This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Old windows has issues [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello -

 

I have an old windows and I recall it running windows xp. Yes, I know it is old and there are no real updates etc, but the issue I have is that it had a malware or a virus and I shut it down and left it. 

 

Now I need the computer. Can I not run HJT in safe mode and get you a file? What if I cannot get the computer to boot into safe mode?

 

If this is in the wrong place I apologize. Thanks for the help. 

:welcome:

 

No need for safemode, just run these scans in normal windows

 

[external image: 1QYkxTZ.jpg] Please download aswMBR to your desktop.
 
  • Right click the aswMBR icon and select Run as Administrator
  • XP users just Double Click it to run
  • If it says that this computer supports VIRTUALIZATION TECHNOLOGY do you want to use it say Yes
  • Click the Scan button to start scan.
  • Select Quickscan on the dropdown list
  • If you are asked to update the Avast Virus database please allow it to do so.
  • The scan could take 20 minutes or more , please be patient and let it finish
  • It will say Scan Finished when its done.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
  •  
    I just want to see the report….Please Do Not Fix Anything
     
    ============================================================================
     
     
     
    Please download Farbar Recovery Scan Tool and save it to your DESKTOP
     
    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
     
    How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
    A simple way to check your system: Start –> Computer (right click) –> Properties
     
    [external image: FRST_zps5d956a1a.jpg]
     
     
    • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
    • Please make sure All Users is checked
    • Just keep the defaults as in the picture checkmarked
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
    • Reason I asked was I was thinking that I would try to start it and it kept shutting down. I could be wrong. I went apple around that time. Now need it for children.

       

      I have to dig all components out and set it up. I will let you know what I have as soon as I can today.

      Good Gravy no. Never had these kinds of issues with an apple and if I am correct WTT doesn't do apple.

       

      However, Here are all three files you requested.

       

       

      aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
      Run date: 2015-06-13 13:58:30
      —————————–
      13:58:30.982    OS Version: Windows 5.1.2600 Service Pack 3
      13:58:30.982    Number of processors: 1 586 0x408
      13:58:30.982    ComputerName: PAPACOYOTE  UserName: Owner
      13:58:40.904    Initialize success
      13:58:41.123    VM: initialized successfully
      13:58:41.123    VM: Amd CPU virtualization not supported 
      14:02:18.792    The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"
       
       
      aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
      Run date: 2015-06-13 14:02:50
      —————————–
      14:02:50.653    OS Version: Windows 5.1.2600 Service Pack 3
      14:02:50.653    Number of processors: 1 586 0x408
      14:02:50.653    ComputerName: PAPACOYOTE  UserName: Owner
      14:03:01.419    Initialize success
      14:03:01.669    VM: initialized successfully
      14:03:01.669    VM: Amd CPU virtualization not supported 
      14:14:15.316    AVAST engine defs: 15061300
      14:15:47.382    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
      14:15:47.382    Disk 0 Vendor: ST3200822A 3.01 Size: 190782MB BusType: 3
      14:15:47.851    Disk 0 MBR read successfully
      14:15:47.867    Disk 0 MBR scan
      14:16:09.774    Disk 0 unknown MBR code
      14:16:09.790    Disk 0 Partition 1 00     0B        FAT32 RECOVERY     4296 MB offset 63
      14:16:17.884    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS       186475 MB offset 8799840
      14:16:17.931    Disk 0 unknown boot code
      14:16:23.118    Disk 0 statistics 271/0/0 @ 0.50 MB/s
      14:16:23.118    Scan finished successfully
      14:16:48.651    Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
      14:16:48.666    The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"
       
       
       
      Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015
      Ran by [removed] (administrator) on PAPACOYOTE on 13-06-2015 14:19:28
      Running from C:\Documents and Settings\[removed]\Desktop
      [removed]
      Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English (United States)
      Internet Explorer Version 8 (Default browser: Chrome)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
       
      ==================== Processes (Whitelisted) =================
       
      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
       
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
      (ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
      (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
      (Conduit) C:\Program Files\SearchProtect\bin\CltMngSvc.exe
      (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\ENAgent.exe
      (SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
      (Seiko Epson Corporation) C:\WINDOWS\system32\escsvc.exe
      (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE
      (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
      (LogMeIn, Inc.) C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
      (LogMeIn, Inc.) C:\Program Files\LogMeIn\x86\ramaint.exe
      (LogMeIn, Inc.) C:\Program Files\LogMeIn\x86\LogMeIn.exe
      (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
      (AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe
      (LogMeIn, Inc.) C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
      () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\loggingserver.exe
      (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
      (Hewlett-Packard Company) C:\WINDOWS\system\hpsysdrv.exe
      (Hewlett-Packard) C:\WINDOWS\system32\hphmon05.exe
      (Agere Systems) C:\WINDOWS\ltmsg.exe
      (Realtek Semiconductor Corp.) C:\WINDOWS\Alcxmntr.exe
      (Hewlett-Packard Company) C:\hp\KBD\kbd.exe
      (Alcor Micro, Corp.) C:\Program Files\Multimedia Card Reader\shwicon2k.exe
      (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
      (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
      (Cisco Systems, Inc.) C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
      (Linksys, LLC) C:\Program Files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe
      (SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
      (SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\FAX Utility\FUFAXRCV.exe
      (SEIKO EPSON CORPORATION) C:\Program Files\EPSON Software\FAX Utility\FUFAXSTM.exe
      (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
      () C:\Program Files\AVG SafeGuard toolbar\vprot.exe
      (Conduit) C:\Documents and Settings\Owner\Application Data\SearchProtect\bin\cltmng.exe
      (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
      (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      (Arcsoft, Inc.) C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
      (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
      (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
       
       
      ==================== Registry (Whitelisted) ==================
       
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
       
      HKLM\…\Run: [hpsysdrv] => c:\windows\system\hpsysdrv.exe [52736 1998-05-07] (Hewlett-Packard Company)
      HKLM\…\Run: [HPHUPD05] => c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe [49152 2003-08-21] (Hewlett-Packard)
      HKLM\…\Run: [HPHmon05] => C:\WINDOWS\System32\hphmon05.exe [483328 2003-08-21] (Hewlett-Packard)
      HKLM\…\Run: [Recguard] => C:\WINDOWS\SMINST\RECGUARD.EXE [221184 2003-11-03] ()
      HKLM\…\Run: [VTTimer] => VTTimer.exe
      HKLM\…\Run: [LTMSG] => LTMSG.exe 7
      HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      HKLM\…\Run: [nwiz] => nwiz.exe /installquiet /keeploaded /nodetect
      HKLM\…\Run: [AlcxMonitor] => C:\WINDOWS\ALCXMNTR.EXE [57344 2004-09-07] (Realtek Semiconductor Corp.)
      HKLM\…\Run: [KBD] => C:\HP\KBD\KBD.EXE [61440 2005-02-02] (Hewlett-Packard Company)
      HKLM\…\Run: [Sunkist2k] => C:\Program Files\Multimedia Card Reader\shwicon2k.exe [135168 2004-02-27] (Alcor Micro, Corp.)
      HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
      HKLM\…\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
      HKLM\…\Run: [nmctxth] => C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe [642856 2008-12-12] (Cisco Systems, Inc.)
      HKLM\…\Run: [Linksys Wireless Manager] => C:\Program Files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe [1358384 2009-02-16] (Linksys, LLC)
      HKLM\…\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1058400 2012-01-26] (SEIKO EPSON CORPORATION)
      HKLM\…\Run: [FUFAXRCV] => C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe [502912 2012-02-29] (SEIKO EPSON CORPORATION)
      HKLM\…\Run: [FUFAXSTM] => C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [863360 2012-02-29] (SEIKO EPSON CORPORATION)
      HKLM\…\Run: [SearchProtectAll] => C:\Program Files\SearchProtect\bin\cltmng.exe [2852640 2013-05-08] (Conduit)
      HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
      HKLM\…\Run: [LogMeIn GUI] => C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [63048 2013-04-30] (LogMeIn, Inc.)
      HKLM\…\Run: [vProt] => C:\Program Files\AVG SafeGuard toolbar\vprot.exe [2314416 2013-08-14] ()
      HKLM\…\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
      HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-06-20] (Microsoft Corporation)
      HKLM\…\Run: [] => [X]
      Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxsrvc.dll [2003-11-18] (Intel Corporation)
      Winlogon\Notify\LMIinit: C:\WINDOWS\system32\LMIinit.dll [2013-06-07] (LogMeIn, Inc.)
      HKLM\…\Policies\Explorer: [NoCDBurning] 0
      HKU\S-1-5-21-1489619779-1396043273-266004695-1003\…\Run: [BackupNotify] => c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe [32768 2004-01-09] (Hewlett-Packard Company)
      HKU\S-1-5-21-1489619779-1396043273-266004695-1003\…\Run: [SearchProtect] => C:\Documents and Settings\Owner\Application Data\SearchProtect\bin\cltmng.exe [2852640 2013-05-08] (Conduit)
      HKU\S-1-5-21-1489619779-1396043273-266004695-1009\…\Run: [RecordNow!] => [X]
      HKU\S-1-5-18\…\Run: [DWQueuedReporting] => c:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [437160 2007-02-26] (Microsoft Corporation)
      HKU\S-1-5-18\…\RunOnce: [RunNarrator] => C:\WINDOWS\system32\Narrator.exe [53760 2008-04-13] (Microsoft Corporation)
      Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2004-01-20]
      ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
      Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Media Card Companion Monitor.lnk [2012-02-28]
      ShortcutTarget: Media Card Companion Monitor.lnk -> C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
      Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\AutoTBar.exe [2013-07-20] (Hewlett-Packard)
       
