This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Getting High Disk Usage - Host Windows Process

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I frequently get a message stating high disk usage from a Host Windows Process.  Recently, a local office supply store did a free diagnostic and identified an infection, but Power Eraser and NIS did not find it.

 

Thanks!

Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.

  • Perform everything in the correct order. Sometimes one step requires the previous one.

  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.

  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.

  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.

  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.

  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.

  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

 
 
 
 
 
HijackThis is not the preferred initial scanning tool in this forum. With today's malware, a more comprehensive set of logs is required to determine the presence of malware.
 
 
 
 
Scan with FRST in normal mode

Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start –> Computer (right click) –> properties)
 
  • Run FRST.

  • Don´t change one of the checkboxes and hit Scan.

  • Logfiles are created on your desktop.

  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.

 
 
 
 
 Scan with aswMBR

Please download aswMBR ( 4.5MB ) to your desktop.
  • Double click the aswMBR.exe icon, and click Run.

  • There will be a short delay before the next dialog box comes up. Please just wait a minute or two.

  • When asked if you'd like to "download the latest Avast! virus definitions", click Yes.

  • Typically this is about a 100MB download so depending on your connection speed it can take a short while to download and become ready.

  • Click the Scan button to start the scan once the update has finished downloading

  • On completion of the scan, click the save log button, save it to your desktop, then copy and paste it in your next reply.

Note: There will also be a file on your desktop named MBR.dat do not delete this for now. It is an actual backup of the MBR (master boot record).

FRST.txt:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:11-07-2015
Ran by [removed] (administrator) on HUNGARYCREEK-PC on 12-07-2015 10:24:45
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec BioExcess\EgisService.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec BioExcess\EgisDSService.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
(Eastman Kodak Company) C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\nis.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Google Inc.) C:\Users\HCRA\AppData\Local\Google\Update\GoogleUpdate.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec BioExcess\EgisTSR.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Eastman Kodak Company) C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(iSkySoft) C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\nis.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_17_0_0_191_ActiveX.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10821224 2010-06-02] (Realtek Semiconductor)
HKLM\…\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [2598280 2010-03-29] (ELAN Microelectronics Corp.)
HKLM\…\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM\…\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4462496 2010-04-12] (Lenovo(beijing) Limited)
HKLM\…\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [7056800 2010-03-18] (Lenovo (Beijing) Limited)
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\…\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [111640 2009-09-30] ()
HKLM-x32\…\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [536576 2010-01-19] (Vimicro)
HKLM-x32\…\Run: [VitaKeyTSR] => C:\Program Files (x86)\EgisTec BioExcess\EgisTSR.exe [376176 2010-05-27] (Egis Technology Inc. )
HKLM-x32\…\Run: [UCam_Menu] => C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\…\Run: [YouCam Mirror Tray icon] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [171104 2010-03-02] (CyberLink Corp.)
HKLM-x32\…\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-10] (Egis Technology Inc.)
HKLM-x32\…\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-10] (Egis Technology Inc.)
HKLM-x32\…\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\…\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\…\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Nikon Message Center 2] => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [619008 2010-05-25] (Nikon Corporation)
HKLM-x32\…\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\…\Run: [EKStatusMonitor] => C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe [2750840 2013-01-15] (Eastman Kodak Company)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKLM-x32\…\Run: [Conime] => %windir%\system32\conime.exe
HKLM-x32\…\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2014-10-31] (iSkySoft)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1094546129-3094227160-2467561277-1000\…\Run: [Google Update] => C:\Users\HCRA\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-05-19] (Google Inc.)
Lsa: [Notification Packages] scecli EgisPwdFilter EgisDSPwdFilter
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\windows\system32\IcnOvrly.dll [2011-03-18] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

URLSearchHook: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
URLSearchHook: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {1B5C3132-2F3A-4A71-A7E0-B3F5A8C4C605} URL = https://search.yahoo.com/search?fr=mcafee&type=B010US714D20110613&p={SearchTerms}
SearchScopes: HKU\.DEFAULT -> {1B5C3132-2F3A-4A71-A7E0-B3F5A8C4C605} URL = https://search.yahoo.com/search?fr=mcafee&type=B010US714D20110613&p={SearchTerms}
SearchScopes: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000 -> DefaultScope {36933FF7-4EC4-40BD-BBD8-DE121CDCC360} URL = https://search.yahoo.com/search?fr=mcafee&type=B010US714D20110613&p={SearchTerms}
SearchScopes: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000 -> {36933FF7-4EC4-40BD-BBD8-DE121CDCC360} URL = https://search.yahoo.com/search?fr=mcafee&type=B010US714D20110613&p={SearchTerms}
SearchScopes: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000 -> {B96A0315-31C5-4707-A286-76E61C15F79B} URL = https://www.google.com/search?q={searchTerms}
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine64\21.7.0.11\coIEPlg.dll [2015-06-26] (Symantec Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: IEPwdBankBHO Class -> {56CBB761-DA41-4E31-B270-B13B4B0A61D0} -> C:\Program Files (x86)\EgisTec BioExcess\EgisIEPwdBank.dll [2010-05-27] (Egis Technology Inc. )
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\coIEPlg.dll [2015-06-26] (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\IPS\IPSBHO.DLL [2015-03-04] (Symantec Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-07-12] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-12] (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.7.0.11\coIEPlg.dll [2015-06-26] (Symantec Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\coIEPlg.dll [2015-06-26] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.7.0.11\coIEPlg.dll [2015-06-26] (Symantec Corporation)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-07-03] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-07-03] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-07-03] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-07-03] (McAfee, Inc.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Handler: WSISVCUchrome - No CLSID Value
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{BE04198F-BD96-42B5-823E-ED649CE3F93E}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_17_0_0_191.dll [2015-07-09] ()
FF Plugin: @bestbuy.com/npBestBuyPcAppDetector,version=1.0 -> C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_191.dll [2015-07-09] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-12] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-12] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-24] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-24] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1094546129-3094227160-2467561277-1000: @tools.google.com/Google Update;version=3 -> C:\Users\HCRA\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-24] (Google Inc.)
FF Plugin HKU\S-1-5-21-1094546129-3094227160-2467561277-1000: @tools.google.com/Google Update;version=9 -> C:\Users\HCRA\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-24] (Google Inc.)
FF HKLM\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee WebAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-03-18]
FF HKLM-x32\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.4.0.13\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.4.0.13\coFFPlgn [2015-07-11]

Chrome:
=======
CHR Profile: C:\Users\HCRA\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Norton Identity Safe) - C:\Users\HCRA\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2014-08-20]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\HCRA\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-29]
CHR Extension: (Google Wallet) - C:\Users\HCRA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-04]
CHR HKLM\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-07-06]
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\Exts\Chrome.crx [2015-03-28]
CHR HKLM-x32\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-07-06]
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM-x32\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\Exts\Chrome.crx [2015-03-28]
StartMenuInternet: Google Chrome - C:\Users\HCRA\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 EgisTec Data Security Service; C:\Program Files (x86)\EgisTec BioExcess\EgisDSService.exe [314736 2010-05-27] (Egis Technology Inc. )
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [1435680 2014-01-10] (Fitbit, Inc.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 McAfee SiteAdvisor Service; c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [155368 2015-07-03] (McAfee, Inc.)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\NIS.exe [276336 2015-03-07] (Symantec Corporation)
S2 RtLedService; C:\Program Files\Realtek\RtLED\RtLEDService.exe [311296 2010-02-05] (Realtek Semiconductor Corp.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.4.0.13\Definitions\BASHDefs\20150706.001\BHDrvx64.sys [1648880 2015-06-16] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1507000.00B\ccSetx64.sys [162392 2014-02-20] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [489776 2015-05-27] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [153936 2015-06-24] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.4.0.13\Definitions\IPSDefs\20150710.001\IDSvia64.sys [692984 2015-06-21] (Symantec Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.4.0.13\Definitions\VirusDefs\20150711.004\ENG64.SYS [138488 2015-06-23] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.4.0.13\Definitions\VirusDefs\20150711.004\EX64.SYS [2146040 2015-06-23] (Symantec Corporation)
S3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [416768 2009-06-10] (Realtek Semiconductor Corporation                           )
R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1507000.00B\SRTSP64.SYS [876248 2014-08-25] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1507000.00B\SRTSPX64.SYS [37592 2014-08-25] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1507000.00B\SYMDS64.SYS [493656 2013-10-30] (Symantec Corporation)
S3 SymDSMon; C:\windows\system32\drivers\SymDSMon.sys [191232 2010-11-30] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1507000.00B\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-07-18] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1507000.00B\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1507000.00B\SYMNETS.SYS [593112 2014-02-17] (Symantec Corporation)
S3 SYMSpeedDisk; C:\windows\system32\drivers\SymSpeedDisk.sys [163384 2010-11-30] (Symantec Corporation)
S3 SYMSpeedDisk; C:\windows\SysWOW64\drivers\SymSpeedDisk.sys [108800 2010-11-30] (Symantec Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-12 10:24 - 2015-07-12 10:25 - 00025639 _____ C:\Users\HCRA\Desktop\FRST.txt
2015-07-12 10:24 - 2015-07-12 10:24 - 00000000 ____D C:\FRST
2015-07-12 10:22 - 2015-07-12 10:22 - 02130944 _____ (Farbar) C:\Users\HCRA\Desktop\FRST64.exe
2015-07-12 00:13 - 2015-07-12 00:11 - 00097888 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2015-07-12 00:12 - 2015-07-12 00:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-07-12 00:06 - 2015-07-12 00:06 - 00562272 _____ (Oracle Corporation) C:\Users\HCRA\Downloads\chromeinstall-8u45.exe
2015-07-11 23:17 - 2015-07-11 23:18 - 03088296 _____ (Symantec Corporation) C:\Users\HCRA\Downloads\NPE.exe
2015-07-02 19:09 - 2015-07-02 19:09 - 00003288 ____N C:\bootsqm.dat
2015-07-02 19:02 - 2015-07-02 19:02 - 00000000 __SHD C:\found.008
2015-07-02 00:26 - 2015-07-02 00:26 - 22777856 _____ C:\Users\HCRA\Downloads\MeetResults (1).mdb
2015-06-30 18:26 - 2015-06-30 18:26 - 00029051 _____ C:\Users\HCRA\Downloads\CRR-VA-Entries-Church Run at Hungary  Creek-01Jul2015-003.ZIP
2015-06-30 18:26 - 2015-06-30 18:26 - 00009360 _____ C:\Users\HCRA\Downloads\CRR Metr-S.REC
2015-06-24 23:57 - 2015-06-24 23:57 - 22777856 _____ C:\Users\HCRA\Downloads\MeetResults.mdb
2015-06-24 07:54 - 2015-06-24 07:54 - 00000000 ____D C:\Users\HCRA\Desktop\Attachments_2015624
2015-06-24 07:53 - 2015-06-24 07:53 - 00037453 _____ C:\Users\HCRA\Desktop\Attachments_2015624.zip
2015-06-23 20:43 - 2015-06-23 20:44 - 00585728 _____ C:\Users\HCRA\Downloads\D1-0624_Twin_Hickory_at_Hungary_Creek.mdb
2015-06-22 23:18 - 2015-07-06 23:31 - 04755456 _____ C:\Users\HCRA\Downloads\EntryCards.mdb
2015-06-17 13:03 - 2015-06-17 13:03 - 00002387 _____ C:\Users\HCRA\Desktop\ctrlcenter PC Checkup and Tuneup ScanReport.lnk
2015-06-17 12:40 - 2015-06-17 13:03 - 00000000 ____D C:\Users\HCRA\Documents\ctrlcenter PC Checkup and Tuneup
2015-06-17 12:32 - 2015-06-17 12:32 - 00000000 ____D C:\Users\HCRA\AppData\Roaming\QuickScan
2015-06-17 12:30 - 2015-06-17 12:30 - 00000000 ____D C:\temp
2015-06-17 12:28 - 2015-06-17 12:28 - 07750336 _____ C:\Users\HCRA\Downloads\CtrlCenterPCHC (1).exe
2015-06-17 12:27 - 2015-06-17 12:28 - 07750336 _____ C:\Users\HCRA\Downloads\CtrlCenterPCHC.exe
2015-06-12 19:35 - 2015-06-12 19:35 - 00000000 ____D C:\Users\HCRA\AppData\Local\GWX

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-12 10:25 - 2014-10-05 10:57 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-12 10:17 - 2009-07-14 00:45 - 00022464 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-12 10:17 - 2009-07-14 00:45 - 00022464 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-12 10:11 - 2014-10-05 10:57 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-12 10:11 - 2012-05-19 20:58 - 00000904 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1094546129-3094227160-2467561277-1000UA.job
2015-07-12 10:10 - 2015-04-02 22:26 - 00750673 _____ C:\FaceProv.log
2015-07-12 10:10 - 2012-05-19 20:58 - 00000852 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1094546129-3094227160-2467561277-1000Core.job
2015-07-12 10:10 - 2012-04-02 20:06 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2015-07-12 10:10 - 2011-03-18 00:30 - 01258545 _____ C:\windows\WindowsUpdate.log
2015-07-12 00:11 - 2013-11-14 19:59 - 00000000 ____D C:\ProgramData\Oracle
2015-07-12 00:11 - 2013-07-03 21:10 - 00000000 ____D C:\Program Files (x86)\Java
2015-07-12 00:08 - 2014-11-23 20:42 - 00000000 ____D C:\Users\HCRA\AppData\Local\NPE
2015-07-11 23:39 - 2014-11-23 21:40 - 00000000 ____D C:\NPE
2015-07-11 23:38 - 2013-01-05 20:00 - 00000000 ____D C:\ProgramData\Kodak
2015-07-11 23:38 - 2009-07-14 01:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-07-11 23:37 - 2009-07-14 00:51 - 00095667 _____ C:\windows\setupact.log
2015-07-09 01:43 - 2015-05-25 08:31 - 00000000 ____D C:\Users\HCRA\Documents\2015 Swim Season
2015-07-09 01:10 - 2012-04-02 20:06 - 00778416 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-07-09 01:10 - 2012-04-02 20:06 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-07-09 01:10 - 2012-01-21 15:17 - 00142512 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-09 00:45 - 2014-05-13 19:47 - 00000000 ____D C:\swmeets5
2015-07-09 00:05 - 2011-06-14 05:38 - 00661276 _____ C:\windows\PFRO.log
2015-07-07 19:01 - 2014-11-19 22:05 - 00000258 _____ C:\windows\Tasks\NUSchedule.job
2015-07-07 19:01 - 2011-03-18 01:20 - 00000000 ____D C:\ProgramData\Temp
2015-07-07 18:31 - 2013-05-21 20:52 - 00000000 ____D C:\entrycards
2015-07-02 01:23 - 2014-05-13 20:02 - 00000000 ____D C:\MeetReports
2015-07-02 00:22 - 2013-05-21 20:54 - 00000000 ____D C:\meet results
2015-06-29 23:20 - 2009-07-14 01:13 - 00795858 _____ C:\windows\system32\PerfStringBackup.INI
2015-06-27 11:00 - 2009-07-13 23:20 - 00000000 ____D C:\windows\system32\NDF
2015-06-25 00:30 - 2012-05-20 20:48 - 00000000 ____D C:\TM5Data
2015-06-22 23:13 - 2009-07-14 01:08 - 00032648 _____ C:\windows\Tasks\SCHEDLGU.TXT
2015-06-18 00:13 - 2013-06-20 00:34 - 00000000 ____D C:\tempMM
2015-06-14 16:29 - 2014-11-24 20:06 - 00000000 __SHD C:\Users\HCRA\AppData\Local\EmieBrowserModeList
2015-06-14 16:29 - 2014-05-15 21:01 - 00000000 __SHD C:\Users\HCRA\AppData\Local\EmieUserList
2015-06-14 16:29 - 2014-05-15 21:01 - 00000000 __SHD C:\Users\HCRA\AppData\Local\EmieSiteList
2015-06-12 21:04 - 2009-07-13 23:20 - 00000000 ____D C:\windows\rescache
2015-06-12 19:35 - 2009-07-14 01:09 - 00000000 ____D C:\windows\System32\Tasks\WPD
2015-06-12 18:47 - 2009-07-14 00:45 - 00415448 _____ C:\windows\system32\FNTCACHE.DAT
2015-06-12 18:42 - 2009-07-13 23:20 - 00000000 ____D C:\windows\PolicyDefinitions
2015-06-12 18:36 - 2011-06-13 10:23 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-12 18:29 - 2013-08-28 20:48 - 00000000 ____D C:\windows\system32\MRT
2015-06-12 18:07 - 2011-06-15 08:34 - 140135120 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe

==================== Files in the root of some directories =======

2013-05-13 20:58 - 2013-05-13 20:58 - 0000268 ___RH () C:\Users\HCRA\AppData\Roaming\Halftone
2013-05-13 20:58 - 2013-05-13 20:58 - 0000268 ___RH () C:\Users\HCRA\AppData\Roaming\Help
2013-05-13 20:58 - 2013-05-13 20:58 - 0000268 ___RH () C:\Users\HCRA\AppData\Roaming\Helper Scripts
2013-01-05 20:09 - 2013-01-05 20:09 - 0000236 _____ () C:\Users\HCRA\AppData\Local\LaunchHomeCenter.log
2013-05-13 20:58 - 2013-05-13 20:58 - 0000268 ___RH () C:\ProgramData\Home
2013-05-13 20:58 - 2013-05-13 20:58 - 0000268 ___RH () C:\ProgramData\HomePageService
2013-05-13 20:58 - 2013-05-13 20:58 - 0000268 ___RH () C:\ProgramData\Horn Section
2013-05-13 20:58 - 2013-05-13 20:58 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
2013-05-13 20:58 - 2014-07-18 20:16 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT
2013-05-13 20:58 - 2013-05-13 21:06 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-06-17 13:23

==================== End of log ============================

Addition.txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:11-07-2015
Ran by [removed] at 2015-07-12 10:26:03
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-1094546129-3094227160-2467561277-500 - Administrator - Disabled)
ASPNET (S-1-5-21-1094546129-3094227160-2467561277-1004 - Limited - Enabled)
Guest (S-1-5-21-1094546129-3094227160-2467561277-501 - Limited - Disabled)
HCRA (S-1-5-21-1094546129-3094227160-2467561277-1000 - Administrator - Enabled) => C:\Users\HCRA
HomeGroupUser$ (S-1-5-21-1094546129-3094227160-2467561277-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Internet Security (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton Internet Security (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acrobat.com (HKLM-x32\…\{77DCDCE3-2DED-62F3-8154-05E745472D07}) (Version: 1.1.377 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe Flash Player 17 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 17.0.0.191 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 17.0.0.191 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
aioscnnr (x32 Version: 7.6.13.10 - Your Company Name) Hidden
Apple Application Support (HKLM-x32\…\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft Panorama Maker 5 (HKLM-x32\…\{F18046C5-1C4E-4BE1-A3D6-A6F970E2E8E8}) (Version: 5.0.1.25 - ArcSoft)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\…\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.26 - Atheros Communications Inc.)
Best Buy pc app (HKU\S-1-5-21-1094546129-3094227160-2467561277-1000\…\48e4cff94f039634) (Version: 3.2.523.2 - Best Buy)
Best Buy pc app (Version: 3.1.1.0 - Best Buy) Hidden
Best Buy pc app (x32 Version: 3.1.1.0 - Best Buy) Hidden
Bing Bar (HKLM-x32\…\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
BioExcess (HKLM-x32\…\InstallShield_{ACF31D9F-70C2-40A1-9C7A-28BA16E64B56}) (Version: 6.0.48.175 - Egis Technology Inc.)
BioExcess (x32 Version: 6.0.48.175 - Egis Technology Inc.) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
C4USelfUpdater (x32 Version: 1.00.0000 - Your Company Name) Hidden
center (x32 Version: 7.7.2.0 - Eastman Kodak Company) Hidden
Comic Life 2 (HKLM-x32\…\{A8405D99-9D76-4456-8752-87DA930CC3A3}) (Version: 2.2.7.0 - plasq LLC)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2626 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Management (HKLM-x32\…\{0CE226F3-EB27-4ECD-BBF5-F088716779FD}) (Version: 5.4.1.9 - Lenovo)
essentials (x32 Version: 7.7.2.0 - Eastman Kodak Company) Hidden
ETDWare PS/2-x64 7.0.4.17_WHQL (HKLM\…\Elantech) (Version: 7.0.4.17 - ELAN Microelectronics Corp.)
Fitbit Connect (HKLM-x32\…\{6A7C2B2E-36A3-4EF5-96C6-708CD090A3AD}) (Version: 1.0.1.5127 - Fitbit Inc.)
Google Chrome (HKU\S-1-5-21-1094546129-3094227160-2467561277-1000\…\Google Chrome) (Version: 43.0.2357.132 - Google Inc.)
Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
HL-2270DW (HKLM-x32\…\{E2A97415-BD97-4867-B906-05E39E9EE51F}) (Version: 1.0.6.0 - Brother Industries, Ltd.)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2189 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.0.1014 - Intel Corporation)
iTunes (HKLM\…\{77DE5105-D05E-448C-96CB-7FA381903753}) (Version: 11.3.1.2 - Apple Inc.)
Java 8 Update 45 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kodak AIO Printer (Version: 7.7.2.0 - Eastman Kodak Company) Hidden
KODAK AiO Software (HKLM-x32\…\{E0F274B7-592B-4669-8FB8-8D9825A09858}) (Version: 7.7.6.0 - Eastman Kodak Company)
Lenovo EasyCamera (HKLM-x32\…\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0333}) (Version: 1.10.0510.01 - Lenovo EasyCamera)
Lenovo OneKey Recovery (HKLM-x32\…\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.1628 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 7.0.1628 - CyberLink Corp.) Hidden
Lenovo Security Suite (HKLM-x32\…\InstallShield_{0034859F-8E01-4C1D-BE77-F891C4786FBC}) (Version: 2.0.10.0 - Lenovo)
Lenovo Security Suite (x32 Version: 2.0.10.0 - Lenovo) Hidden
Lenovo_Wireless_Driver (HKLM-x32\…\{28ABE740-47F3-441B-9437-852F6A64EFF8}) (Version: 1.02.01 - Lenovo)
McAfee SiteAdvisor (HKLM\…\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.0.1.165 - McAfee, Inc.)
McAfee WebAdvisor (HKLM-x32\…\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.354 - McAfee, Inc.)
Meet Manager 5.0 for Swimming (HKLM-x32\…\{DE162A1B-E49F-4092-9A0D-D5AE2753C31E}) (Version: 1.00.0007 - Active Network)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 1.1 (HKLM-x32\…\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.5.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Access Runtime (English) 2007 (HKLM-x32\…\{90120000-001C-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\…\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nikon Message Center 2 (HKLM-x32\…\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.0.1 - Nikon)
Norton Internet Security (HKLM-x32\…\NIS) (Version: 21.7.0.11 - Symantec Corporation)
Norton Utilities 15 (HKLM-x32\…\Norton Utilities 15_is1) (Version: 15.0 - Symantec Corporation)
ocr (x32 Version: 6.2.3.50 - Eastman Kodak Company) Hidden
Picture Control Utility (HKLM-x32\…\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.2.2 - Nikon)
Pixie 2 (HKLM-x32\…\Pixie 2) (Version:  - )
Power2Go (HKLM-x32\…\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.4809d4 - CyberLink Corp.)
PreReq (x32 Version: 6.2.3.0 - Eastman Kodak Company) Hidden
PrintProjects (HKLM-x32\…\PrintProjects) (Version: 1.0.0.9282 - RocketLife Inc.)
QuickTime 7 (HKLM-x32\…\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6128 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30117 - Realtek Semiconductor Corp.)
RtLED (HKLM\…\{5ACF5427-B4E4-4F85-A512-151E0BECF7E3}) (Version: 1.0.2 - Realtek Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Sid Meier's Civilization 4 Gold (HKLM-x32\…\{55502C49-F061-428C-BF26-06ECDFB3AC29}) (Version: 1.72 - Firaxis Games)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SPORE™ Creature Creator Trial Edition (HKLM-x32\…\{ECEE0279-785F-4CB3-9F28-E69813234BF8}) (Version: 1.00.0000 - Electronic Arts)
TEAM MANAGER 6.0 for Swimming (HKLM-x32\…\{9650DF15-A909-4FE3-AE28-F1909356AD27}) (Version: 1.00.0002 - HY-TEK Sports Software)
VeriFace (HKLM-x32\…\VeriFace) (Version: 3.6.1.0226 - Lenovo)
ViewNX 2 (HKLM-x32\…\{DDD62492-32A7-412B-8AF1-2CF032AD42E3}) (Version: 2.1.2 - Nikon)
Windows Driver Package - Lenovo (ACPIVPC) System  (10/19/2009 5.4.0.1) (HKLM\…\0A4175B489A1B4A6E07E11B063A6263480C51D71) (Version: 10/19/2009 5.4.0.1 - Lenovo)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\HCRA\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> No File path
CustomCLSID: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\HCRA\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\HCRA\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> No File path

==================== Restore Points =========================

22-05-2015 21:49:31 Windows Update
25-05-2015 08:33:05 Windows Update
07-06-2015 18:54:18 Windows Update
12-06-2015 17:54:45 Windows Update
12-07-2015 00:02:22 Removed Java 7 Update 60
12-07-2015 00:03:50 Removed Java 7 Update 60

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {32F22CFF-5409-45C6-AEF6-CC0AA23F8D0F} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {368FFC39-51D5-4056-9192-7BF573878A0F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-05] (Google Inc.)
Task: {3F5F98CA-DB89-4F39-8AEA-8F2848E713DC} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\WSCStub.exe [2015-06-16] (Symantec Corporation)
Task: {5D3FD5D9-8F87-48C2-8E60-4B9A7C814C46} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1094546129-3094227160-2467561277-1000UA => C:\Users\HCRA\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-19] (Google Inc.)
Task: {6E624A89-64BF-4C0D-A1F2-95A612AE5674} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-09] (Adobe Systems Incorporated)
Task: {8556506A-2F8D-4258-AA28-9EBC75191A5A} - System32\Tasks\NUSchedule => C:\Program Files (x86)\Norton Utilities 15\nu.exe [2014-09-17] (Symantec Corporation)
Task: {A402FF6D-797C-4829-BCBD-3283CF6A6D0A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-05] (Google Inc.)
Task: {C1615392-2744-493E-91E0-73B093F68E40} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1094546129-3094227160-2467561277-1000Core => C:\Users\HCRA\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-19] (Google Inc.)
Task: {D640B05F-2150-4B76-A5AD-C94C075E9B0C} - System32\Tasks\{C582B347-BB35-48C9-BA96-B605A1A38E42} => pcalua.exe -a C:\Users\HCRA\Downloads\792248d6ad421d577132c2b648bbed45_scc_trial_na.exe -d C:\Users\HCRA\Downloads
Task: {DDBBB2FC-0011-4443-9CE7-82B26EAC416F} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {F632C85C-BA9D-48DE-8661-A7C6780903DA} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1094546129-3094227160-2467561277-1000Core.job => C:\Users\HCRA\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1094546129-3094227160-2467561277-1000UA.job => C:\Users\HCRA\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\NUSchedule.job => C:\Program Files (x86)\Norton Utilities 15\nu.exe

==================== Loaded Modules (Whitelisted) ==============

2010-05-27 23:15 - 2010-05-27 23:15 - 01407344 _____ () C:\Program Files (x86)\EgisTec BioExcess\x64\LIBEAY32.dll
2011-03-18 01:19 - 2011-03-18 01:19 - 01502720 _____ () C:\windows\system32\IcnOvrly.dll
2011-03-18 01:29 - 2009-07-15 11:55 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2011-03-18 01:29 - 2009-07-15 11:55 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-06-15 08:40 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2015-04-26 21:00 - 2014-10-31 16:40 - 01498112 _____ () C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\DAQExp.dll
2015-04-26 21:00 - 2014-05-19 17:19 - 00137728 _____ () C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\CBSCreateVC.dll
2014-10-17 07:37 - 2014-10-17 07:37 - 00170496 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\3d576cbc4ffc5ad06fd61510c5d8f326\IsdiInterop.ni.dll
2011-03-18 00:39 - 2010-03-03 16:08 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:D287FACF
AlternateDataStreams: C:\ProgramData\Temp:D3A96964

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMR430 => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1094546129-3094227160-2467561277-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\HCRA\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Fitbit Connect => "C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: VeriFaceManager => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{920C3173-B101-40CA-83F2-A82ED21AAE81}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{82C0D50F-BD6A-4FDD-BEB4-935371359F0E}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{2E9261D9-B1A0-4FBC-8F8B-53C4E7FCC2E9}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{66B81735-767B-4F43-9556-8854148F0FA3}] => (Allow) LPort=2869
FirewallRules: [{19A3F93C-6A1B-43F1-83BF-84BA6CB9835C}] => (Allow) LPort=1900
FirewallRules: [{D4DE0BB4-162D-4440-84B2-C70A9B4B96D0}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{EAE5903A-C51E-4105-BA4C-77024C9C0495}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{7D6C5774-F520-4AA1-8493-8ADC5A2487DD}] => (Allow) C:\Program Files (x86)\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe
FirewallRules: [{6050B038-3AA8-44DE-9F9D-65D0E2A26F20}] => (Allow) C:\Program Files (x86)\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Civilization4.exe
FirewallRules: [{3CCA52CD-A584-4838-96D6-CC25487FFBD1}] => (Allow) C:\Program Files (x86)\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe
FirewallRules: [{D92E3039-8AF7-40C4-A6F6-7753341D7B1A}] => (Allow) C:\Program Files (x86)\2K Games\Firaxis Games\Sid Meier's Civilization 4 Gold\Warlords\Civ4Warlords.exe
FirewallRules: [{EE27D1D8-721E-481D-A8D5-94088615ACAF}] => (Allow) LPort=5353
FirewallRules: [{BA5E180D-3253-4081-AAB1-792819C207A0}] => (Allow) LPort=9322
FirewallRules: [{12EB0045-903E-40D2-8016-0F4511CBA13D}] => (Allow) LPort=5353
FirewallRules: [{A3D0694F-8677-4065-A60E-1C7C93868835}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0A725C9E-63FE-474A-B566-86076A779537}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{656814A7-C414-427B-9FF9-F182186B3301}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6EEDBF15-B700-472D-B20F-842AAC869812}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{7E53AFB9-D48A-4EF4-9830-E628F8EAA90E}] => (Allow) LPort=9322
FirewallRules: [{9739A669-D609-404F-98B0-85F8015CB14F}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe
FirewallRules: [{5E82E260-35B8-4199-BC49-11BE1F44FD65}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe
FirewallRules: [{1E1EA36B-ED04-47FB-8AE2-D7F635D437DA}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe
FirewallRules: [{ECD84BBA-FBCB-4A7A-A91F-60F592FAC041}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe
FirewallRules: [{C6988ECF-2F50-4EA5-A0C8-BE16428451D6}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe
FirewallRules: [{68051F3C-4BE6-486D-86B0-E6ED3B124CA7}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe
FirewallRules: [{233192A1-B33B-4B3A-81D1-5D58D18AF3CD}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe
FirewallRules: [{DDF3EDBB-6C70-4607-97C8-7DBD245FA59B}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe
FirewallRules: [{22C358F2-57EE-40AE-88AD-B3906ABD6588}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe
FirewallRules: [{6B5AA5BC-9B3A-4E7F-8F14-AE223D34B9E3}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe
FirewallRules: [{4B3AB4F8-E4FF-4443-9856-1AC35EFA1F49}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{4D5BE47E-668D-4483-9885-B8F5AA619680}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
==================
Error: (07/12/2015 10:10:44 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: EKAiOHostService.exe, version: 7.6.10.0, time stamp: 0x5049625e
Faulting module name: EKAiOHostService.exe, version: 7.6.10.0, time stamp: 0x5049625e
Exception code: 0xc0000005
Fault offset: 0x0000b6b2
Faulting process id: 0x404
Faulting application start time: 0xEKAiOHostService.exe0
Faulting application path: EKAiOHostService.exe1
Faulting module path: EKAiOHostService.exe2
Report Id: EKAiOHostService.exe3

Error: (07/12/2015 10:10:39 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: EKAiOHostService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: exception code c0000005, exception address 0040B6B2

Error: (07/12/2015 10:09:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 35151767

Error: (07/12/2015 10:09:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 35151767

Error: (07/12/2015 10:09:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (07/11/2015 10:52:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NIS.exe, version: 12.11.4.4, time stamp: 0x53f531a0
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00000000
Faulting process id: 0xbd8
Faulting application start time: 0xNIS.exe0
Faulting application path: NIS.exe1
Faulting module path: NIS.exe2
Report Id: NIS.exe3

Error: (07/11/2015 10:32:15 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   23 [removed].in-addr.arpa. PTR HungaryCreek-PC.local.

Error: (07/11/2015 10:32:15 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.5:5353   25 [removed].in-addr.arpa. PTR HungaryCreek-PC-2.local.

Error: (07/09/2015 12:07:47 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   23 [removed].in-addr.arpa. PTR HungaryCreek-PC.local.

Error: (07/09/2015 12:07:47 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.5:5353   25 [removed].in-addr.arpa. PTR HungaryCreek-PC-2.local.

System errors:
=============
Error: (07/12/2015 10:26:41 AM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer HOMEPC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{BE04198F-BD96-42B5-823E-ED649CE3F93E}.
The master browser is stopping or an election is being forced.

Error: (07/12/2015 10:14:39 AM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer HOMEPC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{BE04198F-BD96-42B5-823E-ED649CE3F93E}.
The master browser is stopping or an election is being forced.

Error: (07/12/2015 10:11:24 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Kodak AiO Network Discovery Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (07/11/2015 11:40:12 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP      :1d" could not be registered on the interface with IP address 192.168.1.5.
The computer with the IP address 192.168.1.4 did not allow the name to be claimed by
this computer.

Error: (07/11/2015 11:39:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RtLedService Installer service failed to start due to the following error:
%%1053

Error: (07/11/2015 11:39:13 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the RtLedService Installer service to connect.

Error: (07/11/2015 11:32:56 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The NPEService service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Error: (07/11/2015 11:32:55 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer HOMEPC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{BE04198F-BD96-42B5-823E-ED649CE3F93E}.
The master browser is stopping or an election is being forced.

Error: (07/11/2015 10:56:58 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer HOMEPC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{BE04198F-BD96-42B5-823E-ED649CE3F93E}.
The master browser is stopping or an election is being forced.

Error: (07/11/2015 10:44:57 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer HOMEPC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{BE04198F-BD96-42B5-823E-ED649CE3F93E}.
The master browser is stopping or an election is being forced.

Microsoft Office:
=========================
Error: (07/12/2015 10:10:44 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: EKAiOHostService.exe7.6.10.05049625eEKAiOHostService.exe7.6.10.05049625ec00000050000b6b240401d0bc5433747ba4C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exeC:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exec8af6880-289f-11e5-a3c3-f0def14c0816

Error: (07/12/2015 10:10:39 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: EKAiOHostService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: exception code c0000005, exception address 0040B6B2

Error: (07/12/2015 10:09:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 35151767

Error: (07/12/2015 10:09:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 35151767

Error: (07/12/2015 10:09:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (07/11/2015 10:52:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: NIS.exe12.11.4.453f531a0unknown0.0.0.000000000c000000500000000bd801d0bc4b233f9ae1C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\NIS.exeunknownfa0fc755-2840-11e5-8de2-f0def14c0816

Error: (07/11/2015 10:32:15 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   23 [removed].in-addr.arpa. PTR HungaryCreek-PC.local.

Error: (07/11/2015 10:32:15 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.5:5353   25 [removed].in-addr.arpa. PTR HungaryCreek-PC-2.local.

Error: (07/09/2015 12:07:47 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   23 [removed].in-addr.arpa. PTR HungaryCreek-PC.local.

Error: (07/09/2015 12:07:47 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.5:5353   25 [removed].in-addr.arpa. PTR HungaryCreek-PC-2.local.

CodeIntegrity Errors:
===================================
  Date: 2014-05-14 20:59:14.817
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-05-14 20:59:14.583
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Processor: Intel(R) Pentium(R) CPU P6200 @ 2.13GHz
Percentage of memory in use: 77%
Total physical RAM: 1844.51 MB
Available physical RAM: 415.84 MB
Total Virtual: 3689.02 MB
Available Virtual: 1857.08 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:254.14 GB) (Free:179.86 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:19.92 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 6D43DF16)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=254.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=14.8 GB) - (Type=12)

==================== End of log ============================

aswmbr log:

 

aswMBR version 1.0.1.2290 Copyright© 2014 AVAST Software
Run date: 2015-07-12 10:32:52
—————————–
10:32:52.498    OS Version: Windows x64 6.1.7601 Service Pack 1
10:32:52.498    Number of processors: 2 586 0x2505
10:32:52.498    ComputerName: HUNGARYCREEK-PC  UserName: HCRA
10:32:55.072    Initialize success
10:32:55.306    VM: initialized successfully
10:32:55.306    VM: Intel CPU virtualization not supported
10:35:08.251    AVAST engine defs: 15071101
10:36:01.494    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
10:36:01.494    Disk 0 Vendor: WDC_WD32 02.0 Size: 305245MB BusType: 3
10:36:01.666    Disk 0 MBR read successfully
10:36:01.681    Disk 0 MBR scan
10:36:01.775    Disk 0 Windows 7 default MBR code
10:36:01.790    Disk 0 Partition 1 80 (A) 07      HPFS/NTFS NTFS          200 MB offset 2048
10:36:01.837    Disk 0 default boot code
10:36:01.853    Disk 0 Partition 2 00     07      HPFS/NTFS NTFS       260243 MB offset 411648
10:36:01.868    Disk 0 Partition - 00     0F   Extended LBA             29692 MB offset 533389312
10:36:01.900    Disk 0 Partition 3 00     12    Compaq diag NTFS        15109 MB offset 594198528
10:36:01.931    Disk 0 Partition 4 00     07      HPFS/NTFS NTFS        29691 MB offset 533391360
10:36:02.180    Disk 0 scanning C:\windows\system32\drivers
10:36:16.238    Service scanning
10:36:20.762    Service BHDrvx64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.4.0.13\Definitions\BASHDefs\20150706.001\BHDrvx64.sys **LOCKED** 5
10:36:24.896    Service eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys **LOCKED** 5
10:36:25.661    Service EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys **LOCKED** 5
10:36:28.999    Service IDSVia64 C:\Program Files (x86)\Norton Internet Security\NortonData\21.4.0.13\Definitions\IPSDefs\20150710.001\IDSvia64.sys **LOCKED** 5
10:36:33.570    Service NAVENG C:\Program Files (x86)\Norton Internet Security\NortonData\21.4.0.13\Definitions\VirusDefs\20150711.004\ENG64.SYS **LOCKED** 5
10:36:33.757    Service NAVEX15 C:\Program Files (x86)\Norton Internet Security\NortonData\21.4.0.13\Definitions\VirusDefs\20150711.004\EX64.SYS **LOCKED** 5
10:36:50.062    Modules scanning
10:36:50.077    Disk 0 trace - called modules:
10:36:50.093    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
10:36:50.108    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80025b2790]
10:36:50.108    3 CLASSPNP.SYS[fffff8800127343f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8002431050]
10:36:51.746    AVAST engine scan C:\windows
10:37:00.061    AVAST engine scan C:\windows\system32
10:41:38.410    AVAST engine scan C:\windows\system32\drivers
10:41:53.386    AVAST engine scan C:\Users\HCRA
10:48:06.739    AVAST engine scan C:\ProgramData
10:53:26.282    Disk 0 statistics 5798115/0/0 @ 3.96 MB/s
10:53:26.297    Scan finished successfully
10:55:00.758    Disk 0 MBR has been saved successfully to "C:\Users\HCRA\Documents\MBR.dat"
10:55:00.774    The log file has been saved successfully to "C:\Users\HCRA\Documents\aswMBR.txt"

 

I have moved the txt log and the MBR.dat files to the desktop.
 

Fix with FRST (normal mode)

WARNING: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 

  • Download the attached fixlist.txt and save it to the location where FRST is saved to.
  • Run FRST.exe (on 64bit, run FRST64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.

 

 

 

 

Full System Scan with Malwarebytes Antimalware
 

  • If not existing, please download Malwarebytes Anti-Malware to your desktop.
  • Double-click the downloaded setup file and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish.

If the program is already installed:

  • Run Malwarebytes Antimalware
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.

 

Attachments:

Fix result of Farbar Recovery Scan Tool (x64) Version:13-07-2015
Ran by [removed] at 2015-07-13 18:39:40 Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
AlternateDataStreams: C:\ProgramData\Temp:D287FACF
AlternateDataStreams: C:\ProgramData\Temp:D3A96964
CustomCLSID: HKU\S-1-5-21-1094546129-3094227160-2467561277-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> No File path

EmptyTemp:
Reboot:

*****************

C:\ProgramData\Temp => ":D287FACF" ADS removed successfully.
C:\ProgramData\Temp => ":D3A96964" ADS removed successfully.
"HKU\S-1-5-21-1094546129-3094227160-2467561277-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}" => key removed successfully
EmptyTemp: => 706.6 MB temporary data Removed.

The system needed a reboot..

==== End of Fixlog 18:41:07 ====

 

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/13/2015
Scan Time: 7:10 PM
Logfile:
Administrator: Yes

Version: 2.1.8.1057
Malware Database: v2015.07.13.06
Rootkit Database: v2015.07.10.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: HCRA

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 373935
Time Elapsed: 31 min, 17 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)

(end)

Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked

  • Click on Advanced Settings and ensure these options are ticked:
      Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.

Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe

  • Hit Scan and wait for the scan to finish.

  • Confirm the message but don´t uncheck anything.

  • Hit Clean

  • When the run is finished, it will open up a text file

  • Please post its contents within your next reply

  • You´ll find the log file at C:\AdwCleaner[S1].txt also




Delete junk with JRT

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.

  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".

  • The tool will open and start scanning your system.

  • Please be patient as this can take a while to complete depending on your system's specifications.

  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

  • Post the contents of JRT.txt into your next message.




SecurityCheck

Reboot your system before starting!

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.

  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.

# AdwCleaner v4.208 - Logfile created 16/07/2015 at 21:48:47
# Updated 09/07/2015 by Xplode
# Database : 2015-07-15.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : HCRA - HUNGARYCREEK-PC
# Running from : C:\Users\HCRA\Desktop\adwcleaner_4.208.exe
# Option : Cleaning

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\Users\HCRA\AppData\Roaming\download Manager

***** [ Scheduled tasks ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\120DFADEB50841F408F04D2A278F9509
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17840

-\\ Google Chrome v

[C:\Users\HCRA\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\HCRA\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

*************************

AdwCleaner[R0].txt - [1420 bytes] - [16/07/2015 21:43:11]
AdwCleaner[S0].txt - [1353 bytes] - [16/07/2015 21:48:47]

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.1 (07.16.2015:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on Thu 07/16/2015 at 22:12:25.70
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

~~~ Services

 

~~~ Tasks

Successfully deleted: [Task] C:\windows\system32\tasks\NUSchedule
Successfully deleted: [Task] C:\windows\Tasks\NUSchedule.job

 

~~~ Registry Values

 

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{36933FF7-4EC4-40BD-BBD8-DE121CDCC360}

 

~~~ Files

 

~~~ Folders

 

~~~ Chrome

[C:\Users\HCRA\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\HCRA\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\HCRA\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\HCRA\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
  aaaaojmikegpiepcfdkkjaplodkpfmlo
]

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 07/16/2015 at 22:21:02.99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Results of screen317's Security Check version 1.005 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Disabled! 
Norton Internet Security  
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 Java 8 Update 45 
 Adobe Flash Player 18.0.0.209 
 Adobe Reader XI 
 Google Chrome (43.0.2357.132)
 Google Chrome (43.0.2357.134)
````````Process Check: objlist.exe by Laurent```````` 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 7%
````````````````````End of Log``````````````````````
 

Your system is clean now! :)

 

 

Uninstall our tools using delfix

Please follow these steps in order:

  1. In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  2. In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  3. In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process

  4. If there is still something left please delete it manualy.




Delete System Restore Points

To ensure your System Restore Points are free of malware, we will delete all of them but the most recent or create a new one.

On Windows Vista: Please follow these instructions to delete all but the most common System Protection Restore Points.
On Windows 7/8: Please follow these instructions to delete all but the most common System Protection Restore Points.
On Windows XP: Please follow these instructions to delete all but the most common System Protection Restore Points.

 

 

 

Recommendations: How to protect yourself

  • System Updates
  • Please ensure to have automatic updates activated in your control panel.
    For further information and a tutorial, see this Microsoft Support article.
  • Protection
  • What you need is one (not more) virus scanner with background protection. Additionally I recommend a special malware scanner to run on demand weekly.
    Personally I am using avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer good protection for free.
    • To keep your browser free of advertising, you may install the Adblock Plus browser extension.
    • It will filter unwanted advertising out of the website´s content.
    • To protect yourself from accidentally visiting malicious web sites, install the Web of Trust (WOT) browser extension.
    • It will display a green (safe), yellow (unknown) or red (potentially dangerous) icon for a visited website within your browser.
      In addition, before accessing a dangerous classified web site, a warning screen is displayed.


  • Up to date Software
  • Keep your Windows and your third party software up to date. The easiest way to get infected is an outdated windows, followed by: browser(s) (including add-ons and plug-ins), Adobe Flash Player and Adobe Reader, Java Runtime Environment, your antivirus program and so on. These links may help you to check:
    • Secunia Personal Software Inspector - checks if your software has updates available.

    • SecurityCheck (by screen317) - scans your computer for most vulnerable outdated software.

    • Mozilla: Check your plugins - The webpage will tell you if you have outdated plugins running in your Firefox browser.


  • Backup
  • Hardware issues, malware, fire, lightning strike: There is a long list of different ways to loose all your data. Back up your files regularly. Use the windows internal backup function or a third party tool and save your data onto an external hard drive, cloud storage, optical media like CDs or DVDs or (if available) a professional network backup system.
  • Behaviour
  • The commonest error when using a computer is "error 80" - what means that the error is located about 80cm in front of the monitor. This is a common joke between IT support technicians but it shows that all the safety mechanisms won´t help if you aren´t careful enough.
    • While surfing the internet, don´t click on anything you don´t know. In the worst case, it infects your system with malware.

    • Watch your step in social networks! Many cyber criminals use them to spread malware, mine personal pata (to be sold to advertising companies, for example) or simply do damage to other users. Even if a received hyperlink within a message seems to be coming from one of your friends, have a closer look. In addition, don´t click everything.

    • When installing software, have a look to each of the setup windows and uncheck any additional toolbars or free programs that may be offered additionally. Most of today´s setup procedures contain potentially unwanted programs so keep them off your system.

    • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
    • They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI