This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Something seems to be locking or blocking IE and Firefox/Thunderbird. IE is totally unresponsive and crashes.  FF/Thunderbird will error out saying  Firefox cannot use the profile "default" because it is in use.

 
To continue, close the running instance of Firefox or choose a different profile
 
Hope you can help
Ed
 
Firefox cannot use the profile "default" because it is in use.
 
To continue, close the running instance of Firefox or choose a different profile

 

Firefox cannot use the profile "default" because it is in use.
 
To continue, close the running instance of Firefox or choose a different profile
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-03-24 18:48:16
—————————–
18:48:16.547    OS Version: Windows 6.1.7601 Service Pack 1
18:48:16.548    Number of processors: 2 586 0x1706
18:48:16.549    ComputerName: DADS-PC  UserName: Dads
18:48:53.148    Initialize success
18:48:53.415    VM: initialized successfully
18:48:53.417    VM: Intel CPU BiosDisabled 
18:51:00.776    AVAST engine defs: 15032401
18:53:56.776    Disk 0  \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T1L0-8
18:53:56.778    Disk 0 Vendor: ST3160318AS HP34 Size: 152627MB BusType: 3
18:53:56.780    Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-2
18:53:56.783    Disk 1 Vendor: ST380815AS 3.CHH Size: 76319MB BusType: 3
18:53:56.894    Disk 1 MBR read successfully
18:53:56.897    Disk 1 MBR scan
18:53:56.913    Disk 1 Windows 7 default MBR code
18:53:56.924    Disk 1 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
18:53:56.927    Disk 1 default boot code
18:53:56.933    Disk 1 Partition 2 00     07    HPFS/NTFS NTFS        76217 MB offset 206848
18:53:56.939    Disk 1 scanning sectors +156299264
18:53:57.019    Disk 1 scanning C:\Windows\system32\drivers
18:54:10.838    Service scanning
18:54:14.451    Service BHDrvx86 C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\BASHDefs\20150321.001\BHDrvx86.sys **LOCKED** 5
18:54:15.230    Service ccSet_N360 C:\Windows\system32\drivers\N360\1506000.020\ccSetx86.sys **LOCKED** 5
18:54:17.303    Service eeCtrl C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys **LOCKED** 5
18:54:17.657    Service EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys **LOCKED** 5
18:54:20.383    Service IDSVix86 C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\IPSDefs\20150323.001\IDSvix86.sys **LOCKED** 5
18:54:23.900    Service NAVENG C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20150324.003\NAVENG.SYS **LOCKED** 5
18:54:24.102    Service NAVEX15 C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20150324.003\NAVEX15.SYS **LOCKED** 5
18:54:29.335    Service SRTSPX C:\Windows\system32\drivers\N360\1506000.020\SRTSPX.SYS **LOCKED** 5
18:54:30.267    Service SymDS C:\Windows\system32\drivers\N360\1506000.020\SYMDS.SYS **LOCKED** 5
18:54:30.403    Service SymEvent C:\Windows\system32\Drivers\SYMEVENT.SYS **LOCKED** 5
18:54:30.482    Service SymIRON C:\Windows\system32\drivers\N360\1506000.020\Ironx86.SYS **LOCKED** 5
18:54:30.561    Service SymNetS C:\Windows\System32\Drivers\N360\1506000.020\SYMNETS.SYS **LOCKED** 5
18:54:35.568    Modules scanning
18:54:35.576    Disk 1 trace - called modules:
18:54:35.581    
18:54:35.973    AVAST engine scan C:\Windows
18:54:38.365    AVAST engine scan C:\Windows\system32
18:57:51.433    AVAST engine scan C:\Windows\system32\drivers
18:58:03.927    AVAST engine scan C:\Users\Dads
19:19:30.406    AVAST engine scan C:\ProgramData
19:22:19.268    Disk 1 statistics 3263061/0/0 @ 1.21 MB/s
19:22:19.276    Scan finished successfully
19:35:39.442    Disk 1 MBR has been saved successfully to "C:\Users\Dads\Downloads\MBR.dat"
19:35:39.446    The log file has been saved successfully to "C:\Users\Dads\Downloads\aswMBR.txt"
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by [removed] (administrator) on DADS-PC on 24-03-2015 19:41:20
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files\Intel\AMT\atchksrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX86\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files\Canon\IJPLM\ijplmsvc.exe
(Intel) C:\Program Files\Intel\AMT\LMS.exe
(Symantec Corporation) C:\Program Files\Norton Security Suite\Engine\21.6.0.32\n360.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe
(Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Intel) C:\Program Files\Intel\AMT\UNS.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Symantec Corporation) C:\Program Files\Norton Security Suite\Engine\21.6.0.32\n360.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
() C:\Program Files\Traysoft\PhoneTray\PhoneTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(CANON INC.) C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [1282048 2007-08-01] (Analog Devices, Inc.)
HKLM\…\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [542632 2013-01-31] (Lavasoft)
HKLM\…\Run: [PhoneTray] => C:\Program Files\Traysoft\PhoneTray\PhoneTray.exe [445680 2009-05-28] ()
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\…\Run: [CanonQuickMenu] => C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [1284680 2014-01-17] (CANON INC.)
HKLM\…\Run: [IJNetworkScannerSelectorEX] => C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [438888 2014-01-15] (CANON INC.)
HKU\S-1-5-21-4147716943-903763243-1518506203-1001\…\Run: [DellSystemDetect] => C:\Users\Dads\AppData\Local\Apps\2.0\VDQ09968.RT6\B1VH5O9O.NEQ\dell..tion_e30b47f5d4a30e9e_0005.000e_4ab3a7332dd76702\DellSystemDetect.exe [283432 2015-02-11] (Dell)
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\…\AppCertDlls: [x64] -> c:\program files\settings manager\systemk\x64\sysapcrt.dll
ShellIconOverlayIdentifiers: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Security Suite\Engine\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Security Suite\Engine\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Security Suite\Engine\21.6.0.32\buShell.dll (Symantec Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-4147716943-903763243-1518506203-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-4147716943-903763243-1518506203-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/en-us/?ocid=U220DHP&pc;=U220
HKU\S-1-5-21-4147716943-903763243-1518506203-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKLM -> DefaultScope {253C47C6-A263-4056-AFAD-6046361B8A2A} URL = 
SearchScopes: HKU\S-1-5-21-4147716943-903763243-1518506203-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?FORM=U220DF&PC;=U220&q;={searchTerms}&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-4147716943-903763243-1518506203-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?FORM=U220DF&PC;=U220&q;={searchTerms}&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-4147716943-903763243-1518506203-1001 -> {253C47C6-A263-4056-AFAD-6046361B8A2A} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3279412&CUI;=UN38360687178701164&UM;=2
SearchScopes: HKU\S-1-5-21-4147716943-903763243-1518506203-1001 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://lavasoft.blekko.com/ws/?source=f439e2c0&tbp;=rbox&toolbarid;=adawaretb&u;=05F360D528F6F62CE20CA85178657903&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-4147716943-903763243-1518506203-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = http://www.default-search.net/search?sid=492&aid;=100&itype;=a&ver;=12692&tm;=324&src;=ds&p;={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
BHO: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files\PDF Architect\PDFIEHelper.dll [2013-04-08] (pdfforge GmbH)
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security Suite\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton Security Suite\Engine\21.6.0.32\IPS\IPSBHO.DLL [2014-08-25] (Symantec Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-20] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll [2011-05-13] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-02-10] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-02-10] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-20] (Oracle Corporation)
Toolbar: HKLM - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll [2013-04-08] (pdfforge GmbH)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\21.6.0.32\coIEPlg.dll [2014-09-20] (Symantec Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF ProfilePath: C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\nr7m95mu.Default User99
FF Homepage: hxxp://news.yahoo.com/science/|about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-04] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-20] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-20] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2012-02-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-10-13] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-10-13] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\vqy5f7kh.default\user.js [2014-10-05]
FF user.js: detected! => C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\4st1tlx8.Default User 3\user.js [2014-10-05]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2012-10-19] (Coupons, Inc.)
FF SearchPlugin: C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\vqy5f7kh.default\searchplugins\bingp.xml [2013-08-28]
FF Extension: Lavasoft Search Plugin - C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\vqy5f7kh.default\Extensions\jid1-yZwVFzbsyfMrqQ@jetpack [2013-04-24]
FF Extension: PlusWinks - C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\vqy5f7kh.default\Extensions\[removed] [2015-01-24]
FF Extension: Ghostery - C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\4st1tlx8.Default User 3\Extensions\[removed] [2014-08-02]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-09-13]
FF HKLM\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2015-03-24]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.msn.com/
CHR StartupUrls: Default -> "hxxp://www.msn.com/en-us"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs;_ri={google:suggestRid}&xssi;=t&q;={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-22]
CHR Extension: (Google Docs) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-03]
CHR Extension: (Google Drive) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-03]
CHR Extension: (YouTube) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-03]
CHR Extension: (Google Search) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-03]
CHR Extension: (Google Sheets) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-22]
CHR Extension: (YouTube Center) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\gabnjlibfmlilpljjkkbkebfaopgpjmk [2013-09-02]
CHR Extension: (Norton Identity Safe) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2014-08-12]
CHR Extension: (Do Not Disturb!) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilnddakjdkpofoablibghfikpeknhbia [2014-04-03]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-10]
CHR Extension: (Norton Security Toolbar) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2013-03-03]
CHR Extension: (Google Wallet) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-30]
CHR Extension: (ArcadeFrontier) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\peglehonblabfemopkgmfcpofbchegcl [2013-08-26]
CHR Extension: (Gmail) - C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-03]
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [iolllphbfidpiigenecjjflaefapfnef] - C:\Users\Dads\AppData\Local\CRE\iolllphbfidpiigenecjjflaefapfnef.crx [2013-10-20]
CHR HKLM\…\Chrome\Extension: [lfffjahnfbocnaooecgijfnbpcfekoik] - C:\ProgramData\adawaretb\shortcuts\chrome\adawaretb.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [lgnbhdnimikkoodkogjlcllngimhlapp] - C:\Program Files\FTDownloader.com\FTDownloader10.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files\Norton Security Suite\Engine\21.6.0.32\Exts\Chrome.crx [2015-03-13]
CHR HKU\S-1-5-21-4147716943-903763243-1518506203-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [iolllphbfidpiigenecjjflaefapfnef] - C:\Users\Dads\AppData\Local\CRE\iolllphbfidpiigenecjjflaefapfnef.crx [2013-10-20]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 atchksrv; C:\Program Files\Intel\AMT\atchksrv.exe [176128 2009-12-01] (Intel Corporation) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX86\OfficeClickToRun.exe [1843896 2015-02-10] (Microsoft Corporation)
R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [1947344 2015-02-26] (Dell Inc.)
R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [184016 2015-02-26] (Dell Inc.)
R2 HPSLPSVC; C:\Users\Dads\AppData\Local\Temp\7zS513B\hpslpsvc32.dll [701288 2013-07-19] (Hewlett-Packard Co.)
R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
R2 LMS; C:\Program Files\Intel\AMT\LMS.exe [102400 2009-12-01] (Intel) [File not signed]
R2 N360; C:\Program Files\Norton Security Suite\Engine\21.6.0.32\N360.exe [265040 2014-10-02] (Symantec Corporation)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [19288 2015-03-04] (Dell Inc.)
R2 UNS; C:\Program Files\Intel\AMT\UNS.exe [2519040 2009-12-01] (Intel) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-26] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 BHDrvx86; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\BASHDefs\20150321.001\BHDrvx86.sys [1164504 2015-03-09] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1506000.020\ccSetx86.sys [127064 2013-09-25] (Symantec Corporation)
R3 DDDriver; C:\Windows\System32\drivers\DDDriver32Dcsa.sys [20688 2015-01-30] (Dell Computer Corporation)
R3 DellProf; C:\Windows\System32\drivers\DellProf.sys [19984 2015-01-30] (Dell Computer Corporation)
R3 e1express; C:\Windows\System32\DRIVERS\e1e6232.sys [219352 2009-06-05] (Intel Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2015-03-12] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [111408 2015-03-12] (Symantec Corporation)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-04-24] (GFI Software)
R1 IDSVix86; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\IPSDefs\20150323.001\IDSvix86.sys [503512 2015-03-20] (Symantec Corporation)
R3 NAVENG; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20150324.003\NAVENG.SYS [95704 2015-03-22] (Symantec Corporation)
R3 NAVEX15; C:\Program Files\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20150324.003\NAVEX15.SYS [1636696 2015-03-22] (Symantec Corporation)
R1 SRTSP; C:\Windows\System32\Drivers\N360\1506000.020\SRTSP.SYS [664792 2014-08-25] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1506000.020\SRTSPX.SYS [32984 2014-08-25] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1506000.020\SYMDS.SYS [367704 2013-09-09] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1506000.020\SYMEFA.SYS [936152 2014-08-25] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2015-03-13] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1506000.020\Ironx86.SYS [209624 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360\1506000.020\SYMNETS.SYS [447704 2014-08-25] (Symantec Corporation)
S1 AntiLog32; \??\C:\Windows\system32\drivers\AntiLog32.sys [X]
S3 keycrypt; system32\DRIVERS\KeyCrypt32.sys [X]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-13] (Microsoft Corporation)
U3 aswMBR; \??\C:\Users\Dads\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Dads\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-03-24 19:41 - 2015-03-24 19:42 - 00023690 _____ () C:\Users\Dads\Downloads\FRST.txt
2015-03-24 19:39 - 2015-03-24 19:41 - 00000000 ____D () C:\FRST
2015-03-24 19:35 - 2015-03-24 19:35 - 00003400 _____ () C:\Users\Dads\Downloads\aswMBR.txt
2015-03-24 19:35 - 2015-03-24 19:35 - 00000512 _____ () C:\Users\Dads\Downloads\MBR.dat
2015-03-24 18:45 - 2015-03-24 18:45 - 01135104 _____ (Farbar) C:\Users\Dads\Downloads\FRST.exe
2015-03-24 18:38 - 2015-03-24 18:38 - 05198336 _____ (AVAST Software) C:\Users\Dads\Downloads\aswMBR.exe
2015-03-24 16:51 - 2015-03-24 16:53 - 00007727 _____ () C:\Windows\IE11_main.log
2015-03-24 16:51 - 2015-03-24 16:52 - 00000000 ___HD () C:\Windows\msdownld.tmp
2015-03-24 16:49 - 2015-03-24 16:49 - 31943336 _____ (Microsoft Corporation) C:\Users\Dads\Downloads\EIE11_EN-US_MCM_WIN7.EXE
2015-03-24 16:26 - 2013-10-01 19:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-03-24 16:26 - 2013-10-01 19:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-03-24 16:26 - 2013-10-01 19:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-03-24 16:26 - 2013-10-01 19:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-03-24 16:26 - 2013-10-01 19:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-03-24 16:26 - 2013-10-01 18:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-03-24 16:26 - 2013-10-01 18:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-03-24 16:26 - 2013-10-01 18:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-03-24 16:26 - 2013-10-01 18:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-03-24 16:26 - 2013-10-01 17:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-03-24 16:26 - 2013-10-01 17:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-03-24 16:26 - 2013-10-01 15:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-03-24 16:26 - 2012-08-23 09:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-24 16:26 - 2012-08-23 09:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2015-03-24 16:26 - 2012-08-23 08:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-24 16:26 - 2012-08-23 06:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2015-03-24 16:26 - 2012-08-23 05:08 - 02739712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-22 23:02 - 2015-03-22 23:02 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
2015-03-22 22:50 - 2015-03-22 22:51 - 41090240 _____ () C:\Users\Dads\Downloads\Firefox Setup 36.0.4.exe
2015-03-13 16:34 - 2015-03-13 17:13 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared
2015-03-13 16:34 - 2015-03-13 16:34 - 00142936 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT.SYS
2015-03-13 16:34 - 2015-03-13 16:34 - 00008194 _____ () C:\Windows\system32\Drivers\SYMEVENT.CAT
2015-03-13 16:33 - 2015-03-13 16:51 - 00002369 _____ () C:\Users\Public\Desktop\Norton Security Suite.lnk
2015-03-13 16:31 - 2015-03-13 16:52 - 00000000 ____D () C:\Windows\system32\Drivers\N360
2015-03-13 16:31 - 2015-03-13 16:51 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Suite
2015-03-13 16:31 - 2015-03-13 16:31 - 00000000 ____D () C:\Program Files\Norton Security Suite
2015-03-10 22:04 - 2015-03-06 00:15 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-10 22:04 - 2015-03-06 00:15 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-10 22:04 - 2015-03-06 00:10 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-10 22:04 - 2015-03-06 00:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-10 22:04 - 2015-03-06 00:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-10 22:04 - 2015-03-06 00:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-10 22:04 - 2015-03-06 00:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-10 22:04 - 2015-03-06 00:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-10 22:04 - 2015-03-06 00:10 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-10 22:04 - 2015-03-06 00:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-10 22:04 - 2015-03-06 00:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-10 22:04 - 2015-03-06 00:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-10 22:04 - 2015-03-06 00:10 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-10 22:04 - 2015-03-06 00:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-10 22:04 - 2015-03-06 00:09 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-10 22:04 - 2015-03-06 00:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-10 22:04 - 2015-03-06 00:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-10 22:04 - 2015-03-06 00:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-10 22:04 - 2015-02-25 22:11 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-10 22:04 - 2015-02-23 21:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-10 22:04 - 2015-02-20 19:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-10 22:04 - 2015-02-20 19:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-10 22:04 - 2015-02-20 19:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-10 22:04 - 2015-02-20 19:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-10 22:04 - 2015-02-20 18:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-10 22:04 - 2015-02-19 23:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-10 22:04 - 2015-02-19 23:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-10 22:04 - 2015-02-19 23:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-10 22:04 - 2015-02-19 23:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-10 22:04 - 2015-02-19 22:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-10 22:04 - 2015-02-19 21:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-10 22:04 - 2015-02-19 21:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-10 22:04 - 2015-02-19 21:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-10 22:04 - 2015-02-19 21:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-10 22:04 - 2015-02-19 21:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-10 22:04 - 2015-02-19 21:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-10 22:04 - 2015-02-19 21:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-10 22:04 - 2015-02-19 21:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-10 22:04 - 2015-02-19 21:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-10 22:04 - 2015-02-19 20:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-10 22:04 - 2015-02-19 20:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-10 22:04 - 2015-02-19 20:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-10 22:04 - 2015-02-19 20:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-10 22:04 - 2015-02-19 20:50 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-10 22:04 - 2015-02-19 20:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-10 22:04 - 2015-02-19 20:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-10 22:04 - 2015-02-19 20:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-10 22:04 - 2015-02-19 20:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-10 22:04 - 2015-02-19 20:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-10 22:04 - 2015-02-19 20:24 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-10 22:04 - 2015-02-19 20:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-10 22:04 - 2015-02-19 20:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-10 22:04 - 2015-02-19 19:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-10 22:04 - 2015-02-19 19:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-10 22:04 - 2015-02-13 00:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-10 22:04 - 2015-02-03 21:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-10 22:04 - 2015-02-02 22:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-10 22:04 - 2015-02-02 22:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-10 22:04 - 2015-01-16 21:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-10 22:03 - 2015-02-02 22:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-03-10 22:03 - 2015-02-02 22:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-10 22:03 - 2015-02-02 22:16 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-03-10 22:03 - 2015-02-02 22:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-10 22:03 - 2015-02-02 22:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-03-10 22:03 - 2015-02-02 22:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-03-10 22:03 - 2015-02-02 22:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-03-10 22:03 - 2015-02-02 22:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-03-10 22:03 - 2015-02-02 22:11 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-10 22:03 - 2015-02-02 22:11 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-03-10 22:03 - 2015-02-02 22:11 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-03-10 22:03 - 2015-02-02 22:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-03-10 22:03 - 2015-02-02 22:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-03-10 22:03 - 2015-02-02 22:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-03-10 22:03 - 2015-02-02 22:11 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-03-10 22:03 - 2015-02-02 22:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-03-10 22:03 - 2015-02-02 22:10 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-03-10 22:03 - 2015-02-02 22:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-03-10 22:03 - 2015-02-02 22:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-10 22:03 - 2015-02-02 22:00 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-03-10 22:03 - 2015-02-02 21:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-03-10 22:03 - 2015-01-30 18:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-10 22:03 - 2014-10-31 17:22 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-03-05 22:01 - 2015-03-05 22:01 - 00000000 __HDC () C:\ProgramData\{6AACA38B-2810-4B47-BDEC-D7A1F38B1531}
2015-03-04 21:59 - 2015-03-10 21:49 - 00000000 ____D () C:\Users\Dads\AppData\Local\FluxSoftware
2015-03-03 15:49 - 2015-01-08 21:48 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2015-03-03 15:49 - 2015-01-08 21:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
2015-03-03 15:49 - 2015-01-08 21:48 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
2015-03-01 13:14 - 2015-03-01 13:14 - 00000000 ____D () C:\ProgramData\Canon IJ Network Tool
2015-03-01 13:13 - 2015-03-01 13:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG6600 series User Registration
2015-03-01 13:07 - 2015-03-01 13:08 - 52203096 _____ () C:\Users\Dads\Desktop\win-mg6600-1_0-ucd (1).exe
2015-03-01 12:39 - 2015-03-01 12:39 - 00000000 ___HD () C:\ProgramData\CanonIJETV
2015-03-01 12:29 - 2015-03-01 12:29 - 00000000 ____D () C:\Windows\system32\STRING
2015-03-01 12:29 - 2014-03-17 20:15 - 00380928 _____ (CANON INC.) C:\Windows\system32\CNMNPPM.DLL
2015-03-01 12:29 - 2014-03-17 20:15 - 00035840 _____ (CANON INC.) C:\Windows\system32\CNMNPUI.DLL
2015-02-26 18:09 - 2015-02-26 18:09 - 00010275 _____ () C:\ProgramData\regid.1996-01.com.cdesoftware_B72F2639-62F8-4392-957D-5680306D8632.swidtag
2015-02-25 04:01 - 2015-01-08 18:44 - 00419936 _____ () C:\Windows\system32\locale.nls
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-03-24 19:36 - 2012-07-07 00:03 - 01437226 _____ () C:\Windows\WindowsUpdate.log
2015-03-24 19:27 - 2013-03-12 16:53 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-24 19:20 - 2013-03-03 19:04 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-24 19:15 - 2014-10-21 19:15 - 00001328 _____ () C:\Windows\Tasks\DIS.job
2015-03-24 19:14 - 2014-10-21 19:14 - 00001682 _____ () C:\Windows\Tasks\LWBVSUPC.job
2015-03-24 17:03 - 2009-07-13 23:34 - 00023056 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-24 17:03 - 2009-07-13 23:34 - 00023056 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-24 16:55 - 2014-10-22 11:52 - 00004782 _____ () C:\Windows\setupact.log
2015-03-24 16:55 - 2013-04-24 18:06 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection
2015-03-24 16:55 - 2013-03-03 19:04 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-24 16:55 - 2009-07-13 23:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-24 16:31 - 2009-07-13 21:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-24 16:30 - 2014-10-22 11:52 - 01174450 _____ () C:\Windows\PFRO.log
2015-03-24 16:30 - 2013-03-03 20:13 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-03-23 23:05 - 2014-09-06 00:03 - 00000000 ____D () C:\Users\Public\Documents\BLS2015
2015-03-23 17:26 - 2012-02-08 13:47 - 00781790 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-23 01:22 - 2013-03-03 19:04 - 00002136 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-22 22:52 - 2015-02-12 18:25 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-22 22:52 - 2013-03-03 20:13 - 00001124 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-03-22 22:52 - 2013-03-03 20:13 - 00001112 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-03-22 21:31 - 2014-10-24 09:02 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-22 19:30 - 2013-03-03 17:41 - 00000000 ____D () C:\Users\Dads
2015-03-22 19:30 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\system32\wfp
2015-03-22 19:29 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-03-22 19:28 - 2015-02-11 18:13 - 00000000 ____D () C:\Users\Dads\Desktop\Dell Updates
2015-03-22 19:28 - 2015-01-20 23:30 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
2015-03-22 19:28 - 2014-10-21 19:14 - 00000000 ____D () C:\Users\Dads\AppData\Local\Kromtech
2015-03-22 19:28 - 2014-10-19 13:42 - 00000000 ____D () C:\Users\Dads\AppData\Local\Microsoft Help
2015-03-22 19:28 - 2014-10-13 20:17 - 00000000 ____D () C:\Users\Dads\Desktop\Microsoft Office 2013
2015-03-22 19:28 - 2014-10-05 20:40 - 00000000 ____D () C:\Program Files\Web Protect
2015-03-22 19:28 - 2014-06-19 11:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-03-22 19:28 - 2014-06-14 05:59 - 00000000 ____D () C:\Users\Dads\Desktop\OpenOffice 4.1.0 (en-US) Installation Files
2015-03-22 19:28 - 2014-05-10 16:50 - 00000000 ____D () C:\Users\Dads\Downloads\RockAuto Order Confirmation for Order 22562921_files
2015-03-22 19:28 - 2013-12-01 18:10 - 00000000 ____D () C:\Users\Dads\AppData\Local\HP
2015-03-22 19:28 - 2013-08-26 13:38 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ArcadeFrontier
2015-03-22 19:28 - 2013-07-11 17:25 - 00000000 ____D () C:\Users\Dads\AppData\Local\PutLockerDownloader
2015-03-22 19:28 - 2013-06-01 17:48 - 00000000 ____D () C:\Users\Dads\Downloads\Home Policy Details - My Farmers   Farmers®_files
2015-03-22 19:28 - 2013-05-11 13:13 - 00000000 ____D () C:\Users\Dads\Downloads\PCIE_Setup_78050
2015-03-22 19:28 - 2013-05-11 11:07 - 00000000 ____D () C:\Users\Dads\AppData\Local\Traysoft_Inc
2015-03-22 19:28 - 2013-05-02 16:19 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\pdf995
2015-03-22 19:28 - 2013-05-02 16:15 - 00000000 ____D () C:\ProgramData\pdf995
2015-03-22 19:28 - 2013-03-29 17:04 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\vlc
2015-03-22 19:28 - 2013-03-20 22:53 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-22 19:28 - 2013-03-04 17:46 - 00000000 ____D () C:\Users\Dads\Desktop\Dads Stuff
2015-03-22 19:28 - 2013-03-04 00:50 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\Thunderbird
2015-03-22 19:28 - 2013-03-03 22:10 - 00000000 ____D () C:\Users\Dads\AppData\Local\Downloaded Installations
2015-03-22 19:28 - 2013-03-03 19:22 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
2015-03-22 19:28 - 2013-03-03 19:21 - 00000000 ____D () C:\ProgramData\Norton
2015-03-22 19:28 - 2013-03-03 19:19 - 00000000 ____D () C:\Users\Dads\AppData\Local\White_Sky,_Inc
2015-03-22 19:28 - 2013-03-03 19:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-03-22 19:28 - 2013-03-03 17:41 - 00000000 ___RD () C:\Users\Dads\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-03-22 19:28 - 2013-03-03 17:41 - 00000000 ___RD () C:\Users\Dads\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-22 19:27 - 2013-03-06 17:48 - 00000000 ____D () C:\Users\Dads\XP Share
2015-03-22 19:27 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\registration
2015-03-22 19:26 - 2013-03-10 11:20 - 00000000 ____D () C:\Users\Dads\Program Set up Files
2015-03-22 19:25 - 2015-01-20 23:37 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\PCDr
2015-03-22 19:25 - 2014-06-17 07:15 - 00000000 ____D () C:\Users\Dads\Documents\Bowling Doc's
2015-03-22 19:25 - 2013-12-16 18:37 - 00000000 ____D () C:\Users\Dads\Documents\Fax
2015-03-22 19:25 - 2013-09-07 13:58 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\OpenOffice
2015-03-22 19:25 - 2013-05-18 08:56 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\Strongvault
2015-03-22 19:25 - 2013-03-13 19:05 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\Intuit
2015-03-22 19:25 - 2013-03-10 14:06 - 00000000 ____D () C:\Users\Dads\Documents\Brandi's Stuff
2015-03-22 19:25 - 2013-03-06 18:30 - 00000000 ____D () C:\Users\Dads\Documents\Mom's Stuff
2015-03-22 19:25 - 2013-03-04 17:42 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\OpenOffice.org
2015-03-22 19:25 - 2013-03-03 20:14 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\Mozilla
2015-03-22 19:25 - 2013-03-03 19:02 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\Macromedia
2015-03-22 19:25 - 2013-03-03 19:02 - 00000000 ____D () C:\Users\Dads\AppData\Roaming\Adobe
2015-03-22 19:24 - 2013-03-03 20:14 - 00000000 ____D () C:\Users\Dads\AppData\Local\Mozilla
2015-03-22 19:24 - 2013-03-03 19:03 - 00000000 ____D () C:\Users\Dads\AppData\Local\Google
2015-03-22 19:24 - 2013-03-03 17:41 - 00000000 ____D () C:\Users\Dads\AppData\Local\VirtualStore
2015-03-22 19:22 - 2013-03-03 19:03 - 00000000 ____D () C:\Users\Dads\AppData\Local\Apps\2.0
2015-03-17 14:29 - 2013-09-13 21:33 - 00000000 ____D () C:\Program Files\PDF Architect
2015-03-17 04:02 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-03-17 03:56 - 2014-10-13 20:15 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-03-13 16:32 - 2013-04-14 14:12 - 00161792 ___SH () C:\Users\Dads\Desktop\Thumbs.db
2015-03-13 16:31 - 2013-03-03 19:22 - 00001237 _____ () C:\Users\Dads\Desktop\Norton Installation Files.lnk
2015-03-12 11:01 - 2015-02-11 17:55 - 00000000 ____D () C:\ProgramData\SupportAssistAgent
2015-03-11 04:19 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\rescache
2015-03-11 03:18 - 2009-07-13 23:33 - 00479048 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-10 23:35 - 2013-08-14 03:05 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-10 23:27 - 2012-02-08 14:04 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-08 14:01 - 2013-05-02 16:15 - 00000060 _____ () C:\Windows\wpd99.drv
2015-03-03 17:08 - 2009-07-13 21:37 - 00000000 ____D () C:\Windows\tracing
2015-03-01 13:17 - 2015-02-17 21:59 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2015-03-01 13:16 - 2015-02-17 21:48 - 00000000 ____D () C:\Program Files\Canon
2015-03-01 13:14 - 2015-02-17 21:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2015-03-01 13:14 - 2009-07-13 21:37 - 00000000 __RSD () C:\Windows\Media
2015-02-28 19:34 - 2014-11-09 18:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDE Software Support Rescue
2015-02-28 19:34 - 2014-11-03 23:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDE Software
2015-02-28 19:34 - 2014-09-06 00:05 - 00001968 _____ () C:\Users\Public\Desktop\BLS-2015.lnk
2015-02-28 19:34 - 2014-09-06 00:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDE Software BLS-2015
2015-02-28 19:34 - 2014-09-06 00:03 - 00000000 ____D () C:\Program Files\BLS2015
2015-02-27 10:31 - 2012-07-07 00:07 - 00000000 ____D () C:\dell
2015-02-24 04:23 - 2012-02-08 13:54 - 00246920 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
 
==================== Files in the root of some directories =======
 
2014-09-01 03:18 - 2014-09-01 03:18 - 0002086 _____ () C:\Users\Dads\AppData\Roaming\DIS
2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\Dads\AppData\Roaming\LWBVSUPC
2014-06-08 06:46 - 2014-06-08 06:46 - 0019654 _____ () C:\Users\Dads\AppData\Roaming\UserTile.png
2014-06-15 19:43 - 2015-01-25 12:08 - 0007603 _____ () C:\Users\Dads\AppData\Local\Resmon.ResmonCfg
2013-12-01 18:11 - 2013-12-01 18:11 - 0000057 _____ () C:\ProgramData\Ament.ini
2013-03-13 19:04 - 2014-03-02 17:46 - 0000745 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2012-08-29 20:46 - 2012-08-29 20:46 - 0010105 _____ () C:\ProgramData\regid.1996-01.com.cdesoftware_39DD541E-C013-4B78-9FE1-F47F72A51B85.swidtag
2015-02-26 18:09 - 2015-02-26 18:09 - 0010275 _____ () C:\ProgramData\regid.1996-01.com.cdesoftware_B72F2639-62F8-4392-957D-5680306D8632.swidtag
 
Files to move or delete:
====================
C:\Users\Dads\26.05.03.EXE
C:\Users\Dads\3510 print driver.exe
C:\Users\Dads\Adaware_Installer.exe
C:\Users\Public\AlexaNSISPlugin.5812.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-03-15 00:32
 
==================== End Of Log ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by [removed] at 2015-03-24 19:42:26
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Norton Security Suite (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton Security Suite (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton Security Suite (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Ad-Aware Browsing Protection (HKLM\…\Ad-Aware Browsing Protection) (Version: 1.0.1.94 - Lavasoft)
Adobe AIR (HKLM\…\Adobe AIR) (Version: 3.7.0.1860 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Apple Application Support (HKLM\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
BLS-2013 CLIPART (HKLM\…\{59DC8EAC-786A-4041-8A3E-6541C54D63E5}) (Version: 25.2.6.1 - CDE Software)
BLS-2015 (HKLM\…\{E8B12E79-DB5F-4DDB-A27F-9B38C5667528}) (Version: 27.6.4.6282 - CDE Software)
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Canon Easy-WebPrint EX (HKLM\…\Easy-WebPrint EX) (Version: 1.5.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM\…\Canon_IJ_Network_Scanner_Selector_EX) (Version: 1.5.2.3 - Canon Inc.)
Canon IJ Network Tool (HKLM\…\Canon_IJ_Network_UTILITY) (Version: 3.5.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM\…\Canon_IJ_Scan_Utility) (Version: 1.1.10.15 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\…\CANONIJPLM100) (Version: 4.2.0 - Canon Inc.)
Canon MG6600 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6600_series) (Version: 1.00 - Canon Inc.)
Canon MG6600 series On-screen Manual (HKLM\…\Canon MG6600 series On-screen Manual) (Version: 7.7.0 - Canon Inc.)
Canon MG6600 series User Registration (HKLM\…\Canon MG6600 series User Registration) (Version:  - ‭Canon Inc.)
Canon My Image Garden (HKLM\…\Canon My Image Garden) (Version: 3.0.0 - Canon Inc.)
Canon My Image Garden Design Files (HKLM\…\Canon My Image Garden Design Files) (Version: 3.0.0 - Canon Inc.)
Canon My Printer (HKLM\…\CanonMyPrinter) (Version: 3.2.1 - Canon Inc.)
Canon Quick Menu (HKLM\…\CanonQuickMenu) (Version: 2.4.0 - Canon Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 4.17 - Piriform)
Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Data Vault (Version: 4.2.2.0 - Dell Inc.) Hidden
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.0.6584.52 - Dell)
Dell SupportAssistAgent (HKLM\…\{287348C8-8B47-4C36-AF28-441A3B7D8722}) (Version: 1.0.2.57295 - Dell)
Dell System Detect (HKU\S-1-5-21-4147716943-903763243-1518506203-1001\…\73f463568823ebbe) (Version: 5.14.0.9 - Dell)
Google Chrome (HKLM\…\Google Chrome) (Version: 41.0.2272.101 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
HPDiagnosticAlert (Version: 1.00.0001 - Microsoft) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
Intel(R) Management Engine Interface (HKLM\…\HECI) (Version:  - Intel Corporation)
Intel® Active Management Technology (HKLM\…\MESOL) (Version:  - Intel Corporation)
iTunes (HKLM\…\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
Java 8 Update 31 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 15.0.4701.1002 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM\…\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 36.0.4 (x86 en-US) (HKLM\…\Mozilla Firefox 36.0.4 (x86 en-US)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 31.3.0 - Mozilla)
Mozilla Thunderbird 31.3.0 (x86 en-US) (HKLM\…\Mozilla Thunderbird 31.3.0 (x86 en-US)) (Version: 31.3.0 - Mozilla)
Norton Security Suite (HKLM\…\N360) (Version: 21.6.0.32 - Symantec Corporation)
Office 15 Click-to-Run Extensibility Component (Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (Version: 15.0.4701.1002 - Microsoft Corporation) Hidden
OpenOffice 4.1.0 (HKLM\…\{C87EF11D-36E9-479D-9898-7541EA1E8A6A}) (Version: 4.10.9764 - Apache Software Foundation)
PCI Soft Voice SoftRing Modem with SmartCP (HKLM\…\CNXT_MODEM_PCI_HSF) (Version: 7.80.6.0 - Conexant Systems)
PDF Architect (HKLM\…\{064A929A-4DE8-40CF-A901-BD40C14E4D25}) (Version: 1.1.83.9982 - pdfforge GmbH)
Pdf995 (HKLM\…\Pdf995) (Version:  - )
PDFCreator (HKLM\…\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.1 - pdfforge)
PhoneTray Free (HKLM\…\PhoneTray) (Version: 1.35 - Traysoft Inc.)
SoundMAX (HKLM\…\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 6.10.1.5491 - Analog Devices)
TurboTax 2012 (HKLM\…\TurboTax 2012) (Version: 2012.0 - Intuit, Inc)
TurboTax 2013 (HKLM\…\TurboTax 2013) (Version: 2013.0 - Intuit, Inc)
Windows Live Essentials (HKLM\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
XFINITY Caller ID (HKLM\…\com.comcast.callerid.13A1FA90F0FC9DC009FB0956ADD0F13F8608561B.1) (Version: 3.1.38 - Comcast Cable Communications Management LLC)
XFINITY Caller ID (Version: 3.1.38 - Comcast Cable Communications Management LLC) Hidden
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
 
==================== Restore Points  =========================
 
22-03-2015 13:29:32 Windows Backup
22-03-2015 15:04:33 Restore Operation
24-03-2015 16:24:33 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:04 - 2009-06-10 16:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {160274F5-08E0-4360-B708-31F203FC0E61} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [2015-03-04] (Dell Inc.)
Task: {2A5801F8-461A-4283-8311-C4F8A74546D0} - System32\Tasks\Norton Security Suite\Norton Error Processor => C:\Program Files\Norton Security Suite\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {3981FAB2-5552-4CB6-97BF-2EF8BE15F458} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX86\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
Task: {3D0A2D10-F525-497A-A1D7-1EF485B26509} - System32\Tasks\HP AR Program Upload - 100ca3b6c36d464489a8ae72564aec6e66321d2390dc46f7b476449fcf6caa98 => C:\Program Files\HP\HP Deskjet 3510 series\bin\HPRewards.exe
Task: {43B9FD23-312D-46B5-BC83-D2D0E654CD34} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Security Suite\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation)
Task: {4DA12FF1-C020-460B-A608-CA59C0103B43} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2015-02-03] (PC-Doctor, Inc.)
Task: {5692119C-58A9-4FB3-B108-EDD42C4C1819} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX86\OfficeC2RClient.exe [2015-02-10] (Microsoft Corporation)
Task: {75ACB7D2-9F66-4138-B32F-B65F3A6BF84A} - System32\Tasks\HP AR Program Upload - 7f1dffa5d71c476c86474e7206ae6ba842016558c3874d5eb3b26154d61e997a => C:\Program Files\HP\HP Deskjet 3510 series\bin\HPRewards.exe
Task: {78E63CEE-7936-491D-A75C-B10B4FD30F7D} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-02-03] (PC-Doctor, Inc.)
Task: {7A4E5388-3F2C-4C21-AD48-0BF619EF2442} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-03] (Google Inc.)
Task: {83575147-0FC4-47FB-9095-F25055CBDBC8} - System32\Tasks\DIS => C:\Users\Dads\AppData\Roaming\DIS.exe <==== ATTENTION
Task: {9C107829-8A08-4813-8AAF-DAFC6BE1769E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-03] (Google Inc.)
Task: {A1232ACF-E0BA-415E-9C39-AB47C122262E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {A949DC0C-CA31-40CF-96A2-3E4E2BEE5CD4} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04] (Adobe Systems Incorporated)
Task: {B0D2E406-6E04-4EB3-B14A-E10B400AB693} - System32\Tasks\HP AR Program Upload - dead7fc0c55d44f98bf63d724e8fb72de46fb58673e543eb80caac63154a7c7b => C:\Program Files\HP\HP Deskjet 3510 series\bin\HPRewards.exe
Task: {B56382F6-F19D-4876-BC1C-C367CECCFFAC} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {B635ABB1-EBA1-4FD1-9925-07B832C82EC8} - \BackgroundContainer Startup Task No Task File <==== ATTENTION
Task: {C73A485E-F452-4ADB-ACB3-885632EAC025} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {DE92371E-83A5-46AE-8261-AB8EBBFE6744} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2015-02-10] (Microsoft Corporation)
Task: {E24305E8-BAE4-4ACE-97ED-199B886955A2} - System32\Tasks\{630A0978-4B00-499A-8E40-A6F0E42DDFE4} => pcalua.exe -a "C:\Users\Dads\Program Set up Files\pdf995\setup.exe" -d "C:\Users\Dads\Program Set up Files\pdf995"
Task: {E4A7F9D2-C4A4-4EA9-B8F0-936B55EEE09E} - System32\Tasks\LWBVSUPC => C:\Users\Dads\AppData\Roaming\LWBVSUPC.exe <==== ATTENTION
Task: {F3CA6F91-8D05-4D2E-B46E-75F2E7E76C9A} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {F76C1CE5-BE59-4107-883E-DD1FF91ED8A5} - System32\Tasks\hpUrlLauncher.exe_{E32FEA22-50E8-4674-B281-9090E138F080} => C:\Program Files\HP\HP Deskjet 3510 series\Bin\utils\hpUrlLauncher.exe
Task: {F8456109-44DD-48DA-80CA-7D247116B49A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-02-03] (Microsoft Corporation)
Task: {FDA40638-8C43-4E44-93DE-2B561885EE81} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-02-03] (Microsoft Corporation)
Task: {FE73B08E-6BA4-4F18-A3EC-229406432959} - System32\Tasks\Norton Security Suite\Norton Error Analyzer => C:\Program Files\Norton Security Suite\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {FF6FBC9F-DD83-4B00-A2CF-B4174ACC217F} - System32\Tasks\HP AR Program Upload - 45950622f75e4e5d9791f20e4817e44b58753e51f5444903b8772d365ab1762c => C:\Program Files\HP\HP Deskjet 3510 series\bin\HPRewards.exe
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DIS.job => C:\Users\Dads\AppData\Roaming\DIS.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\LWBVSUPC.job => C:\Users\Dads\AppData\Roaming\LWBVSUPC.exe <==== ATTENTION
 
==================== Loaded Modules (whitelisted) ==============
 
2013-05-02 16:14 - 2013-05-02 16:16 - 00036864 _____ () C:\Windows\System32\pdf995mon.dll
2014-10-11 13:06 - 2014-10-11 13:06 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-03-17 03:54 - 2015-01-27 09:13 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
2014-10-13 20:15 - 2014-05-20 02:11 - 00080040 _____ () C:\Program Files\Microsoft Office 15\ClientX86\ApiClient.dll
2015-02-17 22:06 - 2013-06-28 16:28 - 00084616 _____ () C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
2009-05-28 19:44 - 2009-05-28 19:44 - 00445680 _____ () C:\Program Files\Traysoft\PhoneTray\PhoneTray.exe
2015-01-11 21:21 - 2014-02-10 13:44 - 04592128 _____ () C:\Users\Dads\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
2015-01-11 21:21 - 2014-02-10 13:44 - 00112128 _____ () C:\Users\Dads\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll
2015-03-23 01:22 - 2015-03-14 05:12 - 09278792 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.101\pdf.dll
2015-03-23 01:22 - 2015-03-14 05:12 - 14974280 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.101\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\pcwatch.sys => ""="Driver" <==== ATTENTION
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MyOSProtect => ""="service" <==== ATTENTION
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\pcwatch.sys => ""="Driver" <==== ATTENTION
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-4147716943-903763243-1518506203-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Dads\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-4147716943-903763243-1518506203-500 - Administrator - Disabled)
Dads (S-1-5-21-4147716943-903763243-1518506203-1001 - Administrator - Enabled) => C:\Users\Dads
Guest (S-1-5-21-4147716943-903763243-1518506203-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-4147716943-903763243-1518506203-1003 - Limited - Enabled)
 
==================== Faulty Device Manager Devices =============
 
Name: AntiLog32
Description: AntiLog32
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: AntiLog32
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/24/2015 07:39:04 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (1672) WebCacheLocal: An attempt to open the file "C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read / write access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (03/24/2015 07:38:54 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (1672) WebCacheLocal: An attempt to open the file "C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.chk" for read / write access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (03/24/2015 07:38:41 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (1672) WebCacheLocal: An attempt to open the file "C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read / write access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (03/24/2015 07:38:31 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (1672) WebCacheLocal: An attempt to open the file "C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.chk" for read / write access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (03/24/2015 06:49:47 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (1672) WebCacheLocal: An attempt to open the file "C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read / write access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (03/24/2015 06:49:37 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (1672) WebCacheLocal: An attempt to open the file "C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.chk" for read / write access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (03/24/2015 06:49:25 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (1672) WebCacheLocal: An attempt to open the file "C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read / write access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (03/24/2015 06:49:15 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (1672) WebCacheLocal: An attempt to open the file "C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.chk" for read / write access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (03/24/2015 05:55:40 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (1672) WebCacheLocal: An attempt to open the file "C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read / write access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (03/24/2015 05:55:30 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (1672) WebCacheLocal: An attempt to open the file "C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.chk" for read / write access failed with system error 5 (0x00000005): "Access is denied. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
 
System errors:
=============
Error: (03/24/2015 04:56:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (03/24/2015 04:32:12 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (03/22/2015 10:25:47 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (03/22/2015 07:32:04 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The HomeGroup Listener service terminated with service-specific error %%-2147023143.
 
Error: (03/22/2015 07:31:27 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (03/22/2015 07:31:24 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
SRTSP
 
Error: (03/22/2015 07:30:23 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The Windows Firewall service terminated with service-specific error %%5.
 
Error: (03/22/2015 07:29:49 PM) (Source: SRTSP) (EventID: 4) (User: )
Description: Error loading virus definitions.
 
Error: (03/22/2015 07:12:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (03/22/2015 03:09:07 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The HomeGroup Listener service terminated with service-specific error %%-2147023143.
 
 
Microsoft Office Sessions:
=========================
Error: (03/24/2015 07:39:04 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost1672WebCacheLocal: C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.log-1032 (0xfffffbf8)5 (0x00000005)Access is denied.
 
Error: (03/24/2015 07:38:54 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost1672WebCacheLocal: C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.chk-1032 (0xfffffbf8)5 (0x00000005)Access is denied.
 
Error: (03/24/2015 07:38:41 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost1672WebCacheLocal: C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.log-1032 (0xfffffbf8)5 (0x00000005)Access is denied.
 
Error: (03/24/2015 07:38:31 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost1672WebCacheLocal: C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.chk-1032 (0xfffffbf8)5 (0x00000005)Access is denied.
 
Error: (03/24/2015 06:49:47 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost1672WebCacheLocal: C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.log-1032 (0xfffffbf8)5 (0x00000005)Access is denied.
 
Error: (03/24/2015 06:49:37 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost1672WebCacheLocal: C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.chk-1032 (0xfffffbf8)5 (0x00000005)Access is denied.
 
Error: (03/24/2015 06:49:25 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost1672WebCacheLocal: C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.log-1032 (0xfffffbf8)5 (0x00000005)Access is denied.
 
Error: (03/24/2015 06:49:15 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost1672WebCacheLocal: C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.chk-1032 (0xfffffbf8)5 (0x00000005)Access is denied.
 
Error: (03/24/2015 05:55:40 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost1672WebCacheLocal: C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.log-1032 (0xfffffbf8)5 (0x00000005)Access is denied.
 
Error: (03/24/2015 05:55:30 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost1672WebCacheLocal: C:\Users\Dads\AppData\Local\Microsoft\Windows\WebCache\V01.chk-1032 (0xfffffbf8)5 (0x00000005)Access is denied.
 
 
CodeIntegrity Errors:
===================================
  Date: 2015-02-17 22:47:25.010
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-02-17 22:40:00.714
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-02-17 22:40:00.388
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-02-17 22:36:20.189
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-02-17 22:36:16.517
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-02-17 22:32:21.436
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-10-23 16:34:54.727
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-10-23 16:31:53.808
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-10-23 16:31:53.117
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-10-23 16:31:28.983
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Ad-Aware Browsing Protection\adawarebp.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz
Percentage of memory in use: 60%
Total physical RAM: 2004.61 MB
Available physical RAM: 789.32 MB
Total Pagefile: 4009.23 MB
Available Pagefile: 2494.5 MB
Total Virtual: 2047.88 MB
Available Virtual: 1902.18 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:74.43 GB) (Free:19.74 GB) NTFS
Drive e: (System) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: (New Volume) (Fixed) (Total:149.05 GB) (Free:138.72 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: C7F98DD8)
Partition 1: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 74.5 GB) (Disk ID: 2DA00602)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=74.4 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================

 

Hi and welcome

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.
 
~~~~~~~~~~~~~

Running from C:\Users\[removed]\Downloads

It's best we move Farbar's to desktop.

Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\…\AppCertDlls: [x64] -> c:\program files\settings manager\systemk\x64\sysapcrt.dll
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-4147716943-903763243-1518506203-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {253C47C6-A263-4056-AFAD-6046361B8A2A} URL =
SearchScopes: HKU\S-1-5-21-4147716943-903763243-1518506203-1001 -> {253C47C6-A263-4056-AFAD-6046361B8A2A} URL = http://search.condui…7178701164&UM=2
FF user.js: detected! => C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\vqy5f7kh.default\user.js [2014-10-05]
FF user.js: detected! => C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\4st1tlx8.Default User 3\user.js [2014-10-05]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2012-10-19] (Coupons, Inc.)
CHR HKLM\…\Chrome\Extension: [lfffjahnfbocnaooecgijfnbpcfekoik] - C:\ProgramData\adawaretb\shortcuts\chrome\adawaretb.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [lgnbhdnimikkoodkogjlcllngimhlapp] - C:\Program Files\FTDownloader.com\FTDownloader10.crx [Not Found]
2015-03-22 19:28 - 2014-10-05 20:40 - 00000000 ____D () C:\Program Files\Web Protect
C:\Users\Dads\26.05.03.EXE
C:\Users\Dads\3510 print driver.exe
C:\Users\Dads\Adaware_Installer.exe
C:\Users\Public\AlexaNSISPlugin.5812.dll
Task: {83575147-0FC4-47FB-9095-F25055CBDBC8} - System32\Tasks\DIS => C:\Users\Dads\AppData\Roaming\DIS.exe <==== ATTENTION
Task: C:\Windows\Tasks\DIS.job => C:\Users\Dads\AppData\Roaming\DIS.exe <==== ATTENTION
C:\Users\Dads\AppData\Roaming\DIS.exe
Task: {B635ABB1-EBA1-4FD1-9925-07B832C82EC8} - \BackgroundContainer Startup Task No Task File <==== ATTENTION
Task: {E4A7F9D2-C4A4-4EA9-B8F0-936B55EEE09E} - System32\Tasks\LWBVSUPC => C:\Users\Dads\AppData\Roaming\LWBVSUPC.exe <==== ATTENTION
Task: C:\Windows\Tasks\LWBVSUPC.job => C:\Users\Dads\AppData\Roaming\LWBVSUPC.exe <==== ATTENTION
C:\Users\Dads\AppData\Roaming\LWBVSUPC.exe
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\pcwatch.sys => ""="Driver" <==== ATTENTION
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MyOSProtect => ""="service" <==== ATTENTION
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\pcwatch.sys => ""="Driver" <==== ATTENTION
EmptyTemp:
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~~~~~~~~``

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click Scan.
  • Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
  • Follow the prompts and allow your computer to reboot.
  • After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
– File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.

~~~~~~~~~~~~~~~~`

Please download Malwarebytes Anti-Malware and save it to your desktop.
  • Double-click on the setup file (mbam-setup.exe), then click on Run to install.
  • Malwarebytes will automatically open to it's Dashboard. If you have never run this version, you should see a red note at the top indicating "A scan has never been run on your system"
  • Click on Update Now to download the current database definitions, then click the Scan Now >> button.
  • If you have run this version before, you should see a green note at the top indicating "Your system is fully protected".
  • You will be prompted to update Malwarebytes…click on the Update Now button.
  • The THREAT SCAN will automatically begin.
  • When the scan has completed, the results will be displayed. Click on Quarantine All, then click on Apply Actions.
  • To complete any actions taken you will be prompted to restart your computer…click on Yes. Failure to reboot normally will prevent Malwarebytes from removing all the malware.
  • After rebooting the computer, copy and paste the mbam.log in your next reply.
To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 1)
  • Open Malwarebytes Anti-Malware.
  • Click the History Tab at the top and select Application Logs.
  • Select (check) the box next to Scan Log. Choose the most current scan.
  • Click the View button.
  • Click Copy to Clipboard at the bottom…come back to this thread, click Add Reply, then right-click and choose Paste.
  • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
  • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 2)
  • Open Malwarebytes Anti-Malware.
  • Click the Scan Tab at the top.
  • Click the View detailed log link on the right.
  • Click Copy to Clipboard at the bottom…come back to this thread, click Add Reply, then right-click and choose Paste.
  • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
  • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
Logs are named by the date of scan in the following format: mbam-log-yyyy-mm-dd and automatically saved to the following locations:
– XP: C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
– Vista, Windows 7/8: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
 
~~~~~~~~~~
please post
fixlist.txt
AdwCleaner.txt
Malwarebytes Anti-Malware\Logs

here are the log files that you requested

Thanks,

Ed  

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-03-2015
Ran by [removed] at 2015-03-26 16:46:05 Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
 
==============================================
 
Content of fixlist:
*****************
start
CreateRestorePoint:
CloseProcesses:
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\…\AppCertDlls: [x64] -> c:\program files\settings manager\systemk\x64\sysapcrt.dll
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-4147716943-903763243-1518506203-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {253C47C6-A263-4056-AFAD-6046361B8A2A} URL =
SearchScopes: HKU\S-1-5-21-4147716943-903763243-1518506203-1001 -> {253C47C6-A263-4056-AFAD-6046361B8A2A} URL = http://search.condui…7178701164&UM=2
FF user.js: detected! => C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\vqy5f7kh.default\user.js [2014-10-05]
FF user.js: detected! => C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\4st1tlx8.Default User 3\user.js [2014-10-05]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2012-10-19] (Coupons, Inc.)
CHR HKLM\…\Chrome\Extension: [lfffjahnfbocnaooecgijfnbpcfekoik] - C:\ProgramData\adawaretb\shortcuts\chrome\adawaretb.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [lgnbhdnimikkoodkogjlcllngimhlapp] - C:\Program Files\FTDownloader.com\FTDownloader10.crx [Not Found]
2015-03-22 19:28 - 2014-10-05 20:40 - 00000000 ____D () C:\Program Files\Web Protect
C:\Users\Dads\26.05.03.EXE
C:\Users\Dads\3510 print driver.exe
C:\Users\Dads\Adaware_Installer.exe
C:\Users\Public\AlexaNSISPlugin.5812.dll
Task: {83575147-0FC4-47FB-9095-F25055CBDBC8} - System32\Tasks\DIS => C:\Users\Dads\AppData\Roaming\DIS.exe <==== ATTENTION
Task: C:\Windows\Tasks\DIS.job => C:\Users\Dads\AppData\Roaming\DIS.exe <==== ATTENTION
C:\Users\Dads\AppData\Roaming\DIS.exe
Task: {B635ABB1-EBA1-4FD1-9925-07B832C82EC8} - \BackgroundContainer Startup Task No Task File <==== ATTENTION
Task: {E4A7F9D2-C4A4-4EA9-B8F0-936B55EEE09E} - System32\Tasks\LWBVSUPC => C:\Users\Dads\AppData\Roaming\LWBVSUPC.exe <==== ATTENTION
Task: C:\Windows\Tasks\LWBVSUPC.job => C:\Users\Dads\AppData\Roaming\LWBVSUPC.exe <==== ATTENTION
C:\Users\Dads\AppData\Roaming\LWBVSUPC.exe
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\pcwatch.sys => ""="Driver" <==== ATTENTION
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MyOSProtect => ""="service" <==== ATTENTION
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\pcwatch.sys => ""="Driver" <==== ATTENTION
EmptyTemp:
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dprotectsvc.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchinstaller.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotector.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings64.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\umbrella.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\utiljumpflip.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroids.exe" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroidsservice.exe" => Key deleted successfully.
HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x64 => value deleted successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKU\S-1-5-21-4147716943-903763243-1518506203-1001\SOFTWARE\Policies\Google" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKU\S-1-5-21-4147716943-903763243-1518506203-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{253C47C6-A263-4056-AFAD-6046361B8A2A}" => Key deleted successfully.
HKCR\CLSID\{253C47C6-A263-4056-AFAD-6046361B8A2A} => Key not found. 
C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\vqy5f7kh.default\user.js => Moved successfully.
C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\4st1tlx8.Default User 3\user.js => Moved successfully.
C:\Program Files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll => Moved successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\lfffjahnfbocnaooecgijfnbpcfekoik" => Key deleted successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\lgnbhdnimikkoodkogjlcllngimhlapp" => Key deleted successfully.
C:\Program Files\Web Protect => Moved successfully.
C:\Users\Dads\26.05.03.EXE => Moved successfully.
C:\Users\Dads\3510 print driver.exe => Moved successfully.
C:\Users\Dads\Adaware_Installer.exe => Moved successfully.
C:\Users\Public\AlexaNSISPlugin.5812.dll => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{83575147-0FC4-47FB-9095-F25055CBDBC8}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83575147-0FC4-47FB-9095-F25055CBDBC8}" => Key deleted successfully.
C:\Windows\System32\Tasks\DIS => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DIS" => Key deleted successfully.
C:\Windows\Tasks\DIS.job => Moved successfully.
"C:\Users\Dads\AppData\Roaming\DIS.exe" => File/Directory not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B635ABB1-EBA1-4FD1-9925-07B832C82EC8}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B635ABB1-EBA1-4FD1-9925-07B832C82EC8}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BackgroundContainer Startup Task" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E4A7F9D2-C4A4-4EA9-B8F0-936B55EEE09E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E4A7F9D2-C4A4-4EA9-B8F0-936B55EEE09E}" => Key deleted successfully.
C:\Windows\System32\Tasks\LWBVSUPC => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LWBVSUPC" => Key deleted successfully.
C:\Windows\Tasks\LWBVSUPC.job => Moved successfully.
"C:\Users\Dads\AppData\Roaming\LWBVSUPC.exe" => File/Directory not found.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\pcwatch.sys" => Key deleted successfully.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\MyOSProtect" => Key deleted successfully.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\pcwatch.sys" => Key deleted successfully.
EmptyTemp: => Removed 1.7 GB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 16:50:25 ====
 
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 3/26/2015
Scan Time: 5:39:10 PM
Logfile: mabam.txt
Administrator: Yes
 
Version: 2.01.4.1018
Malware Database: v2015.03.26.07
Rootkit Database: v2015.03.26.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Dads
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 332916
Time Elapsed: 14 min, 39 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 1
PUP.Optional.Conduit.A, C:\Users\Dads\AppData\Local\CRE, Quarantined, [d34cf852a1e9f343346f269256ad14ec], 
 
Files: 1
PUP.Optional.Conduit.A, C:\Users\Dads\AppData\Local\CRE\iolllphbfidpiigenecjjflaefapfnef.crx, Quarantined, [d34cf852a1e9f343346f269256ad14ec], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
# AdwCleaner v4.113 - Logfile created 26/03/2015 at 16:59:54
# Updated 22/03/2015 by Xplode
# Database : 2015-03-26.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x86)
# Username : Dads - DADS-PC
# Running from : C:\Users\Dads\Desktop\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
File Found : C:\END
File Found : C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\vqy5f7kh.default\Extensions\[removed]
File Found : C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\vqy5f7kh.default\invalidprefs.js
File Found : C:\Users\Dads\AppData\Roaming\Mozilla\Firefox\Profiles\vqy5f7kh.default\searchplugins\bingp.xml
Folder Found : C:\Program Files\DomaIQ Uninstaller
Folder Found : C:\Program Files\globalUpdate
Folder Found : C:\Program Files\HiDefMedia
Folder Found : C:\ProgramData\AVG SafeGuard toolbar
Folder Found : C:\ProgramData\Kromtech
Folder Found : C:\ProgramData\Tarma Installer
Folder Found : C:\Users\Dads\AppData\Local\Conduit
Folder Found : C:\Users\Dads\AppData\Local\globalUpdate
Folder Found : C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
Folder Found : C:\Users\Dads\AppData\Local\Kromtech
Folder Found : C:\Users\Dads\AppData\Local\PutLockerDownloader
Folder Found : C:\Users\Dads\AppData\LocalLow\Conduit
Folder Found : C:\Users\Dads\AppData\Roaming\pdfforge
Folder Found : C:\Users\Dads\AppData\Roaming\PerformerSoft
Folder Found : C:\Users\Dads\AppData\Roaming\Strongvault
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
Key Found : HKCU\Software\Alexa Internet
Key Found : HKCU\Software\AppDataLow\Software\adawarebp
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\distromatic
Key Found : HKCU\Software\filescout
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\Google\Chrome\Extensions\iolllphbfidpiigenecjjflaefapfnef
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKCU\Software\PerformerSoft
Key Found : HKCU\Software\WebProtect
Key Found : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Found : HKLM\SOFTWARE\Classes\AppID\BackgroundHost.EXE
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Found : HKLM\SOFTWARE\Classes\FTDownloader
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\iolllphbfidpiigenecjjflaefapfnef
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Found : HKLM\SOFTWARE\Tarma Installer
Key Found : HKLM\SOFTWARE\WebProtect
Key Found : HKLM\SOFTWARE\XTRM Group Ltd.
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17689
 
 
-\\ Mozilla Firefox v36.0.4 (x86 en-US)
 
[4st1tlx8.Default User 3] - Line Found : user_pref("browser.search.order.1", "default-search.net");
[vqy5f7kh.default] - Line Found : user_pref("CT3279411.LOCAL_COOKIE_THROTTLE_BASEloopback|hxxp://up.autocompleteplus.com/up?q=oo.com&l=www.yahoo.com&t=2&v=0.4&d=conduit2.enc", "MTM3MzU1OTA0MQ==");
[vqy5f7kh.default] - Line Found : user_pref("CT3279411.LOCAL_COOKIE_THROTTLE_BASEloopback|hxxp://up.autocompleteplus.com/up?q=shrimp%20&l=www.cub.com&t=0&ab=base20&abs=g&v=0.4&d=conduit2.enc", "MTM3MTc1NjMzNA==");
[vqy5f7kh.default] - Line Found : user_pref("CT3279411.embeddedsData", "[{\"appId\":\"130028909967386036\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[…]
[vqy5f7kh.default] - Line Found : user_pref("CT3279411.installType", "conduitnsisintegration");
[vqy5f7kh.default] - Line Found : user_pref("CT3279411.originalHomepage", "hxxp://search.conduit.com/?ctid=CT3289847&CUI=UN68118730217746545&UM=2&SearchSource=13");
[vqy5f7kh.default] - Line Found : user_pref("CT3279411.originalSearchAddressUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource=2&CUI=UN68118730217746545&UM=2&q=");
[vqy5f7kh.default] - Line Found : user_pref("CT3279411.originalSearchEngine", "WhiteSmoke New Customized Web Search");
[vqy5f7kh.default] - Line Found : user_pref("CT3279411.smartbar.CTID", "CT3279411");
[vqy5f7kh.default] - Line Found : user_pref("CT3279411.smartbar.Uninstall", "0");
[vqy5f7kh.default] - Line Found : user_pref("CT3279411.smartbar.homepage", "true");
[vqy5f7kh.default] - Line Found : user_pref("CT3279411.smartbar.toolbarName", "appbario12 ");
[vqy5f7kh.default] - Line Found : user_pref("CT3279412.originalHomepage", "hxxp://www.amazon.com/websearch/ref=bit_bds-p24_serp_ff_us_display?ie=UTF8&tagbase=bds-p24&tbrId=v1_abb-channel-24_cf839969687944d09c549aba78ad2cb3_39_1007_201[…]
[vqy5f7kh.default] - Line Found : user_pref("CT3279412.originalSearchAddressUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279411&SearchSource=2&CUI=UN35270856471363120&UM=2&q=");
[vqy5f7kh.default] - Line Found : user_pref("CT3279412.smartbar.homepage", "true");
 
-\\ Google Chrome v41.0.2272.101
 
[C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Dads\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://search.tb.ask.com/search/GGmain.jhtml?searchfor={searchTerms}&st=kwd&ptb=A576B00A-0E5F-41D5-8667-172E5FB08AF2&n=780c0098&ind=2014052504&p2=^ZJ^xdm268^YYA^us&si=CNf1wJWHyL4CFcU-MgodUCYAbA
*************************
 
AdwCleaner[R0].txt - [8829 bytes] - [26/03/2015 16:59:54]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [8888 bytes] ##########
 

 

Good deal

Now let's remove a couple of things
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click Scan.
  • Upon completion, click Report. A log (AdwCleaner.txt) will open. Briefly check the log for anything you know to be legitimate.
  • Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
  • Follow the prompts and allow your computer to reboot.
  • After rebooting, a log (AdwCleaner.txt) will open. Copy the contents of the log and paste in your next reply.

    – File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.

Tell me how the computer is now?

The log files for this program are not saving to desktop but I believe this is the correct one 

 

# AdwCleaner v4.113 - Logfile created 26/03/2015 at 19:19:34
# Updated 22/03/2015 by Xplode
# Database : 2015-03-26.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x86)
# Username : Dads - DADS-PC
# Running from : C:\Users\Dads\Desktop\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKCU\Software\AppDataLow\Software\adawarebp
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17689
 
 
-\\ Mozilla Firefox v36.0.4 (x86 en-US)
 
 
-\\ Google Chrome v41.0.2272.101
 
*************************
 
AdwCleaner[R0].txt - [8967 bytes] - [26/03/2015 16:59:54]
AdwCleaner[R1].txt - [9026 bytes] - [26/03/2015 17:02:06]
AdwCleaner[R2].txt - [1375 bytes] - [26/03/2015 17:24:07]
AdwCleaner[R3].txt - [1376 bytes] - [26/03/2015 17:24:49]
AdwCleaner[R4].txt - [1238 bytes] - [26/03/2015 19:19:34]
AdwCleaner[S0].txt - [9407 bytes] - [26/03/2015 17:05:30]
AdwCleaner[S1].txt - [1450 bytes] - [26/03/2015 17:29:32]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R4].txt - [1415 bytes] ##########
 

Fire Fox now works as expected after setting up a new profile.  Thunderbird will open if ran as administrator, I am guessing that needs a new profile as well. As for IE it's still unresponsive and crashes when windows searches for a fix.

When you ran AdwCleaner did you allow it to clean what it found?

please download Windows Repair (all in one) from here

[external image: step-4-tab.jpg]
Install the program then go to step 4 and create a new system restore point and new registry backup.

Go to Step 2 and allow it to run CheckDisk by clicking on Do It button:
[external image: p22001645.gif]



NEXT
On the the Start Repairs tab => Click the Start
[external image: start-repairs-tab.jpg]


Please ensure that ONLY items seen in the image below are ticked as indicated (they're all checked by default):
[external image: p22001647.gif]

Click on box next to the Restart System when Finished. Then click on Start.

Yes I did clean the 4 items that Adw did find. I also ran the windows repair program and everything seems to be up and running as it should. 

 

Thank you 

Ed

Good to hear


What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.


[external image: GzlsbnV.png]ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.


Please run a free online scan with the ESET Online Scanner

US Link: http://www.eset.com/us/online-scanner/
EU Link: http://www.eset.eu/online-scanner/

Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan.
  • Click the blue Run ESET Online Scanner button
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
  • Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
  • Click on Advanced Settings
  • Make sure that the option Remove found threats is unticked.
  • Ensure these options are ticked
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Under "Current Scan Targets" > click "change" and ensure all your drives are selected
  • Click Start
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Attach the log as a reply to your next reply..
  • Close the ESET online scan, and let me know how things are now.

Here are the results for the eset scan:

 

C:\AdwCleaner\Quarantine\C\Program Files\DomaIQ Uninstaller\DomaIQUninstall.exe.vir a variant of MSIL/DomaIQ.A potentially unwanted application
C:\FRST\Quarantine\C\Program Files\Web Protect\MyOSProtect.dll Win32/Adware.Loadshop.C application
C:\FRST\Quarantine\C\Program Files\Web Protect\MyOSProtect64.dll Win64/Adware.Loadshop.C application
C:\FRST\Quarantine\C\Program Files\Web Protect\pcwtc64f.sys Win64/Adware.Loadshop.D application
C:\FRST\Quarantine\C\Program Files\Web Protect\pcwtc64r.sys Win64/Adware.Loadshop.E application
C:\FRST\Quarantine\C\Program Files\Web Protect\postcollect.exe Win32/AdWare.Loadshop.G application
C:\FRST\Quarantine\C\Program Files\Web Protect\WDCertInstaller.dll Win32/Adware.Loadshop.F application
C:\Users\Dads\AppData\Roaming\DIS JS/Toolbar.Crossrider.C potentially unwanted application
C:\Users\Dads\AppData\Roaming\LWBVSUPC JS/Toolbar.Crossrider.C potentially unwanted application
C:\Users\Dads\Documents\Mom's Stuff\beth\winzip180.exe a variant of Win32/InstallCore.NP potentially unwanted application
C:\Users\Dads\Downloads\ccsetup328.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\Dads\Downloads\ccsetup414.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\Dads\Downloads\ccsetup417 (1).exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\Dads\Downloads\ccsetup417.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\Dads\Downloads\PDFCreator-1_7_1_setup.exe Win32/InstallMonetizer.AQ potentially unwanted application
C:\Users\Dads\Downloads\PlayFizzSetup.exe Win32/OpenCandy potentially unsafe application
C:\Users\Public\xp share\Tranfers\My Program Setup Files\ccsetup315.exe Win32/Bundled.Toolbar.Google.E potentially unsafe application
C:\Users\Public\xp share\Tranfers\My Program Setup Files\winzip16-32.exe a variant of Win32/Systweak.L potentially unwanted application
 

 

Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)
 

start
CreateRestorePoint:
CloseProcesses:
C:\Users\Dads\AppData\Roaming\DIS
C:\Users\Dads\AppData\Roaming\LWBVSUPC
C:\Users\Dads\Documents\Mom's Stuff\beth\winzip180.exe
C:\Users\Dads\Downloads\ccsetup328.exe
C:\Users\Dads\Downloads\ccsetup414.exe
C:\Users\Dads\Downloads\ccsetup417 (1).exe
C:\Users\Dads\Downloads\ccsetup417.exe
C:\Users\Dads\Downloads\PDFCreator-1_7_1_setup.exe
C:\Users\Dads\Downloads\PlayFizzSetup.exe
C:\Users\Public\xp share\Tranfers\My Program Setup Files\ccsetup315.exe
C:\Users\Public\xp share\Tranfers\My Program Setup Files\winzip16-32.exe
EmptyTemp:
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

Please post this log and tell me how your computer is now.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-03-2015
Ran by [removed] at 2015-03-28 13:19:50 Run:2
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
 
==============================================
 
Content of fixlist:
*****************
start
CreateRestorePoint:
CloseProcesses:
C:\Users\Dads\AppData\Roaming\DIS
C:\Users\Dads\AppData\Roaming\LWBVSUPC
C:\Users\Dads\Documents\Mom's Stuff\beth\winzip180.exe
C:\Users\Dads\Downloads\ccsetup328.exe
C:\Users\Dads\Downloads\ccsetup414.exe
C:\Users\Dads\Downloads\ccsetup417 (1).exe
C:\Users\Dads\Downloads\ccsetup417.exe
C:\Users\Dads\Downloads\PDFCreator-1_7_1_setup.exe
C:\Users\Dads\Downloads\PlayFizzSetup.exe
C:\Users\Public\xp share\Tranfers\My Program Setup Files\ccsetup315.exe
C:\Users\Public\xp share\Tranfers\My Program Setup Files\winzip16-32.exe
EmptyTemp:
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
C:\Users\Dads\AppData\Roaming\DIS => Moved successfully.
C:\Users\Dads\AppData\Roaming\LWBVSUPC => Moved successfully.
C:\Users\Dads\Documents\Mom's Stuff\beth\winzip180.exe => Moved successfully.
C:\Users\Dads\Downloads\ccsetup328.exe => Moved successfully.
C:\Users\Dads\Downloads\ccsetup414.exe => Moved successfully.
C:\Users\Dads\Downloads\ccsetup417 (1).exe => Moved successfully.
C:\Users\Dads\Downloads\ccsetup417.exe => Moved successfully.
C:\Users\Dads\Downloads\PDFCreator-1_7_1_setup.exe => Moved successfully.
C:\Users\Dads\Downloads\PlayFizzSetup.exe => Moved successfully.
C:\Users\Public\xp share\Tranfers\My Program Setup Files\ccsetup315.exe => Moved successfully.
C:\Users\Public\xp share\Tranfers\My Program Setup Files\winzip16-32.exe => Moved successfully.
EmptyTemp: => Removed 513.8 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 13:21:20 ====
 
My machine is running great now. All browsers seem to be working like they should.
 
I think your good to go!

[external image: AFZxnZc.jpg] DelFix
  • Please download DelFix
    or from here http://www.bleepingcomputer.com/download/delfix/and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
    • Activate UAC
    • Remove disinfection tools
    • Create registry backup
  • Click the Run button.
– This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).

~~~~
  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP

The following programmes come highly recommended in the security community.
  • [external image: xKsUqI5A.png.pagespeed.ic.vn1Hlvqi8h.jpg]AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
  • [external image: EG85Vjt.png]Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • [external image: x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpg]Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • [external image: xjv4nhMJ.png.pagespeed.ic.A5YbWn1eDO.png]NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • [external image: DgW1XL2.png.pagespeed.ce.v1OlJl_ZAS.png]Secuina PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • [external image: xj1OLIec.png.pagespeed.ic.k6hhwopU0q.jpg]SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • [external image: xJEP5iWI.png.pagespeed.ic.4tmM1lM7DQ.png]Web of Trust (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.
Want to help others? Join the ClassRoom and learn how.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI