This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer slow [Solved]

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

We're getting there. :)

 

 

I went to another website that I thought was reputable and downloaded what I thought was FRST

You should not have downloaded from anywhere except the sites I gave you links to, (but I think you know that now). Can you remember which site it was?


Uninstall programs

Please uninstall any AVG product left on your computer.

  • click Start, Control Panel, Programs and Features
  • click on AVG PC TuneUp 2014 and then Uninstall
  • repeat this for any other AVG entry.

If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

================================================

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.


CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\1440\G2MOutlookAddin.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.26.9\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> No Filepath
Task: {09F713C9-DD9B-446B-A2F3-0C4F27A5D403} - System32\Tasks\Validate Installation => C:\Program Files\user extensions\updater.exe [2015-07-21] () <==== ATTENTION
Task: {70150072-3745-4970-92F2-319F581F5B89} - System32\Tasks\One System Care Monitor => C:\Program Files\OneSystemCare\CleanupConsole.exe
Task: {D19CEAE8-8D50-43AA-BE02-9BD931893253} - System32\Tasks\One System CarePeriod => C:\Program Files\OneSystemCare\OneSystemCare.exe
Task: {DFF5F404-E5D1-4C9B-A6DF-AD7A86B8B840} - System32\Tasks\GeniusBox => cmd.exe /C start "" "C:\Program Files\user extensions\client.exe" <==== ATTENTION
Task: {E37A6FDD-D5C9-4E94-B251-B372F6A2DCFE} - System32\Tasks\One System Care Run Delay => C:\Program Files\OneSystemCare\OneSystemCare.exe
Task: {F49EF02D-3499-4122-A306-8768A7A6322E} - System32\Tasks\Check Updates => C:\Program Files\user extensions\updater.exe [2015-07-21] () <==== ATTENTION
Task: {FC86BC9D-A39B-4C5F-A3E6-D9E2CFB5D088} - \OptimusNitro_Start No Task File <==== ATTENTION
2014-07-14 02:26 - 2014-07-14 02:26 - 00585528 _____ () C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll
2014-07-14 02:26 - 2014-07-14 02:26 - 00357176 _____ () C:\Program Files\AVG\AVG PC TuneUp\tuavgx.dll
2015-07-21 03:54 - 2015-07-21 03:54 - 00076800 _____ () C:\Program Files\user extensions\Client.exe
FirewallRules: [{4F4D0146-ADF9-4BA9-B769-B9BE6A194012}] => (Allow) C:\Program Files\PremierOpinion\pmropn.exe
FirewallRules: [{976E81F9-33D6-45A9-905C-63E8E6B78923}] => (Allow) C:\Program Files\PremierOpinion\pmropn.exe
C:\Program Files\OneSystemCare\CleanupConsole.exe
C:\Program Files\AVG
C:\Program Files\user extensions\Client.exe
C:\Program Files\PremierOpinion

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

================================================

Please run AdwCleaner again and FRST again and send the new log..

Logs to include in the next post:

Fixlog.txt
New AdwCleaner log
New FRST log


Thanks

Satchfan

 

I don't remember which site I downloaded it.  I will try to look it up again.
 
GB
 
Fix result of Farbar Recovery Scan Tool (x86) Version: 20-07-2015
Ran by [removed] at 2015-07-22 02:40:03 Run:3
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
 
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\1440\G2MOutlookAddin.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.26.9\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> No Filepath
Task: {09F713C9-DD9B-446B-A2F3-0C4F27A5D403} - System32\Tasks\Validate Installation => C:\Program Files\user extensions\updater.exe [2015-07-21] () <==== ATTENTION
Task: {70150072-3745-4970-92F2-319F581F5B89} - System32\Tasks\One System Care Monitor => C:\Program Files\OneSystemCare\CleanupConsole.exe
Task: {D19CEAE8-8D50-43AA-BE02-9BD931893253} - System32\Tasks\One System CarePeriod => C:\Program Files\OneSystemCare\OneSystemCare.exe
Task: {DFF5F404-E5D1-4C9B-A6DF-AD7A86B8B840} - System32\Tasks\GeniusBox => cmd.exe /C start "" "C:\Program Files\user extensions\client.exe" <==== ATTENTION
Task: {E37A6FDD-D5C9-4E94-B251-B372F6A2DCFE} - System32\Tasks\One System Care Run Delay => C:\Program Files\OneSystemCare\OneSystemCare.exe
Task: {F49EF02D-3499-4122-A306-8768A7A6322E} - System32\Tasks\Check Updates => C:\Program Files\user extensions\updater.exe [2015-07-21] () <==== ATTENTION
Task: {FC86BC9D-A39B-4C5F-A3E6-D9E2CFB5D088} - \OptimusNitro_Start No Task File <==== ATTENTION
2014-07-14 02:26 - 2014-07-14 02:26 - 00585528 _____ () C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll
2014-07-14 02:26 - 2014-07-14 02:26 - 00357176 _____ () C:\Program Files\AVG\AVG PC TuneUp\tuavgx.dll
2015-07-21 03:54 - 2015-07-21 03:54 - 00076800 _____ () C:\Program Files\user extensions\Client.exe
FirewallRules: [{4F4D0146-ADF9-4BA9-B769-B9BE6A194012}] => (Allow) C:\Program Files\PremierOpinion\pmropn.exe
FirewallRules: [{976E81F9-33D6-45A9-905C-63E8E6B78923}] => (Allow) C:\Program Files\PremierOpinion\pmropn.exe
C:\Program Files\OneSystemCare\CleanupConsole.exe
C:\Program Files\AVG
C:\Program Files\user extensions\Client.exe
C:\Program Files\PremierOpinion
*****************
 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB} => key not found. 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448} => key not found. 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0} => key not found. 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309} => key not found. 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A} => key not found. 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09F713C9-DD9B-446B-A2F3-0C4F27A5D403} => key not found. 
C:\Windows\System32\Tasks\Validate Installation not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Validate Installation => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70150072-3745-4970-92F2-319F581F5B89} => key not found. 
C:\Windows\System32\Tasks\One System Care Monitor not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Monitor => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D19CEAE8-8D50-43AA-BE02-9BD931893253} => key not found. 
C:\Windows\System32\Tasks\One System CarePeriod not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System CarePeriod => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DFF5F404-E5D1-4C9B-A6DF-AD7A86B8B840} => key not found. 
C:\Windows\System32\Tasks\GeniusBox not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GeniusBox => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E37A6FDD-D5C9-4E94-B251-B372F6A2DCFE} => key not found. 
C:\Windows\System32\Tasks\One System Care Run Delay not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Run Delay => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F49EF02D-3499-4122-A306-8768A7A6322E} => key not found. 
C:\Windows\System32\Tasks\Check Updates not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Check Updates => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC86BC9D-A39B-4C5F-A3E6-D9E2CFB5D088} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OptimusNitro_Start => key not found. 
"C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll" => File/Folder not found.
"C:\Program Files\AVG\AVG PC TuneUp\tuavgx.dll" => File/Folder not found.
"C:\Program Files\user extensions\Client.exe" => File/Folder not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4F4D0146-ADF9-4BA9-B769-B9BE6A194012} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{976E81F9-33D6-45A9-905C-63E8E6B78923} => value not found.
"C:\Program Files\OneSystemCare\CleanupConsole.exe" => File/Folder not found.
"C:\Program Files\AVG" => File/Folder not found.
"C:\Program Files\user extensions\Client.exe" => File/Folder not found.
"C:\Program Files\PremierOpinion" => File/Folder not found.
 
==== End of Fixlog 02:40:07 ====
 
# AdwCleaner v4.208 - Logfile created 22/07/2015 at 02:56:36
# Updated 09/07/2015 by Xplode
# Database : 2015-07-09.2 [Local]
# Operating system : Windows Vista (TM) Home Basic  (x86)
# Username : Sharon - HAK-PC
# Running from : C:\Users\Sharon\Desktop\adwcleaner_4.208.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
Folder Deleted : C:\Program Files\user extensions
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKCU\Software\Search Extensions
Key Deleted : HKCU\Software\Tutorials
Key Deleted : HKCU\Software\TutoTag
Key Deleted : HKCU\Software\geniusboxinstalled
Key Deleted : HKCU\Software\One System Care
Key Deleted : HKLM\SOFTWARE\GAMESDESKTOP
Key Deleted : HKLM\SOFTWARE\GeniusBox
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GeniusBox
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\GeniusBox
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=127.0.0.1:49586;hxxps=127.0.0.1:49586
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v7.0.6000.16982
 
 
-\\ Mozilla Firefox v39.0 (x86 en-US)
 
 
-\\ Google Chrome v43.0.2357.134
 
 
*************************
 
AdwCleaner[R0].txt - [9203 bytes] - [13/07/2015 02:01:01]
AdwCleaner[R1].txt - [1951 bytes] - [22/07/2015 02:43:57]
AdwCleaner[S0].txt - [9208 bytes] - [13/07/2015 02:03:32]
AdwCleaner[S1].txt - [1692 bytes] - [22/07/2015 02:56:36]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1751  bytes] ##########
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-07-2015
Ran by [removed] (administrator) on HAK-PC on 21-07-2015 04:02:27
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft® Windows Vista™ Home Basic  (X86) OS Language: English (United States)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
(Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe
(Realtek Semiconductor) C:\WINDOWS\RtHDVCpl.exe
(Google Inc.) C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\System32\cmd.exe
() C:\Program Files\user extensions\Client.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-01-16] (Microsoft Corporation)
HKLM\…\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2006-09-28] (Hewlett-Packard Company)
HKLM\…\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4390912 2007-03-01] (Realtek Semiconductor)
HKLM\…\Run: [SnapfishMediaDetector] => C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe [1441792 2007-03-02] ()
HKLM\…\Run: [MSConfig] => C:\Windows\system32\msconfig.exe [222208 2006-11-02] (Microsoft Corporation)
HKLM\…\RunOnce: [Launcher] => C:\Windows\SMINST\launcher.exe [44168 2007-03-07] (soft thinks)
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\Run: [Google Update] => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-05-10] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk [2007-05-10]
ShortcutTarget: Snapfish Media Detector.lnk -> C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyEnable: [S-1-5-21-1992874582-3349113656-4066416677-1001] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-1992874582-3349113656-4066416677-1001] => http=127.0.0.1:49586;https=127.0.0.1:49586;
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-18] (SuperAdBlocker.com)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{003F1CAB-9582-432A-976B-A5B40F8B2472}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{015EC064-039A-44FB-930A-94C209392E85}: [DhcpNameServer] 192.168.2.1
 
FireFox:
========
FF ProfilePath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2013-10-12] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-10-12] (RealPlayer)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Sharon\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-07-27] (Citrix Online)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/O1DPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Sharon\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2015-03-17] (Zoom Video Communications, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npatgpc.dll [2012-10-29] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF SearchPlugin: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\searchplugins\amazon-distro.xml [2012-12-13]
FF Extension: adblockvideo - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2012-09-15]
FF Extension: feedly - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2013-05-10]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2012-12-12]
FF Extension: Adblock Plus - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-15]
FF Extension: User Agent Switcher - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2013-05-06]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Video Downloader Plugin - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Youtube Download Button - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-05-20]
FF HKLM\…\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-10-12]
FF HKLM\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
 
Chrome: 
=======
CHR Profile: C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (RealDownloader) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-04-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-21]
CHR Extension: (Skype Click to Call) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-09-01]
CHR Extension: (Google Wallet) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-13]
CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-29] (SUPERAntiSpyware.com)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [5509384 2015-07-08] (Emsisoft Ltd)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-04-25] (Freemake) [File not signed]
S3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-13] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 LightScribeService; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [1858360 2014-07-14] (AVG)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [35640 2014-07-14] (AVG)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [265912 2007-01-16] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 epp32; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp32.sys [112408 2015-07-08] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2014-02-10] (TuneUp Software)
S3 eapihdrv; \??\C:\Users\Sharon\AppData\Local\Temp\ehdrv.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-21 04:02 - 2015-07-21 04:03 - 00016845 _____ C:\Users\Sharon\Desktop\FRST.txt
2015-07-21 03:54 - 2015-07-21 03:54 - 00000064 _____ C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
2015-07-21 03:36 - 2015-07-21 03:36 - 00718104 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Sharon\Desktop\avgremover.exe
2015-07-21 03:36 - 2015-07-21 03:36 - 00098644 _____ C:\Users\Sharon\Desktop\avgremover.log
2015-07-21 00:16 - 2015-07-21 00:16 - 01638912 _____ (Farbar) C:\Users\Sharon\Desktop\FRST.exe
2015-07-19 04:15 - 2015-07-19 04:15 - 00000955 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-07-19 04:12 - 2015-07-20 21:21 - 00001360 _____ C:\blitzblank.log
2015-07-18 13:15 - 2015-07-18 13:15 - 00000000 ____D C:\Program Files\VS Revo Group
2015-07-18 10:30 - 2015-07-21 03:55 - 00000000 ____D C:\Program Files\user extensions
2015-07-18 05:03 - 2015-07-18 05:03 - 00001812 _____ C:\Users\Sharon\Desktop\ESETScan..txt
2015-07-18 02:43 - 2015-07-18 02:43 - 00000000 ____D C:\Program Files\ESET
2015-07-18 02:41 - 2015-07-18 02:41 - 02870984 _____ (ESET) C:\Users\Sharon\Desktop\esetsmartinstaller_enu.exe
2015-07-17 03:20 - 2015-07-17 03:22 - 00035307 _____ C:\Users\Sharon\Desktop\Addition.txt
2015-07-17 03:00 - 2015-07-17 03:00 - 01636864 _____ (Farbar) C:\Users\Sharon\Downloads\FRST.exe
2015-07-16 21:26 - 2015-07-16 20:37 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-16 20:40 - 2015-07-16 21:40 - 00021621 _____ C:\zoek-results.log
2015-07-16 20:36 - 2015-07-16 20:36 - 01308672 _____ C:\Users\Sharon\Desktop\zoek.exe
2015-07-16 20:31 - 2015-07-20 21:22 - 00002644 _____ C:\Windows\PFRO.log
2015-07-16 20:26 - 2015-07-16 20:26 - 01308672 _____ C:\Users\Sharon\Downloads\zoek (1).exe
2015-07-16 20:25 - 2015-07-16 21:20 - 00000000 ____D C:\zoek_backup
2015-07-16 20:24 - 2015-07-16 20:24 - 01308672 _____ C:\Users\Sharon\Desktop\zoek (1).exe
2015-07-16 20:08 - 2015-07-16 20:09 - 01308672 _____ C:\Users\Sharon\Downloads\zoek.exe
2015-07-16 14:38 - 2015-07-16 14:39 - 00000000 ____D C:\Users\Sharon\Desktop\New Folder
2015-07-14 05:39 - 2015-07-14 05:41 - 00034963 _____ C:\Users\Sharon\Downloads\Addition.txt
2015-07-14 05:35 - 2015-07-21 04:02 - 00000000 ____D C:\FRST
2015-07-13 10:24 - 2015-07-13 10:24 - 00000296 _____ C:\Windows\system32\spsys.log
2015-07-13 02:35 - 2015-07-13 02:35 - 00003121 _____ C:\Users\Sharon\Desktop\JRT.txt
2015-07-13 02:22 - 2015-07-13 02:22 - 00000207 _____ C:\Windows\tweaking.com-regbackup-HAK-PC-Windows-Vista-(TM)-Home-Basic-(32-bit).dat
2015-07-13 02:21 - 2015-07-13 02:21 - 00000000 ____D C:\RegBackup
2015-07-13 02:19 - 2015-07-13 02:19 - 00009208 _____ C:\Users\Sharon\Desktop\AdwCleaner[S0].txt
2015-07-13 02:16 - 2015-07-13 02:17 - 03034492 _____ (Malwarebytes Corporation) C:\Users\Sharon\Downloads\JRT.exe
2015-07-13 02:14 - 2015-07-13 02:14 - 00000000 ____D C:\Windows\pss
2015-07-13 02:00 - 2015-07-13 02:05 - 00000000 ____D C:\AdwCleaner
2015-07-13 01:58 - 2015-07-13 01:59 - 02248704 _____ C:\Users\Sharon\Downloads\adwcleaner_4.208.exe
2015-07-12 11:15 - 2015-07-12 11:15 - 00010182 _____ C:\Users\Sharon\Downloads\hijackthis.log
2015-07-12 11:14 - 2015-07-12 11:14 - 00388608 _____ (Trend Micro Inc.) C:\Users\Sharon\Downloads\HiJackThis.exe
2015-07-10 03:41 - 2015-07-10 03:41 - 00027329 _____ C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!.html
2015-07-10 03:41 - 2015-07-10 03:41 - 00000000 ____D C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!_files
2015-07-08 16:22 - 2015-07-12 11:21 - 00001356 _____ C:\Users\Sharon\AppData\Local\d3d9caps.dat
2015-07-08 14:46 - 2015-07-21 03:53 - 00470641 _____ C:\Windows\WindowsUpdate.log
2015-07-07 10:56 - 2015-07-07 10:56 - 00000810 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\Program Files\CCleaner
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507.exe
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507 (1).exe
2015-07-07 01:38 - 2015-07-07 01:44 - 00000000 ____D C:\ProgramData\Emsisoft
2015-07-07 01:10 - 2015-07-07 01:11 - 00000000 ____D C:\Program Files\TrojanHunter
2015-07-07 01:10 - 2015-07-07 01:10 - 00000858 _____ C:\Users\Sharon\Desktop\TrojanHunter.lnk
2015-07-07 01:10 - 2015-07-07 01:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
2015-07-07 01:09 - 2015-07-07 01:09 - 04069672 _____ (Bytelayer AB ) C:\Users\Sharon\Downloads\TrojanHunterSetup.exe
2015-07-06 17:15 - 2015-07-06 17:15 - 00000894 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2015-07-06 17:15 - 2015-07-06 17:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2015-07-06 17:14 - 2015-03-24 00:17 - 00111368 _____ (Emsisoft GmbH) C:\Windows\system32\Drivers\epp32.sys
2015-07-06 17:13 - 2015-07-21 03:52 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2015-07-06 16:13 - 2015-07-06 16:30 - 167273960 _____ (Emsisoft Ltd. ) C:\Users\Sharon\Downloads\EmsisoftAntiMalwareSetup.exe
2015-07-05 12:46 - 2015-07-05 12:46 - 00242712 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 39.0.exe
2015-07-05 10:22 - 2015-07-05 10:26 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Sharon\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-07-03 14:20 - 2015-07-03 14:20 - 01125056 _____ (Adobe Systems Incorporated) C:\Users\Sharon\Downloads\flashplayer18_ha_install.exe
2015-07-02 13:55 - 2015-07-02 13:55 - 00243408 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 38.0.5.exe
2015-06-30 12:25 - 2015-07-05 14:17 - 00000000 ____D C:\Program Files\Mozilla Firefox
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-21 03:53 - 2015-05-30 13:19 - 00000664 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-21 03:50 - 2013-04-27 03:03 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-21 03:50 - 2007-05-10 11:27 - 00000000 ____D C:\Windows\SMINST
2015-07-21 03:50 - 2006-11-02 04:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-21 03:49 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-21 03:49 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-21 03:48 - 2006-11-02 04:58 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-07-21 03:31 - 2014-07-27 15:41 - 00000568 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-21 03:29 - 2013-04-27 03:03 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-21 03:18 - 2012-10-18 13:49 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-21 03:16 - 2015-05-10 16:53 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job
2015-07-20 21:22 - 2014-11-04 14:23 - 00000000 ____D C:\ProgramData\AVG2015
2015-07-20 21:22 - 2012-07-09 10:09 - 00000000 ____D C:\Program Files\AVG
2015-07-20 21:22 - 2012-07-09 10:00 - 00000000 ____D C:\ProgramData\MFAData
2015-07-20 19:31 - 2012-07-09 10:10 - 00000000 ___HD C:\$AVG
2015-07-20 12:16 - 2015-05-10 16:53 - 00000860 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job
2015-07-19 04:14 - 2012-06-06 18:34 - 00000950 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-07-19 04:14 - 2012-06-06 18:34 - 00000921 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2015-07-17 03:28 - 2014-04-11 17:05 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-16 21:40 - 2013-02-18 13:09 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-07-16 21:16 - 2006-11-02 03:18 - 00000000 ___RD C:\Users\Public
2015-07-16 21:16 - 2006-11-02 03:18 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-07-16 03:22 - 2013-07-14 19:21 - 00000000 ____D C:\Windows\system32\MRT
2015-07-14 23:47 - 2012-07-08 00:30 - 00000000 ____D C:\Users\Sharon\AppData\Roaming\Skype
2015-07-14 21:20 - 2012-07-08 00:19 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-14 21:20 - 2012-07-08 00:19 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-08 15:04 - 2013-05-06 08:20 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-07 11:00 - 2012-07-17 15:02 - 00000000 ____D C:\Windows\Minidump
2015-07-07 11:00 - 2007-05-10 11:06 - 00000000 ____D C:\Windows\Panther
2015-07-07 01:25 - 2012-06-06 18:33 - 00000000 ____D C:\Users\Sharon\AppData\Local\VirtualStore
2015-07-05 14:17 - 2013-03-09 15:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-07-05 14:16 - 2006-11-02 04:35 - 00000000 ____D C:\Windows\DigitalLocker
2015-07-05 12:50 - 2013-03-09 15:52 - 00000864 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-05 12:50 - 2013-03-09 15:52 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-05 10:30 - 2014-04-11 17:02 - 00000905 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-07-03 08:49 - 2006-11-02 02:24 - 127070192 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-07-01 12:53 - 2014-04-14 12:13 - 00000000 ____D C:\Users\Sharon\AppData\Local\AVG
 
==================== Files in the root of some directories =======
 
2013-05-21 03:10 - 2014-01-30 13:39 - 0003736 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
2015-07-21 03:54 - 2015-07-21 03:54 - 0000064 _____ () C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
2015-07-08 16:22 - 2015-07-12 11:21 - 0001356 _____ () C:\Users\Sharon\AppData\Local\d3d9caps.dat
2012-07-08 02:19 - 2015-05-06 19:35 - 0025088 _____ () C:\Users\Sharon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2007-05-10 10:43 - 2013-03-21 07:29 - 0002738 _____ () C:\ProgramData\hpzinstall.log
 
Some files in TEMP:
====================
C:\Users\Sharon\AppData\Local\Temp\gb-installer-nsi.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-21 03:56
 
==================== End of log ============================

I don't know why that log was old I did not delete the old one but l looked at each thing on the desktop and that was the only one from FRST except for the program itself.  I made a new fixlist again and here is the log.

 

GB

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 20-07-2015
Ran by [removed] at 2015-07-22 10:28:20 Run:4
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.27.5\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> No Filepath
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Citrix\GoToMeeting\1440\G2MOutlookAddin.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.26.9\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> No Filepath
Task: {09F713C9-DD9B-446B-A2F3-0C4F27A5D403} - System32\Tasks\Validate Installation => C:\Program Files\user extensions\updater.exe [2015-07-21] () <==== ATTENTION
Task: {70150072-3745-4970-92F2-319F581F5B89} - System32\Tasks\One System Care Monitor => C:\Program Files\OneSystemCare\CleanupConsole.exe
Task: {D19CEAE8-8D50-43AA-BE02-9BD931893253} - System32\Tasks\One System CarePeriod => C:\Program Files\OneSystemCare\OneSystemCare.exe
Task: {DFF5F404-E5D1-4C9B-A6DF-AD7A86B8B840} - System32\Tasks\GeniusBox => cmd.exe /C start "" "C:\Program Files\user extensions\client.exe" <==== ATTENTION
Task: {E37A6FDD-D5C9-4E94-B251-B372F6A2DCFE} - System32\Tasks\One System Care Run Delay => C:\Program Files\OneSystemCare\OneSystemCare.exe
Task: {F49EF02D-3499-4122-A306-8768A7A6322E} - System32\Tasks\Check Updates => C:\Program Files\user extensions\updater.exe [2015-07-21] () <==== ATTENTION
Task: {FC86BC9D-A39B-4C5F-A3E6-D9E2CFB5D088} - \OptimusNitro_Start No Task File <==== ATTENTION
2014-07-14 02:26 - 2014-07-14 02:26 - 00585528 _____ () C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll
2014-07-14 02:26 - 2014-07-14 02:26 - 00357176 _____ () C:\Program Files\AVG\AVG PC TuneUp\tuavgx.dll
2015-07-21 03:54 - 2015-07-21 03:54 - 00076800 _____ () C:\Program Files\user extensions\Client.exe
FirewallRules: [{4F4D0146-ADF9-4BA9-B769-B9BE6A194012}] => (Allow) C:\Program Files\PremierOpinion\pmropn.exe
FirewallRules: [{976E81F9-33D6-45A9-905C-63E8E6B78923}] => (Allow) C:\Program Files\PremierOpinion\pmropn.exe
C:\Program Files\OneSystemCare\CleanupConsole.exe
C:\Program Files\AVG
C:\Program Files\user extensions\Client.exe
C:\Program Files\PremierOpinion
*****************
 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB} => key not found. 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448} => key not found. 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0} => key not found. 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309} => key not found. 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A} => key not found. 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09F713C9-DD9B-446B-A2F3-0C4F27A5D403} => key not found. 
C:\Windows\System32\Tasks\Validate Installation not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Validate Installation => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70150072-3745-4970-92F2-319F581F5B89} => key not found. 
C:\Windows\System32\Tasks\One System Care Monitor not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Monitor => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D19CEAE8-8D50-43AA-BE02-9BD931893253} => key not found. 
C:\Windows\System32\Tasks\One System CarePeriod not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System CarePeriod => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DFF5F404-E5D1-4C9B-A6DF-AD7A86B8B840} => key not found. 
C:\Windows\System32\Tasks\GeniusBox not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GeniusBox => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E37A6FDD-D5C9-4E94-B251-B372F6A2DCFE} => key not found. 
C:\Windows\System32\Tasks\One System Care Run Delay not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\One System Care Run Delay => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F49EF02D-3499-4122-A306-8768A7A6322E} => key not found. 
C:\Windows\System32\Tasks\Check Updates not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Check Updates => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC86BC9D-A39B-4C5F-A3E6-D9E2CFB5D088} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OptimusNitro_Start => key not found. 
"C:\Program Files\AVG\AVG PC TuneUp\avgreplibx.dll" => File/Folder not found.
"C:\Program Files\AVG\AVG PC TuneUp\tuavgx.dll" => File/Folder not found.
"C:\Program Files\user extensions\Client.exe" => File/Folder not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4F4D0146-ADF9-4BA9-B769-B9BE6A194012} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{976E81F9-33D6-45A9-905C-63E8E6B78923} => value not found.
"C:\Program Files\OneSystemCare\CleanupConsole.exe" => File/Folder not found.
"C:\Program Files\AVG" => File/Folder not found.
"C:\Program Files\user extensions\Client.exe" => File/Folder not found.
"C:\Program Files\PremierOpinion" => File/Folder not found.
 
==== End of Fixlog 10:28:33 ====

I hope this is what you need.

 

GB

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-07-2015
Ran by [removed] (administrator) on HAK-PC on 22-07-2015 19:01:23
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft® Windows Vista™ Home Basic  (X86) OS Language: English (United States)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe
(Realtek Semiconductor) C:\WINDOWS\RtHDVCpl.exe
(Google Inc.) C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-01-16] (Microsoft Corporation)
HKLM\…\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2006-09-28] (Hewlett-Packard Company)
HKLM\…\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4390912 2007-03-01] (Realtek Semiconductor)
HKLM\…\Run: [SnapfishMediaDetector] => C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe [1441792 2007-03-02] ()
HKLM\…\Run: [MSConfig] => C:\Windows\system32\msconfig.exe [222208 2006-11-02] (Microsoft Corporation)
HKLM\…\RunOnce: [Launcher] => C:\Windows\SMINST\launcher.exe [44168 2007-03-07] (soft thinks)
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\Run: [Google Update] => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-05-10] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk [2007-05-10]
ShortcutTarget: Snapfish Media Detector.lnk -> C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-18] (SuperAdBlocker.com)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{003F1CAB-9582-432A-976B-A5B40F8B2472}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{015EC064-039A-44FB-930A-94C209392E85}: [DhcpNameServer] 192.168.2.1
 
FireFox:
========
FF ProfilePath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2013-10-12] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-10-12] (RealPlayer)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Sharon\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-07-27] (Citrix Online)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/O1DPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Sharon\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2015-03-17] (Zoom Video Communications, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npatgpc.dll [2012-10-29] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF SearchPlugin: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\searchplugins\amazon-distro.xml [2012-12-13]
FF Extension: adblockvideo - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2012-09-15]
FF Extension: feedly - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2013-05-10]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2012-12-12]
FF Extension: Adblock Plus - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-15]
FF Extension: User Agent Switcher - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2013-05-06]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Video Downloader Plugin - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Youtube Download Button - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-05-20]
FF HKLM\…\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-10-12]
FF HKLM\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
 
Chrome: 
=======
CHR Profile: C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (RealDownloader) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-04-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-21]
CHR Extension: (Skype Click to Call) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-09-01]
CHR Extension: (Google Wallet) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-13]
CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-29] (SUPERAntiSpyware.com)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [5509384 2015-07-08] (Emsisoft Ltd)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-04-25] (Freemake) [File not signed]
S3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-13] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 LightScribeService; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [265912 2007-01-16] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 epp32; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp32.sys [112408 2015-07-08] (Emsisoft GmbH)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 eapihdrv; \??\C:\Users\Sharon\AppData\Local\Temp\ehdrv.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-22 12:33 - 2015-07-22 19:01 - 00016369 _____ C:\Users\Sharon\Desktop\FRST.txt
2015-07-22 02:42 - 2015-07-22 02:42 - 02248704 _____ C:\Users\Sharon\Desktop\adwcleaner_4.208.exe
2015-07-21 03:54 - 2015-07-21 03:54 - 00000064 _____ C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
2015-07-21 03:36 - 2015-07-21 03:36 - 00718104 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Sharon\Desktop\avgremover.exe
2015-07-21 03:36 - 2015-07-21 03:36 - 00098644 _____ C:\Users\Sharon\Desktop\avgremover.log
2015-07-21 00:16 - 2015-07-21 00:16 - 01638912 _____ (Farbar) C:\Users\Sharon\Desktop\FRST.exe
2015-07-19 04:15 - 2015-07-19 04:15 - 00000955 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-07-19 04:12 - 2015-07-20 21:21 - 00001360 _____ C:\blitzblank.log
2015-07-18 13:15 - 2015-07-18 13:15 - 00000000 ____D C:\Program Files\VS Revo Group
2015-07-18 05:03 - 2015-07-18 05:03 - 00001812 _____ C:\Users\Sharon\Desktop\ESETScan..txt
2015-07-18 02:43 - 2015-07-18 02:43 - 00000000 ____D C:\Program Files\ESET
2015-07-18 02:41 - 2015-07-18 02:41 - 02870984 _____ (ESET) C:\Users\Sharon\Desktop\esetsmartinstaller_enu.exe
2015-07-17 03:20 - 2015-07-21 04:04 - 00038120 _____ C:\Users\Sharon\Desktop\Addition.txt
2015-07-17 03:00 - 2015-07-17 03:00 - 01636864 _____ (Farbar) C:\Users\Sharon\Downloads\FRST.exe
2015-07-16 21:26 - 2015-07-16 20:37 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-16 20:40 - 2015-07-16 21:40 - 00021621 _____ C:\zoek-results.log
2015-07-16 20:36 - 2015-07-16 20:36 - 01308672 _____ C:\Users\Sharon\Desktop\zoek.exe
2015-07-16 20:31 - 2015-07-20 21:22 - 00002644 _____ C:\Windows\PFRO.log
2015-07-16 20:26 - 2015-07-16 20:26 - 01308672 _____ C:\Users\Sharon\Downloads\zoek (1).exe
2015-07-16 20:25 - 2015-07-16 21:20 - 00000000 ____D C:\zoek_backup
2015-07-16 20:24 - 2015-07-16 20:24 - 01308672 _____ C:\Users\Sharon\Desktop\zoek (1).exe
2015-07-16 20:08 - 2015-07-16 20:09 - 01308672 _____ C:\Users\Sharon\Downloads\zoek.exe
2015-07-16 14:38 - 2015-07-16 14:39 - 00000000 ____D C:\Users\Sharon\Desktop\New Folder
2015-07-14 05:39 - 2015-07-14 05:41 - 00034963 _____ C:\Users\Sharon\Downloads\Addition.txt
2015-07-14 05:35 - 2015-07-22 19:02 - 00000000 ____D C:\FRST
2015-07-13 10:24 - 2015-07-13 10:24 - 00000296 _____ C:\Windows\system32\spsys.log
2015-07-13 02:35 - 2015-07-13 02:35 - 00003121 _____ C:\Users\Sharon\Desktop\JRT.txt
2015-07-13 02:22 - 2015-07-13 02:22 - 00000207 _____ C:\Windows\tweaking.com-regbackup-HAK-PC-Windows-Vista-(TM)-Home-Basic-(32-bit).dat
2015-07-13 02:21 - 2015-07-13 02:21 - 00000000 ____D C:\RegBackup
2015-07-13 02:19 - 2015-07-13 02:19 - 00009208 _____ C:\Users\Sharon\Desktop\AdwCleaner[S0].txt
2015-07-13 02:16 - 2015-07-13 02:17 - 03034492 _____ (Malwarebytes Corporation) C:\Users\Sharon\Downloads\JRT.exe
2015-07-13 02:14 - 2015-07-13 02:14 - 00000000 ____D C:\Windows\pss
2015-07-13 02:00 - 2015-07-22 02:57 - 00000000 ____D C:\AdwCleaner
2015-07-13 01:58 - 2015-07-13 01:59 - 02248704 _____ C:\Users\Sharon\Downloads\adwcleaner_4.208.exe
2015-07-12 11:15 - 2015-07-12 11:15 - 00010182 _____ C:\Users\Sharon\Downloads\hijackthis.log
2015-07-12 11:14 - 2015-07-12 11:14 - 00388608 _____ (Trend Micro Inc.) C:\Users\Sharon\Downloads\HiJackThis.exe
2015-07-10 03:41 - 2015-07-10 03:41 - 00027329 _____ C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!.html
2015-07-10 03:41 - 2015-07-10 03:41 - 00000000 ____D C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!_files
2015-07-08 16:22 - 2015-07-12 11:21 - 00001356 _____ C:\Users\Sharon\AppData\Local\d3d9caps.dat
2015-07-08 14:46 - 2015-07-22 17:42 - 00528698 _____ C:\Windows\WindowsUpdate.log
2015-07-07 10:56 - 2015-07-07 10:56 - 00000810 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\Program Files\CCleaner
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507.exe
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507 (1).exe
2015-07-07 01:38 - 2015-07-07 01:44 - 00000000 ____D C:\ProgramData\Emsisoft
2015-07-07 01:10 - 2015-07-07 01:11 - 00000000 ____D C:\Program Files\TrojanHunter
2015-07-07 01:10 - 2015-07-07 01:10 - 00000858 _____ C:\Users\Sharon\Desktop\TrojanHunter.lnk
2015-07-07 01:10 - 2015-07-07 01:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
2015-07-07 01:09 - 2015-07-07 01:09 - 04069672 _____ (Bytelayer AB ) C:\Users\Sharon\Downloads\TrojanHunterSetup.exe
2015-07-06 17:15 - 2015-07-06 17:15 - 00000894 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2015-07-06 17:15 - 2015-07-06 17:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2015-07-06 17:14 - 2015-03-24 00:17 - 00111368 _____ (Emsisoft GmbH) C:\Windows\system32\Drivers\epp32.sys
2015-07-06 17:13 - 2015-07-22 19:02 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2015-07-06 16:13 - 2015-07-06 16:30 - 167273960 _____ (Emsisoft Ltd. ) C:\Users\Sharon\Downloads\EmsisoftAntiMalwareSetup.exe
2015-07-05 12:46 - 2015-07-05 12:46 - 00242712 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 39.0.exe
2015-07-05 10:22 - 2015-07-05 10:26 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Sharon\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-07-03 14:20 - 2015-07-03 14:20 - 01125056 _____ (Adobe Systems Incorporated) C:\Users\Sharon\Downloads\flashplayer18_ha_install.exe
2015-07-02 13:55 - 2015-07-02 13:55 - 00243408 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 38.0.5.exe
2015-06-30 12:25 - 2015-07-05 14:17 - 00000000 ____D C:\Program Files\Mozilla Firefox
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-22 18:41 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-22 18:41 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-22 18:31 - 2014-07-27 15:41 - 00000568 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-22 18:29 - 2013-04-27 03:03 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-22 18:18 - 2012-10-18 13:49 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-22 18:17 - 2015-05-10 16:53 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job
2015-07-22 17:53 - 2015-05-30 13:19 - 00000664 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-22 12:16 - 2015-05-10 16:53 - 00000860 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job
2015-07-22 11:29 - 2013-04-27 03:03 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-22 03:00 - 2007-05-10 11:27 - 00000000 ____D C:\Windows\SMINST
2015-07-22 03:00 - 2006-11-02 04:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-22 02:59 - 2006-11-02 04:58 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-07-20 21:22 - 2014-11-04 14:23 - 00000000 ____D C:\ProgramData\AVG2015
2015-07-20 21:22 - 2012-07-09 10:00 - 00000000 ____D C:\ProgramData\MFAData
2015-07-20 19:31 - 2012-07-09 10:10 - 00000000 ___HD C:\$AVG
2015-07-19 04:14 - 2012-06-06 18:34 - 00000950 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-07-19 04:14 - 2012-06-06 18:34 - 00000921 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2015-07-17 03:28 - 2014-04-11 17:05 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-16 21:40 - 2013-02-18 13:09 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-07-16 21:16 - 2006-11-02 03:18 - 00000000 ___RD C:\Users\Public
2015-07-16 21:16 - 2006-11-02 03:18 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-07-16 03:22 - 2013-07-14 19:21 - 00000000 ____D C:\Windows\system32\MRT
2015-07-14 23:47 - 2012-07-08 00:30 - 00000000 ____D C:\Users\Sharon\AppData\Roaming\Skype
2015-07-14 21:20 - 2012-07-08 00:19 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-14 21:20 - 2012-07-08 00:19 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-08 15:04 - 2013-05-06 08:20 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-07 11:00 - 2012-07-17 15:02 - 00000000 ____D C:\Windows\Minidump
2015-07-07 11:00 - 2007-05-10 11:06 - 00000000 ____D C:\Windows\Panther
2015-07-07 01:25 - 2012-06-06 18:33 - 00000000 ____D C:\Users\Sharon\AppData\Local\VirtualStore
2015-07-05 14:17 - 2013-03-09 15:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-07-05 14:16 - 2006-11-02 04:35 - 00000000 ____D C:\Windows\DigitalLocker
2015-07-05 12:50 - 2013-03-09 15:52 - 00000864 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-05 12:50 - 2013-03-09 15:52 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-05 10:30 - 2014-04-11 17:02 - 00000905 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-07-03 08:49 - 2006-11-02 02:24 - 127070192 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-07-01 12:53 - 2014-04-14 12:13 - 00000000 ____D C:\Users\Sharon\AppData\Local\AVG
 
==================== Files in the root of some directories =======
 
2013-05-21 03:10 - 2014-01-30 13:39 - 0003736 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
2015-07-21 03:54 - 2015-07-21 03:54 - 0000064 _____ () C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
2015-07-08 16:22 - 2015-07-12 11:21 - 0001356 _____ () C:\Users\Sharon\AppData\Local\d3d9caps.dat
2012-07-08 02:19 - 2015-05-06 19:35 - 0025088 _____ () C:\Users\Sharon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2007-05-10 10:43 - 2013-03-21 07:29 - 0002738 _____ () C:\ProgramData\hpzinstall.log
 
Some files in TEMP:
====================
C:\Users\Sharon\AppData\Local\Temp\gb-installer-nsi.exe
C:\Users\Sharon\AppData\Local\Temp\Quarantine.exe
C:\Users\Sharon\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-22 03:06
 
==================== End of log ============================

That’s looking good.

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

2015-07-21 03:54 - 2015-07-21 03:54 - 00000064 _____ C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
2015-07-21 03:36 - 2015-07-21 03:36 - 00098644 _____ C:\Users\Sharon\Desktop\avgremover.log
2015-07-20 19:31 - 2012-07-09 10:10 - 00000000 ___HD C:\$AVG
2015-07-20 21:22 - 2014-11-04 14:23 - 00000000 ____D C:\ProgramData\AVG2015
2015-07-01 12:53 - 2014-04-14 12:13 - 00000000 ____D C:\Users\Sharon\AppData\Local\AVG
2013-05-21 03:10 - 2014-01-30 13:39 - 0003736 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
2015-07-21 03:54 - 2015-07-21 03:54 - 0000064 _____ () C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
C:\Users\Sharon\Desktop\avgremover.log
C:\$AVG
C:\ProgramData\AVG2015
C:\Users\Sharon\AppData\Local\AVG
C:\Program Files\Mozilla Firefoxavg-secure-search.xml

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

===================================================

Let’s run an online scan to be sure nothing is left and if that’s clear I’ll send instructions to tidy up.


Run ESET Online Scan

Note: This may take a long time so please be patient.

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use Internet Explorer, FireFox or  Chrome for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan

  • click the Eset online Scanner button
  • for alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


    o    click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
    o    double click on the Eset installer icon on your desktop.
     

  • check Yes, I accept the Terms of Use
  • click the Start button
  • accept any security warnings from your browser
  • check Enable detection of potentially unwanted applications
  • click Advanced settings and select the following:


    o    scan archives
    o    scan for potentially unsafe applications
    o    enable Anti-Stealth technology


    Note: Do not check Remove found threats
     

  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • when the scan completes, push List of found threats
  • push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

    Note - if ESET doesn't find any threats, no report will be created.
     

  • push the back button.
  • push Finish

When the scan is complete:

If no threats were found:
 


o    put a checkmark in "Uninstall application on close"
o    close program
o    report to me that nothing was found.
 

If threats were found:



o    click on "list of threats found"
o    click on "export to text file" and save it as ESET results and save to the desktop
o    Click on back
o    put a checkmark in "Uninstall application on close"
o    click on finish
o    close program
o    copy and paste the report here.
 

Thanks

Satchfan

 

 

Thanks

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 20-07-2015
Ran by [removed] at 2015-07-23 03:02:27 Run:5
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
2015-07-21 03:54 - 2015-07-21 03:54 - 00000064 _____ C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
2015-07-21 03:36 - 2015-07-21 03:36 - 00098644 _____ C:\Users\Sharon\Desktop\avgremover.log
2015-07-20 19:31 - 2012-07-09 10:10 - 00000000 ___HD C:\$AVG
2015-07-20 21:22 - 2014-11-04 14:23 - 00000000 ____D C:\ProgramData\AVG2015
2015-07-01 12:53 - 2014-04-14 12:13 - 00000000 ____D C:\Users\Sharon\AppData\Local\AVG
2013-05-21 03:10 - 2014-01-30 13:39 - 0003736 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
2015-07-21 03:54 - 2015-07-21 03:54 - 0000064 _____ () C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47
C:\Users\Sharon\Desktop\avgremover.log
C:\$AVG
C:\ProgramData\AVG2015
C:\Users\Sharon\AppData\Local\AVG
C:\Program Files\Mozilla Firefoxavg-secure-search.xml
*****************
 
C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47 => moved successfully.
C:\Users\Sharon\Desktop\avgremover.log => moved successfully.
C:\$AVG => moved successfully.
C:\ProgramData\AVG2015 => moved successfully.
C:\Users\Sharon\AppData\Local\AVG => moved successfully.
C:\Program Files\Mozilla Firefoxavg-secure-search.xml => moved successfully.
"C:\Users\Sharon\AppData\Local\b74278e376736ee8626f0d56a9de8c47" => File/Folder not found.
"C:\Users\Sharon\Desktop\avgremover.log" => File/Folder not found.
"C:\$AVG" => File/Folder not found.
"C:\ProgramData\AVG2015" => File/Folder not found.
"C:\Users\Sharon\AppData\Local\AVG" => File/Folder not found.
"C:\Program Files\Mozilla Firefoxavg-secure-search.xml" => File/Folder not found.
 
==== End of Fixlog 03:02:36 ====
 
C:\FRST\Quarantine\C\Program Files\PremierOpinion\pmls.dll a variant of Win32/Adware.RK.AM application
C:\FRST\Quarantine\C\Program Files\PremierOpinion\pmropn.exe a variant of Win32/Adware.RK.AE application
C:\FRST\Quarantine\C\Windows\system32\pmls.dll.xBAD a variant of Win32/Adware.RK.AM application
C:\Program Files\HP OFFICEJET 6210 Driver Utility\driverlib.dll Win32/DriverBoss.B potentially unwanted application
C:\Users\Sharon\Downloads\ccsetup507 (1).exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\Sharon\Downloads\ccsetup507.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\Sharon\Downloads\FreemakeVideoDownloader_3.5.0.7.exe Win32/OpenCandy potentially unsafe application
C:\Users\Sharon\Downloads\hp-officejet-6210-driver-utility.exe Win32/DriverBoss.B potentially unwanted application
C:\Users\Sharon\Downloads\HSS-3.42-install-e-680-plain.exe Win32/Bundled.Toolbar.Ask.L potentially unsafe application
C:\Users\Sharon\Downloads\OptimusNitroSetup.exe a variant of MSIL/Rebrand.LittleRegClean.E potentially unwanted application
C:\Users\Sharon\Downloads\youtube_downloader_hd_setup.exe Win32/OpenCandy potentially unsafe application
 

Those appear to be the ones found in the previous scan and should have been removed with the instructions I gave at the time. In case you didn’t follow the instructions to delete them I’ll give them again.


Please copy all text in the code box below and paste it into Notepad:

@echo off
del /f /s /q "C:\Program Files\HP OFFICEJET 6210 Driver Utility\driverlib.dll”
del /f /s /q "C:\Users\Sharon\Downloads\ccsetup507 (1).exe”
del /f /s /q "C:\Users\Sharon\Downloads\ccsetup507.exe”
del /f /s /q "C:\Users\Sharon\Downloads\FreemakeVideoDownloader_3.5.0.7.exe”
del /f /s /q "C:\Users\Sharon\Downloads\hp-officejet-6210-driver-utility.exe”
del /f /s /q "C:\Users\Sharon\Downloads\HSS-3.42-install-e-680-plain.exe”
del /f /s /q "C:\Users\Sharon\Downloads\OptimusNitroSetup.exe”
del /f /s /q "C:\Users\Sharon\Downloads\youtube_downloader_hd_setup.exe”
del %0
  • save the Notepad file to your desktop and name it delfiles.bat
  • save type as "All Files"
  • on your desktop, double-click on delfiles.bat to run it, (a black CMD window will flash, then disappear - this is normal).

The files/folders, if found, will have been deleted and the "delfile.bat" file will also be deleted.

=========================================

Let's do another (shorter) scan to be sure.

Please be patient as scanning may take some time. If you have problem running the scan, you might want to disable any real time protection that you have.

  • click here to go to BitDefender QuickScan page.

For Firefox users:


o    Click on Scan Now. You will be prompted to install a plug-in: allow it. (In case you get stuck, refresh the page to try again).
o    A Software Installation window will appear. Click Install Now and the plugin will be installed as an Add-on.
o    Restart Firefox when done. Go back to the BitDefender QuickScan page again and click on Free Scan Now and proceed accordingly.
 

For Internet Explorer users:


o    Click on Scan Now. You will be prompted to install an ActiveX control. Please install.
o    The page will refresh. Click on Scan Now again and proceed accordingly.

  • when the scan has completed, click on View report and a Notepad log will open.
  • if there are any infections found, you will get a warning and the link to the report will be displayed as the number of infections. Click on it.

Post back the contents of this report. It can also be found at C:\Documents and Settings\\Application Data\QuickScan (“username” is the Windows log-in name.

Satchfan

 

Satchfan,

 

I could have sworn tha tI deleted the log files from both ESET and FRST before I did the scans.  Maybe I am wrong though.  I just opened FRST logfile and it said it had yesterday's date.  I ran te script you  provided and ran BitDefender scan.  It said tere were no infections.  I did not see a log on the desktop.  I also did a search with the file name you provided and the computer could not find it.  I hope this is what you need.

 

Thanks,

GB

I would say that your computer is clean if BitDefender found nothing.

 

Are there any remaining problems?

 

I am travelling back home today so if all is well I'll send instructions to tidy up but my reply will be delayed.

 

Satchfan

Satchfan,

 

Thanks for your help.  I appreciate it.  However, the computer does not seem to work much better.  Maybe I need more RAM.  I did not download an anti-virus yet after deleting AVG.  Would Avira work better?  You also said I need the Service pac.

 

Thanks,

GB

2GB is not bad for Vists so shouldn't be causing any slowness.

I’ve looked over one of your logs again and noticed some entries that may be contributing to the problem so we’re not quite finished yet.

First:

Antivirus

Do NOT install more than one or they will fight against each other and render both ineffective.

Here are some of the better AV products. Download and install one of them:


Bitdefender Antivirus Free Edition
Free Avast Home Edition - includes Dropbox or Google Chrome during installation - pre-checked by default
Avira AntiVir® Personal Edition Classic - includes an option to install Avira Browser Safety Add-on to your browser
Microsoft Security Essentials - de-select the option to join the customer experience improvement program

===================================================

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Video Downloader Plugin - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Youtube Download Button - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
CHR Extension: (Freemake Video Downloader) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf [2013-05-03]
CHR HKLM\…\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2013-04-25]

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

Please run AdwCleaner again and then FRST after running AdwCleaner and send the new logs.

Logs to include:

Fixlog.txt
AdwCleaner log
New FRST.txt


Satchfan

 

Satchfan

 

 I tried this morning and then again tonight.  I did the scan but the log did not show on the desktop.  Before I did scan I deleted all files of FRST except program.  At finish, a folder showed up on desktop called FRST Older…  I could not delete it and I tried to open it and it started to run like a program.  Got a message saying I could not delete it.

 

Thanks GB

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI