This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer slow [Solved]

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is running slow.  It runs Vista with a 64 2 X dual core processor.  It is an HP computer.  It constantly freezes.  It has 2 GB RAM.  Here is my logfile for Hijack this.

 

Thank you.

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:15:30 AM, on 7/12/2015
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Safe mode with network support
 
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\helppane.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Sharon\Downloads\HiJackThis.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Presario&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8555;https=127.0.0.1:8555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O1 - Hosts: ::1 localhost
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Freemake.YoutubeButton - {e9e8eb35-ff77-455d-b677-91e5e4fc06c2} - mscoree.dll (file missing)
O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SnapfishMediaDetector] C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
O4 - HKLM\..\Run: [emsisoft anti-malware] "c:\program files\emsisoft anti-malware\a2guard.exe" /d=60
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter\THGuard.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [FreeScreenSharing] "C:\Users\Sharon\AppData\Local\FreeScreenSharing\FreeScreenSharing.exe"
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 3.4.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
O4 - Global Startup: Snapfish Media Detector.lnk = C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\IE\IEPluginDownloader.dll,-4 - {FC0EA236-1C31-418e-BFCE-A76DDB7F1362} - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\IE\IEPluginDownloader.dll (HKCU)
O9 - Extra 'Tools' menuitem: Freemake Video Downloader - {FC0EA236-1C31-418e-BFCE-A76DDB7F1362} - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\IE\IEPluginDownloader.dll (HKCU)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - (no file)
O20 - AppInit_DLLs: C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Emsisoft Protection Service (a2AntiMalware) - Emsisoft Ltd - C:\Program Files\Emsisoft Anti-Malware\a2service.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgwdsvc.exe
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
O23 - Service: vToolbarUpdater18.5.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.5.0\ToolbarUpdater.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
 
–
End of file - 10180 bytes
 

Hello gbsk and welcome back to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions and run them in “Normal mode”, not “safe mode”.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.


  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

Logs to include with next post:

AdwCleaner log
JRT.txt
Frst.txt
Addition.txt


Thanks

Satchfan

 

Hi gbsk

It has been a couple of days since I replied to your request for help with your computer problems.

Please let me know if you are having problems and still need help.

Thanks

Satchfan

Satchfan

 

These are the the files you wanted.  I copied the logs.  I did not see an upload buttton..

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-07-2015
Ran by [removed] at 2015-07-14 05:39:58
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1992874582-3349113656-4066416677-500 - Administrator - Disabled)
Guest (S-1-5-21-1992874582-3349113656-4066416677-501 - Limited - Disabled)
Sharon (S-1-5-21-1992874582-3349113656-4066416677-1001 - Administrator - Enabled) => C:\Users\Sharon
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
7-Zip 9.20 (HKLM\…\7-Zip) (Version:  - )
Adobe Flash Player 17 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 17.0.0.191 - Adobe Systems Incorporated)
Adobe Flash Player 9 ActiveX (HKLM\…\ShockwaveFlash) (Version: 9 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Atheros Driver Installation Program (HKLM\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.1 - Atheros)
Audacity 2.0.3 (HKLM\…\Audacity_is1) (Version: 2.0.3 - Audacity Team)
AVG 2015 (HKLM\…\AVG) (Version: 2015.0.6081 - AVG Technologies)
AVG 2015 (Version: 15.0.4392 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.6081 - AVG Technologies) Hidden
AVG PC TuneUp 2014 (en-US) (Version: 14.0.1001.519 - AVG) Hidden
AVG PC TuneUp 2014 (HKLM\…\AVG PC TuneUp) (Version: 14.0.1001.519 - AVG)
AVG PC TuneUp 2014 (Version: 14.0.1001.519 - AVG) Hidden
BufferChm (Version: 82.0.173.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.07 - Piriform)
Citrix Online Launcher (HKLM\…\{C57F6C71-C365-4AFF-9108-397BBAD6127F}) (Version: 1.0.204 - Citrix)
Copy (Version: 82.0.188.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Destinations (Version: 82.0.173.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
DocProc (Version: 8.1.0.0 - Hewlett-Packard) Hidden
DocProcQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Elementary Education: Content Knowledge Practice Test (HKLM\…\{0AED2370-A4CD-4D5A-A6FA-32DE353DAE4C}) (Version: 2.0 - Educational Testing Service)
Emsisoft Anti-Malware (HKLM\…\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 10.0 - Emsisoft Ltd.)
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Freemake Video Converter version 4.0.1 (HKLM\…\Freemake Video Converter_is1) (Version: 4.0.1 - Ellora Assets Corporation)
Freemake Video Downloader (HKLM\…\Freemake Video Downloader_is1) (Version: 3.5.0 - Ellora Assets Corporation)
FreeScreenSharing (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\FreeScreenSharing) (Version: 0.56.21.0 - Free Conferencing Corporation)
Google Chrome (HKLM\…\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Talk Plugin (HKLM\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
GoToMeeting 7.2.3.3019 (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\GoToMeeting) (Version: 7.2.3.3019 - CitrixOnline)
HP Customer Experience Enhancements (HKLM\…\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.1.0.2264 - Hewlett-Packard)
HP Customer Participation Program 8.0 (HKLM\…\HPExtendedCapabilities) (Version: 8.0 - HP)
HP Easy Setup - Frontend (HKLM\…\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.1.0.2269 - Hewlett-Packard)
HP Imaging Device Functions 8.0 (HKLM\…\HP Imaging Device Functions) (Version: 8.0 - HP)
HP OCR Software 8.0 (HKLM\…\HPOCR) (Version: 8.0 - HP)
HP OFFICEJET 6210 Driver Utility (HKLM\…\HP OFFICEJET 6210 Driver Utility_is1) (Version:  - Lavians Inc.)
HP Photosmart Essential (HKLM\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
HP Photosmart Essential 2.0 (HKLM\…\HP Photosmart Essential) (Version: 2.0 - HP)
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (HKLM\…\{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}) (Version: 8.0 - HP)
HP Solution Center 8.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 8.0 - HP)
HP Update (HKLM\…\{8C6027FD-53DC-446D-BB75-CACD7028A134}) (Version: 4.000.005.005 - Hewlett-Packard)
HPProductAssistant (Version: 82.0.173.000 - Hewlett-Packard) Hidden
HPSSupply (HKLM\…\{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}) (Version: 2.1.3.0000 - Hewlett Packard Development Company L.P.)
Image Resizer for Windows (HKLM\…\{69d72156-6582-4556-8637-06f40aa7f85b}) (Version: 3.0.4802.35565 - Brice Lambson)
Image Resizer for Windows (Version: 3.0.4802.35565 - Brice Lambson) Hidden
LightScribe  1.4.142.1 (Version: 1.4.142.1 - http://www.lightscribe.com)Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
MarketResearch (Version: 82.0.174.000 - Hewlett-Packard) Hidden
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\…\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
Mozilla Firefox 39.0 (x86 en-US) (HKLM\…\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 39.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM\…\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
muvee autoProducer 6.0 (HKLM\…\{6AF49698-949A-4C89-9B31-041D2CCB5FBD}) (Version: 6.00.050 - muvee Technologies)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version:  - )
OLYMPUS Master 2 (HKLM\…\{45FCADDB-0B29-457E-83A1-D245C62A716C}) (Version: 1.0.6 - OLYMPUS IMAGING CORP.)
OLYMPUS muvee theaterPack (HKLM\…\{B3282FB8-874B-4054-8356-9EB391A826F9}) (Version: 1.0.4 - OLYMPUS IMAGING CORP.)
OpenOffice.org 3.4.1 (HKLM\…\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)
Picasa 3 (HKLM\…\Picasa 3) (Version: 3.9 - Google, Inc.)
PSSWCORE (Version: 2.00.5000 - Hewlett-Packard) Hidden
Python 2.4.3 (HKLM\…\{75E71ADD-042C-4F30-BFAC-A9EC42351313}) (Version: 2.4.3150 - Martin v. Löwis)
QuickTime (HKLM\…\{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}) (Version: 7.1.3.100 - Apple Computer, Inc.)
RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\…\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5377 - Realtek Semiconductor Corp.)
REALTEK RTL8187B Wireless LAN Driver (HKLM\…\{7095FD27-37F0-4750-9DE8-D37DC0043706}) (Version: Package:1.00.0008 Driver:6.1135.625.2008 - REALTEK Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Rhapsody Player Engine (HKLM\…\{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}) (Version: 1.0.604 - RealNetworks)
Roxio Creator Audio (HKLM\…\{83FFCFC7-88C6-41c6-8752-958A45325C82}) (Version: 3.4.0 - Roxio)
Roxio Creator Basic v9 (HKLM\…\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}) (Version: 3.4.0 - Roxio)
Roxio Creator Copy (HKLM\…\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio)
Roxio Creator Data (HKLM\…\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio)
Roxio Creator EasyArchive (HKLM\…\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio)
Roxio Creator Tools (HKLM\…\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio)
Roxio Express Labeler 3 (HKLM\…\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 3.2.1 - Roxio)
Roxio MyDVD Basic v9 (HKLM\…\{938B1CD7-7C60-491E-AA90-1F1888168240}) (Version: 9.0.559 - Roxio)
Skype Click to Call (HKLM\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 7.1 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Snapfish Media Detector (HKLM\…\{4EF6FDB0-3B11-4820-9860-8E08E9965195}) (Version: 1.7.0.15 - HP Snapfish)
SolutionCenter (Version: 82.0.188.000 - Hewlett-Packard) Hidden
Status (Version: 82.0.173.000 - Hewlett-Packard) Hidden
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1014 - SUPERAntiSpyware.com)
TrayApp (Version: 82.0.188.000 - Hewlett-Packard) Hidden
TrojanHunter 6.0 (HKLM\…\TrojanHunter_is1) (Version: 6.0 - Bytelayer AB)
Visual Studio 2012 x86 Redistributables (HKLM\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 1.1.9 (HKLM\…\VLC media player) (Version: 1.1.9 - VideoLAN)
WebEx Event Manager for Firefox or Chrome (HKLM\…\{06B5988F-EBA6-4802-9F7B-4FB471291321}) (Version: 28.7.0.15458 - Cisco WebEx LLC)
Windows 7 Upgrade Advisor (HKLM\…\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation)
WinPcap 4.1.2 (HKLM\…\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
Youtube Downloader HD v. 2.9.6 (HKLM\…\Youtube Downloader HD_is1) (Version:  - YoutubeDownloaderHD.com)
Zoom (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\ZoomUMX) (Version: 3.5 - Zoom Video Communications, Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{39125640-8D80-11DC-A2FE-C5C455D89593}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Google Talk Plugin\googletalkax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\1440\G2MOutlookAddin.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{AB9F4455-E591-4132-A386-0B91EAEDB96C}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Google Talk Plugin\o1dax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.26.9\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\psuser.dll (Google Inc.)
 
