This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC Cleaner and More [Solved]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A friend of mine has a computer that started acting real slow and a program indicated that it had several problems (PC Cleaner) I manually removed that, but I am sure there is a bunch of other stuff going on. I couldn't get the link to FRST to work so I downloaded it elsewhere, so I am not sure if it is the correct version. 

Thanks for your time in looking at this.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-06-2015
Ran by [removed] (administrator) on DEBBIE-PC on 09-06-2015 22:53:09
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\stacsv.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
() C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AOL Inc.) C:\Program Files\Common Files\aol\1356558711\ee\aolsoftware.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(CyberLink Corp.) C:\Program Files\Dell\MediaDirect\PCMService.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\AEstSrv.exe
() C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe
(ConsumerInput) C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe
(Creative Technology Ltd.) C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(COMPANYVERS_NAME) C:\Program Files\CouponXplorer_5z\bar\1.bin\5zbarsvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Lavasoft Limited) C:\Program Files\Lavasoft\Web Companion\TcpService\2.3.3.0\LavasoftTcpService.exe
() C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
(Lavasoft) C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Qihu Software Co. Limited) C:\Program Files\360\Total Security\safemon\QHWatchdog.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
() C:\Program Files\OLBPre\OLBPre.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(ConsumerInput) C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe
(ConsumerInput) C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(RaMMicHaeL) C:\Program Files\Unchecky\bin\unchecky_svc.exe
(RaMMicHaeL) C:\Program Files\Unchecky\bin\unchecky_bg.exe
(AVAST Software) C:\Users\Debbie\Desktop\aswMBR.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [] => [X]
HKLM\…\Run: [HostManager] => C:\Program Files\Common Files\AOL\1356558711\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [978520 2015-01-30] (Microsoft Corporation)
HKLM\…\Run: [PCMService] => C:\Program Files\Dell\MediaDirect\PCMService.exe [126976 2008-05-09] (CyberLink Corp.)
HKLM\…\Run: [Dell Webcam Central] => C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe [438403 2008-02-19] (Creative Technology Ltd.)
HKLM\…\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [196608 2008-06-30] (Alps Electric Co., Ltd.)
HKLM\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2009-12-18] (Adobe Systems Incorporated)
HKLM\…\Run: [ShopAtHomeWatcher] => C:\Users\Debbie\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [948672 2009-12-11] (Adobe Systems Incorporated)
HKLM\…\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM\…\Run: [Price Finder] => C:\Program Files\Price Finder\PriceFinderHelper.exe [43088 2013-11-25] (MindSpark Interactive Network)
HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [442467 2008-06-25] (IDT, Inc.)
HKLM\…\Run: [SunJavaUpdateSched] => "C:\Program Files\Java\jre7\bin\jusched.exe"
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\…\Run: [QHSafeTray] => C:\Program Files\360\Total Security\safemon\QHSafeTray.exe [1208944 2015-03-03] ()
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Run: [Messenger (Yahoo!)] => C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [6276408 2011-08-22] (Yahoo! Inc.)
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Run: [EA Core] => "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Run: [WeatherBug] => C:\Program Files\Earth Networks\WeatherBug\WeatherBug.exe [146736 2014-09-23] ()
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Run: [Web Companion] => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe [1303872 2015-03-12] (Lavasoft)
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Run: [UpdateAdmin] => C:\Users\Debbie\AppData\Local\UpdateAdmin\UpdateAdmin.exe [225552 2014-10-16] (DownloadAdmin)
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\MountPoints2: {1128326d-8a4e-11dd-81d3-806e6f6e6963} - E:\Setup.exe
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [294912 2008-01-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-01-16]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk [2012-12-26]
ShortcutTarget: QuickSet.lnk -> C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
Startup: C:\Users\Debbie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2015-04-11]
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files\OLBPre\OLBPre.exe ()
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2008-09-24]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2008-09-24]
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8&fr;=mkg029
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?ilc=8&fr;=mkg029
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=COSP&ptag;=D041115-ABB80C9363E1D41E9AFF&form;=CONMHP&conlogo;=CT3331964
SearchScopes: HKU\.DEFAULT -> DefaultScope {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ysp
SearchScopes: HKU\.DEFAULT -> {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ysp
SearchScopes: HKU\.DEFAULT -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = http://search.aol.com/aolcom/search?query={searchTerms}&invocationType;=tb50ie7
SearchScopes: HKU\.DEFAULT -> {AC7EE147-3932-4E15-A3CC-2F70D92337FC} URL = http://search.aol.com/aolcom/search?query={searchTerms}&invocationType;=msie70a
SearchScopes: HKU\S-1-5-19 -> DefaultScope {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ysp
SearchScopes: HKU\S-1-5-19 -> {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ysp
SearchScopes: HKU\S-1-5-20 -> DefaultScope {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ysp
SearchScopes: HKU\S-1-5-20 -> {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ysp
SearchScopes: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?pc=COSP&ptag;=D041115-ABB80C9363E1D41E9AFF&form;=CONBDF&conlogo;=CT3331964&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?pc=COSP&ptag;=D041115-ABB80C9363E1D41E9AFF&form;=CONBDF&conlogo;=CT3331964&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> {101180E8-F2DF-4212-A6AF-C7156D894E3F} URL = http://websearch.shopathome.com?user_id={D59E1807-83A8-4B61-9CCA-42EE6F028366}&q;={searchTerms}
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2009-12-18] (Adobe Systems Incorporated)
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO: AOL Toolbar Loader -> {3ef64538-8b54-4573-b48f-4d34b0238ab2} -> C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
BHO: Ask Toolbar -> {4F524A2D-5637-4300-76A7-7A786E7484D7} -> C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-V7C\Passport.dll [2013-11-08] (APN LLC.)
BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-07-25] (Oracle Corporation)
BHO: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files\Consumer Input\InternetExplorer\dca-bho.dll [2015-02-25] (Compete, Inc.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-07-25] (Oracle Corporation)
BHO: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files\Yahoo!\Companion\Installs\cpn4\YTSingleInstance.dll No File
Toolbar: HKLM - Ask Toolbar - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-V7C\Passport.dll [2013-11-08] (APN LLC.)
Toolbar: HKLM - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
Toolbar: HKU\.DEFAULT -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> Ask Toolbar - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\ORJ-V7C\Passport.dll [2013-11-08] (APN LLC.)
Toolbar: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> AOL Toolbar - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll [2014-02-07] (AOL Inc.)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-11-28] (Microsoft Corporation)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Winsock: Catalog9 01 C:\Windows\system32\LavasoftTcpService.dll [326288 2015-04-11] (Lavasoft Limited)
Winsock: Catalog9 02 C:\Windows\system32\LavasoftTcpService.dll [326288 2015-04-11] (Lavasoft Limited)
Winsock: Catalog9 03 C:\Windows\system32\LavasoftTcpService.dll [326288 2015-04-11] (Lavasoft Limited)
Winsock: Catalog9 04 C:\Windows\system32\LavasoftTcpService.dll [326288 2015-04-11] (Lavasoft Limited)
Winsock: Catalog9 30 C:\Windows\system32\LavasoftTcpService.dll [326288 2015-04-11] (Lavasoft Limited)
Hosts: There are more than one entry in Hosts. See Hosts section of  Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF ProfilePath: C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default
FF NewTab: hxxp://www.bing.com/?pc=COSP&ptag;=D041115-ABB80C9363E1D41E9AFF&form;=CONMHP&conlogo;=CT3331964
FF DefaultSearchEngine: Bing
FF SearchEngineOrder.1: Ask Search
FF SelectedSearchEngine: Bing
FF Homepage: hxxp://www.bing.com/?pc=COSP&ptag;=D041115-ABB80C9363E1D41E9AFF&form;=CONMHP&conlogo;=CT3331964
FF Keyword.URL: hxxp://aolsearch.aol.com/aol/search?invocationType=client_searchbox&query;=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-04-11] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin: @CouponXplorer_5z.com/Plugin -> C:\Program Files\CouponXplorer_5z\bar\1.bin\NP5zStub.dll [2013-11-25] (MindSpark)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-07-25] (Oracle Corporation)
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll [2008-09-19] (Yahoo! Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-13] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-13] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2012-02-17] (VideoLAN)
FF Plugin: @viewpoint.com/VMP -> C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2009-12-18] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-06-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-06-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-06-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-06-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-06-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2013-08-02] (Coupons, Inc.)
FF Extension: CouponXplorer - C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\Extensions\5zffxtbr@CouponXplorer_5z.com [2013-12-22]
FF Extension: AOL Toolbar - C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\Extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} [2015-03-13]
FF Extension: Ask Toolbar - C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\Extensions\[removed] [2013-11-08]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-30]
FF HKLM\…\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\IB Updater\Firefox
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\360\Total Security\safemon\webprotection_firefox
FF Extension: 360 Internet Protection - C:\Program Files\360\Total Security\safemon\webprotection_firefox [2015-04-11]
FF HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\Firefox\Extensions: [ConsumerInput@Compete] - C:\Program Files\Consumer Input\Firefox\ciff-3.2.0-12099.xpi
FF Extension: No Name - C:\Program Files\Consumer Input\Firefox\ciff-3.2.0-12099.xpi [2015-01-21]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2014-10-19]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp;=yhs-fullyhosted_003&type;=wny_ggbc_15_15¶m1=1¶m2=f%3D1%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutDtDtBtByCzytA0CzyyEyBtD0DtC0AyDtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyBzzyEyDtB0D0BzytGzz0DzztAtGtC0C0F0EtGyDyE0ByEtGtA0A0ByE0Dzz0AtDyD0CyB0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0E0EyByEzztCzztGzz0DtBtDtGyEtCtCzztGzztA0F0FtGyEyDtC0BtAyDtBtBtDtBtA0A2QtN0A0LzutB%26cr%3D1162628522%26a%3Dwny_ggbc_15_15%26os%3DWindows Vista (TM) Home Premium
CHR StartupUrls: Default -> "hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp;=yhs-fullyhosted_003&type;=wny_ggbc_15_15¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzutDtDtBtByCzytA0CzyyEyBtD0DtC0AyDtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyBzzyEyDtB0D0BzytGzz0DzztAtGtC0C0F0EtGyDyE0ByEtGtA0A0ByE0Dzz0AtDyD0CyB0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0E0EyByEzztCzztGzz0DtBtDtGyEtCtCzztGzztA0F0FtGyEyDtC0BtAyDtBtBtDtBtA0A2QtN0A0LzutB%26cr%3D1162628522%26a%3Dwny_ggbc_15_15%26os%3DWindows Vista (TM) Home Premium", "hxxp://www.google.com/"
CHR DefaultSearchKeyword: Default -> search provided by yahoo.com
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\41.0.2272.118\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Coupons Inc., Coupon Printer Manager ) - C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll No File
CHR Plugin: (downloadUpdater) - C:\Program Files\Mozilla Firefox\plugins\npdnu.dll No File
CHR Plugin: (downloadUpdater2) - C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll No File
CHR Plugin: (Coupons Inc., Coupon Printer Manager ) - C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (MetaStream 3 Plugin) - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-15]
CHR Extension: (Google Search) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-15]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-11]
CHR Extension: (Google Wallet) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-11]
CHR Extension: (Gmail) - C:\Users\Debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-15]
CHR HKLM\…\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\IB Updater\source.crx [Not Found]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\aestsrv.exe [73728 2008-06-25] (Andrea Electronics Corporation)
S3 AOL ACS; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [46184 2014-02-06] (AOL Inc.)
S4 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-11-08] () [File not signed]
R2 consumerinput_update; C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe [106296 2015-04-11] (ConsumerInput)
S3 consumerinput_updatem; C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe [106296 2015-04-11] (ConsumerInput)
R2 CouponXplorer_5zService; C:\Program Files\CouponXplorer_5z\bar\1.bin\5zbarsvc.exe [44752 2013-11-25] (COMPANYVERS_NAME)
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [161048 2008-05-02] (Stardock Corporation)
R2 LavasoftTcpService; C:\Program Files\Lavasoft\Web Companion\TcpService\2.3.3.0\LavasoftTcpService.exe [836984 2015-03-12] (Lavasoft Limited)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation)
R2 QHActiveDefense; C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe [821872 2015-03-03] ()
R2 SearchProtectionService; C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [17768 2015-03-12] ()
R2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2008-08-14] (SupportSoft, Inc.)
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\STacSV.exe [221273 2008-06-25] (IDT, Inc.)
R2 Unchecky; C:\Program Files\Unchecky\bin\Unchecky_svc.exe [164600 2015-06-09] (RaMMicHaeL)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker.sys [88136 2015-03-03] (360.cn)
R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [65608 2015-03-03] (360.cn)
R1 360Box; C:\Windows\System32\DRIVERS\360Box.sys [202312 2015-03-03] (360.cn)
R3 360Camera; C:\Windows\System32\Drivers\360Camera.sys [34888 2015-03-03] (360.cn)
R1 360SelfProtection; C:\Windows\System32\drivers\360SelfProtection.sys [174536 2015-03-03] (360安全中心)
R1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV.sys [169040 2015-03-03] (Qihu 360 Software Co., Ltd.)
R1 EfiMon; C:\Windows\System32\Drivers\Efimon.sys [23752 2015-03-03] (360安全中心)
R0 HookPort; C:\Windows\System32\Drivers\Hookport.sys [58440 2015-03-03] (360安全中心)
R3 itecir; C:\Windows\System32\DRIVERS\itecir.sys [54784 2008-03-14] (ITE Tech. Inc. )
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation)
R1 MpKsl6099da39; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E9AD4444-1FA9-48A9-9987-AA044985AAE1}\MpKsl6099da39.sys [39464 2015-06-09] (Microsoft Corporation)
S1 MpKslefaa4db8; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E9AD4444-1FA9-48A9-9987-AA044985AAE1}\MpKslefaa4db8.sys [39464 2015-04-12] () [File not signed]
R3 OA001Ufd; C:\Windows\System32\DRIVERS\OA001Ufd.sys [144672 2008-06-03] (Creative Technology Ltd.)
R3 OA001Vid; C:\Windows\System32\DRIVERS\OA001Vid.sys [277440 2008-09-19] (Creative Technology Ltd.)
R1 qutmdserv; C:\Windows\system32\drivers\qutmdrv.sys [257352 2015-03-03] (360.cn)
R1 qutmipc; C:\Windows\system32\drivers\qutmipc.sys [45896 2015-03-03] (360.cn)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed]
R3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys [33588 2006-11-29] (America Online, Inc.)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
U3 aswMBR; \??\C:\Users\Debbie\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Debbie\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-09 22:53 - 2015-06-09 22:56 - 00031915 _____ C:\Users\Debbie\Desktop\FRST.txt
2015-06-09 22:52 - 2015-06-09 22:54 - 00000000 ____D C:\FRST
2015-06-09 22:32 - 2015-06-09 22:29 - 05198336 _____ (AVAST Software) C:\Users\Debbie\Desktop\aswMBR.exe
2015-06-09 22:32 - 2015-06-09 22:29 - 01147904 _____ (Farbar) C:\Users\Debbie\Desktop\FRST.exe
2015-06-09 22:28 - 2015-06-09 22:29 - 01147904 _____ (Farbar) C:\Users\Debbie\Downloads\FRST.exe
2015-06-09 22:25 - 2015-06-09 22:29 - 05198336 _____ (AVAST Software) C:\Users\Debbie\Downloads\aswMBR.exe
2015-06-09 22:10 - 2015-06-09 22:23 - 00000000 ____D C:\ProgramData\4bfd38c400002905
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-09 23:08 - 2015-04-11 01:22 - 00000350 _____ C:\Windows\Tasks\CIMT_S-1-5-21-3035152371-51418450-4088448234-1000.job
2015-06-09 23:04 - 2012-09-14 07:11 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-09 23:01 - 2012-12-20 00:01 - 00000380 _____ C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
2015-06-09 22:56 - 2015-04-11 01:19 - 00000954 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job
2015-06-09 22:29 - 2008-09-24 08:36 - 02037775 _____ C:\Windows\WindowsUpdate.log
2015-06-09 22:24 - 2015-04-11 01:19 - 00000958 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job
2015-06-09 22:23 - 2015-04-11 01:19 - 00000000 __SHD C:\ProgramData\360Quarant
2015-06-09 22:23 - 2015-04-11 01:19 - 00000000 __SHD C:\$360Section
2015-06-09 22:08 - 2015-04-11 02:03 - 00000000 ____D C:\Program Files\PremierOpinion
2015-06-09 21:46 - 2015-03-13 08:49 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2015-06-09 21:42 - 2006-11-02 05:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-09 21:42 - 2006-11-02 05:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-09 21:41 - 2013-02-15 08:13 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-09 21:41 - 2006-11-02 06:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-09 21:23 - 2006-11-02 06:01 - 00032588 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-06-09 21:23 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\tracing
2015-06-09 21:13 - 2015-04-11 02:02 - 00000000 ____D C:\Users\Debbie\Documents\ProPCCleaner
2015-06-09 21:10 - 2006-11-02 03:33 - 00703388 _____ C:\Windows\system32\PerfStringBackup.INI
 
==================== Files in the root of some directories =======
 
2008-12-06 22:32 - 2009-10-17 07:17 - 8318896 _____ (Dell, Inc.                                                   ) C:\Users\Debbie\AppData\Roaming\DataSafeDotNet.exe
2015-04-11 01:18 - 2015-04-11 01:18 - 0021066 _____ () C:\Users\Debbie\AppData\Roaming\ICSW_0M0D1V1N1N1S1RtJ1V0G1P1P1J0B2Y1Q1Q2U.txt
2010-09-17 14:53 - 2014-12-08 17:16 - 0000296 _____ () C:\Users\Debbie\AppData\Roaming\wklnhst.dat
2012-12-26 11:16 - 2012-11-23 05:54 - 0196608 _____ () C:\Users\Debbie\AppData\Local\common_functions.dll
2009-02-03 21:24 - 2014-11-22 07:34 - 0007052 _____ () C:\Users\Debbie\AppData\Local\d3d9caps.dat
2008-11-04 22:10 - 2012-10-09 10:02 - 0020992 _____ () C:\Users\Debbie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-11-23 05:54 - 2012-11-23 05:54 - 0114688 _____ () C:\Users\Debbie\AppData\Local\ie_runner_app.exe
2012-12-26 11:16 - 2012-06-26 03:59 - 0940544 _____ (Apache Software Foundation) C:\Users\Debbie\AppData\Local\log4cxx.dll
2013-03-05 08:31 - 2013-03-05 08:31 - 0000057 _____ () C:\ProgramData\Ament.ini
 
Some files in TEMP:
====================
C:\Users\Debbie\AppData\Local\Temp\AcsInstall.dll
C:\Users\Debbie\AppData\Local\Temp\AdobeUpdater12345.exe
C:\Users\Debbie\AppData\Local\Temp\APNSetup.exe
C:\Users\Debbie\AppData\Local\Temp\CloudBackup2209.exe
C:\Users\Debbie\AppData\Local\Temp\compete.exe
C:\Users\Debbie\AppData\Local\Temp\cw.exe
C:\Users\Debbie\AppData\Local\Temp\en_ww_Package.exe
C:\Users\Debbie\AppData\Local\Temp\ICSW_0M0D1V1N1N1S1R.exe
C:\Users\Debbie\AppData\Local\Temp\install_flashplayer11x32axau_gtba_chra_dy_aih.exe
C:\Users\Debbie\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Debbie\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Debbie\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Debbie\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Debbie\AppData\Local\Temp\SHFOLDER.DLL
C:\Users\Debbie\AppData\Local\Temp\SpOrder.dll
C:\Users\Debbie\AppData\Local\Temp\supoptsetup.exe
C:\Users\Debbie\AppData\Local\Temp\UninstallEADM.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-06-09 21:55
 
==================== End of log ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 08-06-2015
Ran by [removed] at 2015-06-09 23:11:04
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3035152371-51418450-4088448234-500 - Administrator - Disabled)
Debbie (S-1-5-21-3035152371-51418450-4088448234-1000 - Administrator - Enabled) => C:\Users\Debbie
Guest (S-1-5-21-3035152371-51418450-4088448234-501 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Out of date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AV: 360 Total Security (Disabled - Up to date) {2B66EE1E-E5C8-C2F7-648F-4E55AC68D37D}
AS: 360 Total Security (Disabled - Up to date) {90070FFA-C3F2-CD79-5E3F-7527D7EF99C0}
AS: Microsoft Security Essentials (Enabled - Out of date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
360 Total Security (HKLM\…\360TotalSecurity) (Version: 6.0.0.1152 - 360 Security Center)
Ad-Aware Web Companion (Version: 1.1.922.1860 - Lavasoft) Hidden
Adobe Flash Player 16 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader 8.1.3 (HKLM\…\{AC76BA86-7AD7-1033-7B44-A81300000003}) (Version: 8.1.3 - Adobe Systems Incorporated)
Adobe Reader 8.2.0 (HKLM\…\{AC76BA86-7AD7-1033-7B44-A82000000003}) (Version: 8.2.0 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM\…\Advanced Audio FX Engine) (Version:  - )
AOL Toolbar (HKLM\…\AOL Toolbar) (Version:  - AOL Inc.)
AOL Uninstaller (Choose which Products to Remove) (HKLM\…\AOL Uninstaller) (Version:  - AOL Inc.)
Apple Application Support (HKLM\…\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ask Toolbar (HKLM\…\{4F524A2D-5637-4300-76A7-A758B70C0700}) (Version: 12.7.0.15 - APN, LLC) <==== ATTENTION
ATI Catalyst Control Center (HKLM\…\{055EE59D-217B-43A7-ABFF-507B966405D8}) (Version: 2.008.0407.2138 - )
Bing Rewards Client Installer (Version: 16.0.345.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
ccc-core-static (Version: 2008.0407.2139.36897 - ATI) Hidden
Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Consumer Input (remove only) (HKLM\…\Consumer Input Installer) (Version:  - Compete Inc.) <==== ATTENTION
Coupon Printer for Windows (HKLM\…\Coupon Printer for Windows5.0.0.4) (Version: 5.0.0.4 - Coupons.com Incorporated)
Dell DataSafe Online (HKLM\…\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.1.0014 - Dell, Inc.)
Dell Dock (HKLM\…\{F6CB42B9-F033-4152-8813-FF11DA8E6A78}) (Version: 1.0.0 - Dell)
Dell Getting Started Guide (HKLM\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell Support Center (Support Software) (HKLM\…\{E3BFEE55-39E2-4BE0-B966-89FE583822C1}) (Version: 2.2.09085 - Dell)
Dell Touchpad (HKLM\…\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.2.101.104 - Alps Electric)
Dell Webcam Central (HKLM\…\Dell Webcam Central) (Version:  - )
Download Updater (AOL Inc.) (HKLM\…\SoftwareUpdUtility) (Version:  - AOL Inc.) <==== ATTENTION
Google Chrome (HKLM\…\Google Chrome) (Version: 41.0.2272.118 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
HP Deskjet 3050 J610 series Basic Device Software (HKLM\…\{0564C76B-8E1F-4157-8654-B0F9F308BEE9}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 3050 J610 series Help (HKLM\…\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}) (Version: 140.0.63.63 - Hewlett Packard)
HP Deskjet 3050 J610 series Product Improvement Study (HKLM\…\{34E90074-C80C-4182-A995-65E88B5B56E0}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM\…\HP Photo Creations) (Version: 1.0.0.3781 - HP Photo Creations Powered by RocketLife)
HP Update (HKLM\…\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard)
HPDiagnosticCoreDll (HKLM\…\{9262B08F-E183-4FED-A2BD-23FF1A84EB7A}) (Version: 1.0.16.0 - Hewlett Packard)
Integrated Webcam Driver (1.03.02.0919)   (HKLM\…\Creative OA001) (Version:  - )
Intel(R) Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - )
ITECIR Driver (Version: 1.00.000 - ITE) Hidden
iTunes (HKLM\…\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 67 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.670 - Oracle)
LavasoftTcpService (Version: 2.3.3.0 - Lavasoft) Hidden
Live! Cam Avatar Creator (HKLM\…\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.1419.1 - Creative Technology Ltd)
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
MediaDirect (HKLM\…\{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}) (Version: 4.0 - Dell)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Works (HKLM\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM\…\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mozilla Firefox 30.0 (x86 en-US) (HKLM\…\Mozilla Firefox 30.0 (x86 en-US)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MyPC Backup  (HKLM\…\OLBPre) (Version:  - MyPC Backup) <==== ATTENTION
PDF Reader Packages (HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\PDF Reader Packages) (Version:  - ) <==== ATTENTION
QuickSet (HKLM\…\{C4972073-2BFE-475D-8441-564EA97DA161}) (Version: 9.0.12 - Dell Inc.)
QuickTime 7 (HKLM\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Roxio Creator DE (HKLM\…\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}) (Version: 10.1 - Roxio)
Skins (Version: 2008.0407.2139.36897 - ATI) Hidden
Spelling Dictionaries Support For Adobe Reader 8 (HKLM\…\{AC76BA86-7AD7-5464-3428-800000000003}) (Version: 8.0.0 - Adobe Systems)
Unchecky v0.3.7.5 (HKLM\…\Unchecky) (Version: 0.3.7.5 - RaMMicHaeL)
UpdateAdmin (HKLM\…\{07B4B423-E4DA-47D1-8327-B589EB4BEB58}) (Version: 2.0.1885 - DownloadAdmin) <==== ATTENTION!
Viewpoint Media Player (HKLM\…\ViewpointMediaPlayer) (Version:  - )
VLC media player 2.0.0 (HKLM\…\VLC media player) (Version: 2.0.0 - VideoLAN)
WeatherBug® (HKLM\…\WeatherBug®) (Version: 10.0.7.4 - Earth Networks, Inc.)
Web Companion (HKLM\…\{902C3D36-9254-437D-98AC-913B78E60864}_WebCompanion) (Version: 1.1.922.1860 - Lavasoft)
Yahoo! Messenger (HKLM\…\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Yahoo! Software Update (HKLM\…\Yahoo! Software Update) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3035152371-51418450-4088448234-1000_Classes\CLSID\{1853e19a-4e54-4190-8deb-2e1cc947cd60}\InprocServer32 -> C:\Program Files\AOL Desktop 9.7c\axtrack.dll (AOL Inc.)
CustomCLSID: HKU\S-1-5-21-3035152371-51418450-4088448234-1000_Classes\CLSID\{7629C9DE-2E38-4963-A01C-02FFAC203D87}\InprocServer32 -> C:\Program Files\AOL Desktop 9.7c\axtrack.dll (AOL Inc.)
CustomCLSID: HKU\S-1-5-21-3035152371-51418450-4088448234-1000_Classes\CLSID\{B9F3009B-976B-41C4-A992-229DCCF3367C}\InprocServer32 -> C:\Program Files\AOL Desktop 9.7c\axtrack.dll (AOL Inc.)
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 03:23 - 2015-06-09 22:29 - 00001930 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
0.0.0.0 cdn.appround.biz
0.0.0.0 cdn.bigspeedpro.com
 
There are 5 more lines.
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {51A7228C-52A5-4AF8-9569-D8E01FA1A297} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Debbie => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-10] (Microsoft Corporation)
Task: {82EE9D76-1F7A-461F-9BC5-5CB47F2E4EDD} - System32\Tasks\SpeedUpMyPC => C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe <==== ATTENTION
Task: {89E65CB6-C786-4800-A2C5-9B8C209439EE} - System32\Tasks\ConsumerInputUpdateTaskMachineCore => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe [2015-04-11] (ConsumerInput) <==== ATTENTION
Task: {8A0C5E62-A6E8-4C64-9BCB-C8312BFE77D3} - System32\Tasks\FreeFileViewerUpdateChecker => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe <==== ATTENTION
Task: {93E23C54-3E67-4BFE-A42D-73D8B7B5621B} - System32\Tasks\UpdateAdmin => C:\Users\Debbie\AppData\Local\UpdateAdmin\UpdateAdmin.exe [2014-10-16] (DownloadAdmin) <==== ATTENTION
Task: {9AB9B2FC-A78D-42EE-8C65-5A927558BA08} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-26] (Google Inc.)
Task: {9F55970E-0C73-4433-BD43-9618091CABC4} - System32\Tasks\ConsumerInputUpdateTaskMachineUA => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe [2015-04-11] (ConsumerInput) <==== ATTENTION
Task: {A835556A-42A9-4D09-A452-CDD184CD4C27} - System32\Tasks\CIMT_daily_S-1-5-21-3035152371-51418450-4088448234-1000 => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe [2015-02-26] () <==== ATTENTION
Task: {AD06DD0F-F4D5-4535-8A91-53B10D72D9D0} - System32\Tasks\CIMT_S-1-5-21-3035152371-51418450-4088448234-1000 => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe [2015-02-26] () <==== ATTENTION
Task: {C3A7A6BC-D093-48DD-8754-6A3F2111D378} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {C86FD90E-B38B-4228-8E8A-BE89250F815D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-11] (Adobe Systems Incorporated)
Task: {C9FDD969-AF3C-4697-9021-01205817211A} - System32\Tasks\LaunchPreSignup => C:\Program Files\OLBPre\OLBPre.exe [2015-04-10] () <==== ATTENTION
Task: {D01DA453-7420-4941-8BFD-DECF3A2AF5AD} - System32\Tasks\spmonitor => C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe <==== ATTENTION
Task: {DF34DA3A-D635-466A-BB6C-3273EEA42D5B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-26] (Google Inc.)
Task: {E1367E2D-CDE6-405C-9A5F-BE0C6DD5567D} - System32\Tasks\PhotoProduct.exe => C:\Program Files\HP Photo Creations\PhotoProduct.exe [2010-07-01] (Visan / RocketLife)
Task: {E6EFEDAC-E808-4320-8736-761889BAD3D0} - System32\Tasks\HPCustParticipation HP Deskjet 3050 J610 series => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2010-11-16] (Hewlett-Packard Co.)
Task: {E7C47B2D-12F3-4045-AA09-0F250606A5EA} - System32\Tasks\ProPCCleaner_Start => C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe <==== ATTENTION
Task: {EBF6768F-DEBD-4ADD-9EC4-3B9D298543A4} - System32\Tasks\ProgramUpdateCheck => C:\Program Files\File Type Assistant\TSAssist.exe <==== ATTENTION
Task: {F0C23A63-7CBA-4485-96D8-CFF752B32069} - System32\Tasks\ProgramRefresh-ATFST => C:\Program Files\File Type Assistant\tsasetup.exe <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\CIMT_daily_S-1-5-21-3035152371-51418450-4088448234-1000.job => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_S-1-5-21-3035152371-51418450-4088448234-1000.job => C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job => C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\FreeFileViewerUpdateChecker.job => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-04-11 01:17 - 2015-03-03 20:18 - 00821872 _____ () C:\Program Files\360\Total Security\safemon\QHActiveDefense.exe
2008-02-04 11:29 - 2008-02-04 11:29 - 00688128 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
2015-04-11 01:17 - 2015-03-03 20:18 - 00426096 _____ () C:\Program Files\360\Total Security\MenuEx.dll
2008-09-24 16:30 - 2008-05-04 01:42 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll
2015-02-26 03:36 - 2015-02-26 03:36 - 01138208 _____ () C:\Program Files\Consumer Input\Monitoring\dca-monitoring.exe
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00017768 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe
2015-03-12 11:57 - 2015-03-12 11:57 - 00012144 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Service.Logger.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00034152 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WcfService.dll
2015-04-11 01:17 - 2015-03-03 20:18 - 01208944 _____ () C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
2015-04-11 01:17 - 2015-03-03 20:18 - 00536688 _____ () C:\Program Files\360\Total Security\safemon\wdui2.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00077632 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.Utils.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00179560 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Business.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00046920 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.adblocker.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00033136 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Repositories.dll
2015-03-12 11:57 - 2015-03-12 11:57 - 00015696 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.Utils.SqlLite.dll
2015-03-12 11:58 - 2015-03-12 11:58 - 00123224 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.PUP.Management.dll
2015-03-12 11:58 - 2015-03-12 11:58 - 00073544 _____ () C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.SysInfo.dll
2008-09-30 21:31 - 2011-08-22 01:18 - 00925696 _____ () C:\Program Files\Yahoo!\Messenger\yui.dll
2015-04-10 21:57 - 2015-04-10 21:57 - 01283072 _____ () C:\Program Files\OLBPre\OLBPre.exe
2015-04-10 21:55 - 2015-04-10 21:55 - 00060928 _____ () C:\Program Files\OLBPre\LinqBridge.dll
2015-04-11 00:46 - 2015-03-30 14:07 - 09279304 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.118\pdf.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Public\Pictures\Sample Pictures\Dock.jpg
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^StrongVaultApp.exe.lnk => C:\Windows\pss\StrongVaultApp.exe.lnk.CommonStartup
MSCONFIG\startupreg: Dell DataSafe Online => "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
MSCONFIG\startupreg: DellSupportCenter => "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
MSCONFIG\startupreg: dscactivate => "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
MSCONFIG\startupreg: ECenter => C:\Dell\E-Center\EULALauncher.exe
MSCONFIG\startupreg: GenieoSystemTray => "C:\Users\Debbie\AppData\Roaming\Genieo\Application\TrayUi\bin\gentray.exe"
MSCONFIG\startupreg: GenieoUpdaterService => "C:\Users\Debbie\AppData\Roaming\Genieo\Application\Updater\bin\genupdater.exe" -wait 5
MSCONFIG\startupreg: Google Desktop Search => "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: IAAnotif => "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
MSCONFIG\startupreg: Messenger => "C:\Program Files\Strongvault Online Backup\SMessenger.exe"
MSCONFIG\startupreg: Search Protection => C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
MSCONFIG\startupreg: StartCCC => "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
MSCONFIG\startupreg: SysTrayApp => %ProgramFiles%\IDT\WDM\sttray.exe
MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide
MSCONFIG\startupreg: YSearchProtection => C:\Program Files\Yahoo!\Search Protection\YspService.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [{0FCF4BF8-60A2-4C20-BDAF-F72EC782CCFB}] => (Allow) C:\Program Files\Dell\MediaDirect\MediaDirect.exe
FirewallRules: [{4590FFC5-15F6-4F8B-ADE9-E60A8970712A}] => (Allow) C:\Program Files\Dell\MediaDirect\PCMService.exe
FirewallRules: [{031DEECF-2B71-4CED-ABD3-1A77B13D7C4D}] => (Allow) C:\Program Files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe
FirewallRules: [{14310A78-4D35-4729-AB7D-03FD013BAAA5}] => (Allow) C:\Program Files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe
FirewallRules: [{FE4D144A-2E38-49C1-BE28-9510E71C0CA3}] => (Allow) C:\Program Files\Common Files\aol\acs\AOLDial.exe
FirewallRules: [{5EB2C47B-266B-410E-ADE0-DADE2CBEBAE0}] => (Allow) C:\Program Files\Common Files\aol\acs\AOLDial.exe
FirewallRules: [{5D879BF9-715A-4581-B67E-BC7E452D7192}] => (Allow) C:\Program Files\Common Files\aol\acs\AOLacsd.exe
FirewallRules: [{0FBD2CE3-1509-46B2-86F6-AF7EFCFFAB9C}] => (Allow) C:\Program Files\Common Files\aol\acs\AOLacsd.exe
FirewallRules: [{6015874E-1F52-41C9-9261-890FE65D1177}] => (Allow) C:\Program Files\Common Files\aol\1222750019\ee\aolsoftware.exe
FirewallRules: [{F102B710-F49F-404F-94C6-AC92696AAB65}] => (Allow) C:\Program Files\Common Files\aol\1222750019\ee\aolsoftware.exe
FirewallRules: [{10B061AF-DA59-4CC9-A871-F217E04E3C64}] => (Allow) C:\Program Files\AOL 9.1\waol.exe
FirewallRules: [{E270613A-BAC0-4423-BD0A-334FFA8A5981}] => (Allow) C:\Program Files\AOL 9.1\waol.exe
FirewallRules: [{2B77A81B-B1ED-4860-9861-C3A9065D1881}] => (Allow) C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{1B502E9E-E93D-4C03-A132-7CD2265CE0EB}] => (Allow) C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{2BCD7931-FD83-4DB8-8881-1915878DED0A}] => (Allow) C:\Program Files\Common Files\aol\Loader\aolload.exe
FirewallRules: [{E09B5238-3064-450B-923A-2AA990262526}] => (Allow) C:\Program Files\Common Files\aol\Loader\aolload.exe
FirewallRules: [{B2AAD55C-26F2-4BCF-8934-B617AFD23CA5}] => (Allow) C:\Program Files\Common Files\aol\System Information\sinf.exe
FirewallRules: [{DA968B3D-4D02-4A4C-AB3A-FA102C18F78B}] => (Allow) C:\Program Files\Common Files\aol\System Information\sinf.exe
FirewallRules: [{F8EA641B-5F6D-4922-9813-0669E777F281}] => (Allow) C:\Program Files\AOL 9.1a\waol.exe
FirewallRules: [{7B516E73-2908-4359-BDC8-521A87A73C2A}] => (Allow) C:\Program Files\AOL 9.1a\waol.exe
FirewallRules: [{1AD87AE7-8D5A-4E58-9B8C-35497DEE2CC3}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{100E7CE4-7D11-401C-9038-B49C4D0E05A8}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{BBC7EF34-1FA1-4E6F-B331-2F5ABB36F4BB}] => (Allow) LPort=80
FirewallRules: [{18348291-09E4-47F0-84FF-32BEB939A488}] => (Allow) LPort=80
FirewallRules: [{CB795EDB-97B5-4C90-81E4-5E0477531D25}] => (Allow) LPort=80
FirewallRules: [{A626637E-B48C-4718-9BF7-7FB4476AD063}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe
FirewallRules: [{C9A3F6EB-F393-4D73-B860-8C0BD5C1AC58}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe
FirewallRules: [{C6E690DF-3397-4D3C-99F2-20E33982ACB3}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{05DF0AF0-05C3-4C55-B199-EADD14DA0D19}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{7017BBC9-7306-4099-8CC4-6048F21E7404}] => (Allow) C:\Program Files\AOL Desktop 9.7\waol.exe
FirewallRules: [{A0513235-E69B-4700-9C90-E046B45DD1A9}] => (Allow) C:\Program Files\AOL Desktop 9.7\waol.exe
FirewallRules: [{70294EED-ACDD-4DC1-B57E-F69458677431}] => (Allow) C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe
FirewallRules: [{195FAA1C-4F89-41FA-8C2E-4B93AF284D34}] => (Allow) C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe
FirewallRules: [TCP Query User{361F0C02-6960-45CA-A47B-AAFDDF793BB7}C:\program files\java\jre1.6.0_05\bin\javaw.exe] => (Allow) C:\program files\java\jre1.6.0_05\bin\javaw.exe
FirewallRules: [UDP Query User{2142573E-CD33-4A25-A36F-D74597EFFA5C}C:\program files\java\jre1.6.0_05\bin\javaw.exe] => (Allow) C:\program files\java\jre1.6.0_05\bin\javaw.exe
FirewallRules: [{3910F279-41DF-47A4-A93A-FB178FB6D79F}] => (Allow) C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe
FirewallRules: [{206E1FB4-1E53-45E6-9EB4-55607E429BA1}] => (Allow) C:\Program Files\File Type Assistant\TSAssist.exe
FirewallRules: [{10211F78-2D66-4433-9BF8-F4B3849D701B}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{DE9C2700-B0FA-45D1-8923-93DDE5560C4F}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{7A3390D6-ACE7-40EF-98DC-E6EF8AC7A074}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{1E5B4321-4CD8-4457-BE37-BC626CD258B8}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{060830E9-F25E-48CF-A45B-1037691F2FCA}] => (Allow) C:\Program Files\Common Files\aol\1356558711\ee\aolsoftware.exe
FirewallRules: [{CFBB1DF3-1B1F-423E-9A54-2543CD09B5F6}] => (Allow) C:\Program Files\Common Files\aol\1356558711\ee\aolsoftware.exe
FirewallRules: [{0B56F9EC-1DD7-48D1-BF63-EB595308D414}] => (Allow) C:\Program Files\AOL Desktop 9.7a\waol.exe
FirewallRules: [{0A1F7322-D581-4270-A4EF-C8AA1ACCE86D}] => (Allow) C:\Program Files\AOL Desktop 9.7a\waol.exe
FirewallRules: [{FE8187C6-8D0A-41B7-932D-7EF87DF32075}] => (Allow) C:\Program Files\AOL Desktop 9.7a\AOLBrowser\aolbrowser.exe
FirewallRules: [{3AFD4FE7-794B-4CDD-8672-5F81E4030734}] => (Allow) C:\Program Files\AOL Desktop 9.7a\AOLBrowser\aolbrowser.exe
FirewallRules: [TCP Query User{00C1CA9F-39F4-482B-97D7-A5D2A2AAF64D}C:\program files\electronic arts\eadm\core.exe] => (Block) C:\program files\electronic arts\eadm\core.exe
FirewallRules: [UDP Query User{53C13880-E75D-49A4-9621-9D9FF96DC7FA}C:\program files\electronic arts\eadm\core.exe] => (Block) C:\program files\electronic arts\eadm\core.exe
FirewallRules: [{F843BC40-16EB-49F4-BDFE-FEAD62932DEE}] => (Allow) C:\Program Files\AOL Desktop 9.7b\waol.exe
FirewallRules: [{4A85AFAF-2775-4350-80DD-425B3244519D}] => (Allow) C:\Program Files\AOL Desktop 9.7b\waol.exe
FirewallRules: [{6E7C051B-70AF-49C4-AEB2-AB4997DD9ECA}] => (Allow) C:\Program Files\AOL Desktop 9.7b\AOLBrowser\aolbrowser.exe
FirewallRules: [{65CE8AEA-ECE3-4358-A58E-5931EBB636BF}] => (Allow) C:\Program Files\AOL Desktop 9.7b\AOLBrowser\aolbrowser.exe
FirewallRules: [{CE7C9BC2-2B22-479E-80B7-39E455F0F949}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0527237F-BC60-40F6-AA26-C84801DCB7BF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{AF95BFA0-0F10-47B2-8BDB-27C48B5BB1C3}] => (Allow) C:\Program Files\AOL Desktop 9.7c\waol.exe
FirewallRules: [{52BE795E-2678-468F-919A-E9B6E9680861}] => (Allow) C:\Program Files\AOL Desktop 9.7c\waol.exe
FirewallRules: [{B66423F7-85D0-4B0A-A314-69D72A30A041}] => (Allow) C:\Program Files\AOL Desktop 9.7c\aolbrowser.exe
FirewallRules: [{9092D0C1-978B-4BD0-B9ED-09236FA8713B}] => (Allow) C:\Program Files\AOL Desktop 9.7c\aolbrowser.exe
FirewallRules: [{9CD8031A-3A96-4196-B958-2D4DCF4596A6}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{A171A0FF-DD53-4FB0-9A16-735A7019AF3D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{0093BB0A-732B-4506-92B5-CB6BFEBB27B0}] => (Allow) C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{A3E7C8A1-0B2C-451F-9A8E-ABA05791931F}] => (Allow) C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{AFB10E07-12D5-4CB0-8086-BE6AAEAC754E}] => (Allow) C:\Program Files\360\Total Security\LiveUpdate360.exe
FirewallRules: [{3FCF58E6-6BD1-4D7D-90CC-1E054669A0B2}] => (Allow) C:\Program Files\360\Total Security\LiveUpdate360.exe
FirewallRules: [{F567F335-BA28-42D4-B4C5-0A103653F01F}] => (Allow) C:\Users\Debbie\AppData\Local\Temp\~os1A44.tmp\pmropn.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Bluetooth Device (RFCOMM Protocol TDI)
Description: Bluetooth Device (RFCOMM Protocol TDI)
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: RFCOMM
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/09/2015 09:46:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (06/09/2015 09:28:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (06/09/2015 09:27:47 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c
 
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (06/09/2015 09:15:50 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (06/09/2015 09:15:50 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
Error: (06/09/2015 09:15:42 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: The entry in the hash map cannot be updated.
 
Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
 
 
System errors:
=============
 
Microsoft Office:
=========================
Error: (06/09/2015 09:46:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (06/09/2015 09:28:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (06/09/2015 09:27:47 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c
 
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\UNINSTALL INSTRUCTIONS.LNK
 
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\UNINSTALL INSTRUCTIONS.LNK
 
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\MEMBER OF GRID -  GOODWARE REPOSITORY INFORMATION DATABASE.LNK
 
Error: (06/09/2015 09:15:52 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\MEMBER OF GRID -  GOODWARE REPOSITORY INFORMATION DATABASE.LNK
 
Error: (06/09/2015 09:15:50 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\SUPPORT.LNK
 
Error: (06/09/2015 09:15:50 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\SUPPORT.LNK
 
Error: (06/09/2015 09:15:42 PM) (Source: Windows Search Service) (EventID: 3013) (User: )
Description: Context:  Application, SystemIndex Catalog
 
 
Details:
A device attached to the system is not functioning.   (0x8007001f)
C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\PREMIEROPINION\ABOUT PREMIEROPINION.LNK
 
 
CodeIntegrity Errors:
===================================
  Date: 2015-06-09 22:55:00.664
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360Box.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-09 22:54:59.034
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360Box.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-09 22:54:57.251
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360Box.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-09 22:54:55.642
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360Box.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-09 21:58:38.157
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-09 21:58:35.334
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-09 21:58:11.082
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-09 21:58:08.638
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-09 21:57:56.121
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\360\Total Security\filemon\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-06-09 21:57:44.432
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\360\Total Security\filemon\360AvFlt.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM)2 Duo CPU T5850 @ 2.16GHz
Percentage of memory in use: 65%
Total physical RAM: 3581.05 MB
Available physical RAM: 1245.99 MB
Total Pagefile: 7347.85 MB
Available Pagefile: 4701.59 MB
Total Virtual: 2047.88 MB
Available Virtual: 1860.29 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:222.75 GB) (Free:183.29 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (RECOVERY) (Fixed) (Total:10 GB) (Free:5.02 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.9 GB) (Disk ID: 08000000)
Partition 1: (Not Active) - (Size=141 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=222.7 GB) - (Type=07 NTFS)
 
==================== End of log ============================
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-06-10 15:07:17
—————————–
15:07:17.652    OS Version: Windows 6.0.6002 Service Pack 2
15:07:17.652    Number of processors: 2 586 0xF0D
15:07:17.655    ComputerName: DEBBIE-PC  UserName: Debbie
15:07:22.061    Initialize success
15:07:22.254    VM: initialized successfully
15:07:22.257    VM: Intel CPU virtualization not supported 
15:09:34.845    AVAST engine defs: 15060901
15:10:33.925    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
15:10:33.934    Disk 0 Vendor: WDC_WD25 01.0 Size: 238475MB BusType: 3
15:10:34.254    Disk 0 MBR read successfully
15:10:34.261    Disk 0 MBR scan
15:10:34.576    Disk 0 Windows VISTA default MBR code
15:10:34.599    Disk 0 Partition 1 00     DE Dell Utility Dell 8.0      141 MB offset 63
15:10:34.818    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS        10240 MB offset 290816
15:10:34.992    Disk 0 Partition 3 80 (A) 07    HPFS/NTFS NTFS       228092 MB offset 21262336
15:10:35.097    Disk 0 scanning sectors +488394752
15:10:35.498    Disk 0 scanning C:\Windows\system32\drivers
15:11:52.880    Service scanning
15:11:54.080    Service 360AntiHacker C:\Windows\System32\Drivers\360AntiHacker.sys **LOCKED** 5
15:11:55.187    Service 360Camera C:\Windows\System32\Drivers\360Camera.sys **LOCKED** 5
15:11:55.474    Service 360SelfProtection C:\Windows\system32\drivers\360SelfProtection.sys **LOCKED** 5
15:12:03.422    Service BAPIDRV C:\Windows\system32\DRIVERS\BAPIDRV.sys **LOCKED** 5
15:12:13.557    Service EfiMon C:\Windows\System32\Drivers\Efimon.sys **LOCKED** 5
15:12:19.740    Service HookPort C:\Windows\System32\Drivers\Hookport.sys **LOCKED** 5
15:12:42.612    Service MpKsl4fe40b34 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E9AD4444-1FA9-48A9-9987-AA044985AAE1}\MpKsl4fe40b34.sys **LOCKED** 32
15:13:08.985    Service qutmdserv C:\Windows\system32\drivers\qutmdrv.sys **LOCKED** 5
15:13:40.975    Modules scanning
15:13:41.001    Disk 0 trace - called modules:
15:13:41.030    ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll 
15:13:41.046    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86ad9ac8]
15:13:41.062    3 CLASSPNP.SYS[8bba18b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85e46030]
15:13:44.378    AVAST engine scan C:\Windows
15:13:52.606    AVAST engine scan C:\Windows\system32
15:29:20.311    File: C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD088.tmp\ciie-3.2.0-12323.exe **HIDDEN**
15:29:22.107    AVAST engine scan C:\Windows\system32\drivers
15:31:12.260    AVAST engine scan C:\Users\Debbie
16:12:26.179    File: C:\Users\Debbie\AppData\Local\Temp\is1238184746\26D20BBC_stp\compete_032415013024.exe  **INFECTED** Win32:Malware-gen
16:48:54.652    File: C:\Users\Debbie\Downloads\PDFReaderSetup.exe  **INFECTED** Win32:Trojan-gen
16:50:32.672    AVAST engine scan C:\ProgramData
17:24:03.647    Disk 0 statistics 3367489/0/0 @ 0.48 MB/s
17:24:03.709    Scan finished successfully
18:33:26.788    Disk 0 MBR has been saved successfully to "C:\Users\Debbie\Desktop\MBR.dat"
18:33:27.053    The log file has been saved successfully to "C:\Users\Debbie\Desktop\aswMBR.txt"
 
 

 

Hello poporacer and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Uninstall programs

Please uninstall these programs:

360 Total Security
Ask Toolbar
Consumer Input
McAfee Security Scan Plus
MyPC Backup
PDF Reader Packages
UpdateAdmin


  • click Start, Control Panel, Programs and Features
  • click on 360 Total Security and then Uninstall
  • repeat this for the other programs listed above.

 If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

 

================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

When you’ve done the above, please run FRST again and send the new log

Logs to include with next post:

AdwCleaner log
JRT.txt
Frst.txt


Thanks

Satchfan

 

I should imagine there has been sign of improvement already as those scans got rid of quite a lot. Let’s clear up some more and find out what’s left.


Enable System Restore

  • click on Start, right-click on Computer and then click on Properties
  • in the left panel, click System protection, (if you're prompted for an administrator password or confirmation, type the password or provide confirmation)
  • under “Protection Settings”, select your system disk and then click Configure
  • select Restore system settings and previous versions of files and then click OK twice.

===================================================

Run Farbar Recovery Scan Tool

Open notepad (Start >All Programs > Accessories > Notepad). Please copy the entire contents of the code box below.

CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\MountPoints2: {1128326d-8a4e-11dd-81d3-806e6f6e6963} - E:\Setup.exe
SearchScopes: HKU\.DEFAULT -> {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=ysp
SearchScopes: HKU\.DEFAULT -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = http://search.aol.com/aolcom/search?query={searchTerms}&invocationType=tb50ie7
SearchScopes: HKU\.DEFAULT -> {AC7EE147-3932-4E15-A3CC-2F70D92337FC} URL = http://search.aol.com/aolcom/search?query={searchTerms}&invocationType=msie70a
Toolbar: HKLM - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll No File
Toolbar: HKU\.DEFAULT -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> AOL Toolbar - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll No File
FF SearchEngineOrder.1: Ask Search
FF Extension: No Name - C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\extensions\[removed] [not found]
FF Extension: No Name - C:\Program Files\Consumer Input\Firefox\ciff-3.2.0-12099.xpi [not found]
FF Extension: No Name - C:\Program Files\360\Total Security\safemon\webprotection_firefox [not found]
FF Extension: No Name - C:\Program Files\Consumer Input\Firefox\ciff-3.2.0-12099.xpi [not found]
S1 BAPIDRV; system32\DRIVERS\BAPIDRV.sys [X]
2015-06-11 20:16 - 2015-04-11 01:13 - 00000000 ____D C:\Program Files\360
2015-06-11 20:16 - 2012-12-20 00:01 - 00000380 _____ C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
2015-06-09 22:23 - 2015-04-11 01:19 - 00000000 __SHD C:\ProgramData\360Quarant
2015-06-09 22:23 - 2015-04-11 01:19 - 00000000 __SHD C:\$360Section
Task: {8A0C5E62-A6E8-4C64-9BCB-C8312BFE77D3} - System32\Tasks\FreeFileViewerUpdateChecker => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe <==== ATTENTION
Task: {E7C47B2D-12F3-4045-AA09-0F250606A5EA} - \ProPCCleaner_Start No Task File <==== ATTENTION
Task: C:\Windows\Tasks\FreeFileViewerUpdateChecker.job => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe <==== ATTENTION
FirewallRules: [{3910F279-41DF-47A4-A93A-FB178FB6D79F}] => (Allow) C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe
FirewallRules: [{10211F78-2D66-4433-9BF8-F4B3849D701B}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{DE9C2700-B0FA-45D1-8923-93DDE5560C4F}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{7A3390D6-ACE7-40EF-98DC-E6EF8AC7A074}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{1E5B4321-4CD8-4457-BE37-BC626CD258B8}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{0093BB0A-732B-4506-92B5-CB6BFEBB27B0}] => (Allow) C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{A3E7C8A1-0B2C-451F-9A8E-ABA05791931F}] => (Allow) C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{AFB10E07-12D5-4CB0-8086-BE6AAEAC754E}] => (Allow) C:\Program Files\360\Total Security\LiveUpdate360.exe
FirewallRules: [{3FCF58E6-6BD1-4D7D-90CC-1E054669A0B2}] => (Allow) C:\Program Files\360\Total Security\LiveUpdate360.exe
FirewallRules: [{F567F335-BA28-42D4-B4C5-0A103653F01F}] => (Allow) C:\Users\Debbie\AppData\Local\Temp\~os1A44.tmp\pmropn.exe
C:\Program Files\360
C:\Windows\Tasks\FreeFileViewer
C:\ProgramData\360Quarant
C:\$360Section
C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
C:\Program Files\FreeFileViewer
EmptyTemp:

NOTE: this script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

================================================

Download Malwarebytes-Anti-Malware

Click here.
 

  • double-click mbam-setup.exe and follow the prompts to install the program – (Note: Vista & Windows 7 users, please right-click and select “Run as Administrator”)
  • select the “Scan” tab at the top
  • there are three scan types; choose Threat Scan, then click on Scan
  • when the scan is complete, if no malicious items are found you can close the program
  • if malicious items are found be sure that everything is checked and click Quarantine
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.

NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Logs to include with the next post:

Fixlog.txt
Mbam.txt


Please copy/paste the logs into the post, not attach them. Thanks

 

Can you tell me if there are any outstanding problems.

Satchfan
 

Yes it is running better. I don't know how it normally ran, but it is way better than when I got it.

I ran accross a slight problem…Probably due to the version of windows this computer has(Vista). The System Properties does not have "Protection Settings" or a Configure so I couldn't do the Restore system settings and previous versions of files and then click OK twice. I followed the other instructions and here are the results:

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 13-06-2015
Ran by [removed] at 2015-06-13 09:41:11 Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal

==============================================

fixlist content:
*****************

CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\…\MountPoints2: {1128326d-8a4e-11dd-81d3-806e6f6e6963} - E:\Setup.exe
SearchScopes: HKU\.DEFAULT -> {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=ysp
SearchScopes: HKU\.DEFAULT -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = http://search.aol.com/aolcom/search?query={searchTerms}&invocationType=tb50ie7
SearchScopes: HKU\.DEFAULT -> {AC7EE147-3932-4E15-A3CC-2F70D92337FC} URL = http://search.aol.com/aolcom/search?query={searchTerms}&invocationType=msie70a
Toolbar: HKLM - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll No File
Toolbar: HKU\.DEFAULT -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-3035152371-51418450-4088448234-1000 -> AOL Toolbar - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll No File
FF SearchEngineOrder.1: Ask Search
FF Extension: No Name - C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\extensions\[removed] [not found]
FF Extension: No Name - C:\Program Files\Consumer Input\Firefox\ciff-3.2.0-12099.xpi [not found]
FF Extension: No Name - C:\Program Files\360\Total Security\safemon\webprotection_firefox [not found]
FF Extension: No Name - C:\Program Files\Consumer Input\Firefox\ciff-3.2.0-12099.xpi [not found]
S1 BAPIDRV; system32\DRIVERS\BAPIDRV.sys [X]
2015-06-11 20:16 - 2015-04-11 01:13 - 00000000 ____D C:\Program Files\360
2015-06-11 20:16 - 2012-12-20 00:01 - 00000380 _____ C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
2015-06-09 22:23 - 2015-04-11 01:19 - 00000000 __SHD C:\ProgramData\360Quarant
2015-06-09 22:23 - 2015-04-11 01:19 - 00000000 __SHD C:\$360Section
Task: {8A0C5E62-A6E8-4C64-9BCB-C8312BFE77D3} - System32\Tasks\FreeFileViewerUpdateChecker => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe <==== ATTENTION
Task: {E7C47B2D-12F3-4045-AA09-0F250606A5EA} - \ProPCCleaner_Start No Task File <==== ATTENTION
Task: C:\Windows\Tasks\FreeFileViewerUpdateChecker.job => C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe <==== ATTENTION
FirewallRules: [{3910F279-41DF-47A4-A93A-FB178FB6D79F}] => (Allow) C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe
FirewallRules: [{10211F78-2D66-4433-9BF8-F4B3849D701B}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{DE9C2700-B0FA-45D1-8923-93DDE5560C4F}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{7A3390D6-ACE7-40EF-98DC-E6EF8AC7A074}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{1E5B4321-4CD8-4457-BE37-BC626CD258B8}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{0093BB0A-732B-4506-92B5-CB6BFEBB27B0}] => (Allow) C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{A3E7C8A1-0B2C-451F-9A8E-ABA05791931F}] => (Allow) C:\Program Files\360\Total Security\safemon\QHSafeTray.exe
FirewallRules: [{AFB10E07-12D5-4CB0-8086-BE6AAEAC754E}] => (Allow) C:\Program Files\360\Total Security\LiveUpdate360.exe
FirewallRules: [{3FCF58E6-6BD1-4D7D-90CC-1E054669A0B2}] => (Allow) C:\Program Files\360\Total Security\LiveUpdate360.exe
FirewallRules: [{F567F335-BA28-42D4-B4C5-0A103653F01F}] => (Allow) C:\Users\Debbie\AppData\Local\Temp\~os1A44.tmp\pmropn.exe
C:\Program Files\360
C:\Windows\Tasks\FreeFileViewer
C:\ProgramData\360Quarant
C:\$360Section
C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
C:\Program Files\FreeFileViewer
EmptyTemp:
*****************

"HKLM\SOFTWARE\Policies\Google" => key removed successfully.
"HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
"HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1128326d-8a4e-11dd-81d3-806e6f6e6963}" => key removed successfully.
HKCR\CLSID\{1128326d-8a4e-11dd-81d3-806e6f6e6963} => key not found.
"HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2381E4B7-5C04-459E-9D46-2F9AC1608B66}" => key removed successfully.
HKCR\CLSID\{2381E4B7-5C04-459E-9D46-2F9AC1608B66} => key not found.
"HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}" => key removed successfully.
HKCR\CLSID\{443789B7-F39C-4b5c-9287-DA72D38F4FE6} => key not found.
"HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AC7EE147-3932-4E15-A3CC-2F70D92337FC}" => key removed successfully.
HKCR\CLSID\{AC7EE147-3932-4E15-A3CC-2F70D92337FC} => key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ba00b7b1-0351-477a-b948-23e3ee5a73d4} => value removed successfully.
"HKCR\CLSID\{ba00b7b1-0351-477a-b948-23e3ee5a73d4}" => key removed successfully.
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found.
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found.
HKU\S-1-5-21-3035152371-51418450-4088448234-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BA00B7B1-0351-477A-B948-23E3EE5A73D4} => value removed successfully.
HKCR\CLSID\{BA00B7B1-0351-477A-B948-23E3EE5A73D4} => key not found.
Firefox SearchEngineOrder.1 removed successfully.
C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\extensions\[removed] => not found.
C:\Program Files\Consumer Input\Firefox\ciff-3.2.0-12099.xpi => not found.
C:\Program Files\360\Total Security\safemon\webprotection_firefox => not found.
C:\Program Files\Consumer Input\Firefox\ciff-3.2.0-12099.xpi => not found.
BAPIDRV => Service removed successfully.
C:\Program Files\360 => moved successfully.
C:\Windows\Tasks\FreeFileViewerUpdateChecker.job => moved successfully.
C:\ProgramData\360Quarant => moved successfully.
C:\$360Section => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8A0C5E62-A6E8-4C64-9BCB-C8312BFE77D3}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A0C5E62-A6E8-4C64-9BCB-C8312BFE77D3}" => key removed successfully.
C:\Windows\System32\Tasks\FreeFileViewerUpdateChecker => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FreeFileViewerUpdateChecker" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E7C47B2D-12F3-4045-AA09-0F250606A5EA}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E7C47B2D-12F3-4045-AA09-0F250606A5EA}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProPCCleaner_Start" => key removed successfully.
C:\Windows\Tasks\FreeFileViewerUpdateChecker.job not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3910F279-41DF-47A4-A93A-FB178FB6D79F} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{10211F78-2D66-4433-9BF8-F4B3849D701B} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DE9C2700-B0FA-45D1-8923-93DDE5560C4F} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7A3390D6-ACE7-40EF-98DC-E6EF8AC7A074} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1E5B4321-4CD8-4457-BE37-BC626CD258B8} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0093BB0A-732B-4506-92B5-CB6BFEBB27B0} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A3E7C8A1-0B2C-451F-9A8E-ABA05791931F} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AFB10E07-12D5-4CB0-8086-BE6AAEAC754E} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3FCF58E6-6BD1-4D7D-90CC-1E054669A0B2} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F567F335-BA28-42D4-B4C5-0A103653F01F} => value removed successfully.
"C:\Program Files\360" => File/Folder not found.
"C:\Windows\Tasks\FreeFileViewer" => File/Folder not found.
"C:\ProgramData\360Quarant" => File/Folder not found.
"C:\$360Section" => File/Folder not found.
"C:\Windows\Tasks\FreeFileViewerUpdateChecker.job" => File/Folder not found.
"C:\Program Files\FreeFileViewer" => File/Folder not found.
EmptyTemp: => 3.2 GB temporary data Removed.

The system needed a reboot.

==== End of Fixlog 10:26:41 ====

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 6/13/2015
Scan Time: 10:45:53 AM
Logfile:
Administrator: Yes

Version: 2.01.6.1022
Malware Database: v2015.06.13.04
Rootkit Database: v2015.06.02.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: Debbie

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 333841
Time Elapsed: 35 min, 9 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 12
PUP.Optional.Mindspark.A, HKLM\SOFTWARE\CLASSES\CLSID\{65c72339-fb1d-4155-84e1-9afacee02d6f}, Quarantined, [3afe7248f3976fc7f8c78a1e877ce020],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{65C72339-FB1D-4155-84E1-9AFACEE02D6F}, Quarantined, [3afe7248f3976fc7f8c78a1e877ce020],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{65C72339-FB1D-4155-84E1-9AFACEE02D6F}, Quarantined, [3afe7248f3976fc7f8c78a1e877ce020],
PUP.Optional.ConsumerInput.A, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}, Quarantined, [e45400ba42488bab6099a7ca16ed9868],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{131A1F72-5C50-43CF-BA3E-3AC75DF1188B}, Quarantined, [74c47d3deaa0f73fd398c5c16e97c937],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110111981166}, Quarantined, [17217248a0ea74c25795e3a4d03517e9],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C8C9C24E-7C07-49A7-8246-3A33AEDB5E65}, Quarantined, [ce6ab00a335702344c1ff5912bda7d83],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{22134214}, Quarantined, [41f7f1c9bccec472f2318900f0154eb2],
PUP.Optional.SuperOptimizer.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, Quarantined, [cc6c596118722016d40c2468030232ce],
PUP.Optional.ProPCCleaner.A, HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\ProPCCleanerLanguage, Quarantined, [f444f7c3404a5bdb9a5e5432a065bd43],
PUP.Optional.CouponAmazing.A, HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\APPDATALOW\SOFTWARE\couponamazing, Quarantined, [fc3c5c5e0b7f1620c62a730750b5ce32],
PUP.Optional.ProductSetup.A, HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\PRODUCTSETUP, Quarantined, [c375c9f1b2d8e0568d08a5e7fb0a6a96],

Registry Values: 4
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{131a1f72-5c50-43cf-ba3e-3ac75df1188b}|AppPath, C:\Program Files\CouponXplorer_5z\bar\1.bin, Quarantined, [74c47d3deaa0f73fd398c5c16e97c937]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{21111111-1111-1111-1111-110111981166}|AppName, Deal Vault-bg.exe, Quarantined, [17217248a0ea74c25795e3a4d03517e9]
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{c8c9c24e-7c07-49a7-8246-3a33aedb5e65}|AppPath, C:\Program Files\CouponXplorer_5z\bar\1.bin, Quarantined, [ce6ab00a335702344c1ff5912bda7d83]
PUP.Optional.ProductSetup.A, HKU\S-1-5-21-3035152371-51418450-4088448234-1000\SOFTWARE\PRODUCTSETUP|tb, 1Y1L1M1G1I1Q, Quarantined, [c375c9f1b2d8e0568d08a5e7fb0a6a96]

Registry Data: 0
(No malicious items detected)

Folders: 1
PUP.Optional.MindSpark.A, C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\CouponXplorer_5z, Quarantined, [84b4f5c59eec6ccaeb7c5f9047bce51b],

Files: 3
PUP.Optional.APNToolBar.A, C:\Users\Debbie\Documents\APNSetup.exe, Quarantined, [e4544b6f5d2d78bea98e1b4abd457f81],
PUP.Optional.MindSpark.A, C:\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\CouponXplorer_5z\761596AE-596D-41F2-B885-F8C5EEECEDC0.sqlite, Quarantined, [84b4f5c59eec6ccaeb7c5f9047bce51b],
PUP.Optional.WinYahoo, C:\Users\Debbie\AppData\LocalLow\Microsoft\Internet Explorer\Services\WinYahoo.ico, Quarantined, [ae8a17a3751576c00ab6dea9bb4a946c],

Physical Sectors: 0
(No malicious items detected)

(end)

That got rid of a lot.

 

Let’s run an online scan to be sure nothing is left and if that’s clear I’ll send instructions to tidy up and reset the System Restore settings.


Run ESET Online Scan

Note: This may take a long time so please be patient.

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use Internet Explorer, FireFox or  Chrome for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan

  • click the Eset online Scanner button
  • for alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


    o    click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
    o    double click on the Eset installer icon on your desktop.
     

  • check Yes, I accept the Terms of Use
  • click the Start button
  • accept any security warnings from your browser
  • check Enable detection of potentially unwanted applications
  • click Advanced settings and select the following:


    o    scan archives
    o    scan for potentially unsafe applications
    o    enable Anti-Stealth technology


    Note: Do not check Remove found threats
     

  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • when the scan completes, push List of found threats
  • push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.


    Note - if ESET doesn't find any threats, no report will be created.

 

  • push the back button.
  • push Finish

When the scan is complete:

If no threats were found:
 


o    put a checkmark in "Uninstall application on close"
o    close program
o    report to me that nothing was found

 

If threats were found:



o    click on "list of threats found"
o    click on "export to text file" and save it as ESET results and save to the desktop
o    Click on back
o    put a checkmark in "Uninstall application on close"
o    click on finish
o    close program
o    copy and paste the report here.

 

Thanks

Satchfan
 

Here are the results:

C:\AdwCleaner\Quarantine\C\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe.vir a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application
C:\AdwCleaner\Quarantine\C\Program Files\AskPartnerNetwork\Toolbar\UpdateManager.exe.vir a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application
C:\AdwCleaner\Quarantine\C\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe.vir a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zauxstb.dll.vir Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zbar.dll.vir a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zbarsvc.exe.vir a variant of Win32/Toolbar.MyWebSearch.AN potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zbprtct.dll.vir Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zbrmon.exe.vir Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zbrstub.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zdatact.dll.vir a variant of Win32/Toolbar.MyWebSearch.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zdlghk.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zdyn.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zfeedmg.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zhighin.exe.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zhkstub.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zhtmlmu.dll.vir a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zhttpct.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zidle.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zieovr.dll.vir a variant of Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zimpipe.exe.vir Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zmedint.exe.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zmlbtn.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zmsg.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zPlugin.dll.vir a variant of Win32/Toolbar.MyWebSearch potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zradio.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zregfft.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zreghk.dll.vir Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zregiet.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zscript.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zskin.dll.vir a variant of Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zsknlcr.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zskplay.exe.vir Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zSrcAs.dll.vir a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zSrchMn.exe.vir Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5ztpinst.dll.vir a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\5zuabtn.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\AppIntegrator64.exe.vir Win64/Toolbar.MyWebSearch.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\AppIntegratorStub64.dll.vir Win64/Toolbar.MyWebSearch.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\CREXT.DLL.vir a variant of Win32/Toolbar.MyWebSearch.Z potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\CrExtP5z.exe.vir a variant of Win32/Toolbar.MyWebSearch.Z potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\DPNMNGR.DLL.vir a variant of Win32/Toolbar.MyWebSearch.AI potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\EXEMANAGER.DLL.vir a variant of Win32/Toolbar.MyWebSearch.AI potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\Hpg64.dll.vir Win64/Toolbar.MyWebSearch.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\NP5zStub.dll.vir Win32/Toolbar.MyWebSearch.T potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\T8EXTEX.DLL.vir a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\T8EXTPEX.DLL.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\T8HTML.DLL.vir a variant of Win32/Toolbar.MyWebSearch.F potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\T8TICKER.DLL.vir a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files\CouponXplorer_5z\bar\1.bin\VERIFY.DLL.vir a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Debbie\AppData\Local\Temp\Assist Point\Setup.exe.vir Win32/BrowseFox.AZ potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\Extensions\5zffxtbr@CouponXplorer_5z.com\plugins\EXEManager.dll.vir a variant of Win32/Toolbar.MyWebSearch.AI potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\Extensions\5zffxtbr@CouponXplorer_5z.com\plugins\FF-NativeMessagingDispatcher.dll.vir a variant of Win32/Toolbar.MyWebSearch.AI potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Debbie\AppData\Roaming\Mozilla\Firefox\Profiles\wif1l4te.default\Extensions\5zffxtbr@CouponXplorer_5z.com\plugins\Verify.dll.vir a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\ProgramData\Adobe\AIH.8da1eab1d02c7fb5e71c1ecf358e3ffd832fdd4f\GTB.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\All Users\Adobe\AIH.8da1eab1d02c7fb5e71c1ecf358e3ffd832fdd4f\GTB.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\Debbie\Downloads\PDFReaderSetup.exe a variant of Win32/InstallCore.YW potentially unwanted application
C:\Windows\Installer\MSI255C.tmp a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application
C:\Windows\Installer\MSI9742.tmp a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application
 

Looking good. We’ll clear up what was found and run one last scan.


Please copy all text in the code box below and paste it into Notepad:
 

@echo off
del /f /s /q "C:\ProgramData\Adobe\AIH.8da1eab1d02c7fb5e71c1ecf358e3ffd832fdd4f\GTB.exe”
del /f /s /q "C:\Users\All Users\Adobe\AIH.8da1eab1d02c7fb5e71c1ecf358e3ffd832fdd4f\GTB.exe”
del /f /s /q "C:\Users\Debbie\Downloads\PDFReaderSetup.exe”
del /f /s /q "C:\Windows\Installer\MSI255C.tmp”
del /f /s /q "C:\Windows\Installer\MSI9742.tmp”
del %0
  • save the Notepad file to your desktop and name it delfiles.bat
  • save type as "All Files"
  • on your desktop, double-click on delfiles.bat to run it, (a black CMD window will flash, then disappear - this is normal).

The files/folders, if found, will have been deleted and the "delfile.bat" file will also be deleted.

The rest of the Online scan is only reporting what has already been quarantined: whatever is in these folders can't cause any harm and will be removed when we tidy up.

==============================================

Run Security Check

Download Security Check by screen317 from here or here.

  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE: If you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED!, try rebooting the system and then run SecurityCheck again.

Can you tell me if there are any outstanding problems. If all is well I’ll send instructions to tidy up.

Satchfan
 

 

Thngs seem to be runnng fine. Here is the report:

 

 Results of screen317's Security Check version 1.004 
 Windows Vista Service Pack 2 x86 (UAC is enabled) 
 Internet Explorer 9 
 Internet Explorer 8 
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled! 
Microsoft Security Essentials  
  (On Access scanning disabled!)
 Error obtaining update status for antivirus! 
`````````Anti-malware/Other Utilities Check:`````````
 Java 7 Update 67 
 Java version 32-bit out of Date!
  Adobe Flash Player  17.0.0.188 Flash Player out of Date! 
 Adobe Reader 8 Adobe Reader out of Date!
 Mozilla Firefox 30.0 Firefox out of Date! 
 Google Chrome 41.0.2272.118 Google Chrome out of date! 
````````Process Check: objlist.exe by Laurent```````` 
 Microsoft Security Essentials MSMpEng.exe
 Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 1 %
````````````````````End of Log``````````````````````
 

Your computer appears to be clean.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:


Uninstall AdwCleaner

  • double click on adwcleaner.exe to run the tool
  • click on Uninstall
  • confirm with Yes.

===================================================

Download & run Delfix

  • download Delfix from here to remove many of the tools we've used during the cleaning process.
  • ensure “Remove disinfection tools” is checked.

Also place a checkmark next to:


o    Create registry backup
o    Purge system restore


  • click the Run button.
     

You can delete all other logs and programs we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Update installed programs

Your versions of Flash Player, Java and Adobe Reader are out-of-date and need to be removed and updated.

Having the latest updates and removing old versions ensures there are no security vulnerabilities in your system.

To remove them:

  • click Start, Control Panel, Programs and Features.
  • click on each of these programs, one at a time, name and then on Uninstall:


Java 7 Update 67
Adobe Flash Player 17.0.0.188
Adobe Reader 8


 

You can also uninstall Eset in the same way.

If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

Go here and download the latest version of Flash Player.

Note: Before you hit the Download now button, uncheck the Chrome offer if it’s not something you want.

NEXT

Visit Adobe and download the latest version of Acrobat Reader.

NEXT

Install the latest version of Java:

Java

NOTE – when you install Java, before clicking on Install, be sure to Uncheck “Install the Ask Toolbar and make Ask my default search provider”

🖼Click to load external image (Java.gif)

Even though I just had you get the latest version of Java, there is a vulnerability with regards to Java and web browsers. Therefore, we recommend to disable java in web browsers.

More information can be found here.

===================================================

Recommended programs

SpywareBlaster. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them. It blocks over 11,000 bad sites and uses no resources of your computer.

======================

Update and run Malwarebytes. This really is an excellent program that you should also update and run on a regular basis, probably weekly.

======================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

======================

Download WOT

Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:


green if it's safe
yellow for caution
red for unsafe

 

You can download the WOT add-on for Firefox, Chrome, Internet Explorer, Opera, and Safari browsers. It does not slow down your browsing experience, it is easy to use and free. Just click “Download” and you are ready to go!

======================

Unchecky

Be careful when downloading free software. Many free programs come bundled with adware, many of which cause redirects/popups and verge on being malware. There is a program that automatically “unckecks” the boxes you may not notice when downloading programs.

Download and install Unchecky .

======================

Download and install CryptoPrevent

Crypto Ransomware Warning

There are particularly nasty “Ransomware” infections out there at the moment that encrypt your files and the only way possible to get them “de-crypted” is to pay a ransome. You can read more about this here.

  • download CryptoPrevent
  • save the file to your Desktop and then open the program by clicking Run when prompted from your browser or by going to the desktop where the file was saved and double-clicking.
  • accept all the defaults during the install. The last screen of the install has a checkmark in "Launch CryptoPrevent". This will launch the program once you click Finish
  • you will get a prompt asking if you purchased a Product Key for Automatic Updates. Click No
  • you will then be prompted to learn more about automatic updates or if you want to purchase a key. This is up to you but you don't have to
  • click OK to continue and select your protection level. Go ahead and click OK.
  • click the Apply button to set Default protection
  • you may get a message stating that Windows Sidebar and Desktop Gadgets are a major security vulnerability and asking you if you want to disable them. If you don't use these features, answer Yes.

You are now protected.

Note: The free version doesn't provide automatic updates but should be updated often, (at least weekly), as this infection has serious consequences. To update it manually, open the program, select the “Updates” menu then select Check for Updates to see if there are any available.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

Help! My computer is slow! by miekiemoes

Simple and easy ways to keep your computer safe and secure on the Internet  by Lawrence Abrams


I will keep this open for 24 hours in case you have any problems, after which I’ll close the topic.

Safe computing

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI