A friend of mine has a computer that started acting real slow and a program indicated that it had several problems (PC Cleaner) I manually removed that, but I am sure there is a bunch of other stuff going on. I couldn't get the link to FRST to work so I downloaded it elsewhere, so I am not sure if it is the correct version.
Thanks for your time in looking at this.
[removed]
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\stacsv.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
() C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AOL Inc.) C:\Program Files\Common Files\aol\1356558711\ee\aolsoftware.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(CyberLink Corp.) C:\Program Files\Dell\MediaDirect\PCMService.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\AEstSrv.exe
() C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe
(ConsumerInput) C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe
(Creative Technology Ltd.) C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(COMPANYVERS_NAME) C:\Program Files\CouponXplorer_5z\bar\1.bin\5zbarsvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Lavasoft Limited) C:\Program Files\Lavasoft\Web Companion\TcpService\2.3.3.0\LavasoftTcpService.exe
() C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
(Lavasoft) C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Qihu Software Co. Limited) C:\Program Files\360\Total Security\safemon\QHWatchdog.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
() C:\Program Files\OLBPre\OLBPre.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(ConsumerInput) C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe
(ConsumerInput) C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(RaMMicHaeL) C:\Program Files\Unchecky\bin\unchecky_svc.exe
(RaMMicHaeL) C:\Program Files\Unchecky\bin\unchecky_bg.exe
(AVAST Software) C:\Users\Debbie\Desktop\aswMBR.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [] => [X]
HKLM\…\Run: [HostManager] => C:\Program Files\Common Files\AOL\1356558711\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [978520 2015-01-30] (Microsoft Corporation)
HKLM\…\Run: [PCMService] => C:\Program Files\Dell\MediaDirect\PCMService.exe [126976 2008-05-09] (CyberLink Corp.)
HKLM\…\Run: [Dell Webcam Central] => C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe [438403 2008-02-19] (Creative Technology Ltd.)
HKLM\…\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [196608 2008-06-30] (Alps Electric Co., Ltd.)
HKLM\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2009-12-18] (Adobe Systems Incorporated)
HKLM\…\Run: [ShopAtHomeWatcher] => C:\Users\Debbie\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [948672 2009-12-11] (Adobe Systems Incorporated)
HKLM\…\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM\…\Run: [Price Finder] => C:\Program Files\Price Finder\PriceFinderHelper.exe [43088 2013-11-25] (MindSpark Interactive Network)
HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [442467 2008-06-25] (IDT, Inc.)
HKLM\…\Run: [SunJavaUpdateSched] => "C:\Program Files\Java\jre7\bin\jusched.exe"
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\…\Run: [QHSafeTray] => C:\Program Files\360\Total Security\safemon\QHSafeTray.exe [1208944 2015-03-03] ()
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Run: [Messenger (Yahoo!)] => C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [6276408 2011-08-22] (Yahoo! Inc.)
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Run: [EA Core] => "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Run: [WeatherBug] => C:\Program Files\Earth Networks\WeatherBug\WeatherBug.exe [146736 2014-09-23] ()
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Run: [Web Companion] => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe [1303872 2015-03-12] (Lavasoft)
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Run: [UpdateAdmin] => C:\Users\Debbie\AppData\Local\UpdateAdmin\UpdateAdmin.exe [225552 2014-10-16] (DownloadAdmin)
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\MountPoints2: {1128326d-8a4e-11dd-81d3-806e6f6e6963} - E:\Setup.exe
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [294912 2008-01-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-01-16]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk [2012-12-26]
ShortcutTarget: QuickSet.lnk -> C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
Startup: C:\Users\Debbie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2015-04-11]
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files\OLBPre\OLBPre.exe ()
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2008-09-24]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2008-09-24]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2009-12-18] (Adobe Systems Incorporated)
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO: AOL Toolbar Loader -> {3ef64538-8b54-4573-b48f-4d34b0238ab2} -> C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
BHO: Ask Toolbar -> {4F524A2D-5637-4300-76A7-7A786E7484D7} -> C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-V7C\Passport.dll [2013-11-08] (APN LLC.)
BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-07-25] (Oracle Corporation)
BHO: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files\Consumer Input\InternetExplorer\dca-bho.dll [2015-02-25] (Compete, Inc.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-07-25] (Oracle Corporation)
BHO: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll No File
Toolbar: HKLM - Ask Toolbar - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-V7C\Passport.dll [2013-11-08] (APN LLC.)
Toolbar: HKLM - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
Toolbar: HKU\.DEFAULT -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> Ask Toolbar - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-V7C\Passport.dll [2013-11-08] (APN LLC.)
Toolbar: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> AOL Toolbar - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-11-28] (Microsoft Corporation)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Winsock: Catalog9 01 C:\Windows\system32\LavasoftTcpService.dll [326288 2015-04-11] (Lavasoft Limited)
Winsock: Catalog9 02 C:\Windows\system32\LavasoftTcpService.dll [326288 2015-04-11] (Lavasoft Limited)
Winsock: Catalog9 03 C:\Windows\system32\LavasoftTcpService.dll [326288 2015-04-11] (Lavasoft Limited)
Winsock: Catalog9 04 C:\Windows\system32\LavasoftTcpService.dll [326288 2015-04-11] (Lavasoft Limited)
Winsock: Catalog9 30 C:\Windows\system32\LavasoftTcpService.dll [326288 2015-04-11] (Lavasoft Limited)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default
FF NewTab: hxxp://www.bing.com/?pc=COSP&ptag;=D041115-ABB80C9363E1D41E9AFF&form;=CONMHP&conlogo;=CT3331964
FF DefaultSearchEngine: Bing
FF SearchEngineOrder.1: Ask Search
FF SelectedSearchEngine: Bing
FF Homepage: hxxp://www.bing.com/?pc=COSP&ptag;=D041115-ABB80C9363E1D41E9AFF&form;=CONMHP&conlogo;=CT3331964
FF Keyword.URL: hxxp://aolsearch.aol.com/aol/search?invocationType=client_searchbox&query;=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-04-11] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin: @CouponXplorer_5z.com/Plugin -> C:\Program Files\CouponXplorer_5z\bar\1.bin\NP5zStub.dll [2013-11-25] (MindSpark)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-07-25] (Oracle Corporation)
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll [2008-09-19] (Yahoo! Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-13] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-13] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2012-02-17] (VideoLAN)
FF Plugin: @viewpoint.com/VMP -> C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2009-12-18] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-06-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-06-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-06-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-06-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-06-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2013-08-02] (Coupons, Inc.)
FF Extension: CouponXplorer - C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\Extensions\5zffxtbr@CouponXplorer_5z.com [2013-12-22]
FF Extension: AOL Toolbar - C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\Extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} [2015-03-13]
FF Extension: Ask Toolbar - C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\Extensions\[removed] [2013-11-08]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-30]
FF HKLM\…\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\IB Updater\Firefox
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\360\Total Security\safemon\webprotection_firefox
FF Extension: 360 Internet Protection - C:\Program Files\360\Total Security\safemon\webprotection_firefox [2015-04-11]
FF HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Firefox\Extensions: [ConsumerInput@Compete] - C:\Program Files\Consumer Input\Firefox\ciff-3.2.0-12099.xpi
FF Extension: No Name - C:\Program Files\Consumer Input\Firefox\ciff-3.2.0-12099.xpi [2015-01-21]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2014-10-19]
Chrome:
=======
CHR HomePage: Default -> hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp;=yhs-fullyhosted_003&type;=wny_ggbc_15_15¶m1=1¶m2=f%3D1%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutDtDtBtByCzytA0CzyyEyBtD0DtC0AyDtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyBzzyEyDtB0D0BzytGzz0DzztAtGtC0C0F0EtGyDyE0ByEtGtA0A0ByE0Dzz0AtDyD0CyB0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0E0EyByEzztCzztGzz0DtBtDtGyEtCtCzztGzztA0F0FtGyEyDtC0BtAyDtBtBtDtBtA0A2QtN0A0LzutB%26cr%3D1162628522%26a%3Dwny_ggbc_15_15%26os%3DWindows Vista (TM) Home Premium
CHR StartupUrls: Default -> "hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp;=yhs-fullyhosted_003&type;=wny_ggbc_15_15¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutDtDtBtByCzytA0CzyyEyBtD0DtC0AyDtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyBzzyEyDtB0D0BzytGzz0DzztAtGtC0C0F0EtGyDyE0ByEtGtA0A0ByE0Dzz0AtDyD0CyB0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0E0EyByEzztCzztGzz0DtBtDtGyEtCtCzztGzztA0F0FtGyEyDtC0BtAyDtBtBtDtBtA0A2QtN0A0LzutB%26cr%3D1162628522%26a%3Dwny_ggbc_15_15%26os%3DWindows Vista (TM) Home Premium", "hxxp://www.google.com/"
CHR DefaultSearchKeyword: Default -> search provided by yahoo.com
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Coupons Inc., Coupon Printer Manager ) - C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll No File
CHR Plugin: (downloadUpdater) - C:\Program Files\Mozilla Firefox\plugins\npdnu.dll No File
CHR Plugin: (downloadUpdater2) - C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll No File
CHR Plugin: (Coupons Inc., Coupon Printer Manager ) - C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (MetaStream 3 Plugin) - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-15]
CHR Extension: (Google Search) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-15]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-11]
CHR Extension: (Google Wallet) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-11]
CHR Extension: (Gmail) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-15]
CHR HKLM\…\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx [Not Found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\aestsrv.exe [73728 2008-06-25] (Andrea Electronics Corporation)
S3 AOL ACS; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [46184 2014-02-06] (AOL Inc.)
S4 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-11-08] () [File not signed]
R2 consumerinput_update; C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe [106296 2015-04-11] (ConsumerInput)
S3 consumerinput_updatem; C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe [106296 2015-04-11] (ConsumerInput)
R2 CouponXplorer_5zService; C:\Program Files\CouponXplorer_5z\bar\1.bin\5zbarsvc.exe [44752 2013-11-25] (COMPANYVERS_NAME)
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [161048 2008-05-02] (Stardock Corporation)
R2 LavasoftTcpService; C:\Program Files\Lavasoft\Web Companion\TcpService\2.3.3.0\LavasoftTcpService.exe [836984 2015-03-12] (Lavasoft Limited)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation)
R2 QHActiveDefense; C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe [821872 2015-03-03] ()
R2 SearchProtectionService; C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [17768 2015-03-12] ()
R2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2008-08-14] (SupportSoft, Inc.)
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\STacSV.exe [221273 2008-06-25] (IDT, Inc.)
R2 Unchecky; C:\Program Files\Unchecky\bin\Unchecky_svc.exe [164600 2015-06-09] (RaMMicHaeL)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker.sys [88136 2015-03-03] (360.cn)
R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [65608 2015-03-03] (360.cn)
R1 360Box; C:\Windows\System32\DRIVERS\360Box.sys [202312 2015-03-03] (360.cn)
R3 360Camera; C:\Windows\System32\Drivers\360Camera.sys [34888 2015-03-03] (360.cn)
R1 360SelfProtection; C:\Windows\System32\drivers\360SelfProtection.sys [174536 2015-03-03] (360安全中心)
R1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV.sys [169040 2015-03-03] (Qihu 360 Software Co., Ltd.)
R1 EfiMon; C:\Windows\System32\Drivers\Efimon.sys [23752 2015-03-03] (360安全中心)
R0 HookPort; C:\Windows\System32\Drivers\Hookport.sys [58440 2015-03-03] (360安全中心)
R3 itecir; C:\Windows\System32\DRIVERS\itecir.sys [54784 2008-03-14] (ITE Tech. Inc. )
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation)
R1 MpKsl6099da39; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E9AD4444-1FA9-48A9-9987-AA044985AAE1}\MpKsl6099da39.sys [39464 2015-06-09] (Microsoft Corporation)
S1 MpKslefaa4db8; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E9AD4444-1FA9-48A9-9987-AA044985AAE1}\MpKslefaa4db8.sys [39464 2015-04-12] () [File not signed]
R3 OA001Ufd; C:\Windows\System32\DRIVERS\OA001Ufd.sys [144672 2008-06-03] (Creative Technology Ltd.)
R3 OA001Vid; C:\Windows\System32\DRIVERS\OA001Vid.sys [277440 2008-09-19] (Creative Technology Ltd.)
R1 qutmdserv; C:\Windows\system32\drivers\qutmdrv.sys [257352 2015-03-03] (360.cn)
R1 qutmipc; C:\Windows\system32\drivers\qutmipc.sys [45896 2015-03-03] (360.cn)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed]
R3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-29] (America Online, Inc.)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U3 aswMBR; \??\C:\Users\Debbie\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Debbie\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-09 22:53 - 2015-06-09 22:56 - 00031915 _____ C:\Users\Debbie\Desktop\FRST.txt
2015-06-09 22:52 - 2015-06-09 22:54 - 00000000 ____D C:\FRST
2015-06-09 22:32 - 2015-06-09 22:29 - 05198336 _____ (AVAST Software) C:\Users\Debbie\Desktop\aswMBR.exe
2015-06-09 22:32 - 2015-06-09 22:29 - 01147904 _____ (Farbar) C:\Users\Debbie\Desktop\FRST.exe
2015-06-09 22:28 - 2015-06-09 22:29 - 01147904 _____ (Farbar) C:\Users\Debbie\Downloads\FRST.exe
2015-06-09 22:25 - 2015-06-09 22:29 - 05198336 _____ (AVAST Software) C:\Users\Debbie\Downloads\aswMBR.exe
2015-06-09 22:10 - 2015-06-09 22:23 - 00000000 ____D C:\ProgramData\4bfd38c400002905
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-09 23:08 - 2015-04-11 01:22 - 00000350 _____ C:\Windows\Tasks\CIMT_S-1-5-21-3035152371-51418450-4088448234-1000.job
2015-06-09 23:04 - 2012-09-14 07:11 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-09 23:01 - 2012-12-20 00:01 - 00000380 _____ C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
2015-06-09 22:56 - 2015-04-11 01:19 - 00000954 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job
2015-06-09 22:29 - 2008-09-24 08:36 - 02037775 _____ C:\Windows\WindowsUpdate.log
2015-06-09 22:24 - 2015-04-11 01:19 - 00000958 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job
2015-06-09 22:23 - 2015-04-11 01:19 - 00000000 __SHD C:\ProgramData\360Quarant
2015-06-09 22:23 - 2015-04-11 01:19 - 00000000 __SHD C:\$360Section
2015-06-09 22:08 - 2015-04-11 02:03 - 00000000 ____D C:\Program Files\PremierOpinion
2015-06-09 21:46 - 2015-03-13 08:49 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2015-06-09 21:42 - 2006-11-02 05:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-09 21:42 - 2006-11-02 05:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-09 21:41 - 2013-02-15 08:13 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-09 21:41 - 2006-11-02 06:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-09 21:23 - 2006-11-02 06:01 - 00032588 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-06-09 21:23 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\tracing
2015-06-09 21:13 - 2015-04-11 02:02 - 00000000 ____D C:\Users\Debbie\Documents\ProPCCleaner
2015-06-09 21:10 - 2006-11-02 03:33 - 00703388 _____ C:\Windows\system32\PerfStringBackup.INI
==================== Files in the root of some directories =======
2008-12-06 22:32 - 2009-10-17 07:17 - 8318896 _____ (Dell, Inc. ) C:\Users\Debbie\AppData\Roaming\DataSafeDotNet.exe
2015-04-11 01:18 - 2015-04-11 01:18 - 0021066 _____ () C:\Users\Debbie\AppData\Roaming\ICSW_0M0D1V1N1N1S1RtJ1V0G1P1P1J0B2Y1Q1Q2U.txt
2010-09-17 14:53 - 2014-12-08 17:16 - 0000296 _____ () C:\Users\Debbie\AppData\Roaming\wklnhst.dat
2012-12-26 11:16 - 2012-11-23 05:54 - 0196608 _____ () C:\Users\Debbie\AppData\Local\common_functions.dll
2009-02-03 21:24 - 2014-11-22 07:34 - 0007052 _____ () C:\Users\Debbie\AppData\Local\d3d9caps.dat
2008-11-04 22:10 - 2012-10-09 10:02 - 0020992 _____ () C:\Users\Debbie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-11-23 05:54 - 2012-11-23 05:54 - 0114688 _____ () C:\Users\Debbie\AppData\Local\ie_runner_app.exe
2012-12-26 11:16 - 2012-06-26 03:59 - 0940544 _____ (Apache Software Foundation) C:\Users\Debbie\AppData\Local\log4cxx.dll
2013-03-05 08:31 - 2013-03-05 08:31 - 0000057 _____ () C:\ProgramData\Ament.ini
Some files in TEMP:
====================
C:\Users\Debbie\AppData\Local\Temp\AcsInstall.dll
C:\Users\Debbie\AppData\Local\Temp\AdobeUpdater12345.exe
C:\Users\Debbie\AppData\Local\Temp\APNSetup.exe
C:\Users\Debbie\AppData\Local\Temp\CloudBackup2209.exe
C:\Users\Debbie\AppData\Local\Temp\compete.exe
C:\Users\Debbie\AppData\Local\Temp\cw.exe
C:\Users\Debbie\AppData\Local\Temp\en_ww_Package.exe
C:\Users\Debbie\AppData\Local\Temp\ICSW_0M0D1V1N1N1S1R.exe
C:\Users\Debbie\AppData\Local\Temp\install_flashplayer11x32axau_gtba_chra_dy_aih.exe
C:\Users\Debbie\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Debbie\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Debbie\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Debbie\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Debbie\AppData\Local\Temp\SHFOLDER.DLL
C:\Users\Debbie\AppData\Local\Temp\SpOrder.dll
C:\Users\Debbie\AppData\Local\Temp\supoptsetup.exe
C:\Users\Debbie\AppData\Local\Temp\UninstallEADM.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-09 21:55
==================== End of log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 08-06-2015
Ran by [removed] at 2015-06-09 23:11:04
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3035152371-51418450-4088448234-500 - Administrator - Disabled)
Debbie (S-1-5-21-3035152371-51418450-4088448234-1000 - Administrator - Enabled) => C:\Users\Debbie
Guest (S-1-5-21-3035152371-51418450-4088448234-501 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Out of date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AV: 360 Total Security (Disabled - Up to date) {2B66EE1E-E5C8-C2F7-648F-4E55AC68D37D}
AS: 360 Total Security (Disabled - Up to date) {90070FFA-C3F2-CD79-5E3F-7527D7EF99C0}
AS: Microsoft Security Essentials (Enabled - Out of date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
360 Total Security (HKLM\…\360TotalSecurity) (Version: 6.0.0.1152 - 360 Security Center)
Ad-Aware Web Companion (Version: 1.1.922.1860 - Lavasoft) Hidden
Adobe Flash Player 16 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader 8.1.3 (HKLM\…\{AC76BA86-7AD7-1033-7B44-A81300000003}) (Version: 8.1.3 - Adobe Systems Incorporated)
Adobe Reader 8.2.0 (HKLM\…\{AC76BA86-7AD7-1033-7B44-A82000000003}) (Version: 8.2.0 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM\…\Advanced Audio FX Engine) (Version: - )
AOL Toolbar (HKLM\…\AOL Toolbar) (Version: - AOL Inc.)
AOL Uninstaller (Choose which Products to Remove) (HKLM\…\AOL Uninstaller) (Version: - AOL Inc.)
Apple Application Support (HKLM\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ask Toolbar (HKLM\…\{4F524A2D-5637-4300-76A7-A758B70C0700}) (Version: 12.7.0.15 - APN, LLC) <==== ATTENTION
ATI Catalyst Control Center (HKLM\…\{055EE59D-217B-43A7-ABFF-507B966405D8}) (Version: 2.008.0407.2138 - )
Bing Rewards Client Installer (Version: 16.0.345.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
ccc-core-static (Version: 2008.0407.2139.36897 - ATI) Hidden
Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Consumer Input (remove only) (HKLM\…\Consumer Input Installer) (Version: - Compete Inc.) <==== ATTENTION
Coupon Printer for Windows (HKLM\…\Coupon Printer for Windows5.0.0.4) (Version: 5.0.0.4 - Coupons.com Incorporated)
Dell DataSafe Online (HKLM\…\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.1.0014 - Dell, Inc.)
Dell Dock (HKLM\…\{F6CB42B9-F033-4152-8813-FF11DA8E6A78}) (Version: 1.0.0 - Dell)
Dell Getting Started Guide (HKLM\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell Support Center (Support Software) (HKLM\…\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}) (Version: 2.2.09085 - Dell)
Dell Touchpad (HKLM\…\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.2.101.104 - Alps Electric)
Dell Webcam Central (HKLM\…\Dell Webcam Central) (Version: - )
Download Updater (AOL Inc.) (HKLM\…\SoftwareUpdUtility) (Version: - AOL Inc.) <==== ATTENTION
Google Chrome (HKLM\…\Google Chrome) (Version: 41.0.2272.118 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
HP Deskjet 3050 J610 series Basic Device Software (HKLM\…\{0564C76B-8E1F-4157-8654-B0F9F308BEE9}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 3050 J610 series Help (HKLM\…\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}) (Version: 140.0.63.63 - Hewlett Packard)
HP Deskjet 3050 J610 series Product Improvement Study (HKLM\…\{34E90074-C80C-4182-A995-65E88B5B56E0}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM\…\HP Photo Creations) (Version: 1.0.0.3781 - HP Photo Creations Powered by RocketLife)
HP Update (HKLM\…\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard)
HPDiagnosticCoreDll (HKLM\…\{9262B08F-E183-4FED-A2BD-23FF1A84EB7A}) (Version: 1.0.16.0 - Hewlett Packard)
Integrated Webcam Driver (1.03.02.0919) (HKLM\…\Creative OA001) (Version: - )
Intel(R) Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - )
ITECIR Driver (Version: 1.00.000 - ITE) Hidden
iTunes (HKLM\…\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 67 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.670 - Oracle)
LavasoftTcpService (Version: 2.3.3.0 - Lavasoft) Hidden
Live! Cam Avatar Creator (HKLM\…\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.1419.1 - Creative Technology Ltd)
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
MediaDirect (HKLM\…\{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}) (Version: 4.0 - Dell)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Works (HKLM\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM\…\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mozilla Firefox 30.0 (x86 en-US) (HKLM\…\Mozilla Firefox 30.0 (x86 en-US)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MyPC Backup (HKLM\…\OLBPre) (Version: - MyPC Backup) <==== ATTENTION
PDF Reader Packages (HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\PDF Reader Packages) (Version: - ) <==== ATTENTION
QuickSet (HKLM\…\{C4972073-2BFE-475D-8441-564EA97DA161}) (Version: 9.0.12 - Dell Inc.)
QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Roxio Creator DE (HKLM\…\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}) (Version: 10.1 - Roxio)
Skins (Version: 2008.0407.2139.36897 - ATI) Hidden
Spelling Dictionaries Support For Adobe Reader 8 (HKLM\…\{AC76BA86-7AD7-5464-3428-800000000003}) (Version: 8.0.0 - Adobe Systems)
Unchecky v0.3.7.5 (HKLM\…\Unchecky) (Version: 0.3.7.5 - RaMMicHaeL)
UpdateAdmin (HKLM\…\{07B4B423-E4DA-47D1-8327-B589EB4BEB58}) (Version: 2.0.1885 - DownloadAdmin) <==== ATTENTION!
Viewpoint Media Player (HKLM\…\ViewpointMediaPlayer) (Version: - )
VLC media player 2.0.0 (HKLM\…\VLC media player) (Version: 2.0.0 - VideoLAN)
WeatherBug® (HKLM\…\WeatherBug®) (Version: 10.0.7.4 - Earth Networks, Inc.)
Web Companion (HKLM\…\{902C3D36-9254-437D-98AC-913B78E60864}_WebCompanion) (Version: 1.1.922.1860 - Lavasoft)
Yahoo! Messenger (HKLM\…\Yahoo! Messenger) (Version: - Yahoo! Inc.)
Yahoo! Software Update (HKLM\…\Yahoo! Software Update) (Version: - )
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3035152371-51418450-4088448234-1000_Classes\CLSID\{1853e19a-4e54-4190-8deb-2e1cc947cd60}\InprocServer32 -> C:\Program Files\AOL Desktop 9.7c\axtrack.dll (AOL Inc.)
CustomCLSID: HKU\S-1-5-21-3035152371-51418450-4088448234-1000_Classes\CLSID\{7629C9DE-2E38-4963-A01C-02FFAC203D87}\InprocServer32 -> C:\Program Files\AOL Desktop 9.7c\axtrack.dll (AOL Inc.)
CustomCLSID: HKU\S-1-5-21-3035152371-51418450-4088448234-1000_Classes\CLSID\{B9F3009B-976B-41C4-A992-229DCCF3367C}\InprocServer32 -> C:\Program Files\AOL Desktop 9.7c\axtrack.dll (AOL Inc.)
==================== Restore Points =========================
ATTENTION: System Restore is disabled
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 03:23 - 2015-06-09 22:29 - 00001930 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
0.0.0.0 cdn.appround.biz
0.0.0.0 cdn.bigspeedpro.com
There are 5 more lines.
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {51A7228C-52A5-4AF8-9569-D8E01FA1A297} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Debbie => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-10] (Microsoft Corporation)
Task: {82EE9D76-1F7A-461F-9BC5-5CB47F2E4EDD} - System32\Tasks\SpeedUpMyPC => C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe <==== ATTENTION
Task: {89E65CB6-C786-4800-A2C5-9B8C209439EE} - System32\Tasks\ConsumerInputUpdateTaskMachineCore => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe [2015-04-11] (ConsumerInput) <==== ATTENTION
Task: {8A0C5E62-A6E8-4C64-9BCB-C8312BFE77D3} - System32\Tasks\FreeFileViewerUpdateChecker => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe <==== ATTENTION
Task: {93E23C54-3E67-4BFE-A42D-73D8B7B5621B} - System32\Tasks\UpdateAdmin => C:\Users\Debbie\AppData\Local\UpdateAdmin\UpdateAdmin.exe [2014-10-16] (DownloadAdmin) <==== ATTENTION
Task: {9AB9B2FC-A78D-42EE-8C65-5A927558BA08} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-26] (Google Inc.)
Task: {9F55970E-0C73-4433-BD43-9618091CABC4} - System32\Tasks\ConsumerInputUpdateTaskMachineUA => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe [2015-04-11] (ConsumerInput) <==== ATTENTION
Task: {A835556A-42A9-4D09-A452-CDD184CD4C27} - System32\Tasks\CIMT_daily_S-1-5-21-3035152371-51418450-4088448234-1000 => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe [2015-02-26] () <==== ATTENTION
Task: {AD06DD0F-F4D5-4535-8A91-53B10D72D9D0} - System32\Tasks\CIMT_S-1-5-21-3035152371-51418450-4088448234-1000 => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe [2015-02-26] () <==== ATTENTION
Task: {C3A7A6BC-D093-48DD-8754-6A3F2111D378} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {C86FD90E-B38B-4228-8E8A-BE89250F815D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-11] (Adobe Systems Incorporated)
Task: {C9FDD969-AF3C-4697-9021-01205817211A} - System32\Tasks\LaunchPreSignup => C:\Program Files\OLBPre\OLBPre.exe [2015-04-10] () <==== ATTENTION
Task: {D01DA453-7420-4941-8BFD-DECF3A2AF5AD} - System32\Tasks\spmonitor => C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe <==== ATTENTION
Task: {DF34DA3A-D635-466A-BB6C-3273EEA42D5B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-26] (Google Inc.)
Task: {E1367E2D-CDE6-405C-9A5F-BE0C6DD5567D} - System32\Tasks\PhotoProduct.exe => C:\Program Files\HP Photo Creations\PhotoProduct.exe [2010-07-01] (Visan / RocketLife)
Task: {E6EFEDAC-E808-4320-8736-761889BAD3D0} - System32\Tasks\HPCustParticipation HP Deskjet 3050 J610 series => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-11-16] (Hewlett-Packard Co.)
Task: {E7C47B2D-12F3-4045-AA09-0F250606A5EA} - System32\Tasks\ProPCCleaner_Start => C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe <==== ATTENTION
Task: {EBF6768F-DEBD-4ADD-9EC4-3B9D298543A4} - System32\Tasks\ProgramUpdateCheck => C:\Program Files\File Type Assistant\TSAssist.exe <==== ATTENTION
Task: {F0C23A63-7CBA-4485-96D8-CFF752B32069} - System32\Tasks\ProgramRefresh-ATFST => C:\Program Files\File Type Assistant\tsasetup.exe <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\CIMT_daily_S-1-5-21-3035152371-51418450-4088448234-1000.job => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_S-1-5-21-3035152371-51418450-4088448234-1000.job => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\FreeFileViewerUpdateChecker.job => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2015-04-11 01:17 - 2015-03-03 20:18 - 00821872 _____ () C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe
2008-02-04 11:29 - 2008-02-04 11:29 - 00688128 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
2015-04-11 01:17 - 2015-03-03 20:18 - 00426096 _____ () C:\Program Files\360\Total Security\MenuEx.dll
2008-09-24 16:30 - 2008-05-04 01:42 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll
2015-02-26 03:36 - 2015-02-26 03:36 - 01138208 _____ () C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00017768 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
2015-03-12 11:57 - 2015-03-12 11:57 - 00012144 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Service.Logger.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00034152 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WcfService.dll
2015-04-11 01:17 - 2015-03-03 20:18 - 01208944 _____ () C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
2015-04-11 01:17 - 2015-03-03 20:18 - 00536688 _____ () C:\Program Files\360\Total Security\safemon\wdui2.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00077632 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.Utils.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00179560 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Business.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00046920 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.adblocker.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00033136 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Repositories.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00015696 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.Utils.SqlLite.dll
2015-03-12 11:58 - 2015-03-12 11:58 - 00123224 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.PUP.Management.dll
2015-03-12 11:58 - 2015-03-12 11:58 - 00073544 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SysInfo.dll
2008-09-30 21:31 - 2011-08-22 01:18 - 00925696 _____ () C:\Program Files\Yahoo!\Messenger\yui.dll
2015-04-10 21:57 - 2015-04-10 21:57 - 01283072 _____ () C:\Program Files\OLBPre\OLBPre.exe
2015-04-10 21:55 - 2015-04-10 21:55 - 00060928 _____ () C:\Program Files\OLBPre\LinqBridge.dll
2015-04-11 00:46 - 2015-03-30 14:07 - 09279304 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.118\pdf.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Public\Pictures\Sample Pictures\Dock.jpg
DNS Servers: 192.168.1.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^StrongVaultApp.exe.lnk => C:\Windows\pss\StrongVaultApp.exe.lnk.CommonStartup
MSCONFIG\startupreg: Dell DataSafe Online => "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
MSCONFIG\startupreg: DellSupportCenter => "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
MSCONFIG\startupreg: dscactivate => "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
MSCONFIG\startupreg: ECenter => C:\Dell\E-Center\EULALauncher.exe
MSCONFIG\startupreg: GenieoSystemTray => "C:\Users\Debbie\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe"
MSCONFIG\startupreg: GenieoUpdaterService => "C:\Users\Debbie\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe" -wait 5
MSCONFIG\startupreg: Google Desktop Search => "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: IAAnotif => "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
MSCONFIG\startupreg: Messenger => "C:\Program Files\Strongvault Online Backup\SMessenger.exe"
MSCONFIG\startupreg: Search Protection => C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
MSCONFIG\startupreg: StartCCC => "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
MSCONFIG\startupreg: SysTrayApp => %ProgramFiles%\IDT\WDM\sttray.exe
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide
MSCONFIG\startupreg: YSearchProtection => C:\Program Files\Yahoo!\Search Protection\YspService.exe
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [{0FCF4BF8-60A2-4C20-BDAF-F72EC782CCFB}] => (Allow) C:\Program Files\Dell\MediaDirect\MediaDirect.exe
FirewallRules: [{4590FFC5-15F6-4F8B-ADE9-E60A8970712A}] => (Allow) C:\Program Files\Dell\MediaDirect\PCMService.exe
FirewallRules: [{031DEECF-2B71-4CED-ABD3-1A77B13D7C4D}] => (Allow) C:\Program Files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe
FirewallRules: [{14310A78-4D35-4729-AB7D-03FD013BAAA5}] => (Allow) C:\Program Files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe
FirewallRules: [{FE4D144A-2E38-49C1-BE28-9510E71C0CA3}] => (Allow) C:\Program Files\Common Files\aol\acs\AOLDial.exe
FirewallRules: [{5EB2C47B-266B-410E-ADE0-DADE2CBEBAE0}] => (Allow) C:\Program Files\Common Files\aol\acs\AOLDial.exe
FirewallRules: [{5D879BF9-715A-4581-B67E-BC7E452D7192}] => (Allow) C:\Program Files\Common Files\aol\acs\AOLacsd.exe
FirewallRules: [{0FBD2CE3-1509-46B2-86F6-AF7EFCFFAB9C}] => (Allow) C:\Program Files\Common Files\aol\acs\AOLacsd.exe
FirewallRules: [{6015874E-1F52-41C9-9261-890FE65D1177}] => (Allow) C:\Program Files\Common Files\aol\1222750019\ee\aolsoftware.exe
FirewallRules: [{F102B710-F49F-404F-94C6-AC92696AAB65}] => (Allow) C:\Program Files\Common Files\aol\1222750019\ee\aolsoftware.exe
FirewallRules: [{10B061AF-DA59-4CC9-A871-F217E04E3C64}] => (Allow) C:\Program Files\AOL 9.1\waol.exe
FirewallRules: [{E270613A-BAC0-4423-BD0A-334FFA8A5981}] => (Allow) C:\Program Files\AOL 9.1\waol.exe
FirewallRules: [{2B77A81B-B1ED-4860-9861-C3A9065D1881}] => (Allow) C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{1B502E9E-E93D-4C03-A132-7CD2265CE0EB}] => (Allow) C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{2BCD7931-FD83-4DB8-8881-1915878DED0A}] => (Allow) C:\Program Files\Common Files\aol\Loader\aolload.exe
FirewallRules: [{E09B5238-3064-450B-923A-2AA990262526}] => (Allow) C:\Program Files\Common Files\aol\Loader\aolload.exe
FirewallRules: [{B2AAD55C-26F2-4BCF-8934-B617AFD23CA5}] => (Allow) C:\Program Files\Common Files\aol\System Information\sinf.exe
FirewallRules: [{DA968B3D-4D02-4A4C-AB3A-FA102C18F78B}] => (Allow) C:\Program Files\Common Files\aol\System Information\sinf.exe
FirewallRules: [{F8EA641B-5F6D-4922-9813-0669E777F281}] => (Allow) C:\Program Files\AOL 9.1a\waol.exe
FirewallRules: [{7B516E73-2908-4359-BDC8-521A87A73C2A}] => (Allow) C:\Program Files\AOL 9.1a\waol.exe
FirewallRules: [{1AD87AE7-8D5A-4E58-9B8C-35497DEE2CC3}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{100E7CE4-7D11-401C-9038-B49C4D0E05A8}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{BBC7EF34-1FA1-4E6F-B331-2F5ABB36F4BB}] => (Allow) LPort=80
FirewallRules: [{18348291-09E4-47F0-84FF-32BEB939A488}] => (Allow) LPort=80
FirewallRules: [{CB795EDB-97B5-4C90-81E4-5E0477531D25}] => (Allow) LPort=80
FirewallRules: [{A626637E-B48C-4718-9BF7-7FB4476AD063}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe
FirewallRules: [{C9A3F6EB-F393-4D73-B860-8C0BD5C1AC58}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe
FirewallRules: [{C6E690DF-3397-4D3C-99F2-20E33982ACB3}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{05DF0AF0-05C3-4C55-B199-EADD14DA0D19}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{7017BBC9-7306-4099-8CC4-6048F21E7404}] => (Allow) C:\Program Files\AOL Desktop 9.7\waol.exe
FirewallRules: [{A0513235-E69B-4700-9C90-E046B45DD1A9}] => (Allow) C:\Program Files\AOL Desktop 9.7\waol.exe
FirewallRules: [{70294EED-ACDD-4DC1-B57E-F69458677431}] => (Allow) C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe
FirewallRules: [{195FAA1C-4F89-41FA-8C2E-4B93AF284D34}] => (Allow) C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe
FirewallRules: [TCP Query User{361F0C02-6960-45CA-A47B-AAFDDF793BB7}C:\program files\java\jre1.6.0_05\bin\javaw.exe] => (Allow) C:\program files\java\jre1.6.0_05\bin\javaw.exe
FirewallRules: [UDP Query User{2142573E-CD33-4A25-A36F-D74597EFFA5C}C:\program files\java\jre1.6.0_05\bin\javaw.exe] => (Allow) C:\program files\java\jre1.6.0_05\bin\javaw.exe
FirewallRules: [{3910F279-41DF-47A4-A93A-FB178FB6D79F}] => (Allow) C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe
FirewallRules: [{206E1FB4-1E53-45E6-9EB4-55607E429BA1}] => (Allow) C:\Program Files\File Type Assistant\TSAssist.exe
FirewallRules: [{10211F78-2D66-4433-9BF8-F4B3849D701B}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{DE9C2700-B0FA-45D1-8923-93DDE5560C4F}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{7A3390D6-ACE7-40EF-98DC-E6EF8AC7A074}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{1E5B4321-4CD8-4457-BE37-BC626CD258B8}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{060830E9-F25E-48CF-A45B-1037691F2FCA}] => (Allow) C:\Program Files\Common Files\aol\1356558711\ee\aolsoftware.exe
FirewallRules: [{CFBB1DF3-1B1F-423E-9A54-2543CD09B5F6}] => (Allow) C:\Program Files\Common Files\aol\1356558711\ee\aolsoftware.exe
FirewallRules: [{0B56F9EC-1DD7-48D1-BF63-EB595308D414}] => (Allow) C:\Program Files\AOL Desktop 9.7a\waol.exe
FirewallRules: [{0A1F7322-D581-4270-A4EF-C8AA1ACCE86D}] => (Allow) C:\Program Files\AOL Desktop 9.7a\waol.exe
FirewallRules: [{FE8187C6-8D0A-41B7-932D-7EF87DF32075}] => (Allow) C:\Program Files\AOL Desktop 9.7a\AOLBrowser\aolbrowser.exe
FirewallRules: [{3AFD4FE7-794B-4CDD-8672-5F81E4030734}] => (Allow) C:\Program Files\AOL Desktop 9.7a\AOLBrowser\aolbrowser.exe
FirewallRules: [TCP Query User{00C1CA9F-39F4-482B-97D7-A5D2A2AAF64D}C:\program files\electronic arts\eadm\core.exe] => (Block) C:\program files\electronic arts\eadm\core.exe
FirewallRules: [UDP Query User{53C13880-E75D-49A4-9621-9D9FF96DC7FA}C:\program files\electronic arts\eadm\core.exe] => (Block) C:\program files\electronic arts\eadm\core.exe
FirewallRules: [{F843BC40-16EB-49F4-BDFE-FEAD62932DEE}] => (Allow) C:\Program Files\AOL Desktop 9.7b\waol.exe
FirewallRules: [{4A85AFAF-2775-4350-80DD-425B3244519D}] => (Allow) C:\Program Files\AOL Desktop 9.7b\waol.exe
FirewallRules: [{6E7C051B-70AF-49C4-AEB2-AB4997DD9ECA}] => (Allow) C:\Program Files\AOL Desktop 9.7b\AOLBrowser\aolbrowser.exe
FirewallRules: [{65CE8AEA-ECE3-4358-A58E-5931EBB636BF}] => (Allow) C:\Program Files\AOL Desktop 9.7b\AOLBrowser\aolbrowser.exe
FirewallRules: [{CE7C9BC2-2B22-479E-80B7-39E455F0F949}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0527237F-BC60-40F6-AA26-C84801DCB7BF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{AF95BFA0-0F10-47B2-8BDB-27C48B5BB1C3}] => (Allow) C:\Program Files\AOL Desktop 9.7c\waol.exe
FirewallRules: [{52BE795E-2678-468F-919A-E9B6E9680861}] => (Allow) C:\Program Files\AOL Desktop 9.7c\waol.exe
FirewallRules: [{B66423F7-85D0-4B0A-A314-69D72A30A041}] => (Allow) C:\Program Files\AOL Desktop 9.7c\aolbrowser.exe
FirewallRules: [{9092D0C1-978B-4BD0-B9ED-09236FA8713B}] => (Allow) C:\Program Files\AOL Desktop 9.7c\aolbrowser.exe
FirewallRules: [{9CD8031A-3A96-4196-B958-2D4DCF4596A6}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{A171A0FF-DD53-4FB0-9A16-735A7019AF3D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{0093BB0A-732B-4506-92B5-CB6BFEBB27B0}] => (Allow) C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{A3E7C8A1-0B2C-451F-9A8E-ABA05791931F}] => (Allow) C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{AFB10E07-12D5-4CB0-8086-BE6AAEAC754E}] => (Allow) C:\Program Files\360\Total Security\LiveUpdate360.exe
FirewallRules: [{3FCF58E6-6BD1-4D7D-90CC-1E054669A0B2}] => (Allow) C:\Program Files\360\Total Security\LiveUpdate360.exe
FirewallRules: [{F567F335-BA28-42D4-B4C5-0A103653F01F}] => (Allow) C:\Users\Debbie\AppData\Local\Temp\~os1A44.tmp\pmropn.exe
==================== Faulty Device Manager Devices =============
Name: Bluetooth Device (RFCOMM Protocol TDI)
Description: Bluetooth Device (RFCOMM Protocol TDI)
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: RFCOMM
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/09/2015 09:46:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/09/2015 09:28:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/09/2015 09:27:47 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (06/09/2015 09:15:50 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (06/09/2015 09:15:50 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Error: (06/09/2015 09:15:42 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
System errors:
=============
Microsoft Office:
=========================
Error: (06/09/2015 09:46:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/09/2015 09:28:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/09/2015 09:27:47 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\UNINSTALL INSTRUCTIONS.LNK
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\UNINSTALL INSTRUCTIONS.LNK
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\MEMBER OF GRID - GOODWARE REPOSITORY INFORMATION DATABASE.LNK
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\MEMBER OF GRID - GOODWARE REPOSITORY INFORMATION DATABASE.LNK
Error: (06/09/2015 09:15:50 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\SUPPORT.LNK
Error: (06/09/2015 09:15:50 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\SUPPORT.LNK
Error: (06/09/2015 09:15:42 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\ABOUT PREMIEROPINION.LNK
CodeIntegrity Errors:
===================================
Date: 2015-06-09 22:55:00.664
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360Box.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-06-09 22:54:59.034
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360Box.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-06-09 22:54:57.251
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360Box.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-06-09 22:54:55.642
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360Box.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-06-09 21:58:38.157
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-06-09 21:58:35.334
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-06-09 21:58:11.082
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-06-09 21:58:08.638
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-06-09 21:57:56.121
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\360\Total Security\filemon\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
Date: 2015-06-09 21:57:44.432
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\360\Total Security\filemon\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU T5850 @ 2.16GHz
Percentage of memory in use: 65%
Total physical RAM: 3581.05 MB
Available physical RAM: 1245.99 MB
Total Pagefile: 7347.85 MB
Available Pagefile: 4701.59 MB
Total Virtual: 2047.88 MB
Available Virtual: 1860.29 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:222.75 GB) (Free:183.29 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (RECOVERY) (Fixed) (Total:10 GB) (Free:5.02 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.9 GB) (Disk ID: 08000000)
Partition 1: (Not Active) - (Size=141 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=222.7 GB) - (Type=07 NTFS)
==================== End of log ============================
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-06-10 15:07:17
—————————–
15:07:17.652 OS Version: Windows 6.0.6002 Service Pack 2
15:07:17.652 Number of processors: 2 586 0xF0D
15:07:17.655 ComputerName: DEBBIE-PC UserName: Debbie
15:07:22.061 Initialize success
15:07:22.254 VM: initialized successfully
15:07:22.257 VM: Intel CPU virtualization not supported
15:09:34.845 AVAST engine defs: 15060901
15:10:33.925 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
15:10:33.934 Disk 0 Vendor: WDC_WD25 01.0 Size: 238475MB BusType: 3
15:10:34.254 Disk 0 MBR read successfully
15:10:34.261 Disk 0 MBR scan
15:10:34.576 Disk 0 Windows VISTA default MBR code
15:10:34.599 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 141 MB offset 63
15:10:34.818 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 290816
15:10:34.992 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 228092 MB offset 21262336
15:10:35.097 Disk 0 scanning sectors +488394752
15:10:35.498 Disk 0 scanning C:\Windows\system32\drivers
15:11:52.880 Service scanning
15:11:54.080 Service 360AntiHacker C:\Windows\System32\Drivers\360AntiHacker.sys **LOCKED** 5
15:11:55.187 Service 360Camera C:\Windows\System32\Drivers\360Camera.sys **LOCKED** 5
15:11:55.474 Service 360SelfProtection C:\Windows\system32\drivers\360SelfProtection.sys **LOCKED** 5
15:12:03.422 Service BAPIDRV C:\Windows\system32\DRIVERS\BAPIDRV.sys **LOCKED** 5
15:12:13.557 Service EfiMon C:\Windows\System32\Drivers\Efimon.sys **LOCKED** 5
15:12:19.740 Service HookPort C:\Windows\System32\Drivers\Hookport.sys **LOCKED** 5
15:12:42.612 Service MpKsl4fe40b34 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E9AD4444-1FA9-48A9-9987-AA044985AAE1}\MpKsl4fe40b34.sys **LOCKED** 32
15:13:08.985 Service qutmdserv C:\Windows\system32\drivers\qutmdrv.sys **LOCKED** 5
15:13:40.975 Modules scanning
15:13:41.001 Disk 0 trace - called modules:
15:13:41.030 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll
15:13:41.046 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86ad9ac8]
15:13:41.062 3 CLASSPNP.SYS[8bba18b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85e46030]
15:13:44.378 AVAST engine scan C:\Windows
15:13:52.606 AVAST engine scan C:\Windows\system32
15:29:20.311 File: C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD088.tmp\ciie-3.2.0-12323.exe **HIDDEN**
15:29:22.107 AVAST engine scan C:\Windows\system32\drivers
15:31:12.260 AVAST engine scan C:\Users\Debbie
16:12:26.179 File: C:\Users\Debbie\AppData\Local\Temp\is1238184746\26D20BBC_stp\compete_032415013024.exe **INFECTED** Win32:Malware-gen
16:48:54.652 File: C:\Users\Debbie\Downloads\PDFReaderSetup.exe **INFECTED** Win32:Trojan-gen
16:50:32.672 AVAST engine scan C:\ProgramData
17:24:03.647 Disk 0 statistics 3367489/0/0 @ 0.48 MB/s
17:24:03.709 Scan finished successfully
18:33:26.788 Disk 0 MBR has been saved successfully to "C:\Users\Debbie\Desktop\MBR.dat"
18:33:27.053 The log file has been saved successfully to "C:\Users\Debbie\Desktop\aswMBR.txt"