      ==================== Internet (Whitelisted) ====================
       
      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
       
      HKU\S-1-5-21-1489619779-1396043273-266004695-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
      HKU\S-1-5-21-1489619779-1396043273-266004695-1003\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
      HKU\S-1-5-21-1489619779-1396043273-266004695-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
      HKU\S-1-5-21-1489619779-1396043273-266004695-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?ctid=CT3227981&octid;=CT3227981&SearchSource;=61&CUI;=UN11816971971956949&UM;=2&UP;=SP92F5FF14-06D9-4776-A722-9D1DF10A7193
      HKU\S-1-5-21-1489619779-1396043273-266004695-1009\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver;=6&ar;=msnhome
      HKU\S-1-5-21-1489619779-1396043273-266004695-1009\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
      SearchScopes: HKLM -> DefaultScope {047C9747-3C5F-4629-A13C-21AA1911BE04} URL = 
      SearchScopes: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> DefaultScope {047C9747-3C5F-4629-A13C-21AA1911BE04} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3227981&CUI;=UN11816971971956949&UM;=2
      SearchScopes: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> {047C9747-3C5F-4629-A13C-21AA1911BE04} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource;=4&ctid;=CT3227981&CUI;=UN11816971971956949&UM;=2
      SearchScopes: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear
      SearchScopes: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={96211E0F-148F-4486-90A2-C700654052FA}∣=256174646cbd4596a312ebda400eb2e5-89315e00ac81f121d4ef749ca57c4981f0771d55⟨=en&ds;=or011≺=sa&d;=2013-07-1601:07:58&v;=15.3.0.11&pid;=safeguard&sg;=0&sap;=dsp&q;={searchTerms}
      BHO: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files\Epson Software\E-Web Print\ewps_tb.dll [2013-02-28] (SEIKO EPSON CORPORATION)
      BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-06-26] (Oracle Corporation)
      BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
      BHO: AVG SafeGuard toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG SafeGuard toolbar\15.5.0.2\AVG SafeGuard toolbar_toolbar.dll [2013-08-14] (AVG Secure Search)
      BHO: CNavExtBho Class -> {BDF3E430-B101-42AD-A544-FADC6B084872} -> c:\Program Files\Norton AntiVirus\NavShExt.dll No File
      BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-06-26] (Oracle Corporation)
      Toolbar: HKLM - HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll [2003-11-21] (Hewlett-Packard Company)
      Toolbar: HKLM - Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26] ()
      Toolbar: HKLM - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\15.5.0.2\AVG SafeGuard toolbar_toolbar.dll [2013-08-14] (AVG Secure Search)
      Toolbar: HKLM - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files\Epson Software\E-Web Print\ewps_tb.dll [2013-02-28] (SEIKO EPSON CORPORATION)
      Toolbar: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll [2003-11-21] (Hewlett-Packard Company)
      Toolbar: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll No File
      Toolbar: HKU\S-1-5-21-1489619779-1396043273-266004695-1003 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
      Toolbar: HKU\S-1-5-21-1489619779-1396043273-266004695-1009 -> HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll [2003-11-21] (Hewlett-Packard Company)
      DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect118.cab
      Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll [2009-02-13] (Cisco Systems, Inc.)
      Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll [2013-08-14] (AVG Secure Search)
      ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
      Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
      Winsock: Catalog9 01 SpSubLSP.dll File not found
      Winsock: Catalog9 02 SpSubLSP.dll File not found
      Winsock: Catalog9 03 SpSubLSP.dll File not found
      Winsock: Catalog9 04 SpSubLSP.dll File not found
      Winsock: Catalog9 05 SpSubLSP.dll File not found
      Winsock: Catalog9 11 SpSubLSP.dll File not found
      Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
       
      FireFox:
      ========
      FF ProfilePath: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default
      FF DefaultSearchEngine: AVG Secure Search
      FF DefaultSearchUrl: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981&CUI;=UN98000957190671894&UM;=2&SearchSource;=3&q;={searchTerms}
      FF SelectedSearchEngine: Google
      FF Homepage: hxxp://www.knoxnews.com/
      FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-06-13] ()
      FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll [2013-04-03] (Adobe Systems, Inc.)
      FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2013-04-08] ()
      FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.5.0\\npsitesafety.dll [2013-08-14] (AVG Technologies)
      FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\WINDOWS\system32\npDeployJava1.dll [2013-06-26] (Oracle Corporation)
      FF Plugin: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-06-26] (Oracle Corporation)
      FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation)
      FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
      FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
      FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
      FF Plugin: @real.com/nppl3260;version=6.0.10.835 -> C:\Program Files\Real\RealOne Player\Netscape6\nppl3260.dll [2004-01-20] (RealNetworks, Inc.)
      FF Plugin: @real.com/nprjplug;version=1.0.2.1136 -> C:\Program Files\Real\RealOne Player\Netscape6\nprjplug.dll [2004-01-20] (RealNetworks)
      FF Plugin: @real.com/nprpjplug;version=6.0.11.847 -> C:\Program Files\Real\RealOne Player\Netscape6\nprpjplug.dll [2004-01-20] (RealNetworks, Inc.)
      FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll [2013-07-11] (Google Inc.)
      FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll [2013-07-11] (Google Inc.)
      FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-05-10] (Adobe Systems Inc.)
      FF Plugin HKU\S-1-5-21-1489619779-1396043273-266004695-1003: @talk.google.com/GoogleTalkPlugin -> C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgoogletalk.dll [2013-08-27] (Google)
      FF Plugin HKU\S-1-5-21-1489619779-1396043273-266004695-1003: @talk.google.com/O1DPlugin -> C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npo1d.dll [2013-08-27] (Google)
      FF Plugin HKU\S-1-5-21-1489619779-1396043273-266004695-1003: @talk.google.com/O3DPlugin -> C:\Documents and Settings\Owner\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll [2013-08-27] ()
      FF Plugin HKU\S-1-5-21-1489619779-1396043273-266004695-1003: @tools.google.com/Google Update;version=3 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll [2013-07-11] (Google Inc.)
      FF Plugin HKU\S-1-5-21-1489619779-1396043273-266004695-1003: @tools.google.com/Google Update;version=9 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll [2013-07-11] (Google Inc.)
      FF Plugin HKU\S-1-5-21-1489619779-1396043273-266004695-1003: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll [2013-05-11] (Unity Technologies ApS)
      FF user.js: detected! => C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\user.js [2013-05-29]
      FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\Owner\Application Data\mozilla\plugins\npgoogletalk.dll [2013-08-27] (Google)
      FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\Owner\Application Data\mozilla\plugins\npgtpo3dautoplugin.dll [2013-08-27] ()
      FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\Owner\Application Data\mozilla\plugins\npo1d.dll [2013-08-27] (Google)
      FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\searchplugins\conduit.xml [2013-06-26]
      FF SearchPlugin: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\searchplugins\startpage-http.xml [2013-08-10]
      FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml [2013-08-25]
      FF Extension: DoNotTrackMe - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\[removed] [2013-07-11]
      FF Extension: appbario7  - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\{6926c7f7-6006-42d1-b046-eba1b3010315} [2013-06-26]
      FF Extension: Adblock Plus Pop-up Addon - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\[removed] [2012-03-01]
      FF Extension: Element Hiding Helper for Adblock Plus - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\[removed] [2012-03-01]
      FF Extension: Ghostery - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\[removed] [2013-08-03]
      FF Extension: Online HD TV - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\[removed] [2012-10-24]
      FF Extension: Adblock Plus - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-03-01]
      FF Extension: BetterPrivacy - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2012-03-01]
      FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
      FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-01-22]
      FF HKLM\…\Firefox\Extensions: [avg@toolbar] - C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar\FireFoxExt\15.5.0.2
      FF Extension: AVG SafeGuard toolbar - C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar\FireFoxExt\15.5.0.2 [2013-08-14]
      FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Epson Software\E-Web Print\Firefox Add-on
      FF Extension: E-Web Print - C:\Program Files\Epson Software\E-Web Print\Firefox Add-on [2013-08-02]
      FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2013-05-29]
       
      Chrome: 
      =======
      CHR Profile: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default
      CHR Extension: (Google Docs) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-10]
      CHR Extension: (Google Drive) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-10]
      CHR Extension: (YouTube) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-10]
      CHR Extension: (Adblock Plus) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-08-11]
      CHR Extension: (Google Search) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-10]
      CHR Extension: (DoNotTrackMe) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd [2013-08-11]
      CHR Extension: (Disconnect) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo [2013-08-11]
      CHR Extension: (Ghostery) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2013-08-11]
      CHR Extension: (AVG SafeGuard) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2013-08-10]
      CHR Extension: (Chrome In-App Payments service) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
      CHR Extension: (Gmail) - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-10]
      CHR HKLM\…\Chrome\Extension: [dkinklhnkmkhkhofcnapakaoehijaoih] - C:\Program Files\OnlineHD.TV\onhd11.crx [Not Found]
      CHR HKLM\…\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar\ChromeExt\15.5.0.2\avg.crx [2013-08-14]
       
      ========================== Services (Whitelisted) =================
       
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
       
      R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
      R2 CltMngSvc; C:\Program Files\SearchProtect\bin\CltMngSvc.exe [97056 2013-05-08] (Conduit)
      R2 ENAgent; C:\WINDOWS\system32\ENAgent.exe [4209856 2013-01-22] (SEIKO EPSON CORPORATION)
      R2 EpsonCustomerParticipation; C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [539744 2012-05-10] (SEIKO EPSON CORPORATION)
      R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation)
      R2 EPSON_PM_RPCV4_05; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_JT50RP.EXE [142432 2013-01-22] (SEIKO EPSON CORPORATION)
      S2 IBUpdaterService; C:\Documents and Settings\All Users\Application Data\IBUpdaterService\ibsvc.exe [555264 2013-06-26] () [File not signed]
      R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182184 2013-06-26] (Oracle Corporation)
      R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-06-20] (Microsoft Corporation)
      S2 nmservice; C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [642856 2008-12-12] (Cisco Systems, Inc.)
      R2 vToolbarUpdater15.5.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [1643184 2013-08-14] (AVG Secure Search)
       
      ==================== Drivers (Whitelisted) ====================
       
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
       
      R1 AFS2K; C:\WINDOWS\system32\Drivers\AFS2K.sys [35840 2004-10-07] (Oak Technology Inc.)
      S3 ALCXSENS; C:\WINDOWS\System32\drivers\ALCXSENS.SYS [391424 2003-12-12] (Sensaura Ltd)
      R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [2279424 2004-10-01] (Realtek Semiconductor Corp.)
      R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [35328 2003-11-07] (Advanced Micro Devices)
      R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx86.sys [37664 2013-08-14] (AVG Technologies)
      R0 fasttx2k; C:\WINDOWS\System32\DRIVERS\fasttx2k.sys [142336 2003-12-02] (Promise Technology, Inc.)
      R2 fssfltr; C:\WINDOWS\System32\DRIVERS\fssfltr_tdi.sys [54760 2010-04-28] (Microsoft Corporation)
      R3 ltmodem5; C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys [652689 2003-12-12] (Agere Systems)
      R0 MpFilter; C:\WINDOWS\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
      R1 MpKslf85518d6; c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5B3DDDBF-29D2-4146-9BAB-CD480323291B}\MpKslf85518d6.sys [29904 2015-06-13] (Microsoft Corporation)
      R3 NVENET; C:\WINDOWS\System32\DRIVERS\NVENET.sys [54784 2003-04-22] (NVIDIA Corporation)
      R0 nv_agp; C:\WINDOWS\System32\DRIVERS\nv_agp.sys [21120 2003-09-03] (NVIDIA Corporation)
      R3 Pfc; C:\WINDOWS\System32\drivers\pfc.sys [10368 2003-09-19] (Padus, Inc.) [File not signed]
      R2 pnarp; C:\WINDOWS\System32\DRIVERS\pnarp.sys [23984 2008-12-12] (Cisco Systems, Inc.)
      R2 purendis; C:\WINDOWS\System32\DRIVERS\purendis.sys [25264 2008-12-12] (Cisco Systems, Inc.)
      R0 PxHelp20; C:\WINDOWS\System32\DRIVERS\PxHelp20.sys [17168 2003-07-30] (Sonic Solutions) [File not signed]
      S3 rtl8139; C:\WINDOWS\System32\DRIVERS\R8139n51.SYS [46976 2002-10-04] (Realtek Semiconductor Corporation       )
      S3 SiS315; C:\WINDOWS\System32\DRIVERS\sisgrp.sys [429440 2003-12-06] (Silicon Integrated Systems Corporation)
      R1 SiSkp; C:\WINDOWS\System32\DRIVERS\srvkp.sys [11392 2003-12-05] (Silicon Integrated Systems Corporation)
      R3 SunkFilt; C:\WINDOWS\System32\Drivers\sunkfilt.sys [39904 2004-03-22] (Alcor Micro Corp.) [File not signed]
      S3 taphss; C:\WINDOWS\System32\DRIVERS\taphss.sys [33512 2013-02-12] (AnchorFree Inc)
      R0 viaagp1; C:\WINDOWS\System32\DRIVERS\viaagp1.sys [27904 2003-07-02] (VIA Technologies, Inc.)
      S3 viagfx; C:\WINDOWS\System32\DRIVERS\vtmini.sys [117760 2003-10-17] (Copyright (C) VIA/S3 Graphics, Inc.)
      S3 WUSB54GCv3; C:\WINDOWS\System32\DRIVERS\WUSB54GCv3.sys [627072 2008-12-04] (Ralink Technology, Corp.)
      S3 {6080A529-897E-4629-A488-ABA0C29B635E}; C:\WINDOWS\System32\drivers\ialmsbw.sys [122110 2003-11-20] (Intel Corporation)
      S3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}; C:\WINDOWS\System32\drivers\ialmkchw.sys [99002 2003-11-20] (Intel Corporation)
      S4 LMIRfsClientNP; No ImagePath
      U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
      S3 Sunkfiltp; \??\C:\WINDOWS\System32\Drivers\sunkfiltp.sys [X]
      U3 aswMBR; \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\aswMBR.sys [X]
      U3 aswVmm; \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\aswVmm.sys [X]
       
      ==================== NetSvcs (Whitelisted) ===================
       
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
       
       
      ==================== One Month Created files and folders ========
       
      (If an entry is included in the fixlist, the file/folder will be moved.)
       
      2015-06-13 14:19 - 2015-06-13 14:21 - 00028898 _____ C:\Documents and Settings\Owner\Desktop\FRST.txt
      2015-06-13 14:18 - 2015-06-13 14:20 - 00000000 ____D C:\FRST
      2015-06-13 14:16 - 2015-06-13 14:16 - 00000512 _____ C:\Documents and Settings\Owner\Desktop\MBR.dat
      2015-06-13 14:02 - 2015-06-13 14:16 - 00001862 _____ C:\Documents and Settings\Owner\Desktop\aswMBR.txt
      2015-06-13 13:58 - 2015-06-13 11:08 - 01148416 _____ (Farbar) C:\Documents and Settings\Owner\Desktop\FRST.exe
      2015-06-13 13:58 - 2014-11-14 04:16 - 05198336 _____ (AVAST Software) C:\Documents and Settings\Owner\Desktop\aswMBR.exe
       
      ==================== One Month Modified files and folders ========
       
      (If an entry is included in the fixlist, the file/folder will be moved.)
       
      2015-06-13 14:21 - 2012-01-22 01:16 - 01432332 _____ C:\WINDOWS\WindowsUpdate.log
      2015-06-13 14:21 - 2004-01-20 21:19 - 00000000 ____D C:\Documents and Settings\Owner\Local Settings\Temp
      2015-06-13 14:11 - 2013-01-21 23:38 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
      2015-06-13 14:10 - 2013-01-21 23:37 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
      2015-06-13 14:10 - 2013-01-21 23:37 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
      2015-06-13 14:04 - 2013-08-20 15:10 - 00000384 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
      2015-06-13 13:54 - 2013-08-10 17:30 - 00000880 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
      2015-06-13 13:54 - 2012-01-22 00:37 - 00000186 _____ C:\WINDOWS\system\hpsysdrv.DAT
      2015-06-13 13:54 - 2004-01-20 21:16 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
      2015-06-13 13:54 - 2004-01-20 13:11 - 00000159 _____ C:\WINDOWS\wiadebug.log
      2015-06-13 13:54 - 2004-01-20 13:11 - 00000049 _____ C:\WINDOWS\wiaservc.log
      2015-06-13 12:01 - 2013-07-09 16:48 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\LogMeIn
      2015-06-13 12:01 - 2004-01-20 21:19 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Temp
      2015-06-13 12:00 - 2004-01-20 20:04 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
       
      ==================== Files in the root of some directories =======
       
      2013-07-16 01:07 - 2013-08-25 17:30 - 0003725 _____ () C:\Program Files\Mozilla Firefoxsafeguard-secure-search.xml
      2012-07-09 14:54 - 2012-07-09 14:56 - 0005632 _____ () C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
      2004-01-21 00:04 - 2004-01-21 00:04 - 0000128 _____ () C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
      2013-01-18 13:12 - 2013-01-18 13:12 - 0000218 _____ () C:\Documents and Settings\Owner\Local Settings\Application Data\recently-used.xbel
       
      Some files in TEMP:
      ====================
      C:\Documents and Settings\Owner\Local Settings\Temp\Miro_Installer.exe
      C:\Documents and Settings\Owner\Local Settings\Temp\oi_{A7A1DE9E-C1B8-48CC-B7FC-8F9BAA18C94B}.exe
      C:\Documents and Settings\Owner\Local Settings\Temp\QTInstallerHelper.dll
      C:\Documents and Settings\Owner\Local Settings\Temp\SecurityScan_Release.exe
      C:\Documents and Settings\Owner\Local Settings\Temp\SPStub.exe
      C:\Documents and Settings\Owner\Local Settings\Temp\tbappb.dll
      C:\Documents and Settings\Owner\Local Settings\Temp\ToolbarHelper.exe
      C:\Documents and Settings\Owner\Local Settings\Temp\UNINSTALL.EXE
       
       
      ==================== Bamital & volsnap Check =================
       
      (There is no automatic fix for files that do not pass verification.)
       
      C:\WINDOWS\explorer.exe => File is digitally signed
      C:\WINDOWS\system32\winlogon.exe => File is digitally signed
      C:\WINDOWS\system32\svchost.exe => File is digitally signed
      C:\WINDOWS\system32\services.exe => File is digitally signed
      C:\WINDOWS\system32\User32.dll => File is digitally signed
      C:\WINDOWS\system32\userinit.exe => File is digitally signed
      C:\WINDOWS\system32\rpcss.dll => File is digitally signed
      C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
       
      ==================== End of log ============================
       
       
      Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-06-2015
      Ran by [removed] at 2015-06-13 14:22:26
      Running from C:\Documents and Settings\[removed]\Desktop
      Boot Mode: Normal
      ==========================================================
       
       
      ==================== Accounts: =============================
       
      Administrator (S-1-5-21-1489619779-1396043273-266004695-500 - Administrator - Enabled)
      ASPNET (S-1-5-21-1489619779-1396043273-266004695-1007 - Limited - Enabled)
      Guest (S-1-5-21-1489619779-1396043273-266004695-501 - Limited - Disabled)
      HelpAssistant (S-1-5-21-1489619779-1396043273-266004695-1006 - Limited - Disabled)
      LogMeInRemoteUser (S-1-5-21-1489619779-1396043273-266004695-1009 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\LogMeInRemoteUser
      Owner (S-1-5-21-1489619779-1396043273-266004695-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Owner
      SUPPORT_388945a0 (S-1-5-21-1489619779-1396043273-266004695-1002 - Limited - Disabled)
      SUPPORT_fddfa904 (S-1-5-21-1489619779-1396043273-266004695-1005 - Limited - Disabled)
       
      ==================== Security Center ========================
       
      (If an entry is included in the fixlist, it will be removed.)
       
      AV: Microsoft Security Essentials (Enabled - Up to date) {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
       
      ==================== Installed Programs ======================
       
      (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
       
      ABBYY FineReader 9.0 Sprint (HKLM\…\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY)
      ABBYY FineReader 9.0 Sprint (Version: 9.01.513.58212 - ABBYY) Hidden
      Adobe AIR (HKLM\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
      Adobe Flash Player 17 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
      Adobe Reader X (10.1.7) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.7 - Adobe Systems Incorporated)
      Adobe Shockwave Player 12.0 (HKLM\…\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.)
      AiO_Scan (Version: 5.31.1.27 - Hewlett-Packard) Hidden
      AIOMinimal (Version: 5.31.1.27 - Hewlett-Packard) Hidden
      AiOSoftware (Version: 5.31.1.27 - Hewlett-Packard) Hidden
      Amazon Kindle (HKLM\…\Amazon Kindle) (Version:  - Amazon)
      Apple Application Support (HKLM\…\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
      Apple Mobile Device Support (HKLM\…\{E14ADE0E-75F3-4A46-87E5-26692DD626EC}) (Version: 6.1.0.13 - Apple Inc.)
      Apple Software Update (HKLM\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
      ArcSoft Media Card Companion (HKLM\…\{AC0C7D59-DE76-4AC0-9A84-A3B4D315CE11}) (Version:  - ArcSoft)
      ArcSoft PhotoStudio 5.5 (HKLM\…\{85309D89-7BE9-4094-BB17-24999C6118FC}) (Version:  - ArcSoft)
      AVG SafeGuard toolbar (HKLM\…\AVG SafeGuard toolbar) (Version: 15.5.0.2 - AVG Technologies)
      Bonjour (HKLM\…\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
      Bonjour Print Services (HKLM\…\{9D210D79-AEC5-453B-960C-4DD2C73931E1}) (Version: 2.0.2.0 - Apple Inc.)
      CameraDrivers (Version: 3.1.0 - Hewlett-Packard) Hidden
      Canon MP Navigator 2.0 (HKLM\…\MP Navigator 2.0) (Version:  - )
      Canon MP500 (HKLM\…\{BA4DF4C3-196E-4128-969A-00996B5A46F8}) (Version:  - )
      Canon Utilities Easy-PhotoPrint (HKLM\…\Easy-PhotoPrint) (Version:  - )
      Cisco WebEx Meetings (HKLM\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
      Compatibility Pack for the 2007 Office system (HKLM\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
      Copy (Version: 5.35.0.065 - Hewlett-Packard) Hidden
      CreativeProjects (Version: 5.35.0.059 - Hewlett-Packard) Hidden
      Director (Version: 5.35.0.051 - Hewlett-Packard) Hidden
      DocProc (Version: 3.5.0.0 - Hewlett-Packard) Hidden
      Easy-WebPrint (HKLM\…\Easy-WebPrint) (Version:  - )
      Enhanced Multimedia Keyboard Solution (HKLM\…\KBD) (Version:  - )
      Epson Connect Printer Setup (HKLM\…\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.1.1 - SEIKO EPSON CORPORATION)
      EPSON Connect version 1.0 (HKLM\…\EPSON Connect_is1) (Version: 1.0 - Epson America Inc.)
      Epson Customer Participation (HKLM\…\{814FA673-A085-403C-9545-747FC1495069}) (Version: 1.4.0.0 - SEIKO EPSON CORPORATION)
      Epson Event Manager (HKLM\…\{44F72193-F59C-4303-BAE8-E3E4BC1C122C}) (Version: 3.01.0003 - Seiko Epson Corporation)
      Epson E-Web Print (HKLM\…\{695C8469-7822-4B31-A673-5ED84815B649}) (Version: 1.17.0000 - SEIKO EPSON CORPORATION)
      Epson FAX Utility (HKLM\…\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.30.00 - SEIKO EPSON CORPORATION)
      Epson PC-FAX Driver (HKLM\…\EPSON PC-FAX Driver 2) (Version:  - )
      EPSON Printer Finder (HKLM\…\{B8ECD0D3-AE08-4891-B6C7-32F96B75EB6C}) (Version: 1.0.0 - SEIKO EPSON CORPORATION)
      EPSON Scan (HKLM\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
      EPSON WF-3520 Series Printer Uninstall (HKLM\…\EPSON WF-3520 Series) (Version:  - SEIKO EPSON Corporation)
      EpsonNet Print (HKLM\…\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.5.00 - SEIKO EPSON CORPORATION)
      Fax (Version: 5.31.1.27 - Hewlett-Packard) Hidden
      Google Chrome (HKLM\…\Google Chrome) (Version: 29.0.1547.66 - Google Inc.)
      Google Talk Plugin (HKLM\…\{EB38C3E0-4863-3123-9114-5BE86EC8E5C7}) (Version: 4.5.3.14917 - Google)
      Google Update Helper (Version: 1.3.21.153 - Google Inc.) Hidden
      Hewlett-Packard ACLM.NET v1.1.0.0 (Version: 1.00.0000 - Hewlett-Packard) Hidden
      HP Deskjet Preloaded Printer Drivers (HKLM\…\{F419D20A-7719-4639-8E30-C073A040D878}) (Version: 8.3.3.0 - Hewlett-Packard Company)
      HP Image Zone 3.5 (HKLM\…\HP Photo & Imaging) (Version: 3.5 - HP)
      HP Image Zone Plus 3.5 (HKLM\…\{C6C44651-7C66-4b11-92E8-17565D3D22DD}) (Version: 3.5 - HP)
      HP Instant Support (HKLM\…\HP Instant Support) (Version:  - )
      HP Organize (HKLM\…\{D0122362-6333-4DE4-93F6-A5A2F3CC101A}) (Version:  - )
      HP Photo & Imaging 3.5 - HP Devices (HKLM\…\{15B9DC72-73F9-4d99-9E28-848D66DA8D99}) (Version: 3.0 - HP)
      HP Product Detection (HKLM\…\{A436F67F-687E-4736-BD2B-537121A804CF}) (Version: 11.14.0001 - HP)
      HP PSC & OfficeJet 3.0 (HKLM\…\{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}) (Version: 3.0 - HP)
      HP Update (HKLM\…\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard)
      hpg2436 (Version: 3.5.0.0 - Hewlett-Packard) Hidden
      hpg3970 (Version: 3.5.0.0 - Hewlett-Packard) Hidden
      hpg4600 (Version: 3.5.0.0 - Hewlett-Packard) Hidden
      hpg5530 (Version: 3.5.0.0 - Hewlett-Packard) Hidden
      hpg8200 (Version: 3.5.0.0 - Hewlett-Packard) Hidden
      HPIZ350 (Version: 35.1.2 - Hewlett-Packard) Hidden
      hpmdtab (Version: 2.0.479.1607 - Hewlett-Packard) Hidden
      HpSdpAppCoreApp (Version: 2.00.0000 - Hewlett-Packard) Hidden
      HPSystemDiagnostics (Version: 1.5.0.0 - Your Company Name) Hidden
      InstantShare (Version: 3.5.0.21 - Hewlett-Packard) Hidden
      InstantShareAlert (Version: 1.00.0000 - HP) Hidden
      IntelliMover Data Transfer Demo (HKLM\…\{14589F05-C658-4594-9429-D437BA688686}) (Version:  - )
      InterActual Player (HKLM\…\InterActual Player) (Version:  - )
      InterVideo WinDVD Creator 2 (HKLM\…\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}) (Version: 2.0.14.248 - InterVideo Inc.)
      InterVideo WinDVD Player (HKLM\…\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}) (Version: 5.0-B11.896 - InterVideo Inc.)
      iTunes (HKLM\…\{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}) (Version: 11.0.4.4 - Apple Inc.)
      Java 7 Update 25 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle)
      Linksys Wireless Manager (HKLM\…\Linksys Wireless Manager) (Version: 4.9.9047.0 - Linksys, LLC)
      LogMeIn (HKLM\…\{CB7AF84A-1B7F-4C6B-8A58-EB7CDE48C23A}) (Version: 4.1.3268 - LogMeIn, Inc.)
      Memories Disc Creator 2.0 (HKLM\…\{2E132061-C78A-48D4-A899-1D13B9D189FA}) (Version: 2.0.481.1611 - Memories Disc Creator 2.0)
      Microsoft .NET Framework 1.1 (HKLM\…\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
      Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\…\M2698023) (Version:  - )
      Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\…\M2833941) (Version:  - )
      Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
      Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
      Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
      Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
      Microsoft Base Smart Card Cryptographic Service Provider Package (HKLM\…\KB909520) (Version:  - Microsoft Corporation)
      Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\…\MSCompPackV1) (Version: 1 - Microsoft Corporation)
      Microsoft Office File Validation Add-In (HKLM\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
      Microsoft Office Live Add-in 1.5 (HKLM\…\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
      Microsoft Office Outlook Connector (HKLM\…\{95120000-0122-0409-0000-0000000FF1CE}) (Version: 12.0.6423.1000 - Microsoft Corporation)
      Microsoft Office Professional Edition 2003 (HKLM\…\{91110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
      Microsoft Office Standard Edition 2003 (HKLM\…\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
      Microsoft Office Word Viewer 2003 (HKLM\…\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
      Microsoft Plus! Digital Media Edition (HKLM\…\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}) (Version: 1.1.0.2423 - Microsoft Corporation)
      Microsoft PowerPoint Viewer (HKLM\…\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
      Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.3.215.0 - Microsoft Corporation)
      Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation)
      Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
      Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\…\Wudf01000) (Version:  - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\…\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Works 7.0 (HKLM\…\{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}) (Version: 07.02.0808 - Microsoft Corporation)
      Miro (HKLM\…\Miro) (Version: 6.0 - Participatory Culture Foundation)
      Mozilla Firefox 22.0 (x86 en-US) (HKLM\…\Mozilla Firefox 22.0 (x86 en-US)) (Version: 22.0 - Mozilla)
      Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 22.0 - Mozilla)
      MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
      MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
      Multimedia Card Reader (HKLM\…\InstallShield_{B662D841-AAA0-41E8-B2AB-E374560DC5B1}) (Version: 6.14 - )
      Multimedia Card Reader (Version: 6.14 - ) Hidden
      Nikon Message Center (HKLM\…\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}) (Version: 0.91.000 - )
      NVIDIA Display Driver (HKLM\…\NVIDIA Display Driver) (Version:  - )
      NVIDIA Ethernet Driver (HKLM\…\NVIDIA Ethernet Driver) (Version:  - )
      NVIDIA GART Driver (HKLM\…\NVIDIA GART Driver) (Version:  - )
      OmniPage SE 2.0 (HKLM\…\{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}) (Version: 2.00.0004 - ScanSoft, Inc.)
      PC-Doctor for Windows (HKLM\…\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}) (Version:  - )
      PhotoGallery (Version: 5.35.0.059 - Hewlett-Packard) Hidden
      Photosmart 140,240,7200,7600,7700,7900 Series (HKLM\…\{45B6180B-DCAB-4093-8EE8-6164457517F0}) (Version: 2.0 - Hewlett-Packard)
      PictureProject (HKLM\…\{FF3999BE-1A7B-4738-88AA-97BF14094A4A}) (Version: 1.0 - )
      PictureProject In Touch Downloader 1.0 (HKLM\…\PictureProject In Touch Downloader) (Version: 1.0 - Fotonation Inc.)
      PrintScreen (Version: 5.35.0.035 - Hewlett-Packard) Hidden
      PS2 (HKLM\…\PS2) (Version:  - )
      PSShortcutsP (Version: 1.00.0000 - Hewlett-Packard) Hidden
      Pure Networks Platform (Version: 11.1.9044.0 - Pure Networks) Hidden
      Python 2.2 combined Win32 extensions (HKLM\…\Python 2.2 combined Win32 extensions) (Version:  - )
      Python 2.2.1 (HKLM\…\Python 2.2.1) (Version: 2.2.1 - PythonLabs at Zope Corporation)
      QFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
      QuickProjects (Version: 5.35.0.047 - Hewlett-Packard) Hidden
      QuickTime (HKLM\…\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
      Readme (Version: 5.31.1.27 - Hewlett-Packard) Hidden
      RealOne Player (HKLM\…\RealPlayer 6.0) (Version:  - )
      Realtek AC'97 Audio (HKLM\…\{FB08F381-6533-4108-B7DD-039E11FBC27E}) (Version:  - )
      RecordNow! (HKLM\…\{9541FED0-327F-4DF0-8B96-EF57EF622F19}) (Version: 6.5.1 - Hewlett-Packard)
      Scan (Version: 3.5.0.0 - Hewlett-Packard) Hidden
      Search Protect by conduit (HKLM\…\SearchProtect) (Version: 1.5.0.71 - Conduit) <==== ATTENTION
      Segoe UI (Version: 14.0.4327.805 - Microsoft Corp) Hidden
      SkinsHP1 (Version: 5.35.0.043 - Hewlett-Packard) Hidden
      SkinsHP2 (Version: 5.35.0.043 - Hewlett-Packard) Hidden
      Software Updater (HKLM\…\{A737E18A-5171-40D0-8034-7DD243420081}) (Version: 4.1.1 - SEIKO EPSON CORPORATION)
      Sonic Update Manager (HKLM\…\{09DA4F91-2A09-4232-AB8C-6BC740096DE3}) (Version: 2.9 - Sonic Solutions)
      SpamSubtract (HKLM\…\SpamSubtract) (Version:  - interMute, Inc.)
      swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
      Toolkit View(HP) (HKLM\…\HPTOOLKIT) (Version:  - )
      TrayApp (Version: 5.35.0.035 - Hewlett-Packard) Hidden
      Unity Web Player (HKU\S-1-5-21-1489619779-1396043273-266004695-1003\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
      Unload (Version: 3.5.0 - Hewlett-Packard) Hidden
      Updater Service (HKLM\…\Updater Service) (Version: 15,9,28,27 - ) <==== ATTENTION
      Updates from HP (HKLM\…\BackWeb-137903 Uninstaller) (Version:  - )
      WebFldrs XP (Version: 9.50.6513 - Microsoft Corporation) Hidden
      WebReg (Version: 5.31.0.147 - Hewlett-Packard) Hidden
      Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray (HKLM\…\KB952011) (Version: 1.0 - Microsoft Corporation)
      Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\KB892130) (Version:  - Microsoft Corporation)
      Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
      Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
      Windows Live Essentials (HKLM\…\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
      Windows Live Sign-in Assistant (HKLM\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
      Windows Live Sync (HKLM\…\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
      Windows Live Upload Tool (HKLM\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
      Windows Management Framework Core (HKLM\…\KB968930) (Version:  - Microsoft Corporation)
      Windows Media Format 11 runtime (HKLM\…\Windows Media Format Runtime) (Version:  - )
      Windows Media Player 11 (HKLM\…\Windows Media Player) (Version:  - )
      Windows Search 4.0 (HKLM\…\KB940157) (Version: 04.00.6001.503 - Microsoft Corporation)
      Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
       
      ==================== Custom CLSID (Whitelisted): ==========================
       
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
       
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.135\psuser.dll  (the data entry has 7 more characters).
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{047466F1-82AE-455A-AFC4-D3AC463FBF6B}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.153\GoogleUpdateOnDemand.exe (Google Inc.)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.153\GoogleUpdateOnDemand.exe (Google Inc.)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{39125640-8D80-11DC-A2FE-C5C455D89593}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkax.dll (Google)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.153\GoogleUpdateOnDemand.exe (Google Inc.)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.145\psuser.dll  (the data entry has 7 more characters).
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.123\psuser.dll  (the data entry has 7 more characters).
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.153\psuser.dll (Google Inc.)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.149\psuser.dll  (the data entry has 7 more characters).
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{97090E2F-3062-4459-855B-014F0D3CDBB1}\InprocServer32 -> C:\Program Files\Windows Desktop Search\deskbar.dll (Microsoft Corporation)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{9793fbbf-e9db-3b01-b322-3430cbcf3cd5}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\gtpo3d_host.dll (Google Inc.)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{AB9F4455-E591-4132-A386-0B91EAEDB96C}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\o1dax.dll (Google)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.153\GoogleUpdateOnDemand.exe (Google Inc.)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.153\psuser.dll (Google Inc.)
      CustomCLSID: HKU\S-1-5-21-1489619779-1396043273-266004695-1003_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.111\psuser.dll  (the data entry has 7 more characters).
       
      ==================== Restore Points =========================
       
      05-09-2013 15:50:32 System Checkpoint
      06-09-2013 08:24:56 Software Distribution Service 3.0
      06-09-2013 08:52:36 System Checkpoint
      07-09-2013 23:15:34 Software Distribution Service 3.0
      08-09-2013 23:36:07 System Checkpoint
      09-09-2013 09:06:24 Software Distribution Service 3.0
       
      ==================== Hosts content: ==========================
       
      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
       
      2004-01-20 20:04 - 2013-07-11 22:46 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts
      127.0.0.1       localhost
       
      ==================== Scheduled Tasks (Whitelisted) =============
       
      (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
       
      Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
      Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
      Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
      Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
      Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1489619779-1396043273-266004695-1003Core.job => C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
      Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1489619779-1396043273-266004695-1003UA.job => C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
      Task: C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
       
      ==================== Loaded Modules (Whitelisted) ==============
       
      2011-09-27 07:23 - 2011-09-27 07:23 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
      2011-09-27 07:22 - 2011-09-27 07:22 - 01242472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
      2013-08-14 23:59 - 2013-08-14 23:59 - 00161968 _____ () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\loggingserver.exe
      2013-08-14 23:59 - 2013-08-14 23:59 - 00521904 _____ () C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\log4cplusU.dll
      2013-07-16 01:07 - 2013-08-14 23:59 - 02314416 _____ () C:\Program Files\AVG SafeGuard toolbar\vprot.exe
      2013-08-14 23:59 - 2013-08-14 23:59 - 00144560 _____ () C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.5.0\SiteSafety.dll
      2003-10-15 14:03 - 2003-10-15 14:03 - 00163840 _____ () c:\Program Files\HP\Digital Imaging\bin\HpqUtil.dll
      2012-02-28 11:17 - 2003-10-21 17:45 - 00442368 _____ () C:\Program Files\ArcSoft\Media Card Companion\fpxlib.dll
      2012-02-28 11:17 - 2004-09-22 13:02 - 00053248 _____ () C:\Program Files\ArcSoft\Media Card Companion\ustor.dll
       
      ==================== Alternate Data Streams (Whitelisted) =========
       
      (If an entry is included in the fixlist, only the ADS will be removed.)
       
       
      ==================== Safe Mode (Whitelisted) ===================
       
      (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
       
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UploadMgr => ""="Service"
       
      ==================== EXE Association (Whitelisted) ===============
       
      (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
       
       
      ==================== Internet Explorer trusted/restricted ===============
       
      (If an entry is included in the fixlist, it will be removed from the registry.)
       
       
      ==================== Other Areas ============================
       
      (Currently there is no automatic fix for this section.)
       
      HKU\S-1-5-21-1489619779-1396043273-266004695-1003\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
      HKU\S-1-5-21-1489619779-1396043273-266004695-1009\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\welcome.htm
      DNS Servers: 192.168.1.1
       
      ==================== MSCONFIG/TASK MANAGER disabled items ==
       
      (Currently there is no automatic fix for this section.)
       
      MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk => C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
      MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk => C:\WINDOWS\pss\Windows Search.lnkCommon Startup
      MSCONFIG\startupfolder: C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Organize.lnk => C:\WINDOWS\pss\Organize.lnkStartup
      MSCONFIG\startupfolder: C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk => C:\WINDOWS\pss\spamsubtract.lnkStartup
      MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
      MSCONFIG\startupreg: Google Update => "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
      MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
      MSCONFIG\startupreg: MSMSGS => "C:\Program Files\Messenger\msmsgs.exe" /background
      MSCONFIG\startupreg: OpwareSE2 => "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
      MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      MSCONFIG\startupreg: RecordNow! => 
      MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
      MSCONFIG\startupreg: TkBellExe => "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      MSCONFIG\startupreg: UpdateManager => "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
       
      ==================== FirewallRules (Whitelisted) ===============
       
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
       
      DomainProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe] => Enabled:Windows Live Sync
      StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Owner\Local Settings\Temp\7zS6.tmp\SymNRT.exe] => Disabled:Norton Removal Tool
      StandardProfile\AuthorizedApplications: [C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe] => Enabled:Windows Live Sync
      StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe] => Enabled:Google Talk Plugin
      StandardProfile\AuthorizedApplications: [C:\Program Files\Participatory Culture Foundation\Miro\Miro_Downloader.exe] => Enabled:Miro_Downloader
      StandardProfile\AuthorizedApplications: [C:\Program Files\Participatory Culture Foundation\Miro\Miro.exe] => Enabled:Miro
      StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service
      StandardProfile\AuthorizedApplications: [E:\Common\EpsonNet Setup\ENEasyApp.exe] => Enabled:EpsonNet Setup
      StandardProfile\AuthorizedApplications: [C:\Program Files\EPSON Software\Event Manager\EEventManager.exe] => Enabled:EEventManager Application
      StandardProfile\AuthorizedApplications: [C:\Program Files\EPSON Software\ECPrinterSetup\ENPApp.exe] => Enabled:Epson Connect Printer Setup
      StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe] => Enabled:WebKit
      StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes
      StandardProfile\GloballyOpenPorts: [5985:TCP] => Disabled:Windows Remote Management 
      StandardProfile\GloballyOpenPorts: [80:TCP] => Disabled:Windows Remote Management - Compatibility Mode (HTTP-In) 
       
      ==================== Faulty Device Manager Devices =============
       
       
      ==================== Event log errors: =========================
       
      Application errors:
      ==================
      Error: (06/13/2015 01:55:16 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application nmsrvc.exe, version 11.0.8268.0, faulting module nmcore.dll, version 11.1.9044.0, fault address 0x001d3d50.
      Processing media-specific event for [nmsrvc.exe!ws!]
       
      Error: (06/13/2015 00:04:19 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application nmsrvc.exe, version 11.0.8268.0, faulting module nmcore.dll, version 11.1.9044.0, fault address 0x001d3d50.
      Processing media-specific event for [nmsrvc.exe!ws!]
       
      Error: (06/13/2015 00:03:42 PM) (Source: crypt32) (EventID: 11) (User: )
      Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
       
      Error: (06/13/2015 00:03:41 PM) (Source: crypt32) (EventID: 11) (User: )
      Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
       
      Error: (06/13/2015 00:01:19 PM) (Source: crypt32) (EventID: 11) (User: )
      Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
       
      Error: (06/13/2015 00:01:18 PM) (Source: crypt32) (EventID: 11) (User: )
      Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
       
      Error: (09/09/2013 01:45:14 PM) (Source: nview_info) (EventID: 1) (User: )
      Description: NVIEW :  rundll32: Mutex Recovery Code - leaving recovery code.
       
      Error: (09/09/2013 01:45:14 PM) (Source: nview_info) (EventID: 1) (User: )
      Description: NVIEW :  rundll32: Mutex Recovery Code - after 60 seconds, mutex recovered. NView (and Mutexes) are now enabled again.
       
      Error: (09/09/2013 01:45:14 PM) (Source: nview_info) (EventID: 1) (User: )
      Description: NVIEW :  logon: Mutex Recovery Code - Process 80 has been kicked out
       
      Error: (09/09/2013 01:45:09 PM) (Source: nview_info) (EventID: 1) (User: )
      Description: NVIEW :  rundll32: Entered Mutex Recovery Code. NView (and Mutexes) are not enabled.
       
       
      System errors:
      =============
      Error: (06/13/2015 02:19:43 PM) (Source: 0) (EventID: 9) (User: )
      Description: \Device\Ide\IdePort0
       
      Error: (06/13/2015 01:57:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Pure Networks Platform Service service terminated unexpectedly.  It has done this 1 time(s).
       
      Error: (06/13/2015 01:56:22 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
      Description: The Pure Networks Platform Service service hung on starting.
       
      Error: (06/13/2015 01:54:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: The Updater Service service failed to start due to the following error: 
      %%5
       
      Error: (06/13/2015 00:05:24 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
      Description: The Pure Networks Platform Service service hung on starting.
       
      Error: (09/09/2013 11:15:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Pure Networks Platform Service service terminated unexpectedly.  It has done this 1 time(s).
       
      Error: (09/09/2013 11:10:20 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
      Description: The Pure Networks Platform Service service hung on starting.
       
      Error: (09/09/2013 08:57:29 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Pure Networks Platform Service service terminated unexpectedly.  It has done this 1 time(s).
       
      Error: (09/09/2013 08:56:25 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
      Description: The Pure Networks Platform Service service hung on starting.
       
      Error: (09/09/2013 08:48:43 AM) (Source: 0) (EventID: 2019) (User: )
      Description: \Device\LanmanServer
       
       
      Microsoft Office:
      =========================
      Error: (06/13/2015 01:55:16 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: nmsrvc.exe11.0.8268.0nmcore.dll11.1.9044.0001d3d50
       
      Error: (06/13/2015 00:04:19 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: nmsrvc.exe11.0.8268.0nmcore.dll11.1.9044.0001d3d50
       
      Error: (06/13/2015 00:03:42 PM) (Source: crypt32) (EventID: 11) (User: )
      Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabArequired certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
       
      Error: (06/13/2015 00:03:41 PM) (Source: crypt32) (EventID: 11) (User: )
      Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabArequired certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
       
      Error: (06/13/2015 00:01:19 PM) (Source: crypt32) (EventID: 11) (User: )
      Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabArequired certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
       
      Error: (06/13/2015 00:01:18 PM) (Source: crypt32) (EventID: 11) (User: )
      Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabArequired certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
       
      Error: (09/09/2013 01:45:14 PM) (Source: nview_info) (EventID: 1) (User: )
      Description: NVIEW :  rundll32: Mutex Recovery Code - leaving recovery code.
       
      Error: (09/09/2013 01:45:14 PM) (Source: nview_info) (EventID: 1) (User: )
      Description: NVIEW :  rundll32: Mutex Recovery Code - after 60 seconds, mutex recovered. NView (and Mutexes) are now enabled again.
       
      Error: (09/09/2013 01:45:14 PM) (Source: nview_info) (EventID: 1) (User: )
      Description: NVIEW :  logon: Mutex Recovery Code - Process 80 has been kicked out
       
      Error: (09/09/2013 01:45:09 PM) (Source: nview_info) (EventID: 1) (User: )
      Description: NVIEW :  rundll32: Entered Mutex Recovery Code. NView (and Mutexes) are not enabled.
       
       
      ==================== Memory info =========================== 
       
      Processor: AMD Athlon™ 64 Processor 3200+
      Percentage of memory in use: 66%
      Total physical RAM: 1023.3 MB
      Available physical RAM: 342.43 MB
      Total Pagefile: 1692.91 MB
      Available Pagefile: 820.03 MB
      Total Virtual: 2047.88 MB
      Available Virtual: 1931.23 MB
       
      ==================== Drives ================================
       
      Drive c: (HP_PAVILION) (Fixed) (Total:182.1 GB) (Free:139.98 GB) NTFS ==>[Drive with boot components (Windows XP)]
      Drive d: (HP_RECOVERY) (Fixed) (Total:4.19 GB) (Free:0.61 GB) FAT32 ==>[Drive with boot components (Windows XP)]
      Drive k: (MPM) (Removable) (Total:3.72 GB) (Free:3.58 GB) FAT32
       
      ==================== MBR & Partition Table ==================
       
      ========================================================
      Disk: 0 (Size: 186.3 GB) (Disk ID: F806F806)
      Partition 1: (Not Active) - (Size=4.2 GB) - (Type=0B)
      Partition 2: (Active) - (Size=182.1 GB) - (Type=07 NTFS)
       
      ========================================================
      Disk: 5 (Size: 3.7 GB) (Disk ID: 00000000)
       
      Partition: GPT Partition Type.
       
      ==================== End of log ============================

      Just looking at some bogus software to remove, there known as PUPs (Potentially Unwanted Programs)

       

       
      -AdwCleaner-by Xplode
       
      Click on this link to download : ADWCleaner To your Desktop
      Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
      Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
       
       
      Do not click on any links in the top Advertisment.
       
      [external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
       
      • Close all open programs and internet browsers.
      • Double click on AdwCleaner.exe to run the tool.
      • Click on Scan.
      • After the scan is complete click on "Clean"
      • Confirm each time with Ok.
      • Your computer will be rebooted automatically. A text file will open after the restart.
      • Please post the content of that logfile with your next reply.
      • You can find the logfile at C:\AdwCleaner[S1].txt as well.
      •  
         
        ===============================================================================
         
         
        [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
        • Shut down your protection software now to avoid potential conflicts.
        • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
        • The tool will open and start scanning your system.
        • Please be patient as this can take a while to complete depending on your system's specifications.
        • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
        • Post the contents of JRT.txt into your next message.
        •  
           
           
          ===============================================================================
           
          Download Malwarebytes' Anti-Malware  to your desktop. <———
           
          • Windows XP : Double click on the icon to run it.
          • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
          •  
            [external image: MBAM2010601022_zpsyvzbaddn.jpg]
             
            • On the Dashboard click on Update Now
            • Go to the Setting Tab
            • Under Setting go to Detection and Protection
            • Under PUP and PUM make sure both are set to show Treat Detections as Malware
            • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
            • Then on the Dashboard click on Scan
            • Make sure to select THREAT SCAN
            • Then click on Scan
            • When the scan is finished and the log pops up…select Copy to Clipboard
            • Please paste the log back into this thread for review
            • Exit Malwarebytes
            • C:\AdwCleaner[S1].txt  is not found.

               

              C:\AdwCleaner\AdwCleaner[R0)

              or S0

              Or 

              R1

              are the choices I have for you. Let me know and I will get it to you.  If you know another path let me know. 

              next issue,

              JRT will open and run. Goes through a creating reg backup does a checking startup runs for a bit and shuts self down. No log anywhere.

              Ideas?

              Nahhh. it will work, might have to call LDTate in but we can make it work. Cant afford a new setup right now. have to use what we got, its just a hair more work. So thanks for walking me through this and being a lot of help. 

               MBAM is running now and found 1 thing thus far. The JRT wouldn't run and I wonder if it is because I can't turn off the microsoft antivirus sweet. I have the firewall off but couldn't get the other turned off. Once MBAM is done I will post the 3 txt files from AdwCleaner.

              Here are the files . I tried JRT again and it did the same. I am going to re run AdwCleaner and I will see if the file is the same as one of the three I gave you below. Again, thanks for seeing me through this. 

               

              MBAM

              Malwarebytes Anti-Malware

              www.malwarebytes.org
               
              Scan Date: 6/13/2015
              Scan Time: 5:37:51 PM
              Logfile: MBAM found.txt
              Administrator: Yes
               
              Version: 2.01.6.1022
              Malware Database: v2015.06.13.05
              Rootkit Database: v2015.06.02.01
              License: Trial
              Malware Protection: Enabled
              Malicious Website Protection: Enabled
              Self-protection: Disabled
               
              OS: Windows XP Service Pack 3
              CPU: x86
              File System: NTFS
              User: Owner
               
              Scan Type: Threat Scan
              Result: Completed
              Objects Scanned: 448628
              Time Elapsed: 40 min, 28 sec
               
              Memory: Enabled
              Startup: Enabled
              Filesystem: Enabled
              Archives: Enabled
              Rootkits: Disabled
              Heuristics: Enabled
              PUP: Enabled
              PUM: Enabled
               
              Processes: 0
              (No malicious items detected)
               
              Modules: 0
              (No malicious items detected)
               
              Registry Keys: 2
              Trojan.Agent, HKU\S-1-5-21-1489619779-1396043273-266004695-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{549B5CA7-4A86-11D7-A4DF-000874180BB3}, , [6acf8d2d96f4fc3a4c1fafe415eeb54b], 
              PUP.Optional.SmartBar.A, HKU\S-1-5-21-1489619779-1396043273-266004695-1003\SOFTWARE\SMARTBAR, , [b2873684602a5adc8f893e4dd332728e], 
               
              Registry Values: 1
              PUP.Optional.SmartBar.A, HKU\S-1-5-21-1489619779-1396043273-266004695-1003\SOFTWARE\SMARTBAR|GlobalUserId, 05F126B3-2718-4828-81DB-6A339F009985, , [b2873684602a5adc8f893e4dd332728e]
               
              Registry Data: 0
              (No malicious items detected)
               
              Folders: 0
              (No malicious items detected)
               
              Files: 4
              PUP.Optional.Conduit.A, C:\Documents and Settings\Owner\Local Settings\Temp\SPStub.exe, , [fe3b704ae6a463d373fe2232b64b46ba], 
              PUP.Optiona.ConduitTB.Gen, C:\Documents and Settings\Owner\Local Settings\Temp\tbappb.dll, , [45f49822701a2e08750a88f4a5610ef2], 
              PUP.Optional.Conduit.A, C:\Documents and Settings\Owner\Local Settings\Temp\ToolbarHelper.exe, , [f5444575b8d20e28b7db80a02cd4fc04], 
              Trojan.Agent.AI, C:\Documents and Settings\Owner\Local Settings\Temp\Quarantine.exe, , [3efb63574e3cdb5b2bd16a030af811ef], 
               
              Physical Sectors: 0
              (No malicious items detected)
               
               
              (end)
               
              ADWCleaner files I have
              R0
              # AdwCleaner v4.206 - Logfile created 13/06/2015 at 16:34:34
              # Updated 01/06/2015 by Xplode
              # Database : 2015-05-31.5 [Local]
              # Operating system : Microsoft Windows XP Service Pack 3 (x86)
              # Username : Owner - PAPACOYOTE
              # Running from : C:\Documents and Settings\Owner\My Documents\Downloads\AdwCleaner.exe
              # Option : Scan
               
              ***** [ Services ] *****
               
              Service Found : CltMngSvc
              Service Found : IBUpdaterService
              Service Found : vToolbarUpdater15.5.0
               
              ***** [ Files / Folders ] *****
               
              File Found : C:\DOCUME~1\Owner\LOCALS~1\Temp\Uninstall.exe
              File Found : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\searchplugins\Conduit.xml
              File Found : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\user.js
              File Found : C:\END
              File Found : C:\Program Files\Mozilla Firefox\browser\nsprotector.js
              File Found : C:\Program Files\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml
              File Found : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
              File Found : C:\WINDOWS\system32\roboot.exe
              Folder Found : C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar
              Folder Found : C:\Documents and Settings\All Users\Application Data\IBUpdaterService
              Folder Found : C:\Documents and Settings\All Users\Application Data\Tarma Installer
              Folder Found : C:\Documents and Settings\Owner\Application Data\AVG SafeGuard toolbar
              Folder Found : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\{6926c7f7-6006-42d1-b046-eba1b3010315}
              Folder Found : C:\Documents and Settings\Owner\Application Data\PerformerSoft
              Folder Found : C:\Documents and Settings\Owner\Application Data\SearchProtect
              Folder Found : C:\Documents and Settings\Owner\Local Settings\Application Data\AVG SafeGuard toolbar
              Folder Found : C:\Documents and Settings\Owner\Local Settings\Application Data\Conduit
              Folder Found : C:\Program Files\AVG SafeGuard toolbar
              Folder Found : C:\Program Files\Common Files\AVG Secure Search
              Folder Found : C:\Program Files\Conduit
              Folder Found : C:\Program Files\OnlineHD.TV
              Folder Found : C:\Program Files\SearchProtect
               
              ***** [ Scheduled tasks ] *****
               
               
              ***** [ Shortcuts ] *****
               
               
              ***** [ Registry ] *****
               
              Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - localhost;*.local
              Key Found : HKCU\Software\1ClickDownload
              Key Found : HKCU\Software\AVG SafeGuard toolbar
              Key Found : HKCU\Software\ConduitSearchScopes
              Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{047C9747-3C5F-4629-A13C-21AA1911BE04}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Key Found : HKCU\Software\SearchProtect
              Key Found : HKCU\Software\Softonic
              Key Found : HKCU\Software\SweetIM
              Key Found : HKCU\Software\WEDLMNGR
              Key Found : HKCU\Software\Zugo
              Key Found : HKLM\SOFTWARE\AVG SafeGuard toolbar
              Key Found : HKLM\SOFTWARE\AVG Security Toolbar
              Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
              Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
              Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{BF0118D4-63FF-4138-9327-F3028FB1A578}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
              Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A81E737A17150D040843D72D34240018
              Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A81E737A17150D040843D72D34240018
              Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
              Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
              Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
              Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
              Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
              Key Found : HKLM\SOFTWARE\Classes\S
              Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
              Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar
              Key Found : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem
              Key Found : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_launcher
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_launcher.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_printmanager
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_printmanager.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.tbtoolband
              Key Found : HKLM\SOFTWARE\Classes\toolband.tbtoolband.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.useroptions
              Key Found : HKLM\SOFTWARE\Classes\toolband.useroptions.1
              Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3227981
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
              Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
              Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
              Key Found : HKLM\SOFTWARE\Conduit
              Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dkinklhnkmkhkhofcnapakaoehijaoih
              Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
              Key Found : HKLM\SOFTWARE\Iminent
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG SafeGuard toolbar
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Updater Service
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A81E737A17150D040843D72D34240018
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service
              Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
              Key Found : HKLM\SOFTWARE\SearchProtect
              Key Found : HKLM\SOFTWARE\SweetIM
              Key Found : HKLM\SOFTWARE\Tarma Installer
              Key Found : HKU\.DEFAULT\Software\Avg Secure Update
              Key Found : HKU\.DEFAULT\Software\IBUpdaterService
              Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
              Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SearchProtect]
              Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{327C2873-E90D-4C37-AA9D-10AC9BABA46C}]
              Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
              Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll]
              Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
              Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
               
              ***** [ Web browsers ] *****
               
              -\\ Internet Explorer v8.0.6001.18702
               
              Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.conduit.com/?ctid=CT3227981&octid=CT3227981&SearchSource=61&CUI=UN11816971971956949&UM=2&UP=SP92F5FF14-06D9-4776-A722-9D1DF10A7193
               
              -\\ Mozilla Firefox v22.0 (en-US)
               
              [18f4bars.default] - Line Found : user_pref("CT3227981.smartbar.CTID", "CT3227981");
              [18f4bars.default] - Line Found : user_pref("CT3227981.smartbar.Uninstall", "0");
              [18f4bars.default] - Line Found : user_pref("CT3227981.smartbar.homepage", "true");
              [18f4bars.default] - Line Found : user_pref("CT3227981.smartbar.isHidden", true);
              [18f4bars.default] - Line Found : user_pref("CT3227981.smartbar.toolbarName", "appbario7 ");
              [18f4bars.default] - Line Found : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3227981&octid=CT3227981&SearchSource=61&CUI=UN98000957190671894&UM=2&UP=SP92F5FF14-06D9-4776-A722-9D1DF10A7193");
              [18f4bars.default] - Line Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
              [18f4bars.default] - Line Found : user_pref("browser.search.defaultenginename", "AVG Secure Search");
              [18f4bars.default] - Line Found : user_pref("browser.search.defaultthis.engineName", "appbario7 Customized Web Search");
              [18f4bars.default] - Line Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981&CUI=UN98000957190671894&UM=2&SearchSource=3&q={searchTerms}");
              [18f4bars.default] - Line Found : user_pref("extensions.ghostery.lsos", "{\"copyright\":\"This proprietary database is protected by copyright, and is owned exclusively by Evidon and all rights to it are expressly reserved. If you are […]
              [18f4bars.default] - Line Found : user_pref("smartbar.addressBarOwnerCTID", "CT3227981");
              [18f4bars.default] - Line Found : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3227981&CUI=UN98000957190671894&UM=2&SearchSource=13,hxxp://search.conduit.com/?ctid=CT3227981&octid=CT3227981&SearchSource[…]
              [18f4bars.default] - Line Found : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981&SearchSource=2&CUI=UN98000957190671894&UM=2&q=");
              [18f4bars.default] - Line Found : user_pref("smartbar.defaultSearchOwnerCTID", "CT3227981");
              [18f4bars.default] - Line Found : user_pref("smartbar.homePageOwnerCTID", "CT3227981");
              [18f4bars.default] - Line Found : user_pref("smartbar.machineId", "CKYBJ89AFUEI/SUPAT2UWM42QHWMAZ1KSZV6HITDTPI5PXT5DYFE9T0E5ICMMPIX4V+TAC/YJD3IEQXYR4+LWQ");
              [18f4bars.default] - Line Found : user_pref("smartbar.originalHomepage", "about:home");
               
              -\\ Google Chrome v43.0.2357.124
               
               
              *************************
               
              AdwCleaner[R0].txt - [12697 bytes] - [13/06/2015 16:34:34]
               
              ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [12757 bytes] ##########
               
              R1
              # AdwCleaner v4.206 - Logfile created 13/06/2015 at 16:37:29
              # Updated 01/06/2015 by Xplode
              # Database : 2015-05-31.5 [Local]
              # Operating system : Microsoft Windows XP Service Pack 3 (x86)
              # Username : Owner - PAPACOYOTE
              # Running from : C:\Documents and Settings\Owner\My Documents\Downloads\AdwCleaner.exe
              # Option : Scan
               
              ***** [ Services ] *****
               
              Service Found : CltMngSvc
              Service Found : IBUpdaterService
              Service Found : vToolbarUpdater15.5.0
               
              ***** [ Files / Folders ] *****
               
              File Found : C:\DOCUME~1\Owner\LOCALS~1\Temp\Uninstall.exe
              File Found : C:\DOCUME~1\Owner\LOCALS~1\Temp\Uninstall.exe
              File Found : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\searchplugins\Conduit.xml
              File Found : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\searchplugins\Conduit.xml
              File Found : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\user.js
              File Found : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\user.js
              File Found : C:\END
              File Found : C:\END
              File Found : C:\Program Files\Mozilla Firefox\browser\nsprotector.js
              File Found : C:\Program Files\Mozilla Firefox\browser\nsprotector.js
              File Found : C:\Program Files\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml
              File Found : C:\Program Files\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml
              File Found : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
              File Found : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
              File Found : C:\WINDOWS\system32\roboot.exe
              File Found : C:\WINDOWS\system32\roboot.exe
              Folder Found : C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar
              Folder Found : C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar
              Folder Found : C:\Documents and Settings\All Users\Application Data\IBUpdaterService
              Folder Found : C:\Documents and Settings\All Users\Application Data\IBUpdaterService
              Folder Found : C:\Documents and Settings\All Users\Application Data\Tarma Installer
              Folder Found : C:\Documents and Settings\All Users\Application Data\Tarma Installer
              Folder Found : C:\Documents and Settings\Owner\Application Data\AVG SafeGuard toolbar
              Folder Found : C:\Documents and Settings\Owner\Application Data\AVG SafeGuard toolbar
              Folder Found : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\{6926c7f7-6006-42d1-b046-eba1b3010315}
              Folder Found : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\{6926c7f7-6006-42d1-b046-eba1b3010315}
              Folder Found : C:\Documents and Settings\Owner\Application Data\PerformerSoft
              Folder Found : C:\Documents and Settings\Owner\Application Data\PerformerSoft
              Folder Found : C:\Documents and Settings\Owner\Application Data\SearchProtect
              Folder Found : C:\Documents and Settings\Owner\Application Data\SearchProtect
              Folder Found : C:\Documents and Settings\Owner\Local Settings\Application Data\AVG SafeGuard toolbar
              Folder Found : C:\Documents and Settings\Owner\Local Settings\Application Data\AVG SafeGuard toolbar
              Folder Found : C:\Documents and Settings\Owner\Local Settings\Application Data\Conduit
              Folder Found : C:\Documents and Settings\Owner\Local Settings\Application Data\Conduit
              Folder Found : C:\Program Files\AVG SafeGuard toolbar
              Folder Found : C:\Program Files\AVG SafeGuard toolbar
              Folder Found : C:\Program Files\Common Files\AVG Secure Search
              Folder Found : C:\Program Files\Common Files\AVG Secure Search
              Folder Found : C:\Program Files\Conduit
              Folder Found : C:\Program Files\Conduit
              Folder Found : C:\Program Files\OnlineHD.TV
              Folder Found : C:\Program Files\OnlineHD.TV
              Folder Found : C:\Program Files\SearchProtect
              Folder Found : C:\Program Files\SearchProtect
               
              ***** [ Scheduled tasks ] *****
               
               
              ***** [ Shortcuts ] *****
               
               
              ***** [ Registry ] *****
               
              Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - localhost;*.local
              Data Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - localhost;*.local
              Key Found : HKCU\Software\1ClickDownload
              Key Found : HKCU\Software\1ClickDownload
              Key Found : HKCU\Software\AVG SafeGuard toolbar
              Key Found : HKCU\Software\AVG SafeGuard toolbar
              Key Found : HKCU\Software\ConduitSearchScopes
              Key Found : HKCU\Software\ConduitSearchScopes
              Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{047C9747-3C5F-4629-A13C-21AA1911BE04}
              Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{047C9747-3C5F-4629-A13C-21AA1911BE04}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Key Found : HKCU\Software\SearchProtect
              Key Found : HKCU\Software\SearchProtect
              Key Found : HKCU\Software\Softonic
              Key Found : HKCU\Software\Softonic
              Key Found : HKCU\Software\SweetIM
              Key Found : HKCU\Software\SweetIM
              Key Found : HKCU\Software\WEDLMNGR
              Key Found : HKCU\Software\WEDLMNGR
              Key Found : HKCU\Software\Zugo
              Key Found : HKCU\Software\Zugo
              Key Found : HKLM\SOFTWARE\AVG SafeGuard toolbar
              Key Found : HKLM\SOFTWARE\AVG SafeGuard toolbar
              Key Found : HKLM\SOFTWARE\AVG Security Toolbar
              Key Found : HKLM\SOFTWARE\AVG Security Toolbar
              Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
              Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
              Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
              Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
              Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
              Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
              Key Found : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{BF0118D4-63FF-4138-9327-F3028FB1A578}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{BF0118D4-63FF-4138-9327-F3028FB1A578}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
              Key Found : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
              Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A81E737A17150D040843D72D34240018
              Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A81E737A17150D040843D72D34240018
              Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A81E737A17150D040843D72D34240018
              Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A81E737A17150D040843D72D34240018
              Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
              Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
              Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
              Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
              Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
              Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
              Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
              Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
              Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
              Key Found : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
              Key Found : HKLM\SOFTWARE\Classes\S
              Key Found : HKLM\SOFTWARE\Classes\S
              Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
              Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
              Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
              Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar
              Key Found : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar
              Key Found : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem
              Key Found : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem
              Key Found : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_launcher
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_launcher
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_launcher.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_launcher.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_printmanager
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_printmanager
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_printmanager.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pm_printmanager.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.tbtoolband
              Key Found : HKLM\SOFTWARE\Classes\toolband.tbtoolband
              Key Found : HKLM\SOFTWARE\Classes\toolband.tbtoolband.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.tbtoolband.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.useroptions
              Key Found : HKLM\SOFTWARE\Classes\toolband.useroptions
              Key Found : HKLM\SOFTWARE\Classes\toolband.useroptions.1
              Key Found : HKLM\SOFTWARE\Classes\toolband.useroptions.1
              Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3227981
              Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3227981
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
              Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
              Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
              Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
              Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
              Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
              Key Found : HKLM\SOFTWARE\Conduit
              Key Found : HKLM\SOFTWARE\Conduit
              Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dkinklhnkmkhkhofcnapakaoehijaoih
              Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dkinklhnkmkhkhofcnapakaoehijaoih
              Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
              Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
              Key Found : HKLM\SOFTWARE\Iminent
              Key Found : HKLM\SOFTWARE\Iminent
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG SafeGuard toolbar
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG SafeGuard toolbar
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Updater Service
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Updater Service
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A81E737A17150D040843D72D34240018
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A81E737A17150D040843D72D34240018
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service
              Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service
              Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
              Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
              Key Found : HKLM\SOFTWARE\SearchProtect
              Key Found : HKLM\SOFTWARE\SearchProtect
              Key Found : HKLM\SOFTWARE\SweetIM
              Key Found : HKLM\SOFTWARE\SweetIM
              Key Found : HKLM\SOFTWARE\Tarma Installer
              Key Found : HKLM\SOFTWARE\Tarma Installer
              Key Found : HKU\.DEFAULT\Software\Avg Secure Update
              Key Found : HKU\.DEFAULT\Software\Avg Secure Update
              Key Found : HKU\.DEFAULT\Software\IBUpdaterService
              Key Found : HKU\.DEFAULT\Software\IBUpdaterService
              Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
              Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
              Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SearchProtect]
              Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SearchProtect]
              Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{327C2873-E90D-4C37-AA9D-10AC9BABA46C}]
              Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{327C2873-E90D-4C37-AA9D-10AC9BABA46C}]
              Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
              Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
              Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll]
              Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll]
              Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
              Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
              Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
              Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
               
              ***** [ Web browsers ] *****
               
              -\\ Internet Explorer v8.0.6001.18702
               
              Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.conduit.com/?ctid=CT3227981&octid=CT3227981&SearchSource=61&CUI=UN11816971971956949&UM=2&UP=SP92F5FF14-06D9-4776-A722-9D1DF10A7193
               
              -\\ Mozilla Firefox v22.0 (en-US)
               
              [18f4bars.default] - Line Found : user_pref("CT3227981.smartbar.CTID", "CT3227981");
              [18f4bars.default] - Line Found : user_pref("CT3227981.smartbar.Uninstall", "0");
              [18f4bars.default] - Line Found : user_pref("CT3227981.smartbar.homepage", "true");
              [18f4bars.default] - Line Found : user_pref("CT3227981.smartbar.isHidden", true);
              [18f4bars.default] - Line Found : user_pref("CT3227981.smartbar.toolbarName", "appbario7 ");
              [18f4bars.default] - Line Found : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3227981&octid=CT3227981&SearchSource=61&CUI=UN98000957190671894&UM=2&UP=SP92F5FF14-06D9-4776-A722-9D1DF10A7193");
              [18f4bars.default] - Line Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
              [18f4bars.default] - Line Found : user_pref("browser.search.defaultenginename", "AVG Secure Search");
              [18f4bars.default] - Line Found : user_pref("browser.search.defaultthis.engineName", "appbario7 Customized Web Search");
              [18f4bars.default] - Line Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981&CUI=UN98000957190671894&UM=2&SearchSource=3&q={searchTerms}");
              [18f4bars.default] - Line Found : user_pref("extensions.ghostery.lsos", "{\"copyright\":\"This proprietary database is protected by copyright, and is owned exclusively by Evidon and all rights to it are expressly reserved. If you are […]
              [18f4bars.default] - Line Found : user_pref("smartbar.addressBarOwnerCTID", "CT3227981");
              [18f4bars.default] - Line Found : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3227981&CUI=UN98000957190671894&UM=2&SearchSource=13,hxxp://search.conduit.com/?ctid=CT3227981&octid=CT3227981&SearchSource[…]
              [18f4bars.default] - Line Found : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981&SearchSource=2&CUI=UN98000957190671894&UM=2&q=");
              [18f4bars.default] - Line Found : user_pref("smartbar.defaultSearchOwnerCTID", "CT3227981");
              [18f4bars.default] - Line Found : user_pref("smartbar.homePageOwnerCTID", "CT3227981");
              [18f4bars.default] - Line Found : user_pref("smartbar.machineId", "CKYBJ89AFUEI/SUPAT2UWM42QHWMAZ1KSZV6HITDTPI5PXT5DYFE9T0E5ICMMPIX4V+TAC/YJD3IEQXYR4+LWQ");
              [18f4bars.default] - Line Found : user_pref("smartbar.originalHomepage", "about:home");
               
              -\\ Google Chrome v43.0.2357.124
               
               
              *************************
               
              AdwCleaner[R0].txt - [12837 bytes] - [13/06/2015 16:34:34]
              AdwCleaner[R1].txt - [22086 bytes] - [13/06/2015 16:37:29]
               
              ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [22146 bytes] ##########
               
              S0
              # AdwCleaner v4.206 - Logfile created 13/06/2015 at 16:47:50
              # Updated 01/06/2015 by Xplode
              # Database : 2015-05-31.5 [Local]
              # Operating system : Microsoft Windows XP Service Pack 3 (x86)
              # Username : Owner - PAPACOYOTE
              # Running from : C:\Documents and Settings\Owner\My Documents\Downloads\AdwCleaner.exe
              # Option : Cleaning
               
              ***** [ Services ] *****
               
              [#] Service Deleted : CltMngSvc
              [#] Service Deleted : IBUpdaterService
              [#] Service Deleted : vToolbarUpdater15.5.0
               
              ***** [ Files / Folders ] *****
               
              Folder Deleted : C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar
              Folder Deleted : C:\Documents and Settings\All Users\Application Data\IBUpdaterService
              Folder Deleted : C:\Documents and Settings\All Users\Application Data\Tarma Installer
              Folder Deleted : C:\Program Files\AVG SafeGuard toolbar
              Folder Deleted : C:\Program Files\Conduit
              Folder Deleted : C:\Program Files\OnlineHD.TV
              Folder Deleted : C:\Program Files\SearchProtect
              Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
              [!] Folder Deleted : C:\Documents and Settings\Owner\Local Settings\Application Data\AVG SafeGuard toolbar
              Folder Deleted : C:\Documents and Settings\Owner\Local Settings\Application Data\Conduit
              Folder Deleted : C:\Documents and Settings\Owner\Application Data\AVG SafeGuard toolbar
              Folder Deleted : C:\Documents and Settings\Owner\Application Data\PerformerSoft
              Folder Deleted : C:\Documents and Settings\Owner\Application Data\SearchProtect
              Folder Deleted : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\Extensions\{6926c7f7-6006-42d1-b046-eba1b3010315}
              [!] Folder Deleted : C:\Documents and Settings\Owner\Local Settings\Application Data\AVG SafeGuard toolbar
              File Deleted : C:\END
              File Deleted : C:\WINDOWS\system32\roboot.exe
              File Deleted : C:\DOCUME~1\Owner\LOCALS~1\Temp\Uninstall.exe
              File Deleted : C:\Program Files\Mozilla Firefox\browser\nsprotector.js
              File Deleted : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\searchplugins\Conduit.xml
              File Deleted : C:\Program Files\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml
              File Deleted : C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\18f4bars.default\user.js
              File Deleted : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
               
              ***** [ Scheduled tasks ] *****
               
               
              ***** [ Shortcuts ] *****
               
               
              ***** [ Registry ] *****
               
              Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
              Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dkinklhnkmkhkhofcnapakaoehijaoih
              Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
              Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SearchProtect]
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
              Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
              Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
              Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
              Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
              Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
              Key Deleted : HKLM\SOFTWARE\Classes\S
              Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
              Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.eb_explorerbar.1
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.ipm_printlistitem.1
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.pm_launcher
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.pm_launcher.1
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.pm_printmanager
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.pm_printmanager.1
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.pr_bindstatuscallback.1
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.pr_cancelbuttoneventhandler.1
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.tbtoolband
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.tbtoolband.1
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.useroptions
              Key Deleted : HKLM\SOFTWARE\Classes\toolband.useroptions.1
              Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
              Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
              Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll]
              Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
              Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
              Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3227981
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
              Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BF0118D4-63FF-4138-9327-F3028FB1A578}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
              Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
              Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
              Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
              Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
              Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{327C2873-E90D-4C37-AA9D-10AC9BABA46C}
              Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
              Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{327C2873-E90D-4C37-AA9D-10AC9BABA46C}]
              Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
              Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
              Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{047C9747-3C5F-4629-A13C-21AA1911BE04}
              Key Deleted : HKCU\Software\1ClickDownload
              Key Deleted : HKCU\Software\AVG SafeGuard toolbar
              Key Deleted : HKCU\Software\ConduitSearchScopes
              Key Deleted : HKCU\Software\SearchProtect
              Key Deleted : HKCU\Software\Softonic
              Key Deleted : HKCU\Software\SweetIM
              Key Deleted : HKCU\Software\WEDLMNGR
              Key Deleted : HKCU\Software\Zugo
              Key Deleted : HKLM\SOFTWARE\AVG SafeGuard toolbar
              Key Deleted : HKLM\SOFTWARE\AVG Security Toolbar
              Key Deleted : HKLM\SOFTWARE\Conduit
              Key Deleted : HKLM\SOFTWARE\Iminent
              Key Deleted : HKLM\SOFTWARE\SearchProtect
              Key Deleted : HKLM\SOFTWARE\SweetIM
              Key Deleted : HKLM\SOFTWARE\Tarma Installer
              Key Deleted : HKU\.DEFAULT\Software\IBUpdaterService
              Key Deleted : HKU\.DEFAULT\Software\Avg Secure Update
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG SafeGuard toolbar
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Updater Service
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A81E737A17150D040843D72D34240018
              Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A81E737A17150D040843D72D34240018
              Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A81E737A17150D040843D72D34240018
              Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - localhost;*.local
              Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - localhost;*.local
               
              ***** [ Web browsers ] *****
               
              -\\ Internet Explorer v8.0.6001.18702
               
              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
              Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
               
              -\\ Mozilla Firefox v22.0 (en-US)
               
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("CT3227981.smartbar.CTID", "CT3227981");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("CT3227981.smartbar.Uninstall", "0");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("CT3227981.smartbar.homepage", "true");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("CT3227981.smartbar.isHidden", true);
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("CT3227981.smartbar.toolbarName", "appbario7 ");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3227981&octid=CT3227981&SearchSource=61&CUI=UN98000957190671894&UM=2&UP=SP92F5FF14-06D9-4776-A722-9D1DF10A7193");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultthis.engineName", "appbario7 Customized Web Search");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981&CUI=UN98000957190671894&UM=2&SearchSource=3&q={searchTerms}");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("extensions.ghostery.lsos", "{\"copyright\":\"This proprietary database is protected by copyright, and is owned exclusively by Evidon and all rights to it are expressly reserved. If you are […]
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3227981");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3227981&CUI=UN98000957190671894&UM=2&SearchSource=13,hxxp://search.conduit.com/?ctid=CT3227981&octid=CT3227981&SearchSource[…]
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981&SearchSource=2&CUI=UN98000957190671894&UM=2&q=");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3227981");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3227981");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.machineId", "CKYBJ89AFUEI/SUPAT2UWM42QHWMAZ1KSZV6HITDTPI5PXT5DYFE9T0E5ICMMPIX4V+TAC/YJD3IEQXYR4+LWQ");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.originalHomepage", "about:home");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("CT3227981.smartbar.CTID", "CT3227981");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("CT3227981.smartbar.Uninstall", "0");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("CT3227981.smartbar.homepage", "true");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("CT3227981.smartbar.isHidden", true);
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("CT3227981.smartbar.toolbarName", "appbario7 ");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3227981&octid=CT3227981&SearchSource=61&CUI=UN98000957190671894&UM=2&UP=SP92F5FF14-06D9-4776-A722-9D1DF10A7193");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultthis.engineName", "appbario7 Customized Web Search");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981&CUI=UN98000957190671894&UM=2&SearchSource=3&q={searchTerms}");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("extensions.ghostery.lsos", "{\"copyright\":\"This proprietary database is protected by copyright, and is owned exclusively by Evidon and all rights to it are expressly reserved. If you are […]
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3227981");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3227981&CUI=UN98000957190671894&UM=2&SearchSource=13,hxxp://search.conduit.com/?ctid=CT3227981&octid=CT3227981&SearchSource[…]
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3227981&SearchSource=2&CUI=UN98000957190671894&UM=2&q=");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3227981");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3227981");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.machineId", "CKYBJ89AFUEI/SUPAT2UWM42QHWMAZ1KSZV6HITDTPI5PXT5DYFE9T0E5ICMMPIX4V+TAC/YJD3IEQXYR4+LWQ");
              [18f4bars.default\prefs.js] - Line Deleted : user_pref("smartbar.originalHomepage", "about:home");
               
              -\\ Google Chrome v43.0.2357.124
               
               
              *************************
               
              AdwCleaner[R0].txt - [12837 bytes] - [13/06/2015 16:34:34]
              AdwCleaner[R1].txt - [22226 bytes] - [13/06/2015 16:37:29]
              AdwCleaner[S0].txt - [16013 bytes] - [13/06/2015 16:47:50]
               
              ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16073  bytes] ##########

              :thumbup:

               

              Let me ask you about Malwarebytes, it should show those entries it found as Quarantined and it does not. 

               

              When you set it up did you do this ??

              On the Dashboard under Settings > Advanced setting make sure to checkmark Automatically Quarantine Detected Items

               

               

              After Malwarebytes comes back clean, open up FRST, make sure to checkmark Additions, run a new scan and post both the FRST and Additions logs please

              I did tell it too and did a save log the first time it showed me a save log button. After the save log I clicked finish and it rebooted. More in a bit

              Ask AI

              AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

              Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI