2015-10-10, 01:23
AVG version 2015.0.6140 has detected "Trojan horse Generic36.BOKP" which it cannot remove from my laptop. Can you help?

FRST.txt follows:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:08-10-2015
Ran by Ed (administrator) on ED-PC (09-10-2015 17:56:46)
Running from C:\Users\Ed\Desktop
Loaded Profiles: Ed (Available Profiles: Ed)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== End of FRST.txt ============================

Addition.txt follows:

Additional scan result of Farbar Recovery Scan Tool (x86) Version:08-10-2015
Ran by Ed (2015-10-09 17:57:22)
Running from C:\Users\Ed\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) (2015-07-21 18:41:30)
Boot Mode: Normal

aswMBR follows:

aswMBR version Copyright(c) 2014 AVAST Software
Run date: 2015-10-09 18:08:47
18:08:47.000 OS Version: Windows 6.1.7601 Service Pack 1
18:08:47.000 Number of processors: 2 586 0x170A
18:08:47.000 ComputerName: ED-PC UserName: Ed
18:09:07.155 Initialize success
18:09:07.343 VM: initialized successfully
18:09:07.343 VM: Intel CPU BiosDisabled
18:10:43.493 AVAST engine defs: 15100900
18:11:58.108 The log file has been saved successfully to "C:\Users\Ed\Desktop\aswMBR.txt"



2015-10-10, 15:00
AVG version 2015.0.6140 has detected "Trojan horse Generic36.BOKP"
By chance, can you post the file/folder it says it detected this in?


Download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam-download.php) TO YOUR DESKTOP

Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"


On the Dashboard click on Update Now

Go to the Setting Tab

Under Setting go to Detection and Protection

Under PUP and PUM make sure both are set to show Treat Detections as Malware

Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked

Then on the Dashboard click on Scan

Make sure to select THREAT SCAN

Then click on Scan

When the scan is finished and the log pops up...select Copy to Clipboard

Please paste the log back into this thread for review

Exit Malwarebytes


http://i24.photobucket.com/albums/c30/ken545/MBAM%20Application_zps7zm0ftdm.png (http://s24.photobucket.com/user/ken545/media/MBAM%20Application_zps7zm0ftdm.png.html)

1. Open up Malwarebytes and you will be on the Dashboard
2. Click on the History Tab
3. Then click on Application Logs
4. Double click on the SCAN LOG (Not Protection Log ) you just ran
5. When it opens it will look like this

http://i24.photobucket.com/albums/c30/ken545/MBAM%20Export_zpsjbtttjun.jpg (http://s24.photobucket.com/user/ken545/media/MBAM%20Export_zpsjbtttjun.jpg.html)

6. Then click on Export
7. On the drop down list click on Copy to Clipboard
8. Then paste the log back into this thread

On completion of the scan (or after the reboot), start MBAM,

Click History, then Application Logs, then check the Select box by the first Scan Log in the list and then click on the log to highlight it.

Click Export, select text file and save to the desktop as MBAM.txt and post in your next reply.


http://i.imgur.com/BY4dvz9.png AdwCleaner

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) and save the file to your Desktop.
Right-Click AdwCleaner.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Follow the prompts.
Click Scan.
Upon completion, click Report. A log (AdwCleaner[SX].txt) will open. Briefly check the log for anything you know to be legitimate.
Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
Follow the prompts and allow your computer to reboot.
After rebooting, a log (AdwCleaner[SX].txt) will open. Copy the contents of the log and paste in your next reply.

-- File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.


Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/)
or from here http://downloads.malwarebytes.org/file/jrt
to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.

please post
Malwarebytes log

2015-10-13, 00:38
AVG did not report which file Generic Trojan horse was detected in. Only reported: "access denied"

Following your instructions step by step, I had a few problems and didn't always get what I expected.

MBAM Scan Log follows:

Malwarebytes Anti-Malware

Scan Date: 10/12/2015
Scan Time: 4:34 PM
Logfile: MBAM Scan Log.txt
Administrator: Yes

Malware Database: v2015.10.12.03
Rootkit Database: v2015.10.06.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Ed

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 304205
Time Elapsed: 5 min, 59 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 1
PUP.Optional.MindSpark, HKLM\SOFTWARE\HowToSimplified_8e, Quarantined, [878c1f375b301f17137dc8fa70949967],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


After AdwCleaner Scan, I got no option to click Report, so did not reboot at that point.

Ran JRT, and JRT.txt follows:

Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 7 Home Premium x86
Ran by Ed on Mon 10/12/2015 at 17:24:08.36

~~~ Services

~~~ Tasks

Successfully deleted: [Task] C:\Windows\Tasks\0915avUpdateInfo.job

~~~ Registry Values

~~~ Registry Keys

~~~ Files

~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\Avg_Update_0915av

Scan was completed on Mon 10/12/2015 at 17:28:21.78
End of JRT log



2015-10-13, 00:49
AVG did not report which file Generic Trojan horse was detected in. Only reported: "access denied"
This could be many things but, AVG is doing it's job which doesn't necessarily mean there is an infection.

Since running these tools has it shown an alert again?

See if you can locate this

if you find it copy and paste it in your next reply.

What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.

Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

http://i.imgur.com/GzlsbnV.png ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

Please download ESET Online Scan (http://download.eset.com/special/eos/esetsmartinstaller_enu.exe) and save the file to your Desktop.
Temporarily disable your anti-virus software. For instructions, please refer to the following link (http://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/).
Double-click esetsmartinstaller_enu.exe to run the programme.
Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
Agree to the Terms of Use once more and click Start. Allow components to download.
Place a checkmark next to Enable detection of potentially unwanted applications.
Click Advanced settings. Place a checkmark next to:

Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology

Ensure Remove found threats is unchecked.
Click Start.
Wait for the scan to finish. Please be patient as this can take some time.
Upon completion, click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png. If no threats were found, skip the next two bullet points.
Click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png and save the file to your Desktop, naming it something such as "MyEsetScan".
Push the Back button.
Place a checkmark next to http://3-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png and click http://1-ps.googleusercontent.com/x/forums.whatthetech.com/i.imgur.com/SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png.
Re-enable your anti-virus software.
Copy the contents of the log and paste in your next reply.

2015-10-13, 23:46
I could not find AdwCleaner[CX].txt.

After my last post, I ran an AVG scan, and it found nothing. In disbelief, I ran it again, and it again found nothing. Does that mean my system is clean?

Should I now continue with your last instruction or not?



2015-10-14, 02:15
Should I now continue with your last instruction or not?
Yes, let's make sure it wasn't some sort of fluke.

2015-10-18, 20:38
The ESET scan ran for 28 minutes, which surprised me since the last time I used ESET the scan ran for hours. It reported nothing. I ran another AVG scan, which also reported nothing.

2015-10-18, 21:55
The ESET scan ran for 28 minutes, which surprised me since the last time I used ESET the scan ran for hours. It reported nothing. I ran another AVG scan, which also reported nothing.

The Eset scan surprises me too.

OK, let's watch it for a day or two, come back and give me an update. If all is still good we'll remove tools and quarantine folders.

2015-10-30, 00:09
Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.

2015-11-11, 17:45
Topic re-opened.

Post the new logs here.

2015-11-12, 10:08
FRST.txt follows:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-11-2015
Ran by Ed (administrator) on ED-PC (12-11-2015 02:52:14)
Running from C:\Users\Ed\Desktop
Loaded Profiles: Ed (Available Profiles: Ed)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== End of FRST.txt ============================

Addition.txt follows:

Additional scan result of Farbar Recovery Scan Tool (x86) Version:07-11-2015
Ran by Ed (2015-11-12 02:52:57)
Running from C:\Users\Ed\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) (2015-07-21 18:41:30)
Boot Mode: Normal

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

System errors:
Error: (11/11/2015 07:00:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Update for Windows 7 (KB3107998).

Error: (11/11/2015 07:00:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB3101246).

Error: (11/11/2015 07:00:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB3092601).

Error: (11/11/2015 07:00:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB3101746).

Error: (11/11/2015 07:00:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB3101722).

Error: (11/11/2015 07:00:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB3097877).

Error: (11/11/2015 07:00:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB3081320).

Error: (11/11/2015 07:00:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB3100213).

Error: (11/11/2015 07:00:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Update for Windows 7 (KB3102810).

Error: (11/11/2015 07:00:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 11 for Windows 7.

==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU P8400 @ 2.26GHz
Percentage of memory in use: 59%
Total physical RAM: 1944.03 MB
Available physical RAM: 783.24 MB
Total Virtual: 3888.06 MB
Available Virtual: 2641.42 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:294.72 GB) (Free:263.6 GB) NTFS
Drive e: () (Removable) (Total:57.87 GB) (Free:41.8 GB) FAT32

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 9C948886)
Partition 1: (Active) - (Size=3.4 GB) - (Type=27)
Partition 2: (Not Active) - (Size=294.7 GB) - (Type=07 NTFS)

Disk: 1 (Size: 57.9 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

2015-11-12, 14:51
Looking over the logs I don't think this is related to malware but rather windows system errors.

I did find the update related to a few problems located below in the log you posted but, I think you were having problems before this was released for updates.
Error: (11/11/2015 07:00:34 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB3097877).

And if I read it right, updates from yesterday all failed?

name="AplusWebMaster" post="872876" timestamp="1447320935"]

MS15-115 / re-released ...
- https://technet.microsoft.com/library/security/MS15-115
V2.0 (November 11, 2015): Bulletin revised to inform customers running Windows 7 that the 3097877 update has been re-released to address an issue that caused crashes for some customers when they viewed certain emails. Customers who previously installed update 3097877 should -reinstall- the update to correct this known issue. See Microsoft Knowledge Base Article 3097877* for more information.

* https://support.microsoft.com/en-us/kb/3097877
Last Review: 11/11/2015 22:26:00 - Rev: 2.0 - "... Issues in this security update: We are aware of reports of crashes in all supported versions of Microsoft Outlook that occur when users are reading certain emails after this update is installed..."


Do all your USB Ports work ?

Also please download Windows Repair (all in one) from here (http://www.tweaking.com/content/page/windows_repair_all_in_one.html)

Install the program then go to step 4 and create a new system restore point and new registry backup.

Go to Step 2 and allow it to run CheckDisk by clicking on Do It button:

On the the Start Repairs tab => Click the Start

Please ensure that ONLY items seen in the image below are ticked as indicated (they're all checked by default):

Click on box next to the Restart System when Finished. Then click on Start.

2015-11-12, 23:29
4 out of 15 Windows Updates failed on 11/11, however, today (11/12) they (plus one or two more) were successful.

I've tried my wireless keyboard and mouse on two USB ports, and on both they exhibit intermittent problems. For example, briefly keyboard/mouse is fine, then cursor suddenly won't move easily, or when a mouse button is pushed, it's as if nothing happened, or the mouse might act as if I were holding that button down (dragging/highlighting stuff I don't want to drag or highlight). :mad: When that starts, I can usually stop it with ESC on the laptop keyboard.

I'll try the next instructions you sent, and then report.

2015-11-12, 23:32
Windows Update 3097877 successful.

2015-11-12, 23:59
Did you try Windows Repair (all in one)?

Also, does your mouse require a battery?

2015-11-13, 00:01
Tweaking.COM seriously recommends running Windows Repair in Safe Mode with Networking. You didn't mention that, so is it important?

2015-11-13, 00:02
I'll put a new batty in Mouse just to make sure.

2015-11-13, 00:04
Will wait to hear from you regarding Safe Mode before I run Windows Repair.

2015-11-13, 00:37
I would think safe mode would be good since thats where less applications are likely to interfere.

2015-11-16, 04:41
I'm not having success. I performed a Registry Backup, and then ran Windows Repair. It ran for 21.5 hours before I stopped it. I ran another Registry Backup, and then attempted Windows Repair again. This time, I got a pop-up saying Registry Backup either had error or failed.

Meanwhile, the sluggish mouse problem I originally reported is now not noticeable, however Windows Explorer restarts itself when I attempt to right-click on C: drive to look at Properties.

2015-11-16, 12:41
well, glad the mouse got better then, seems like we jumped from one thing to another.

Please run SFC (System File Checker)
Please run System File Checker sfc /scannow...
Below is a good tutorial

NOTE for Vista/WIN 7 users..The command needs to be run from an Elevated Command Prompt (http://www.bleepingcomputer.com/tutorials/tutorial167.html).Click Start, type cmd into the Start/Search box,
right-click cmd.exe in the list above and select 'Run as Administrator'

You will need your operating system CD handy.

Open Windows Task Manager....by pressing CTRL+SHIFT+ESC

Then click File.. then New Task(Run)

In the box that opens type sfc /scannow ......There is a space between c and /

Click OK
Let it run and insert the CD when asked.


Please download MiniToolBox http://www.bleepingcomputer.com/download/minitoolbox/
save it to your desktop and run it.

Checkmark the following check-boxes:

Flush DNS
List last 10 Event Viewer log
List Installed Programs
List Devices
List Minidump Files

Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

2015-11-16, 14:07
With Elevated Command Prompt, ran sfc /scannow and got: Windows Resource Protection did not find any integrity violations.

Ran MiniToolBox and got MTB.txt (NOT Result.txt), which follows:

MiniToolBox by Farbar Version: 02-11-2015
Ran by Ed (administrator) on 16-11-2015 at 06:57:53
Running from "C:\Users\Ed\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X86)
Model: 2716WM5 Manufacturer: LENOVO
Boot Mode: Normal

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

=========================== Installed Programs ============================

Adobe Acrobat Reader DC (HKLM\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20077 - Adobe Systems Incorporated)
Adobe Flash Player 19 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Photoshop 5.0.2 (HKLM\...\Adobe Photoshop 5.0.2) (Version: 5.0 - Adobe Systems, Inc.)
Adobe Refresh Manager (HKLM\...\{AC76BA86-0804-1033-1959-001824161310}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AVG (HKLM\...\{8D70C10A-4314-4ED2-ABE8-23F45AE36F89}) (Version: 16.7.7227 - AVG Technologies) Hidden
AVG 2016 (HKLM\...\{290CF037-215E-4A66-8CCC-31DCD7E0693F}) (Version: 16.0.4455 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.7.7227 - AVG Technologies)
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - )
FMW 1 (HKLM\...\{F1EA36EA-6E73-465A-BCCB-F758EFD165A2}) (Version: 1.22.2 - AVG Technologies) Hidden
H&R Block Deluxe + Efile 2014 (HKLM\...\{C89CA854-CE87-4CC6-A79F-86E0D7FB0B32}) (Version: 14.04.7401 - HRB Technology, LLC.)
Malwarebytes Anti-Malware version (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2000 Premium (HKLM\...\{00000409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation)
Microsoft Visio Professional 2002 [English] (HKLM\...\{90510409-6D54-11D4-BEE3-00C04F990354}) (Version: 10.0.525 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 38.1.0 - Mozilla)
Mozilla Thunderbird 38.3.0 (x86 en-US) (HKLM\...\Mozilla Thunderbird 38.3.0 (x86 en-US)) (Version: 38.3.0 - Mozilla)
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
ThinkPad Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.55 - )
Tweaking.com - Registry Backup (HKLM\...\Tweaking.com - Registry Backup) (Version: 3.2.2 - Tweaking.com)
Tweaking.com - Windows Repair (HKLM\...\Tweaking.com - Windows Repair) (Version: 3.6.3 - Tweaking.com)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: - AVG Technologies CZ, s.r.o.)

========================= Devices: ================================

Name: Base System Device
Description: Base System Device
Class Guid:
Device ID: PCI\VEN_1180&DEV_0592&SUBSYS_20CA17AA&REV_11\4&132DB2BD&0&04F0
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: PCI Simple Communications Controller
Description: PCI Simple Communications Controller
Class Guid:
Device ID: PCI\VEN_8086&DEV_2A44&SUBSYS_20E617AA&REV_07\3&E89B380&0&18
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Base System Device
Description: Base System Device
Class Guid:
Device ID: PCI\VEN_1180&DEV_0843&SUBSYS_20C917AA&REV_11\4&132DB2BD&0&03F0
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

**** End of log ****

2015-11-16, 16:07
I want you to manually search for critical windows updates.

Go to and click on the Microsoft Orb, click on All Programs, then windows updates.
Let it scan and let's see if all critical updates have finished.

let me know.

I may have to send you to a tech forum to help with the Explorer crashes.

2015-11-16, 17:15
Checked for Updates, and tried to install 1 Important Update. As usual, IE 11 failed to Install, which it's been doing for some time. However, when I open IE, it says it IS IE 11.

See Attachment.

2015-11-16, 19:34
you manually uninstalled the above update correct?

There should had been a revised version ready to download and install afterwards?

Please run chkdsk /r

Chkdsk /r checks for bad sectors on the hdd and recovers any readable information.

Click on the Start orb and type in cmd in the Search programs and files box. When cmd is seen in Programs above the Search box right click on it, then click on Run as administrator.

Type in chkdsk c:/r then press Enter. Please notice the space between the chkdsk and the /r

You will receieve the message "CHKDSK cannot be run because it is in use by another process. Would you like to schedule this volume to be checked the next time the system restarts? <Y/N>"

Type in Y and press Enter.

Restart your computer to start the scan.

This will take a while to run, please be patient and allow it to complete the scan.

reboot and post back here to let me know if anything improves.

2015-11-17, 00:53
No, I have not manually uninstalled KB3097877. I'm unsure how to go about manually uninstalling an Update. Assuming I need to do that, can you get me started?

2015-11-17, 01:09
Go to the Microsoft ORB and click on that
Go to All Programs, then click on Windows Update.
A window should open, in the left pane you'll see where it says "View Update History"
Click on that, next when that window opens, look for see "Installed Updates", it then changes to yet another window. Let it load because it can take a couple of minutes.
Using the Scroll bar on the right, scroll down to where you see Microsoft Windows, locate Security update KB3097877 right click on that and follow the prompts.
It might take a reboot.

let me know how it goes.

2015-11-17, 16:55
Manually removed Update KB3097877. Then, checked for new Updates and found two: KB3097877 and IE 11 (latter has been failing repeatedly for weeks even though IE says it's already IE 11).

Installed Updates, and only KB3097877 was successful. IE 11 Update failed again.

Ran chkdsk c:/r. After reboot, ran Windows Explorer. It opened, but crashed as soon as I right-clicked on C: Pop-up said Windows Explorer has stopped working, searching for a solution... After a moment, new pop-up said Windows Explorer was restarting, but it did not.

2015-11-17, 18:34
See if you can manually download and install IE 11 update from this site

The above may or may not help....fingers crossed on that one.

We have another option. You can do a system restore point to a date before these issues started.
I've had to do this with my own computer and worked very well for me.

2015-11-18, 01:21
I tried a couple of things I found on the technet.microsoft site, but nothing had any effect. IE11 still crashes whenever I right-click on C:.

I tried the earliest System Restore Point available, but there was no effect on IE11, so I did an UNDO on that Restore.

IE11 says it is:
Version 11.0.9600.17843
Update Versions: 11.0.20 (KB3058515) but I can find no record of that Update having been installed. How about if I go into Internet Options and click on Reset IE Settings?

2015-11-18, 01:24
Or...if I Uninstall IE11, will system automatically revert to IE10, or do something else that I don't want to do?

2015-11-18, 03:55
let's try that


2015-11-18, 13:59
I'm not sure which you meant: Reset IE Settings, or Uninstall IE11?

2015-11-18, 15:28
I think you can do both but the link I supplied was to try and reset settings in IE.

2015-11-18, 20:56
Following instructions on the link you sent, I reset IE Settings, and then restarted laptop. There was no immediate effect on Windows Explorer crashing. Some time later, I saw a pop-up informing that IE 11 had been downloaded. I re-tested Windows Explorer, but saw no change.

I then tried to Uninstall IE11. However, on the list of Installed Updates, IE11 does NOT appear, so I couldn't delete it.

I looked for an alternative Uninstall technique, and found the Elevated Command Prompt method. I tried that, but afterwards had NO BROWSER and had to run System Restore to recover IE11.

2015-11-18, 21:49

the above is a good article on Checklist before you install Internet Explorer 11

I have no idea whats got turned upside down.

Right-Click FRST.exe / FRST64.exe and select http://i.imgur.com/AVOiBNU.jpg Run as administrator to run the programme.
Click Yes to the disclaimer.
Ensure the Addition.txt box is checked.
Click the Scan button and let the programme run.
Upon completion, click OK, then OK on the Addition.txt pop up screen.
Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

2015-11-19, 15:37
FRST.txt follows:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:18-11-2015
Ran by Ed (administrator) on ED-PC (19-11-2015 08:28:24)
Running from C:\Users\Ed\Desktop
Loaded Profiles: Ed (Available Profiles: Ed)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgcsrvx.exe
(Lenovo) C:\Windows\System32\ibmpmsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avgsvcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgwdsvcx.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgemcx.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Av\avgui.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Framework\Common\avguix.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Tweaking.com) C:\Program Files\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_19_0_0_245_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\Av\avgui.exe [3826600 2015-10-30] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM\...\Run: [AvgUi] => C:\Program Files\AVG\Framework\Common\avguix.exe [1136552 2015-11-12] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-3659970256-991337627-2867597209-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk [2015-08-07]
ShortcutTarget: Adobe Gamma Loader.exe.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2015-07-22]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{9E83D762-23C5-409C-B0E5-D0B48741C9B3}: [DhcpNameServer]

Internet Explorer:
HKU\S-1-5-21-3659970256-991337627-2867597209-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.toast.net/start

FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AvgAMPS; C:\Program Files\AVG\Av\avgamps.exe [595376 2015-10-30] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files\AVG\Av\avgidsagent.exe [3815648 2015-10-30] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files\AVG\Framework\Common\avgsvcx.exe [862632 2015-11-12] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\Av\avgwdsvcx.exe [579776 2015-10-30] (AVG Technologies CZ, s.r.o.)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [156080 2015-08-10] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [256432 2015-10-19] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [231344 2015-08-20] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [31664 2015-08-14] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [229296 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [308656 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [192944 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [36784 2015-08-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [231856 2015-10-08] (AVG Technologies CZ, s.r.o.)
S3 e1express; C:\Windows\System32\DRIVERS\e1e6232.sys [219352 2009-06-05] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation)
S3 eapihdrv; \??\C:\Users\Ed\AppData\Local\Temp\ehdrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-19 08:24 - 2015-11-19 08:24 - 00000000 ____D C:\Users\Ed\Desktop\FRST-OlderVersion
2015-11-19 08:13 - 2015-11-19 08:13 - 29720784 _____ (Microsoft Corporation) C:\Users\Ed\Desktop\IE11-Windows6.1-x86-en-us.exe
2015-11-17 19:44 - 2015-11-17 19:43 - 00450771 ____R C:\Windows\system32\Drivers\etc\hosts.20151117-194404.backup
2015-11-17 19:43 - 2015-11-08 09:58 - 00450771 _____ C:\Windows\system32\Drivers\etc\hosts.20151117-194329.backup
2015-11-16 06:57 - 2015-11-16 06:57 - 00012611 _____ C:\Users\Ed\Desktop\MTB.txt
2015-11-16 06:54 - 2015-11-16 06:54 - 00891392 _____ (Farbar) C:\Users\Ed\Desktop\MiniToolBox.exe
2015-11-14 13:34 - 2015-11-14 13:34 - 00002100 _____ C:\Users\Ed\Documents\Registry backup 14nov2015.reg
2015-11-14 13:10 - 2015-11-14 12:54 - 30932992 _____ C:\Windows\system32\config\components.old
2015-11-14 12:56 - 2015-11-15 21:20 - 00000550 _____ C:\Windows\Tasks\Tweaking.com - Windows Repair Tray Icon.job
2015-11-14 12:53 - 2015-11-14 12:53 - 20715632 _____ (Tweaking.com) C:\Users\Ed\Desktop\tweaking.com_windows_repair_aio_setup.exe
2015-11-12 16:47 - 2015-11-17 17:22 - 00000000 ____D C:\Users\Ed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2015-11-12 16:47 - 2015-11-15 21:20 - 00002124 _____ C:\Users\Ed\Desktop\Tweaking.com - Windows Repair.lnk
2015-11-12 13:48 - 2015-11-17 17:18 - 00000000 ____D C:\Users\Ed\AppData\Roaming\TaxCut
2015-11-12 13:48 - 2015-11-12 13:48 - 00001994 _____ C:\Users\Public\Desktop\H&R Block 2014.lnk
2015-11-12 13:47 - 2015-11-17 17:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\H&R Block 2014
2015-11-12 13:46 - 2015-11-17 17:22 - 00000000 ____D C:\Program Files\PDF995
2015-11-12 13:46 - 2015-11-17 17:18 - 00000000 ____D C:\Program Files\HRBlock2014
2015-11-12 13:46 - 2015-11-12 13:46 - 00000000 ____D C:\Users\Ed\Documents\HRBlock
2015-11-12 13:45 - 2015-11-17 17:18 - 00000000 ____D C:\ProgramData\TaxCut
2015-11-12 03:36 - 2015-11-03 12:46 - 02386944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-12 03:09 - 2015-10-29 12:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-11-12 03:09 - 2015-10-29 12:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-11-12 03:09 - 2015-10-29 12:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-11-12 03:09 - 2015-10-29 12:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-11-12 03:09 - 2015-10-13 11:31 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-12 03:09 - 2015-10-13 11:31 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-12 03:08 - 2015-10-19 19:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-11-12 03:08 - 2015-10-19 19:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-12 03:08 - 2015-10-19 19:52 - 00138176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-11-12 03:08 - 2015-10-19 19:52 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-12 03:08 - 2015-10-19 19:48 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-11-12 03:08 - 2015-10-19 19:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-11-12 03:08 - 2015-10-19 19:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-11-12 03:08 - 2015-10-19 19:45 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-11-12 03:08 - 2015-10-19 19:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-11-12 03:08 - 2015-10-19 19:44 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-11-12 03:08 - 2015-10-19 19:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-11-12 03:08 - 2015-10-19 19:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-11-12 03:08 - 2015-10-19 19:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-11-12 03:08 - 2015-10-19 19:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-11-12 03:08 - 2015-10-19 18:29 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-11-12 03:08 - 2015-10-19 18:28 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-11-12 03:08 - 2015-10-19 18:28 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-11-12 03:08 - 2015-10-12 23:50 - 00712640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-12 03:07 - 2015-10-20 12:46 - 02955776 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-12 03:07 - 2015-10-20 12:46 - 02061824 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-12 03:07 - 2015-10-20 12:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-12 03:07 - 2015-10-20 12:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-12 03:07 - 2015-10-20 12:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-12 03:07 - 2015-10-20 12:46 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-11-12 03:07 - 2015-10-20 12:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-11-12 03:07 - 2015-10-20 12:45 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-12 03:07 - 2015-10-20 12:45 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-11-12 03:07 - 2015-10-20 12:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-12 03:07 - 2015-10-20 12:45 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-11-12 03:07 - 2015-10-01 12:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-11-12 03:07 - 2015-10-01 12:50 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-11-12 03:07 - 2015-09-23 08:09 - 00371920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-11-12 03:07 - 2015-09-23 08:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2015-11-12 02:52 - 2015-11-19 08:28 - 00007560 _____ C:\Users\Ed\Desktop\FRST.txt
2015-11-12 02:47 - 2015-11-19 08:24 - 01378816 _____ (Farbar) C:\Users\Ed\Desktop\FRST.exe
2015-11-11 18:18 - 2015-11-11 18:18 - 00000000 ____D C:\New folder
2015-11-01 15:15 - 2015-11-01 15:15 - 00000340 _____ C:\Windows\Tasks\1015avUpdateInfo.job
2015-11-01 15:15 - 2015-11-01 15:15 - 00000000 ____D C:\ProgramData\Avg_Update_1015av
2015-10-24 10:55 - 2015-10-24 10:55 - 00000000 ____D C:\Users\Ed\AppData\Roaming\AVG
2015-10-24 10:51 - 2015-10-24 10:53 - 00000000 ____D C:\ProgramData\Avg
2015-10-24 10:40 - 2015-10-24 12:08 - 00000000 ____D C:\Users\Ed\AppData\Local\AvgSetupLog
2015-10-21 16:24 - 2015-10-21 16:24 - 00229296 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx86.sys
2015-10-21 16:14 - 2015-10-21 16:14 - 00192944 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx86.sys
2015-10-21 14:20 - 2015-11-19 07:47 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-19 08:28 - 2015-10-09 16:54 - 00000000 ____D C:\FRST
2015-11-19 08:05 - 2015-07-21 13:40 - 01400490 _____ C:\Windows\WindowsUpdate.log
2015-11-19 07:00 - 2009-07-13 23:34 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-19 07:00 - 2009-07-13 23:34 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-19 06:52 - 2009-07-13 23:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-19 06:52 - 2009-07-13 23:39 - 00054505 _____ C:\Windows\setupact.log
2015-11-18 21:46 - 2015-07-21 16:29 - 00344476 _____ C:\Windows\IE11_main.log
2015-11-18 20:55 - 2015-07-21 15:09 - 00000000 ____D C:\ProgramData\MFAData
2015-11-18 16:05 - 2015-07-26 18:21 - 00063808 _____ C:\Users\Ed\AppData\Local\GDIPFONTCACHEV1.DAT
2015-11-18 09:11 - 2015-07-21 13:41 - 00000000 ____D C:\Users\Ed
2015-11-18 09:09 - 2009-07-13 23:52 - 00000000 ____D C:\Windows\Offline Web Pages
2015-11-18 09:09 - 2009-07-13 21:37 - 00000000 __RSD C:\Windows\Media
2015-11-18 09:09 - 2009-07-13 21:37 - 00000000 ____D C:\Windows\registration
2015-11-17 17:24 - 2011-04-11 21:24 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-17 17:24 - 2009-07-13 21:37 - 00000000 ____D C:\Windows\system32\wfp
2015-11-17 17:23 - 2009-07-13 21:37 - 00000000 ____D C:\Windows\rescache
2015-11-17 17:22 - 2015-07-25 12:53 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-11-17 17:22 - 2015-07-22 17:42 - 00000000 ___SD C:\Windows\system32\GWX
2015-11-17 17:22 - 2015-07-21 15:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-11-17 17:22 - 2009-07-13 21:37 - 00000000 __RHD C:\Users\Default
2015-11-17 17:19 - 2009-07-13 21:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-11-17 17:18 - 2015-10-09 16:44 - 00000000 ____D C:\Program Files\Tweaking.com
2015-11-17 08:06 - 2009-07-13 23:33 - 00282232 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-16 14:46 - 2010-11-20 16:01 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-14 09:37 - 2015-07-21 15:26 - 00000000 ____D C:\Users\Ed\Desktop\Unused Icons
2015-11-12 02:47 - 2015-07-25 09:29 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-11-12 02:47 - 2015-07-25 09:29 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-11-11 19:00 - 2015-07-21 14:43 - 00000000 ____D C:\Windows\system32\MRT
2015-11-11 18:57 - 2015-07-21 14:43 - 143250520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-11-11 18:47 - 2011-04-11 21:24 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-11-11 18:47 - 2011-04-11 21:24 - 00000000 ____D C:\Windows\ShellNew
2015-11-04 16:41 - 2015-07-21 15:16 - 00000000 ___HD C:\$AVG
2015-11-04 16:40 - 2015-09-17 11:34 - 00000000 ____D C:\Users\Ed\AppData\Local\Avg
2015-10-29 08:55 - 2015-07-22 08:50 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-10-24 12:32 - 2009-07-13 21:04 - 00450771 ____R C:\Windows\system32\Drivers\etc\hosts.20151108-095805.backup
2015-10-24 10:57 - 2010-11-20 16:48 - 00088004 _____ C:\Windows\PFRO.log
2015-10-24 10:56 - 2015-07-21 15:14 - 00000000 ____D C:\Program Files\AVG
2015-10-24 10:55 - 2015-07-21 15:18 - 00000000 ____D C:\Program Files\Common Files\AV

Addition.txt follows:

Additional scan result of Farbar Recovery Scan Tool (x86) Version:18-11-2015
Ran by Ed (2015-11-19 08:28:49)
Running from C:\Users\Ed\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) (2015-07-21 18:41:30)
Boot Mode: Normal

==================== Accounts: =============================

Administrator (S-1-5-21-3659970256-991337627-2867597209-500 - Administrator - Disabled)
Ed (S-1-5-21-3659970256-991337627-2867597209-1001 - Administrator - Enabled) => C:\Users\Ed
Guest (S-1-5-21-3659970256-991337627-2867597209-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3659970256-991337627-2867597209-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20077 - Adobe Systems Incorporated)
Adobe Flash Player 19 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Photoshop 5.0.2 (HKLM\...\Adobe Photoshop 5.0.2) (Version: 5.0 - Adobe Systems, Inc.)
AVG (Version: 16.7.7227 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4460 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.7.7227 - AVG Technologies)
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - )
FMW 1 (Version: 1.32.2 - AVG Technologies) Hidden
H&R Block Deluxe + Efile 2014 (HKLM\...\{C89CA854-CE87-4CC6-A79F-86E0D7FB0B32}) (Version: 14.04.7401 - HRB Technology, LLC.)
Malwarebytes Anti-Malware version (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2000 Premium (HKLM\...\{00000409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation)
Microsoft Visio Professional 2002 [English] (HKLM\...\{90510409-6D54-11D4-BEE3-00C04F990354}) (Version: 10.0.525 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 38.1.0 - Mozilla)
Mozilla Thunderbird 38.3.0 (x86 en-US) (HKLM\...\Mozilla Thunderbird 38.3.0 (x86 en-US)) (Version: 38.3.0 - Mozilla)
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
ThinkPad Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.55 - )
Tweaking.com - Registry Backup (HKLM\...\Tweaking.com - Registry Backup) (Version: 3.2.2 - Tweaking.com)
Tweaking.com - Windows Repair (HKLM\...\Tweaking.com - Windows Repair) (Version: 3.6.3 - Tweaking.com)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: - AVG Technologies CZ, s.r.o.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Restore Points =========================

15-11-2015 22:06:27 Windows Update
16-11-2015 08:20:38 Windows Update
16-11-2015 09:56:24 Windows Update
16-11-2015 10:00:02 Windows Update
16-11-2015 10:01:35 Windows Update
16-11-2015 12:11:40 Windows Update
16-11-2015 14:47:37 Windows Update
16-11-2015 17:54:07 Windows Update
17-11-2015 06:28:55 Windows Modules Installer
17-11-2015 07:45:17 Windows Update
17-11-2015 10:54:09 Windows Update
17-11-2015 16:56:40 Restore Operation
17-11-2015 17:09:07 Windows Update
17-11-2015 17:15:53 Restore Operation
17-11-2015 21:23:02 Windows Update
18-11-2015 07:22:44 Windows Update
18-11-2015 07:24:06 Windows Update
18-11-2015 07:40:46 Windows Update
18-11-2015 07:41:50 Windows Update
18-11-2015 07:51:17 Windows Update
18-11-2015 08:27:15 Windows Update
18-11-2015 08:27:48 Windows Update
18-11-2015 09:03:23 Windows Modules Installer
18-11-2015 09:03:48 Windows Modules Installer
18-11-2015 09:04:15 Windows Modules Installer
18-11-2015 09:06:57 Restore Operation
18-11-2015 13:22:12 Windows Update
18-11-2015 13:23:35 Windows Update
18-11-2015 14:27:23 Windows Update
18-11-2015 17:58:02 Windows Update
18-11-2015 21:45:44 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {1F4C501C-34A1-4D9E-B7C6-840AE68FE10A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {2D9C48DE-C694-436F-9123-580EB099AA51} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-12] (Adobe Systems Incorporated)
Task: {4EEBD237-DBCF-4B4A-A40E-F6ACB68CF00A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {9F7842C1-875A-4B83-8AF5-FC70D5457E41} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {CFCCB0B6-5314-49C3-9F2E-CDEB398D885A} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-11] (Tweaking.com)
Task: {DCDA5300-1724-4338-B20E-88517EF64AD0} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\0615piUpdateInfo.job => C:\ProgramData\Avg_Update_0615pi\0615pi_AVG-Secure-Search-Update.exe
Task: C:\Windows\Tasks\1015avUpdateInfo.job => C:\ProgramData\Avg_Update_1015av\1015av_AVG-Secure-Search-Update.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Tweaking.com - Windows Repair Tray Icon.job => C:\Program Files\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe C:\Program Files\Tweaking.com\Windows Repair (All in One)Tweaking.com - Windows Repair)Created By Tweaking.com

==================== Loaded Modules (Whitelisted) ==============

2014-01-16 19:11 - 2013-01-14 23:47 - 00079648 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2015-07-25 12:53 - 2014-05-13 11:04 - 00109400 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2015-07-25 12:53 - 2014-05-13 11:04 - 00416600 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
2015-07-25 12:53 - 2014-05-13 11:04 - 00167768 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2015-07-25 12:53 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll
2015-07-25 12:53 - 2012-04-03 16:06 - 00565640 _____ () C:\Program Files\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2015-10-24 10:51 - 2015-10-24 10:40 - 40500224 _____ () C:\Program Files\AVG\UiDll\2171\libcef.dll

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3659970256-991337627-2867597209-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Ed\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{61EA1F3F-8266-4D1B-B088-DE4F26244D3F}] => (Allow) C:\Program Files\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{3B24444F-1A9A-4A78-9645-5074030A84BA}] => (Allow) C:\Program Files\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{23658621-CB50-42A5-8B7A-63E236D9DFEF}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{CC8C4175-2F17-4693-B6D5-7CA81FDEA919}] => (Allow) C:\Program Files\AVG\Av\avgmfapx.exe
FirewallRules: [{8C5147FC-B773-4348-849A-16B2304D8535}] => (Allow) C:\Program Files\AVG\Av\avgmfapx.exe
FirewallRules: [{E581DDF9-5119-4FE2-95B4-927D1E3890A2}] => (Allow) C:\Program Files\AVG\Av\avgnsx.exe
FirewallRules: [{4A26A062-57E2-432F-9DFC-519F92185DF3}] => (Allow) C:\Program Files\AVG\Av\avgnsx.exe
FirewallRules: [{281ED8C6-EF35-4F56-B20A-461CB176C0BE}] => (Allow) C:\Program Files\AVG\Av\avgdiagex.exe
FirewallRules: [{0D6D5B17-7D80-483E-B67F-C648C3FBC5A1}] => (Allow) C:\Program Files\AVG\Av\avgdiagex.exe
FirewallRules: [{A908C295-5AAF-4F2F-8AD1-D52A14EFEC60}] => (Allow) C:\Program Files\AVG\Av\avgemcx.exe
FirewallRules: [{49DE1C6F-8974-4C2D-A006-748022507B95}] => (Allow) C:\Program Files\AVG\Av\avgemcx.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU P8400 @ 2.26GHz
Percentage of memory in use: 43%
Total physical RAM: 1944.03 MB
Available physical RAM: 1099.21 MB
Total Virtual: 3888.06 MB
Available Virtual: 2632.74 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:294.72 GB) (Free:262.39 GB) NTFS
Drive e: () (Removable) (Total:57.87 GB) (Free:41.8 GB) FAT32

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 9C948886)
Partition 1: (Active) - (Size=3.4 GB) - (Type=27)
Partition 2: (Not Active) - (Size=294.7 GB) - (Type=07 NTFS)

Disk: 1 (Size: 57.9 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

2015-11-19, 17:09
As far as anything related to malware, there isn't anything. What I think I see now from the last log appears to be probably hardware related.
What brand of computer are you using? (for instance I have a Dell Vostro 3500)
Could be, if you ran a driver system check from the manufacturer for your computer there could be a few driver updates that could be very useful.

We could look in Device Manager to see if any drivers have red flags

Update drivers: recommended links

the issue still persists, then I would suggest you to perform an in-place upgrade or a repair install of the Windows operating system.

How to Perform an In-Place Upgrade on Windows Vista, Windows 7, Windows Server 2008 & Windows Server 2008 R2


Important: Make sure to back up all your date before performing the repair installation.

Note: After performing In-Place Upgrade, your personal data and installed programs will not be removed but you may need to run Windows Update to install all the available updates for your system to update these system files to the current version.

If your DVD installation disk is prior to Sp1, and you have SP1 installed on your computer, you will need to uninstall SP1 to complete the in-place upgrade and then reinstall the necessary windows updates. This applies if you have SP2 also.

2015-11-19, 23:22
This is a Lenovo R500 laptop that originally ran the Vista OS, but was "upgraded" by Joy Systems to run Windows 7 Home Premium. It has a one-year Joy Systems warranty (expiration 2/16). Joy replaced the first battery (so they do honor the warranty). I rather doubt Lenovo would support it now.

Found flags on two Base System Devices and one PCI Simple Communications Controller that do not have drivers installed. Windows Device Manager cannot identify the manufacturer of these devices, or their drivers, and says these three are not using any resources because they “have a problem.”

From MS site, I searched for drivers, but none of the three missing could be found. I plan to call Joy Systems Tech Support to ask for information on these devices and any drivers required.

Suddenly, Windows Explorer is behaving normally, and I’ve tried it several times to see if it’s just being flakey. Therefore, I think everything I originally mentioned on this thread, plus a few, has been resolved (somehow) if you want to close the thread.

Thanks for your help!

2015-11-20, 00:54
Suddenly, Windows Explorer is behaving normally
I don't believe you! (joking)
wonder if going into device manager stirred something up?

I researched your laptop and found a couple of things related to these drivers

read over these and see if you think it might relate to your issues.

I plan to call Joy Systems Tech Support to ask for information on these devices and any drivers required
Do that next then.

let me know how it goes, also, we need to remove tools and quarantine folders.

http://i.imgur.com/AFZxnZc.jpg DelFix

Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix) or from Here (http://www.bleepingcomputer.com/download/delfix/) and save the file to your Desktop.

Double-click DelFix.exe to run the programme.
Place a checkmark next to the following items:

Activate UAC
Remove disinfection tools

Click the Run button.
-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).

2015-11-20, 15:04
Did you intend to send me a link to something about the drivers?

2015-11-20, 15:53
you ain't going to believe this, yes, I did and forgot to post them....(I sure thought I did)

let me see if I can find them again.

2015-11-20, 16:03
There was a wealth of information really.

Lenovo forums
This is a site where other people ask questions about Lenovo machines


Updating Lenovo Drivers and Applications using ThinkVantage System Update


See if any of the information is those links help :)

2015-11-20, 18:59
After surfing through the links you sent, I called Joy Systems technical support. The attendant connected to my computer remotely, saw the three flags on the Device Manager, went to one of the same Lenovo sites, and downloaded several drivers. Some did nothing, but he eventually cleared all three missing driver flags.

Installing the missing drivers had no effect on the crashing Windows Explorer. I showed him that, and he said it looked like a software problem and showed me a workaround. If I get tired of that; he suggested I run a System Restore on Startup to reinstall Windows. Since that means downloading and installing WELL over 100 Windows Updates, I think I’ll put that off until I have absolutely nothing else to do because the system is otherwise running fine.

2015-11-20, 23:30
From my last post, you may have noticed that my Windows Explorer has gone back to its wicked ways...I guess I can live with that.

2015-11-21, 00:56
From my last post, you may have noticed that my Windows Explorer has gone back to its wicked ways...I guess I can live with that.

We've done all we can do in the malware removal.

Wish the Tech from Joy Systems could had brought in more joy!

I didn't want to bring up doing a reformat till there was no other options.....I'll have to leave that up to you what you can and cannot live with.

2015-11-22, 05:42
Fair enough! Thanks for your help. Have a nice Thanksgiving!

2015-11-22, 14:17
Glad we could help. :)http://i204.photobucket.com/albums/bb106/Juliet702/sparkle.gif

Since this issue appears resolved ... this Topic is closed.