TechSpot

Toshiba Satelite File corruption problem

By soccer27
Aug 27, 2013
  1. (C:) file TI102605W0F says it is corrupt when I try to do a system restore.
    before starting up it wants to scan the hard drives

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-08-2013
    Ran by SYSTEM on 27-08-2013 22:16:51
    Running from C:\
    Windows 7 Home Premium (X86) OS Language: English(US)
    Internet Explorer Version 9
    Boot Mode: Recovery

    The current controlset is ControlSet001
    ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

    ==================== Registry (Whitelisted) ==================

    HKLM\...\Run: [] - [x]
    HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7625248 2009-07-28] (Realtek Semiconductor)
    HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1545512 2009-07-20] (Synaptics Incorporated)
    HKLM\...\Run: [SVPWUTIL] - C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe [352256 2009-07-09] (TOSHIBA CORPORATION)
    HKLM\...\Run: [HWSetup] - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [425984 2009-06-02] (TOSHIBA Electronics, Inc.)
    HKLM\...\Run: [KeNotify] - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe [34088 2009-01-13] (TOSHIBA CORPORATION)
    HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [476512 2009-08-05] (TOSHIBA Corporation)
    HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [460088 2009-07-28] (TOSHIBA Corporation)
    HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [738616 2009-08-05] (TOSHIBA Corporation)
    HKLM\...\Run: [ToshibaServiceStation] - C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1295736 2011-02-11] (TOSHIBA Corporation)
    HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [611672 2009-09-17] (TOSHIBA Corporation)
    HKLM\...\Run: [NortonOnlineBackupReminder] - C:\Program Files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe [529256 2009-07-16] (Toshiba)
    HKLM\...\Run: [dcmsvc] - C:\Program Files\dcmsvc\dcmsvc.exe [30440 2009-04-07] ()
    HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
    HKLM\...\Run: [FixCamera] - C:\windows\FixCamera.exe [20480 2007-07-11] ()
    HKLM\...\Run: [tsnp2std] - C:\windows\tsnp2std.exe [270336 2007-05-12] ()
    HKLM\...\Run: [snp2std] - C:\windows\vsnp2std.exe [344064 2007-05-10] (Sonix)
    HKLM\...\Run: [DATAMNGR] - C:\PROGRA~1\IMESHA~1\Mediabar\Datamngr\DATAMN~1.EXE [x]
    HKLM\...\Run: [lxdjmon.exe] - "C:\Program Files\Lexmark 1400 Series\lxdjmon.exe" [x]
    HKLM\...\Run: [lxdjamon] - C:\Program Files\Lexmark 1400 Series\lxdjamon.exe [20480 2007-03-05] (Lexmark)
    HKLM\...\Run: [LXDJCATS] - C:\windows\system32\spool\DRIVERS\W32X86\3\LXDJtime.dll [102400 2007-02-09] (Lexmark International, Inc.)
    HKLM\...\Run: [vProt] - C:\Program Files\AVG SafeGuard toolbar\vprot.exe [2314416 2013-08-16] ()
    HKLM\...\Run: [SearchProtectAll] - C:\Program Files\SearchProtect\bin\cltmng.exe [2852640 2013-05-07] (Conduit)
    HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-04-30] (Apple Inc.)
    HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
    HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-06-30] (AVG Technologies CZ, s.r.o.)
    HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] ATTENTION! ====> ZeroAccess?
    HKU\KV\...\Run: [MyTOSHIBA] - C:\Program Files\TOSHIBA\My Toshiba\MyToshiba.exe [ 2009-08-06] (TOSHIBA)
    HKU\KV\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [ 2013-01-08] (Skype Technologies S.A.)
    HKU\KV\...\Run: [ROC_ROC_APR2013_AV] - C:\Users\KV\AppData\Roaming\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe /PROMPT --mid a4c61421756647d681ddd16f64a6e16e-3b955f333b2602aabe7386a44fb5492f14699849 --CMPID ROC_APR2013_AV [x]
    HKU\KV\...\Run: [SearchProtect] - C:\Users\KV\AppData\Roaming\SearchProtect\bin\cltmng.exe [ 2013-05-07] (Conduit)
    HKU\KV\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2009-09-03] (Google Inc.)
    HKU\Rebecca\...\Run: [MyTOSHIBA] - C:\Program Files\TOSHIBA\My Toshiba\MyToshiba.exe [ 2009-08-06] (TOSHIBA)
    Startup: C:\Users\KV\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

    ========================== Services (Whitelisted) =================

    S2 avgfws; C:\Program Files\AVG\AVG2013\avgfws.exe [1432080 2013-07-25] (AVG Technologies CZ, s.r.o.)
    S2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)
    S2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.)
    S2 cfWiMAXService; C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [185712 2009-08-10] (TOSHIBA CORPORATION)
    S2 CltMngSvc; C:\Program Files\SearchProtect\bin\CltMngSvc.exe [97056 2013-05-07] (Conduit)
    S2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [46448 2009-03-10] (TOSHIBA CORPORATION)
    S2 DatamngrCoordinator; C:\Program Files\Search Results Toolbar\Datamngr\DatamngrCoordinator.exe [4558912 2013-04-03] (iMesh Inc.)
    S2 DefaultTabSearch; C:\Program Files\DefaultTab\DefaultTabSearch.exe [572928 2013-02-10] ()
    S2 lxdj_device; C:\windows\system32\lxdjcoms.exe [537520 2007-03-12] ( )
    S2 Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll [135024 2010-01-28] (Symantec Corporation)
    S3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [54136 2011-02-11] (TOSHIBA Corporation)
    S3 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [111960 2009-09-17] (TOSHIBA Corporation)
    S2 vToolbarUpdater15.5.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [1643184 2013-08-16] (AVG Secure Search)

    ==================== Drivers (Whitelisted) ====================

    S1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6x.sys [50296 2012-09-04] (AVG Technologies CZ, s.r.o.)
    S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-19] (AVG Technologies CZ, s.r.o.)
    S0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-19] (AVG Technologies CZ, s.r.o.)
    S1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-03-01] (AVG Technologies CZ, s.r.o.)
    S1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-19] (AVG Technologies CZ, s.r.o.)
    S0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-19] (AVG Technologies CZ, s.r.o.)
    S0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-06-30] (AVG Technologies CZ, s.r.o.)
    S0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-07-09] (AVG Technologies CZ, s.r.o.)
    S1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-20] (AVG Technologies CZ, s.r.o.)
    S1 avgtp; C:\windows\system32\drivers\avgtpx86.sys [37664 2013-08-16] (AVG Technologies)
    S1 BHDrvx86; C:\Windows\System32\Drivers\NIS\1008000.029\BHDrvx86.sys [259632 2009-08-21] (Symantec Corporation)
    S1 ccHP; C:\Windows\System32\Drivers\NIS\1008000.029\ccHPx86.sys [482432 2010-01-28] (Symantec Corporation)
    S0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-13] (Microsoft Corporation)
    S1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [371248 2010-09-16] (Symantec Corporation)
    S1 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100119.001\IDSvix86.sys [343088 2009-10-28] (Symantec Corporation)
    S0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [36208 2009-07-02] (COMPAL ELECTRONIC INC.)
    S3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [379904 2010-03-31] (Realtek Semiconductor Corporation )
    S3 SNP2STD; C:\Windows\System32\DRIVERS\snp2sxp.sys [12212864 2007-08-31] ()
    S3 SRTSP; C:\Windows\System32\Drivers\NIS\1008000.029\SRTSP.SYS [308272 2009-08-21] (Symantec Corporation)
    S1 SRTSPX; C:\Windows\system32\drivers\NIS\1008000.029\SRTSPX.SYS [43696 2009-08-21] (Symantec Corporation)
    S0 SymEFA; C:\Windows\System32\drivers\NIS\1008000.029\SYMEFA.SYS [310320 2009-08-21] (Symantec Corporation)
    S3 SymEvent; C:\windows\system32\Drivers\SYMEVENT.SYS [124976 2009-12-25] (Symantec Corporation)
    S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [25648 2009-09-03] (Symantec Corporation)
    S1 SYMTDI; C:\Windows\System32\Drivers\NIS\1008000.029\SYMTDI.SYS [217136 2009-08-21] (Symantec Corporation)
    S3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100123.023\NAVENG.SYS [x]
    S3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100123.023\NAVEX15.SYS [x]
    S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [x]
    S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x]
    S3 SYMFW; \SystemRoot\System32\Drivers\NIS\1007020.00B\SYMFW.SYS [x]
    S3 SYMNDISV; \SystemRoot\System32\Drivers\NIS\1007020.00B\SYMNDISV.SYS [x]
    S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x]

    ==================== NetSvcs (Whitelisted) ===================


    ==================== One Month Created Files and Folders ========

    2013-08-27 18:02 - 2013-08-27 18:03 - 01072975 _____ (Farbar) C:\FRST.exe
    2013-08-21 08:08 - 2013-08-21 08:08 - 17139080 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
    2013-08-16 22:20 - 2013-08-16 22:23 - 00000000 ____D C:\Windows\System32\MRT
    2013-08-09 10:21 - 2013-08-09 10:21 - 00000000 ____D C:\ProgramData\TorchCrashHandler
    2013-08-04 09:30 - 2013-08-04 09:30 - 00002141 _____ C:\Users\Public\Desktop\Google Earth.lnk
    2013-08-04 09:06 - 2013-08-04 09:06 - 00000000 ____D C:\Users\KV\AppData\Roaming\AVG2013
    2013-08-04 08:55 - 2013-08-04 08:55 - 00000906 _____ C:\Users\Public\Desktop\AVG 2013.lnk
    2013-08-04 08:55 - 2013-08-04 08:55 - 00000000 ____D C:\Users\KV\AppData\Roaming\TuneUp Software
    2013-08-04 08:47 - 2013-08-04 08:59 - 00000000 ____D C:\ProgramData\AVG2013
    2013-08-04 08:42 - 2013-08-04 09:03 - 00000000 ____D C:\Users\KV\AppData\Local\Avg2013
    2013-08-04 08:42 - 2013-08-04 08:42 - 00000000 ____D C:\Users\KV\AppData\Local\MFAData

    ==================== One Month Modified Files and Folders =======

    2013-08-27 18:10 - 2013-07-11 17:23 - 00000000 ____D C:\Program Files\LyricsSpeaker
    2013-08-27 18:09 - 2013-04-22 15:17 - 00000000 ____D C:\ProgramData\Datamngr
    2013-08-27 18:09 - 2009-07-13 20:39 - 00094447 _____ C:\Windows\setupact.log
    2013-08-27 18:06 - 2013-06-02 13:40 - 00141430 _____ C:\Windows\IE10_main.log
    2013-08-27 18:06 - 2011-05-12 19:20 - 00242333 _____ C:\Windows\IE9_main.log
    2013-08-27 18:06 - 2009-10-17 13:30 - 01788148 _____ C:\Windows\WindowsUpdate.log
    2013-08-27 18:06 - 2009-07-13 20:34 - 00016304 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2013-08-27 18:06 - 2009-07-13 20:34 - 00016304 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2013-08-27 18:03 - 2013-08-27 18:02 - 01072975 _____ (Farbar) C:\FRST.exe
    2013-08-27 18:00 - 2011-02-28 08:43 - 00000000 ____D C:\ProgramData\MFAData
    2013-08-27 17:58 - 2013-04-22 14:42 - 00000000 ____D C:\Program Files\Lx_cats
    2013-08-21 08:08 - 2013-08-21 08:08 - 17139080 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
    2013-08-21 08:08 - 2012-10-08 18:22 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
    2013-08-21 08:08 - 2011-05-19 11:00 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
    2013-08-21 08:04 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET
    2013-08-16 22:23 - 2013-08-16 22:20 - 00000000 ____D C:\Windows\System32\MRT
    2013-08-16 22:20 - 2009-12-25 04:23 - 75778376 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2013-08-16 22:20 - 2009-10-17 13:34 - 00000000 ____D C:\ProgramData\Microsoft Help
    2013-08-16 22:16 - 2009-09-03 00:26 - 00740814 _____ C:\Windows\System32\PerfStringBackup.INI
    2013-08-16 19:01 - 2013-05-04 06:01 - 00000000 ____D C:\Program Files\AVG SafeGuard toolbar
    2013-08-16 19:00 - 2013-05-04 06:01 - 00037664 _____ (AVG Technologies) C:\Windows\System32\Drivers\avgtpx86.sys
    2013-08-09 11:45 - 2012-04-10 17:18 - 00000000 ____D C:\Users\KV\AppData\Roaming\Skype
    2013-08-09 11:10 - 2013-04-22 15:18 - 00000000 ____D C:\Users\KV\AppData\Local\Torch
    2013-08-09 10:21 - 2013-08-09 10:21 - 00000000 ____D C:\ProgramData\TorchCrashHandler
    2013-08-09 10:15 - 2013-05-04 06:01 - 00000000 ____D C:\Users\KV\AppData\Local\AVG SafeGuard toolbar
    2013-08-04 09:30 - 2013-08-04 09:30 - 00002141 _____ C:\Users\Public\Desktop\Google Earth.lnk
    2013-08-04 09:29 - 2009-09-03 00:27 - 00000000 ____D C:\Program Files\Google
    2013-08-04 09:06 - 2013-08-04 09:06 - 00000000 ____D C:\Users\KV\AppData\Roaming\AVG2013
    2013-08-04 09:04 - 2013-05-15 20:40 - 00002100 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2013-08-04 09:03 - 2013-08-04 08:42 - 00000000 ____D C:\Users\KV\AppData\Local\Avg2013
    2013-08-04 09:02 - 2011-02-28 08:53 - 00000000 ____D C:\ProgramData\AVG10
    2013-08-04 08:59 - 2013-08-04 08:47 - 00000000 ____D C:\ProgramData\AVG2013
    2013-08-04 08:55 - 2013-08-04 08:55 - 00000906 _____ C:\Users\Public\Desktop\AVG 2013.lnk
    2013-08-04 08:55 - 2013-08-04 08:55 - 00000000 ____D C:\Users\KV\AppData\Roaming\TuneUp Software
    2013-08-04 08:49 - 2011-02-28 09:24 - 00000000 ___HD C:\$AVG
    2013-08-04 08:46 - 2011-02-28 08:52 - 00000000 ____D C:\Program Files\AVG
    2013-08-04 08:42 - 2013-08-04 08:42 - 00000000 ____D C:\Users\KV\AppData\Local\MFAData
    2013-08-04 08:25 - 2011-02-28 08:53 - 00000000 ____D C:\Windows\System32\Drivers\AVG
    2013-07-30 13:57 - 2009-09-03 00:39 - 00075376 _____ C:\Windows\PFRO.log

    Files to move or delete:
    ====================
    C:\Users\KV\AppData\Local\Temp\ConduitInstaller.exe
    C:\Users\KV\AppData\Local\Temp\Couponscom.exe
    C:\Users\KV\AppData\Local\Temp\CUninst.exe
    C:\Users\KV\AppData\Local\Temp\GLB1A2B.EXE
    C:\Users\KV\AppData\Local\Temp\iMesh_3535918.exe
    C:\Users\KV\AppData\Local\Temp\iMesh_setup.exe
    C:\Users\KV\AppData\Local\Temp\InstallFlashPlayer.exe
    C:\Users\KV\AppData\Local\Temp\Installhelper.dll
    C:\Users\KV\AppData\Local\Temp\install_flashplayer11x32axau_gtbp_chra_aih.exe
    C:\Users\KV\AppData\Local\Temp\LyrcStmp.exe
    C:\Users\KV\AppData\Local\Temp\nsl4F8D.exe
    C:\Users\KV\AppData\Local\Temp\nsv65A.exe
    C:\Users\KV\AppData\Local\Temp\nsy23AC.exe
    C:\Users\KV\AppData\Local\Temp\nsyDAD7.exe
    C:\Users\KV\AppData\Local\Temp\Second Life Setup.exe
    C:\Users\KV\AppData\Local\Temp\SingAlong.exe
    C:\Users\KV\AppData\Local\Temp\sngalng.exe
    C:\Users\KV\AppData\Local\Temp\SPStub.exe
    C:\Users\KV\AppData\Local\Temp\SRAssetsHelper.dll
    C:\Users\KV\AppData\Local\Temp\ToolbarHelper.exe
    C:\Users\KV\AppData\Local\Temp\TorchSetupFull.exe
    C:\Users\KV\AppData\Local\Temp\~nsu.tmp\Au_.exe
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\GoogleCrashHandler.exe
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\GoogleCrashHandler64.exe
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\GoogleUpdate.exe
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\GoogleUpdateBroker.exe
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\GoogleUpdateOnDemand.exe
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\GoogleUpdateSetup.exe
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdate.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_am.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_ar.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_bg.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_bn.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_ca.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_cs.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_da.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_de.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_el.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_en-GB.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_en.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_es-419.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_es.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_et.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_fa.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_fi.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_fil.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_fr.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_gu.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_hi.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_hr.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_hu.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_id.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_is.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_it.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_iw.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_ja.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_kn.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_ko.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_lt.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_lv.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_ml.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_mr.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_ms.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_nl.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_no.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_pl.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_pt-BR.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_pt-PT.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_ro.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_ru.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_sk.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_sl.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_sr.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_sv.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_sw.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_ta.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_te.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_th.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_tr.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_uk.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_ur.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_vi.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_zh-CN.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\goopdateres_zh-TW.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\npGoogleUpdate3.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\psmachine.dll
    C:\Users\KV\AppData\Local\Temp\{BF8D7337-B693-4D7E-9CBC-D393297C98AD}\psuser.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\GoogleCrashHandler.exe
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\GoogleCrashHandler64.exe
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\GoogleUpdate.exe
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\GoogleUpdateBroker.exe
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\GoogleUpdateOnDemand.exe
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\GoogleUpdateSetup.exe
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdate.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_am.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_ar.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_bg.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_bn.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_ca.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_cs.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_da.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_de.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_el.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_en-GB.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_en.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_es-419.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_es.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_et.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_fa.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_fi.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_fil.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_fr.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_gu.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_hi.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_hr.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_hu.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_id.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_is.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_it.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_iw.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_ja.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_kn.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_ko.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_lt.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_lv.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_ml.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_mr.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_ms.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_nl.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_no.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_pl.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_pt-BR.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_pt-PT.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_ro.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_ru.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_sk.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_sl.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_sr.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_sv.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_sw.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_ta.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_te.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_th.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_tr.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_uk.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_ur.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_vi.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_zh-CN.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\goopdateres_zh-TW.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\npGoogleUpdate3.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\psmachine.dll
    C:\Users\KV\AppData\Local\Temp\{BD331761-471A-426F-B9E8-F4738FE68C91}\psuser.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\GoogleCrashHandler.exe
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\GoogleCrashHandler64.exe
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\GoogleUpdate.exe
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\GoogleUpdateBroker.exe
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\GoogleUpdateOnDemand.exe
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\GoogleUpdateSetup.exe
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdate.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_am.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_ar.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_bg.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_bn.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_ca.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_cs.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_da.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_de.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_el.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_en-GB.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_en.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_es-419.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_es.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_et.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_fa.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_fi.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_fil.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_fr.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_gu.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_hi.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_hr.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_hu.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_id.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_is.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_it.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_iw.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_ja.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_kn.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_ko.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_lt.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_lv.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_ml.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_mr.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_ms.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_nl.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_no.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_pl.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_pt-BR.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_pt-PT.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_ro.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_ru.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_sk.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_sl.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_sr.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_sv.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_sw.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_ta.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_te.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_th.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_tr.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_uk.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_ur.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_vi.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_zh-CN.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\goopdateres_zh-TW.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\npGoogleUpdate3.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\psmachine.dll
    C:\Users\KV\AppData\Local\Temp\{A4D7BBAA-AF38-4310-ABB7-71A0F861B77B}\psuser.dll
    C:\Users\KV\AppData\Local\Temp\{8053FD62-0EBA-4FCE-A12A-C7ECA5FACED6}\{75438C0E-9925-412E-AD85-D0E71C6CE2ED}\difxapi.dll
    C:\Users\KV\AppData\Local\Temp\_ir_sf_temp_0\npCouponPrinter.dll
    C:\Users\KV\AppData\Local\Temp\_ir_sf_temp_0\npMozCouponPrinter.dll
    C:\Users\KV\AppData\Local\Temp\nst2E42.tmp\InetC.dll
    C:\Users\KV\AppData\Local\Temp\nst2E42.tmp\nsExec.dll
    C:\Users\KV\AppData\Local\Temp\nst2E42.tmp\System.dll
    C:\Users\KV\AppData\Local\Temp\nsr13EE.tmp\Helper.dll
    C:\Users\KV\AppData\Local\Temp\nsr13EE.tmp\nsr1611.tmp\setup.exe
    C:\Users\KV\AppData\Local\Temp\nso63A3.tmp\Helper.dll
    C:\Users\KV\AppData\Local\Temp\nsj4940.tmp\NSISpcre.dll
    C:\Users\KV\AppData\Local\Temp\DIQM\FlashPlayer_151\bin.dll
    C:\Users\KV\AppData\Local\Temp\DIQM\FlashPlayer_151\config.dll
    C:\Users\KV\AppData\Local\Temp\DIQM\FlashPlayer_151\DomaIQ.exe
    C:\Users\KV\AppData\Local\Temp\DIQM\FlashPlayer_151\DomaIQ10.exe
    C:\Users\KV\AppData\Local\Temp\DIQM\FlashPlayer_151\routes.dll
    C:\Users\KV\AppData\Local\Temp\DIQM\FlashPlayer_151\setup__120.exe
    C:\Users\KV\AppData\Local\Temp\DIQM\FlashPlayer_151\software\Addlyrics.exe
    C:\Users\KV\AppData\Local\Temp\DIQM\FlashPlayer_151\software\Setup__120_i19452636.exe
    C:\Users\KV\AppData\Local\Temp\DIQM\FlashPlayer_151\software\StrongVault.exe
    C:\Users\KV\AppData\Local\Temp\ct3289847\chLogic.exe
    C:\Users\KV\AppData\Local\Temp\ct3289847\ctbe.exe
    C:\Users\KV\AppData\Local\Temp\ct3289847\ieLogic.exe
    C:\Users\KV\AppData\Local\Temp\ct3289847\spch.exe
    C:\Users\KV\AppData\Local\Temp\ct2612669\chLogic.exe
    C:\Users\KV\AppData\Local\Temp\ct2612669\ieLogic.exe
    C:\Users\KV\AppData\Local\Temp\CRX_DF399A9B283A\ChromeRecovery.exe
    C:\Users\KV\AppData\Local\Temp\CRX_DF399A9B283A\GoogleUpdateSetup.exe
    C:\Users\KV\AppData\Local\Temp\A9A7.dir\InstallFlashPlayer.exe
    C:\Users\KV\AppData\Local\Temp\152153_10.42.25.TC10106100A.temp\tinstall.exe
    C:\Users\KV\AppData\Local\Temp\152153_10.42.25.TC10106100A.temp\tinstallwb.exe
    C:\Users\KV\AppData\Local\Temp\152153_10.42.25.TC10106100A.temp\TSSsetup.exe
    C:\Users\KV\AppData\Local\Temp\152153_10.42.25.TC10106100A.temp\WBDJA44I.DLL
    C:\Users\KV\AppData\Local\Temp\152153_10.42.25.TC10106100A.temp\WBTOS45I.DLL
    C:\Users\KV\AppData\Local\Temp\._msige61\GoogleEarth.exe
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemyext.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\earthps.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\geplugin.exe
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\ge_expat.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\googleearth_free.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\icudt.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\IGAttrs.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\IGCore.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\IGExportCommon.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\IGGfx.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\IGMath.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\IGOpt.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\IGSg.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\IGUtils.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\Leap.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\msvcp100.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\msvcr100.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\npgeplugin.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\plugin_ax.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\QtCore4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\QtGui4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\QtNetwork4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\QtWebKit4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\imageformats\qgif4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\imageformats\qjpeg4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemy\optimizations\IGOptExtension.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\D3DCompiler_43.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\d3dx9_43.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\IGAttrs.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\IGGfx.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\IGSg.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\libEGL.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemy\ogles20\libGLESv2.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemy\ogl\IGAttrs.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemy\ogl\IGGfx.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\plugin\alchemy\ogl\IGSg.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemyext.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\earthflashsol.exe
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\earthps.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\ge_expat.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\googleearth.exe
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\googleearth_free.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\gpsbabel.exe
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\icudt.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\IGAttrs.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\IGCore.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\IGExportCommon.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\IGGfx.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\IGMath.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\IGOpt.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\IGSg.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\IGUtils.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\Leap.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\msvcp100.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\msvcr100.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\QtCore4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\QtGui4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\QtNetwork4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\QtWebKit4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\Plugins\npgeinprocessplugin.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\imageformats\qgif4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\imageformats\qjpeg4.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemy\optimizations\IGOptExtension.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\D3DCompiler_43.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\d3dx9_43.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\IGAttrs.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\IGGfx.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\IGSg.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\libEGL.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemy\ogles20\libGLESv2.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemy\ogl\IGAttrs.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemy\ogl\IGGfx.dll
    C:\Users\KV\AppData\Local\Temp\._msige61\program files\Google\Google Earth\client\alchemy\ogl\IGSg.dll
    C:\Users\Public\dcmsvcsetup.exe
    C:\Users\Public\invokesi.exe

    ==================== Known DLLs (Whitelisted) ============


    ==================== Bamital & volsnap Check =================

    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points =========================

    Restore point made on: 2013-07-14 19:21:27
    Restore point made on: 2013-07-15 22:00:28
    Restore point made on: 2013-07-16 05:51:49
    Restore point made on: 2013-07-28 13:41:40
    Restore point made on: 2013-07-30 13:53:56
    Restore point made on: 2013-07-30 14:13:58
    Restore point made on: 2013-07-30 14:52:31
    Restore point made on: 2013-08-04 08:46:15
    Restore point made on: 2013-08-04 08:47:34
    Restore point made on: 2013-08-04 09:29:15
    Restore point made on: 2013-08-08 10:31:02
    Restore point made on: 2013-08-09 10:18:43
    Restore point made on: 2013-08-09 12:00:29
    Restore point made on: 2013-08-09 16:48:41
    Restore point made on: 2013-08-10 14:54:19
    Restore point made on: 2013-08-11 17:47:35
    Restore point made on: 2013-08-11 18:44:25
    Restore point made on: 2013-08-12 07:51:37
    Restore point made on: 2013-08-16 22:13:13
    Restore point made on: 2013-08-17 06:00:17
    Restore point made on: 2013-08-17 17:03:28
    Restore point made on: 2013-08-19 19:21:08
    Restore point made on: 2013-08-19 20:01:57
    Restore point made on: 2013-08-20 05:43:02
    Restore point made on: 2013-08-20 17:09:14
    Restore point made on: 2013-08-21 08:37:59
    Restore point made on: 2013-08-27 18:04:27
    Restore point made on: 2013-08-27 18:06:50

    ==================== Memory info ===========================

    Percentage of memory in use: 21%
    Total physical RAM: 1912.89 MB
    Available physical RAM: 1504.28 MB
    Total Pagefile: 1912.89 MB
    Available Pagefile: 1509.41 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1957.95 MB

    ==================== Drives ================================

    Drive c: (TI102605W0F) (Fixed) (Total:223.27 GB) (Free:167.63 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive d: (System) (Fixed) (Total:1.46 GB) (Free:1.28 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: 6C676C67)
    Partition 1: (Active) - (Size=1 GB) - (Type=27)
    Partition 2: (Not Active) - (Size=223 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=8 GB) - (Type=17)


    LastRegBack: 2012-02-04 13:52

    ==================== End Of Log ============================
     
  2. Broni

    Broni Malware Annihilator Posts: 52,897   +344

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ================================

    I don't quite understand what you're saying.
    What are your computer problems?
    Why are you trying to use system restore?
    Is the computer bootable?
    What does want to scan drives?

    Please be more clear.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...