==================== Restore Points =========================
 
29-05-2015 20:54:00 Scheduled Checkpoint
30-05-2015 11:26:54 Scheduled Checkpoint
31-05-2015 11:13:38 Scheduled Checkpoint
01-07-2015 12:42:58 Windows Update
02-07-2015 12:02:26 Scheduled Checkpoint
03-07-2015 11:44:40 Scheduled Checkpoint
04-07-2015 11:57:52 Scheduled Checkpoint
05-07-2015 00:00:05 Scheduled Checkpoint
05-07-2015 16:42:42 Scheduled Checkpoint
08-07-2015 22:24:40 Scheduled Checkpoint
13-07-2015 03:04:14 Scheduled Checkpoint
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 02:23 - 2006-09-18 13:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {02B1C58A-086C-4ED9-B993-C6450A1DBC27} - System32\Tasks\Registration => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-03-05] ()
Task: {1B6DBECF-3A87-479C-9AEE-97A6A053F36F} - System32\Tasks\HP online update program => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {2406BCAB-604C-46CC-8541-B7A1BE9F6CF2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-27] (Google Inc.)
Task: {2A42CD5F-56F8-4BF2-9DCB-4539B8A920A8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-27] (Google Inc.)
Task: {5DCB035D-4B45-4509-A148-84B06314AD4B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-08] (Adobe Systems Incorporated)
Task: {63C8F07F-D02D-4EBD-8DBE-2194C65FAA96} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {76748A9F-364C-4BA3-A180-A8A9E65E30AC} - System32\Tasks\Real Player online update program => C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-10-12] (RealNetworks, Inc.)
Task: {AFF35159-F6E9-49C8-8CA7-9669E9B18DCC} - System32\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupdate.exe [2015-07-09] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {C37BA6B1-ADD5-4F04-A7B0-04BEB36E59A2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-10] (Google Inc.)
Task: {D42CA714-CB4E-4AA5-BC29-026CAF953660} - System32\Tasks\IntenetServiceOffers => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-03-05] ()
Task: {D5B4D35F-5815-451D-9D4A-CA951A9A7186} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-06-01] (Piriform Ltd)
Task: {E29A3170-0CD7-46E7-8DD5-DAC5DB3B337A} - System32\Tasks\Adobe online update program => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {EED84F28-F38A-4C31-8D42-E093B56E74A5} - System32\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupload.exe [2015-07-09] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {F563A206-B0DB-41F9-B0A8-ACEBB032707D} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Sharon => C:\Program Files\Windows Calendar\WinCal.exe [2007-06-26] (Microsoft Corporation)
Task: {F9011493-B85D-4B2F-BD39-CDF7FE8536A8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-10] (Google Inc.)
Task: {FA63882F-4A5A-4C97-9855-5D7FA1F9709A} - System32\Tasks\{3092C782-E801-4022-8631-A592DFCCADB7} => pcalua.exe -a "C:\Program Files\QuickTime\QTSystem\QuickTime.cpl" -c @0,0x63737064
Task: {FA71853D-E21F-45D1-A4BB-7D16CF8065F6} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {FC86BC9D-A39B-4C5F-A3E6-D9E2CFB5D088} - \OptimusNitro_Start No Task File <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupload.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2012-08-10 16:51 - 2012-08-10 16:51 - 00985088 _____ () C:\Program Files\OpenOffice.org 3\program\libxml2.dll
2014-07-14 10:07 - 2014-02-10 13:44 - 04592128 _____ () C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
2014-07-14 10:07 - 2014-02-10 13:44 - 00112128 _____ () C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Sharon\Pictures\p.3 joy.jpg
DNS Servers: 192.168.2.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk => C:\Windows\pss\OpenOffice.org 3.4.1.lnk.Startup
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: emsisoft anti-malware => "c:\program files\emsisoft anti-malware\a2guard.exe" /d=60
MSCONFIG\startupreg: FreeScreenSharing => "C:\Users\Sharon\AppData\Local\FreeScreenSharing\FreeScreenSharing.exe"
MSCONFIG\startupreg: Google Update => "C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: OM2_Monitor => "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: THGuard => "C:\Program Files\TrojanHunter\THGuard.exe"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{C39C9369-DF78-4BA3-B71E-AAEBCCC33157}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{E6281A08-83AE-4E62-8A1A-2C189B8D1BE7}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{21C042E9-8F4D-4046-980E-4F45283AC8F2}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{61D8597E-437D-43DD-89CC-62F487F13081}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{CFE6DE30-FE46-4C60-B0B7-09C12C3214F0}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{B82921CB-E57D-4E9E-AADF-71E261A9A6FC}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{9434D6F6-9325-449C-83A6-688A78CD132F}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{5CDBFFA3-A48D-4445-88DC-6D5364623797}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{3EF2AD33-05C0-4EFB-8F08-EC2B6BBC3FE7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{C160F25F-0B64-4732-8263-97D07C2E73EB}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{0C16FA18-D5B1-4409-ACDA-1C3308C7BD9D}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{16B9DCCF-ECA7-481C-8CF0-D9E749F23A52}] => (Allow) C:\Program Files\AVG\AVG2015\avgnsx.exe
FirewallRules: [{7D687C39-533C-4B68-9896-282F2C63A60C}] => (Allow) C:\Program Files\AVG\AVG2015\avgnsx.exe
FirewallRules: [{3C94EE9E-A0CA-484C-B082-936FB1DDFC81}] => (Allow) C:\Program Files\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{43A2EA19-F75D-4B68-AFEB-BF94D6A9FD6D}] => (Allow) C:\Program Files\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{94E3137F-E0E6-4D52-A88E-624EBD131210}] => (Allow) C:\Program Files\AVG\AVG2015\avgemcx.exe
FirewallRules: [{7C10B454-7729-4ECA-B09B-5E121653AA86}] => (Allow) C:\Program Files\AVG\AVG2015\avgemcx.exe
FirewallRules: [{4839C1AC-5CD7-4C77-87DF-1A41AE07EE0D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe] => Enabled:Earthlink
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/14/2015 05:13:37 AM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
 
Error: (07/14/2015 04:39:04 AM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
 
Error: (07/14/2015 03:13:35 AM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
 
Error: (07/14/2015 01:13:37 AM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
 
Error: (07/13/2015 11:14:01 PM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0x80080005
 
Error: (07/13/2015 09:13:36 PM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
 
Error: (07/13/2015 07:13:32 PM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
 
Error: (07/13/2015 05:13:30 PM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
 
Error: (07/13/2015 03:13:30 PM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
 
Error: (07/13/2015 01:13:28 PM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
 
 
System errors:
=============
Error: (07/14/2015 05:13:37 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: SL UI Notification Service3221541889 (0xC004D401)
 
Error: (07/14/2015 04:39:04 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: SL UI Notification Service3221541889 (0xC004D401)
 
Error: (07/14/2015 03:13:36 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: SL UI Notification Service3221541889 (0xC004D401)
 
Error: (07/14/2015 01:13:37 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: SL UI Notification Service3221541889 (0xC004D401)
 
Error: (07/13/2015 11:14:01 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: SL UI Notification Service2148007941 (0x80080005)
 
Error: (07/13/2015 11:14:00 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {CC4A75EF-73D4-46CB-960E-3BFF6151C2B3}
 
Error: (07/13/2015 09:13:36 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: SL UI Notification Service3221541889 (0xC004D401)
 
Error: (07/13/2015 07:13:33 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: SL UI Notification Service3221541889 (0xC004D401)
 
Error: (07/13/2015 05:13:31 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: SL UI Notification Service3221541889 (0xC004D401)
 
Error: (07/13/2015 03:13:30 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: SL UI Notification Service3221541889 (0xC004D401)
 
 
Microsoft Office:
=========================
Error: (04/19/2015 10:43:02 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20499 seconds with 120 seconds of active time.  This session ended with a crash.
 
Error: (04/17/2015 10:53:03 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2093 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (09/12/2014 08:49:26 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 516 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (09/05/2012 11:47:41 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 322286 seconds with 720 seconds of active time.  This session ended with a crash.
 
 
CodeIntegrity Errors:
===================================
  Date: 2015-07-14 05:38:42.655
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-14 05:38:42.608
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-14 05:38:42.565
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-14 05:38:42.521
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-14 05:38:42.221
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-14 05:38:42.180
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-14 05:38:42.136
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-14 05:38:42.092
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-14 05:38:41.437
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-14 05:38:41.394
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ 64 X2 Dual Core Processor 3600+
Percentage of memory in use: 89%
Total physical RAM: 1917.94 MB
Available physical RAM: 198.71 MB
Total Virtual: 4933.09 MB
Available Virtual: 1762.36 MB
 
==================== Drives ================================
 
Drive c: (COMPAQ) (Fixed) (Total:140.67 GB) (Free:88.81 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Recovery) (Fixed) (Total:8.38 GB) (Free:1.01 GB) NTFS ==>[system with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 149.1 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=140.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=8.4 GB) - (Type=07 NTFS)
 
==================== End of log ============================
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-07-2015
Ran by [removed] (administrator) on HAK-PC on 14-07-2015 05:36:14
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Microsoft® Windows Vista™ Home Basic  (X86) OS Language: English (United States)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcsrvx.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgemcx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\WINDOWS\System32\cmd.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Microsoft Corporation) C:\WINDOWS\System32\LogonUI.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\System32\SndVol.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-01-16] (Microsoft Corporation)
HKLM\…\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2006-09-28] (Hewlett-Packard Company)
HKLM\…\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4390912 2007-03-01] (Realtek Semiconductor)
HKLM\…\Run: [SnapfishMediaDetector] => C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe [1441792 2007-03-02] ()
HKLM\…\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3730344 2015-06-30] (AVG Technologies CZ, s.r.o.)
HKLM\…\Run: [MSConfig] => C:\Windows\system32\msconfig.exe [222208 2006-11-02] (Microsoft Corporation)
HKLM\…\RunOnce: [Launcher] => C:\Windows\SMINST\launcher.exe [44168 2007-03-07] (soft thinks)
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil32_17_0_0_191_Plugin.exe [927920 2015-07-08] (Adobe Systems Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2013-11-15]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk [2007-05-10]
ShortcutTarget: Snapfish Media Detector.lnk -> C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\Software\Microsoft\Internet Explorer\Main,Start Page = 
SearchScopes: HKLM -> {F21EE9D8-5723-4F76-866F-2CD49B3624D1} URL = http://search.yahoo.com/search?p={searchTerms}&ei;={inputEncoding}&fr;=hp-psdt
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001 -> {F21EE9D8-5723-4F76-866F-2CD49B3624D1} URL = http://search.yahoo.com/search?p={searchTerms}&ei;={inputEncoding}&fr;=hp-psdt
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-18] (SuperAdBlocker.com)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{003F1CAB-9582-432A-976B-A5B40F8B2472}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{015EC064-039A-44FB-930A-94C209392E85}: [DhcpNameServer] 192.168.2.1
 
FireFox:
========
FF ProfilePath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
FF NetworkProxy: "http", "127.0.0.1"
FF NetworkProxy: "http_port", 8555
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_191.dll [2015-07-08] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2013-10-12] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-10-12] (RealPlayer)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Sharon\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-07-27] (Citrix Online)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/O1DPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Sharon\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2015-03-17] (Zoom Video Communications, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npatgpc.dll [2012-10-29] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF SearchPlugin: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\searchplugins\amazon-distro.xml [2012-12-13]
FF Extension: adblockvideo - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2012-09-15]
FF Extension: feedly - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2013-05-10]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2012-12-12]
FF Extension: Adblock Plus - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-15]
FF Extension: User Agent Switcher - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2013-05-06]
FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files\Mozilla Firefox\extensions\[removed] [2015-06-30]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Video Downloader Plugin - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Youtube Download Button - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-05-20]
FF HKLM\…\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-10-12]
FF HKLM\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
 
Chrome: 
=======
CHR Profile: C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Freemake Video Downloader) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf [2013-05-03]
CHR Extension: (RealDownloader) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-04-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-21]
CHR Extension: (Skype Click to Call) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-09-01]
CHR Extension: (Google Wallet) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-13]
CHR HKLM\…\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2013-04-25]
CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-29] (SUPERAntiSpyware.com)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [5509384 2015-07-08] (Emsisoft Ltd)
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3518376 2015-06-30] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [314304 2015-06-30] (AVG Technologies CZ, s.r.o.)
S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-04-25] (Freemake) [File not signed]
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-13] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S2 LightScribeService; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [1858360 2014-07-14] (AVG)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [35640 2014-07-14] (AVG)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [265912 2007-01-16] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [132576 2015-03-11] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [231856 2015-06-26] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [190944 2015-05-12] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [29664 2015-05-14] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [207328 2015-06-16] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [290272 2015-05-07] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [170464 2015-06-10] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [35808 2015-03-20] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [213984 2015-05-12] (AVG Technologies CZ, s.r.o.)
R1 epp32; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp32.sys [112408 2015-07-08] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2014-02-10] (TuneUp Software)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-14 05:36 - 2015-07-14 05:38 - 00019985 _____ C:\Users\Sharon\Downloads\FRST.txt
2015-07-14 05:35 - 2015-07-14 05:37 - 00000000 ____D C:\FRST
2015-07-14 05:34 - 2015-07-14 05:34 - 01636864 _____ (Farbar) C:\Users\Sharon\Downloads\FRST.exe
2015-07-14 05:32 - 2015-07-14 05:32 - 02133504 _____ (Farbar) C:\Users\Sharon\Downloads\FRST64 (3).exe
2015-07-14 05:31 - 2015-07-14 05:31 - 02133504 _____ (Farbar) C:\Users\Sharon\Downloads\FRST64 (2).exe
2015-07-14 05:31 - 2015-07-14 05:31 - 02133504 _____ (Farbar) C:\Users\Sharon\Downloads\FRST64 (1).exe
2015-07-14 05:28 - 2015-07-14 05:29 - 02133504 _____ (Farbar) C:\Users\Sharon\Downloads\FRST64.exe
2015-07-13 10:24 - 2015-07-13 10:24 - 00000296 _____ C:\Windows\system32\spsys.log
2015-07-13 02:35 - 2015-07-13 02:35 - 00003121 _____ C:\Users\Sharon\Desktop\JRT.txt
2015-07-13 02:22 - 2015-07-13 02:22 - 00000207 _____ C:\Windows\tweaking.com-regbackup-HAK-PC-Windows-Vista-(TM)-Home-Basic-(32-bit).dat
2015-07-13 02:21 - 2015-07-13 02:21 - 00000000 ____D C:\RegBackup
2015-07-13 02:19 - 2015-07-13 02:19 - 00009208 _____ C:\Users\Sharon\Desktop\AdwCleaner[S0].txt
2015-07-13 02:16 - 2015-07-13 02:17 - 03034492 _____ (Malwarebytes Corporation) C:\Users\Sharon\Downloads\JRT.exe
2015-07-13 02:14 - 2015-07-13 02:14 - 00000000 ____D C:\Windows\pss
2015-07-13 02:00 - 2015-07-13 02:05 - 00000000 ____D C:\AdwCleaner
2015-07-13 01:58 - 2015-07-13 01:59 - 02248704 _____ C:\Users\Sharon\Downloads\adwcleaner_4.208.exe
2015-07-12 11:15 - 2015-07-12 11:15 - 00010182 _____ C:\Users\Sharon\Downloads\hijackthis.log
2015-07-12 11:14 - 2015-07-12 11:14 - 00388608 _____ (Trend Micro Inc.) C:\Users\Sharon\Downloads\HiJackThis.exe
2015-07-10 03:41 - 2015-07-10 03:41 - 00027329 _____ C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!.html
2015-07-10 03:41 - 2015-07-10 03:41 - 00000000 ____D C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!_files
2015-07-08 16:22 - 2015-07-12 11:21 - 00001356 _____ C:\Users\Sharon\AppData\Local\d3d9caps.dat
2015-07-08 14:46 - 2015-07-14 04:29 - 00204255 _____ C:\Windows\WindowsUpdate.log
2015-07-07 10:56 - 2015-07-07 10:56 - 00000810 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\Program Files\CCleaner
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507.exe
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507 (1).exe
2015-07-07 01:38 - 2015-07-07 01:44 - 00000000 ____D C:\ProgramData\Emsisoft
2015-07-07 01:10 - 2015-07-07 01:11 - 00000000 ____D C:\Program Files\TrojanHunter
2015-07-07 01:10 - 2015-07-07 01:10 - 00000858 _____ C:\Users\Sharon\Desktop\TrojanHunter.lnk
2015-07-07 01:10 - 2015-07-07 01:10 - 00000000 ____D C:\ProgramData\TrojanHunter
2015-07-07 01:10 - 2015-07-07 01:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
2015-07-07 01:09 - 2015-07-07 01:09 - 04069672 _____ (Bytelayer AB ) C:\Users\Sharon\Downloads\TrojanHunterSetup.exe
2015-07-06 17:15 - 2015-07-06 17:15 - 00000894 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2015-07-06 17:15 - 2015-07-06 17:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2015-07-06 17:14 - 2015-03-24 00:17 - 00111368 _____ (Emsisoft GmbH) C:\Windows\system32\Drivers\epp32.sys
2015-07-06 17:13 - 2015-07-14 05:36 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2015-07-06 16:13 - 2015-07-06 16:30 - 167273960 _____ (Emsisoft Ltd. ) C:\Users\Sharon\Downloads\EmsisoftAntiMalwareSetup.exe
2015-07-05 12:46 - 2015-07-05 12:46 - 00242712 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 39.0.exe
2015-07-05 10:22 - 2015-07-05 10:26 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Sharon\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-07-03 14:20 - 2015-07-03 14:20 - 01125056 _____ (Adobe Systems Incorporated) C:\Users\Sharon\Downloads\flashplayer18_ha_install.exe
2015-07-02 13:55 - 2015-07-02 13:55 - 00243408 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 38.0.5.exe
2015-06-30 12:25 - 2015-07-05 14:17 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-26 09:49 - 2015-06-26 09:49 - 00231856 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdriverx.sys
2015-06-16 15:54 - 2015-06-16 15:54 - 00207328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx86.sys
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-14 05:31 - 2014-07-27 15:41 - 00000568 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-14 05:18 - 2012-10-18 13:49 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-14 05:10 - 2015-05-10 16:53 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job
2015-07-14 05:09 - 2013-04-27 03:03 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-14 04:44 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-14 04:44 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-14 03:53 - 2015-05-30 13:19 - 00000664 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-14 03:21 - 2012-07-09 10:00 - 00000000 ____D C:\ProgramData\MFAData
2015-07-13 22:57 - 2015-05-10 16:53 - 00000860 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job
2015-07-13 15:26 - 2012-07-08 00:30 - 00000000 ____D C:\Users\Sharon\AppData\Roaming\Skype
2015-07-13 11:09 - 2013-04-27 03:03 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-13 02:10 - 2007-05-10 11:27 - 00000000 ____D C:\Windows\SMINST
2015-07-13 02:09 - 2006-11-02 04:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-13 02:07 - 2006-11-02 04:58 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-07-09 11:53 - 2014-11-04 14:36 - 00000848 _____ C:\Users\Public\Desktop\AVG 2015.lnk
2015-07-09 11:53 - 2014-03-31 14:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-07-08 15:21 - 2012-07-08 00:19 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-08 15:21 - 2012-07-08 00:19 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-08 15:04 - 2013-05-06 08:20 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-07 11:00 - 2012-07-17 15:02 - 00000000 ____D C:\Windows\Minidump
2015-07-07 11:00 - 2007-05-10 11:06 - 00000000 ____D C:\Windows\Panther
2015-07-07 01:25 - 2012-06-06 18:33 - 00000000 ____D C:\Users\Sharon\AppData\Local\VirtualStore
2015-07-05 14:17 - 2013-03-09 15:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-07-05 14:16 - 2006-11-02 04:35 - 00000000 ____D C:\Windows\DigitalLocker
2015-07-05 12:50 - 2013-03-09 15:52 - 00000864 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-05 12:50 - 2013-03-09 15:52 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-05 10:37 - 2014-04-11 17:05 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-05 10:30 - 2014-04-11 17:02 - 00000905 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-07-01 13:07 - 2013-07-14 19:21 - 00000000 ____D C:\Windows\system32\MRT
2015-07-01 12:53 - 2014-04-14 12:13 - 00000000 ____D C:\Users\Sharon\AppData\Local\AVG
2015-07-01 12:45 - 2006-11-02 02:24 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-06-18 08:41 - 2014-04-11 17:02 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-18 08:41 - 2014-04-11 17:02 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-18 08:41 - 2013-05-04 07:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
 
==================== Files in the root of some directories =======
 
2013-05-21 03:10 - 2014-01-30 13:39 - 0003736 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
2015-07-08 16:22 - 2015-07-12 11:21 - 0001356 _____ () C:\Users\Sharon\AppData\Local\d3d9caps.dat
2012-07-08 02:19 - 2015-05-06 19:35 - 0025088 _____ () C:\Users\Sharon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2007-05-10 10:43 - 2013-03-21 07:29 - 0002738 _____ () C:\ProgramData\hpzinstall.log
 
Some files in TEMP:
====================
C:\Users\Sharon\AppData\Local\Temp\Quarantine.exe
C:\Users\Sharon\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-14 02:21
 
==================== End of log ============================
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.4.6 (07.12.2015:2)
OS: Windows Vista (TM) Home Basic x86
Ran by [removed] on Mon 07/13/2015 at  2:21:49.15
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
Successfully deleted: [Task] C:\Windows\System32\tasks\OptimusNitro_Start
 
 
 
~~~ Registry Values
 
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
 
# AdwCleaner v4.208 - Logfile created 13/07/2015 at 02:03:32
# Updated 09/07/2015 by Xplode
# Database : 2015-07-11.1 [Server]
# Operating system : Windows Vista (TM) Home Basic  (x86)
# Username : Sharon - HAK-PC
# Running from : C:\Users\Sharon\Downloads\adwcleaner_4.208.exe
# Option : Cleaning
 
***** [ Services ] *****
 
[#] Service Deleted : vToolbarUpdater18.5.0
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\SearchProtect
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\Avg_Update_0814tb
Folder Deleted : C:\Program Files\AVG Secure Search
Folder Deleted : C:\Program Files\AVG Security Toolbar
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Windows\system32\SearchProtect
Folder Deleted : C:\Users\Sharon\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Sharon\AppData\Local\Zoom_Downloader
Folder Deleted : C:\Users\Sharon\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj
File Deleted : C:\END
File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
File Deleted : C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\invalidprefs.js
File Deleted : C:\Program Files\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
File Deleted : C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\user.js
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2096DA77-8920-466B-AE1D-464BA43E204A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2096DA77-8920-466B-AE1D-464BA43E204A}
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\distromatic
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\Microsoft\Babylon
Key Deleted : HKCU\Software\Avg Secure Update
Key Deleted : HKLM\SOFTWARE\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Avg Secure Update
Key Deleted : HKU\.DEFAULT\Software\AVG Secure Search
Key Deleted : HKU\.DEFAULT\Software\Avg Secure Update
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{83AA2913-C123-4146-85BD-AD8F93971D39}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2468513CA2D6943A1A233CD3F88CE7
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3192AA38321C641458DBDAF83979D193
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\3192AA38321C641458DBDAF83979D193
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=127.0.0.1:8555;hxxps=127.0.0.1:8555
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - 127.0.0.1;localhost;10.*;192.168.*;127.0.0.1:895;127.0.0.1:896;
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v7.0.6000.16982
 
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls
 
-\\ Mozilla Firefox v39.0 (x86 en-US)
 
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\FireFoxExt\\14.2.0.1");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.admin", false);
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false);
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.id", "d4528d9c00000000000000027274c6be");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15551");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://www.google.com/search?babsrc=TB_ggl&q;=");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.5.29.1");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.5.29.1");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=113959&tt;=3112_8");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
[jmphnpxt.default\prefs.js] - Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.29.112:22:02");
 
-\\ Google Chrome v43.0.2357.132
 
 
*************************
 
AdwCleaner[R0].txt - [9203 bytes] - [13/07/2015 02:01:01]
AdwCleaner[S0].txt - [9069 bytes] - [13/07/2015 02:03:32]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9128  bytes] ##########
 

I copied the logs.  I did not see an upload buttton.

I didn't ask for them to be "uploaded - copy/paste is fine.

A couple of points before we start.

Farbar Recovery Scan Tool is in your Downloads folder. It’s a good idea to move it to your desktop otherwise future fixes may not work.

  • go to your Downloads folder and locate Farbar Recovery Scan Tool
  • right click and select Cut
  • go to an empty spot on your desktop, right click and select Paste

Farbar Recovery Scan Tool should now be on your desktop.

======================

I don't see any Service Pack installed for your Vista operating system. Is there a reason for that?

======================

Run Farbar Recovery Scan Tool

Open notepad (Start >All Programs > Accessories > Notepad). Please copy the entire contents of the code box below and paste it into Notepad.

FF NetworkProxy: "http_port", 8555
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
Task: {FC86BC9D-A39B-4C5F-A3E6-D9E2CFB5D088} - \OptimusNitro_Start No Task File <==== ATTENTION

NOTE: this script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

================================================

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:

  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scan” tab, select Threat Scan, then click Scan.
  • when the scan is complete, if no malicious items are found you can close the program
  • if malicious items are found be sure that everything is checked and click Quarantine
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.

NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

================================================

Download zoek.exe to your Desktop:

Important: Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here.

 

  • on Windows Vista, 7/8, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    createsrpoint;
    autoclean;
    emptyalltemp;
    ipconfig /flushdns;b
  • close any open programs
  • click the Run script button, and wait. It takes a few minutes to run
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

 

Logs to include with the next post:

Fixlog.txt
Mbam.txt
zoek-results.log


Can you tell me how your computer is now and tell me what outstanding problems you still have.

Satchfan

Satchfan,

 

Thanks for your help.  I moved the FRST to the desktop.  The problem is that when some files open up, they do not indicate where I CAN SAVE IT.  

Satchfan,

 

Thanks for your help.  I moved the FRST to the desktop.  The problem is that when some files open up, they do not indicate where I CAN SAVE IT.  iS THERE A WAY i CAN EFFEICIENTLY JUST SAVE IT TO THE desktop without actually cut and pasting it?  This is my wife's computer.  2-3 years ago my son reinstalled Vista.  I do not know where he got the program.  I guess he did not install the Service Packs.  Is just SP1 missing?  I can install them if you like.  I am confused about combining and naming FRST and script.  It seems like you want me to combine them in a new folder.  What do I call the new folder?  It would not let me name the new folder FRST or fixlist.  I will run the rest of your requests now and send info you require when finished.

 

Thanks

GB

Satchfan,

 

There were no threats in MBAM and there was no log for it.  I ran zoek and here is the log for it.   I think the computer is working better.  It is hard to tel since I have different windowns open.  I'll keep you posted.

 

Thanks

GB

 

 
Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Sharon on Thu 07/16/2015 at 20:37:33.27.
Microsoft® Windows Vista™ Home Basic  6.0.6000  x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Sharon\Desktop\zoek.exe [Scan all users] [Script inserted] 
 
==== System Restore Info ======================
 
7/16/2015 8:41:12 PM Zoek.exe System Restore Point Created Successfully.
 
==== Empty Folders Check ======================
 
C:\Program Files\MSXML 4.0 deleted successfully
C:\PROGRA~2\HPSSUPPLY deleted successfully
C:\PROGRA~2\TrojanHunter deleted successfully
C:\PROGRA~2\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted successfully
C:\Users\Sharon\AppData\Roaming\Malwarebytes deleted successfully
C:\Users\Sharon\AppData\Roaming\webex deleted successfully
C:\Users\Sharon\AppData\Local\PowerCinema deleted successfully
 
==== Deleting CLSID Registry Keys ======================
 
HKEY_USERS\S-1-5-21-1992874582-3349113656-4066416677-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{e9e8eb35-ff77-455d-b677-91e5e4fc06c2} deleted successfully
HKEY_USERS\S-1-5-21-1992874582-3349113656-4066416677-1001\Software\Microsoft\Internet Explorer\SearchScopes\{F21EE9D8-5723-4F76-866F-2CD49B3624D1} deleted successfully
HKEY_USERS\S-1-5-21-1992874582-3349113656-4066416677-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4E39681-15F8-4fda-B8A3-B5C98378F2F3} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F21EE9D8-5723-4F76-866F-2CD49B3624D1} deleted successfully
 
==== Deleting CLSID Registry Values ======================
 
 
==== Deleting Services ======================
 
 
==== FireFox Fix ======================
 
ProfilePath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
 
user.js not found
—- Lines Search  removed from prefs.js —-
user_pref("extensions.AMAZONNEW_NS_PH.toolbarXMLText", "\n\n  \n    \n  
—- FireFox user.js and prefs.js backups —- 
 
prefs_20150716_0916_.backup
 
==== Batch Command(s) Run By Tool======================
 
 
==== Deleting Files \ Folders ======================
 
C:\PROGRA~2\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} not found
C:\PROGRA~2\DivX deleted
C:\Program Files\GUM23E2.tmp deleted
C:\Program Files\GUM865C.tmp deleted
C:\Program Files\Yahoo! deleted
C:\found.000 deleted
C:\Windows\system32\config\systemprofile\AppData\Roaming\Hotspot Shield deleted
C:\PROGRA~2\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
C:\Users\Public\AlexaNSISPlugin.2964.dll deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\Windows\system32\GroupPolicy\Machine deleted
C:\Windows\system32\GroupPolicy\User deleted
C:\Windows\system32\GroupPolicy\gpt.ini deleted
C:\Windows\System32\Hotspot Shield deleted
 
==== Firefox Extensions Registry ======================
 
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [10/12/2013 08:51 PM]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04/04/2014 02:36 AM]
 
==== Firefox Extensions ======================
 
ProfilePath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
- adblockvideo - %ProfilePath%\extensions\[removed]
- feedly - %ProfilePath%\extensions\[removed]
- Download YouTube Videos as MP4 - %ProfilePath%\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- User Agent Switcher - %ProfilePath%\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi
 
AppDir: C:\Program Files\Mozilla Firefox
- Hotspot Shield Helper Please allow this installation - %AppDir%\extensions\[removed]
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
==== Firefox Plugins ======================
 
Profilepath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
0D18EE6AA78A9B3E8F95712812EF1DE8 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.1.3
69381B2D346878637D793407B29A7804 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.1.3
61967C540F5E29A5F1FDFDBE4F8967B0 - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.1.3
E2D0341646A7BAE01A477DAEB924B490 - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.1.3
D55959632B71CE1F9C992BCE7D7E41DA - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.1.3
2D7AB3805EFF23BB6D6C7AA44CE65EEE - C:\Program Files\QuickTime\Plugins\npqtplugin6.dll - QuickTime Plug-in 7.1.3
38D097E51BA924D79C2C735D1B33152A - C:\Program Files\QuickTime\Plugins\npqtplugin7.dll - QuickTime Plug-in 7.1.3
F055C91A961601B8D50EF2976145AEE6 - C:\Program Files\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat
1E5E8C84DE796A01D1D46E3A660690F1 - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
1F352B5944AF5C2204D9EFF7F845C5AF - C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll - Google Update
F8CB60A5ACA5D73807ECBD9942A8BCB7 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll - RealDownloader Plugin
4356F21FB6D547F22BFBC91164A597A6 - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll - RealNetworks Rhapsody Player Engine
96B3689320E9B16EDF38B7A5001C35F0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealNetworks™ RealDownloader HTML5VideoShim Plug-In (32-bit)
EAC427FEF96A13058C1ACD17C38966CF - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll - RealNetworks™ RealDownloader PepperFlashVideoShim Plug-In (32-bit)
BE126CB7049E89ED6F3038016668B502 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll - RealNetworks™ RealDownloader Chrome Background Extension Plug-In (32-bit)
0FCEAA7D12B7B0BA825E5C770B1DCA48 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll - RealPlayer Download Plugin
3A9E1940B4459CC97FDCBB24FCB69004 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll - RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit)
AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
5B4DA1113F240C3F06FFF9D52761528B - C:\Program Files\Google\Picasa3\npPicasa3.dll - Picasa
FD82108FD60B63010325D9AF6F00AF99 - C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll - Shockwave Flash
3BD80F4DAE84A0CBB153CB49A171B0FC - C:\Users\Sharon\AppData\Roaming\Zoom\bin\npzoomplugin.dll - Zoom launcher - 3.0.1
1F352B5944AF5C2204D9EFF7F845C5AF - C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll - Google Update
E3B4EA121F7BDEB0F6366E2BA9608CB5 - C:\Users\Sharon\AppData\Local\Citrix\Plugins\104\npappdetector.dll - Citrix Online Web Deployment Plugin 1.0.0.104
49D429EBF5305FC9ADD7545B7C914333 - C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin
6BEAD7859E8A087BE04556AB5A78855C - C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer
 
 
==== Deleted Firefox Extensions ======================
 
C:\Program Files\Mozilla Firefox\extensions\[removed] deleted
 
==== Chromium Look ======================
 
Google Chrome Version: 43.0.2357.134
 
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
bpegkgagfojjbcpkihigfmkojdmmimdf - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx[02/01/2013 10:31 AM]
idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[08/14/2013 03:24 PM]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[10/09/2013 10:59 AM]
 
Freemake Video Downloader - Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf
RealDownloader - Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
Chrome Hotword Shared Module - Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
Skype Click to Call - Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
 
==== Chromium Startpages ======================
 
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Preferences
e":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":386063},"supports_spdy":true},"www.googlecommerce.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.googletagmanager.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.googletagservices.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"supports_spdy":true},"www.googletagservices.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":214618}},"www.gstatic.com:443":{"supports_spdy":true},"www.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.youtube-nocookie.com:443":{"supports_spdy":true},"www.youtube.com:443":{"supports_spdy":true},"www.youtube.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"yt3.ggpht.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"supports_spdy":true}},"supports_quic":{"address":"192.168.2.3","used_quic":true},"version":3}},"password_bubble":{"nopes":1},"plugins":{"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"printing":{"print_preview_sticky_settings":{"appState":"{\"version\":2,\"isGcpPromoDismissed\":false,\"selectedDestinationId\":\"Brother MFC-J825DW Printer\",\"selectedDestinationOrigin\":\"local\",\"selectedDestinationAccount\":\"\",\"selectedDestinationCapabilities\":{\"printer\":{\"collate\":{\"default\":false},\"color\":{\"option\":[{\"is_default\":true,\"type\":\"STANDARD_COLOR\",\"vendor_id\":\"2\"},{\"type\":\"STANDARD_MONOCHROME\",\"vendor_id\":\"1\"}]},\"copies\":{},\"duplex\":{\"option\":[{\"is_default\":true,\"type\":\"NO_DUPLEX\"},{\"type\":\"LONG_EDGE\"},{\"type\":\"SHORT_EDGE\"}]},\"media_size\":{\"option\":[{\"custom_display_name\":\"Letter (8 ½ x 11 in)\",\"height_microns\":279400,\"is_default\":true,\"name\":\"NA_LETTER\",\"vendor_id\":\"1\",\"width_microns\":215900},{\"custom_display_name\":\"4 x 6 in (10 x 15 cm)\",\"height_microns\":152400,\"name\":\"NA_INDEX_4X6\",\"vendor_id\":\"265\",\"width_microns\":101600},{\"custom_display_name\":\"Legal (8 ½ x 14 in)\",\"height_microns\":355600,\"name\":\"NA_LEGAL\",\"vendor_id\":\"5\",\"width_microns\":215900},{\"custom_display_name\":\"Executive (7 ¼ x 10 ½ in)\",\"height_microns\":266700,\"name\":\"NA_EXECUTIVE\",\"vendor_id\":\"7\",\"width_microns\":184100},{\"custom_display_name\":\"A4 (8.3 x 11.7 in)\",\"height_microns\":297000,\"name\":\"ISO_A4\",\"vendor_id\":\"9\",\"width_microns\":210000},{\"custom_display_name\":\"A5 (5.8 x 8.3 in)\",\"height_microns\":210000,\"name\":\"ISO_A5\",\"vendor_id\":\"11\",\"width_microns\":148000},{\"custom_display_name\":\"A6 (4.1 x 5.8 in)\",\"height_microns\":148000,\"name\":\"ISO_A6\",\"vendor_id\":\"70\",\"width_microns\":105000},{\"custom_display_name\":\"Ledger (11 x 17 in)\",\"height_microns\":431800,\"name\":\"NA_LEDGER\",\"vendor_id\":\"3\",\"width_microns\":279400},{\"custom_display_name\":\"A3 (11.7 x 16.5 in)\",\"height_microns\":420000,\"name\":\"ISO_A3\",\"vendor_id\":\"8\",\"width_microns\":297000},{\"custom_display_name\":\"5 x 7 in (13 x 18 cm)\",\"height_microns\":177800,\"name\":\"NA_5X7\",\"vendor_id\":\"273\",\"width_microns\":127000},{\"custom_display_name\":\"5 x 8 in (13 x 20 cm)\",\"height_microns\":203200,\"name\":\"NA_INDEX_5X8\",\"vendor_id\":\"266\",\"width_microns\":127000},{\"custom_display_name\":\"3.5 x 5 in (9 x 13 cm)\",\"height_microns\":127000,\"vendor_id\":\"272\",\"width_microns\":88900},{\"custom_display_name\":\"C5 Envelope (6.4 x 9 in)\",\"height_microns\":229000,\"name\":\"ISO_C5\",\"vendor_id\":\"28\",\"width_microns\":162000},{\"custom_display_name\":\"Com-10 (4 1/8 x 9 ½ in)\",\"height_microns\":241300,\"name\":\"NA_NUMBER_10\",\"vendor_id\":\"20\",\"width_microns\":104700},{\"custom_display_name\":\"DL Envelope (4.3 x 8.7 in)\",\"height_microns\":220000,\"name\":\"ISO_DL\",\"vendor_id\":\"27\",\"width_microns\":110000},{\"custom_display_name\":\"Monarch (3 7/8 x 7 ½ in)\",\"height_microns\":190500,\"name\":\"NA_MONARCH\",\"vendor_id\":\"37\",\"width_microns\":98400},{\"custom_display_name\":\"12 cm Disc (4.7 in)\",\"height_microns\":120000,\"vendor_id\":\"308\",\"width_microns\":120000},{\"custom_display_name\":\"Letter (Borderless) (8 ½ x 11 in)\",\"height_microns\":288400,\"vendor_id\":\"275\",\"width_microns\":224900},{\"custom_display_name\":\"4 x 6 in (Borderless) (10 x 15 cm)\",\"height_microns\":161400,\"vendor_id\":\"280\",\"width_microns\":110600},{\"custom_display_name\":\"A4 (Borderless) (8.3 x 11.7 in)\",\"height_microns\":306000,\"vendor_id\":\"274\",\"width_microns\":219000},{\"custom_display_name\":\"A6 (Borderless) (4.1 x 5.8 in)\",\"height_microns\":157000,\"vendor_id\":\"276\",\"width_microns\":114000},{\"custom_display_name\":\"3.5 x 5 in (Borderless) (9 x 13 cm)\",\"height_microns\":136000,\"vendor_id\":\"278\",\"width_microns\":97900},{\"custom_display_name\":\"5 x 7 in (Borderless) (13 x 18 cm)\",\"height_microns\":186800,\"vendor_id\":\"279\",\"width_microns\":136000},{\"custom_display_name\":\"5 x 8 in (Borderless) (13 x 20 cm)\",\"height_microns\":212200,\"vendor_id\":\"281\",\"width_microns\":136000}]},\"page_orientation\":{\"option\":[{\"is_default\":true,\"type\":\"PORTRAIT\"},{\"type\":\"LANDSCAPE\"},{\"type\":\"AUTO\"}]},\"supported_content_type\":[{\"content_type\":\"application/pdf\"}]},\"version\":\"1.0\"},\"selectedDestinationName\":\"Brother MFC-J825DW Printer\",\"mediaSize\":{\"custom_display_name\":\"Letter (8 ½ x 11 in)\",\"height_microns\":279400,\"is_default\":true,\"name\":\"NA_LETTER\",\"vendor_id\":\"1\",\"width_microns\":215900},\"selectedDestinationExtensionId\":\"\",\"customMargins\":null,\"vendorOptions\":{},\"selectedDestinationExtensionName\":\"\",\"isColorEnabled\":false,\"isDuplexEnabled\":false}"}},"profile":{"avatar_bubble_tutorial_shown":1,"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{},"geolocation":{},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"https://www.craigslist.org:443,https://www.craigslist.org:443":{"geolocation":2}},"pref_version":1},"default_content_settings":{},"exit_type":"Crashed","exited_cleanly":true,"icon_version":3,"managed_user_id":"","migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"Firstuser","password_manager_groups_for_domains":[2,null,null,null,0,null,4],"per_host_zoom_levels":{}},"protection":{"macs":{}},"savefile":{"default_directory":"C:\\Users\\Sharon\\Desktop","type":1},"selectfile":{"last_directory":"C:\\Users\\Sharon\\Pictures\\2015-05-28"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13041824175471000"},"translate_accepted_count":{"zh-CN":0},"translate_blocked_languages":["en"],"translate_denied_count":{"zh-CN":2},"translate_last_denied_time":1436520533909.51,"translate_whitelists":{},"zerosuggest":{"cachedresults":""}}
 
 
==== Chromium Fix ======================
 
C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx deleted successfully
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_savethelink.org_0.localstorage deleted successfully
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_savethelink.org_0.localstorage-journal deleted successfully
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf deleted successfully
 
==== Set IE to Default ======================
 
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="http://www.google.com"
 
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
 
==== All HKCU SearchScopes ======================
 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
 
==== Deleting Registry Keys ======================
 
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{7095FD27-37F0-4750-9DE8-D37DC0043706} deleted successfully
 
==== Empty IE Cache ======================
 
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Sharon\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
 
==== Empty FireFox Cache ======================
 
C:\Users\Sharon\AppData\Local\Mozilla\Firefox\Profiles\jmphnpxt.default\cache2 emptied successfully
 
==== Empty Chrome Cache ======================
 
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
 
==== Empty All Flash Cache ======================
 
Flash Cache Emptied Successfully
 
==== Empty All Java Cache ======================
 
No Java Cache Found
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=148 folders=29 39043239 bytes)
 
==== Empty Temp Folders ======================
 
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Sharon\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
 
==== After Reboot ======================
 
==== Empty Temp Folders ======================
 
C:\Windows\Temp successfully emptied
C:\Users\Sharon\AppData\Local\Temp successfully emptied
 
==== Empty Recycle Bin ======================
 
C:\$RECYCLE.BIN successfully emptied
 
==== Deleting Files / Folders ======================
 
"C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
 
==== EOF on Thu 07/16/2015 at 21:40:56.09 ======================  

Is just SP1 missing?  I can install them if you like.

Best to wait. I’ll give you that information when we finish here.
 

they do not indicate where I CAN SAVE IT.  iS THERE A WAY i CAN EFFEICIENTLY JUST SAVE IT TO THE desktop

To ensure that all “downloads” are saved to your desktop, you can do the following:

From your logs it would appear that Firefox is the default browser on your computer so let’s set it to save all downloads there:

  • click the "Open Menu" button in the upper-right corner
  • choose Options
  • in the “Downloads” section, click the Browse button
  • click on the Desktop folder and then click the "Select Folder" button
  • click OK to get out of the Options menu.

What do I call the new folder?  It would not let me name the new folder FRST or fixlist.

If you have moved FRST to the desktop there is no need to create a folder; all you need to do is save the “Fixlist.txt” also to the desktop: that way, they will both be saved in the same place.

========================================

Malwarebytes will have produced a log.

Open Malwarebytes, click on the “Logs” tab then double-click on the last log to open it.

Please copy & paste that in together with Fixlog.txt.

Thanks

Satchfan
 

Satchfan,

 

Here are my logs.  Thanks for the download info and clarification on FRST.  One problem was tha t  AVG kept  deleting FRST since it thought it was malware.  I disabled it twice.  It even deleted it after the scan so 3 times all together.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-07-2015
Ran by [removed] (administrator) on HAK-PC on 17-07-2015 03:19:24
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft® Windows Vista™ Home Basic  (X86) OS Language: English (United States)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-07-2015
Ran by [removed] at 2015-07-17 03:20:49
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1992874582-3349113656-4066416677-500 - Administrator - Disabled)
Guest (S-1-5-21-1992874582-3349113656-4066416677-501 - Limited - Disabled)
Sharon (S-1-5-21-1992874582-3349113656-4066416677-1001 - Administrator - Enabled) => C:\Users\Sharon
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
7-Zip 9.20 (HKLM\…\7-Zip) (Version:  - )
Adobe Flash Player 18 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 9 ActiveX (HKLM\…\ShockwaveFlash) (Version: 9 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Atheros Driver Installation Program (HKLM\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.1 - Atheros)
Audacity 2.0.3 (HKLM\…\Audacity_is1) (Version: 2.0.3 - Audacity Team)
AVG 2015 (HKLM\…\AVG) (Version: 2015.0.6081 - AVG Technologies)
AVG 2015 (Version: 15.0.4392 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.6081 - AVG Technologies) Hidden
AVG PC TuneUp 2014 (en-US) (Version: 14.0.1001.519 - AVG) Hidden
AVG PC TuneUp 2014 (HKLM\…\AVG PC TuneUp) (Version: 14.0.1001.519 - AVG)
AVG PC TuneUp 2014 (Version: 14.0.1001.519 - AVG) Hidden
BufferChm (Version: 82.0.173.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.07 - Piriform)
Citrix Online Launcher (HKLM\…\{C57F6C71-C365-4AFF-9108-397BBAD6127F}) (Version: 1.0.204 - Citrix)
Copy (Version: 82.0.188.000 - Hewlett-Packard) Hidden
CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Destinations (Version: 82.0.173.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
DocProc (Version: 8.1.0.0 - Hewlett-Packard) Hidden
DocProcQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Elementary Education: Content Knowledge Practice Test (HKLM\…\{0AED2370-A4CD-4D5A-A6FA-32DE353DAE4C}) (Version: 2.0 - Educational Testing Service)
Emsisoft Anti-Malware (HKLM\…\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 10.0 - Emsisoft Ltd.)
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Freemake Video Converter version 4.0.1 (HKLM\…\Freemake Video Converter_is1) (Version: 4.0.1 - Ellora Assets Corporation)
Freemake Video Downloader (HKLM\…\Freemake Video Downloader_is1) (Version: 3.5.0 - Ellora Assets Corporation)
FreeScreenSharing (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\FreeScreenSharing) (Version: 0.56.21.0 - Free Conferencing Corporation)
Google Chrome (HKLM\…\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Talk Plugin (HKLM\…\{CA3DD97D-1FD7-37A7-BD5C-FC4430C8B8E6}) (Version: 5.41.2.0 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
GoToMeeting 7.2.3.3019 (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\GoToMeeting) (Version: 7.2.3.3019 - CitrixOnline)
HP Customer Experience Enhancements (HKLM\…\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}) (Version: 5.1.0.2264 - Hewlett-Packard)
HP Customer Participation Program 8.0 (HKLM\…\HPExtendedCapabilities) (Version: 8.0 - HP)
HP Easy Setup - Frontend (HKLM\…\{40F7AED3-0C7D-4582-99F6-484A515C73F2}) (Version: 5.1.0.2269 - Hewlett-Packard)
HP Imaging Device Functions 8.0 (HKLM\…\HP Imaging Device Functions) (Version: 8.0 - HP)
HP OCR Software 8.0 (HKLM\…\HPOCR) (Version: 8.0 - HP)
HP OFFICEJET 6210 Driver Utility (HKLM\…\HP OFFICEJET 6210 Driver Utility_is1) (Version:  - Lavians Inc.)
HP Photosmart Essential (HKLM\…\{EB21A812-671B-4D08-B974-2A347F0D8F70}) (Version: 1.12.0.46 - HP)
HP Photosmart Essential 2.0 (HKLM\…\HP Photosmart Essential) (Version: 2.0 - HP)
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B (HKLM\…\{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}) (Version: 8.0 - HP)
HP Solution Center 8.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 8.0 - HP)
HP Update (HKLM\…\{8C6027FD-53DC-446D-BB75-CACD7028A134}) (Version: 4.000.005.005 - Hewlett-Packard)
HPProductAssistant (Version: 82.0.173.000 - Hewlett-Packard) Hidden
HPSSupply (HKLM\…\{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}) (Version: 2.1.3.0000 - Hewlett Packard Development Company L.P.)
Image Resizer for Windows (HKLM\…\{69d72156-6582-4556-8637-06f40aa7f85b}) (Version: 3.0.4802.35565 - Brice Lambson)
Image Resizer for Windows (Version: 3.0.4802.35565 - Brice Lambson) Hidden
LightScribe  1.4.142.1 (Version: 1.4.142.1 - http://www.lightscribe.com)Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
MarketResearch (Version: 82.0.174.000 - Hewlett-Packard) Hidden
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\…\HOMESTUDENTR) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\…\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
Mozilla Firefox 39.0 (x86 en-US) (HKLM\…\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 39.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM\…\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
muvee autoProducer 6.0 (HKLM\…\{6AF49698-949A-4C89-9B31-041D2CCB5FBD}) (Version: 6.00.050 - muvee Technologies)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version:  - )
OLYMPUS Master 2 (HKLM\…\{45FCADDB-0B29-457E-83A1-D245C62A716C}) (Version: 1.0.6 - OLYMPUS IMAGING CORP.)
OLYMPUS muvee theaterPack (HKLM\…\{B3282FB8-874B-4054-8356-9EB391A826F9}) (Version: 1.0.4 - OLYMPUS IMAGING CORP.)
OpenOffice.org 3.4.1 (HKLM\…\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)
Picasa 3 (HKLM\…\Picasa 3) (Version: 3.9 - Google, Inc.)
PSSWCORE (Version: 2.00.5000 - Hewlett-Packard) Hidden
Python 2.4.3 (HKLM\…\{75E71ADD-042C-4F30-BFAC-A9EC42351313}) (Version: 2.4.3150 - Martin v. Löwis)
QuickTime (HKLM\…\{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}) (Version: 7.1.3.100 - Apple Computer, Inc.)
RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM\…\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5377 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Rhapsody Player Engine (HKLM\…\{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}) (Version: 1.0.604 - RealNetworks)
Roxio Creator Audio (HKLM\…\{83FFCFC7-88C6-41c6-8752-958A45325C82}) (Version: 3.4.0 - Roxio)
Roxio Creator Basic v9 (HKLM\…\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}) (Version: 3.4.0 - Roxio)
Roxio Creator Copy (HKLM\…\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.4.0 - Roxio)
Roxio Creator Data (HKLM\…\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.4.0 - Roxio)
Roxio Creator EasyArchive (HKLM\…\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}) (Version: 3.4.0 - Roxio)
Roxio Creator Tools (HKLM\…\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.4.0 - Roxio)
Roxio Express Labeler 3 (HKLM\…\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 3.2.1 - Roxio)
Roxio MyDVD Basic v9 (HKLM\…\{938B1CD7-7C60-491E-AA90-1F1888168240}) (Version: 9.0.559 - Roxio)
Skype Click to Call (HKLM\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 7.1 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Snapfish Media Detector (HKLM\…\{4EF6FDB0-3B11-4820-9860-8E08E9965195}) (Version: 1.7.0.15 - HP Snapfish)
SolutionCenter (Version: 82.0.188.000 - Hewlett-Packard) Hidden
Status (Version: 82.0.173.000 - Hewlett-Packard) Hidden
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1014 - SUPERAntiSpyware.com)
TrayApp (Version: 82.0.188.000 - Hewlett-Packard) Hidden
TrojanHunter 6.0 (HKLM\…\TrojanHunter_is1) (Version: 6.0 - Bytelayer AB)
Visual Studio 2012 x86 Redistributables (HKLM\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 1.1.9 (HKLM\…\VLC media player) (Version: 1.1.9 - VideoLAN)
WebEx Event Manager for Firefox or Chrome (HKLM\…\{06B5988F-EBA6-4802-9F7B-4FB471291321}) (Version: 28.7.0.15458 - Cisco WebEx LLC)
Windows 7 Upgrade Advisor (HKLM\…\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation)
WinPcap 4.1.2 (HKLM\…\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
Youtube Downloader HD v. 2.9.6 (HKLM\…\Youtube Downloader HD_is1) (Version:  - YoutubeDownloaderHD.com)
Zoom (HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\ZoomUMX) (Version: 3.5 - Zoom Video Communications, Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{39125640-8D80-11DC-A2FE-C5C455D89593}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Google Talk Plugin\googletalkax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\1440\G2MOutlookAddin.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{AB9F4455-E591-4132-A386-0B91EAEDB96C}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Google Talk Plugin\o1dax.dll (Google)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.26.9\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\psuser.dll (Google Inc.)
 
==================== Restore Points =========================
 
01-07-2015 12:42:58 Windows Update
02-07-2015 12:02:26 Scheduled Checkpoint
03-07-2015 11:44:40 Scheduled Checkpoint
04-07-2015 11:57:52 Scheduled Checkpoint
05-07-2015 00:00:05 Scheduled Checkpoint
05-07-2015 16:42:42 Scheduled Checkpoint
08-07-2015 22:24:40 Scheduled Checkpoint
13-07-2015 03:04:14 Scheduled Checkpoint
16-07-2015 03:01:38 Windows Update
16-07-2015 19:55:08 Scheduled Checkpoint
16-07-2015 20:40:45 zoek.exe restore point
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 02:23 - 2006-09-18 13:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {02B1C58A-086C-4ED9-B993-C6450A1DBC27} - System32\Tasks\Registration => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-03-05] ()
Task: {1B6DBECF-3A87-479C-9AEE-97A6A053F36F} - System32\Tasks\HP online update program => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10] (Hewlett-Packard Co.)
Task: {2406BCAB-604C-46CC-8541-B7A1BE9F6CF2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-27] (Google Inc.)
Task: {2A42CD5F-56F8-4BF2-9DCB-4539B8A920A8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-04-27] (Google Inc.)
Task: {5DCB035D-4B45-4509-A148-84B06314AD4B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-14] (Adobe Systems Incorporated)
Task: {63C8F07F-D02D-4EBD-8DBE-2194C65FAA96} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {76748A9F-364C-4BA3-A180-A8A9E65E30AC} - System32\Tasks\Real Player online update program => C:\Program Files\Real\RealPlayer\update\realsched.exe [2013-10-12] (RealNetworks, Inc.)
Task: {A6977348-A03B-45E1-BB2C-CD4C13F04918} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Sharon => C:\Program Files\Windows Calendar\WinCal.exe [2007-06-26] (Microsoft Corporation)
Task: {AFF35159-F6E9-49C8-8CA7-9669E9B18DCC} - System32\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupdate.exe [2015-07-09] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {C37BA6B1-ADD5-4F04-A7B0-04BEB36E59A2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-10] (Google Inc.)
Task: {D42CA714-CB4E-4AA5-BC29-026CAF953660} - System32\Tasks\IntenetServiceOffers => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-03-05] ()
Task: {D5B4D35F-5815-451D-9D4A-CA951A9A7186} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-06-01] (Piriform Ltd)
Task: {E29A3170-0CD7-46E7-8DD5-DAC5DB3B337A} - System32\Tasks\Adobe online update program => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {EED84F28-F38A-4C31-8D42-E093B56E74A5} - System32\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupload.exe [2015-07-09] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {F9011493-B85D-4B2F-BD39-CDF7FE8536A8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-10] (Google Inc.)
Task: {FA63882F-4A5A-4C97-9855-5D7FA1F9709A} - System32\Tasks\{3092C782-E801-4022-8631-A592DFCCADB7} => pcalua.exe -a "C:\Program Files\QuickTime\QTSystem\QuickTime.cpl" -c @0,0x63737064
Task: {FA71853D-E21F-45D1-A4BB-7D16CF8065F6} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1992874582-3349113656-4066416677-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {FC86BC9D-A39B-4C5F-A3E6-D9E2CFB5D088} - \OptimusNitro_Start No Task File <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job => C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupload.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-07-14 02:26 - 2014-07-14 02:26 - 00585528 _____ () C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll
2014-07-14 02:26 - 2014-07-14 02:26 - 00357176 _____ () C:\Program Files\AVG\AVG PC TuneUp\tuavgx.dll
2014-07-14 10:07 - 2014-02-10 13:44 - 04592128 _____ () C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
2014-07-14 10:07 - 2014-02-10 13:44 - 00112128 _____ () C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll
2015-07-14 05:33 - 2015-07-13 13:55 - 16308040 _____ () C:\Program Files\Google\Chrome\Application\43.0.2357.134\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Sharon\Pictures\p.3 joy.jpg
DNS Servers: 192.168.2.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk => C:\Windows\pss\OpenOffice.org 3.4.1.lnk.Startup
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: emsisoft anti-malware => "c:\program files\emsisoft anti-malware\a2guard.exe" /d=60
MSCONFIG\startupreg: FreeScreenSharing => "C:\Users\Sharon\AppData\Local\FreeScreenSharing\FreeScreenSharing.exe"
MSCONFIG\startupreg: Google Update => "C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: OM2_Monitor => "C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: THGuard => "C:\Program Files\TrojanHunter\THGuard.exe"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{C39C9369-DF78-4BA3-B71E-AAEBCCC33157}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{E6281A08-83AE-4E62-8A1A-2C189B8D1BE7}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{21C042E9-8F4D-4046-980E-4F45283AC8F2}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{61D8597E-437D-43DD-89CC-62F487F13081}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{CFE6DE30-FE46-4C60-B0B7-09C12C3214F0}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{B82921CB-E57D-4E9E-AADF-71E261A9A6FC}] => (Allow) C:\Program Files\earthlink totalaccess\TaskPanl.exe
FirewallRules: [{9434D6F6-9325-449C-83A6-688A78CD132F}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{5CDBFFA3-A48D-4445-88DC-6D5364623797}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{3EF2AD33-05C0-4EFB-8F08-EC2B6BBC3FE7}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{C160F25F-0B64-4732-8263-97D07C2E73EB}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{0C16FA18-D5B1-4409-ACDA-1C3308C7BD9D}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{16B9DCCF-ECA7-481C-8CF0-D9E749F23A52}] => (Allow) C:\Program Files\AVG\AVG2015\avgnsx.exe
FirewallRules: [{7D687C39-533C-4B68-9896-282F2C63A60C}] => (Allow) C:\Program Files\AVG\AVG2015\avgnsx.exe
FirewallRules: [{3C94EE9E-A0CA-484C-B082-936FB1DDFC81}] => (Allow) C:\Program Files\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{43A2EA19-F75D-4B68-AFEB-BF94D6A9FD6D}] => (Allow) C:\Program Files\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{94E3137F-E0E6-4D52-A88E-624EBD131210}] => (Allow) C:\Program Files\AVG\AVG2015\avgemcx.exe
FirewallRules: [{7C10B454-7729-4ECA-B09B-5E121653AA86}] => (Allow) C:\Program Files\AVG\AVG2015\avgemcx.exe
FirewallRules: [{4839C1AC-5CD7-4C77-87DF-1A41AE07EE0D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe] => Enabled:Earthlink
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/16/2015 09:42:10 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (07/16/2015 09:42:10 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (07/16/2015 03:30:24 AM) (Source: usbperf) (EventID: 2004) (User: )
Description: Usbperf data collection failed. Collect function called with usupported Query Type.
 
Error: (07/16/2015 03:24:30 AM) (Source: usbperf) (EventID: 2004) (User: )
Description: Usbperf data collection failed. Collect function called with usupported Query Type.
 
Error: (07/16/2015 03:22:10 AM) (Source: usbperf) (EventID: 2004) (User: )
Description: Usbperf data collection failed. Collect function called with usupported Query Type.
 
Error: (07/16/2015 03:21:56 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4
 
Error: (07/16/2015 03:21:53 AM) (Source: Perflib) (EventID: 1010) (User: )
Description: EmdCacheC:\Windows\system32\emdmgmt.dll4
 
Error: (07/16/2015 03:21:52 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: DFSRC:\Windows\System32\DfsrPerf.dll4
 
Error: (07/15/2015 09:17:33 AM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
 
Error: (07/15/2015 07:17:35 AM) (Source: Software Licensing Service) (EventID: 8193) (User: )
Description: License Activation Scheduler (SLUINotify.dll) failed with the following error code:
0xC004D401
 
 
System errors:
=============
Error: (07/16/2015 09:38:54 PM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 11, function 0.
Please contact your system vendor for technical assistance.
 
Error: (07/16/2015 09:38:54 PM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 9, function 0.
Please contact your system vendor for technical assistance.
 
Error: (07/16/2015 09:16:15 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
 
Error: (07/16/2015 09:16:14 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
 
Error: (07/16/2015 09:16:13 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
 
Error: (07/16/2015 09:16:12 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
 
Error: (07/16/2015 09:16:10 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
 
Error: (07/16/2015 08:33:05 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: i8042prt
 
Error: (07/16/2015 08:33:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
 
Error: (07/16/2015 08:31:28 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:28:06 PM on 7/16/2015 was unexpected.
 
 
Microsoft Office:
=========================
Error: (04/19/2015 10:43:02 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20499 seconds with 120 seconds of active time.  This session ended with a crash.
 
Error: (04/17/2015 10:53:03 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2093 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (09/12/2014 08:49:26 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 516 seconds with 0 seconds of active time.  This session ended with a crash.
 
Error: (09/05/2012 11:47:41 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 322286 seconds with 720 seconds of active time.  This session ended with a crash.
 
 
CodeIntegrity Errors:
===================================
  Date: 2015-07-17 03:20:35.548
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-17 03:20:35.505
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-17 03:20:35.462
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-17 03:20:35.420
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-17 03:20:35.176
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-17 03:20:35.131
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-17 03:20:35.087
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-17 03:20:35.014
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-17 03:20:34.401
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-07-17 03:20:34.356
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ 64 X2 Dual Core Processor 3600+
Percentage of memory in use: 88%
Total physical RAM: 1917.94 MB
Available physical RAM: 217.61 MB
Total Virtual: 4073.09 MB
Available Virtual: 1029.62 MB
 
==================== Drives ================================
 
Drive c: (COMPAQ) (Fixed) (Total:140.67 GB) (Free:89.62 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Recovery) (Fixed) (Total:8.38 GB) (Free:1.01 GB) NTFS ==>[system with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 149.1 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=140.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=8.4 GB) - (Type=07 NTFS)
 
==================== End of log ============================
 
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 7/16/2015
Scan Time: 4:08:40 PM
Logfile: 
Administrator: Yes
 
Version: 2.1.8.1057
Malware Database: v2015.07.16.05
Rootkit Database: v2015.07.16.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows Vista
CPU: x86
File System: NTFS
User: Sharon
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 309988
Time Elapsed: 21 min, 24 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

Well done on working that out but you sent the wrong Farbar log, (which was also incomplete).

I need to see the “fixlog” which will be on your Desktop (Fixlog.txt).

Thanks

Sorry about that.   There is a file called FRST-Notepad.  At the end it says  "End of log".  I will send this.

 

Thanks

GB

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-07-2015
Ran by [removed] (administrator) on HAK-PC on 17-07-2015 03:19:24
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft® Windows Vista™ Home Basic  (X86) OS Language: English (United States)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
(Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe
(Realtek Semiconductor) C:\WINDOWS\RtHDVCpl.exe
(Microsoft Corporation) C:\WINDOWS\System32\mobsync.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe
(Google Inc.) C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe
(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-01-16] (Microsoft Corporation)
HKLM\…\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2006-09-28] (Hewlett-Packard Company)
HKLM\…\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4390912 2007-03-01] (Realtek Semiconductor)
HKLM\…\Run: [SnapfishMediaDetector] => C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe [1441792 2007-03-02] ()
HKLM\…\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3730344 2015-06-30] (AVG Technologies CZ, s.r.o.)
HKLM\…\Run: [MSConfig] => C:\Windows\system32\msconfig.exe [222208 2006-11-02] (Microsoft Corporation)
HKLM\…\RunOnce: [Launcher] => C:\Windows\SMINST\launcher.exe [44168 2007-03-07] (soft thinks)
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\Run: [Google Update] => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-05-10] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk [2007-05-10]
ShortcutTarget: Snapfish Media Detector.lnk -> C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-18] (SuperAdBlocker.com)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{003F1CAB-9582-432A-976B-A5B40F8B2472}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{015EC064-039A-44FB-930A-94C209392E85}: [DhcpNameServer] 192.168.2.1
 
FireFox:
========
FF ProfilePath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2013-10-12] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-10-12] (RealPlayer)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Sharon\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-07-27] (Citrix Online)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/O1DPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Sharon\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2015-03-17] (Zoom Video Communications, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npatgpc.dll [2012-10-29] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF SearchPlugin: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\searchplugins\amazon-distro.xml [2012-12-13]
FF Extension: adblockvideo - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2012-09-15]
FF Extension: feedly - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2013-05-10]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2012-12-12]
FF Extension: Adblock Plus - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-15]
FF Extension: User Agent Switcher - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2013-05-06]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Video Downloader Plugin - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Youtube Download Button - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-05-20]
FF HKLM\…\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-10-12]
FF HKLM\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
 
Chrome: 
=======
CHR Profile: C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (RealDownloader) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-04-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-21]
CHR Extension: (Skype Click to Call) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-09-01]
CHR Extension: (Google Wallet) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-13]
CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-29] (SUPERAntiSpyware.com)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [5509384 2015-07-08] (Emsisoft Ltd)
S2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3518376 2015-06-30] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [314304 2015-06-30] (AVG Technologies CZ, s.r.o.)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-04-25] (Freemake) [File not signed]
S3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-13] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 LightScribeService; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [1858360 2014-07-14] (AVG)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [35640 2014-07-14] (AVG)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [265912 2007-01-16] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [132576 2015-03-11] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [231856 2015-06-26] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [190944 2015-05-12] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [29664 2015-05-14] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [207328 2015-06-16] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [290272 2015-05-07] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [170464 2015-06-10] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [35808 2015-03-20] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [213984 2015-05-12] (AVG Technologies CZ, s.r.o.)
R1 epp32; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp32.sys [112408 2015-07-08] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2014-02-10] (TuneUp Software)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-17 03:19 - 2015-07-17 03:20 - 00019334 _____ C:\Users\Sharon\Desktop\FRST.txt
2015-07-17 03:18 - 2015-07-17 03:18 - 01636864 _____ (Farbar) C:\Users\Sharon\Desktop\FRST.exe
2015-07-17 03:00 - 2015-07-17 03:00 - 01636864 _____ (Farbar) C:\Users\Sharon\Downloads\FRST.exe
2015-07-17 02:55 - 2015-07-17 02:55 - 00000377 _____ C:\Users\Sharon\Desktop\fixlist.txt
2015-07-16 21:26 - 2015-07-16 20:37 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-16 20:40 - 2015-07-16 21:40 - 00021621 _____ C:\zoek-results.log
2015-07-16 20:36 - 2015-07-16 20:36 - 01308672 _____ C:\Users\Sharon\Desktop\zoek.exe
2015-07-16 20:31 - 2015-07-16 21:39 - 00001048 _____ C:\Windows\PFRO.log
2015-07-16 20:26 - 2015-07-16 20:26 - 01308672 _____ C:\Users\Sharon\Downloads\zoek (1).exe
2015-07-16 20:25 - 2015-07-16 21:20 - 00000000 ____D C:\zoek_backup
2015-07-16 20:24 - 2015-07-16 20:24 - 01308672 _____ C:\Users\Sharon\Desktop\zoek (1).exe
2015-07-16 20:08 - 2015-07-16 20:09 - 01308672 _____ C:\Users\Sharon\Downloads\zoek.exe
2015-07-16 14:38 - 2015-07-16 14:39 - 00000000 ____D C:\Users\Sharon\Desktop\New Folder
2015-07-14 05:39 - 2015-07-14 05:41 - 00034963 _____ C:\Users\Sharon\Downloads\Addition.txt
2015-07-14 05:35 - 2015-07-17 03:19 - 00000000 ____D C:\FRST
2015-07-13 10:24 - 2015-07-13 10:24 - 00000296 _____ C:\Windows\system32\spsys.log
2015-07-13 02:35 - 2015-07-13 02:35 - 00003121 _____ C:\Users\Sharon\Desktop\JRT.txt
2015-07-13 02:22 - 2015-07-13 02:22 - 00000207 _____ C:\Windows\tweaking.com-regbackup-HAK-PC-Windows-Vista-(TM)-Home-Basic-(32-bit).dat
2015-07-13 02:21 - 2015-07-13 02:21 - 00000000 ____D C:\RegBackup
2015-07-13 02:19 - 2015-07-13 02:19 - 00009208 _____ C:\Users\Sharon\Desktop\AdwCleaner[S0].txt
2015-07-13 02:16 - 2015-07-13 02:17 - 03034492 _____ (Malwarebytes Corporation) C:\Users\Sharon\Downloads\JRT.exe
2015-07-13 02:14 - 2015-07-13 02:14 - 00000000 ____D C:\Windows\pss
2015-07-13 02:00 - 2015-07-13 02:05 - 00000000 ____D C:\AdwCleaner
2015-07-13 01:58 - 2015-07-13 01:59 - 02248704 _____ C:\Users\Sharon\Downloads\adwcleaner_4.208.exe
2015-07-12 11:15 - 2015-07-12 11:15 - 00010182 _____ C:\Users\Sharon\Downloads\hijackthis.log
2015-07-12 11:14 - 2015-07-12 11:14 - 00388608 _____ (Trend Micro Inc.) C:\Users\Sharon\Downloads\HiJackThis.exe
2015-07-10 03:41 - 2015-07-10 03:41 - 00027329 _____ C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!.html
2015-07-10 03:41 - 2015-07-10 03:41 - 00000000 ____D C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!_files
2015-07-08 16:22 - 2015-07-12 11:21 - 00001356 _____ C:\Users\Sharon\AppData\Local\d3d9caps.dat
2015-07-08 14:46 - 2015-07-17 01:43 - 00332859 _____ C:\Windows\WindowsUpdate.log
2015-07-07 10:56 - 2015-07-07 10:56 - 00000810 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\Program Files\CCleaner
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507.exe
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507 (1).exe
2015-07-07 01:38 - 2015-07-07 01:44 - 00000000 ____D C:\ProgramData\Emsisoft
2015-07-07 01:10 - 2015-07-07 01:11 - 00000000 ____D C:\Program Files\TrojanHunter
2015-07-07 01:10 - 2015-07-07 01:10 - 00000858 _____ C:\Users\Sharon\Desktop\TrojanHunter.lnk
2015-07-07 01:10 - 2015-07-07 01:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
2015-07-07 01:09 - 2015-07-07 01:09 - 04069672 _____ (Bytelayer AB ) C:\Users\Sharon\Downloads\TrojanHunterSetup.exe
2015-07-06 17:15 - 2015-07-06 17:15 - 00000894 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2015-07-06 17:15 - 2015-07-06 17:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2015-07-06 17:14 - 2015-03-24 00:17 - 00111368 _____ (Emsisoft GmbH) C:\Windows\system32\Drivers\epp32.sys
2015-07-06 17:13 - 2015-07-17 02:26 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2015-07-06 16:13 - 2015-07-06 16:30 - 167273960 _____ (Emsisoft Ltd. ) C:\Users\Sharon\Downloads\EmsisoftAntiMalwareSetup.exe
2015-07-05 12:46 - 2015-07-05 12:46 - 00242712 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 39.0.exe
2015-07-05 10:22 - 2015-07-05 10:26 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Sharon\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-07-03 14:20 - 2015-07-03 14:20 - 01125056 _____ (Adobe Systems Incorporated) C:\Users\Sharon\Downloads\flashplayer18_ha_install.exe
2015-07-02 13:55 - 2015-07-02 13:55 - 00243408 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 38.0.5.exe
2015-06-30 12:25 - 2015-07-05 14:17 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-06-26 09:49 - 2015-06-26 09:49 - 00231856 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdriverx.sys
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-17 03:18 - 2012-10-18 13:49 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-17 03:16 - 2015-05-10 16:53 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job
2015-07-17 02:39 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-17 02:39 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-17 02:31 - 2014-07-27 15:41 - 00000568 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-17 02:29 - 2013-04-27 03:03 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-17 01:53 - 2015-05-30 13:19 - 00000664 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-16 21:41 - 2007-05-10 11:27 - 00000000 ____D C:\Windows\SMINST
2015-07-16 21:40 - 2013-02-18 13:09 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-07-16 21:39 - 2013-04-27 03:03 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-16 21:39 - 2006-11-02 04:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-16 21:38 - 2006-11-02 04:58 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-07-16 21:16 - 2006-11-02 03:18 - 00000000 ___RD C:\Users\Public
2015-07-16 21:16 - 2006-11-02 03:18 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-07-16 20:31 - 2015-05-10 16:53 - 00000860 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job
2015-07-16 18:34 - 2012-07-09 10:00 - 00000000 ____D C:\ProgramData\MFAData
2015-07-16 16:08 - 2014-04-11 17:05 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-16 03:22 - 2013-07-14 19:21 - 00000000 ____D C:\Windows\system32\MRT
2015-07-14 23:47 - 2012-07-08 00:30 - 00000000 ____D C:\Users\Sharon\AppData\Roaming\Skype
2015-07-14 21:20 - 2012-07-08 00:19 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-14 21:20 - 2012-07-08 00:19 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-09 11:53 - 2014-11-04 14:36 - 00000848 _____ C:\Users\Public\Desktop\AVG 2015.lnk
2015-07-09 11:53 - 2014-03-31 14:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-07-08 15:04 - 2013-05-06 08:20 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-07 11:00 - 2012-07-17 15:02 - 00000000 ____D C:\Windows\Minidump
2015-07-07 11:00 - 2007-05-10 11:06 - 00000000 ____D C:\Windows\Panther
2015-07-07 01:25 - 2012-06-06 18:33 - 00000000 ____D C:\Users\Sharon\AppData\Local\VirtualStore
2015-07-05 14:17 - 2013-03-09 15:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-07-05 14:16 - 2006-11-02 04:35 - 00000000 ____D C:\Windows\DigitalLocker
2015-07-05 12:50 - 2013-03-09 15:52 - 00000864 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-05 12:50 - 2013-03-09 15:52 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-05 10:30 - 2014-04-11 17:02 - 00000905 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-07-03 08:49 - 2006-11-02 02:24 - 127070192 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-07-01 12:53 - 2014-04-14 12:13 - 00000000 ____D C:\Users\Sharon\AppData\Local\AVG
2015-06-18 08:41 - 2014-04-11 17:02 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-18 08:41 - 2014-04-11 17:02 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-18 08:41 - 2013-05-04 07:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
 
==================== Files in the root of some directories =======
 
2013-05-21 03:10 - 2014-01-30 13:39 - 0003736 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
2015-07-08 16:22 - 2015-07-12 11:21 - 0001356 _____ () C:\Users\Sharon\AppData\Local\d3d9caps.dat
2012-07-08 02:19 - 2015-05-06 19:35 - 0025088 _____ () C:\Users\Sharon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2007-05-10 10:43 - 2013-03-21 07:29 - 0002738 _____ () C:\ProgramData\hpzinstall.log
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-16 21:45
 
==================== End of log ============================

That was not what I asked for but what you sent looks good, means that it was done successfully.

 

Let’s run an online scan to be sure nothing is left. If that’s clear and you have no further problems I’ll send instructions to tidy up.


Run ESET Online Scan

Note: This may take a long time so please be patient.

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use Internet Explorer, FireFox or  Chrome for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan

  • click the Eset online Scanner button
  • for alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


    o    click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
    o    double click on the Eset installer icon on your desktop.
     

  • check Yes, I accept the Terms of Use
  • click the Start button
  • accept any security warnings from your browser
  • check Enable detection of potentially unwanted applications
  • click Advanced settings and select the following:


    o    scan archives
    o    scan for potentially unsafe applications
    o    enable Anti-Stealth technology


    Note: Do not check Remove found threats
     

  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • when the scan completes, push List of found threats
  • push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.


    Note - if ESET doesn't find any threats, no report will be created.

  • push the back button.
  • push Finish

When the scan is complete:

If no threats were found:
 


o    put a checkmark in "Uninstall application on close"
o    close program
o    report to me that nothing was found

If threats were found:




o    click on "list of threats found"
o    click on "export to text file" and save it as ESET results and save to the desktop
o    Click on back
o    put a checkmark in "Uninstall application on close"
o    click on finish
o    close program
o    copy and paste the report here.

Thanks

Satchfan

 

C:\Program Files\HP OFFICEJET 6210 Driver Utility\driverlib.dll Win32/DriverBoss.B potentially unwanted application
C:\Users\Sharon\Downloads\ccsetup507 (1).exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\Sharon\Downloads\ccsetup507.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\Sharon\Downloads\FreemakeVideoDownloader_3.5.0.7.exe Win32/OpenCandy potentially unsafe application
C:\Users\Sharon\Downloads\hp-officejet-6210-driver-utility.exe Win32/DriverBoss.B potentially unwanted application
C:\Users\Sharon\Downloads\HSS-3.42-install-e-680-plain.exe Win32/Bundled.Toolbar.Ask.L potentially unsafe application
C:\Users\Sharon\Downloads\OptimusNitroSetup.exe a variant of MSIL/Rebrand.LittleRegClean.E potentially unwanted application
C:\Users\Sharon\Downloads\youtube_downloader_hd_setup.exe Win32/OpenCandy potentially unsafe application

We’ll clear up what was found by the scan and then I’d like one last look.

==============================================

Please copy all text in the code box below and paste it into Notepad:

@echo off
del /f /s /q "C:\Program Files\HP OFFICEJET 6210 Driver Utility\driverlib.dll”
del /f /s /q "C:\Users\Sharon\Downloads\ccsetup507 (1).exe”
del /f /s /q "C:\Users\Sharon\Downloads\ccsetup507.exe”
del /f /s /q "C:\Users\Sharon\Downloads\FreemakeVideoDownloader_3.5.0.7.exe”
del /f /s /q "C:\Users\Sharon\Downloads\hp-officejet-6210-driver-utility.exe”
del /f /s /q "C:\Users\Sharon\Downloads\HSS-3.42-install-e-680-plain.exe”
del /f /s /q "C:\Users\Sharon\Downloads\OptimusNitroSetup.exe”
del /f /s /q "C:\Users\Sharon\Downloads\youtube_downloader_hd_setup.exe”
del %0
  • save the Notepad file to your desktop and name it delfiles.bat
  • save type as "All Files"
  • on your desktop, double-click on delfiles.bat to run it, (a black CMD window will flash, then disappear - this is normal).

The files/folders, if found, will have been deleted and the "delfile.bat" file will also be deleted.


Please run FRST again and send the new log.

Thanks

Satchfan

 

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI