Hi,
I scanned my system through farbar recovery scan tool. scan result are listed below
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-04-2017
Ran by ROSHITH (20-04-2017 10:20:43)
Running from C:\Documents and Settings\ROSHITH\My Documents\Downloads
Microsoft Windows XP Professional Service Pack 3 (X86) (2016-01-16 08:23:21)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-436374069-790525478-1644491937-500 - Administrator - Enabled)
Guest (S-1-5-21-436374069-790525478-1644491937-501 - Limited - Enabled) => %SystemDrive%\Documents and Settings\Guest
HelpAssistant (S-1-5-21-436374069-790525478-1644491937-1000 - Limited - Disabled)
ROSHITH (S-1-5-21-436374069-790525478-1644491937-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\ROSHITH
SUPPORT_388945a0 (S-1-5-21-436374069-790525478-1644491937-1002 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: ESET NOD32 Antivirus 9.0.408.0 (Enabled - Up to date) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 23 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 23.0.0.162 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 25.0.0.127 - Adobe Systems Incorporated)
Adobe Photoshop CS (HKLM\...\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}) (Version: CS - Adobe Systems, Inc.)
Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Advertising Center (Version: 0.0.0.1 - Nero AG) Hidden
Anvsoft Photo Slideshow Maker Free 5.58 (HKLM\...\Anvsoft Photo Slideshow Maker Free) (Version: 5.58 - Anvsoft, Inc.)
Apple Application Support (32-bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{A75CA58D-DB9C-4D14-9428-E0C7B0F623DC}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Brother MFL-Pro Suite MFC-8510DN (HKLM\...\{37372D85-4945-4B6B-AC87-7BC5D1AB9F5C}) (Version: 2.0.1.0 - Brother Industries, Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 5.14 - Piriform)
Crystal Reports 9 (HKLM\...\{71A7D000-0D1F-4CF9-BB75-BB5920436F0C}) (Version: 9.2.2.570 - Crystal Decisions, Inc.)
EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version: - EaseUS)
EasyVideoMaker (HKLM\...\{03EC818F-96E5-497F-AF28-EC6BC4CF32D3}) (Version: 6.35 - Easy Video Maker)
ESET NOD32 Antivirus (HKLM\...\{2E94E0C3-CB66-4A59-AF7A-C70BB9F5F0B3}) (Version: 9.0.318.0 - ESET, spol. s r.o.)
Free Video Cutter 1.1 (HKLM\...\{94895EA7-873E-4FCB-9C7B-DD3F7019D618}_is1) (Version: - FreeVideoCutter.com)
Google Chrome (HKLM\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Update Helper (Version: 1.3.33.3 - Google Inc.) Hidden
Intel(R) Network Connections 13.1.33.0 (HKLM\...\{DDD076BF-C5C3-468C-AA1B-F9A7E47446FE}) (Version: 13.1.33.0 - Intel)
iTunes (HKLM\...\{868B9974-4F23-494D-B6BC-4FAB92B2755D}) (Version: 12.1.3.6 - Apple Inc.)
JobGen Plus (HKLM\...\JobGen Plus) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 6.0 Enterprise Edition (HKLM\...\Visual Studio 6.0 Enterprise Edition) (Version: - )
Microsoft VM for Java (HKLM\...\MsJavaVM) (Version: - )
Microsoft Web Publishing Wizard 1.53 (HKLM\...\WebPost) (Version: - )
Microsoft WinUsb 1.0 (HKLM\...\winusb0100) (Version: - Microsoft Corporation)
Mozilla Firefox 50.0.2 (x86 en-GB) (HKLM\...\Mozilla Firefox 50.0.2 (x86 en-GB)) (Version: 50.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 50.0.2 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Nero Suite (HKLM\...\NeroMultiInstaller!UninstallKey) (Version: - )
Nuance PaperPort 12 (HKLM\...\{88B5FBDC-967D-4B1F-B291-39284AE12201}) (Version: 12.1.0005 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
PaperPort Image Printer (HKLM\...\{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}) (Version: 14.00.0000 - Nuance Communications, Inc.)
PhotoScape (HKLM\...\PhotoScape) (Version: - )
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 2.00 - Realtek Semiconductor Corp.)
Samsung Kies3 (HKLM\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.59.0 - Samsung Electronics Co., Ltd.)
Scansoft PDF Professional (Version: - ) Hidden
SoundMAX (HKLM\...\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 5.12.01.3665 - Analog Devices)
TeamViewer 12 (HKLM\...\TeamViewer) (Version: 12.0.75813 - TeamViewer)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Winamp (HKLM\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray (HKLM\...\KB952011) (Version: 1.0 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - )
WinRAR 5.31 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\Browser Updater Task(Core).job => C:\Program Files\QQBrowser\Update\851F10F1C9A94800E9E20AA8ABF4EFCA\Update\BrowserUpdate.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ParetoLogic Registration3.job => rundll32.exe C:\Program Files\Common Files\ParetoLogic\UUS3\UUS3.dll <==== ATTENTION
Task: C:\WINDOWS\Tasks\ParetoLogic Update Version3 Startup Task.job => C:\Program Files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\ParetoLogic Update Version3.job => C:\Program Files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\WinTaske.job => C:\Program Files\WinTaske\WinTaske\WinTaske.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Documents and Settings\ROSHITH\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1458719105&a=1049763&src=sh&uuid=1f8404d4-8852-4995-ac8b-765fadde5611"
ShortcutWithArgument: C:\Documents and Settings\ROSHITH\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1458719105&a=1049763&src=sh&uuid=1f8404d4-8852-4995-ac8b-765fadde5611"
ShortcutWithArgument: C:\Documents and Settings\ROSHITH\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1458719105&a=1049763&src=sh&uuid=1f8404d4-8852-4995-ac8b-765fadde5611"
==================== Loaded Modules (Whitelisted) ==============
2015-03-20 18:12 - 2015-03-20 18:12 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-04-02 14:29 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
2012-06-13 18:35 - 2012-06-13 18:35 - 01292288 _____ () C:\WINDOWS\system32\quartz.dll
2008-04-14 15:00 - 2008-04-14 15:00 - 00059904 _____ () C:\WINDOWS\system32\devenum.dll
2008-04-14 15:00 - 2008-04-14 15:00 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll
2012-09-23 20:43 - 2012-09-23 20:43 - 00313992 _____ () C:\Program Files\Adobe\Reader 11.0\Reader\sqlite.dll
2008-04-14 15:00 - 2008-04-14 15:00 - 00355112 _____ () C:\WINDOWS\system32\msjetoledb40.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:661DFA1C [270]
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP
BC416F8 [128]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot => "AlternateShell"=""
"HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal" is missing and should be manually restored.
"HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network" is missing and should be manually restored.
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-436374069-790525478-1644491937-1003\...\driversupport.com -> hxxp://apps.driversupport.com
IE trusted site: HKU\S-1-5-21-436374069-790525478-1644491937-1003\...\driversupport.com -> hxxps://apps.driversupport.com
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2008-04-14 15:00 - 2017-01-26 12:28 - 00001162 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 idb.iobit.com
127.0.0.1 asc55.iobit.com
127.0.0.1 is360.iobit.com
127.0.0.1 asc.iobit.com
127.0.0.1 pf.iobit.com
127.0.0.1 track.easeus.com
127.0.0.1 activation.easeus.com
127.0.0.1 By Roonney
127.0.0.1 track.easeus.com
127.0.0.1 activation.easeus.com
127.0.0.1 By Roonney
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-436374069-790525478-1644491937-1003\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\ROSHITH\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: 192.168.1.59
sharedaccess => Firewall Service is not running.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupreg: BluetoothAuthenticationAgent =>
MSCONFIG\startupreg: LuckyBrowse =>
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
DomainProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\Tencentdl.exe] => Enabled:腾讯产品下载组件
DomainProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\bugreport_xf.exe] => Enabled:腾讯产品下载组件Crash上报
DomainProfile\AuthorizedApplications: [C:\Program Files\Winamp\winamp.exe] => Enabled:Winamp
DomainProfile\AuthorizedApplications: [C:\Documents and Settings\ROSHITH\Local Settings\Application Data\TNT2\2.0.0.2065\TNT2User.exe] => Enabled:TNT2
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE] => Enabled:Microsoft Office Outlook
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\GROOVE.EXE] => Enabled:Microsoft Office Groove
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE] => Enabled:Microsoft Office OneNote
StandardProfile\AuthorizedApplications: [C:\WINDOWS\Explorer.EXE] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\ControlCenter4\BrCcBoot.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Samsung\Kies3\Kies3.exe] => Enabled:Samsung Kies 3
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\ctfmon.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\userinit.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [E:\DIAMOND\DIAMOND50.EXE] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\ControlCenter4\BrCcUxSys.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Browny02\BrYNSvc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Browny02\Brother\BrStMonW.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:Google Chrome
StandardProfile\AuthorizedApplications: [C:\WINDOWS\Network Diagnostic\xpnetdiag.exe] => Enabled
xpsp3res.dll,-20000
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\Tencentdl.exe] => Enabled:腾讯产品下载组件
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\bugreport_xf.exe] => Enabled:腾讯产品下载组件Crash上报
StandardProfile\AuthorizedApplications: [C:\Program Files\Winamp\winamp.exe] => Enabled:Winamp
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)
StandardProfile\AuthorizedApplications: [C:\Program Files\TeamViewer\TeamViewer.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\TeamViewer\TeamViewer_Service.exe] => Enabled:Teamviewer Remote Control Service
StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service
StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes
StandardProfile\AuthorizedApplications: [E:\DIAMOND\LicenseServer.EXE] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\ControlCenter4\BrCtrlCntr.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\aevx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winsrka.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winyrsopc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winnkrsc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\brmic.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\PhotoScape\PhotoScape.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\whywst.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winejbqak.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\ROSHITH\My Documents\Downloads\realplayer-18.1.3.100_1931024936.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winukge.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Picasa3\PicasaPhotoViewer.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\xvtkja.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\chhvvw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Browny02\Brother\WarningDialog.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winvfleq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\mpdys.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\hdtdv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wingdbmv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\tmrns.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\eahvqw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winsmdfwk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wingqtdro.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\igkk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winjrerdd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winxtct.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\rvjtxn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winyhpgie.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winluvevf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\haih.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\gvwcb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\jfbx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wmidc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\slomj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winufne.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\oxbuf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winrnwisu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\orgjyd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\uduv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\yqjknn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winhajj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winsxsm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wintchecq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\vgwyy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\kihdxx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wingbvy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winecfieu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winqicah.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\gvwbrh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\itgocp.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\ostsmt.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winpqgg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\trlsfi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wintdrdxi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winqijihv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winhuxdic.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winsumwqi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winlgsetq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\ywvgja.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winyxvk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\phqsya.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\csetw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\sfbmq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winthjxm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winoknr.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\pahd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\potihm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winsgdan.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winnkpdfa.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\twba.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\xivy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\ngnn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winxkvlpj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winlqhcan.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winybywj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winghcv.exe] => Enabled:ipsec
DomainProfile\GloballyOpenPorts: [139:TCP] => Enabled
xpsp2res.dll,-22004
DomainProfile\GloballyOpenPorts: [445:TCP] => Enabled
xpsp2res.dll,-22005
DomainProfile\GloballyOpenPorts: [137:UDP] => Enabled
xpsp2res.dll,-22001
DomainProfile\GloballyOpenPorts: [138:UDP] => Enabled
xpsp2res.dll,-22002
DomainProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet
isabled
xpsp2res.dll,-22007
DomainProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet
isabled
xpsp2res.dll,-22008
StandardProfile\GloballyOpenPorts: [139:TCP] => :LocalSubNet:Enabled
xpsp2res.dll,-22004
StandardProfile\GloballyOpenPorts: [445:TCP] => :LocalSubNet:Enabled
xpsp2res.dll,-22005
StandardProfile\GloballyOpenPorts: [137:UDP] => :LocalSubNet:Enabled
xpsp2res.dll,-22001
StandardProfile\GloballyOpenPorts: [138:UDP] => :LocalSubNet:Enabled
xpsp2res.dll,-22002
StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet
isabled
xpsp2res.dll,-22007
StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet
isabled
xpsp2res.dll,-22008
==================== Restore Points =========================
01-03-2017 13:03:55 System Checkpoint
02-03-2017 13:04:36 System Checkpoint
04-03-2017 08:58:22 System Checkpoint
05-03-2017 09:17:33 System Checkpoint
06-03-2017 10:44:14 System Checkpoint
07-03-2017 13:01:24 System Checkpoint
08-03-2017 15:52:30 System Checkpoint
11-03-2017 15:03:46 System Checkpoint
13-03-2017 08:32:44 System Checkpoint
14-03-2017 08:45:32 System Checkpoint
15-03-2017 09:13:22 System Checkpoint
16-03-2017 11:16:10 System Checkpoint
16-03-2017 15:18:25 Installed Windows Media Format 9 Series Runtime Setup
18-03-2017 08:39:53 System Checkpoint
19-03-2017 08:44:23 System Checkpoint
20-03-2017 13:04:26 System Checkpoint
21-03-2017 15:17:57 System Checkpoint
23-03-2017 08:49:16 System Checkpoint
25-03-2017 08:54:56 System Checkpoint
26-03-2017 08:55:56 System Checkpoint
27-03-2017 13:04:12 System Checkpoint
28-03-2017 14:54:27 System Checkpoint
29-03-2017 15:53:27 System Checkpoint
01-04-2017 08:40:58 System Checkpoint
02-04-2017 08:50:00 System Checkpoint
03-04-2017 08:53:28 System Checkpoint
04-04-2017 09:07:37 System Checkpoint
05-04-2017 10:52:34 System Checkpoint
06-04-2017 13:05:46 System Checkpoint
08-04-2017 08:43:47 System Checkpoint
09-04-2017 09:02:19 System Checkpoint
10-04-2017 13:02:04 System Checkpoint
11-04-2017 13:03:53 System Checkpoint
12-04-2017 13:21:32 System Checkpoint
15-04-2017 08:46:43 System Checkpoint
16-04-2017 08:46:50 System Checkpoint
17-04-2017 08:48:21 System Checkpoint
18-04-2017 08:56:12 System Checkpoint
19-04-2017 13:15:01 System Checkpoint
19-04-2017 14:50:43 Restore Operation
19-04-2017 15:02:53 Removed EasyVideoMaker.
19-04-2017 15:11:09 Installed EasyVideoMaker.
19-04-2017 15:31:03 Removed EasyVideoMaker.
20-04-2017 08:15:19 Installed EasyVideoMaker.
Check "winmgmt" service or repair WMI.
==================== Faulty Device Manager Devices =============
Name: Video Controller (VGA Compatible)
Description: Video Controller (VGA Compatible)
Class Guid: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/19/2017 03:04:19 PM) (Source: MsiInstaller) (EventID: 11905) (User: GBB)
Description: Product: EasyVideoMaker -- Error 1905.Module C:\Program Files\Common Files\EVMMediaCodec\decoder\VisioForge_Bridge_Audio.ax failed to unregister. HRESULT -2147220472. Contact your support personnel.
Error: (04/19/2017 03:04:15 PM) (Source: MsiInstaller) (EventID: 11905) (User: GBB)
Description: Product: EasyVideoMaker -- Error 1905.Module C:\Program Files\Common Files\EVMMediaCodec\decoder\VisioForge_Bridge_Video.ax failed to unregister. HRESULT -2147220472. Contact your support personnel.
System errors:
=============
Error: (04/20/2017 07:57:40 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/19/2017 04:04:52 PM) (Source: WPDMTPDriver) (EventID: 15300) (User: )
Description: MTP WPD Driver has failed to start. Error 0x8007001f.
Error: (04/19/2017 03:30:20 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/19/2017 03:10:18 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/19/2017 02:52:02 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/18/2017 07:57:12 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/17/2017 03:22:47 PM) (Source: 0) (EventID: 11) (User: )
Description: Event-ID 11
Error: (04/17/2017 08:00:02 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/16/2017 07:57:45 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/15/2017 07:51:00 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz
Percentage of memory in use: 86%
Total physical RAM: 1014.79 MB
Available physical RAM: 141.73 MB
Total Virtual: 2445.34 MB
Available Virtual: 1564.79 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:29.29 GB) (Free:7.35 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:45.23 GB) (Free:44.92 GB) NTFS
Drive e: (New Volume) (Fixed) (Total:34.18 GB) (Free:32.75 GB) NTFS
Drive f: () (Fixed) (Total:40.35 GB) (Free:40.1 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: 9C879C87)
Partition 1: (Active) - (Size=29.3 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=45.2 GB) - (Type=OF Extended)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: 6584BCFD)
Partition 1: (Not Active) - (Size=34.2 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=40.3 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
I scanned my system through farbar recovery scan tool. scan result are listed below
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 19-04-2017
Ran by ROSHITH (20-04-2017 10:20:43)
Running from C:\Documents and Settings\ROSHITH\My Documents\Downloads
Microsoft Windows XP Professional Service Pack 3 (X86) (2016-01-16 08:23:21)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-436374069-790525478-1644491937-500 - Administrator - Enabled)
Guest (S-1-5-21-436374069-790525478-1644491937-501 - Limited - Enabled) => %SystemDrive%\Documents and Settings\Guest
HelpAssistant (S-1-5-21-436374069-790525478-1644491937-1000 - Limited - Disabled)
ROSHITH (S-1-5-21-436374069-790525478-1644491937-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\ROSHITH
SUPPORT_388945a0 (S-1-5-21-436374069-790525478-1644491937-1002 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: ESET NOD32 Antivirus 9.0.408.0 (Enabled - Up to date) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 23 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 23.0.0.162 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 25.0.0.127 - Adobe Systems Incorporated)
Adobe Photoshop CS (HKLM\...\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}) (Version: CS - Adobe Systems, Inc.)
Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Advertising Center (Version: 0.0.0.1 - Nero AG) Hidden
Anvsoft Photo Slideshow Maker Free 5.58 (HKLM\...\Anvsoft Photo Slideshow Maker Free) (Version: 5.58 - Anvsoft, Inc.)
Apple Application Support (32-bit) (HKLM\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{A75CA58D-DB9C-4D14-9428-E0C7B0F623DC}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Brother MFL-Pro Suite MFC-8510DN (HKLM\...\{37372D85-4945-4B6B-AC87-7BC5D1AB9F5C}) (Version: 2.0.1.0 - Brother Industries, Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 5.14 - Piriform)
Crystal Reports 9 (HKLM\...\{71A7D000-0D1F-4CF9-BB75-BB5920436F0C}) (Version: 9.2.2.570 - Crystal Decisions, Inc.)
EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version: - EaseUS)
EasyVideoMaker (HKLM\...\{03EC818F-96E5-497F-AF28-EC6BC4CF32D3}) (Version: 6.35 - Easy Video Maker)
ESET NOD32 Antivirus (HKLM\...\{2E94E0C3-CB66-4A59-AF7A-C70BB9F5F0B3}) (Version: 9.0.318.0 - ESET, spol. s r.o.)
Free Video Cutter 1.1 (HKLM\...\{94895EA7-873E-4FCB-9C7B-DD3F7019D618}_is1) (Version: - FreeVideoCutter.com)
Google Chrome (HKLM\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Update Helper (Version: 1.3.33.3 - Google Inc.) Hidden
Intel(R) Network Connections 13.1.33.0 (HKLM\...\{DDD076BF-C5C3-468C-AA1B-F9A7E47446FE}) (Version: 13.1.33.0 - Intel)
iTunes (HKLM\...\{868B9974-4F23-494D-B6BC-4FAB92B2755D}) (Version: 12.1.3.6 - Apple Inc.)
JobGen Plus (HKLM\...\JobGen Plus) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 6.0 Enterprise Edition (HKLM\...\Visual Studio 6.0 Enterprise Edition) (Version: - )
Microsoft VM for Java (HKLM\...\MsJavaVM) (Version: - )
Microsoft Web Publishing Wizard 1.53 (HKLM\...\WebPost) (Version: - )
Microsoft WinUsb 1.0 (HKLM\...\winusb0100) (Version: - Microsoft Corporation)
Mozilla Firefox 50.0.2 (x86 en-GB) (HKLM\...\Mozilla Firefox 50.0.2 (x86 en-GB)) (Version: 50.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 50.0.2 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Nero Suite (HKLM\...\NeroMultiInstaller!UninstallKey) (Version: - )
Nuance PaperPort 12 (HKLM\...\{88B5FBDC-967D-4B1F-B291-39284AE12201}) (Version: 12.1.0005 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
PaperPort Image Printer (HKLM\...\{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}) (Version: 14.00.0000 - Nuance Communications, Inc.)
PhotoScape (HKLM\...\PhotoScape) (Version: - )
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 2.00 - Realtek Semiconductor Corp.)
Samsung Kies3 (HKLM\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (Version: 3.2.16011.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.59.0 - Samsung Electronics Co., Ltd.)
Scansoft PDF Professional (Version: - ) Hidden
SoundMAX (HKLM\...\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 5.12.01.3665 - Analog Devices)
TeamViewer 12 (HKLM\...\TeamViewer) (Version: 12.0.75813 - TeamViewer)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Winamp (HKLM\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray (HKLM\...\KB952011) (Version: 1.0 - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - )
WinRAR 5.31 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\Browser Updater Task(Core).job => C:\Program Files\QQBrowser\Update\851F10F1C9A94800E9E20AA8ABF4EFCA\Update\BrowserUpdate.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ParetoLogic Registration3.job => rundll32.exe C:\Program Files\Common Files\ParetoLogic\UUS3\UUS3.dll <==== ATTENTION
Task: C:\WINDOWS\Tasks\ParetoLogic Update Version3 Startup Task.job => C:\Program Files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\ParetoLogic Update Version3.job => C:\Program Files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\WinTaske.job => C:\Program Files\WinTaske\WinTaske\WinTaske.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Documents and Settings\ROSHITH\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1458719105&a=1049763&src=sh&uuid=1f8404d4-8852-4995-ac8b-765fadde5611"
ShortcutWithArgument: C:\Documents and Settings\ROSHITH\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1458719105&a=1049763&src=sh&uuid=1f8404d4-8852-4995-ac8b-765fadde5611"
ShortcutWithArgument: C:\Documents and Settings\ROSHITH\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1458719105&a=1049763&src=sh&uuid=1f8404d4-8852-4995-ac8b-765fadde5611"
==================== Loaded Modules (Whitelisted) ==============
2015-03-20 18:12 - 2015-03-20 18:12 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-04-02 14:29 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
2012-06-13 18:35 - 2012-06-13 18:35 - 01292288 _____ () C:\WINDOWS\system32\quartz.dll
2008-04-14 15:00 - 2008-04-14 15:00 - 00059904 _____ () C:\WINDOWS\system32\devenum.dll
2008-04-14 15:00 - 2008-04-14 15:00 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll
2012-09-23 20:43 - 2012-09-23 20:43 - 00313992 _____ () C:\Program Files\Adobe\Reader 11.0\Reader\sqlite.dll
2008-04-14 15:00 - 2008-04-14 15:00 - 00355112 _____ () C:\WINDOWS\system32\msjetoledb40.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:661DFA1C [270]
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot => "AlternateShell"=""
"HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal" is missing and should be manually restored.
"HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network" is missing and should be manually restored.
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-436374069-790525478-1644491937-1003\...\driversupport.com -> hxxp://apps.driversupport.com
IE trusted site: HKU\S-1-5-21-436374069-790525478-1644491937-1003\...\driversupport.com -> hxxps://apps.driversupport.com
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2008-04-14 15:00 - 2017-01-26 12:28 - 00001162 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 idb.iobit.com
127.0.0.1 asc55.iobit.com
127.0.0.1 is360.iobit.com
127.0.0.1 asc.iobit.com
127.0.0.1 pf.iobit.com
127.0.0.1 track.easeus.com
127.0.0.1 activation.easeus.com
127.0.0.1 By Roonney
127.0.0.1 track.easeus.com
127.0.0.1 activation.easeus.com
127.0.0.1 By Roonney
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-436374069-790525478-1644491937-1003\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\ROSHITH\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: 192.168.1.59
sharedaccess => Firewall Service is not running.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupreg: BluetoothAuthenticationAgent =>
MSCONFIG\startupreg: LuckyBrowse =>
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
DomainProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\Tencentdl.exe] => Enabled:腾讯产品下载组件
DomainProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\bugreport_xf.exe] => Enabled:腾讯产品下载组件Crash上报
DomainProfile\AuthorizedApplications: [C:\Program Files\Winamp\winamp.exe] => Enabled:Winamp
DomainProfile\AuthorizedApplications: [C:\Documents and Settings\ROSHITH\Local Settings\Application Data\TNT2\2.0.0.2065\TNT2User.exe] => Enabled:TNT2
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE] => Enabled:Microsoft Office Outlook
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\GROOVE.EXE] => Enabled:Microsoft Office Groove
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE] => Enabled:Microsoft Office OneNote
StandardProfile\AuthorizedApplications: [C:\WINDOWS\Explorer.EXE] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\ControlCenter4\BrCcBoot.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Samsung\Kies3\Kies3.exe] => Enabled:Samsung Kies 3
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\ctfmon.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\userinit.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [E:\DIAMOND\DIAMOND50.EXE] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\ControlCenter4\BrCcUxSys.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Browny02\BrYNSvc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Browny02\Brother\BrStMonW.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Enabled:Google Chrome
StandardProfile\AuthorizedApplications: [C:\WINDOWS\Network Diagnostic\xpnetdiag.exe] => Enabled
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\Tencentdl.exe] => Enabled:腾讯产品下载组件
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Tencent\QQDownload\130\bugreport_xf.exe] => Enabled:腾讯产品下载组件Crash上报
StandardProfile\AuthorizedApplications: [C:\Program Files\Winamp\winamp.exe] => Enabled:Winamp
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)
StandardProfile\AuthorizedApplications: [C:\Program Files\TeamViewer\TeamViewer.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\TeamViewer\TeamViewer_Service.exe] => Enabled:Teamviewer Remote Control Service
StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service
StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes
StandardProfile\AuthorizedApplications: [E:\DIAMOND\LicenseServer.EXE] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\ControlCenter4\BrCtrlCntr.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\aevx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winsrka.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winyrsopc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winnkrsc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\brmic.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\PhotoScape\PhotoScape.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\whywst.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winejbqak.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\ROSHITH\My Documents\Downloads\realplayer-18.1.3.100_1931024936.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winukge.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Picasa3\PicasaPhotoViewer.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\xvtkja.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\chhvvw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Browny02\Brother\WarningDialog.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winvfleq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\mpdys.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\hdtdv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wingdbmv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\tmrns.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\eahvqw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winsmdfwk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wingqtdro.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\igkk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winjrerdd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winxtct.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\rvjtxn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winyhpgie.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winluvevf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\haih.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\gvwcb.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\jfbx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wmidc.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\slomj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winufne.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\oxbuf.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winrnwisu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\orgjyd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\uduv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\yqjknn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winhajj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winsxsm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wintchecq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\vgwyy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\kihdxx.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wingbvy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winecfieu.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winqicah.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\gvwbrh.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\itgocp.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\ostsmt.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winpqgg.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\trlsfi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\wintdrdxi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winqijihv.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winhuxdic.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winsumwqi.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winlgsetq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\ywvgja.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winyxvk.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\phqsya.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\csetw.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\sfbmq.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winthjxm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winoknr.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\pahd.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\potihm.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winsgdan.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winnkpdfa.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\twba.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\xivy.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\ngnn.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winxkvlpj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winlqhcan.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winybywj.exe] => Enabled:ipsec
StandardProfile\AuthorizedApplications: [C:\DOCUME~1\ROSHITH\LOCALS~1\Temp\winghcv.exe] => Enabled:ipsec
DomainProfile\GloballyOpenPorts: [139:TCP] => Enabled
DomainProfile\GloballyOpenPorts: [445:TCP] => Enabled
DomainProfile\GloballyOpenPorts: [137:UDP] => Enabled
DomainProfile\GloballyOpenPorts: [138:UDP] => Enabled
DomainProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet
DomainProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet
StandardProfile\GloballyOpenPorts: [139:TCP] => :LocalSubNet:Enabled
StandardProfile\GloballyOpenPorts: [445:TCP] => :LocalSubNet:Enabled
StandardProfile\GloballyOpenPorts: [137:UDP] => :LocalSubNet:Enabled
StandardProfile\GloballyOpenPorts: [138:UDP] => :LocalSubNet:Enabled
StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet
StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet
==================== Restore Points =========================
01-03-2017 13:03:55 System Checkpoint
02-03-2017 13:04:36 System Checkpoint
04-03-2017 08:58:22 System Checkpoint
05-03-2017 09:17:33 System Checkpoint
06-03-2017 10:44:14 System Checkpoint
07-03-2017 13:01:24 System Checkpoint
08-03-2017 15:52:30 System Checkpoint
11-03-2017 15:03:46 System Checkpoint
13-03-2017 08:32:44 System Checkpoint
14-03-2017 08:45:32 System Checkpoint
15-03-2017 09:13:22 System Checkpoint
16-03-2017 11:16:10 System Checkpoint
16-03-2017 15:18:25 Installed Windows Media Format 9 Series Runtime Setup
18-03-2017 08:39:53 System Checkpoint
19-03-2017 08:44:23 System Checkpoint
20-03-2017 13:04:26 System Checkpoint
21-03-2017 15:17:57 System Checkpoint
23-03-2017 08:49:16 System Checkpoint
25-03-2017 08:54:56 System Checkpoint
26-03-2017 08:55:56 System Checkpoint
27-03-2017 13:04:12 System Checkpoint
28-03-2017 14:54:27 System Checkpoint
29-03-2017 15:53:27 System Checkpoint
01-04-2017 08:40:58 System Checkpoint
02-04-2017 08:50:00 System Checkpoint
03-04-2017 08:53:28 System Checkpoint
04-04-2017 09:07:37 System Checkpoint
05-04-2017 10:52:34 System Checkpoint
06-04-2017 13:05:46 System Checkpoint
08-04-2017 08:43:47 System Checkpoint
09-04-2017 09:02:19 System Checkpoint
10-04-2017 13:02:04 System Checkpoint
11-04-2017 13:03:53 System Checkpoint
12-04-2017 13:21:32 System Checkpoint
15-04-2017 08:46:43 System Checkpoint
16-04-2017 08:46:50 System Checkpoint
17-04-2017 08:48:21 System Checkpoint
18-04-2017 08:56:12 System Checkpoint
19-04-2017 13:15:01 System Checkpoint
19-04-2017 14:50:43 Restore Operation
19-04-2017 15:02:53 Removed EasyVideoMaker.
19-04-2017 15:11:09 Installed EasyVideoMaker.
19-04-2017 15:31:03 Removed EasyVideoMaker.
20-04-2017 08:15:19 Installed EasyVideoMaker.
Check "winmgmt" service or repair WMI.
==================== Faulty Device Manager Devices =============
Name: Video Controller (VGA Compatible)
Description: Video Controller (VGA Compatible)
Class Guid: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/19/2017 03:04:19 PM) (Source: MsiInstaller) (EventID: 11905) (User: GBB)
Description: Product: EasyVideoMaker -- Error 1905.Module C:\Program Files\Common Files\EVMMediaCodec\decoder\VisioForge_Bridge_Audio.ax failed to unregister. HRESULT -2147220472. Contact your support personnel.
Error: (04/19/2017 03:04:15 PM) (Source: MsiInstaller) (EventID: 11905) (User: GBB)
Description: Product: EasyVideoMaker -- Error 1905.Module C:\Program Files\Common Files\EVMMediaCodec\decoder\VisioForge_Bridge_Video.ax failed to unregister. HRESULT -2147220472. Contact your support personnel.
System errors:
=============
Error: (04/20/2017 07:57:40 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/19/2017 04:04:52 PM) (Source: WPDMTPDriver) (EventID: 15300) (User: )
Description: MTP WPD Driver has failed to start. Error 0x8007001f.
Error: (04/19/2017 03:30:20 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/19/2017 03:10:18 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/19/2017 02:52:02 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/18/2017 07:57:12 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/17/2017 03:22:47 PM) (Source: 0) (EventID: 11) (User: )
Description: Event-ID 11
Error: (04/17/2017 08:00:02 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/16/2017 07:57:45 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
Error: (04/15/2017 07:51:00 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
qutmipc
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz
Percentage of memory in use: 86%
Total physical RAM: 1014.79 MB
Available physical RAM: 141.73 MB
Total Virtual: 2445.34 MB
Available Virtual: 1564.79 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:29.29 GB) (Free:7.35 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:45.23 GB) (Free:44.92 GB) NTFS
Drive e: (New Volume) (Fixed) (Total:34.18 GB) (Free:32.75 GB) NTFS
Drive f: () (Fixed) (Total:40.35 GB) (Free:40.1 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: 9C879C87)
Partition 1: (Active) - (Size=29.3 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=45.2 GB) - (Type=OF Extended)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: 6584BCFD)
Partition 1: (Not Active) - (Size=34.2 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=40.3 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================