This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected again! [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Malware again…..this time along with the endless popups….it is cahnging the homepage and changing the proxy setting for the browser….also had to start in safe mode and do a system restore… any help would be appreciated!!

 

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-02-01 18:30:49
—————————–
18:30:49.112    OS Version: Windows x64 6.2.9200 
18:30:49.112    Number of processors: 2 586 0x200
18:30:49.112    ComputerName: OURPC  UserName: jimmy
18:30:58.440    Initialize success
18:30:58.486    VM: initialized successfully
18:30:58.486    VM: Amd CPU supported virtualized 
18:31:02.432    AVAST engine defs: 15012701
18:31:25.777    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000026
18:31:25.793    Disk 0 Vendor: WDC_WD5000AAKX-22ERMA0 17.01H17 Size: 476940MB BusType: 11
18:31:26.107    Disk 0 MBR read successfully
18:31:26.122    Disk 0 MBR scan
18:31:26.138    Disk 0 unknown MBR code
18:31:26.138    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
18:31:26.232    Disk 0 scanning C:\WINDOWS\system32\drivers
18:31:50.503    Service scanning
18:32:22.689    Modules scanning
18:32:22.699    Disk 0 trace - called modules:
18:32:22.715    
18:32:33.584    AVAST engine scan C:\WINDOWS
18:32:46.877    AVAST engine scan C:\WINDOWS\system32
18:39:05.291    AVAST engine scan C:\WINDOWS\system32\drivers
18:39:52.935    AVAST engine scan C:\Users\jimmy
18:40:54.494    Disk 0 MBR has been saved successfully to "C:\Users\jimmy\Desktop\MBR.dat"
18:40:54.525    The log file has been saved successfully to "C:\Users\jimmy\Desktop\aswMBR.txt"
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015
Ran by [removed] at 2015-02-01 18:44:28
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Ableton Live 9 Trial (HKLM-x32\…\{A29BB48D-59ED-411C-AB20-3FA488D08161}) (Version: 9.0.0.0 - Ableton)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 15.0.0.356 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
AMD Catalyst Install Manager (HKLM\…\{19CB64EB-ACFE-681D-B571-A8A3398F1943}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\…\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audacity 2.0.3 (HKLM-x32\…\Audacity_is1) (Version: 2.0.3 - Audacity Team)
avast! Free Antivirus (HKLM-x32\…\Avast) (Version: 9.0.2021 - AVAST Software)
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Blender (HKLM\…\Blender) (Version: 2.72b - Blender Foundation)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Canon Easy-WebPrint EX (HKLM-x32\…\Easy-WebPrint EX) (Version: 1.4.1.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\…\Canon_IJ_Scan_Utility) (Version:  - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\…\CANONIJPLM100) (Version: 4.0.0 - Canon Inc.)
Canon MG2500 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2500_series) (Version: 1.00 - Canon Inc.)
Canon MG2500 series On-screen Manual (HKLM-x32\…\Canon MG2500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
Canon MG2500 series User Registration (HKLM-x32\…\Canon MG2500 series User Registration) (Version:  - ‭Canon Inc.)
Canon My Image Garden (HKLM-x32\…\Canon My Image Garden) (Version: 2.0.1 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\…\Canon My Image Garden Design Files) (Version: 2.0.0 - Canon Inc.)
Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\…\CanonQuickMenu) (Version: 2.2.1 - Canon Inc.)
Catalyst Control Center (HKLM-x32\…\WUCCCApp) (Version: 1.00.0000 - AMD)
Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
Cricut (TM) Driver v2.01 (HKLM-x32\…\Cricut (TM) Driver v2.01) (Version: 2.01 - Provo Craft & Novelty, Inc.)
Cricut Craft Room® (HKLM-x32\…\com.cricut.Cricut-CraftRoom) (Version: v1.0 build-187 - Provo Craft & Novelty, Inc.)
Cricut Craft Room® (x32 Version: 1.0.187 - Provo Craft & Novelty, Inc.) Hidden
CyberLink MediaEspresso 6.5 (HKLM-x32\…\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.3103_44819 - CyberLink Corp.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4220.52 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DC Universe Online (HKU\S-1-5-21-1271087293-465154865-2948633367-1002\…\SOE-DC Universe Online) (Version: 1.0.3.183 - Sony Online Entertainment)
DC Universe Online Live (HKU\S-1-5-21-1271087293-465154865-2948633367-1002\…\SOE-DC Universe Online Live) (Version:  - Sony Online Entertainment)
Delicious: Emily's True Love Premium Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
eBay Worldwide (HKLM-x32\…\{A694AF57-9891-4D62-824C-7E55A1361A14}) (Version: 2.3.0630 - OEM)
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
FPS Creator Free (HKLM-x32\…\{800218C2-2E07-461C-85D6-8FDB4F9161D9}) (Version:  - )
Free YouTube Downloader 3.5.181 (HKLM-x32\…\{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1) (Version:  - HOW Inc.)
Game Channels (x32 Version: 7.1.0.17 - WildTangent, Inc.) Hidden
GameMaker: Player (HKLM-x32\…\GameMakerPlayer) (Version: 1.4.242.35310 - YoYo Games Ltd.)
GameMaker-Studio 1.4 (HKU\S-1-5-21-1271087293-465154865-2948633367-1002\…\GameMaker-Studio14) (Version:  - YoYo Games Ltd.)
Gateway Power Management (HKLM\…\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.3006 - Gateway Incorporated)
Gateway Recovery Management (HKLM\…\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.3011 - Gateway Incorporated)
GeniusBox 2.0 (HKLM-x32\…\GeniusBox) (Version: 2.0 - GeniusBox 2.0)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 40.0.2214.93 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Horizon v2.7.9.0 (HKLM-x32\…\d4cfeebc-b821-40b7-9f81-d366b1466f03_is1) (Version: 2.7.9.0 - Daring Development Inc.)
Hotkey Utility (HKLM-x32\…\{A6DC88AD-501A-44BC-884D-57435F972E2C}) (Version: 3.00.3001 - Gateway Incorporated)
Hunting Unlimited 2010 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Hunting Unlimited 2011 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Identity Card (HKLM-x32\…\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.3004 - Gateway Incorporated)
iTunes (HKLM\…\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}) (Version: 11.1.3.8 - Apple Inc.)
Java 7 Update 60 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F03217060FF}) (Version: 7.0.600 - Oracle)
Java 8 Update 25 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Live Updater (HKLM-x32\…\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.3003 - Gateway Incorporated)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\…\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Minecraft Packages (HKU\S-1-5-21-1271087293-465154865-2948633367-1002\…\Minecraft Packages) (Version:  - ) <==== ATTENTION
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 34.0.5 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 34.0.5 (x86 en-US)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
MuseScore 1.3 (HKLM-x32\…\MuseScore) (Version: 1.3.0 - Werner Schweer and Others)
Mystery P.I. - Curious Case of Counterfeit Cove (x32 Version: 2.2.0.98 - WildTangent) Hidden
Nero 12 Essentials OEM.a01 (HKLM-x32\…\{9BF0D9FE-9893-4647-81B9-17B7BEA4E6FD}) (Version: 12.5.00000 - Nero AG)
Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\…\{B2B0EC73-AD4A-4716-A3DE-CEA8440B309B}) (Version: 12.5.00000 - Nero AG)
Norton Online Backup (HKLM-x32\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.2.3.45 - Symantec Corporation)
Norton Online Backup ARA (x32 Version: 4.1.0.10 - Symantec Corporation) Hidden
NVIDIA PhysX (HKLM-x32\…\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
PCBooster (HKLM-x32\…\{AF0EAAE6-B2E2-48E7-8A74-0A0F909CE382}) (Version: 1.0.0 - Portable Booster) <==== ATTENTION
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
Perfect Uninstaller v6.3.3.9 (HKLM\…\Perfect Uninstaller_is1) (Version:  - www.PerfectUninstaller.com)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.98 - WildTangent) Hidden
Prerequisite installer (x32 Version: 12.0.0002 - Nero AG) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6680 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.2.8400.30137 - Realtek Semiconductor Corp.)
Sculptris Alpha 6 (HKLM-x32\…\InstallShield_{D2883AB6-09B4-4981-AAF8-E695411EEC9A}) (Version: 0.6 - Pixologic)
Sculptris Alpha 6 (x32 Version: 0.6 - Pixologic) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SMART Common Files (HKLM-x32\…\{ED2455F7-6AA6-4D3C-85E9-A72297DD7051}) (Version: 11.1.34.1 - SMART Technologies ULC)
SMART Ink (HKLM-x32\…\{4A1F2472-6164-43FA-9D2F-B35E71A8DF32}) (Version: 1.1.233.0 - SMART Technologies ULC)
SMART Notebook (HKLM-x32\…\{AFE024C7-7CA7-4C8E-90EE-D877C7CD96A3}) (Version: 11.0.705.1 - SMART Technologies ULC)
SMART Product Drivers (HKLM-x32\…\{E3189F44-F7BD-4F96-B756-A0AEFAF61D3A}) (Version: 11.0.510.2 - SMART Technologies ULC)
SMART Response Software (HKLM-x32\…\{02885557-ACA5-4B6F-85D2-3F1A9B8580F5}) (Version: 4.0.450.1 - SMART Technologies ULC)
SMART Sync Teacher (HKLM-x32\…\{9D81615E-B150-488B-90CA-1159E2113BE3}) (Version: 10.0.576.0 - SMART Technologies ULC)
Spotify (HKLM-x32\…\Spotify) (Version: 0.8.4.99.ga249b5f1 - Spotify AB)
Star Wars: The Old Republic (HKLM-x32\…\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Tales of Lagoona (x32 Version: 2.2.0.110 - WildTangent) Hidden
Unity Web Player (HKU\S-1-5-21-1271087293-465154865-2948633367-1002\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
UpdateAdmin (HKLM-x32\…\{07B4B423-E4DA-47D1-8327-B589EB4BEB58}) (Version: 2.0.1885 - DownloadAdmin)
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.11.9 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Wondershare Video Editor(Build 4.5.0) (HKLM-x32\…\Wondershare Video Editor_is1) (Version:  - Wondershare Software)
Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-1271087293-465154865-2948633367-1002_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\jimmy\AppData\Local\Roblox\Versions\version-c2a7e6748ad54a86\RobloxProxy64.dll No File
 
==================== Restore Points  =========================
 
15-01-2015 05:31:17 Windows Update
22-01-2015 06:32:00 Scheduled Checkpoint
27-01-2015 19:24:42 Removed UpdateAdmin
01-02-2015 18:23:46 avast! antivirus system restore point
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 08:25 - 2015-01-04 15:24 - 00000035 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {066D7012-D626-4B3A-88A4-2EFF2BE832ED} - System32\Tasks\{1B5A351E-6456-4DCD-9137-9C2476C8113D} => pcalua.exe -a "C:\Users\jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2C8RVGXX\cda-to-mp3-converter.exe" -d C:\Users\jimmy\Desktop
Task: {1EB54D96-8023-4FEE-A90A-EBF7A4AE10BF} - System32\Tasks\GeniusBox => cmd.exe /C start "" "C:\Users\jimmy\AppData\Local\browser extensions\client.exe"
Task: {360A0CDF-FE35-4A24-8D14-560A1196F977} - System32\Tasks\GoogleUpdateTaskMachineUA1cf6a24736f14b2 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-15] (Google Inc.)
Task: {369D7B29-33DB-4B77-992B-E2333FC1F33F} - System32\Tasks\Check Updates => C:\Users\jimmy\AppData\Local\browser extensions\updater.exe [2015-01-22] ()
Task: {408DBE6A-D817-4107-8EAD-08D1427CBDDB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-24] (Adobe Systems Incorporated)
Task: {55FB2DED-03A4-4D80-9060-C7F5BB981BEE} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {58E7D624-6ACB-492B-8D91-09ABC2E80715} - System32\Tasks\UpdateAdmin => C:\Users\jimmy\AppData\Local\UpdateAdmin\UpdateAdmin.exe [2014-10-16] (DownloadAdmin)
Task: {691C5007-EADB-411E-A1C3-D155647E5129} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2012-07-04] (CyberLink)
Task: {69A79124-8170-4D64-B9F3-3F8F85126E0A} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Gateway\Live Updater\liveupdater_agent.exe [2012-06-21] ()
Task: {6C486CAD-5C9D-410A-80E5-5BA22409EA21} - System32\Tasks\{AB7133B4-07D0-495A-A9A6-C71305016BB2} => pcalua.exe -a C:\Users\jimmy\Downloads\kremove.exe -d C:\Users\jimmy\Downloads
Task: {8816E06C-14A4-4232-B8F7-9DAAB8A52487} - System32\Tasks\Validate Installation => C:\Users\jimmy\AppData\Local\browser extensions\updater.exe [2015-01-22] ()
Task: {8BBB856F-24E0-41A8-8297-EEB1825C9FC1} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Gateway\Gateway Recovery Management\Notification\Notification.exe [2012-07-31] (Acer Incorporated)
Task: {8EA43C2D-1C36-4648-8A81-D6A27EB6A0F0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-15] (Google Inc.)
Task: {90FA3452-9D0D-4E28-AB4F-438CDD128B8D} - System32\Tasks\Hotkey Utility => C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe [2012-07-05] (Acer Incorporated)
Task: {95AC0CC9-89E3-4DB0-B575-F824B6AFC767} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-08-04] (AVAST Software)
Task: {A0772BF0-15D3-43E1-833D-676DD0FA37AD} - System32\Tasks\Power Management => C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe [2012-08-22] (Acer Incorporated)
Task: {AA4C659F-5A11-4E0A-A27A-0A7D56D5491E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {BE2827F4-3520-468C-A8D8-7AEAA7BA5985} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {C75750FE-9491-4958-B769-0FE29B4F5BED} - System32\Tasks\{89CD0DFD-7378-404D-BAED-78521FB39DF9} => pcalua.exe -a "C:\Users\Public\Sony Online Entertainment\Installed Games\DC Universe Online\Uninstaller.exe"
Task: {D4591815-48B9-44D3-AEE1-077BF572887B} - System32\Tasks\avastBCLRestartS-1-5-21-1271087293-465154865-2948633367-1002 => Chrome.exe 
Task: {D61D7859-723F-44DC-AC2C-7413E2995BD0} - System32\Tasks\ALU => C:\Program Files (x86)\Gateway\Live Updater\updater.exe [2012-08-24] ()
Task: {D8FF2921-9A51-42DB-BA52-C2C4DDAA65E4} - System32\Tasks\{590EA461-2B48-470E-A64E-A8F7E95B5972} => pcalua.exe -a C:\Users\jimmy\AppData\Roaming\IMVUClient\Uninstall.exe
Task: {DB6A93D2-DFDF-4495-9AD7-4B6DFFA91BB1} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-01-15] (Microsoft Corporation)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cf6a24736f14b2.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2014-06-27 16:50 - 2012-03-27 22:49 - 00140456 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2015-01-21 09:24 - 2015-01-22 17:00 - 01932000 _____ () C:\Users\jimmy\AppData\Local\browser extensions\Client.exe
2014-07-04 20:33 - 2014-07-04 20:33 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2014-08-04 17:03 - 2014-08-04 17:03 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2015-01-27 18:43 - 2015-01-27 18:43 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15012701\algo.dll
2015-02-01 18:33 - 2015-02-01 18:33 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15020101\algo.dll
2013-01-28 13:08 - 2013-01-28 13:08 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2013-01-28 13:08 - 2013-01-28 13:08 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-10-19 21:32 - 2014-10-19 21:32 - 00022440 _____ () C:\WINDOWS\WinSxS\x86_smarttech.boost_system.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_3b5a2197c9e04a1f\boost_system-vc100-mt-1_44.dll
2014-10-19 21:32 - 2014-10-19 21:32 - 00054184 _____ () C:\WINDOWS\WinSxS\x86_smarttech.boost_thread.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_472b4edec4bf8550\boost_thread-vc100-mt-1_44.dll
2014-10-19 21:32 - 2014-10-19 21:32 - 00053680 _____ () C:\WINDOWS\WinSxS\x86_smarttech.boost_signals.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_8ce60f5e6bc42419\boost_signals-vc100-mt-1_44.dll
2014-10-19 21:32 - 2014-10-19 21:32 - 02296736 _____ () C:\WINDOWS\WinSxS\x86_smarttech.qt.vc100.4.7_9ca15c999435ee05_1.0.1.0_none_421d23a1fa0a055d\QtCore4.dll
2014-10-19 21:30 - 2014-10-19 21:30 - 02364840 _____ () C:\WINDOWS\WinSxS\x86_smarttech.xqilla.vc100.1.1_9ca15c999435ee05_1.0.1.0_none_1bed397492abdaf4\xqilla-vc100-1_0.dll
2014-10-19 21:30 - 2014-10-19 21:30 - 00066976 _____ () C:\WINDOWS\WinSxS\x86_smarttech.zlib.vc100.1.2_9ca15c999435ee05_1.0.1.0_none_a9eddec61c291613\zlib1-vc100-mt-1.2.dll
2014-10-19 21:32 - 2014-10-19 21:32 - 02310056 _____ () C:\WINDOWS\WinSxS\x86_smarttech.redland.vc100.1.0_9ca15c999435ee05_1.0.1.0_none_abdcef110f80cf28\redland-vc100-1_0_9.dll
2014-10-19 21:32 - 2014-10-19 21:32 - 00145328 _____ () C:\WINDOWS\WinSxS\x86_smarttech.boost_filesystem.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_73736a4543634e09\boost_filesystem-vc100-mt-1_44.dll
2014-10-19 21:31 - 2014-10-19 21:31 - 00051120 _____ () C:\WINDOWS\WinSxS\x86_smarttech.boost_date_time.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_50d6b3902c95d15a\boost_date_time-vc100-mt-1_44.dll
2012-10-17 07:40 - 2012-10-17 07:40 - 00454656 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\SBSDK.node
2012-10-17 07:40 - 2012-10-17 07:40 - 00030208 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\HWR.node
2014-10-19 21:32 - 2014-10-19 21:32 - 07546272 _____ () C:\WINDOWS\WinSxS\x86_smarttech.qt.vc100.4.5_9ca15c999435ee05_1.0.1.0_none_4232c379f9f9cd7b\QtGui4.dll
2014-10-19 21:32 - 2014-10-19 21:32 - 02027424 _____ () C:\WINDOWS\WinSxS\x86_smarttech.qt.vc100.4.5_9ca15c999435ee05_1.0.1.0_none_4232c379f9f9cd7b\QtCore4.dll
2014-10-19 21:32 - 2014-10-19 21:32 - 00524712 _____ () C:\WINDOWS\WinSxS\x86_smarttech.boost_regex.vc100.1.44_9ca15c999435ee05_1.0.1.0_none_cae4ebd2526cf46f\boost_regex-vc100-mt-1_44.dll
2012-10-24 13:11 - 2012-10-24 13:11 - 01435544 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\activation2.dll
2014-10-19 21:30 - 2014-10-19 21:30 - 02996648 _____ () C:\WINDOWS\WinSxS\x86_smarttech.xqilla.vc100.2.1_9ca15c999435ee05_1.0.1.0_none_1bed22ac92abf495\xqilla21.dll
2011-06-22 07:19 - 2011-06-22 07:19 - 00070656 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\libLogger-vc100-2_0.dll
2014-08-04 17:03 - 2014-08-04 17:03 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-08-26 20:30 - 2014-07-09 11:01 - 01459712 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2014-08-26 20:30 - 2014-05-19 16:19 - 00137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2014-10-19 21:32 - 2014-10-19 21:32 - 01030048 _____ () C:\WINDOWS\WinSxS\x86_smarttech.js.vc70.1.8_37a8c5fef6a21868_1.0.2.1_none_e909cd048128eadf\js32.dll
2012-10-24 13:11 - 2012-10-24 13:11 - 00466840 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\ziparchive-vc100-3_1_1a.dll
2015-01-26 23:14 - 2015-01-25 01:08 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\libglesv2.dll
2015-01-26 23:14 - 2015-01-25 01:08 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\libegl.dll
2015-01-26 23:14 - 2015-01-25 01:08 - 09170760 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\pdf.dll
2015-01-26 23:14 - 2015-01-25 01:08 - 14913864 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.93\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
 
========================= Accounts: ==========================
 
Administrator (S-1-5-21-1271087293-465154865-2948633367-500 - Administrator - Disabled) => C:\Users\Administrator
Guest (S-1-5-21-1271087293-465154865-2948633367-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1271087293-465154865-2948633367-1004 - Limited - Enabled)
jimmy (S-1-5-21-1271087293-465154865-2948633367-1002 - Administrator - Enabled) => C:\Users\jimmy
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT AUTHORITY)
Description: Event filter with query "select * from __InstanceModificationEvent where targetinstance isa '__ArbitratorConfiguration'" could not be reactivated in namespace "//./root" because of error 0x80041033. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __TimerEvent" whose target class "__TimerEvent" in //./root namespace does not exist. The query will be ignored.
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __SystemEvent" whose target class "__SystemEvent" in //./root namespace does not exist. The query will be ignored.
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __NamespaceOperationEvent" whose target class "__NamespaceOperationEvent" in //./root namespace does not exist. The query will be ignored.
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __ClassOperationEvent" whose target class "__ClassOperationEvent" in //./root namespace does not exist. The query will be ignored.
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __TimerEvent" whose target class "__TimerEvent" in //./root/subscription namespace does not exist. The query will be ignored.
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __TimerEvent" whose target class "__TimerEvent" in //./root/CIMV2 namespace does not exist. The query will be ignored.
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __SystemEvent" whose target class "__SystemEvent" in //./root/subscription namespace does not exist. The query will be ignored.
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __SystemEvent" whose target class "__SystemEvent" in //./root/CIMV2 namespace does not exist. The query will be ignored.
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider $Core attempted to register query "select * from __NamespaceOperationEvent" whose target class "__NamespaceOperationEvent" in //./root/subscription namespace does not exist. The query will be ignored.
 
 
System errors:
=============
Error: (02/01/2015 05:58:38 PM) (Source: DCOM) (EventID: 10005) (User: ourpc)
Description: 1084WSearchUnavailable{9E175B68-F52A-11D8-B9A5-505054503030}
 
Error: (02/01/2015 05:58:38 PM) (Source: DCOM) (EventID: 10005) (User: ourpc)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (02/01/2015 05:58:32 PM) (Source: DCOM) (EventID: 10005) (User: ourpc)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (02/01/2015 05:58:26 PM) (Source: DCOM) (EventID: 10005) (User: ourpc)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (02/01/2015 05:58:16 PM) (Source: DCOM) (EventID: 10005) (User: ourpc)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (02/01/2015 05:58:09 PM) (Source: DCOM) (EventID: 10005) (User: ourpc)
Description: 1084ShellHWDetectionUnavailable{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (02/01/2015 05:55:48 PM) (Source: DCOM) (EventID: 10005) (User: ourpc)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (02/01/2015 05:55:48 PM) (Source: DCOM) (EventID: 10005) (User: ourpc)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (02/01/2015 05:55:48 PM) (Source: DCOM) (EventID: 10005) (User: ourpc)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (02/01/2015 05:55:48 PM) (Source: DCOM) (EventID: 10005) (User: ourpc)
Description: 1084WSearchUnavailable{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
 
Microsoft Office Sessions:
=========================
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT AUTHORITY)
Description: //./rootselect * from __InstanceModificationEvent where targetinstance isa '__ArbitratorConfiguration'0x80041033
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __TimerEvent__TimerEvent//./root
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __SystemEvent__SystemEvent//./root
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __NamespaceOperationEvent__NamespaceOperationEvent//./root
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __ClassOperationEvent__ClassOperationEvent//./root
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __TimerEvent__TimerEvent//./root/subscription
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __TimerEvent__TimerEvent//./root/CIMV2
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __SystemEvent__SystemEvent//./root/subscription
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __SystemEvent__SystemEvent//./root/CIMV2
 
Error: (02/01/2015 06:04:21 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __NamespaceOperationEvent__NamespaceOperationEvent//./root/subscription
 
 
==================== Memory info =========================== 
 
Processor: AMD E1-1200 APU with Radeon™ HD Graphics
Percentage of memory in use: 46%
Total physical RAM: 3810.07 MB
Available physical RAM: 2047.23 MB
Total Pagefile: 4770.07 MB
Available Pagefile: 2322.89 MB
Total Virtual: 131072 MB
Available Virtual: 131071.84 MB
 
==================== Drives ================================
 
Drive c: (Gateway) (Fixed) (Total:446.51 GB) (Free:295.36 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 70D4E092)
 
Partition: GPT Partition Type.
 
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by [removed] (administrator) on OURPC on 01-02-2015 18:41:39
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Torch)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(SMART Technologies ULC) C:\Program Files (x86)\SMART Technologies\Education Software\ResponseHardwareService.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe
(Acer Incorporated) C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
() C:\Users\jimmy\AppData\Local\browser extensions\Client.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Spotify Ltd) C:\Users\jimmy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardService.exe
(Joyent, Inc) C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\SBWDKService.exe
(SMART Technologies ULC) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardTools.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInk.exe
(SMART Technologies ULC) C:\Program Files (x86)\SMART Technologies\Education Software\DesktopMenu.exe
(SMART Technologies ULC.) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTClassroomCoordinator.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Flexera Software, Inc.) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\Office\SMARTInk-SBSDKProxy.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(SMART Technologies ULC) C:\Program Files (x86)\SMART Technologies\Education Software\ResponseSoftwareService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInkPrivilegedAccess.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SrTasks.exe
(AVAST Software) C:\Users\jimmy\Downloads\aswMBR (4).exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12921488 2012-07-02] (Realtek Semiconductor)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2995904 2012-07-11] (Symantec Corporation)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\…\Run: [sbsdk-server] => C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\NodeLauncher.exe [62360 2012-10-24] (SMART Technologies)
HKLM-x32\…\Run: [SMART Board Service] => C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardService.exe [2219416 2012-10-24] (SMART Technologies)
HKLM-x32\…\Run: [SMART Board Tools] => C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardTools.exe [10132336 2012-03-09] (SMART Technologies ULC)
HKLM-x32\…\Run: [SMART Ink] => C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInk.exe [98200 2012-10-25] (SMART Technologies)
HKLM-x32\…\Run: [Response Desktop Menu] => C:\Program Files (x86)\SMART Technologies\Education Software\DesktopMenu.exe [1990040 2012-10-17] (SMART Technologies ULC)
HKLM-x32\…\Run: [SMARTClassroomCoordinator.exe] => C:\Program Files (x86)\SMART Technologies\Education Software\SMARTClassroomCoordinator.exe [485232 2011-06-22] (SMART Technologies ULC.)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-04] (AVAST Software)
HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1282120 2013-05-02] (CANON INC.)
HKLM-x32\…\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020704 2014-07-09] (Wondershare)
HKLM\…\Policies\Explorer: [NoFolderOptions] 0
HKLM\…\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\…\Run: [Spotify Web Helper] => C:\Users\jimmy\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-12] (Spotify Ltd)
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\…\Run: [UpdateAdmin] => C:\Users\jimmy\AppData\Local\UpdateAdmin\UpdateAdmin.exe [225552 2014-10-16] (DownloadAdmin)
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\…\MountPoints2: {70a1e263-92fe-11e4-bf94-eca86baeef58} - "D:\setup.exe" -a
Startup: C:\Users\jimmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyEnable: [S-1-5-21-1271087293-465154865-2948633367-1002] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-1271087293-465154865-2948633367-1002] => http=127.0.0.1:49697;https=127.0.0.1:49697
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\Software\Microsoft\Internet Explorer\Main,DisableRequiresActiveXPrompt = web.roblox.com
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll (CANON INC.)
BHO: SMART Notebook Download Utility -> {67BCF957-85FC-4036-8DC4-D4D80E00A77B} -> C:\Program Files (x86)\SMART Technologies\Education Software\Win64\NotebookPlugin.dll (SMART Technologies ULC.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: SMART Notebook Download Utility -> {67BCF957-85FC-4036-8DC4-D4D80E00A77B} -> C:\Program Files (x86)\SMART Technologies\Education Software\Win32\NotebookPlugin.dll (SMART Technologies ULC.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - SMART Sync - {8E1233B3-485A-4E51-B77E-9E075A68C588} - C:\Program Files (x86)\SMART Technologies\Education Software\SyncIEToolbar.dll (SMART Technologies ULC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKU\S-1-5-21-1271087293-465154865-2948633367-1002 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll (CANON INC.)
DPF: HKLM-x32 {784797A8-342D-4072-9486-03C8D0F2F0A1} http://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.203.0.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF ProfilePath: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\l8b5k1dm.default
FF SearchEngineOrder.1: Secure Search
FF SelectedSearchEngine: Taplika
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\7\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1271087293-465154865-2948633367-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\jimmy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF user.js: detected! => C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\l8b5k1dm.default\user.js
FF SearchPlugin: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\l8b5k1dm.default\searchplugins\Vosteran.xml
FF Extension: Solution Real 1.0.1 - C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\l8b5k1dm.default\Extensions\{5c281c6e-0132-4ac6-ad9d-d1d95d218412}.xpi [2015-01-24]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-12-30]
StartMenuInternet: FIREFOX.EXE - firefox.exe
 
Chrome: 
=======
CHR HomePage: Default -> https://www.google.com/?gws_rd=ssl
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs;_ri={google:suggestRid}&xssi;=t&q;={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-06]
CHR Extension: (Solution Real) - C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjnbbdonfhdjpangbkdcikdageggmfbg [2015-01-25]
CHR Extension: (Google Wallet) - C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-22]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-04]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-04] (AVAST Software)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-29] (WildTangent)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed]
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-27] ()
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [3939008 2012-07-11] (Symantec Corporation)
R2 Response Hardware; C:\Program Files (x86)\SMART Technologies\Education Software\ResponseHardwareService.exe [19352 2012-10-17] (SMART Technologies ULC)
R2 SMARTHelperService; C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe [582552 2012-10-24] (SMART Technologies)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-21] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-21] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-04] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-04] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-04] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-04] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-04] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-04] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-07-16] (Advanced Micro Devices)
R1 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0401000.00A\ccSetx64.sys [168608 2012-05-25] (Symantec Corporation)
S3 cricut; C:\Windows\system32\DRIVERS\cricut_x64.sys [72248 2014-12-30] ()
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-27] (Malwarebytes Corporation)
R3 SMARTMouseFilterx64; C:\Windows\System32\drivers\SMARTMouseFilterx64.sys [16280 2012-10-24] (SMART Technologies)
R3 SMARTVHidMiniVistaAmd64; C:\Windows\System32\drivers\SMARTVHidMiniVistaAmd64.sys [15256 2012-10-24] (SMART Technologies)
R3 SMARTVTabletPCx64; C:\Windows\System32\drivers\SMARTVTabletPCx64.sys [24984 2012-10-24] (SMART Technologies ULC)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-21] (Microsoft Corporation)
U3 aswMBR; \??\C:\Users\jimmy\AppData\Local\Temp\aswMBR.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-01 18:30 - 2015-02-01 18:30 - 05198336 _____ (AVAST Software) C:\Users\jimmy\Downloads\aswMBR (4).exe
2015-02-01 16:05 - 2015-02-01 16:05 - 00000000 _____ () C:\Recovery.txt
2015-02-01 11:57 - 2015-02-01 21:20 - 00000000 ____D () C:\WINDOWS\Minidump
2015-01-31 15:50 - 2015-01-31 15:50 - 00000000 ____D () C:\Users\jimmy\AppData\Local\Vosteran
2015-01-31 15:49 - 2015-02-01 03:46 - 00000000 ____D () C:\Program Files (x86)\WSE_Vosteran
2015-01-31 15:49 - 2015-01-31 15:49 - 00000000 ____D () C:\Users\jimmy\AppData\Roaming\WSE_Vosteran
2015-01-31 15:49 - 2015-01-31 15:49 - 00000000 ____D () C:\ProgramData\{E7C80F0B-B74A-DE8D-06CC-AE0FD64E7D81}
2015-01-31 15:48 - 2015-02-01 21:21 - 00000000 ____D () C:\Program Files (x86)\IntelliTerm_1.10.0.8
2015-01-31 15:47 - 2015-01-31 15:47 - 03703013 _____ () C:\Users\jimmy\Downloads\Project64 2.1.rar
2015-01-31 15:42 - 2015-01-31 15:42 - 33231414 _____ () C:\Users\jimmy\Downloads\N64 Emulator +2 Roms [Hexific Tutorials].rar
2015-01-31 14:37 - 2015-01-31 14:37 - 03440640 _____ () C:\Users\jimmy\Downloads\Tave20131120193651.bin
2015-01-31 14:11 - 2015-01-31 14:12 - 19124224 _____ () C:\Users\jimmy\Downloads\Qokemon.bin
2015-01-31 14:11 - 2015-01-31 14:11 - 01933853 _____ () C:\Users\jimmy\Downloads\PokemonGold.zip
2015-01-29 18:41 - 2015-02-01 21:20 - 00000000 ____D () C:\Users\jimmy\AppData\Roaming\PhotoScape
2015-01-29 18:39 - 2015-02-01 21:21 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2015-01-27 05:16 - 2015-01-27 05:23 - 00113063 _____ () C:\Users\jimmy\Documents\Little Miss Muffet.notebook
2015-01-25 14:32 - 2015-01-25 14:34 - 49206948 _____ () C:\Users\jimmy\Downloads\Adventure Time Adventure Map!.zip
2015-01-25 09:46 - 2015-01-25 09:47 - 11931648 _____ () C:\Users\jimmy\Downloads\Titan City V32 XBOX.bin
2015-01-25 08:15 - 2015-01-25 08:15 - 04042752 _____ () C:\Users\jimmy\Downloads\Zelda Ocarina of time adventure map.bin
2015-01-25 08:13 - 2015-01-25 08:14 - 05648384 _____ () C:\Users\jimmy\Downloads\Zelda Majoras Mask Adventure map.bin
2015-01-25 06:51 - 2015-01-25 06:51 - 00234679 _____ () C:\Users\jimmy\AppData\Local\dsi1.dat
2015-01-25 06:51 - 2015-01-25 06:51 - 00161916 _____ () C:\Users\jimmy\AppData\Local\dsi2.dat
2015-01-24 18:37 - 2015-01-24 18:37 - 03985408 _____ () C:\Users\jimmy\Downloads\The Forest Of The WoodLand Realm HG.bin
2015-01-24 18:35 - 2015-01-24 18:36 - 14692352 _____ () C:\Users\jimmy\Downloads\atlantis.bin
2015-01-24 18:33 - 2015-01-24 18:34 - 11440128 _____ () C:\Users\jimmy\Downloads\HarryPotterAdventurePart1and2.bin
2015-01-24 16:28 - 2015-01-24 16:28 - 03944448 _____ () C:\Users\jimmy\Downloads\Sky Towers Adventure Map 2.bin
2015-01-24 16:18 - 2015-01-24 16:20 - 142276760 _____ () C:\Users\jimmy\Downloads\Save20120513004504.rar
2015-01-24 16:06 - 2015-01-24 16:07 - 04521808 _____ () C:\Users\jimmy\Downloads\AdventureTimeCraft_2.zip
2015-01-24 15:45 - 2015-01-24 15:45 - 00000000 ____D () C:\Users\jimmy\AppData\Roaming\java
2015-01-24 15:44 - 2015-01-24 16:21 - 00000000 ____D () C:\Users\jimmy\AppData\Roaming\.minecraft
2015-01-24 15:34 - 2015-01-24 15:36 - 03515537 _____ () C:\Users\jimmy\Downloads\zeldaswordskills-1.7.10-beta-0.1.4.jar
2015-01-24 15:32 - 2015-01-24 15:32 - 00283286 _____ () C:\Users\jimmy\Downloads\PandorasBox-2.1.jar
2015-01-24 12:52 - 2015-01-24 12:52 - 06098944 _____ () C:\Users\jimmy\Downloads\Tave20130104031949.bin
2015-01-24 12:46 - 2015-01-24 12:47 - 10506240 _____ () C:\Users\jimmy\Downloads\Future 1.31.bin
2015-01-24 12:14 - 2015-01-24 12:15 - 05496832 _____ () C:\Users\jimmy\Downloads\Breeze Island Hunger Games.bin
2015-01-24 12:06 - 2015-01-24 12:06 - 07299072 _____ () C:\Users\jimmy\Downloads\Cops & Robbers Alcatraz.bin
2015-01-24 11:46 - 2015-01-24 11:47 - 16027402 _____ () C:\Users\jimmy\Downloads\The dropper by BIGRE.zip
2015-01-24 11:40 - 2015-01-24 11:40 - 00452776 _____ (InstallerTech Corp) C:\Users\jimmy\Downloads\Setup_ODM.exe
2015-01-23 23:50 - 2015-01-23 23:50 - 00000000 ___RD () C:\Users\jimmy\Documents\Notes
2015-01-23 16:51 - 2015-01-27 00:52 - 00000129 _____ () C:\Users\jimmy\AppData\Roaming\WB.CFG
2015-01-23 16:18 - 2015-01-23 16:19 - 26747527 _____ () C:\Users\jimmy\Downloads\oPryzeLP_setup.exe
2015-01-23 15:56 - 2015-01-23 16:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Horizon
2015-01-23 15:52 - 2015-02-01 18:27 - 00000000 ____D () C:\Users\jimmy\AppData\Local\browser extensions
2015-01-23 15:52 - 2015-01-23 15:52 - 00004530 _____ () C:\WINDOWS\System32\Tasks\Validate Installation
2015-01-23 15:52 - 2015-01-23 15:52 - 00004322 _____ () C:\WINDOWS\System32\Tasks\Check Updates
2015-01-23 15:52 - 2015-01-23 15:52 - 00003890 _____ () C:\WINDOWS\System32\Tasks\GeniusBox
2015-01-23 15:52 - 2015-01-23 15:52 - 00000064 _____ () C:\Users\jimmy\AppData\Local\ddbe2c08329a1e6b43cc28dae2cdb262
2015-01-23 15:51 - 2015-02-01 21:21 - 00000000 ____D () C:\Users\jimmy\AppData\Local\UpdateAdmin
2015-01-23 15:51 - 2015-02-01 21:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UpdateAdmin
2015-01-23 15:51 - 2015-01-23 15:51 - 00003830 _____ () C:\WINDOWS\System32\Tasks\UpdateAdmin
2015-01-23 06:35 - 2015-01-23 06:37 - 476169925 _____ () C:\Users\jimmy\Downloads\PrincessRescue-Final1.zip
2015-01-23 05:27 - 2015-01-23 05:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Game Creators
2015-01-23 05:23 - 2015-01-23 05:24 - 118137367 _____ () C:\Users\jimmy\Downloads\FPSCreatorFree (1).zip
2015-01-22 17:47 - 2015-01-22 17:49 - 118137367 _____ () C:\Users\jimmy\Downloads\FPSCreatorFree.zip
2015-01-21 22:45 - 2015-01-21 22:47 - 00000000 ____D () C:\Users\jimmy\Downloads\TheBestRhythmBingoGameEverPerfectforaSubstitute
2015-01-21 22:44 - 2015-01-21 22:44 - 05657888 _____ () C:\Users\jimmy\Downloads\TheBestRhythmBingoGameEverPerfectforaSubstitute.zip
2015-01-21 18:13 - 2015-01-21 18:13 - 00000000 ____D () C:\Users\jimmy\AppData\Local\ProjectSidescroller
2015-01-20 19:30 - 2015-01-20 19:30 - 00000000 ____D () C:\Users\jimmy\AppData\Local\1st_RPG
2015-01-20 19:28 - 2015-01-20 19:28 - 00000000 ____D () C:\Users\jimmy\Documents\GameMaker
2015-01-20 18:57 - 2015-01-20 18:57 - 00000000 ____D () C:\Users\jimmy\AppData\Local\YoYo_Games_Ltd
2015-01-20 18:56 - 2015-01-20 19:28 - 00000000 ____D () C:\Users\jimmy\AppData\Roaming\GameMaker-Studio
2015-01-20 18:55 - 2015-01-20 18:55 - 00000000 ____D () C:\WINDOWS\SysWOW64\directx
2015-01-20 18:55 - 2015-01-20 18:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameMaker Player
2015-01-20 18:54 - 2015-01-30 17:50 - 00000000 ____D () C:\Users\jimmy\AppData\Local\GameMaker-Studio
2015-01-20 18:53 - 2015-01-20 18:53 - 98955008 _____ () C:\Users\jimmy\Downloads\GMStudio-Installer-1.4.1474.exe
2015-01-14 07:00 - 2014-12-19 01:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2015-01-14 07:00 - 2014-12-11 21:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2015-01-14 07:00 - 2014-12-11 19:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-01-14 07:00 - 2014-12-08 20:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-01-14 07:00 - 2014-12-08 14:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-01-14 07:00 - 2014-12-08 14:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-01-14 07:00 - 2014-12-08 14:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2015-01-14 07:00 - 2014-12-08 14:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2015-01-14 07:00 - 2014-12-08 14:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2015-01-14 07:00 - 2014-12-08 14:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-01-14 07:00 - 2014-12-08 14:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2015-01-14 07:00 - 2014-12-08 14:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2015-01-14 07:00 - 2014-12-05 22:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-01-14 07:00 - 2014-12-05 20:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-01-14 07:00 - 2014-12-05 20:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-01-14 07:00 - 2014-10-28 23:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2015-01-14 07:00 - 2014-10-28 23:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2015-01-14 07:00 - 2014-10-28 22:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-01-14 07:00 - 2014-10-28 22:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-01-14 07:00 - 2014-10-28 22:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-01-14 07:00 - 2014-10-28 22:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-01-14 07:00 - 2014-10-28 22:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2015-01-14 07:00 - 2014-10-28 22:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2015-01-14 07:00 - 2014-10-28 22:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-01-14 07:00 - 2014-10-28 22:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-01-14 07:00 - 2014-10-28 22:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-01-14 07:00 - 2014-10-28 21:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-01-14 07:00 - 2014-10-28 20:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2015-01-14 07:00 - 2014-10-28 20:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2015-01-14 07:00 - 2014-10-28 20:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-01-14 07:00 - 2014-10-28 20:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2015-01-10 11:22 - 2015-01-10 13:31 - 1289761974 _____ () C:\Users\jimmy\Downloads\StarWar-Battlefront2.zip
2015-01-09 16:50 - 2015-01-09 16:54 - 00003270 _____ () C:\WINDOWS\System32\Tasks\avastBCLRestartS-1-5-21-1271087293-465154865-2948633367-1002
2015-01-04 16:57 - 2015-01-04 16:57 - 03579246 _____ () C:\Users\jimmy\Downloads\2970275_7725991.mp4
2015-01-04 15:11 - 2015-01-04 15:11 - 00001835 _____ () C:\Users\jimmy\Desktop\malwarebytes2.txt
2015-01-04 15:11 - 2015-01-04 15:11 - 00000419 _____ () C:\Users\jimmy\Downloads\Fixlist.txt
2015-01-04 13:38 - 2015-01-04 13:38 - 00002636 _____ () C:\Users\jimmy\Documents\test movie.wlmp
2015-01-03 12:35 - 2015-01-03 12:35 - 00001423 _____ () C:\Users\jimmy\Desktop\malwarebytes1.txt
2015-01-03 12:35 - 2015-01-03 12:35 - 00001422 _____ () C:\Users\jimmy\Desktop\malwarebytes.txt
2015-01-03 10:53 - 2015-01-03 10:54 - 67183278 _____ () C:\Users\jimmy\Downloads\ITB v23.zip
2015-01-03 09:02 - 2015-01-27 19:22 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-01-03 09:00 - 2015-02-01 21:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-03 09:00 - 2015-01-03 09:00 - 00001121 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-03 08:59 - 2015-02-01 21:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-03 08:59 - 2015-02-01 21:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-03 08:59 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-01-03 08:59 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-01-03 08:59 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-01-03 08:58 - 2015-01-03 08:58 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\jimmy\Downloads\mbam-setup-2.0.4.1028 (4).exe
2015-01-03 08:45 - 2015-01-03 08:45 - 00321848 _____ (Malwarebytes Corporation) C:\Users\jimmy\Downloads\mbam-clean-2.1.1.1001 (1).exe
2015-01-03 08:35 - 2015-01-03 08:35 - 00321848 _____ (Malwarebytes Corporation) C:\Users\jimmy\Downloads\mbam-clean-2.1.1.1001.exe
2015-01-02 23:21 - 2015-01-02 23:21 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\jimmy\Downloads\mbam-setup-2.0.4.1028 (3).exe
2015-01-02 21:45 - 2015-01-02 21:45 - 00018917 _____ () C:\Users\jimmy\Documents\My Movie.wlmp
2015-01-02 21:45 - 2015-01-02 21:45 - 00000000 ____D () C:\Users\jimmy\Tracing
2015-01-02 19:56 - 2015-01-27 18:42 - 00000000 ____D () C:\WINDOWS\en
2015-01-02 19:55 - 2015-01-02 19:55 - 00001481 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-01-02 19:55 - 2015-01-02 19:55 - 00001397 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-01-02 19:55 - 2015-01-02 19:55 - 00001328 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2015-01-02 19:55 - 2015-01-02 19:55 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2015-01-02 19:55 - 2015-01-02 19:55 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-01-02 19:54 - 2015-01-02 19:54 - 00002509 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2015-01-02 19:53 - 2015-01-02 19:55 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-01-02 19:53 - 2015-01-02 19:53 - 00000000 ____D () C:\WINDOWS\PCHEALTH
2015-01-02 19:53 - 2015-01-02 19:53 - 00000000 ____D () C:\Program Files\Windows Live
2015-01-02 19:51 - 2015-01-02 19:51 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
2015-01-02 19:49 - 2015-01-31 10:05 - 00000000 ____D () C:\Users\jimmy\AppData\Local\Windows Live
2015-01-02 19:47 - 2015-01-02 19:47 - 01239752 _____ (Microsoft Corporation) C:\Users\jimmy\Downloads\wlsetup-web.exe
2015-01-02 08:19 - 2015-01-02 08:19 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\jimmy\Downloads\mbam-setup-2.0.4.1028 (2).exe
2015-01-02 08:12 - 2015-01-02 08:13 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\jimmy\Downloads\mbam-setup-2.0.4.1028 (1).exe
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-02-01 21:21 - 2014-10-19 21:14 - 00000000 ____D () C:\Users\Administrator
2015-02-01 21:21 - 2013-12-15 20:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-01 21:21 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\WinMetadata
2015-02-01 21:21 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-02-01 21:21 - 2013-03-16 08:22 - 00000000 ____D () C:\ProgramData\FLEXnet
2015-02-01 21:21 - 2013-03-16 08:19 - 00000000 ____D () C:\Users\jimmy\AppData\Roaming\SMART Technologies
2015-02-01 21:21 - 2012-08-03 04:40 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-02-01 21:21 - 2012-08-03 04:40 - 00000000 ____D () C:\ProgramData\WildTangent
2015-02-01 21:13 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\registration
2015-02-01 21:12 - 2013-08-22 08:36 - 00000000 ____D () C:\WINDOWS\system32\Sysprep
2015-02-01 21:12 - 2012-12-22 17:03 - 00000000 ____D () C:\Users\jimmy\AppData\Local\Packages
2015-02-01 21:11 - 2013-02-21 20:58 - 00000000 ___HD () C:\$SysReset
2015-02-01 21:11 - 2012-08-03 04:40 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
2015-02-01 18:42 - 2014-11-25 21:22 - 00021998 _____ () C:\Users\jimmy\Desktop\FRST.txt
2015-02-01 18:41 - 2014-10-28 17:13 - 00000000 ____D () C:\Users\jimmy\Desktop\FRST-OlderVersion
2015-02-01 18:41 - 2014-10-24 20:58 - 02131456 _____ (Farbar) C:\Users\jimmy\Desktop\FRST64.exe
2015-02-01 18:41 - 2014-10-24 20:58 - 00000000 ____D () C:\FRST
2015-02-01 18:40 - 2014-11-25 21:21 - 00004910 _____ () C:\Users\jimmy\Desktop\aswMBR.txt
2015-02-01 18:40 - 2014-10-24 20:57 - 00000512 _____ () C:\Users\jimmy\Desktop\MBR.dat
2015-02-01 18:38 - 2014-10-19 21:05 - 01171867 _____ () C:\WINDOWS\WindowsUpdate.log
2015-02-01 18:37 - 2012-07-26 02:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-02-01 18:36 - 2013-02-22 17:01 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1271087293-465154865-2948633367-1002
2015-02-01 18:31 - 2014-10-20 17:16 - 00003914 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B9791AE5-E39C-4E49-8217-4386C0483A75}
2015-02-01 18:31 - 2013-12-30 12:55 - 00001989 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2015-02-01 18:31 - 2013-08-22 08:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-02-01 18:29 - 2013-12-30 12:55 - 00003924 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-02-01 18:25 - 2013-12-15 20:16 - 00000914 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-01 18:23 - 2014-10-19 21:14 - 00000000 ____D () C:\Users\jimmy
2015-02-01 18:23 - 2013-08-22 09:46 - 00337248 _____ () C:\WINDOWS\setupact.log
2015-02-01 18:23 - 2013-08-22 09:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-02-01 17:51 - 2014-10-21 20:40 - 00000000 ____D () C:\Users\jimmy\AppData\Local\Deployment
2015-02-01 11:56 - 2014-09-24 02:03 - 00192122 _____ () C:\WINDOWS\PFRO.log
2015-02-01 11:49 - 2014-12-31 16:26 - 00037177 _____ () C:\Users\jimmy\Desktop\Addition.txt
2015-02-01 08:27 - 2014-06-27 16:50 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2015-01-30 17:50 - 2014-10-24 21:28 - 00234496 ___SH () C:\Users\jimmy\Desktop\Thumbs.db
2015-01-28 17:21 - 2013-03-11 00:06 - 00000000 ____D () C:\Users\jimmy\AppData\Local\Spotify
2015-01-27 19:12 - 2014-05-07 13:45 - 00000918 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cf6a24736f14b2.job
2015-01-27 18:45 - 2013-03-16 08:30 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-01-27 18:42 - 2014-11-21 22:00 - 00000258 __RSH () C:\ProgramData\ntuser.pol
2015-01-27 18:41 - 2013-08-22 08:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-01-27 18:39 - 2012-07-26 00:26 - 00000194 _____ () C:\WINDOWS\win.ini
2015-01-26 23:15 - 2013-12-15 20:17 - 00002210 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-26 21:37 - 2013-01-28 17:05 - 00000000 ____D () C:\Users\jimmy\Documents\Christians Work
2015-01-26 21:36 - 2013-11-21 20:01 - 00000000 ____D () C:\Users\jimmy\Desktop\YouTube
2015-01-26 21:25 - 2014-10-24 20:13 - 00439808 ___SH () C:\Users\jimmy\Downloads\Thumbs.db
2015-01-26 21:23 - 2013-02-21 21:21 - 00000000 ____D () C:\Users\jimmy\AppData\Roaming\Adobe
2015-01-26 21:17 - 2014-07-18 22:38 - 00000000 ____D () C:\Users\jimmy\Downloads\chocolate_covered_raindrops
2015-01-26 05:18 - 2014-09-24 02:15 - 00863592 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-01-25 00:04 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\system32\GroupPolicy
2015-01-24 22:47 - 2013-03-11 00:06 - 00000000 ____D () C:\Users\jimmy\AppData\Roaming\Spotify
2015-01-24 16:16 - 2014-10-24 20:13 - 00178688 ___SH () C:\Users\jimmy\Documents\Thumbs.db
2015-01-24 15:45 - 2013-03-16 08:30 - 00003718 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-01-23 15:56 - 2013-03-03 21:45 - 00000000 ____D () C:\Temp
2015-01-23 15:50 - 2013-02-25 21:31 - 00001166 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-01-23 05:27 - 2012-08-03 04:51 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-21 22:55 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-01-20 18:55 - 2013-11-23 07:44 - 00000000 ___HD () C:\WINDOWS\msdownld.tmp
2015-01-19 16:32 - 2014-12-12 21:33 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-01-19 16:32 - 2014-12-12 21:33 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-15 05:47 - 2013-08-24 19:32 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-01-15 05:32 - 2013-02-22 23:11 - 113365784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-01-12 17:57 - 2014-12-14 13:43 - 00000000 ____D () C:\Users\jimmy\Desktop\mods
2015-01-11 21:30 - 2015-01-01 12:38 - 00008692 _____ () C:\Users\jimmy\Documents\The_Lord_Never_Closes_His_Eyes.mscz
2015-01-11 17:40 - 2015-01-01 12:38 - 00006854 _____ () C:\Users\jimmy\Documents\.The_Lord_Never_Closes_His_Eyes.mscz,
2015-01-09 06:20 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp
2015-01-06 18:59 - 2013-12-07 15:48 - 00000000 ____D () C:\Program Files (x86)\McAfee
2015-01-06 18:59 - 2013-12-07 15:39 - 00000000 ____D () C:\ProgramData\McAfee
2015-01-06 18:52 - 2012-07-26 03:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
2015-01-06 18:48 - 2013-11-20 18:42 - 00000000 ____D () C:\Users\hedev
2015-01-06 18:48 - 2012-07-26 00:37 - 00000000 ____D () C:\Users\Default.migrated
2015-01-06 18:47 - 2013-12-07 15:51 - 00000000 ____D () C:\Users\jimmy\Documents\McAfee Vaults
2015-01-04 15:36 - 2013-08-22 10:43 - 00000000 ____D () C:\WINDOWS\DigitalLocker
2015-01-03 11:28 - 2013-08-22 09:45 - 00000000 ____D () C:\WINDOWS\Setup
2015-01-02 21:47 - 2013-03-24 12:33 - 00000000 ____D () C:\Users\jimmy\AppData\Roaming\Audacity
2015-01-02 19:53 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-01-02 19:52 - 2013-11-23 07:49 - 00031301 _____ () C:\WINDOWS\DirectX.log
2015-01-02 09:31 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\Vss
 
==================== Files in the root of some directories =======
 
2015-01-23 16:51 - 2015-01-27 00:52 - 0000129 _____ () C:\Users\jimmy\AppData\Roaming\WB.CFG
2013-04-01 14:59 - 2014-11-04 10:37 - 0005632 _____ () C:\Users\jimmy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-23 15:52 - 2015-01-23 15:52 - 0000064 _____ () C:\Users\jimmy\AppData\Local\ddbe2c08329a1e6b43cc28dae2cdb262
2015-01-25 06:51 - 2015-01-25 06:51 - 0234679 _____ () C:\Users\jimmy\AppData\Local\dsi1.dat
2015-01-25 06:51 - 2015-01-25 06:51 - 0161916 _____ () C:\Users\jimmy\AppData\Local\dsi2.dat
 
Some content of TEMP:
====================
C:\Users\jimmy\AppData\Local\Temp\FPS Creator Free.exe
C:\Users\jimmy\AppData\Local\Temp\mccspuninstall.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-01-30 06:32
 
==================== End Of Log ============================
 
 
 

Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

 

 

 

 

We need to remove some programs with Revo Uninstaller Free:


Note: Revo Uninstaller is more thorough in deleting programs on your computer than using the Add/Remove option in Windows. Since it is a more powerful tool, please be sure to follow the instructions carefully.
Note: If the program you want to uninstall is not listed by Revo, let me know and we will try an altenate method of removal.

  • Please download and install Revo Uninstaller Free
    note: there is no need to click anything on that page, the download will start automatically
  • Double click Revo Uninstaller to run it
  • From the list of programs double click on the listed program(s), or anything similar, to remove it:
    Minecraft Packages
    
    PCBooster
    
    
  • When prompted if you want to uninstall click Yes
  • Be sure the Moderate option is selected then click Next
  • The program will run, If prompted again click Yes
  • When the built-in uninstaller is finished click on Next
  • Once the program has searched for leftovers click Next
  • Check the items in bold only on the list then click Delete
    note: you may have to expand some folders by clicking the "+" mark
  • When prompted click on Yes and then on Next
  • Put a check on any folders that are found and select Delete
  • When prompted select Yes then Next
  • Once done click Finish

 

 

 

 

 

Fix with FRST (normal mode)

WARNING: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 

  • Download the attached fixlist.txt and save it to the location where FRST is saved to.
  • Run FRST.exe (on 64bit, run FRST64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.

Full System Scan with Malwarebytes Antimalware



  • If not existing, please download Malwarebytes Anti-Malware to your desktop.
  • Double-click the downloaded setup file and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish.

If the program is already installed:

  • Run Malwarebytes Antimalware
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.

Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.

 

Attachments:

Here are the logs you requested.

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-02-2015
Ran by [removed] at 2015-02-02 07:33:01 Run:3
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
ProxyEnable: [S-1-5-21-1271087293-465154865-2948633367-1002] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-1271087293-465154865-2948633367-1002] => http=127.0.0.1:49697;https=127.0.0.1:49697
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\Software\Microsoft\Internet Explorer\Main,DisableRequiresActiveXPrompt = web.roblox.com
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://Taplika.com/r…=1962780214&ir=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://Taplika.com/r…=1962780214&ir=
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1271087293-465154865-2948633367-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://Taplika.com/r…=1962780214&ir=
SearchScopes: HKU\S-1-5-21-1271087293-465154865-2948633367-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://Taplika.com/r…=1962780214&ir=
FF SearchEngineOrder.1: Secure Search
FF SelectedSearchEngine: Taplika
FF SearchPlugin: C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\l8b5k1dm.default\searchplugins\Vosteran.xml
FF Extension: Solution Real 1.0.1 - C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\l8b5k1dm.default\Extensions\{5c281c6e-0132-4ac6-ad9d-d1d95d218412}.xpi [2015-01-24]
 
Task: {58E7D624-6ACB-492B-8D91-09ABC2E80715} - System32\Tasks\UpdateAdmin => C:\Users\jimmy\AppData\Local\UpdateAdmin\UpdateAdmin.exe [2014-10-16] (DownloadAdmin)
CustomCLSID: HKU\S-1-5-21-1271087293-465154865-2948633367-1002_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\jimmy\AppData\Local\Roblox\Versions\version-c2a7e6748ad54a86\RobloxProxy64.dll No File
Task: {066D7012-D626-4B3A-88A4-2EFF2BE832ED} - System32\Tasks\{1B5A351E-6456-4DCD-9137-9C2476C8113D} => pcalua.exe -a "C:\Users\jimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2C8RVGXX\cda-to-mp3-converter.exe" -d C:\Users\jimmy\Desktop
Task: {1EB54D96-8023-4FEE-A90A-EBF7A4AE10BF} - System32\Tasks\GeniusBox => cmd.exe /C start "" "C:\Users\jimmy\AppData\Local\browser extensions\client.exe"
Task: {369D7B29-33DB-4B77-992B-E2333FC1F33F} - System32\Tasks\Check Updates => C:\Users\jimmy\AppData\Local\browser extensions\updater.exe [2015-01-22] ()
Task: {6C486CAD-5C9D-410A-80E5-5BA22409EA21} - System32\Tasks\{AB7133B4-07D0-495A-A9A6-C71305016BB2} => pcalua.exe -a C:\Users\jimmy\Downloads\kremove.exe -d C:\Users\jimmy\Downloads
Task: {8816E06C-14A4-4232-B8F7-9DAAB8A52487} - System32\Tasks\Validate Installation => C:\Users\jimmy\AppData\Local\browser extensions\updater.exe [2015-01-22] ()
 
2015-01-23 15:52 - 2015-01-23 15:52 - 00004530 _____ () C:\WINDOWS\System32\Tasks\Validate Installation
2015-01-23 15:52 - 2015-01-23 15:52 - 00004322 _____ () C:\WINDOWS\System32\Tasks\Check Updates
2015-01-23 15:52 - 2015-01-23 15:52 - 00003890 _____ () C:\WINDOWS\System32\Tasks\GeniusBox
2015-01-23 15:52 - 2015-01-23 15:52 - 00000064 _____ () C:\Users\jimmy\AppData\Local\ddbe2c08329a1e6b43cc28dae2cdb262
2015-01-23 15:51 - 2015-02-01 21:21 - 00000000 ____D () C:\Users\jimmy\AppData\Local\UpdateAdmin
2015-01-23 15:51 - 2015-02-01 21:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UpdateAdmin
2015-01-23 15:51 - 2015-01-23 15:51 - 00003830 _____ () C:\WINDOWS\System32\Tasks\UpdateAdmin
2015-01-31 15:50 - 2015-01-31 15:50 - 00000000 ____D () C:\Users\jimmy\AppData\Local\Vosteran
2015-01-31 15:49 - 2015-02-01 03:46 - 00000000 ____D () C:\Program Files (x86)\WSE_Vosteran
2015-01-31 15:49 - 2015-01-31 15:49 - 00000000 ____D () C:\Users\jimmy\AppData\Roaming\WSE_Vosteran
2015-01-31 15:49 - 2015-01-31 15:49 - 00000000 ____D () C:\ProgramData\{E7C80F0B-B74A-DE8D-06CC-AE0FD64E7D81}
2015-01-31 15:48 - 2015-02-01 21:21 - 00000000 ____D () C:\Program Files (x86)\IntelliTerm_1.10.0.8
C:\Users\jimmy\AppData\Local\browser extensions
C:\Users\jimmy\AppData\Local\Roblox
C:\Users\jimmy\AppData\Local\UpdateAdmin
*****************
 
C:\WINDOWS\system32\GroupPolicy\Machine => Moved successfully.
C:\WINDOWS\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\Software\Microsoft\Internet Explorer\Main\\DisableRequiresActiveXPrompt => value deleted successfully.
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. 
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-21-1271087293-465154865-2948633367-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-1271087293-465154865-2948633367-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. 
Firefox SearchEngineOrder.1 deleted successfully.
Firefox SelectedSearchEngine deleted successfully.
C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\l8b5k1dm.default\searchplugins\Vosteran.xml => Moved successfully.
C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\l8b5k1dm.default\Extensions\{5c281c6e-0132-4ac6-ad9d-d1d95d218412}.xpi => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{58E7D624-6ACB-492B-8D91-09ABC2E80715}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58E7D624-6ACB-492B-8D91-09ABC2E80715}" => Key deleted successfully.
C:\Windows\System32\Tasks\UpdateAdmin => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UpdateAdmin" => Key deleted successfully.
"HKU\S-1-5-21-1271087293-465154865-2948633367-1002_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{066D7012-D626-4B3A-88A4-2EFF2BE832ED}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{066D7012-D626-4B3A-88A4-2EFF2BE832ED}" => Key deleted successfully.
C:\Windows\System32\Tasks\{1B5A351E-6456-4DCD-9137-9C2476C8113D} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1B5A351E-6456-4DCD-9137-9C2476C8113D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1EB54D96-8023-4FEE-A90A-EBF7A4AE10BF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EB54D96-8023-4FEE-A90A-EBF7A4AE10BF}" => Key deleted successfully.
C:\Windows\System32\Tasks\GeniusBox => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GeniusBox" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{369D7B29-33DB-4B77-992B-E2333FC1F33F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{369D7B29-33DB-4B77-992B-E2333FC1F33F}" => Key deleted successfully.
C:\Windows\System32\Tasks\Check Updates => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Check Updates" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C486CAD-5C9D-410A-80E5-5BA22409EA21}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C486CAD-5C9D-410A-80E5-5BA22409EA21}" => Key deleted successfully.
C:\Windows\System32\Tasks\{AB7133B4-07D0-495A-A9A6-C71305016BB2} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AB7133B4-07D0-495A-A9A6-C71305016BB2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8816E06C-14A4-4232-B8F7-9DAAB8A52487}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8816E06C-14A4-4232-B8F7-9DAAB8A52487}" => Key deleted successfully.
C:\Windows\System32\Tasks\Validate Installation => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Validate Installation" => Key deleted successfully.
"C:\WINDOWS\System32\Tasks\Validate Installation" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\Check Updates" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\GeniusBox" => File/Directory not found.
C:\Users\jimmy\AppData\Local\ddbe2c08329a1e6b43cc28dae2cdb262 => Moved successfully.
C:\Users\jimmy\AppData\Local\UpdateAdmin => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UpdateAdmin => Moved successfully.
"C:\WINDOWS\System32\Tasks\UpdateAdmin" => File/Directory not found.
C:\Users\jimmy\AppData\Local\Vosteran => Moved successfully.
C:\Program Files (x86)\WSE_Vosteran => Moved successfully.
C:\Users\jimmy\AppData\Roaming\WSE_Vosteran => Moved successfully.
C:\ProgramData\{E7C80F0B-B74A-DE8D-06CC-AE0FD64E7D81} => Moved successfully.
C:\Program Files (x86)\IntelliTerm_1.10.0.8 => Moved successfully.
 
"C:\Users\jimmy\AppData\Local\browser extensions" directory move:
 
C:\Users\jimmy\AppData\Local\browser extensions\certmanager.exe => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\Client.exe => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\makecert.exe => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\settings.config => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\Tasks.exe => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\TrustedRoot.cer => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\Uninstall.exe => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\Updater.exe => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\Resources\certutil.exe => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\Resources\libnspr4.dll => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\Resources\libplc4.dll => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\Resources\libplds4.dll => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\Resources\nss3.dll => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\Resources\smime3.dll => Moved successfully.
C:\Users\jimmy\AppData\Local\browser extensions\Resources\softokn3.dll => Moved successfully.
Could not move "C:\Users\jimmy\AppData\Local\browser extensions" directory. => Scheduled to move on reboot.
 
C:\Users\jimmy\AppData\Local\Roblox => Moved successfully.
"C:\Users\jimmy\AppData\Local\UpdateAdmin" => File/Directory not found.
 
=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-02-02 07:35:03)<=
 
C:\Users\jimmy\AppData\Local\browser extensions => Is moved successfully.
 
==== End of Fixlog 07:35:03 ====
 
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 2/2/2015
Scan Time: 7:36:56 AM
Logfile: 
Administrator: Yes
 
Version: 2.00.4.1028
Malware Database: v2015.02.02.02
Rootkit Database: v2015.01.14.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 8.1
CPU: x64
File System: NTFS
User: jimmy
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 427240
Time Elapsed: 54 min, 21 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 8
PUP.Optional.BoostSaves.A, C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage, Quarantined, [1793ba5f92f849edcf67721615eeb54b], 
PUP.Optional.BoostSaves.A, C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage-journal, Quarantined, [f5b5b6632367d85e0432c0c8ef1460a0], 
PUP.Optional.Boost.A, C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage, Quarantined, [fdada9707c0ee35357105a48748fae52], 
PUP.Optional.Boost.A, C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage-journal, Quarantined, [fdad0910a8e2e45289de3f639d66ed13], 
PUP.Optional.Vitruvian.A, C:\Users\jimmy\AppData\Local\Temp\vitruvian-installer-hardwareprofile-v0001, Quarantined, [555565b4800ab383a713dc2c897c38c8], 
PUP.Optional.Vitruvian.A, C:\Users\jimmy\AppData\Local\Temp\vitruvian-installer-install-v0003, Quarantined, [5d4d51c89bef3cfae0da0dfbb94c2cd4], 
PUP.Optional.Vitruvian.A, C:\Users\jimmy\AppData\Local\Temp\vitruvian-installer-processes-v0002, Quarantined, [931733e6d1b9f4420bafa86081847a86], 
PUP.Optional.Vitruvian.A, C:\Users\jimmy\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001, Quarantined, [b7f3e633c1c981b595256f99cd3847b9], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
C:\$Recycle.Bin\S-1-5-21-1271087293-465154865-2948633367-1002\$R6RX3R3.exe a variant of Win32/InstallCore.OZ potentially unwanted application
C:\$Recycle.Bin\S-1-5-21-1271087293-465154865-2948633367-1002\$RAJVVA0.exe a variant of Win32/InstallCore.PL potentially unwanted application
C:\$Recycle.Bin\S-1-5-21-1271087293-465154865-2948633367-1002\$RZW25UK.exe a variant of Win32/InstallCore.VW potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll.vir Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\ProgramData\Browser\prompt.exe.vir a variant of MSIL/Adware.PullUpdate.H application
C:\AdwCleaner\Quarantine\C\Users\jimmy\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll.vir Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\jimmy\AppData\Local\Conduit\BackgroundContainer\TBUpdaterLogic_1.0.0.1.dll.vir Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\jimmy\AppData\Local\Conduit\BackgroundContainer\TBUpdaterLogic_1.0.0.2.dll.vir Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\jimmy\AppData\Local\iLivid\Helper.dll.vir a variant of Win32/Toolbar.SearchSuite.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\jimmy\AppData\Local\torch\Helper.dll.vir a variant of Win32/Toolbar.SearchSuite.X potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\jimmy\AppData\Local\torch\Uninstall.exe.vir a variant of Win32/TorchMedia potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\jimmy\AppData\Local\torch\Update\Download\TorchSetup.exe.vir a variant of Win32/TorchMedia potentially unwanted application
C:\FRST\Quarantine\C\Program Files (x86)\Portable Booster\JHSoft_PC_Booster.exe a variant of MSIL/RegProCleaner.A potentially unwanted application
C:\FRST\Quarantine\C\Program Files (x86)\Portable Booster\JHSoft_PC_BoosterAuto.exe a variant of MSIL/RegProCleaner.A potentially unwanted application
C:\FRST\Quarantine\C\Users\jimmy\AppData\Local\browser extensions\Client.exe.xBAD a variant of MSIL/Adware.iBryte.S application
C:\ProgramData\fgtyHUPuUn\dat\OSgXwPRv.dll a variant of MSIL/Adware.PullUpdate.F application
C:\ProgramData\fgtyHUPuUn\dat\ZijiRIU.dll a variant of MSIL/Adware.PullUpdate.C application
C:\Users\All Users\fgtyHUPuUn\dat\OSgXwPRv.dll a variant of MSIL/Adware.PullUpdate.F application
C:\Users\All Users\fgtyHUPuUn\dat\ZijiRIU.dll a variant of MSIL/Adware.PullUpdate.C application
C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjnbbdonfhdjpangbkdcikdageggmfbg\1.0.1_0\background.js Win32/BrowseFox.Q potentially unwanted application
C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjnbbdonfhdjpangbkdcikdageggmfbg\1.0.1_0\content.js Win32/BrowseFox.Q potentially unwanted application
C:\Users\jimmy\AppData\Local\Microsoft\Windows\INetCache\IE\S5LLCBAA\SolutionReal[1].dll a variant of Win32/BrowseFox.O potentially unwanted application
C:\Users\jimmy\AppData\Local\Temp\Temp1_FPSCreatorFree (1).zip\Integrated_FPSCreatorFree.exe a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\Users\jimmy\AppData\Local\Temp\Temp1_FPSCreatorFree.zip\Integrated_FPSCreatorFree.exe a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\Users\jimmy\Downloads\FPSCreatorFree (1).zip a variant of Win32/Toolbar.Conduit.B potentially unwanted application
C:\Users\jimmy\Downloads\FPSCreatorFree.zip a variant of Win32/Toolbar.Conduit.B potentially unwanted application
 
 

Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe

  • Hit Scan and wait for the scan to finish.

  • Confirm the message but don´t uncheck anything.

  • Hit Clean

  • When the run is finished, it will open up a text file

  • Please post its contents within your next reply

  • You´ll find the log file at C:\AdwCleaner[S1].txt also




Delete junk with JRT

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.

  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".

  • The tool will open and start scanning your system.

  • Please be patient as this can take a while to complete depending on your system's specifications.

  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

  • Post the contents of JRT.txt into your next message.




SecurityCheck

Reboot your system before starting!

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.

  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.

Here are the logs you requested.

 

 

# AdwCleaner v4.110 - Logfile created 07/02/2015 at 10:22:51
# Updated 05/02/2015 by Xplode
# Database : 2015-02-05.2 [Server]
# Operating system : Windows 8.1  (x64)
# Username : jimmy - OURPC
# Running from : C:\Users\jimmy\Downloads\adwcleaner_4.110.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\Users\jimmy\AppData\Local\Temp\Solution Real
File Deleted : C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\l8b5k1dm.default\user.js
File Deleted : C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
File Deleted : C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
File Deleted : C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal
File Deleted : C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage-journal
File Deleted : C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.publikeco00.publikeco.com_0.localstorage
File Deleted : C:\Users\jimmy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.publikeco00.publikeco.com_0.localstorage-journal
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKCU\Software\Search Extensions
Key Deleted : HKCU\Software\Vittalia
Key Deleted : HKLM\SOFTWARE\InstallCore
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=127.0.0.1:49499;hxxps=127.0.0.1:49499
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17416
 
 
-\\ Mozilla Firefox v34.0.5 (x86 en-US)
 
 
-\\ Google Chrome v40.0.2214.111
 
 
*************************
 
AdwCleaner[R0].txt - [5385 bytes] - [26/10/2014 16:19:01]
AdwCleaner[R1].txt - [7188 bytes] - [01/01/2015 09:02:14]
AdwCleaner[R2].txt - [2941 bytes] - [07/02/2015 10:08:00]
AdwCleaner[S0].txt - [5345 bytes] - [26/10/2014 16:33:19]
AdwCleaner[S1].txt - [7161 bytes] - [01/01/2015 09:11:06]
AdwCleaner[S2].txt - [2809 bytes] - [07/02/2015 10:22:51]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2868  bytes] ##########
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 8.1 x64
Ran by [removed] on Sat 02/07/2015 at 10:32:12.90
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 02/07/2015 at 11:04:43.20
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 Results of screen317's Security Check version 0.99.96  
   x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
Windows Defender   
avast! Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 Java 7 Update 60  
 Java 8 Update 25  
 Java version 32-bit out of Date! 
  Java 64-bit 8 Update 31  
 Adobe Flash Player 16.0.0.305  
 Adobe Reader XI  
 Mozilla Firefox 34.0.5 Firefox out of Date!  
 Google Chrome (40.0.2214.111) 
 Google Chrome (40.0.2214.94) 
````````Process Check: objlist.exe by Laurent````````  
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 Malwarebytes Anti-Malware mbamscheduler.exe   
 Symantec Norton Online Backup NOBuAgent.exe  
 Symantec Norton Online Backup NOBuClient.exe  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast ng vbox\AvastVBoxSVC.exe 
 AVAST Software Avast ng ngservice.exe 
 AVAST Software Avast AvastUI.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  % 
````````````````````End of Log`````````````````````` 
 
 
 

Your system is clean now! :)

 

 

 

Java runtime Environment out of date

Your Java runtime environment is outdated. We will fix this.

  • Get the actual JRE from here
  • Save jxpiinstall.exe to your desktop
  • Close all running programs, especially your browser(s)
  • Run jxpiinstall.exe. This will download the newest JRE installer and install the software
  • when finished, go to
  • Start–>control panel–>add/remove programs and remove all older Java versions. (if existing)
  • When finished, reboot your computer.

After the reboot
  • Open control panel again and click the java symbol.
  • Click Settings under Temporary Internet Files.
  • The Temporary Files Settings dialog box appears.
  • Click Delete Files.
  • The Delete Temporary Files dialog box appears
  • Click OK on Delete Temporary Files window.
  • Click OK again.

 

 

 

 

Mozilla Firefox out of date

Your Firefox browser is outdated. Please follow these instructions to update it:

  • Get the actual firefox from here.
  • Run setup and follow the instructions on your monitor.
  • Report any problems you have with the update.

 

 

 

 

Uninstall our tools using delfix

Please follow these steps in order:

  1. In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  2. In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  3. In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process

  4. If there is still something left please delete it manualy.




Delete System Restore Points

To ensure your System Restore Points are free of malware, we will delete all of them but the most recent or create a new one.

On Windows Vista: Please follow these instructions to delete all but the most common System Protection Restore Points.
On Windows 7/8: Please follow these instructions to delete all but the most common System Protection Restore Points.
On Windows XP: Please follow these instructions to delete all but the most common System Protection Restore Points.

 

 

 

 

Recommendations: How to protect yourself

  • System Updates
  • Please ensure to have automatic updates activated in your control panel.
    For further information and a tutorial, see this Microsoft Support article.
  • Protection
  • What you need is one (not more) virus scanner with background protection. Additionally I recommend a special malware scanner to run on demand weekly.
    Personally I am using avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer good protection for free.
    • To keep your browser free of advertising, you may install the Adblock Plus browser extension.
    • It will filter unwanted advertising out of the website´s content.
    • To protect yourself from accidentally visiting malicious web sites, install the Web of Trust (WOT) browser extension.
    • It will display a green (safe), yellow (unknown) or red (potentially dangerous) icon for a visited website within your browser.
      In addition, before accessing a dangerous classified web site, a warning screen is displayed.


  • Up to date Software
  • Keep your Windows and your third party software up to date. The easiest way to get infected is an outdated windows, followed by: browser(s) (including add-ons and plug-ins), Adobe Flash Player and Adobe Reader, Java Runtime Environment, your antivirus program and so on. These links may help you to check:
    • Secunia Personal Software Inspector - checks if your software has updates available.

    • SecurityCheck (by screen317) - scans your computer for most vulnerable outdated software.

    • Mozilla: Check your plugins - The webpage will tell you if you have outdated plugins running in your Firefox browser.


  • Backup
  • Hardware issues, malware, fire, lightning strike: There is a long list of different ways to loose all your data. Back up your files regularly. Use the windows internal backup function or a third party tool and save your data onto an external hard drive, cloud storage, optical media like CDs or DVDs or (if available) a professional network backup system.
  • Behaviour
  • The commonest error when using a computer is "error 80" - what means that the error is located about 80cm in front of the monitor. This is a common joke between IT support technicians but it shows that all the safety mechanisms won´t help if you aren´t careful enough.
    • While surfing the internet, don´t click on anything you don´t know. In the worst case, it infects your system with malware.

    • Watch your step in social networks! Many cyber criminals use them to spread malware, mine personal pata (to be sold to advertising companies, for example) or simply do damage to other users. Even if a received hyperlink within a message seems to be coming from one of your friends, have a closer look. In addition, don´t click everything.

    • When installing software, have a look to each of the setup windows and uncheck any additional toolbars or free programs that may be offered additionally. Most of today´s setup procedures contain potentially unwanted programs so keep them off your system.

    • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
    • They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI