This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

hi hoping you can help me with iswebssearches. hijacker [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My lap top is running win 7 32 bit
Today i downloaded what i thought was a genuine windows update and a hijacker called websearches has taken over my internet explorer . It wont even let me communicate with you !! Im sending this from my phone. I do have accsses to a desktop machine which is working fine.
The lap top seems to running fine except the internet explorer. Hope you can advise me what to do. But i cant use ie 11 on the laptop. !!!!
 

:welcome:

 

I edited your post, please do not post any personal info like email address .

 

I am going to give you some instructions, you may have to download these programs to a clean computer and copy them to a USB Thumb drive to this infected one and run them

 

 

 
[external image: 1QYkxTZ.jpg] Please download aswMBR to your desktop.
 
  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
  •  
    I just want to see the report….Please Do Not Fix Anything
     
    ============================================================================
     
     
     
     
    Please download Farbar Recovery Scan Tool and save it to your desktop.
     
    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
     
    How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
    A simple way to check your system: Start –> Computer (right click) –> Properties
     
    [external image: FRST_zps5d956a1a.jpg]
     
     
    • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
    • Please make sure All Users is checked
    • Just keep the defaults as in the picture checkmarked
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
    • hi Ken,

        first thing id like to say a big thanks and appreciate your help and work.

         heres what you asked me to do.

       

       

      aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
      Run date: 2015-01-27 11:01:36
      —————————–
      11:01:36.680    OS Version: Windows 6.1.7601 Service Pack 1
      11:01:36.680    Number of processors: 2 586 0xF06
      11:01:36.680    ComputerName: EDITMACHINE-PC  UserName: EDIT MACHINE
      11:01:37.444    Initialize success
      11:01:37.616    VM: initialized successfully
      11:01:37.616    VM: Intel CPU supported 
      11:01:54.892    VM: supported disk I/O ataport.SYS
      11:05:21.639    AVAST engine defs: 15012700
      11:05:45.335    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
      11:05:45.351    Disk 0 Vendor: ST9200420AS 3.AAA Size: 190782MB BusType: 3
      11:05:45.507    VM: Disk 0 MBR read successfully
      11:05:45.522    Disk 0 MBR scan
      11:05:45.585    Disk 0 Windows 7 default MBR code
      11:05:45.600    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS        40962 MB offset 63
      11:05:45.600    Disk 0 default boot code
      11:05:45.663    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       149817 MB offset 83891430
      11:05:45.694    Disk 0 scanning sectors +390716865
      11:05:45.850    Disk 0 scanning C:\Windows\system32\drivers
      11:06:03.275    File: C:\Windows\system32\drivers\webinstrNHKT.sys  **INFECTED** Win32:Rootkit-gen [Rtk]
      11:06:03.930    Disk 0 statistics 97330/0/274 @ 7.18 MB/s
      11:06:03.930    Scan finished successfully
      11:06:37.517    Disk 0 MBR has been saved successfully to "F:\logs\MBR.dat"
      11:06:37.533    The log file has been saved successfully to "F:\logs\aswMBR.txt"
       
       
      Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-01-2015 01
      Ran by [removed] (administrator) on EDITMACHINE-PC on 27-01-2015 11:08:58
      Running from C:\Users\[removed]\Desktop
      [removed]
      Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: English (United States)
      Internet Explorer Version 11 (Default browser: IE)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
       
      ==================== Processes (Whitelisted) =================
       
      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
       
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
      (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
      (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
      (SysTool PasSame LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
      (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
      () C:\Program Files\35556262-902E-49AE-8622-66E14F1F041C\arrmeapsie.exe
      (XTab system) C:\Program Files\XTab\ProtectService.exe
      (Aztec Media Inc) C:\Program Files\Settings Manager\smdmf\SmdmFService.exe
      (Aztec Media Inc) C:\Program Files\Settings Manager\smdmf\SmdmFService.exe
      (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
      (Aztec Media Inc) C:\Program Files\Settings Manager\smdmf\smdmfu.exe
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
      (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer.exe
      (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\tv_w32.exe
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
      (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
      (SearchProtect) C:\Program Files\XTab\CmdShell.exe
      (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
      (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
      (Samsung) C:\Program Files\Samsung\Kies\Kies.exe
      (XTab system) C:\Program Files\XTab\HPNotify.exe
      (Grass Valley K.K.) C:\Program Files\Grass Valley\GV LicenseManager\AppMaintainer.exe
      (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
      (Nero AG) C:\Program Files\Nero\Update\NASvc.exe
      (Flexera Software LLC.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
       
       
      ==================== Registry (Whitelisted) ==================
       
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
       
      HKLM\…\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
      HKLM\…\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
      HKLM\…\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-22] (Microsoft Corporation)
      HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
      HKLM\…\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
      HKLM\…\Run: [] => [X]
      HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
      HKLM\…\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.)
      HKLM\…\Run: [gmsd_gb_101] => [X]
      HKU\S-1-5-21-851169767-2126091772-1983836877-1001\…\Run: [HP Deskjet 3050A J611 series (NET)] => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe [1804648 2011-06-08] (Hewlett-Packard Co.)
      HKU\S-1-5-21-851169767-2126091772-1983836877-1001\…\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1562264 2014-07-25] (Samsung)
      HKU\S-1-5-21-851169767-2126091772-1983836877-1001\…\MountPoints2: {45fb4f69-f9a0-11e3-8653-806e6f6e6963} - E:\Setup.exe
      Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
      ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
      Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GV LicenseManager.lnk
      ShortcutTarget: GV LicenseManager.lnk -> C:\Program Files\Grass Valley\GV LicenseManager\AppMaintainer.exe (Grass Valley K.K.)
      HKLM\…\AppCertDlls: [x64] -> c:\program files\settings manager\smdmf\x64\sysapcrt.dll
      HKLM\…\AppCertDlls: [x86] -> C:\Program Files\Settings Manager\smdmf\sysapcrt.dll [493584 2014-12-15] ()
      CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
       
      ==================== Internet (Whitelisted) ====================
       
      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
       
      ProxyServer: [S-1-5-21-851169767-2126091772-1983836877-1001] =>
      HKU\S-1-5-21-851169767-2126091772-1983836877-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/en-gb/?ocid=U220DHP&pc;=U220
      HKU\S-1-5-21-851169767-2126091772-1983836877-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
      HKU\S-1-5-21-851169767-2126091772-1983836877-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts;=1422292359&from;=brd&uid;=ST9200420AS_5SH016RDXXXX5SH016RD
      HKU\S-1-5-21-851169767-2126091772-1983836877-1001\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1me10IE11ENGB/MCM_WCP
      StartMenuInternet: IEXPLORE.EXE - iexplore.exe
      SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 
      SearchScopes: HKU\S-1-5-21-851169767-2126091772-1983836877-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?FORM=U220DF&PC;=U220&q;={searchTerms}&src;=IE-SearchBox
      SearchScopes: HKU\S-1-5-21-851169767-2126091772-1983836877-1001 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = 
      SearchScopes: HKU\S-1-5-21-851169767-2126091772-1983836877-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = 
      SearchScopes: HKU\S-1-5-21-851169767-2126091772-1983836877-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?FORM=U220DF&PC;=U220&q;={searchTerms}&src;=IE-SearchBox
      SearchScopes: HKU\S-1-5-21-851169767-2126091772-1983836877-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
      SearchScopes: HKU\S-1-5-21-851169767-2126091772-1983836877-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492&aid;=292&itype;=a&ver;=15005&tm;=604&src;=ds&p;={searchTerms}
      BHO: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files\XTab\SupTab.dll (Thinknice Co. Limited)
      BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
      BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
      Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
      Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [152864] (Apple Inc.)
      Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
      Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
       
      FireFox:
      ========
      FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
      FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
      FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
      FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
      FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
      FF Plugin: @videolan.org/vlc,version=2.0.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
      FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
      FF HKU\S-1-5-21-851169767-2126091772-1983836877-1001\…\Firefox\Extensions: [{9DBD7E94-0916-D9AC-EFF0-25CB7DE4421A}] - C:\Program Files\ver8BlockAndSurf\186.xpi
       
      Chrome: 
      =======
      CHR dev: Chrome dev build detected! <======= ATTENTION
       
      ========================== Services (Whitelisted) =================
       
      (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
       
      R2 CouponArificService; C:\Program Files\35556262-902E-49AE-8622-66E14F1F041C\arrmeapsie.exe [150528 2014-09-29] () [File not signed]
      R3 FlexNet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1045840 2014-06-22] (Flexera Software LLC.)
      S2 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2015-01-26] (globalUpdate) [File not signed]
      S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2015-01-26] (globalUpdate) [File not signed]
      R2 IHProtect Service; C:\Program Files\XTab\ProtectService.exe [158896 2015-01-16] (XTab system)
      R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
      R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [503080 2010-05-04] (Nero AG)
      R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
      R2 SmdmFService; C:\Program Files\Settings Manager\smdmf\SmdmFService.exe [3573264 2014-12-15] (Aztec Media Inc)
      S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
      R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [464384 2015-01-26] (SysTool PasSame LIMITED) [File not signed]
      S2 Update Yula; "C:\Program Files\Yula\updateYulasee.exe" [X]
       
      ==================== Drivers (Whitelisted) ====================
       
      (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
       
      R1 cdrblock; C:\Windows\System32\DRIVERS\cdrblock.sys [31304 2014-01-27] (Grass Valley K.K.)
      R1 F06DEFF2-5B9C-490D-910F-35D3A91196222; C:\Program Files\Settings Manager\smdmf\smdmfmgrc3.cfg [38288 2014-12-15] (Aztec Media Inc)
      R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
      R1 MpKsld13f90bf; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{96A0D570-99AE-4AF1-8BB6-BCF8B7008C07}\MpKsld13f90bf.sys [39464 2015-01-27] (Microsoft Corporation)
      R1 netfilter; C:\Windows\System32\drivers\netfilter.sys [31744 2014-09-29] (NetFilterSDK.com) [File not signed]
      R0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [45968 2012-09-01] (Rovi Corporation)
      S3 SxSmemcd; C:\Windows\System32\DRIVERS\SxSmemcd.sys [45056 2010-02-09] (Sony Corporation)
      R2 SXSUDFMF; C:\Windows\System32\DRIVERS\SXSUDFMF.sys [4352 2012-06-18] (Sony Corporation)
      R4 SXSUDFS; C:\Windows\System32\DRIVERS\SXSUDFS.sys [809472 2012-06-18] (Sony Corporation)
      R2 webinstrNHKT; C:\Windows\system32\Drivers\webinstrNHKT.sys [49216 2015-01-26] (Corsica)
      R1 {facdc9f6-60e8-45b2-8807-bf1a7548ccda}Gw; C:\Windows\System32\drivers\{facdc9f6-60e8-45b2-8807-bf1a7548ccda}Gw.sys [43160 2014-10-22] (StdLib)
      R1 {fef7f75c-f985-4250-96f9-8183cd04238b}Gw; C:\Windows\System32\drivers\{fef7f75c-f985-4250-96f9-8183cd04238b}Gw.sys [43160 2014-10-22] (StdLib)
      S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
      S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
      S3 VGPU; System32\drivers\rdvgkmd.sys [X]
      U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-13] (Microsoft Corporation)
      U3 aswMBR; \??\C:\Users\EDITMA~1\AppData\Local\Temp\aswMBR.sys [X]
      U3 aswVmm; \??\C:\Users\EDITMA~1\AppData\Local\Temp\aswVmm.sys [X]
       
      ==================== NetSvcs (Whitelisted) ===================
       
       
      (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
       
       
      ==================== One Month Created Files and Folders ========
       
      (If an entry is included in the fixlist, the file\folder will be moved.)
       
      2015-01-27 11:08 - 2015-01-27 11:09 - 00015778 _____ () C:\Users\EDIT MACHINE\Desktop\FRST.txt
      2015-01-27 11:07 - 2015-01-27 11:09 - 00000000 ____D () C:\FRST
      2015-01-27 11:00 - 2015-01-27 09:48 - 05198336 _____ (AVAST Software) C:\Users\EDIT MACHINE\Desktop\aswMBR.exe
      2015-01-27 11:00 - 2015-01-27 09:48 - 01120768 _____ (Farbar) C:\Users\EDIT MACHINE\Desktop\FRST.exe
      2015-01-26 20:15 - 2015-01-26 20:16 - 29720784 _____ (Microsoft Corporation) C:\Users\EDIT MACHINE\Downloads\IE11-Windows6.1-x86-en-us.exe
      2015-01-26 20:10 - 2015-01-26 20:10 - 00000000 ___HD () C:\Windows\msdownld.tmp
      2015-01-26 17:33 - 2015-01-26 17:33 - 00000000 ____D () C:\Users\EDIT MACHINE\AppData\Local\10609
      2015-01-26 17:30 - 2015-01-27 10:00 - 00000414 _____ () C:\Windows\Tasks\BlockAndSurf Update.job
      2015-01-26 17:30 - 2015-01-26 17:36 - 00000000 ____D () C:\Program Files\ver8BlockAndSurf
      2015-01-26 17:30 - 2015-01-26 17:30 - 00049216 _____ (Corsica) C:\Windows\system32\Drivers\webinstrNHKT.sys
      2015-01-26 17:14 - 2015-01-26 17:14 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
      2015-01-26 17:14 - 2015-01-26 17:14 - 00000000 ____D () C:\Program Files\XTab
      2015-01-26 17:13 - 2015-01-26 17:13 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
      2015-01-26 17:11 - 2015-01-27 10:32 - 00000330 _____ () C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
      2015-01-26 17:11 - 2015-01-26 17:36 - 00000000 ____D () C:\Program Files\PC Speed Up
      2015-01-26 17:11 - 2015-01-26 17:11 - 00000000 ____D () C:\Program Files\predm
      2015-01-26 16:55 - 2015-01-27 11:09 - 00000000 ____D () C:\ProgramData\smdmf
      2015-01-26 16:26 - 2015-01-27 10:36 - 00001366 _____ () C:\Windows\Tasks\KVSELX.job
      2015-01-26 16:26 - 2015-01-27 10:31 - 00000976 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
      2015-01-26 16:26 - 2015-01-27 10:26 - 00003456 _____ () C:\Windows\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-1.job
      2015-01-26 16:26 - 2015-01-27 10:26 - 00002442 _____ () C:\Windows\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5_user.job
      2015-01-26 16:26 - 2015-01-27 10:26 - 00002442 _____ () C:\Windows\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5.job
      2015-01-26 16:26 - 2015-01-27 10:26 - 00002108 _____ () C:\Windows\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-10_user.job
      2015-01-26 16:26 - 2015-01-27 10:26 - 00002106 _____ () C:\Windows\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-2.job
      2015-01-26 16:26 - 2015-01-27 10:00 - 00000972 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
      2015-01-26 16:26 - 2015-01-26 17:30 - 00001864 _____ () C:\Windows\patsearch.bin
      2015-01-26 16:26 - 2015-01-26 16:26 - 01832936 _____ (Cinema PlusV26.01) C:\Users\EDIT MACHINE\AppData\Roaming\KVSELX.exe
      2015-01-26 16:26 - 2015-01-26 16:26 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNHKT_01009.Wdf
      2015-01-26 16:26 - 2015-01-26 16:26 - 00000000 ____D () C:\Users\EDIT MACHINE\AppData\Local\globalUpdate
      2015-01-26 16:26 - 2015-01-26 16:26 - 00000000 ____D () C:\Program Files\globalUpdate
      2015-01-26 16:23 - 2015-01-26 16:23 - 00000000 ____D () C:\Program Files\Settings Manager
      2015-01-26 14:17 - 2015-01-26 17:55 - 00001114 _____ () C:\Users\EDIT MACHINE\Desktop\Continue Live Installation.lnk
      2015-01-26 14:05 - 2015-01-26 14:05 - 00000000 ____D () C:\ProgramData\9492754456844433337UL
      2015-01-26 13:49 - 2014-12-12 05:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
      2015-01-26 13:49 - 2014-12-12 05:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
      2015-01-26 13:49 - 2014-11-11 02:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
      2015-01-26 13:48 - 2014-12-11 17:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
      2015-01-26 13:48 - 2014-11-27 01:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
      2015-01-26 13:48 - 2014-11-22 02:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
      2015-01-26 13:48 - 2014-11-22 02:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
      2015-01-26 13:48 - 2014-11-22 02:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
      2015-01-26 13:48 - 2014-11-22 02:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
      2015-01-26 13:48 - 2014-11-22 02:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
      2015-01-26 13:48 - 2014-11-22 02:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
      2015-01-26 13:48 - 2014-11-22 02:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
      2015-01-26 13:48 - 2014-11-22 02:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
      2015-01-26 13:48 - 2014-11-22 01:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
      2015-01-26 13:48 - 2014-11-22 01:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
      2015-01-26 13:48 - 2014-11-22 01:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
      2015-01-26 13:48 - 2014-11-22 01:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
      2015-01-26 13:48 - 2014-11-22 01:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
      2015-01-26 13:48 - 2014-11-22 01:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
      2015-01-26 13:48 - 2014-11-22 01:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
      2015-01-26 13:48 - 2014-11-22 01:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
      2015-01-26 13:48 - 2014-11-22 01:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
      2015-01-26 13:48 - 2014-11-22 01:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
      2015-01-26 13:48 - 2014-11-22 01:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
      2015-01-26 13:48 - 2014-11-22 01:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
      2015-01-26 13:48 - 2014-11-22 01:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
      2015-01-26 13:48 - 2014-11-22 01:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
      2015-01-26 13:48 - 2014-11-22 01:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
      2015-01-26 13:48 - 2014-11-22 01:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
      2015-01-26 13:48 - 2014-11-22 01:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
      2015-01-26 13:48 - 2014-11-22 01:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
      2015-01-26 13:48 - 2014-11-22 01:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
      2015-01-26 13:48 - 2014-11-22 00:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
      2015-01-26 13:48 - 2014-11-22 00:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
      2015-01-26 13:47 - 2014-12-19 02:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
      2015-01-26 13:47 - 2014-12-06 03:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
      2015-01-26 13:46 - 2014-12-19 01:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
      2015-01-26 13:41 - 2014-11-11 02:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
      2015-01-26 13:41 - 2014-11-11 02:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
      2015-01-25 16:12 - 2015-01-25 16:12 - 00001248 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\KVSELX
       
      ==================== One Month Modified Files and Folders =======
       
      (If an entry is included in the fixlist, the file\folder will be moved.)
       
      2015-01-27 11:01 - 2014-06-22 01:03 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI
      2015-01-27 11:00 - 2009-07-14 04:34 - 00009904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
      2015-01-27 11:00 - 2009-07-14 04:34 - 00009904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
      2015-01-27 10:37 - 2009-07-14 02:37 - 00000000 ____D () C:\Windows\rescache
      2015-01-27 10:04 - 2014-06-22 00:04 - 01539674 _____ () C:\Windows\WindowsUpdate.log
      2015-01-27 10:00 - 2009-07-14 04:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
      2015-01-27 10:00 - 2009-07-14 04:39 - 00025345 _____ () C:\Windows\setupact.log
      2015-01-26 22:05 - 2014-10-23 12:24 - 00000000 ____D () C:\Program Files\CouponArific
      2015-01-26 21:36 - 2014-06-22 13:16 - 00003298 _____ () C:\Windows\FORGXP32.INI
      2015-01-26 21:36 - 2014-06-22 13:16 - 00000000 ____D () C:\Program Files\Sound Forge XP
      2015-01-26 20:53 - 2014-06-22 09:19 - 00041596 _____ () C:\Windows\PFRO.log
      2015-01-26 20:10 - 2014-06-22 05:34 - 00018260 _____ () C:\Windows\IE11_main.log
      2015-01-26 17:26 - 2014-07-25 14:23 - 00000000 ____D () C:\ProgramData\83bd09e23c37f7b9
      2015-01-26 17:12 - 2014-06-22 06:18 - 00002335 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
      2015-01-26 17:12 - 2014-06-22 00:58 - 00001621 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
      2015-01-26 16:56 - 2014-06-22 11:07 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
      2015-01-26 16:56 - 2014-06-22 11:07 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
      2015-01-26 16:46 - 2014-06-22 10:06 - 00000000 ____D () C:\ProgramData\Microsoft Help
      2015-01-26 16:46 - 2014-06-22 05:44 - 00000000 ____D () C:\Windows\system32\MRT
      2015-01-26 13:34 - 2014-06-22 14:49 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
      2014-12-31 13:15 - 2014-06-22 05:44 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
      2014-12-31 11:13 - 2014-06-22 01:16 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
       
      ==================== Files in the root of some directories =======
       
      2014-10-22 19:49 - 2014-10-22 19:49 - 0001307 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\Bubble Dock.boostrap.log
      2014-10-22 19:49 - 2014-10-22 19:49 - 0005817 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\Bubble Dock.installation.log
      2015-01-25 16:12 - 2015-01-25 16:12 - 0001248 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\KVSELX
      2015-01-26 16:26 - 2015-01-26 16:26 - 1832936 _____ (Cinema PlusV26.01) C:\Users\EDIT MACHINE\AppData\Roaming\KVSELX.exe
      2014-10-22 20:36 - 2014-10-22 20:36 - 0000045 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\WB.CFG
      2014-10-22 21:06 - 2014-10-22 21:06 - 0627648 _____ (CMI Limited) C:\Users\EDIT MACHINE\AppData\Local\nsgBE14.tmp
      2014-10-22 19:55 - 2014-10-22 19:54 - 0612212 _____ (CMI Limited) C:\Users\EDIT MACHINE\AppData\Local\nsuCF42.tmp
      2014-06-26 11:32 - 2014-06-26 11:32 - 0000057 _____ () C:\ProgramData\Ament.ini
       
      Some content of TEMP:
      ====================
      C:\Users\EDIT MACHINE\AppData\Local\Temp\0D3FA6CD-D378-31D0-2ED5-DE2CEF4D3C3F.exe
      C:\Users\EDIT MACHINE\AppData\Local\Temp\4721.exe
      C:\Users\EDIT MACHINE\AppData\Local\Temp\8988D349-9EF9-B3CD-1347-E5BEBBFD4598.dll
      C:\Users\EDIT MACHINE\AppData\Local\Temp\8988D349-9EF9-B3CD-1347-E5BEBBFD4598.exe
      C:\Users\EDIT MACHINE\AppData\Local\Temp\amisetup6292__11003.exe
      C:\Users\EDIT MACHINE\AppData\Local\Temp\ICReinstall_UltimateCodecsSetup.exe
      C:\Users\EDIT MACHINE\AppData\Local\Temp\optprosetup.exe
      C:\Users\EDIT MACHINE\AppData\Local\Temp\System.Data.SQLite.dll
      C:\Users\EDIT MACHINE\AppData\Local\Temp\System.Data.SQLite58686.dll
      C:\Users\EDIT MACHINE\AppData\Local\Temp\System.Data.SQLite62256.dll
      C:\Users\EDIT MACHINE\AppData\Local\Temp\System.Data.SQLite80616.dll
      C:\Users\EDIT MACHINE\AppData\Local\Temp\System.Data.SQLite82851.dll
      C:\Users\EDIT MACHINE\AppData\Local\Temp\Uninstall.exe
      C:\Users\EDIT MACHINE\AppData\Local\Temp\vcredist_x64.exe
      C:\Users\EDIT MACHINE\AppData\Local\Temp\vcredist_x86.exe
       
       
      ==================== Bamital & volsnap Check =================
       
      (There is no automatic fix for files that do not pass verification.)
       
      C:\Windows\explorer.exe => File is digitally signed
      C:\Windows\system32\winlogon.exe => File is digitally signed
      C:\Windows\system32\wininit.exe => File is digitally signed
      C:\Windows\system32\svchost.exe => File is digitally signed
      C:\Windows\system32\services.exe => File is digitally signed
      C:\Windows\system32\User32.dll => File is digitally signed
      C:\Windows\system32\userinit.exe => File is digitally signed
      C:\Windows\system32\rpcss.dll => File is digitally signed
      C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
       
       
      LastRegBack: 2015-01-26 16:19
       
      ==================== End Of Log ============================
       
       
       
       
      Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-01-2015 01
      Ran by [removed] at 2015-01-27 11:09:40
      Running from C:\Users\[removed]\Desktop
      Boot Mode: Normal
      ==========================================================
       
       
      ==================== Security Center ========================
       
      (If an entry is included in the fixlist, it will be removed.)
       
      AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
      AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
      AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
       
      ==================== Installed Programs ======================
       
      (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
       
      Adobe After Effects CS4 (HKLM\…\Adobe_3dcb365ab9e01871fb8c6f27b0ea079) (Version: 9 - Adobe Systems Incorporated)
      Adobe AIR (HKLM\…\Adobe AIR) (Version: 1.1.0.5790 - Adobe Systems Inc.)
      Adobe Flash Player 16 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
      Adobe Media Player (HKLM\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
      Adobe Photoshop 7.0 (HKLM\…\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.)
      Adobe Reader XI (11.0.10) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
      Apple Application Support (HKLM\…\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
      Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
      Bonjour (HKLM\…\{0CB9668D-F979-4F31-B8B8-67FE90F929F8}) (Version: 2.0.2.0 - Apple Inc.)
      ContentBrowser (HKLM\…\{36651F49-C025-4927-9006-7935F11E1449}) (Version: 1.1.0.372 - Sony Corporation)
      EDIUS (HKLM\…\{E778FC49-5FE7-486E-AB18-0F418BE97189}) (Version: 6.55 - Grass Valley K.K.)
      EDIUS Codec Option 6.55 (HKLM\…\{E7EE42CB-C5A2-46C5-93AC-EA285F86C022}) (Version: 6.55 - Grass Valley K.K.)
      EDIUS DVD Menu Style 1.00 (HKLM\…\{E4F24AE3-CA17-423A-8CF9-43EBE3C9012B}) (Version: 1.00 - Grass Valley K.K.)
      FileZilla Client 3.9.0.6 (HKLM\…\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse)
      GV LicenseManager 1.05 (HKLM\…\{EE256B6B-7F66-409B-9CF2-CE9B64947CBC}) (Version: 1.05 - Grass Valley K.K.)
      H.264 Encoder (HKLM\…\{B99459D2-B91A-417E-9DFA-F53D569F4445}_is1) (Version:  - www.H264Encoder.com)
      HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\…\CNXT_MODEM_HDA_HSF) (Version: 7.80.4.50 - Conexant Systems)
      High-Definition Video Playback (Version: 7.1.13900.47.0 - Nero AG) Hidden
      HP Deskjet 3050A J611 series Basic Device Software (HKLM\…\{AE47EB5B-1789-4480-AD6D-7753473E9DDE}) (Version: 25.0.571.0 - Hewlett-Packard Co.)
      HP Deskjet 3050A J611 series Help (HKLM\…\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
      HP Update (HKLM\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
      HPDiagnosticAlert (Version: 1.00.0001 - Microsoft) Hidden
      Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
      Microsoft Office Professional Plus 2010 (HKLM\…\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation)
      Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
      Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (HKLM\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\…\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
      MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
      MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
      MyFreeCodec (HKU\S-1-5-21-851169767-2126091772-1983836877-1001\…\MyFreeCodec) (Version:  - )
      Nero 10 Movie ThemePack 1 (HKLM\…\{43FBAB46-5969-4200-9958-1FF81FEE506F}) (Version: 10.2.10000.11.0 - Nero AG)
      Nero BurnRights 10 (HKLM\…\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.2.10500.1.102 - Nero AG)
      Nero CoverDesigner 10 (HKLM\…\{FCF00A6E-FB58-477A-ABE9-232907105521}) (Version: 5.2.11400.11.100 - Nero AG)
      Nero DiscCopy Gadget 10 (HKLM\…\{92EC1A84-7FFC-42DF-A8F6-79C21C4765A5}) (Version: 3.2.10700.9.100 - Nero AG)
      Nero DiscSpeed 10 (HKLM\…\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG)
      Nero Express 10 (HKLM\…\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.11900.20.100 - Nero AG)
      Nero InfoTool 10 (HKLM\…\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.2.10400.5.100 - Nero AG)
      Nero MediaHub 10 (HKLM\…\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}) (Version: 1.2.13200.33.100 - Nero AG)
      Nero Multimedia Suite 10 Essentials (HKLM\…\{ADEF1F0B-635E-4041-B50F-A510C1B4D2C5}) (Version: 10.5.10400 - Nero AG)
      Nero RescueAgent 10 (HKLM\…\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.2.10800.9.100 - Nero AG)
      Nero StartSmart 10 (HKLM\…\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
      Nero Update (HKLM\…\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
      Photoshop Camera Raw (Version: 5.0 - Adobe Systems Incorporated) Hidden
      Pixel Bender Toolkit (Version: 1.0 - Adobe Systems Incorporated) Hidden
      QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
      Revo Uninstaller 1.95 (HKLM\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
      Riva FLV Player (HKLM\…\Riva FLV Player_is1) (Version: 1.0.0000 - Rothenberger & Partner)
      Samsung Kies (HKLM\…\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.)
      Samsung Kies (Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.) Hidden
      SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
      Settings Manager (HKLM\…\Settings Manager) (Version: 5.0.0.14963 - Aztec Media Inc) <==== ATTENTION
      Software Version Updater (HKU\S-1-5-21-851169767-2126091772-1983836877-1001\…\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}) (Version: 1.1.4.2 - ) <==== ATTENTION
      Sony SxS UDF driver (HKLM\…\{D4499B3C-3036-4667-8827-DEB4DA53ECD6}) (Version: 2.0.1.1 - Sony Corporation)
      Sound Forge XP 4.0 for Windows 95 and NT (x86) (HKLM\…\Sound Forge XP) (Version:  - )
      Suite Shared Configuration CS4 (Version: 1.0 - Adobe Systems Incorporated) Hidden
      SxS device driver (HKLM\…\{D2D8328B-F031-4F69-8621-250701844E9A}) (Version: 1.01.00000 - Sony Corporation)
      TeamViewer 9 (HKLM\…\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
      TeraCentral (HKLM\…\{3A971636-157A-4503-AA59-D445AD833D83}) (Version: 0.9.1 - Teradek)
      VLC media player 2.0.0 (HKLM\…\VLC media player) (Version: 2.0.0 - VideoLAN)
      WinRAR 5.01 (32-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
      WinZip 12.1 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}) (Version: 12.1.8497 - WinZip Computing, S.L. )
       
      ==================== Custom CLSID (selected items): ==========================
       
      (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
       
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{00b7e0ab-817a-44ad-a04b-d1148d524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{117270FA-48AC-45BB-9171-B63D1B42A910}\localserver32 -> C:\Users\EDIT MACHINE\AppData\Local\10609\Updater.exe ()
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{7c6e29bc-8b8b-4c3d-859e-af6cd158be0f}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c0-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c1-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c2-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c3-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c4-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c5-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c8-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c9-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969ca-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969d6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
       
      ==================== Restore Points  =========================
       
       
      ==================== Hosts content: ==========================
       
      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
       
      2009-07-14 02:04 - 2014-06-22 15:48 - 00001796 ____A C:\Windows\system32\Drivers\etc\hosts
      127.0.0.1 activate.adobe.com
      127.0.0.1 practivate.adobe.com
      127.0.0.1 ereg.adobe.com
      127.0.0.1 activate.wip3.adobe.com
      127.0.0.1 wip3.adobe.com
      127.0.0.1 3dns-3.adobe.com
      127.0.0.1 3dns-2.adobe.com
      127.0.0.1 adobe-dns.adobe.com
      127.0.0.1 adobe-dns-2.adobe.com
      127.0.0.1 adobe-dns-3.adobe.com
      127.0.0.1 ereg.wip3.adobe.com
      127.0.0.1 activate-sea.adobe.com
      127.0.0.1 wwis-dubc1-vip60.adobe.com
      127.0.0.1 activate-sjc0.adobe.com
      127.0.0.1                               adobe.activate.com
      127.0.0.1                               adobeereg.com                        
      127.0.0.1                               www.adobeereg.com                    
      127.0.0.1                               wwis-dubc1-vip60.adobe.com           
      127.0.0.1                               125.252.224.90                       
      127.0.0.1                               125.252.224.91
      127.0.0.1                               hl2rcv.adobe.com
       
       
      ==================== Scheduled Tasks (whitelisted) =============
       
      (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
       
      Task: {03031ED8-7E0F-4C41-8FEC-554C2FD19425} - System32\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5 => C:\Program Files\CinemaP-1.9cV26.01\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5.exe <==== ATTENTION
      Task: {1EF24780-AA4C-406C-9434-D83595D3B92E} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files\PC Speed Up\PCSUSD.exe <==== ATTENTION
      Task: {236BA4C9-A518-456A-803C-B69BECB99717} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-02] (Apple Inc.)
      Task: {2F284918-26F6-4BD4-9113-C76BCF7BBDDA} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2015-01-26] (globalUpdate) <==== ATTENTION
      Task: {456046B3-E148-4709-9AF0-056087F9611E} - System32\Tasks\APSnotifierPP3 => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
      Task: {45F8236B-52BD-4B46-AAF3-3482E0D6AE5C} - System32\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5_user => C:\Program Files\CinemaP-1.9cV26.01\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5.exe <==== ATTENTION
      Task: {4E0E65A6-90A2-4499-BDC2-6C04E733038B} - System32\Tasks\APSnotifierPP2 => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
      Task: {51B0DAE2-5DF8-48AB-8ED2-B979F7270B73} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [2015-01-26] (globalUpdate) <==== ATTENTION
      Task: {743C4B8C-6C85-46FD-989D-DE9AB452001C} - System32\Tasks\APSnotifierPP1 => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
      Task: {755B9112-B2B6-4E4E-83FF-07BFC3725E38} - System32\Tasks\BlockAndSurf Update => C:\Program Files\ver8BlockAndSurf\J6BlockAndSurfR79.exe <==== ATTENTION
      Task: {762E47CC-ECB8-42E1-BD86-CB100B1B9CA7} - System32\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-10_user => C:\Program Files\CinemaP-1.9cV26.01\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-10.exe <==== ATTENTION
      Task: {827123FB-2B18-46BD-8A79-449B0B411CD3} - System32\Tasks\Digital Sites => C:\Users\EDITMA~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
      Task: {A31FFB0F-8D15-444D-B7BA-AB1221089EB5} - System32\Tasks\KVSELX => C:\Users\EDIT MACHINE\AppData\Roaming\KVSELX.exe [2015-01-26] (Cinema PlusV26.01) <==== ATTENTION
      Task: {A61BDC60-017E-4D39-8656-C678C3255D34} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
      Task: {CD1E684D-DE46-4541-AA68-193CE57ED5EC} - System32\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-2 => C:\Program Files\CinemaP-1.9cV26.01\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-2.exe <==== ATTENTION
      Task: {D65B3407-678C-4461-9A4A-2F7A8143560B} - System32\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-1 => C:\Program Files\CinemaP-1.9cV26.01\CinemaP-1.9cV26.01-codedownloader.exe <==== ATTENTION
       
      (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
       
      Task: C:\Windows\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-1.job => C:\Program Files\CinemaP-1.9cV26.01\CinemaP-1.9cV26.01-codedownloader.exe <==== ATTENTION
      Task: C:\Windows\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-10_user.job => C:\Program Files\CinemaP-1.9cV26.01\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-10.exe <==== ATTENTION
      Task: C:\Windows\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-2.job => C:\Program Files\CinemaP-1.9cV26.01\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-2.exe <==== ATTENTION
      Task: C:\Windows\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5.job => C:\Program Files\CinemaP-1.9cV26.01\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5.exe <==== ATTENTION
      Task: C:\Windows\Tasks\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5_user.job => C:\Program Files\CinemaP-1.9cV26.01\8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5.exe <==== ATTENTION
      Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
      Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
      Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files\AnyProtectEx\AnyProtect.exe <==== ATTENTION
      Task: C:\Windows\Tasks\BlockAndSurf Update.job => C:\Program Files\ver8BlockAndSurf\J6BlockAndSurfR79.exe <==== ATTENTION
      Task: C:\Windows\Tasks\Digital Sites.job => C:\Users\EDITMA~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
      Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
      Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
      Task: C:\Windows\Tasks\KVSELX.job => C:\Users\EDIT MACHINE\AppData\Roaming\KVSELX.exe <==== ATTENTION
      Task: C:\Windows\Tasks\PC SpeedUp Service Deactivator.job => C:\Program Files\PC Speed Up\PCSUSD.exe <==== ATTENTION
       
      ==================== Loaded Modules (whitelisted) =============
       
      2015-01-26 16:56 - 2014-12-15 00:27 - 00493584 _____ () C:\Program Files\Settings Manager\smdmf\sysapcrt.dll
      2014-09-29 20:13 - 2014-09-29 20:13 - 00150528 _____ () C:\Program Files\35556262-902E-49AE-8622-66E14F1F041C\arrmeapsie.exe
      2014-09-29 20:13 - 2014-09-29 20:13 - 00102400 _____ () C:\Program Files\35556262-902E-49AE-8622-66E14F1F041C\nfapi.dll
      2014-09-29 20:13 - 2014-09-29 20:13 - 00323584 _____ () C:\Program Files\35556262-902E-49AE-8622-66E14F1F041C\ProtocolFilters.dll
      2010-01-10 03:18 - 2010-01-10 03:18 - 04254560 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
      2010-01-21 08:34 - 2010-01-21 08:34 - 08793952 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
      2014-10-16 09:15 - 2014-10-16 09:15 - 00035328 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
      2014-05-24 16:41 - 2014-05-24 16:41 - 00091648 _____ () C:\Program Files\FileZilla FTP Client\libgcc_s_sjlj-1.dll
      2014-05-24 16:41 - 2014-05-24 16:41 - 00892416 _____ () C:\Program Files\FileZilla FTP Client\libstdc++-6.dll
      2014-11-13 11:46 - 2014-11-13 11:46 - 00186368 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Commonc65c5a95#\6f89b5b53fe8ec7cdda041b8a8fd99f4\Kies.Common.DeviceServiceLib.Interface.ni.dll
      2014-11-13 11:46 - 2014-11-13 11:46 - 14993920 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\04fbc79d0fd8ef7beb4df41de59f7580\Kies.Theme.ni.dll
      2014-11-13 11:45 - 2014-11-13 11:45 - 01865728 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\595f727940c4532edbacd5cb1943335e\Kies.UI.ni.dll
      2014-11-13 11:45 - 2014-11-13 11:45 - 00081920 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\e8b2465977dafc28af412e4ae0caf712\Kies.MVVM.ni.dll
      2014-11-13 11:28 - 2014-11-13 11:28 - 00236032 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\6815ff93472d008087880a6462931188\ASF_cSharpAPI.ni.dll
       
      ==================== Alternate Data Streams (whitelisted) =========
       
      (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
       
       
      ==================== Safe Mode (whitelisted) ===================
       
      (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
       
       
      ==================== EXE Association (whitelisted) =============
       
      (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
       
       
      ==================== MSCONFIG/TASK MANAGER disabled items =========
       
      (Currently there is no automatic fix for this section.)
       
      MSCONFIG\startupreg: SwvUpdtr => C:\Users\EDIT MACHINE\AppData\Local\10609\Updater.exe /reg
       
      ========================= Accounts: ==========================
       
      Administrator (S-1-5-21-851169767-2126091772-1983836877-500 - Administrator - Disabled)
      EDIT MACHINE (S-1-5-21-851169767-2126091772-1983836877-1001 - Administrator - Enabled) => C:\Users\EDIT MACHINE
      Guest (S-1-5-21-851169767-2126091772-1983836877-501 - Limited - Disabled)
      HomeGroupUser$ (S-1-5-21-851169767-2126091772-1983836877-1002 - Limited - Enabled)
       
      ==================== Faulty Device Manager Devices =============
       
      Name: Mass Storage Controller
      Description: Mass Storage Controller
      Class Guid: 
      Manufacturer: 
      Service: 
      Problem: : The drivers for this device are not installed. (Code 28)
      Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
       
      Name: Teredo Tunneling Pseudo-Interface
      Description: Microsoft Teredo Tunneling Adapter
      Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
      Manufacturer: Microsoft
      Service: tunnel
      Problem: : This device cannot start. (Code10)
      Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
      On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
       
       
      ==================== Event log errors: =========================
       
      Application errors:
      ==================
      Error: (01/27/2015 10:31:05 AM) (Source: SideBySide) (EventID: 63) (User: )
      Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.
      The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.
       
      Error: (01/26/2015 08:54:18 PM) (Source: Winlogon) (EventID: 4103) (User: )
      Description: Windows license activation failed. Error 0x00000000.
       
      Error: (01/26/2015 08:54:18 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
      Description: License Activation (slui.exe) failed with the following error code:
      0x8007043C
       
      Error: (01/26/2015 08:35:17 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: iexplore.exe, version: 11.0.9600.17496, time stamp: 0x546fddcc
      Faulting module name: Flash32_16_0_0_296.ocx, version: 16.0.0.296, time stamp: 0x54c2a103
      Exception code: 0xc0000005
      Fault offset: 0x006a6eaa
      Faulting process id: 0x122c
      Faulting application start time: 0xiexplore.exe0
      Faulting application path: iexplore.exe1
      Faulting module path: iexplore.exe2
      Report Id: iexplore.exe3
       
      Error: (01/26/2015 05:42:54 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: iexplore.exe, version: 11.0.9600.17496, time stamp: 0x546fddcc
      Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea91c
      Exception code: 0xc0000374
      Fault offset: 0x000c3873
      Faulting process id: 0x1084
      Faulting application start time: 0xiexplore.exe0
      Faulting application path: iexplore.exe1
      Faulting module path: iexplore.exe2
      Report Id: iexplore.exe3
       
      Error: (01/26/2015 05:39:26 PM) (Source: VSS) (EventID: 8194) (User: )
      Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
      .
      This is often caused by incorrect security settings in either the writer or requestor process.
       
       
      Operation:
         Gathering Writer Data
       
      Context:
         Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
         Writer Name: System Writer
         Writer Instance ID: {ac5dfb8a-2e90-4398-91fb-0ebaae10b204}
       
      Error: (01/26/2015 05:32:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
      Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
       
       
      Details:
      AddWin32ServiceFiles: Unable to back up image of service PC Speed Up Service since QueryServiceConfig API failed
       
      System Error:
      The system cannot find the file specified.
      .
       
      Error: (01/26/2015 05:29:13 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
      Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
       
       
      Details:
      AddWin32ServiceFiles: Unable to back up image of service PC Speed Up Service since QueryServiceConfig API failed
       
      System Error:
      The system cannot find the file specified.
      .
       
      Error: (01/26/2015 05:25:21 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
      Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
       
       
      Details:
      AddWin32ServiceFiles: Unable to back up image of service PC Speed Up Service since QueryServiceConfig API failed
       
      System Error:
      The system cannot find the file specified.
      .
       
      Error: (01/26/2015 05:22:28 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
      Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
       
       
      Details:
      AddWin32ServiceFiles: Unable to back up image of service PC Speed Up Service since QueryServiceConfig API failed
       
      System Error:
      The system cannot find the file specified.
      .
       
       
      System errors:
      =============
      Error: (01/27/2015 10:39:49 AM) (Source: volsnap) (EventID: 36) (User: )
      Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
       
      Error: (01/27/2015 10:00:46 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: The Update Yula service failed to start due to the following error: 
      %%2
       
      Error: (01/26/2015 10:03:36 PM) (Source: DCOM) (EventID: 10016) (User: EDITMACHINE-PC)
      Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}EDITMACHINE-PCEDIT MACHINES-1-5-21-851169767-2126091772-1983836877-1001LocalHost (Using LRPC)
       
      Error: (01/26/2015 10:03:16 PM) (Source: DCOM) (EventID: 10016) (User: EDITMACHINE-PC)
      Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}EDITMACHINE-PCEDIT MACHINES-1-5-21-851169767-2126091772-1983836877-1001LocalHost (Using LRPC)
       
      Error: (01/26/2015 09:44:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: The Update Yula service failed to start due to the following error: 
      %%2
       
      Error: (01/26/2015 09:39:14 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
      Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
      %%1068
       
      Error: (01/26/2015 09:39:14 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
      Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
      %%1068
       
      Error: (01/26/2015 09:39:14 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
      Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
      %%1068
       
      Error: (01/26/2015 09:37:08 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
      Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
      %%1068
       
      Error: (01/26/2015 09:37:08 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
      Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
      %%1068
       
       
      Microsoft Office Sessions:
      =========================
      Error: (01/27/2015 10:31:05 AM) (Source: SideBySide) (EventID: 63) (User: )
      Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3
       
      Error: (01/26/2015 08:54:18 PM) (Source: Winlogon) (EventID: 4103) (User: )
      Description: 0x000000000x00000001
       
      Error: (01/26/2015 08:54:18 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
      Description: 0x8007043C
       
      Error: (01/26/2015 08:35:17 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: iexplore.exe11.0.9600.17496546fddccFlash32_16_0_0_296.ocx16.0.0.29654c2a103c0000005006a6eaa122c01d03991d98e8034C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\Macromed\Flash\Flash32_16_0_0_296.ocxd645e2bb-a59a-11e4-b882-0090f55804ac
       
      Error: (01/26/2015 05:42:54 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: iexplore.exe11.0.9600.17496546fddccntdll.dll6.1.7601.18247521ea91cc0000374000c3873108401d0398f8039534eC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\SYSTEM32\ntdll.dllc11a24ad-a582-11e4-b882-0090f55804ac
       
      Error: (01/26/2015 05:39:26 PM) (Source: VSS) (EventID: 8194) (User: )
      Description: 0x80070005, Access is denied.
       
       
      Operation:
         Gathering Writer Data
       
      Context:
         Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
         Writer Name: System Writer
         Writer Instance ID: {ac5dfb8a-2e90-4398-91fb-0ebaae10b204}
       
      Error: (01/26/2015 05:32:43 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
      Description: 
      Details:
      AddWin32ServiceFiles: Unable to back up image of service PC Speed Up Service since QueryServiceConfig API failed
       
      System Error:
      The system cannot find the file specified.
       
      Error: (01/26/2015 05:29:13 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
      Description: 
      Details:
      AddWin32ServiceFiles: Unable to back up image of service PC Speed Up Service since QueryServiceConfig API failed
       
      System Error:
      The system cannot find the file specified.
       
      Error: (01/26/2015 05:25:21 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
      Description: 
      Details:
      AddWin32ServiceFiles: Unable to back up image of service PC Speed Up Service since QueryServiceConfig API failed
       
      System Error:
      The system cannot find the file specified.
       
      Error: (01/26/2015 05:22:28 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
      Description: 
      Details:
      AddWin32ServiceFiles: Unable to back up image of service PC Speed Up Service since QueryServiceConfig API failed
       
      System Error:
      The system cannot find the file specified.
       
       
      ==================== Memory info =========================== 
       
      Processor: Intel(R) Core(TM)2 CPU T7600 @ 2.33GHz
      Percentage of memory in use: 33%
      Total physical RAM: 3070.12 MB
      Available physical RAM: 2037.64 MB
      Total Pagefile: 6438.52 MB
      Available Pagefile: 5334.16 MB
      Total Virtual: 2047.88 MB
      Available Virtual: 1891.98 MB
       
      ==================== Drives ================================
       
      Drive c: (Programs) (Fixed) (Total:40 GB) (Free:7.85 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
      Drive d: (Video) (Fixed) (Total:146.31 GB) (Free:101.29 GB) NTFS
      Drive f: () (Removable) (Total:15.38 GB) (Free:15.38 GB) FAT32
       
      ==================== MBR & Partition Table ==================
       
      ========================================================
      Disk: 0 (MBR Code: Windows 7 or 8) (Size: 186.3 GB) (Disk ID: EC88EC88)
      Partition 1: (Active) - (Size=40 GB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=146.3 GB) - (Type=07 NTFS)
       
      ========================================================
      Disk: 1 (Size: 15.4 GB) (Disk ID: 6F20736B)
      No partition Table on disk 1.
      Disk 1 is a removable device.
       
      ==================== End Of Log ============================

      Good Morning,

       

      You have quite a bit going on, I am going to have you run 3 tools, run them in order if you can and post the logs. Also if you can copy and paste the logs directly into this thread in lieu of attaching them.

       

      -AdwCleaner-by Xplode
       
      Click on this link to download : ADWCleaner
      Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
       
      Do not click on any links in the top Advertisment.
       
      • Close all open programs and internet browsers.
      • Double click on AdwCleaner.exe to run the tool.
      • Click on Scan.
      • After the scan is complete click on "Clean"
      • Confirm each time with Ok.
      • Your computer will be rebooted automatically. A text file will open after the restart.
      • Please post the content of that logfile with your next reply.
      • You can find the logfile at C:\AdwCleaner[S1].txt as well.
      •  
         
        ===============================================================================
         
         
        [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
        • Shut down your protection software now to avoid potential conflicts.
        • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
        • The tool will open and start scanning your system.
        • Please be patient as this can take a while to complete depending on your system's specifications.
        • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
        • Post the contents of JRT.txt into your next message.
        •  
           
           
          ===============================================================================
           
          Download Malwarebytes' Anti-Malware  to your desktop. 
           
          • Windows XP : Double click on the icon to run it.
          • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
          •  
            [external image: MBAM203_zps0a230260.jpg]
             
            • On the Dashboard click on Update Now
            • Go to the Setting Tab
            • Under Setting go to Detection and Protection
            • Under PUP and PUM make sure both are set to show Treat Detections as Malware
            • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked<————
            • Then on the Dashboard click on Scan
            • Make sure to select THREAT SCAN
            • Then click on Scan
            • When the scan is finished click on VIEW DETAILED LOG
            • When it opens click on COPY TO CLIPBOARD
            • Then paste the log back into this thread for review
            • Exit Malwarebytes
            • hi Ken

               here are the three logs

               

              # AdwCleaner v4.109 - Report created 27/01/2015 at 13:22:12
              # Updated 24/01/2015 by Xplode
              # Database : 2015-01-26.1 [Live]
              # Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
              # Username : EDIT MACHINE - EDITMACHINE-PC
              # Running from : C:\Users\EDIT MACHINE\Desktop\AdwCleaner.exe
              # Option : Clean

              ***** [ Services ] *****

              [#] Service Deleted : F06DEFF2-5B9C-490D-910F-35D3A91196222
              [#] Service Deleted : globalUpdate
              [#] Service Deleted : globalUpdatem
              Service Deleted : netfilter
              [#] Service Deleted : SmdmFService
              Service Deleted : WindowsMangerProtect
              [#] Service Deleted : Update Yula
              Service Deleted : IHProtect Service
              Service Deleted : webinstrNHKT
              Service Deleted : {facdc9f6-60e8-45b2-8807-bf1a7548ccda}Gw
              Service Deleted : {fef7f75c-f985-4250-96f9-8183cd04238b}Gw

              ***** [ Files / Folders ] *****

              Folder Deleted : C:\ProgramData\2308189059
              [!] Folder Deleted : C:\ProgramData\smdmf
              Folder Deleted : C:\ProgramData\WindowsMangerProtect
              Folder Deleted : C:\ProgramData\IHProtectUpDate
              Folder Deleted : C:\ProgramData\deaal2DealiT
              Folder Deleted : C:\ProgramData\FlexIbleShoopper
              Folder Deleted : C:\ProgramData\SmartComPPaore
              Folder Deleted : C:\ProgramData\websaaver
              Folder Deleted : C:\ProgramData\83bd09e23c37f7b9
              Folder Deleted : C:\ProgramData\9492754456844433337UL
              Folder Deleted : C:\Program Files\globalUpdate
              Folder Deleted : C:\Program Files\pc speed up
              Folder Deleted : C:\Program Files\predm
              [!] Folder Deleted : C:\Program Files\Settings Manager
              Folder Deleted : C:\Program Files\CouponArific
              Folder Deleted : C:\Program Files\XTab
              Folder Deleted : C:\Program Files\SmartComPPaore
              Folder Deleted : C:\Program Files\websaaver
              Folder Deleted : C:\Program Files\dealster
              Folder Deleted : C:\Program Files\ver8BlockAndSurf
              Folder Deleted : C:\Users\EDITMA~1\AppData\Local\Temp\SunriseBrowse
              Folder Deleted : C:\Users\EDITMA~1\AppData\Local\Temp\Yula
              Folder Deleted : C:\Users\EDIT MACHINE\AppData\Local\globalUpdate
              Folder Deleted : C:\Users\EDIT MACHINE\AppData\Local\LPT
              Folder Deleted : C:\Users\EDIT MACHINE\AppData\Local\Microsoft\Silverlight\OutOfBrowser\Speedchecker.PCSpeedUp
              Folder Deleted : C:\Users\EDIT MACHINE\AppData\Roaming\AnyProtectEx
              Folder Deleted : C:\Users\EDIT MACHINE\AppData\Roaming\DigitalSites
              Folder Deleted : C:\Users\EDIT MACHINE\AppData\Roaming\Nosibay
              File Deleted : C:\END
              File Deleted : C:\Windows\patsearch.bin
              File Deleted : C:\Windows\system32\drivers\netfilter.sys
              File Deleted : C:\Windows\system32\drivers\Msft_Kernel_webinstrNHKT_01009.Wdf
              File Deleted : C:\Windows\system32\drivers\webinstrNHKT.sys
              File Deleted : C:\Windows\system32\drivers\{facdc9f6-60e8-45b2-8807-bf1a7548ccda}Gw.sys
              File Deleted : C:\Windows\system32\drivers\{fef7f75c-f985-4250-96f9-8183cd04238b}Gw.sys
              File Deleted : C:\Users\EDITMA~1\AppData\Local\Temp\Uninstall.exe
              File Deleted : C:\Users\EDIT MACHINE\AppData\Roaming\Bubble Dock.boostrap.log
              File Deleted : C:\Users\EDIT MACHINE\AppData\Roaming\Bubble Dock.installation.log
              File Deleted : C:\Users\EDIT MACHINE\Desktop\Continue Live Installation.lnk

              ***** [ Scheduled Tasks ] *****

              Task Deleted : APSnotifierPP1
              Task Deleted : APSnotifierPP2
              Task Deleted : APSnotifierPP3
              Task Deleted : BlockAndSurf Update
              Task Deleted : Digital Sites
              Task Deleted : globalUpdateUpdateTaskMachineCore
              Task Deleted : globalUpdateUpdateTaskMachineUA
              Task Deleted : PC SpeedUp Service Deactivator
              Task Deleted : 8b7843a1-4db0-49e4-b671-7378c7b4ddb4-1
              Task Deleted : 8b7843a1-4db0-49e4-b671-7378c7b4ddb4-10_user
              Task Deleted : 8b7843a1-4db0-49e4-b671-7378c7b4ddb4-2
              Task Deleted : 8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5
              Task Deleted : 8b7843a1-4db0-49e4-b671-7378c7b4ddb4-5_user

              ***** [ Shortcuts ] *****

              Shortcut Disinfected : C:\Users\EDIT MACHINE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
              Shortcut Disinfected : C:\Users\EDIT MACHINE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
              Shortcut Disinfected : C:\Users\EDIT MACHINE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
              Shortcut Disinfected : C:\Users\EDIT MACHINE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
              Shortcut Disinfected : C:\Users\EDIT MACHINE\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk

              ***** [ Registry ] *****

              Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
              Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
              Key Deleted : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
              Key Deleted : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
              Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
              Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
              Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
              Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
              Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
              Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
              Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
              Key Deleted : HKLM\SOFTWARE\Classes\SettingsManagerIEHelper.DNSGuard.1
              Key Deleted : HKLM\SOFTWARE\Classes\SettingsManagerIEHelper.DNSGuard
              Key Deleted : HKLM\SOFTWARE\Classes\dieal2dEEaliT.dieal2dEEaliT
              Key Deleted : HKLM\SOFTWARE\Classes\dieal2dEEaliT.dieal2dEEaliT.2.0
              Key Deleted : HKLM\SOFTWARE\Classes\SmaRtCompare.SmaRtCompare
              Key Deleted : HKLM\SOFTWARE\Classes\SmaRtCompare.SmaRtCompare.4.41
              Key Deleted : HKLM\SOFTWARE\Classes\FlexibleShopper.FlexibleShopper
              Key Deleted : HKLM\SOFTWARE\Classes\FlexibleShopper.FlexibleShopper.9
              Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1842850-FB16-4471-B327-7343FBAED55C}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CC49943-A993-21AC-81C3-C94611B6B5A5}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4863BBDB-49A2-5DB4-6B98-D88F38E1900A}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6af73f04-1f23-4641-aeab-baa00082857f}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ea2611e2-2394-4be9-8279-333a63fbef74}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AA760BA8-5862-4BC5-9263-4452CBC0B264}
              Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
              Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
              Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
              Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93D511B5-143B-4A99-ABFC-B5B78AD0AE1B}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CC49943-A993-21AC-81C3-C94611B6B5A5}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4863BBDB-49A2-5DB4-6B98-D88F38E1900A}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6af73f04-1f23-4641-aeab-baa00082857f}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ea2611e2-2394-4be9-8279-333a63fbef74}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CC49943-A993-21AC-81C3-C94611B6B5A5}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4863BBDB-49A2-5DB4-6B98-D88F38E1900A}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6af73f04-1f23-4641-aeab-baa00082857f}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ea2611e2-2394-4be9-8279-333a63fbef74}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3CC49943-A993-21AC-81C3-C94611B6B5A5}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4863BBDB-49A2-5DB4-6B98-D88F38E1900A}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6af73f04-1f23-4641-aeab-baa00082857f}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ea2611e2-2394-4be9-8279-333a63fbef74}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
              Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
              Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
              Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}
              Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}
              Key Deleted : HKCU\Software\AnyProtect
              Key Deleted : HKCU\Software\dsiteproducts
              Key Deleted : HKCU\Software\GlobalUpdate
              Key Deleted : HKCU\Software\InstallCore
              Key Deleted : HKCU\Software\InstalledBrowserExtensions
              Key Deleted : HKCU\Software\Myfree Codec
              Key Deleted : HKCU\Software\Nosibay
              Key Deleted : HKCU\Software\Optimizer Pro
              Key Deleted : HKCU\Software\SmdmF
              Key Deleted : HKCU\Software\Speedchecker Limited
              Key Deleted : HKCU\Software\TutoTag
              Key Deleted : HKCU\Software\StormWatchApp
              Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
              Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
              Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
              Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
              Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
              Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
              Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
              Key Deleted : HKLM\SOFTWARE\GlobalUpdate
              Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
              Key Deleted : HKLM\SOFTWARE\Myfree Codec
              Key Deleted : HKLM\SOFTWARE\SmdmF
              Key Deleted : HKLM\SOFTWARE\Speedchecker Limited
              Key Deleted : HKLM\SOFTWARE\SupDp
              Key Deleted : HKLM\SOFTWARE\SupTab
              Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
              Key Deleted : HKLM\SOFTWARE\Tutorials
              Key Deleted : HKLM\SOFTWARE\webssearchesSoftware
              Key Deleted : HKLM\SOFTWARE\IHProtect
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Settings Manager
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D831E399-50FE-84AE-F5F7-0A63AC282464}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
              Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
              Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] -

              ***** [ Browsers ] *****

              -\\ Internet Explorer v11.0.9600.17496

              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
              Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
              Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
              Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
              Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
              Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]

              *************************

              AdwCleaner[R0].txt - [19578 octets] - [27/01/2015 13:20:33]
              AdwCleaner[S0].txt - [18219 octets] - [27/01/2015 13:22:12]

              ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [18280 octets] ##########

               

               

              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
              Junkware Removal Tool (JRT) by Thisisu
              Version: 6.4.1 (12.28.2014:1)
              OS: Windows 7 Ultimate x86
              Ran by [removed] on 27/01/2015 at 13:28:45.82
              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

               

              ~~~ Services

              Successfully stopped: [Service] netfilter
              Successfully deleted: [Service] netfilter

              ~~~ Registry Values

              ~~~ Registry Keys

              ~~~ Files

              ~~~ Folders

              Successfully deleted: [Folder] "C:\Users\EDIT MACHINE\appdata\locallow\datamngr"
              Failed to delete: [Folder] "C:\Program Files\myfree codec"

               

              ~~~ Event Viewer Logs were cleared

               

              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
              Scan was completed on 27/01/2015 at 13:30:18.64
              End of JRT log
              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

               

              Malwarebytes Anti-Malware
              www.malwarebytes.org

              Scan Date: 27/01/2015
              Scan Time: 13:51:47
              Logfile: mwb.txt
              Administrator: Yes

              Version: 2.00.4.1028
              Malware Database: v2015.01.27.06
              Rootkit Database: v2015.01.14.01
              License: Trial
              Malware Protection: Enabled
              Malicious Website Protection: Enabled
              Self-protection: Disabled

              OS: Windows 7 Service Pack 1
              CPU: x86
              File System: NTFS
              User: EDIT MACHINE

              Scan Type: Threat Scan
              Result: Completed
              Objects Scanned: 308118
              Time Elapsed: 11 min, 7 sec

              Memory: Enabled
              Startup: Enabled
              Filesystem: Enabled
              Archives: Enabled
              Rootkits: Disabled
              Heuristics: Enabled
              PUP: Enabled
              PUM: Enabled

              Processes: 0
              (No malicious items detected)

              Modules: 0
              (No malicious items detected)

              Registry Keys: 10
              PUP.Optional.CouponArific.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CouponArificService, , [8dd52fcdf396ce682eafb9d7c441e51b],
              PUP.Optional.Snapdo.T, HKU\S-1-5-21-851169767-2126091772-1983836877-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, , [baa897653950d95d410bf63bb3500ff1],
              PUP.Optional.SearchProtect.A, HKU\S-1-5-21-851169767-2126091772-1983836877-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, , [2b377a825039ce68a0e74fa52ed4ea16],
              PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, , [2b377a825039ce68a0e74fa52ed4ea16],
              PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\SmdmF, , [b5ad0fed7316a5918dcb4153f50e619f],
              PUP.Optional.Cinema.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\CinemaP-1.9cV26.01, , [b2b00bf19eeb47ef6c40523f53b01de3],
              PUP.Optional.Cinema.A, HKU\S-1-5-21-851169767-2126091772-1983836877-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\CinemaP-1.9cV26.01, , [481aae4efe8bae8826861f7236cdfd03],
              PUP.Optional.Qone8, HKU\S-1-5-21-851169767-2126091772-1983836877-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [c0a28676a6e36cca4b162eb5b252ac54],
              PUP.Optional.Linkury.A, HKU\S-1-5-21-851169767-2126091772-1983836877-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, , [72f0a5574d3c0036baa66430b3500ef2],
              PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [2d35f20a4a3fde5885f8afac47bce21e],

              Registry Values: 4
              PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_gb_101, , [283a76862e5bf93d880cb7ca14ef758b],
              PUP.Optional.SettingsManager, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER\APPCERTDLLS|x64, c:\program files\settings manager\smdmf\x64\sysapcrt.dll, , [65fd19e31970231308cfdeb991729f61]
              PUP.Optional.SettingsManager, HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER\APPCERTDLLS|x86, c:\program files\settings manager\smdmf\sysapcrt.dll, , [b6ac42ba56332b0b31a6fd9a9b6850b0]
              PUP.Optional.Linkury.A, HKU\S-1-5-21-851169767-2126091772-1983836877-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, YahooTR, , [72f0a5574d3c0036baa66430b3500ef2]

              Registry Data: 0
              (No malicious items detected)

              Folders: 4
              PUP.Optional.GlobalUpdate.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\comh.349375, , [2d35f20a4a3fde5885f8afac47bce21e],
              PUP.Optional.CouponArific, C:\Program Files\CouponArific, , [a8ba41bb3f4a56e04306bdb1b84ba65a],
              PUP.Optional.CouponArific, C:\Program Files\CouponArific\SSL, , [a8ba41bb3f4a56e04306bdb1b84ba65a],
              PUP.Optional.CouponArific.A, C:\Program Files\35556262-902E-49AE-8622-66E14F1F041C, , [540edd1f2366ed49e684a9c5c1425ca4],

              Files: 45
              PUP.Optional.CouponArific.A, C:\Program Files\35556262-902E-49AE-8622-66E14F1F041C\arrmeapsie.exe, , [8dd52fcdf396ce682eafb9d7c441e51b],
              PUP.Optional.CrossRider.A, C:\Users\EDIT MACHINE\AppData\Roaming\KVSELX.exe, , [8ed433c997f2a78f5a496e6b60a5e61a],
              PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-851169767-2126091772-1983836877-1001\$RAFG32E.exe, , [68fad824c8c1da5cf5aebb1e08fd718f],
              PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-851169767-2126091772-1983836877-1001\$RDVYZ48.exe, , [f66c9a62f693b68052516a6f020317e9],
              PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-851169767-2126091772-1983836877-1001\$RSAWFSQ.exe, , [540eca32b7d2a59176eebb91ec147d83],
              PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-851169767-2126091772-1983836877-1001\$REQN8BT.exe, , [431f926af3965adc8f14924758ad8080],
              PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-851169767-2126091772-1983836877-1001\$RHLSYGP.exe, , [451d9d5fcfbab383713224b5d13445bb],
              PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-851169767-2126091772-1983836877-1001\$R7I6LMC.exe, , [a5bd5e9e5831d363aef5efea1ce9e719],
              PUP.Optional.SmartBar, C:\$Recycle.Bin\S-1-5-21-851169767-2126091772-1983836877-1001\$R7WDF2G.msi, , [d68c6c901f6a0a2c4f2d17460cf4748c],
              PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-851169767-2126091772-1983836877-1001\$R130EES.dll, , [530fe11b3f4a5dd97e25c811ee170ef2],
              PUP.Optional.Multiplug, C:\$Recycle.Bin\S-1-5-21-851169767-2126091772-1983836877-1001\$RFO1UJW\SMartCommPPArre.exe, , [3e24b64694f5a492c681d5165aa8e917],
              PUP.Optional.FriedCookie, C:\RECYCLER\S-1-5-21-220523388-1592454029-1801674531-1003\Dc670.exe, , [243e29d3444541f5a54e1af330d57a86],
              PUP.Optional.CrossRider.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\4721.exe, , [a6bc97652f5a3df98a19efea9174a060],
              PUP.Optional.Amonetize, C:\Users\EDIT MACHINE\AppData\Local\Temp\amisetup6292__11003.exe, , [c999e11b8cfd9c9a2be2da394cb651af],
              Riskware.Vmdetector, C:\Users\EDIT MACHINE\AppData\Local\Temp\nst4E95.tmp, , [a6bcc13b0c7d989ed8305144749132ce],
              Riskware.Vmdetector, C:\Users\EDIT MACHINE\AppData\Local\Temp\nst80A0.tmp, , [da88cb31cdbc201634d4f69f01047789],
              PUP.Optional.InstallCore, C:\Users\EDIT MACHINE\AppData\Local\Temp\ICReinstall_UltimateCodecsSetup.exe, , [4e14bc407c0d84b2159b6d0cd82d9e62],
              PUP.Optional.BubbleDock.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\23102014100840\Uninstall Bubble Dock.exe, , [fc66a854e9a069cd55c12a35ee137c84],
              PUP.Optional.InstallCore, C:\Users\EDIT MACHINE\AppData\Local\Temp\49781182.Uninstall\uninstaller.exe, , [e87a34c8e4a585b151d324f254ae54ac],
              PUP.Optional.InstallCore, C:\Users\EDIT MACHINE\AppData\Local\Temp\49873348.Uninstall\uninstaller.exe, , [a8ba24d8a2e7f73f9d87b4628f730af6],
              Trojan.Dropper.NS, C:\Users\EDIT MACHINE\AppData\Local\Temp\is765589038\52614A36_stp.EXE, , [e28000fc0b7e85b191b86930dc29be42],
              PUP.Optional.BPlug, C:\Users\EDIT MACHINE\AppData\Local\Temp\is765589038\5EE6D9F8_stp.EXE, , [c59dd02ce0a9fe3803018f4029d8ac54],
              PUP.Optional.InstallCore, C:\Users\EDIT MACHINE\AppData\Local\Temp\is765589038\5D4B7A38_stp\uninstaller.exe, , [de84837996f38caa1b09db3b7a88837d],
              PUP.Optional.Tuto4PC.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\is-HRQVF.tmp\package_hyperbrows_installer_multilang.exe, , [c69c9468b1d88caa3cc16a8ae81936ca],
              PUP.Optional.Tuto4PC.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\is-HRQVF.tmp\package_speedup_installer_multilang.exe, , [8ad8718bbacfaf8721dcd81c3cc5ac54],
              PUP.Optional.Tuto4PC.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\is-HRQVF.tmp\package_vpnprivat_installer_multilang.exe, , [76ec54a8deab989e1de046ae877acb35],
              PUP.Optional.Tuto4PC.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\is-HRQVF.tmp\package_websearches_pariente_installer_multilang.exe, , [d290d12b6c1d06308f6efdf7a35eb34d],
              PUP.Optional.Linkey.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\is45637729\1908367_stp\SettingsManagerSetup.exe, , [d09249b37f0ac076d9cf9714f20f916f],
              PUP.Optional.Linkey.A, C:\Windows\Temp\78790c52\SettingsManagerSetup.exe, , [d19178840f7a4ee8099f7932b849d030],
              PUP.Optional.Amonetize.A, C:\Users\EDIT MACHINE\AppData\Local\10609\Updater.exe, , [a5bd43b91079dd594acc1f44857b7090],
              PUP.Optional.Linkey, C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Browse and Search the Internet.lnk, , [09591be11b6e0234a74fd1c35ea5c739],
              PUP.Optional.GlobalUpdate.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\comh.349375\GoogleCrashHandler.exe, , [2d35f20a4a3fde5885f8afac47bce21e],
              PUP.Optional.GlobalUpdate.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\comh.349375\GoogleUpdate.exe, , [2d35f20a4a3fde5885f8afac47bce21e],
              PUP.Optional.GlobalUpdate.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\comh.349375\GoogleUpdateBroker.exe, , [2d35f20a4a3fde5885f8afac47bce21e],
              PUP.Optional.GlobalUpdate.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\comh.349375\GoogleUpdateHelper.msi, , [2d35f20a4a3fde5885f8afac47bce21e],
              PUP.Optional.GlobalUpdate.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\comh.349375\GoogleUpdateOnDemand.exe, , [2d35f20a4a3fde5885f8afac47bce21e],
              PUP.Optional.GlobalUpdate.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\comh.349375\goopdate.dll, , [2d35f20a4a3fde5885f8afac47bce21e],
              PUP.Optional.GlobalUpdate.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\comh.349375\goopdateres_en.dll, , [2d35f20a4a3fde5885f8afac47bce21e],
              PUP.Optional.GlobalUpdate.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\comh.349375\npGoogleUpdate4.dll, , [2d35f20a4a3fde5885f8afac47bce21e],
              PUP.Optional.GlobalUpdate.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\comh.349375\psmachine.dll, , [2d35f20a4a3fde5885f8afac47bce21e],
              PUP.Optional.GlobalUpdate.A, C:\Users\EDIT MACHINE\AppData\Local\Temp\comh.349375\psuser.dll, , [2d35f20a4a3fde5885f8afac47bce21e],
              PUP.Optional.CouponArific.A, C:\Program Files\35556262-902E-49AE-8622-66E14F1F041C\libeay32.dll, , [540edd1f2366ed49e684a9c5c1425ca4],
              PUP.Optional.CouponArific.A, C:\Program Files\35556262-902E-49AE-8622-66E14F1F041C\nfapi.dll, , [540edd1f2366ed49e684a9c5c1425ca4],
              PUP.Optional.CouponArific.A, C:\Program Files\35556262-902E-49AE-8622-66E14F1F041C\ProtocolFilters.dll, , [540edd1f2366ed49e684a9c5c1425ca4],
              PUP.Optional.CouponArific.A, C:\Program Files\35556262-902E-49AE-8622-66E14F1F041C\ssleay32.dll, , [540edd1f2366ed49e684a9c5c1425ca4],

              Physical Sectors: 0
              (No malicious items detected)

              (end)

               

              thanks phil c

              Good job Phil.  Did you have Malwarebytes remove all those entries because on the log it should say that they where quarantined, if not run Malwarebytes again and have it remove them all, and post the new log

               

              Then run a new scan with FRST, be sure to checkmark Additions and post both new logs please

              hi Ken,

                the rescan on mwb came up with no threats detected, here you go

               

              Malwarebytes Anti-Malware
              www.malwarebytes.org

              Scan Date: 27/01/2015
              Scan Time: 16:23:10
              Logfile: mwb.txt
              Administrator: Yes

              Version: 2.00.4.1028
              Malware Database: v2015.01.27.07
              Rootkit Database: v2015.01.14.01
              License: Trial
              Malware Protection: Enabled
              Malicious Website Protection: Enabled
              Self-protection: Disabled

              OS: Windows 7 Service Pack 1
              CPU: x86
              File System: NTFS
              User: EDIT MACHINE

              Scan Type: Threat Scan
              Result: Completed
              Objects Scanned: 307774
              Time Elapsed: 11 min, 40 sec

              Memory: Enabled
              Startup: Enabled
              Filesystem: Enabled
              Archives: Enabled
              Rootkits: Disabled
              Heuristics: Enabled
              PUP: Enabled
              PUM: Enabled

              Processes: 0
              (No malicious items detected)

              Modules: 0
              (No malicious items detected)

              Registry Keys: 0
              (No malicious items detected)

              Registry Values: 0
              (No malicious items detected)

              Registry Data: 0
              (No malicious items detected)

              Folders: 0
              (No malicious items detected)

              Files: 0
              (No malicious items detected)

              Physical Sectors: 0
              (No malicious items detected)

              (end)

               

               

              Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-01-2015 01
              Ran by [removed] (administrator) on EDITMACHINE-PC on 27-01-2015 16:38:09
              Running from C:\Users\[removed]\Desktop
              [removed] Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: English (United States)
              Internet Explorer Version 11 (Default browser: IE)
              Boot Mode: Normal
              Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

              ==================== Processes (Whitelisted) =================

              (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

              (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
              (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
              (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
              (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
              (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
              (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
              (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
              (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
              (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
              (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
              (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
              (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
              (Samsung) C:\Program Files\Samsung\Kies\Kies.exe
              (Grass Valley K.K.) C:\Program Files\Grass Valley\GV LicenseManager\AppMaintainer.exe
              (Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
              (Flexera Software LLC.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer.exe
              (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\tv_w32.exe
              (Nero AG) C:\Program Files\Nero\Update\NASvc.exe
              (Microsoft Corporation) C:\Windows\System32\wuauclt.exe

              ==================== Registry (Whitelisted) ==================

              (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

              HKLM\…\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
              HKLM\…\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
              HKLM\…\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-22] (Microsoft Corporation)
              HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
              HKLM\…\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
              HKLM\…\Run: [] => [X]
              HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
              HKLM\…\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.)
              HKU\S-1-5-21-851169767-2126091772-1983836877-1001\…\Run: [HP Deskjet 3050A J611 series (NET)] => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe [1804648 2011-06-08] (Hewlett-Packard Co.)
              HKU\S-1-5-21-851169767-2126091772-1983836877-1001\…\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1562264 2014-07-25] (Samsung)
              HKU\S-1-5-21-851169767-2126091772-1983836877-1001\…\MountPoints2: {45fb4f69-f9a0-11e3-8653-806e6f6e6963} - E:\Setup.exe
              Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
              ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
              Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GV LicenseManager.lnk
              ShortcutTarget: GV LicenseManager.lnk -> C:\Program Files\Grass Valley\GV LicenseManager\AppMaintainer.exe (Grass Valley K.K.)
              CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

              ==================== Internet (Whitelisted) ====================

              (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

              HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
              HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
              HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
              HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
              HKU\S-1-5-21-851169767-2126091772-1983836877-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/en-gb/?ocid=U220DHP&pc;=U220
              HKU\S-1-5-21-851169767-2126091772-1983836877-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
              HKU\S-1-5-21-851169767-2126091772-1983836877-1001\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1me10IE11ENGB/MCM_WCP
              StartMenuInternet: IEXPLORE.EXE - iexplore.exe
              SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
              SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
              SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
              BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
              BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
              DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [152864] (Apple Inc.)
              Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
              Tcpip\Parameters: [DhcpNameServer] [removed] [removed]

              FireFox:
              ========
              FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
              FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
              FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
              FF Plugin: @videolan.org/vlc,version=2.0.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
              FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
              FF HKU\S-1-5-21-851169767-2126091772-1983836877-1001\…\Firefox\Extensions: [{9DBD7E94-0916-D9AC-EFF0-25CB7DE4421A}] - C:\Program Files\ver8BlockAndSurf\186.xpi

              Chrome:
              =======
              CHR dev: Chrome dev build detected! <======= ATTENTION

              ========================== Services (Whitelisted) =================

              (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

              R3 FlexNet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1045840 2014-06-22] (Flexera Software LLC.)
              R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
              R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
              R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
              R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [503080 2010-05-04] (Nero AG)
              S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
              S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

              ==================== Drivers (Whitelisted) ====================

              (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

              R1 cdrblock; C:\Windows\System32\DRIVERS\cdrblock.sys [31304 2014-01-27] (Grass Valley K.K.)
              R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
              R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-01-27] (Malwarebytes Corporation)
              R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
              R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
              R0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [45968 2012-09-01] (Rovi Corporation)
              S3 SxSmemcd; C:\Windows\System32\DRIVERS\SxSmemcd.sys [45056 2010-02-09] (Sony Corporation)
              R2 SXSUDFMF; C:\Windows\System32\DRIVERS\SXSUDFMF.sys [4352 2012-06-18] (Sony Corporation)
              R4 SXSUDFS; C:\Windows\System32\DRIVERS\SXSUDFS.sys [809472 2012-06-18] (Sony Corporation)
              S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
              S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
              S3 VGPU; System32\drivers\rdvgkmd.sys [X]
              U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-13] (Microsoft Corporation)

              ==================== NetSvcs (Whitelisted) ===================

              (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

              ==================== One Month Created Files and Folders ========

              (If an entry is included in the fixlist, the file\folder will be moved.)

              2015-01-27 13:48 - 2015-01-27 16:22 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
              2015-01-27 13:48 - 2015-01-27 13:48 - 00001068 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
              2015-01-27 13:48 - 2015-01-27 13:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
              2015-01-27 13:48 - 2015-01-27 13:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
              2015-01-27 13:48 - 2015-01-27 13:48 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
              2015-01-27 13:48 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
              2015-01-27 13:48 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
              2015-01-27 13:48 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
              2015-01-27 13:30 - 2015-01-27 13:30 - 00000862 _____ () C:\Users\EDIT MACHINE\Desktop\JRT.txt
              2015-01-27 13:28 - 2015-01-27 13:28 - 00000000 ____D () C:\Windows\ERUNT
              2015-01-27 13:20 - 2015-01-27 13:22 - 00000000 ____D () C:\AdwCleaner
              2015-01-27 13:19 - 2015-01-27 13:16 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\EDIT MACHINE\Desktop\mbam-setup-2.0.4.1028.exe
              2015-01-27 13:19 - 2015-01-27 13:15 - 01707939 _____ (Thisisu) C:\Users\EDIT MACHINE\Desktop\JRT.exe
              2015-01-27 13:19 - 2015-01-27 13:14 - 02194432 _____ () C:\Users\EDIT MACHINE\Desktop\AdwCleaner.exe
              2015-01-27 11:09 - 2015-01-27 11:10 - 00031701 _____ () C:\Users\EDIT MACHINE\Desktop\Addition.txt
              2015-01-27 11:08 - 2015-01-27 16:38 - 00009806 _____ () C:\Users\EDIT MACHINE\Desktop\FRST.txt
              2015-01-27 11:07 - 2015-01-27 16:38 - 00000000 ____D () C:\FRST
              2015-01-27 11:00 - 2015-01-27 09:48 - 05198336 _____ (AVAST Software) C:\Users\EDIT MACHINE\Desktop\aswMBR.exe
              2015-01-27 11:00 - 2015-01-27 09:48 - 01120768 _____ (Farbar) C:\Users\EDIT MACHINE\Desktop\FRST.exe
              2015-01-26 20:15 - 2015-01-26 20:16 - 29720784 _____ (Microsoft Corporation) C:\Users\EDIT MACHINE\Downloads\IE11-Windows6.1-x86-en-us.exe
              2015-01-26 20:10 - 2015-01-26 20:10 - 00000000 ___HD () C:\Windows\msdownld.tmp
              2015-01-26 17:33 - 2015-01-27 14:07 - 00000000 ____D () C:\Users\EDIT MACHINE\AppData\Local\10609
              2015-01-26 16:26 - 2015-01-27 16:26 - 00001366 _____ () C:\Windows\Tasks\KVSELX.job
              2015-01-26 13:49 - 2014-12-12 05:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
              2015-01-26 13:49 - 2014-12-12 05:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
              2015-01-26 13:49 - 2014-11-11 02:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
              2015-01-26 13:48 - 2014-12-11 17:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
              2015-01-26 13:48 - 2014-11-27 01:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
              2015-01-26 13:48 - 2014-11-22 02:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
              2015-01-26 13:48 - 2014-11-22 02:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
              2015-01-26 13:48 - 2014-11-22 02:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
              2015-01-26 13:48 - 2014-11-22 02:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
              2015-01-26 13:48 - 2014-11-22 02:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
              2015-01-26 13:48 - 2014-11-22 02:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
              2015-01-26 13:48 - 2014-11-22 02:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
              2015-01-26 13:48 - 2014-11-22 02:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
              2015-01-26 13:48 - 2014-11-22 01:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
              2015-01-26 13:48 - 2014-11-22 01:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
              2015-01-26 13:48 - 2014-11-22 01:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
              2015-01-26 13:48 - 2014-11-22 01:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
              2015-01-26 13:48 - 2014-11-22 01:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
              2015-01-26 13:48 - 2014-11-22 01:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
              2015-01-26 13:48 - 2014-11-22 01:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
              2015-01-26 13:48 - 2014-11-22 01:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
              2015-01-26 13:48 - 2014-11-22 01:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
              2015-01-26 13:48 - 2014-11-22 01:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
              2015-01-26 13:48 - 2014-11-22 01:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
              2015-01-26 13:48 - 2014-11-22 01:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
              2015-01-26 13:48 - 2014-11-22 01:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
              2015-01-26 13:48 - 2014-11-22 01:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
              2015-01-26 13:48 - 2014-11-22 01:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
              2015-01-26 13:48 - 2014-11-22 01:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
              2015-01-26 13:48 - 2014-11-22 01:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
              2015-01-26 13:48 - 2014-11-22 01:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
              2015-01-26 13:48 - 2014-11-22 01:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
              2015-01-26 13:48 - 2014-11-22 00:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
              2015-01-26 13:48 - 2014-11-22 00:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
              2015-01-26 13:47 - 2014-12-19 02:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
              2015-01-26 13:47 - 2014-12-06 03:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
              2015-01-26 13:46 - 2014-12-19 01:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
              2015-01-26 13:41 - 2014-11-11 02:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
              2015-01-26 13:41 - 2014-11-11 02:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
              2015-01-25 16:12 - 2015-01-25 16:12 - 00001248 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\KVSELX

              ==================== One Month Modified Files and Folders =======

              (If an entry is included in the fixlist, the file\folder will be moved.)

              2015-01-27 16:37 - 2014-06-22 01:03 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI
              2015-01-27 16:24 - 2014-06-22 00:04 - 01616156 _____ () C:\Windows\WindowsUpdate.log
              2015-01-27 16:21 - 2009-07-14 04:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
              2015-01-27 16:21 - 2009-07-14 04:39 - 00025513 _____ () C:\Windows\setupact.log
              2015-01-27 16:20 - 2014-06-22 09:19 - 00056452 _____ () C:\Windows\PFRO.log
              2015-01-27 16:08 - 2009-07-14 04:34 - 00009904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
              2015-01-27 16:08 - 2009-07-14 04:34 - 00009904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
              2015-01-27 14:08 - 2009-07-14 02:37 - 00000000 ____D () C:\Windows\LiveKernelReports
              2015-01-27 13:22 - 2014-06-22 06:18 - 00001066 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
              2015-01-27 13:22 - 2014-06-22 00:58 - 00001164 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
              2015-01-27 10:37 - 2009-07-14 02:37 - 00000000 ____D () C:\Windows\rescache
              2015-01-26 21:36 - 2014-06-22 13:16 - 00003298 _____ () C:\Windows\FORGXP32.INI
              2015-01-26 21:36 - 2014-06-22 13:16 - 00000000 ____D () C:\Program Files\Sound Forge XP
              2015-01-26 20:10 - 2014-06-22 05:34 - 00018260 _____ () C:\Windows\IE11_main.log
              2015-01-26 16:56 - 2014-06-22 11:07 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
              2015-01-26 16:56 - 2014-06-22 11:07 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
              2015-01-26 16:46 - 2014-06-22 10:06 - 00000000 ____D () C:\ProgramData\Microsoft Help
              2015-01-26 16:46 - 2014-06-22 05:44 - 00000000 ____D () C:\Windows\system32\MRT
              2015-01-26 13:34 - 2014-06-22 14:49 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
              2014-12-31 13:15 - 2014-06-22 05:44 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
              2014-12-31 11:13 - 2014-06-22 01:16 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

              ==================== Files in the root of some directories =======

              2015-01-25 16:12 - 2015-01-25 16:12 - 0001248 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\KVSELX
              2014-10-22 20:36 - 2014-10-22 20:36 - 0000045 _____ () C:\Users\EDIT MACHINE\AppData\Roaming\WB.CFG
              2014-10-22 21:06 - 2014-10-22 21:06 - 0627648 _____ (CMI Limited) C:\Users\EDIT MACHINE\AppData\Local\nsgBE14.tmp
              2014-10-22 19:55 - 2014-10-22 19:54 - 0612212 _____ (CMI Limited) C:\Users\EDIT MACHINE\AppData\Local\nsuCF42.tmp
              2014-06-26 11:32 - 2014-06-26 11:32 - 0000057 _____ () C:\ProgramData\Ament.ini

              Some content of TEMP:
              ====================
              C:\Users\EDIT MACHINE\AppData\Local\Temp\0D3FA6CD-D378-31D0-2ED5-DE2CEF4D3C3F.exe
              C:\Users\EDIT MACHINE\AppData\Local\Temp\8988D349-9EF9-B3CD-1347-E5BEBBFD4598.dll
              C:\Users\EDIT MACHINE\AppData\Local\Temp\8988D349-9EF9-B3CD-1347-E5BEBBFD4598.exe
              C:\Users\EDIT MACHINE\AppData\Local\Temp\optprosetup.exe
              C:\Users\EDIT MACHINE\AppData\Local\Temp\Quarantine.exe
              C:\Users\EDIT MACHINE\AppData\Local\Temp\sqlite3.dll
              C:\Users\EDIT MACHINE\AppData\Local\Temp\System.Data.SQLite.dll
              C:\Users\EDIT MACHINE\AppData\Local\Temp\System.Data.SQLite58686.dll
              C:\Users\EDIT MACHINE\AppData\Local\Temp\System.Data.SQLite62256.dll
              C:\Users\EDIT MACHINE\AppData\Local\Temp\System.Data.SQLite80616.dll
              C:\Users\EDIT MACHINE\AppData\Local\Temp\System.Data.SQLite82851.dll
              C:\Users\EDIT MACHINE\AppData\Local\Temp\vcredist_x64.exe
              C:\Users\EDIT MACHINE\AppData\Local\Temp\vcredist_x86.exe

              ==================== Bamital & volsnap Check =================

              (There is no automatic fix for files that do not pass verification.)

              C:\Windows\explorer.exe => File is digitally signed
              C:\Windows\system32\winlogon.exe => File is digitally signed
              C:\Windows\system32\wininit.exe => File is digitally signed
              C:\Windows\system32\svchost.exe => File is digitally signed
              C:\Windows\system32\services.exe => File is digitally signed
              C:\Windows\system32\User32.dll => File is digitally signed
              C:\Windows\system32\userinit.exe => File is digitally signed
              C:\Windows\system32\rpcss.dll => File is digitally signed
              C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

              LastRegBack: 2015-01-26 16:19

              ==================== End Of Log ============================

               

               

              Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-01-2015 01
              Ran by [removed] at 2015-01-27 16:38:39
              Running from C:\Users\[removed]\Desktop
              Boot Mode: Normal
              ==========================================================

              ==================== Security Center ========================

              (If an entry is included in the fixlist, it will be removed.)

              AV: Microsoft Security Essentials (Disabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
              AS: Microsoft Security Essentials (Disabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
              AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

              ==================== Installed Programs ======================

              (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

              Adobe After Effects CS4 (HKLM\…\Adobe_3dcb365ab9e01871fb8c6f27b0ea079) (Version: 9 - Adobe Systems Incorporated)
              Adobe AIR (HKLM\…\Adobe AIR) (Version: 1.1.0.5790 - Adobe Systems Inc.)
              Adobe Flash Player 16 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
              Adobe Media Player (HKLM\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
              Adobe Photoshop 7.0 (HKLM\…\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.)
              Adobe Reader XI (11.0.10) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
              Apple Application Support (HKLM\…\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
              Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
              Bonjour (HKLM\…\{0CB9668D-F979-4F31-B8B8-67FE90F929F8}) (Version: 2.0.2.0 - Apple Inc.)
              ContentBrowser (HKLM\…\{36651F49-C025-4927-9006-7935F11E1449}) (Version: 1.1.0.372 - Sony Corporation)
              EDIUS (HKLM\…\{E778FC49-5FE7-486E-AB18-0F418BE97189}) (Version: 6.55 - Grass Valley K.K.)
              EDIUS Codec Option 6.55 (HKLM\…\{E7EE42CB-C5A2-46C5-93AC-EA285F86C022}) (Version: 6.55 - Grass Valley K.K.)
              EDIUS DVD Menu Style 1.00 (HKLM\…\{E4F24AE3-CA17-423A-8CF9-43EBE3C9012B}) (Version: 1.00 - Grass Valley K.K.)
              FileZilla Client 3.9.0.6 (HKLM\…\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse)
              GV LicenseManager 1.05 (HKLM\…\{EE256B6B-7F66-409B-9CF2-CE9B64947CBC}) (Version: 1.05 - Grass Valley K.K.)
              H.264 Encoder (HKLM\…\{B99459D2-B91A-417E-9DFA-F53D569F4445}_is1) (Version:  - www.H264Encoder.com)
              HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\…\CNXT_MODEM_HDA_HSF) (Version: 7.80.4.50 - Conexant Systems)
              High-Definition Video Playback (Version: 7.1.13900.47.0 - Nero AG) Hidden
              HP Deskjet 3050A J611 series Basic Device Software (HKLM\…\{AE47EB5B-1789-4480-AD6D-7753473E9DDE}) (Version: 25.0.571.0 - Hewlett-Packard Co.)
              HP Deskjet 3050A J611 series Help (HKLM\…\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
              HP Update (HKLM\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
              HPDiagnosticAlert (Version: 1.00.0001 - Microsoft) Hidden
              Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
              Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
              Microsoft Office Professional Plus 2010 (HKLM\…\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation)
              Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
              Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
              Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
              Microsoft Visual C++ 2005 Redistributable (HKLM\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\…\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
              Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
              MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
              MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
              MyFreeCodec (HKU\S-1-5-21-851169767-2126091772-1983836877-1001\…\MyFreeCodec) (Version:  - )
              Nero 10 Movie ThemePack 1 (HKLM\…\{43FBAB46-5969-4200-9958-1FF81FEE506F}) (Version: 10.2.10000.11.0 - Nero AG)
              Nero BurnRights 10 (HKLM\…\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.2.10500.1.102 - Nero AG)
              Nero CoverDesigner 10 (HKLM\…\{FCF00A6E-FB58-477A-ABE9-232907105521}) (Version: 5.2.11400.11.100 - Nero AG)
              Nero DiscCopy Gadget 10 (HKLM\…\{92EC1A84-7FFC-42DF-A8F6-79C21C4765A5}) (Version: 3.2.10700.9.100 - Nero AG)
              Nero DiscSpeed 10 (HKLM\…\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG)
              Nero Express 10 (HKLM\…\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.11900.20.100 - Nero AG)
              Nero InfoTool 10 (HKLM\…\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.2.10400.5.100 - Nero AG)
              Nero MediaHub 10 (HKLM\…\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}) (Version: 1.2.13200.33.100 - Nero AG)
              Nero Multimedia Suite 10 Essentials (HKLM\…\{ADEF1F0B-635E-4041-B50F-A510C1B4D2C5}) (Version: 10.5.10400 - Nero AG)
              Nero RescueAgent 10 (HKLM\…\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.2.10800.9.100 - Nero AG)
              Nero StartSmart 10 (HKLM\…\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
              Nero Update (HKLM\…\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
              Photoshop Camera Raw (Version: 5.0 - Adobe Systems Incorporated) Hidden
              Pixel Bender Toolkit (Version: 1.0 - Adobe Systems Incorporated) Hidden
              QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
              Revo Uninstaller 1.95 (HKLM\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
              Riva FLV Player (HKLM\…\Riva FLV Player_is1) (Version: 1.0.0000 - Rothenberger & Partner)
              Samsung Kies (HKLM\…\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.)
              Samsung Kies (Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.) Hidden
              SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
              Sony SxS UDF driver (HKLM\…\{D4499B3C-3036-4667-8827-DEB4DA53ECD6}) (Version: 2.0.1.1 - Sony Corporation)
              Sound Forge XP 4.0 for Windows 95 and NT (x86) (HKLM\…\Sound Forge XP) (Version:  - )
              Suite Shared Configuration CS4 (Version: 1.0 - Adobe Systems Incorporated) Hidden
              SxS device driver (HKLM\…\{D2D8328B-F031-4F69-8621-250701844E9A}) (Version: 1.01.00000 - Sony Corporation)
              TeamViewer 9 (HKLM\…\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
              TeraCentral (HKLM\…\{3A971636-157A-4503-AA59-D445AD833D83}) (Version: 0.9.1 - Teradek)
              VLC media player 2.0.0 (HKLM\…\VLC media player) (Version: 2.0.0 - VideoLAN)
              WinRAR 5.01 (32-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
              WinZip 12.1 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}) (Version: 12.1.8497 - WinZip Computing, S.L. )

              ==================== Custom CLSID (selected items): ==========================

              (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{00b7e0ab-817a-44ad-a04b-d1148d524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{117270FA-48AC-45BB-9171-B63D1B42A910}\localserver32 -> "C:\Users\EDIT MACHINE\AppData\Local\10609\Updater.exe" No File
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{7c6e29bc-8b8b-4c3d-859e-af6cd158be0f}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c0-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c1-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c2-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c3-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c4-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c5-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c8-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969c9-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969ca-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
              CustomCLSID: HKU\S-1-5-21-851169767-2126091772-1983836877-1001_Classes\CLSID\{88d969d6-f192-11d4-a65f-0040963251e5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)

              ==================== Restore Points  =========================

              ==================== Hosts content: ==========================

              (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

              2009-07-14 02:04 - 2014-06-22 15:48 - 00001796 ____A C:\Windows\system32\Drivers\etc\hosts
              127.0.0.1    activate.adobe.com
              127.0.0.1    practivate.adobe.com
              127.0.0.1    ereg.adobe.com
              127.0.0.1    activate.wip3.adobe.com
              127.0.0.1    wip3.adobe.com
              127.0.0.1    3dns-3.adobe.com
              127.0.0.1    3dns-2.adobe.com
              127.0.0.1    adobe-dns.adobe.com
              127.0.0.1    adobe-dns-2.adobe.com
              127.0.0.1    adobe-dns-3.adobe.com
              127.0.0.1    ereg.wip3.adobe.com
              127.0.0.1    activate-sea.adobe.com
              127.0.0.1    wwis-dubc1-vip60.adobe.com
              127.0.0.1    activate-sjc0.adobe.com
              127.0.0.1                               adobe.activate.com
              127.0.0.1                               adobeereg.com                       
              127.0.0.1                               www.adobeereg.com                   
              127.0.0.1                               wwis-dubc1-vip60.adobe.com          
              127.0.0.1                               125.252.224.90                      
              127.0.0.1                               125.252.224.91
              127.0.0.1                               hl2rcv.adobe.com

              ==================== Scheduled Tasks (whitelisted) =============

              (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

              Task: {236BA4C9-A518-456A-803C-B69BECB99717} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-02] (Apple Inc.)
              Task: {A31FFB0F-8D15-444D-B7BA-AB1221089EB5} - System32\Tasks\KVSELX => C:\Users\EDIT MACHINE\AppData\Roaming\KVSELX.exe <==== ATTENTION
              Task: {A61BDC60-017E-4D39-8656-C678C3255D34} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc

              (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

              Task: C:\Windows\Tasks\KVSELX.job => C:\Users\EDIT MACHINE\AppData\Roaming\KVSELX.exe <==== ATTENTION

              ==================== Loaded Modules (whitelisted) =============

              2010-01-10 03:18 - 2010-01-10 03:18 - 04254560 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
              2010-01-21 08:34 - 2010-01-21 08:34 - 08793952 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
              2011-06-08 21:57 - 2011-06-08 21:57 - 01929576 _____ () C:\Windows\system32\HPScanTRDrv_DJ3050A_J611.dll
              2014-10-16 09:15 - 2014-10-16 09:15 - 00035328 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
              2014-05-24 16:41 - 2014-05-24 16:41 - 00091648 _____ () C:\Program Files\FileZilla FTP Client\libgcc_s_sjlj-1.dll
              2014-05-24 16:41 - 2014-05-24 16:41 - 00892416 _____ () C:\Program Files\FileZilla FTP Client\libstdc++-6.dll
              2014-11-13 11:46 - 2014-11-13 11:46 - 00186368 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Commonc65c5a95#\6f89b5b53fe8ec7cdda041b8a8fd99f4\Kies.Common.DeviceServiceLib.Interface.ni.dll
              2014-11-13 11:46 - 2014-11-13 11:46 - 14993920 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\04fbc79d0fd8ef7beb4df41de59f7580\Kies.Theme.ni.dll
              2014-11-13 11:45 - 2014-11-13 11:45 - 01865728 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\595f727940c4532edbacd5cb1943335e\Kies.UI.ni.dll
              2014-11-13 11:45 - 2014-11-13 11:45 - 00081920 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\e8b2465977dafc28af412e4ae0caf712\Kies.MVVM.ni.dll
              2014-11-13 11:28 - 2014-11-13 11:28 - 00236032 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\6815ff93472d008087880a6462931188\ASF_cSharpAPI.ni.dll

              ==================== Alternate Data Streams (whitelisted) =========

              (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

              ==================== Safe Mode (whitelisted) ===================

              (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

              ==================== EXE Association (whitelisted) =============

              (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

              ==================== MSCONFIG/TASK MANAGER disabled items =========

              (Currently there is no automatic fix for this section.)

              MSCONFIG\startupreg: SwvUpdtr => C:\Users\EDIT MACHINE\AppData\Local\10609\Updater.exe /reg

              ========================= Accounts: ==========================

              Administrator (S-1-5-21-851169767-2126091772-1983836877-500 - Administrator - Disabled)
              EDIT MACHINE (S-1-5-21-851169767-2126091772-1983836877-1001 - Administrator - Enabled) => C:\Users\EDIT MACHINE
              Guest (S-1-5-21-851169767-2126091772-1983836877-501 - Limited - Disabled)
              HomeGroupUser$ (S-1-5-21-851169767-2126091772-1983836877-1002 - Limited - Enabled)

              ==================== Faulty Device Manager Devices =============

              Name: Mass Storage Controller
              Description: Mass Storage Controller
              Class Guid:
              Manufacturer:
              Service:
              Problem: : The drivers for this device are not installed. (Code 28)
              Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

              Name: Teredo Tunneling Pseudo-Interface
              Description: Microsoft Teredo Tunneling Adapter
              Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
              Manufacturer: Microsoft
              Service: tunnel
              Problem: : This device cannot start. (Code10)
              Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
              On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

              ==================== Event log errors: =========================

              Application errors:
              ==================

              System errors:
              =============
              Error: (01/27/2015 04:21:07 PM) (Source: EventLog) (EventID: 6008) (User: )
              Description: The previous system shutdown at 16:18:05 on ‎27/‎01/‎2015 was unexpected.

              Error: (01/27/2015 03:27:45 PM) (Source: volsnap) (EventID: 36) (User: )
              Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.

              Error: (01/27/2015 02:12:11 PM) (Source: Disk) (EventID: 11) (User: )
              Description: The driver detected a controller error on \Device\Harddisk1\DR1.

              Error: (01/27/2015 02:12:11 PM) (Source: Disk) (EventID: 11) (User: )
              Description: The driver detected a controller error on \Device\Harddisk1\DR1.

              Error: (01/27/2015 02:12:10 PM) (Source: Disk) (EventID: 11) (User: )
              Description: The driver detected a controller error on \Device\Harddisk1\DR1.

              Error: (01/27/2015 02:12:10 PM) (Source: Disk) (EventID: 11) (User: )
              Description: The driver detected a controller error on \Device\Harddisk1\DR1.

              Microsoft Office Sessions:
              =========================

              ==================== Memory info ===========================

              Processor: Intel(R) Core(TM)2 CPU T7600 @ 2.33GHz
              Percentage of memory in use: 32%
              Total physical RAM: 3070.12 MB
              Available physical RAM: 2085.32 MB
              Total Pagefile: 6438.52 MB
              Available Pagefile: 5342.85 MB
              Total Virtual: 2047.88 MB
              Available Virtual: 1912.86 MB

              ==================== Drives ================================

              Drive c: (Programs) (Fixed) (Total:40 GB) (Free:7.79 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
              Drive d: (Video) (Fixed) (Total:146.31 GB) (Free:101.29 GB) NTFS
              Drive f: () (Removable) (Total:15.38 GB) (Free:15.38 GB) FAT32

              ==================== MBR & Partition Table ==================

              ========================================================
              Disk: 0 (MBR Code: Windows 7 or 8) (Size: 186.3 GB) (Disk ID: EC88EC88)
              Partition 1: (Active) - (Size=40 GB) - (Type=07 NTFS)
              Partition 2: (Not Active) - (Size=146.3 GB) - (Type=07 NTFS)

              ========================================================
              Disk: 1 (Size: 15.4 GB) (Disk ID: 6F20736B)
              No partition Table on disk 1.
              Disk 1 is a removable device.

              ==================== End Of Log ============================

               

              thanks phil c

              While I am looking over your logs run this quick scanner please

               

               

               
              Download CKScanner by askey127 from Here & save it to your Desktop.
              •  
              • Doubleclick CKScanner.exe then click Search For Files
              • When the cursor hourglass disappears, click Save List To File
              • A message box will verify the file saved
              • Please Run this program only once
              • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
               
              here you go Ken

              CKScanner 2.4 - Additional Security Risks - These are not necessarily bad
              hosts 127.0.0.1 activate.adobe.com
              hosts 127.0.0.1 practivate.adobe.com
              hosts 127.0.0.1 ereg.adobe.com
              hosts 127.0.0.1 activate.wip3.adobe.com
              hosts 127.0.0.1 wip3.adobe.com
              hosts 127.0.0.1 3dns-3.adobe.com
              hosts 127.0.0.1 3dns-2.adobe.com
              hosts 127.0.0.1 adobe-dns.adobe.com
              hosts 127.0.0.1 adobe-dns-2.adobe.com
              hosts 127.0.0.1 adobe-dns-3.adobe.com
              hosts 127.0.0.1 ereg.wip3.adobe.com
              hosts 127.0.0.1 activate-sea.adobe.com
              hosts 127.0.0.1 wwis-dubc1-vip60.adobe.com
              hosts 127.0.0.1 activate-sjc0.adobe.com
              hosts 127.0.0.1 adobe.activate.com
              hosts 127.0.0.1 adobeereg.com
              hosts 127.0.0.1 www.adobeereg.com
              hosts 127.0.0.1 wwis-dubc1-vip60.adobe.com
              hosts 127.0.0.1 hl2rcv.adobe.com
              scanner sequence 3.HK.11.TSNAIZ
              —– EOF —–
              thanks phil c

              Thanks Phil,

               

              I am going to attach a Fixlist file, its important that you download it to your desktop where you are running FRST from or the fix wont work, actually use your mouse and drag it either above or below FRST but not right on top of it, once its downloaded open FRST and click FIX (NOT SCAN) After your system reboots you will find a FIXLOG on your desktop, post it please.

               

              Also, the first tool you ran was aswMBR and it picked up an infected file, run it again, let it update if it asks you and post the new log, to avoid confusion if the original log is still on your desktop go ahead and drag it to the trash 

              Attachments:

              hi Ken ,
              here is what you've asked for

              Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 24-01-2015 01
              Ran by [removed] at 2015-01-27 19:35:00 Run:1
              Running from C:\Users\[removed]\Desktop
              [removed]

              Good, the infected file that aswMBR picked up on the first run is now gone, looked for it in some of the logs but didn't see it.

               

              Everything looks good, how is your system behaving now ??

              Hi Ken,
              tried it out last night and all seems back to how it was I know have explorer back with my regular homepage not taking me off some where else and my machine feels quite fast again on net, looks like you've sorted it ?? what do you think is it ok now? regards phil c

              Phil,

               

              Thats good to hear, we like to do a free online virus scanner just to make sure nothing else is present that the other scanners missed, i have seen this run in about an hour or so on some systems and for a few hours on others so do it when you have time, post the results when done

               

              First lets get rid of AdwCleaner because it will scan that also and may slow it down looking for things in quarantine

               

              Double click on AdwCleaner.exe to run the tool again.
              • Click on the Uninstall button.
              • Click Yes when asked are you sure you want to uninstall.
              • Both AdwCleaner.exe, its folder and all logs will be removed.
              •  
                 
                 
                 
                 
                 
                ESET Online Scanner
                I'd like us to scan your machine with ESET OnlineScan
                 
                *Note
                It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
                Please don't go surfing while your resident protection is disabled!
                Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
                 
                1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
                2. ESET OnlineScan
                3. Click the [external image: esetOnline.png] button.
                4. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
                  1. Click on [external image: esetSmartInstall.png] to download the ESET Smart Installer. Save it to your desktop.
                  2. Double click on the [external image: esetSmartInstallDesktopIcon.png] icon on your desktop.
                  3. Check [external image: esetAcceptTerms.png]
                  4. Click the [external image: esetStart.png] button.
                  5. Accept any security warnings from your browser.
                  6. Check [external image: esetScanArchives.png]
                  7. Make sure that the option "Remove found threats" is Unchecked
                  8. Push the Start button.
                  9. ESET will then download updates for itself, install itself, and begin
                  10. scanning your computer. Please be patient as this can take some time.
                  11. When the scan completes, push [external image: esetListThreats.png]
                  12. Push [external image: esetExport.png], and save the file to your desktop using a unique name, such as
                  13. ESETScan. Include the contents of this report in your next reply.
                  14. Push the [external image: esetBack.png] button.
                  15. Push [external image: esetFinish.png]
                  16. Please make sure you include the following items in your next post:
                    The log that was produced after running ESET Online Scanner.

                    Hi Ken

                                 Tried to do the online scan as soon as mwb flagged up Trojan alert , I have now lost my internet explorer again to something called omega plus, funnily enough looks almost identical to webssearches!!!!!   

                     it wont let me run eset online scanner.

                      regards phil c

                    Ask AI

                    AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

                    Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI