This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

SLOW PC POSSIBLE VIRUSES [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

 

Just wanted to get some help to fix my dads computer. It is very slow and possibly has some viruses or spyware.

 

Thanks in advance!! :adios:

 

aswMBR log below

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-04-04 15:35:26
—————————–
15:35:26.088    OS Version: Windows 6.0.6001 Service Pack 1
15:35:26.088    Number of processors: 2 586 0x170A
15:35:26.088    ComputerName: USER-PC  UserName: User
15:36:16.773    Initialize success
15:36:16.992    VM: initialized successfully
15:36:16.992    VM: Intel CPU virtualization not supported
15:38:03.661    The log file has been saved successfully to "C:\Users\User\Desktop\aswMBR.txt"

 

FRST NOTE:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by [removed] (administrator) on USER-PC on 04-04-2015 15:58:12
Running from C:\Users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2PANU6QD
[removed] Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Egis Technology Inc.) C:\Program Files\Acer Bio Protection\CompPtcVUI.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
(Egis Technology Inc.) C:\Program Files\Acer Bio Protection\BASVC.exe
() C:\Windows\PLFSetI.exe
(Egis Technology Inc.) C:\Program Files\Acer Bio Protection\PdtWzd.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
(EgisTec Inc.) C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe
(EgisTec Inc.) C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe
(EgisTec Inc.) C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
(Symantec Corporation) C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\ccsvchst.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(THOMSON multimedia) C:\Program Files\Alcatel\SpeedTouch USB\dragdiag.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Realtek Semiconductor Corp.) C:\Users\User\AppData\Local\Temp\RtkBtMnt.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Visicom Media Inc. (Powered by Panda Security)) C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe
(Telstra) C:\Program Files\Telstra\Mobile Broadband Manager\TelstraUCM.exe
(RealNetworks, Inc.) C:\Program Files\Online Games Manager\ogmservice.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Sierra Wireless, Inc.) C:\Program Files\Sierra Wireless Inc\Common\SwiCardDetect.exe
() C:\Program Files\Amazon Browser Bar\ToolbarUpdaterService.exe
() C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Symantec Corporation) C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\ccsvchst.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
() C:\Program Files\Amazon Browser Bar\AmazonBrowserBarSSB.3.0.dll
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_17_0_0_134_ActiveX.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Symantec Corporation) C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360\2454B0AB\21.6.0.32\InstStub.exe
(Farbar) C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2PANU6QD\FRST[3].exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6814240 2009-02-14] (Realtek Semiconductor)
HKLM\…\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-02-14] (Realtek Semiconductor Corp.)
HKLM\…\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [200704 2008-07-29] ()
HKLM\…\Run: [VitaKeyPdtWzd] => c:\Program Files\Acer Bio Protection\PdtWzd.exe [3551744 2009-02-19] (Egis Technology Inc.)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1410344 2008-12-05] (Synaptics, Inc.)
HKLM\…\Run: [BackupManagerTray] => C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [248576 2009-02-17] (NewTech Infosystems, Inc.)
HKLM\…\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe [707104 2009-02-19] (Acer Incorporated)
HKLM\…\Run: [EgisTecLiveUpdate] => C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe [199464 2008-10-27] (EgisTec Inc.)
HKLM\…\Run: [mwlDaemon] => C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [346672 2008-10-27] (EgisTec Inc.)
HKLM\…\Run: [Acer Assist Launcher] => C:\Program Files\Acer\Acer Assist\launcher.exe [1261568 2007-11-20] ()
HKLM\…\Run: [Acer Product Registration] => C:\Program Files\Acer\Acer Registration\ACE1.exe [3387392 2007-11-27] (Leader Technologies)
HKLM\…\Run: [signup] => D:\hb5.exe
HKLM\…\Run: [SpeedTouch USB Diagnostics] => C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe [861184 2002-06-06] (THOMSON multimedia)
HKLM\…\Run: [OPSE reminder] => "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-22] (Adobe Systems Incorporated)
HKLM\…\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM\…\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM\…\Run: [B2C_AGENT] => C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [404568 2011-09-28] (LG Electronics)
HKLM\…\Run: [Anti-phishing Domain Advisor] => C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe [217256 2012-05-04] (Visicom Media Inc. (Powered by Panda Security))
HKLM\…\Run: [BigPondWirelessBroadbandCM] => C:\Program Files\Telstra\Mobile Broadband Manager\TelstraUCM.exe [6137432 2011-12-19] (Telstra)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\Run: [lime pro] => "C:\Program Files\Lime PRO\LimePro.exe" -h
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\Run: [APISupport] => "C:\Windows\system32\Rundll32.exe" "C:\Users\User\AppData\Local\TB\APISupport\APISupport.dll",DLLRunAPISupport <===== ATTENTION
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\Run: [Norton Download Manager{N360P216032-SHPD-FSD40014}] => C:\Users\Public\Downloads\Norton\{N360P216032-SHPD-FSD40014}\NortonN360Downloader.exe [1021952 2015-04-04] (Symantec Corporation)
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\MountPoints2: F - F:\setup.exe -a
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\MountPoints2: {3648cf53-2169-11df-af65-000e50199ddd} - F:\InstallTomTomHOME.exe
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\MountPoints2: {3648cf76-2169-11df-af65-000e50199ddd} - E:\InstallTomTomHOME.exe
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\MountPoints2: {e90b657b-67ad-11e3-93fc-001d72f89be0} - E:\AutoRun.exe
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\MountPoints2: {e90b65a8-67ad-11e3-93fc-001d72f89be0} - E:\AutoRun.exe
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\MountPoints2: {eb31cf24-669c-11e3-88fb-001d72f89be0} - E:\AutoRun.exe
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\MountPoints2: {eb31cf33-669c-11e3-88fb-001d72f89be0} - E:\AutoRun.exe
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\Control Panel\Desktop\\SCRNSAVE.EXE ->
Lsa: [Notification Packages] c:\Program Files\Acer Bio Protection\PwdFilter
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files\EgisTec\MyWinLocker 3\x86\psdprotect.dll (EgisTec Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\buShell.dll (Symantec Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-19\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-20\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyServer: [.DEFAULT] => proxy.ozemail.com.au:8080
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l;=0409&s;=2&o;=vp32&d;=0809&m;=aspire_5738
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid;=N360&pvid;=20.6.0.27
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid;=N360&pvid;=20.6.0.27
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid;=N360&pvid;=20.6.0.27
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l;=0409&s;=2&o;=vp32&d;=0809&m;=aspire_5738
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.telstra.com.au/
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKU\S-1-5-21-3813807832-1416314213-169775867-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
SearchScopes: HKLM -> DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
SearchScopes: HKLM -> {3d29c02b-bf3e-4d3b-8a7a-e0e7d0f6dbab} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^Z7^xdm029^YY^au&si;=CMmIzuS2vrYCFcFdpQodtVUApQ&ptb;=16771E8E-E3A7-4A9D-8D7E-1F70744E6D68&psa;=&ind;=2013040916&st;=sb&n;=77fc9114&searchfor;={searchTerms}
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACAW
SearchScopes: HKLM -> {99C48F82-BAE3-451C-9560-A89F9AE0B9E0} URL = http://search.aol.com/aolcom/search?query={searchTerms}&invocationType;=msie70a
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> DefaultScope {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = http://www.bing.com/search?FORM=UP97DF&PC;=UP97&q;={searchTerms}&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> {155C015C-6AEF-4B1B-A68A-FD94358476E3} URL = http://search.aol.com/aolcom/search?query={searchTerms}&invocationType;=msie70a
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> {33F7723A-9931-4383-AEFE-6E9050E9BA00} URL = http://websearch.ask.com/redirect?client=ie&tb;=ORJ&o;=100000027&src;=crm&q;={searchTerms}&locale;=en_US&apn;_ptnrs=U3&apn;_dtid=OSJ000YYAU&apn;_uid=AB08333A-19E4-42D8-84AC-8605FBCCBFC9&apn;_sauid=78F5350F-EBF4-4E92-84F9-054A79620499
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://blekko.com/ws/?source=c3348dd4&tbp;=rbox&toolbarid;=blekkotb_031&u;=E378706A1740C0D953B4B45054D3DCA0&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> {3d29c02b-bf3e-4d3b-8a7a-e0e7d0f6dbab} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^Z7^xdm029^YY^au&si;=CMmIzuS2vrYCFcFdpQodtVUApQ&ptb;=16771E8E-E3A7-4A9D-8D7E-1F70744E6D68&psa;=&ind;=2013040916&st;=sb&n;=77fc9114&searchfor;={searchTerms}
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> {6B9855A7-0037-4775-B3B2-97006E1154FB} URL = http://www.amazon.com/websearch/ref=bit_bds-p12_serp_ie_us_display?ie=UTF8&tagbase;=bds-p12&tag;=bds-p12-serp-us-ie-20&tbrId;=v1_abb-channel-12_da54a71407fc44368242eb78dfa472ee_39_1006_20140719_AU_ie_ds_dcomnew-util-728&query;={searchTerms}
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> {99C48F82-BAE3-451C-9560-A89F9AE0B9E0} URL =
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = http://www.ask.com/web?q={SEARCHTERMS}&o;=15527&l;=dis&prt;=360&chn;=retail&geo;=US&ver;=5
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = http://www.bing.com/search?FORM=UP97DF&PC;=UP97&q;={searchTerms}&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredibar.com/mb188/?search={searchTerms}&loc;=IB_DS&a;=6OyOdQK59I&i;=26
BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> C:\Program Files\McAfee\MSK\MskAPBho.dll No File
BHO: Web Assistant -> {336D0C35-8A85-403a-B9D2-65C292C39087} -> C:\Program Files\Web Assistant\Extension32.dll [2013-06-30] ()
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} ->  No File
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\coIEPlg.dll [2014-11-28] (Symantec Corporation)
BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\IPS\IPSBHO.DLL [2013-04-09] (Symantec Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-05-07] (Oracle Corporation)
BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-05-07] (Oracle Corporation)
BHO: AlxHelper Class -> {F443A627-5009-4323-9C1D-7FD598D0D712} -> C:\Program Files\Amazon Browser Bar\AmazonBrowserBar.3.0.dll [2012-08-16] (Amazon.com)
Toolbar: HKLM - Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26] ()
Toolbar: HKLM - Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll [2012-01-22] (Montera Technologeis LTD)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\coIEPlg.dll [2014-11-28] (Symantec Corporation)
Toolbar: HKLM - Amazon Browser Bar - {EA582743-9076-4178-9AA6-7393FDF4D5CE} - C:\Program Files\Amazon Browser Bar\AmazonBrowserBar.3.0.dll [2012-08-16] (Amazon.com)
Toolbar: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> No Name - {F92A9FE4-2850-4198-B9D5-279880E49B16} -  No File
Toolbar: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> No Name - {55D7C7BC-12A7-4F9B-81C0-600D9A182395} -  No File
Toolbar: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKU\S-1-5-21-3813807832-1416314213-169775867-1000 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\coIEPlg.dll [2014-11-28] (Symantec Corporation)
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-06-09] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll No File []
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -  No File []
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32.dll [2008-10-05] ()
FF Plugin: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-05-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-05-07] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-16] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll [2013-03-22] (RocketLife, LLP)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @viewpoint.com/VMP -> C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-21] ()
FF Plugin: @zylom.com/ZylomGamesPlayer -> C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll [2009-07-02] (Zylom)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-08-03] (Adobe Systems Inc.)
FF HKLM\…\Firefox\Extensions: [{B7082FAA-CB62-4872-9106-E42DD88EDE45}] - C:\Program Files\McAfee\SiteAdvisor
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-09-03]
FF HKLM\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\coFFPlgn [2015-04-04]
FF HKLM\…\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox [2012-09-16]
FF HKLM\…\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\IPSFFPlgn
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\IPSFFPlgn [2013-05-12]
FF HKLM\…\Firefox\Extensions: [{8E9E3331-D360-4f87-8803-52DE43566502}] - C:\Program Files\Web Assistant\Firefox

Chrome:
=======
CHR HomePage: Default -> hxxp://www.amazon.com/websearch/ref=bit_bds-p12_serp_cr_us_display?ie=UTF8&tagbase;=bds-p12&tbrId;=v1_abb-channel-12_da54a71407fc44368242eb78dfa472ee_39_1006_20140719_AU_cr_sp_dcomnew-util-728
CHR StartupUrls: Default -> "hxxp://www.amazon.com/websearch/ref=bit_bds-p12_serp_cr_us_display?ie=UTF8&tagbase;=bds-p12&tbrId;=v1_abb-channel-12_da54a71407fc44368242eb78dfa472ee_39_1006_20140719_AU_cr_sp_dcomnew-util-728"
CHR DefaultSearchKeyword: Default -> amazon.com
CHR DefaultSuggestURL: Default -> http://suggestqueries.google.com/complete/search?q={searchTerms}&output;=chrome
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (Photodex Presenter Plugin) - C:\Users\User\AppData\Roaming\Mozilla\plugins\npPxPlay.dll No File
CHR Plugin: (Exent® AOD Gecko Plugin) - C:\Program Files\Free Ride Games\npExentCtl.dll No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (MetaStream 3 Plugin) - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll No File
CHR Plugin: (Zylom Plugin) - C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Entanglement Web App) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd [2011-06-02]
CHR Extension: (Norton Security Toolbar) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bejnhdlplbjhffionohbdnpcbobfejcc [2014-05-09]
CHR Extension: (Web Assistant) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd [2012-09-16]
CHR Extension: (Norton Identity Safe) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2014-12-13]
CHR Extension: (A Free Ride Games Bar) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\jojhdgnandjllaeaaccnkddgieegmljj [2012-12-20]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Poppit!) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi [2011-06-02]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
CHR Extension: (Amazon 1Button App for Chrome) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2014-07-20]
CHR HKLM\…\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\Exts\Chrome.crx [2014-12-12]
CHR HKLM\…\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [2012-09-16]
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [jojhdgnandjllaeaaccnkddgieegmljj] - C:\Users\User\AppData\Local\CRE\jojhdgnandjllaeaaccnkddgieegmljj.crx [2013-10-03]
CHR HKU\S-1-5-21-3813807832-1416314213-169775867-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3813807832-1416314213-169775867-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [jojhdgnandjllaeaaccnkddgieegmljj] - C:\Users\User\AppData\Local\CRE\jojhdgnandjllaeaaccnkddgieegmljj.crx [2013-10-03]
CHR HKU\S-1-5-21-3813807832-1416314213-169775867-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] - C:\Program Files\Amazon\ABB\AmazonChrome-bds-amzn.crx [2014-04-05]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [666144 2009-02-19] (Acer Incorporated)
S2 gupdate1ca2811c7b2cf60; C:\Program Files\Google\Update\GoogleUpdate.exe [107912 2014-10-20] (Google Inc.)
R2 IGBASVC; c:\Program Files\Acer Bio Protection\BASVC.exe [3440128 2009-02-19] (Egis Technology Inc.) [File not signed]
R2 MWLService; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [306736 2008-10-27] (EgisTec Inc.)
R2 N360; C:\Program Files\Norton 360 Premier Edition\Engine\21.6.0.32\N360.exe [265040 2014-09-21] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [44800 2009-02-17] (NewTech Infosystems, Inc.)
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144632 2008-09-24] (NewTech Infosystems, Inc.)
R2 ogmservice; C:\Program Files\Online Games Manager\ogmservice.exe [581568 2014-03-27] (RealNetworks, Inc.)
R2 SwiCardDetectSvc; C:\Program Files\Sierra Wireless Inc\Common\SwiCardDetect.exe [238960 2011-06-24] (Sierra Wireless, Inc.)
R2 Updater Service for AMZN; C:\Program Files\Amazon Browser Bar\ToolbarUpdaterService.exe [222368 2013-03-22] ()
R2 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2013-06-30] () [File not signed]
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 alcan5ln; C:\Windows\System32\DRIVERS\alcan5ln.sys [36048 2002-06-06] (THOMSON multimedia)
S3 alcaudsl; C:\Windows\System32\DRIVERS\alcaudsl.sys [743136 2002-06-06] (THOMSON multimedia)
R0 AlfaFF; C:\Windows\System32\drivers\AlfaFF.sys [42608 2008-07-11] (Alfa Corporation)
R3 ATSWPDRV; C:\Windows\System32\DRIVERS\ATSwpDrv.sys [146944 2008-05-30] (AuthenTec, Inc.)
R3 BHDrvx86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\BASHDefs\20150321.001\BHDrvx86.sys [1164504 2015-02-03] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360\1506000.020\ccSetx86.sys [127064 2014-02-21] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2014-12-12] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [111408 2014-12-12] (Symantec Corporation)
R3 IDSVix86; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\IPSDefs\20150401.001\IDSvix86.sys [505048 2015-03-28] (Symantec Corporation)
R2 int15; c:\Windows\system32\drivers\int15.sys [69632 2008-03-13] () [File not signed]
R2 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [19504 2008-10-09] (Egis Incorporated.)
R2 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2008-10-09] (Egis Incorporated.)
R2 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [59952 2008-10-09] (Egis Incorporated.)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20150403.002\NAVENG.SYS [95704 2015-01-21] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20150403.002\NAVEX15.SYS [1636696 2015-01-21] (Symantec Corporation)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl.sys [17408 2009-08-28] (Apple Inc.) [File not signed]
R3 SRTSP; C:\Windows\System32\Drivers\N360\1406000.01B\SRTSP.SYS [603224 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360\1506000.020\SRTSPX.SYS [32984 2014-08-26] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360\1506000.020\SYMDS.SYS [367704 2014-08-26] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360\1506000.020\SYMEFA.SYS [936152 2014-08-26] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2015-04-04] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [36512 2013-03-05] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360\1506000.020\Ironx86.SYS [209624 2014-08-07] (Symantec Corporation)
R3 SYMTDIv; C:\Windows\System32\Drivers\N360\1406000.01B\SYMTDIV.SYS [352344 2013-04-25] (Symantec Corporation)
S3 Andbus; system32\DRIVERS\lgandbus.sys [X]
S3 AndDiag; system32\DRIVERS\lganddiag.sys [X]
S3 AndGps; system32\DRIVERS\lgandgps.sys [X]
S3 ANDModem; system32\DRIVERS\lgandmodem.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_cdcecm; system32\DRIVERS\ew_jucdcecm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 massfilter_lte; \??\C:\Windows\system32\drivers\massfilter_lte.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X]
S3 USBAAPL; System32\Drivers\usbaapl.sys [X]
S3 wanatw; system32\DRIVERS\wanatw4.sys [X]
S2 X6XSEx; \??\C:\Program Files\Free Ride Games\X6XSEx.Sys [X]
S3 zgdcat; system32\DRIVERS\zgdcat.sys [X]
S3 zgdcdiag; system32\DRIVERS\zgdcdiag.sys [X]
S3 zgdcmdm; system32\DRIVERS\zgdcmdm.sys [X]
S3 zgdcnet; system32\DRIVERS\zgdcnet.sys [X]
U3 aswMBR; \??\C:\Users\User\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\User\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-04 15:57 - 2015-04-04 15:58 - 00000000 ____D () C:\FRST
2015-04-04 15:51 - 2015-04-04 15:51 - 00000967 _____ () C:\Users\User\Desktop\Norton Download Manager.lnk
2015-04-04 15:51 - 2015-04-04 15:51 - 00000843 _____ () C:\Users\User\Desktop\Norton Installation Files.lnk
2015-04-04 15:51 - 2015-04-04 15:51 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
2015-04-04 15:50 - 2015-04-04 15:50 - 01021952 _____ (Symantec Corporation) C:\Users\User\Downloads\NortonN360Downloader.exe
2015-04-04 15:38 - 2015-04-04 15:38 - 00000532 _____ () C:\Users\User\Desktop\aswMBR.txt
2015-04-04 15:11 - 2015-04-04 15:32 - 00000000 ____D () C:\Users\User\Desktop\Jackson Folder
2015-03-30 20:00 - 2015-03-30 20:00 - 00002735 _____ () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Foxtel PLAY.lnk
2015-03-30 20:00 - 2015-03-30 20:00 - 00002727 _____ () C:\Users\User\Desktop\Foxtel PLAY.lnk
2015-03-30 20:00 - 2015-03-30 20:00 - 00000000 __SHD () C:\Windows\system32\AI_RecycleBin
2015-03-30 19:57 - 2015-03-30 19:57 - 06170416 _____ (Foxtel) C:\Users\User\Downloads\setupFoxtelPlay (2).exe
2015-03-30 19:56 - 2015-03-30 19:56 - 06170416 _____ (Foxtel) C:\Users\User\Downloads\setupFoxtelPlay (1).exe
2015-03-30 19:55 - 2015-03-30 19:56 - 06170416 _____ (Foxtel) C:\Users\User\Downloads\setupFoxtelPlay.exe
2015-03-30 19:54 - 2015-03-30 19:54 - 06504296 _____ (Foxtel) C:\Users\User\Downloads\setupFoxtelGo (2).exe
2015-03-30 19:53 - 2015-03-30 19:54 - 06504296 _____ (Foxtel) C:\Users\User\Downloads\setupFoxtelGo (1).exe
2015-03-30 19:51 - 2015-03-30 19:52 - 06504296 _____ (Foxtel) C:\Users\User\Downloads\setupFoxtelGo.exe
2015-03-13 07:54 - 2015-03-13 07:54 - 00139336 _____ () C:\Windows\Minidump\Mini031315-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-04 15:56 - 2011-05-28 15:12 - 00000000 ____D () C:\ProgramData\Norton
2015-04-04 15:55 - 2013-05-12 07:46 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition
2015-04-04 15:55 - 2011-05-28 15:16 - 00142936 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT.SYS
2015-04-04 15:55 - 2011-05-28 15:16 - 00008194 _____ () C:\Windows\system32\Drivers\SYMEVENT.CAT
2015-04-04 15:55 - 2011-05-28 15:16 - 00002199 _____ () C:\Users\Public\Desktop\Norton 360.lnk
2015-04-04 15:54 - 2011-05-28 15:14 - 00000000 ____D () C:\Windows\system32\Drivers\N360
2015-04-04 15:54 - 2011-05-28 15:14 - 00000000 ____D () C:\Program Files\Norton 360 Premier Edition
2015-04-04 15:53 - 2013-08-05 20:15 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2015-04-04 15:46 - 2006-11-02 22:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-04 15:46 - 2006-11-02 22:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-04 15:37 - 2012-04-13 05:19 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-04 15:31 - 2014-10-07 04:47 - 00000000 ____D () C:\Users\User\Desktop\TRI CARE
2015-04-04 15:20 - 2009-08-29 05:21 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-04 15:18 - 2009-02-14 06:52 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-04 15:16 - 2013-04-14 09:08 - 00000336 _____ () C:\Windows\Tasks\HP Photo Creations Communicator.job
2015-04-04 15:14 - 2009-08-04 03:11 - 01234098 _____ () C:\Windows\WindowsUpdate.log
2015-04-04 15:11 - 2009-08-17 09:49 - 00095828 _____ () C:\ProgramData\nvModes.001
2015-04-04 15:09 - 2009-08-29 05:21 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-04 15:09 - 2009-08-15 09:29 - 00095828 _____ () C:\ProgramData\nvModes.dat
2015-04-04 15:09 - 2006-11-02 23:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-04 08:00 - 2009-08-06 13:33 - 00000012 _____ () C:\Windows\bthservsdp.dat
2015-04-04 08:00 - 2006-11-02 23:01 - 00032652 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-03 05:13 - 2008-01-21 12:47 - 01067430 _____ () C:\Windows\PFRO.log
2015-03-30 20:00 - 2013-10-03 11:43 - 00000000 ____D () C:\Users\User\AppData\Local\filestore
2015-03-30 19:59 - 2013-10-03 11:41 - 00000000 ____D () C:\Users\User\AppData\Roaming\Foxtel
2015-03-30 19:45 - 2009-02-12 06:16 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-03-30 19:45 - 2006-11-02 21:18 - 00000000 ____D () C:\Windows\system
2015-03-30 19:42 - 2014-10-08 20:38 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2015-03-30 19:42 - 2009-12-16 19:34 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-03-30 19:27 - 2013-04-28 09:21 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype
2015-03-30 19:27 - 2013-04-28 09:20 - 00000000 ____D () C:\ProgramData\Skype
2015-03-30 19:20 - 2009-08-28 08:06 - 00000000 ____D () C:\Program Files\Canon
2015-03-30 19:19 - 2009-08-28 08:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2015-03-28 05:15 - 2014-09-23 20:05 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe
2015-03-28 05:10 - 2012-04-13 05:19 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-28 05:10 - 2011-05-16 05:39 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-13 07:54 - 2009-08-23 20:53 - 374451400 _____ () C:\Windows\MEMORY.DMP
2015-03-13 07:54 - 2009-08-23 20:53 - 00000000 ____D () C:\Windows\Minidump
2015-03-12 05:37 - 2013-07-12 08:05 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-12 05:12 - 2006-11-02 20:24 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe

==================== Files in the root of some directories =======

2011-11-15 12:23 - 2011-11-15 12:23 - 0000272 _____ () C:\Users\User\AppData\Roaming\.backup.dm
2009-08-19 11:33 - 2015-03-04 12:23 - 0001354 _____ () C:\Users\User\AppData\Roaming\wklnhst.dat
2012-12-02 04:57 - 2012-12-02 04:57 - 0000552 _____ () C:\Users\User\AppData\Local\d3d8caps.dat
2009-08-30 07:37 - 2014-09-06 22:15 - 0007592 _____ () C:\Users\User\AppData\Local\d3d9caps.dat
2009-08-23 08:22 - 2013-04-14 07:18 - 0025600 _____ () C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-25 07:25 - 2014-02-25 07:25 - 0004096 ____H () C:\Users\User\AppData\Local\keyfile3.drm
2009-08-06 13:46 - 2009-08-06 13:46 - 0003070 _____ () C:\Users\User\AppData\Local\MyWinLockerInstaller.txt-20090806.log
2009-02-14 07:02 - 2009-08-06 13:50 - 0004530 _____ () C:\ProgramData\ArcadeDeluxe2.log
2011-08-12 06:24 - 2011-08-12 07:51 - 0000356 _____ () C:\ProgramData\aygdr_save.log
2011-04-22 07:45 - 2011-04-22 09:59 - 0003900 _____ () C:\ProgramData\dorcrane_save.log
2009-08-17 09:49 - 2015-04-04 15:11 - 0095828 _____ () C:\ProgramData\nvModes.001
2009-08-15 09:29 - 2015-04-04 15:09 - 0095828 _____ () C:\ProgramData\nvModes.dat
2011-04-24 12:02 - 2011-04-24 12:05 - 0000090 _____ () C:\ProgramData\PS.log

Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.560.dll
C:\Users\User\blackra1n.exe

Some content of TEMP:
====================
C:\Users\User\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\User\AppData\Local\Temp\MSNE565.exe
C:\Users\User\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\User\AppData\Local\Temp\SkypeSetup.exe
C:\Users\User\AppData\Local\Temp\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}_N360_24331.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-04-04 15:17

==================== End Of Log ============================

 

 

ADDITION NOTE:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by [removed] at 2015-04-04 15:59:23
Running from C:\Users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2PANU6QD
Boot Mode: Normal
==========================================================

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton 360 Premier Edition (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton 360 Premier Edition (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton 360 Premier Edition (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer Assist (HKLM\…\Acer Assist) (Version:  - Acer Incorporated)
Acer Backup Manager (HKLM\…\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 1.0.0.26 - NewTech Infosystems)
Acer Bio Protection (HKLM\…\InstallShield_{565A39D6-4FB0-4F35-A2AC-0DC66ACC3520}) (Version: 6.1.22 - Egis Technology Inc.)
Acer Crystal Eye Webcam (HKLM\…\{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}) (Version: 5.0.7.1 - Suyin Optronics Corp)
Acer eRecovery Management (HKLM\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.00.3005 - Acer Incorporated)
Acer GridVista (HKLM\…\GridVista) (Version: 2.72.317 - )
Acer PowerSmart Manager (HKLM\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 4.01.3004 - Acer Incorporated)
Acer Registration (HKLM\…\Acer Registration) (Version:  - Acer - Leader Technologies)
Acer ScreenSaver (HKLM\…\Acer Screensaver) (Version: 1.0.0.0226 - Acer)
Acrobat.com (HKLM\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated)
Acrobat.com (Version: 0.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM\…\Adobe AIR) (Version: 3.7.0.1530 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM\…\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.5 - Adobe Systems Incorporated)
Adobe Flash Player 10 Plugin (HKLM\…\{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}) (Version: 10.0.12.36 - Adobe Systems, Inc.)
Adobe Flash Player 17 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader X (10.1.11) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.11 - Adobe Systems Incorporated)
Agere Systems HDA Modem (HKLM\…\Agere Systems Soft Modem) (Version:  - Agere Systems)
Alcatel SpeedTouch USB Software (HKLM\…\{D41FAAA9-8048-4906-86B2-9AADEA1FA0B7}) (Version:  - )
Amazon 1Button App (HKLM\…\Amazon Browser Settings) (Version: 3.0 - Amazon)
Amazon Browser Bar (Version: 3.0.2012.0802 - Amazon.com) Hidden <==== ATTENTION
Anti-phishing Domain Advisor (HKLM\…\Anti-phishing Domain Advisor) (Version: 1.0.0.0 - Visicom Media Inc. (Powered by Panda Security))
Apple Application Support (HKLM\…\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft PhotoStudio 5.5 (HKLM\…\{85309D89-7BE9-4094-BB17-24999C6118FC}) (Version:  - ArcSoft)
Backup Manager Basic (Version: 1.0.0.26 - NewTech Infosystems) Hidden
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom Gigabit NetLink Controller (HKLM\…\{9AF0B106-56F1-461B-A270-95BC1682E282}) (Version: 11.34.02 - Broadcom Corporation)
C:\Program Files\Acer GameZone\GameConsole (HKLM\…\{71C2828F-2678-4675-BDEC-895424861262}_is1) (Version: 2.0.1.5 - Oberon Media, Inc.)
Canon MP170 (HKLM\…\{91175441-4E5D-4e13-B116-828FD352CDB2}) (Version:  - )
Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Download Updater (AOL LLC) (HKLM\…\SoftwareUpdUtility) (Version:  - ) <==== ATTENTION
Easy-WebPrint (HKLM\…\Easy-WebPrint) (Version:  - )
eSobi v2 (HKLM\…\InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.3.000223 - esobi Inc.)
eSobi v2 (Version: 2.0.3.000223 - esobi Inc.) Hidden
Fingerprint Solution (Version: 6.1.22.0 - Egis Technology Inc.) Hidden
Foxtel PLAY (HKU\S-1-5-21-3813807832-1416314213-169775867-1000\…\Foxtel PLAY 1.6) (Version: 1.6 - Foxtel)
Foxtel PLAY (Version: 1.6 - Foxtel) Hidden
Google Chrome (HKLM\…\Google Chrome) (Version: 41.0.2272.118 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
HP Deskjet 2050 J510 series Basic Device Software (HKLM\…\{E654D1E3-B18B-4953-BFBC-F16227323E05}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 2050 J510 series Help (HKLM\…\{7A3DF2E2-CF13-44FB-A93E-F71D5381DB3F}) (Version: 140.0.61.61 - Hewlett Packard)
HP Deskjet 2050 J510 series Product Improvement Study (HKLM\…\{29498512-A137-4478-8691-922829F108DC}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM\…\HP Photo Creations) (Version: 1.0.0.12992 - HP Photo Creations Powered by RocketLife)
HP Update (HKLM\…\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard)
Java 7 Update 60 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.600 - Oracle)
Junk Mail filter update (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Mahjong Escape Ancient China (HKLM\…\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}) (Version:  - Oberon Media)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM\…\{91110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\…\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Works (HKLM\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Microsoft Works 6-9 Converter (HKLM\…\{95140000-0137-0409-0000-0000000FF1CE}) (Version: 14.0.6120.5002 - Microsoft Corporation)
Mobile Broadband Manager (Version: 3.8.11219 - Telstra) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyWinLocker (HKLM\…\{68301905-2DEA-41CE-A4D4-E8B443B099BA}) (Version: 3.1.36.0 - EgisTec)
Norton 360 Premier Edition (HKLM\…\N360) (Version: 20.6.0.27 - Symantec Corporation)
NTI Backup Now 5 (HKLM\…\InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}) (Version: 5.1.2.616 - NewTech Infosystems)
NTI Backup Now Standard (Version: 5.1.2.616 - NewTech Infosystems) Hidden
NTI Media Maker 8 (HKLM\…\InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}) (Version: 8.0.2.6509 - NewTech Infosystems)
NTI Media Maker 8 (Version: 8.0.2.6509 - NewTech Infosystems) Hidden
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version:  - NVIDIA Corporation)
Online Games Manager v1.30 (HKLM\…\Online Games Manager) (Version: 1.30.14 - Real Networks, Inc.)
Orion (HKLM\…\{5B63A470-9334-44D1-AF61-6CE2DB565AE9}) (Version: 2.5.0 - Convesoft)
QuickTime 7 (HKLM\…\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5791 - Realtek Semiconductor Corp.)
Safari (HKLM\…\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Kies3 (HKLM\…\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.0.13091.39 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (Version: 3.0.13091.39 - Samsung Electronics Co., Ltd.) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 12.1.0.0 - Synaptics)
Telstra Mobile Broadband Manager (HKLM\…\Mobile Broadband Manager) (Version: 3.8.11219 - Telstra)
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Viewpoint Media Player (HKLM\…\ViewpointMediaPlayer) (Version:  - )
Web Assistant 2.0.0.604 (HKLM\…\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1) (Version: 2.0.0.604 - IncrediBar) <==== ATTENTION
Web Games Player Plugin (HKLM\…\Web Games Player Plugin) (Version:  - Zylom Games)
WIDCOMM Bluetooth Software 6.0.1.6400 (HKLM\…\{03D1988F-469F-4843-8E6E-E5FE9D17889D}) (Version: 6.0.1.6400 - Broadcom Corporation)
Windows Live Essentials (HKLM\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM\…\{9422C8EA-B0C6-4197-B8FC-DC797658CA00}) (Version: 5.000.818.6 - Microsoft Corporation)
Windows Live Sync (HKLM\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3813807832-1416314213-169775867-1000_Classes\CLSID\{1853e19a-4e54-4190-8deb-2e1cc947cd60}\InprocServer32 -> C:\Program Files\AOL Desktop 9.6\axtrack.dll No File
CustomCLSID: HKU\S-1-5-21-3813807832-1416314213-169775867-1000_Classes\CLSID\{7629C9DE-2E38-4963-A01C-02FFAC203D87}\InprocServer32 -> C:\Program Files\AOL Desktop 9.6\axtrack.dll No File
CustomCLSID: HKU\S-1-5-21-3813807832-1416314213-169775867-1000_Classes\CLSID\{B9F3009B-976B-41C4-A992-229DCCF3367C}\InprocServer32 -> C:\Program Files\AOL Desktop 9.6\axtrack.dll No File

==================== Restore Points  =========================

25-07-2014 04:08:00 Windows Update
15-08-2014 03:36:51 Windows Update
21-08-2014 12:50:11 Windows Update
11-09-2014 04:40:05 Windows Update
08-10-2014 20:30:24 Device Driver Package Install: Apple, Inc. Universal Serial Bus controllers
18-10-2014 04:55:43 Windows Update
14-11-2014 05:52:39 Windows Update
12-12-2014 03:38:18 Windows Update
15-01-2015 05:10:10 Windows Update
12-02-2015 05:50:10 Windows Update
06-03-2015 03:00:21 Windows Update
12-03-2015 04:59:40 Windows Update
30-03-2015 19:00:10 Removed AuthenTec Fingerprint Sensor Minimum Install.
30-03-2015 19:10:10 Removed Ask Shopping Toolbar
30-03-2015 19:10:39 Removed Ask Shopping Toolbar
30-03-2015 19:13:41 Removed Ask Toolbar
30-03-2015 19:15:00 Removed AuthenTec Fingerprint Sensor Minimum Install.
30-03-2015 19:16:08 Removed Apple Mobile Device Support
30-03-2015 19:21:30 Removed LG United Mobile Driver
30-03-2015 19:24:35 Removed Skype Click to Call
30-03-2015 19:25:09 Removed Skype Click to Call
30-03-2015 19:26:24 Removed Skype™ 7.0
30-03-2015 19:37:06 Removed iTunes
30-03-2015 19:45:26 Removed Realtek USB 2.0 Card Reader
30-03-2015 19:57:27 Removed Foxtel GO
30-03-2015 19:59:41 Installed Foxtel PLAY

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 20:23 - 2006-09-19 07:41 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0549801E-FEAD-48F5-A548-5A469A6C0B98} - System32\Tasks\Acer\Burn Notification => C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe [2009-02-05] (Acer)
Task: {24A9568F-2939-408F-AD07-B7D288B79D80} - System32\Tasks\HPCustParticipation HP Deskjet 2050 J510 series => C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\HPCustPartic.exe [2010-11-16] (Hewlett-Packard Co.)
Task: {27DF964F-3B43-4AD2-B577-B8CAFA2260CD} - System32\Tasks\McQcTask => c:\PROGRA~1\mcafee\mqc\QcConsol.exe
Task: {29E8E62F-CCC1-4808-81C3-2323AA7E1178} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-28] (Adobe Systems Incorporated)
Task: {310D13D2-722A-4AE4-A526-6A97705DFF4C} - System32\Tasks\McDefragTask => c:\PROGRA~1\mcafee\mqc\QcConsol.exe
Task: {312709FF-0C3E-4BCF-AE0A-B26333F44A57} - System32\Tasks\Microsoft\Windows\RestartManager\{0FE66A63-2083-4eec-B7E7-EF53E7C07C10} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation)
Task: {494EC38E-B639-453A-A862-FC43A27E1294} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-20] (Google Inc.)
Task: {67D07F4C-BA26-4CB6-A74D-912B7126ADE1} - System32\Tasks\HP Deskjet 2050 J510 series.exe => C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\HP Deskjet 2050 J510 series.exe [2010-11-16] (Hewlett-Packard Co.)
Task: {6936C532-1283-4BF0-B4DE-A758ED2F977E} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2014-10-16] ()
Task: {6D61D295-2BAD-4D06-9D52-F2F16AB3DDC8} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {78E8499D-CED4-46A6-8340-90EBF72B2D57} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {9576132D-0A14-419A-B1D0-559B6D0B0016} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {BB2C7FD9-750A-4FAA-903F-28916DA2D1E5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-20] (Google Inc.)
Task: {C24FFB84-182F-415E-AD16-6E54FC200AB1} - System32\Tasks\ASP => C:\Program Files\RegClean Pro\SystweakASP.exe <==== ATTENTION
Task: {D3F9771A-3193-4E43-BCAC-FC094502039F} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton 360 Premier Edition\Engine\20.6.0.27\WSCStub.exe [2014-12-07] (Symantec Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\Communicator.exe
Task: C:\Windows\Tasks\McDefragTask.job => c:\PROGRA~1\mcafee\mqc\QcConsol.exe C:\Windows\system32\defrag.exe
Task: C:\Windows\Tasks\McQcTask.job => c:\PROGRA~1\mcafee\mqc\QcConsol.exe

==================== Loaded Modules (whitelisted) ==============

2008-04-23 11:16 - 2008-04-23 11:16 - 00126976 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2009-08-06 13:39 - 2008-07-29 19:29 - 00200704 _____ () C:\Windows\PLFSetI.exe
2009-02-01 21:28 - 2009-02-01 21:28 - 00460199 _____ () C:\Program Files\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2009-02-05 19:28 - 2009-02-05 19:28 - 01076224 _____ () C:\Program Files\NewTech Infosystems\Acer Backup Manager\ACE.dll
2013-03-22 04:24 - 2013-03-22 04:24 - 00222368 _____ () C:\Program Files\Amazon Browser Bar\ToolbarUpdaterService.exe
2012-09-16 05:16 - 2013-06-30 16:37 - 00188760 _____ () C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
2014-12-12 03:55 - 2012-05-31 00:51 - 00699280 ____R () C:\PROGRAM FILES\NORTON 360 PREMIER EDITION\ENGINE\20.6.0.27\wincfi39.dll
2012-08-16 05:34 - 2012-08-16 05:34 - 00066256 _____ () C:\Program Files\Amazon Browser Bar\AlxSSBPS.dll
2012-09-16 05:16 - 2013-06-30 16:37 - 00170840 _____ () C:\Program Files\Web Assistant\Extension32.dll
2012-08-16 05:36 - 2012-08-16 05:36 - 00577072 _____ () C:\Program Files\Amazon Browser Bar\AmazonBrowserBarSSB.3.0.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:131C0EE9
AlternateDataStreams: C:\ProgramData\Temp:2CB9631F
AlternateDataStreams: C:\ProgramData\Temp:4F636E25
AlternateDataStreams: C:\ProgramData\Temp:798A3728
AlternateDataStreams: C:\ProgramData\Temp:8750DCE4
AlternateDataStreams: C:\ProgramData\Temp:9836B5E4
AlternateDataStreams: C:\ProgramData\Temp:9E22BBE8
AlternateDataStreams: C:\ProgramData\Temp:A7C40691
AlternateDataStreams: C:\ProgramData\Temp:B203B914
AlternateDataStreams: C:\ProgramData\Temp:B623B5B8
AlternateDataStreams: C:\ProgramData\Temp:BB24555F
AlternateDataStreams: C:\ProgramData\Temp:CDFF58FE
AlternateDataStreams: C:\ProgramData\Temp:CE0A077E
AlternateDataStreams: C:\ProgramData\Temp:DCAF903C
AlternateDataStreams: C:\ProgramData\Temp:F7862839

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3813807832-1416314213-169775867-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
DNS Servers: 192.168.1.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

==================== Accounts: =============================

Administrator (S-1-5-21-3813807832-1416314213-169775867-500 - Administrator - Disabled)
Guest (S-1-5-21-3813807832-1416314213-169775867-501 - Limited - Disabled)
User (S-1-5-21-3813807832-1416314213-169775867-1000 - Administrator - Enabled) => C:\Users\User

==================== Faulty Device Manager Devices =============

Name: Belkin USB Easy Transfer Cable
Description: Belkin USB Easy Transfer Cable
Class Guid: {bc103702-dd72-406f-9b28-95c868337b59}
Manufacturer: Microsoft
Service: winusb
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

==================== Event log errors: =========================

Application errors:
==================
Error: (04/04/2015 03:17:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SETUP.EXE version 12.0.6606.1000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 9fc
Start Time: 01d06e95ec5f9083
Termination Time: 31

Error: (04/04/2015 03:09:55 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 11) (User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (04/04/2015 03:09:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/04/2015 07:07:16 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 8.0.6001.19088 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 12d4
Start Time: 01d06e3dc5ef2ea0
Termination Time: 36

Error: (04/04/2015 04:40:52 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 11) (User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabA required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Error: (04/04/2015 04:40:43 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (04/03/2015 06:16:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.19088, time stamp 0x4de07b1b, faulting module ntdll.dll, version 6.0.6001.18538, time stamp 0x4cb733dc, exception code 0xc0000005, fault offset 0x0003ce36,
process id 0x1704, application start time 0xiexplore.exe0.

Error: (04/03/2015 06:13:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.19088, time stamp 0x4de07b1b, faulting module AmazonBrowserBar.3.0.dll_unloaded, version 0.0.0.0, time stamp 0x501ad87c, exception code 0xc0000005, fault offset 0x04ac900e,
process id 0x854, application start time 0xiexplore.exe0.

Error: (04/03/2015 06:09:34 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.19088, time stamp 0x4de07b1b, faulting module AmazonBrowserBar.3.0.dll_unloaded, version 0.0.0.0, time stamp 0x501ad87c, exception code 0xc0000005, fault offset 0x0350829c,
process id 0x148c, application start time 0xiexplore.exe0.

Error: (04/03/2015 06:08:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.19088, time stamp 0x4de07b1b, faulting module AmazonBrowserBar.3.0.dll_unloaded, version 0.0.0.0, time stamp 0x501ad87c, exception code 0xc0000005, fault offset 0x04a2829c,
process id 0xfd0, application start time 0xiexplore.exe0.

System errors:
=============
Error: (04/04/2015 03:39:30 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: 30000

Error: (04/04/2015 03:09:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: X6XSEx%%2

Error: (04/04/2015 03:09:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Error: (04/04/2015 03:09:26 PM) (Source: HTTP) (EventID: 15016) (User: )
Description: \Device\Http\ReqQueueKerberos

Error: (04/04/2015 04:40:44 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: X6XSEx%%2

Error: (04/04/2015 04:40:44 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Error: (04/04/2015 04:40:23 AM) (Source: Microsoft-Windows-ResourcePublication) (EventID: 1002) (User: NT AUTHORITY)
Description: Provider\Microsoft.Base.Publication/Publication/Computer

Error: (04/04/2015 04:40:14 AM) (Source: HTTP) (EventID: 15016) (User: )
Description: \Device\Http\ReqQueueKerberos

Error: (04/03/2015 05:15:01 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: X6XSEx%%2

Error: (04/03/2015 05:15:01 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Microsoft Office Sessions:
=========================
Error: (02/17/2015 04:50:43 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6715.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 136 seconds with 60 seconds of active time.  This session ended with a crash.

CodeIntegrity Errors:
===================================
  Date: 2015-04-04 15:59:11.969
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2015-04-04 15:59:11.828
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2015-04-04 15:59:11.672
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2015-04-04 15:59:11.532
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS because the set of per-page image hashes could not be found on the system.

  Date: 2015-04-04 15:58:50.706
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-04-04 15:58:50.550
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-04-04 15:58:50.378
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-04-04 15:58:50.113
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-04-04 15:58:49.910
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

  Date: 2015-04-04 15:58:49.770
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
Percentage of memory in use: 55%
Total physical RAM: 3065.9 MB
Available physical RAM: 1349.83 MB
Total Pagefile: 6334.09 MB
Available Pagefile: 4628.67 MB
Total Virtual: 2047.88 MB
Available Virtual: 1886.61 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:288.32 GB) (Free:174.28 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: 50CD7CDE)
Partition 1: (Not Active) - (Size=9.8 GB) - (Type=27)
Partition 2: (Active) - (Size=288.3 GB) - (Type=07 NTFS)

==================== End Of Log ============================

 

 

 

 

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days.

:)


Hello there, megan.pen

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
  • IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

    —————————————————————————————————

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • The tool will start to update the database, please wait a bit.
    • Click on I agree button.
    • Click on the Scan button.
    • AdwCleaner will begin…be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button…a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Copy and paste the contents of that logfile in your next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
    —————————————————————————————————

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI