43756D89593}]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{1BB22D38-A411-4B13-A746-C2A4F4EC7344}]
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{1BB22D38-A411-4B13-A746-C2A4F4EC7344}]
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{27BF8F8D-58B8-D41C-F913-B7EEB57EF6F6}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A07E5BFF-B16C-4ABA-A30F-514213A945E6}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EBB289A-2D7B-465B-825F-1530B813E95A}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B37B4BA6-334E-72C1-B57E-6AFE8F8A5AF3}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B77AD4AC-C1C2-B293-7737-71E13A11FFEA}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{CD5C92AE-97B0-4BC3-BA65-BA0308D543BF}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E773F2CF-5E6E-FF2B-81A1-AC581A26B2B2}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{596BB86E-F1E5-A1DE-3363-41AB634E77EF}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A3492A3A-6715-9371-F8DB-1C48CC4DAAA1}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
[!] Key Not Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D15809AA-50CF-4EE0-BCC9-E91A681BEFD3}
[-] Key Deleted : HKCU\Software\bearsharemediabartb
[-] Key Deleted : HKCU\Software\GlobalUpdate
[-] Key Deleted : HKCU\Software\IM
[-] Key Deleted : HKCU\Software\Imesh
[-] Key Deleted : HKCU\Software\ImInstaller
[-] Key Deleted : HKCU\Software\Proxy
[-] Key Deleted : HKCU\Software\SGPUpdater
[-] Key Deleted : HKCU\Software\UpdaterEX
[-] Key Deleted : HKCU\Software\YahooPartnerToolbar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\bearsharemediabartb
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Hotbar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\iMeshMediabarTb
[-] Key Deleted : HKCU\Software\AppDataLow\Software\MyWebSearch
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Object Browser
[-] Key Deleted : HKCU\Software\AppDataLow\Software\ShoppingReport
[-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate
[-] Key Deleted : HKLM\SOFTWARE\Trymedia Systems
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\UpdaterEX
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\facetheme
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{597FB4A5-DD86-4316-A410-7E8074CC2CCE}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ClearThink
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\facetheme
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\mywebsearch bar uninstall
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Optimizer Pro_is1
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Search Guard Plus
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Search Guard Plus Updater
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\UpdaterEX
[-] Key Deleted : [x64] HKLM\SOFTWARE\SearchModule
[-] Key Deleted : HKU\.DEFAULT\Software\PennyBee
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\Object Browser
[-] Key Deleted : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\iWebar
[-] Key Deleted : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Object Browser
[-] Key Deleted : HKU\S-1-5-19\Software\Proxy
[-] Key Deleted : HKU\S-1-5-20\Software\Proxy
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{F8ED5CD5-F20C-4E7E-983C-C0E12444AA51}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F8ED5CD5-F20C-4E7E-983C-C0E12444AA51}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F8ED5CD5-F20C-4E7E-983C-C0E12444AA51}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\astromenda.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\conduit.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\outfox.tv
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\shoppingate.info
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\trovi.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www-search.net
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
[-] Key Deleted : HKLM\SOFTWARE\Classes\AniGIFCtrl.AniGIF
[-] Key Deleted : HKLM\SOFTWARE\Classes\AniGIFPpg.AniGIFPpg
[-] Key Deleted : HKLM\SOFTWARE\Classes\AniGIFPpg2.AniGIFPpg2

***** [ Web browsers ] *****

[-] [C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\wol76vpk.default\prefs.js] [Preference] Deleted : user_pref("browser.search.defaulturl", "hxxp://www.startsearcher.com/?q=");
[-] [C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\wol76vpk.default\prefs.js] [Preference] Deleted : user_pref("browser.search.selectedEngine", "Astromenda");
[-] [C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\wol76vpk.default\prefs.js] [Preference] Deleted : user_pref("extensions.mywebsearch.openSearchURL", "hxxp://s("extensions.sudoku.installerVersion", "");
[-] [C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\wol76vpk.default\prefs.js] [Preference] Deleted : user_pref("keyword.URL", "hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCxdm492YYUS&fl=0&ptb=FVqOIMtMXJ3CgJymAPNtqA&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor="[...]
[-] [C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\wol76vpk.default\prefs.js] [Preference] Deleted : user_pref("browser.search.selectedEngine", "Astromenda");
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Gigi\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [24221 bytes] ##########



#10 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:06:27 PM

Posted 21 January 2016 - 05:33 PM

There was still a lot of stuff to clean!

 

This one is pretty puzzling. I did encounter this problem on many machines. Turned out to be easier to fix.

 

Gotta do something, but will be back later.


Edited by Phantom010, 21 January 2016 - 05:33 PM.


#11 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:06:27 PM

Posted 21 January 2016 - 08:29 PM

I can't believe I missed that before! I had to leave and went through the logs a little too fast... Not showing in Autoruns, but was in the first log for Scheduled Tasks

 

Folder: \Microsoft\Windows\Maintenance
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============

SMupdate2                                1/21/2016 1:53:41 PM   Running

 

 

 

Folder: \Microsoft\Windows\Multimedia
TaskName                                 Next Run Time          Status         
======================================== ====================== ===============
SMupdate3                                1/21/2016 3:53:43 PM   Ready          
SystemSoundsService                      N/A                    Running      

 

 

 

I'm surprised you're still getting the error message after running AdwCleaner. It's showing in the report.

 

[-] Task Deleted : Microsoft\Windows\Multimedia\SMupdate3
[-] Task Deleted : Microsoft\Windows\Maintenance\SMupdate2

 

 

Still getting it?

 

 

If you are, please run AdwCleaner again and restart the computer.

 

 

If still no luck,

 

Click Start > Run > type control schedtasks

 

Press Enter.

 

Do you see anything resembling those tasks?

 

Microsoft\Windows\Maintenance\SMupdate2

 

Microsoft\Windows\Multimedia\SMupdate3

 

Right-click and delete them both!


Edited by Phantom010, 21 January 2016 - 08:40 PM.


#12 davlinford

davlinford
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:27 PM

Posted 21 January 2016 - 11:48 PM

Hi Phantom010,

 

I ran Adwcleaner again and it said that it cleaned it but it did not. I followed the manual instructions you provided to me and it worked!! I really appreciate your help. Things look good now.

 

Thanks,

David



#13 Phantom010

Phantom010

  • Members
  • 1,022 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Cyberspace
  • Local time:06:27 PM

Posted 22 January 2016 - 07:19 AM

You're welcome!



#14 aajjaa

aajjaa

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:San Pedro, CA
  • Local time:03:27 PM

Posted 06 June 2016 - 08:21 PM

Read the above exchange as I have the same problem on my HPE-510f using Win 7 64bit. I had previously used ccleaner more than once but still had the Rundll SysMenu.dll not found Notice.  Towards the end you suggested using 'control schedtasks'.  I did so but did not find \SMupdate2 or 3.  I did find \SMupdate1.  I deleted it and so far have not had the error. It occurred both at boot and during general operations. Have not rebooted yet but will report back once I do.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users