This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer slow [Solved]

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Before I did scan I deleted all files of FRST except program.

 

I didn't ask you to do that.

 

Please follow the other instructions and finish up with a new FRST scan.

 

Satchfan

Satchfan,

 

I ran FRST with the script twice and it left no log.  That is why I tried to delete the FRST folder.  I thought it might be interferring with leaving a log.  Adw Cleaner would not leave log.  FRST did leave a log for the scan.  I also had to shut down the computer twice since it would not respond.  For instance, Adw would not open so I restarted the computer.  I was on page 3 of whatthe tech forum and it would not go to page 4 afte waiti9ng 5-10 minutes.  Here is the scan for FRST.  Would it be better to just wait for Win 10 and install or is it something in the registry?

 

Thanks

GB

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-07-2015
Ran by [removed] (administrator) on HAK-PC (26-07-2015 10:25:07)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft® Windows Vista™ Home Basic  (X86) Language: English (United States)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe
(Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
(Realtek Semiconductor) C:\WINDOWS\RtHDVCpl.exe
(Google Inc.) C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
(Microsoft Corporation) C:\WINDOWS\System32\mobsync.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-01-16] (Microsoft Corporation)
HKLM\…\Run: [hpsysdrv] => c:\hp\support\hpsysdrv.exe [65536 2006-09-28] (Hewlett-Packard Company)
HKLM\…\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\…\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\…\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\…\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4390912 2007-03-01] (Realtek Semiconductor)
HKLM\…\Run: [SnapfishMediaDetector] => C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe [1441792 2007-03-02] ()
HKLM\…\Run: [MSConfig] => C:\Windows\system32\msconfig.exe [222208 2006-11-02] (Microsoft Corporation)
HKLM\…\RunOnce: [Launcher] => C:\Windows\SMINST\launcher.exe [44168 2007-03-07] (soft thinks)
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\Run: [Google Update] => C:\Users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-05-10] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk [2007-05-10]
ShortcutTarget: Snapfish Media Detector.lnk -> C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [113024 2011-07-18] (SuperAdBlocker.com)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{003F1CAB-9582-432A-976B-A5B40F8B2472}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{015EC064-039A-44FB-930A-94C209392E85}: [DhcpNameServer] 192.168.2.1
 
FireFox:
========
FF ProfilePath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2013-10-12] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-10-12] (RealPlayer)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Sharon\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-07-27] (Citrix Online)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @talk.google.com/O1DPlugin -> C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1992874582-3349113656-4066416677-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\Sharon\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2015-03-17] (Zoom Video Communications, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npatgpc.dll [2012-10-29] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-04-17] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Sharon\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-04-17] (Google)
FF SearchPlugin: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\searchplugins\amazon-distro.xml [2012-12-13]
FF Extension: adblockvideo - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2012-09-15]
FF Extension: Bitdefender QuickScan - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2015-07-24]
FF Extension: feedly - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\[removed] [2013-05-10]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2012-12-12]
FF Extension: Adblock Plus - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-15]
FF Extension: User Agent Switcher - C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2013-05-06]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-06-30]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Video Downloader Plugin - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed]
FF Extension: Freemake Youtube Download Button - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[removed] [2013-04-25]
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-05-20]
FF HKLM\…\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-10-12]
FF HKLM\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKU\S-1-5-21-1992874582-3349113656-4066416677-1001\…\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
 
Chrome: 
=======
CHR Profile: C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (RealDownloader) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-04-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-21]
CHR Extension: (Skype Click to Call) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-09-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-13]
CHR HKLM\…\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-10-09]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-08-29] (SUPERAntiSpyware.com)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [5509384 2015-07-08] (Emsisoft Ltd)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-04-25] (Freemake) [File not signed]
R2 gzserv; C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [57520 2013-10-23] (Bitdefender)
S3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-13] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 LightScribeService; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [265912 2007-01-16] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [633344 2013-04-17] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [486536 2013-04-17] (BitDefender)
R1 bdftdif; C:\Program Files\Bitdefender\Antivirus Free Edition\bdftdif.sys [148600 2013-04-17] (Bitdefender SRL)
R1 bdselfpr; C:\Program Files\Bitdefender\Antivirus Free Edition\bdselfpr.sys [135472 2013-07-16] (BitDefender LLC)
S3 eapihdrv; C:\Users\Sharon\AppData\Local\Temp\ehdrv.sys [135760 2015-07-23] (ESET)
R1 epp32; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp32.sys [112408 2015-07-08] (Emsisoft GmbH)
R3 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [164952 2013-04-22] (BitDefender LLC)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [355744 2013-05-28] (BitDefender S.R.L.)
U5 avchv; C:\Windows\System32\Drivers\avchv.sys [0 2015-07-25] () <==== ATTENTION (zero byte File/Folder)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-26 10:25 - 2015-07-26 10:25 - 00017217 _____ C:\Users\Sharon\Desktop\FRST.txt
2015-07-25 05:44 - 2015-07-25 06:00 - 00000000 ____D C:\Users\Sharon\Desktop\FRST-OlderVersion
2015-07-25 02:30 - 2015-07-25 01:56 - 00000000 _____ C:\Windows\system32\Drivers\avchv.sys
2015-07-25 02:07 - 2015-07-25 02:07 - 00252294 _____ C:\ProgramData\1437816991.bdinstall.bin
2015-07-25 02:05 - 2015-07-25 02:05 - 00002013 _____ C:\Users\Public\Desktop\Bitdefender Antivirus Free Edition.lnk
2015-07-25 02:05 - 2015-07-25 02:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus Free Edition
2015-07-25 02:03 - 2015-07-25 02:03 - 00000000 ____H C:\Windows\system32\Drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2015-07-25 02:00 - 2009-07-13 17:19 - 00445008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2015-07-25 02:00 - 2009-07-13 17:19 - 00038480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2015-07-25 02:00 - 2009-06-10 13:27 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
2015-07-25 01:58 - 2015-07-25 02:03 - 00002374 _____ C:\Windows\setupact.log
2015-07-25 01:58 - 2015-07-25 01:58 - 00000000 _____ C:\Windows\setuperr.log
2015-07-25 01:57 - 2009-07-14 23:27 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2015-07-25 01:56 - 2013-04-17 14:59 - 00633344 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys
2015-07-25 01:56 - 2013-04-17 14:59 - 00486536 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys
2015-07-25 01:53 - 2015-07-25 02:05 - 00000000 ____D C:\Program Files\Bitdefender
2015-07-25 01:38 - 2013-05-28 12:11 - 00355744 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2015-07-25 01:38 - 2013-04-22 13:20 - 00164952 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2015-07-25 01:35 - 2015-07-25 01:36 - 09927424 _____ C:\Users\Sharon\Desktop\Antivirus_Free_Edition_x86.exe
2015-07-25 01:32 - 2015-07-25 01:33 - 00162208 _____ C:\Users\Sharon\Desktop\Antivirus_Free_Edition.exe
2015-07-24 05:53 - 2015-07-25 01:53 - 00000000 ____D C:\Users\Sharon\AppData\Roaming\QuickScan
2015-07-23 19:47 - 2015-07-23 19:47 - 00002280 _____ C:\Users\Sharon\Desktop\Hari Atma Kaur Khalsa Cover Letter.txt
2015-07-23 18:38 - 2015-07-23 18:38 - 00002426 _____ C:\Users\Sharon\Desktop\ESETScan.txt
2015-07-23 03:08 - 2015-07-23 03:08 - 02870984 _____ (ESET) C:\Users\Sharon\Desktop\esetsmartinstaller_enu (1).exe
2015-07-22 21:09 - 2015-07-22 22:22 - 00002273 _____ C:\Users\Sharon\Desktop\Hari Atma Kaur Khalsa resume.txt
2015-07-22 19:27 - 2015-07-23 02:55 - 00001331 _____ C:\Users\Sharon\Desktop\cover letter.txt
2015-07-22 02:42 - 2015-07-22 02:42 - 02248704 _____ C:\Users\Sharon\Desktop\adwcleaner_4.208.exe
2015-07-21 03:36 - 2015-07-21 03:36 - 00718104 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Sharon\Desktop\avgremover.exe
2015-07-21 00:16 - 2015-07-25 05:44 - 01650688 _____ (Farbar) C:\Users\Sharon\Desktop\FRST.exe
2015-07-19 04:15 - 2015-07-19 04:15 - 00000955 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-07-19 04:12 - 2015-07-20 21:21 - 00001360 _____ C:\blitzblank.log
2015-07-18 13:15 - 2015-07-18 13:15 - 00000000 ____D C:\Program Files\VS Revo Group
2015-07-18 02:43 - 2015-07-18 02:43 - 00000000 ____D C:\Program Files\ESET
2015-07-18 02:41 - 2015-07-18 02:41 - 02870984 _____ (ESET) C:\Users\Sharon\Desktop\esetsmartinstaller_enu.exe
2015-07-17 03:20 - 2015-07-21 04:04 - 00038120 _____ C:\Users\Sharon\Desktop\Addition.txt
2015-07-17 03:00 - 2015-07-17 03:00 - 01636864 _____ (Farbar) C:\Users\Sharon\Downloads\FRST.exe
2015-07-16 21:26 - 2015-07-16 20:37 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-16 20:40 - 2015-07-16 21:40 - 00021621 _____ C:\zoek-results.log
2015-07-16 20:36 - 2015-07-16 20:36 - 01308672 _____ C:\Users\Sharon\Desktop\zoek.exe
2015-07-16 20:31 - 2015-07-20 21:22 - 00002644 _____ C:\Windows\PFRO.log
2015-07-16 20:26 - 2015-07-16 20:26 - 01308672 _____ C:\Users\Sharon\Downloads\zoek (1).exe
2015-07-16 20:25 - 2015-07-16 21:20 - 00000000 ____D C:\zoek_backup
2015-07-16 20:24 - 2015-07-16 20:24 - 01308672 _____ C:\Users\Sharon\Desktop\zoek (1).exe
2015-07-16 20:08 - 2015-07-16 20:09 - 01308672 _____ C:\Users\Sharon\Downloads\zoek.exe
2015-07-14 05:39 - 2015-07-14 05:41 - 00034963 _____ C:\Users\Sharon\Downloads\Addition.txt
2015-07-14 05:35 - 2015-07-26 10:25 - 00000000 ____D C:\FRST
2015-07-13 10:24 - 2015-07-13 10:24 - 00000296 _____ C:\Windows\system32\spsys.log
2015-07-13 02:35 - 2015-07-13 02:35 - 00003121 _____ C:\Users\Sharon\Desktop\JRT.txt
2015-07-13 02:22 - 2015-07-13 02:22 - 00000207 _____ C:\Windows\tweaking.com-regbackup-HAK-PC-Windows-Vista-(TM)-Home-Basic-(32-bit).dat
2015-07-13 02:21 - 2015-07-13 02:21 - 00000000 ____D C:\RegBackup
2015-07-13 02:19 - 2015-07-13 02:19 - 00009208 _____ C:\Users\Sharon\Desktop\AdwCleaner[S0].txt
2015-07-13 02:16 - 2015-07-13 02:17 - 03034492 _____ (Malwarebytes Corporation) C:\Users\Sharon\Downloads\JRT.exe
2015-07-13 02:14 - 2015-07-13 02:14 - 00000000 ____D C:\Windows\pss
2015-07-13 02:00 - 2015-07-22 02:57 - 00000000 ____D C:\AdwCleaner
2015-07-13 01:58 - 2015-07-13 01:59 - 02248704 _____ C:\Users\Sharon\Downloads\adwcleaner_4.208.exe
2015-07-12 11:15 - 2015-07-12 11:15 - 00010182 _____ C:\Users\Sharon\Downloads\hijackthis.log
2015-07-12 11:14 - 2015-07-12 11:14 - 00388608 _____ (Trend Micro Inc.) C:\Users\Sharon\Downloads\HiJackThis.exe
2015-07-10 03:41 - 2015-07-10 03:41 - 00027329 _____ C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!.html
2015-07-10 03:41 - 2015-07-10 03:41 - 00000000 ____D C:\Users\Sharon\Downloads\What the Tech _ HijackThis – Quick Start!_files
2015-07-08 16:22 - 2015-07-12 11:21 - 00001356 _____ C:\Users\Sharon\AppData\Local\d3d9caps.dat
2015-07-08 14:46 - 2015-07-26 10:12 - 00662222 _____ C:\Windows\WindowsUpdate.log
2015-07-07 10:56 - 2015-07-07 10:56 - 00000810 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-07 10:56 - 2015-07-07 10:56 - 00000000 ____D C:\Program Files\CCleaner
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507.exe
2015-07-07 10:54 - 2015-07-07 10:55 - 06565736 _____ (Piriform Ltd) C:\Users\Sharon\Downloads\ccsetup507 (1).exe
2015-07-07 01:38 - 2015-07-07 01:44 - 00000000 ____D C:\ProgramData\Emsisoft
2015-07-07 01:10 - 2015-07-07 01:11 - 00000000 ____D C:\Program Files\TrojanHunter
2015-07-07 01:10 - 2015-07-07 01:10 - 00000858 _____ C:\Users\Sharon\Desktop\TrojanHunter.lnk
2015-07-07 01:10 - 2015-07-07 01:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
2015-07-07 01:09 - 2015-07-07 01:09 - 04069672 _____ (Bytelayer AB ) C:\Users\Sharon\Downloads\TrojanHunterSetup.exe
2015-07-06 17:15 - 2015-07-06 17:15 - 00000894 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2015-07-06 17:15 - 2015-07-06 17:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2015-07-06 17:14 - 2015-03-24 00:17 - 00111368 _____ (Emsisoft GmbH) C:\Windows\system32\Drivers\epp32.sys
2015-07-06 17:13 - 2015-07-26 10:23 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2015-07-06 16:13 - 2015-07-06 16:30 - 167273960 _____ (Emsisoft Ltd. ) C:\Users\Sharon\Downloads\EmsisoftAntiMalwareSetup.exe
2015-07-05 12:46 - 2015-07-05 12:46 - 00242712 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 39.0.exe
2015-07-05 10:22 - 2015-07-05 10:26 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Sharon\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-07-03 14:20 - 2015-07-03 14:20 - 01125056 _____ (Adobe Systems Incorporated) C:\Users\Sharon\Downloads\flashplayer18_ha_install.exe
2015-07-02 13:55 - 2015-07-02 13:55 - 00243408 _____ C:\Users\Sharon\Downloads\Firefox Setup Stub 38.0.5.exe
2015-06-30 12:25 - 2015-07-05 14:17 - 00000000 ____D C:\Program Files\Mozilla Firefox
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-26 10:23 - 2007-05-10 11:27 - 00000000 ____D C:\Windows\SMINST
2015-07-26 10:22 - 2015-05-10 16:53 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job
2015-07-26 10:22 - 2013-04-27 03:03 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-26 10:22 - 2012-10-18 13:49 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-26 10:22 - 2006-11-02 04:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-26 10:22 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-26 10:22 - 2006-11-02 04:45 - 00003456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-26 04:31 - 2014-07-27 15:41 - 00000568 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-26 04:30 - 2013-04-27 03:03 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-26 03:53 - 2015-05-30 13:19 - 00000664 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
2015-07-26 03:27 - 2014-11-26 20:01 - 00000000 ____D C:\Users\Sharon\Desktop\W2'3 Ut GBS
2015-07-25 12:16 - 2015-05-10 16:53 - 00000860 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job
2015-07-25 02:42 - 2006-11-02 04:58 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-07-25 01:58 - 2012-06-06 18:33 - 00000000 ____D C:\Users\Sharon
2015-07-20 21:22 - 2012-07-09 10:00 - 00000000 ____D C:\ProgramData\MFAData
2015-07-19 04:14 - 2012-06-06 18:34 - 00000950 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-07-19 04:14 - 2012-06-06 18:34 - 00000921 _____ C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2015-07-17 03:28 - 2014-04-11 17:05 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-16 21:40 - 2013-02-18 13:09 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-07-16 21:16 - 2006-11-02 03:18 - 00000000 ___RD C:\Users\Public
2015-07-16 21:16 - 2006-11-02 03:18 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-07-16 03:22 - 2013-07-14 19:21 - 00000000 ____D C:\Windows\system32\MRT
2015-07-14 23:47 - 2012-07-08 00:30 - 00000000 ____D C:\Users\Sharon\AppData\Roaming\Skype
2015-07-14 21:20 - 2012-07-08 00:19 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-14 21:20 - 2012-07-08 00:19 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-08 15:04 - 2013-05-06 08:20 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-07 11:00 - 2012-07-17 15:02 - 00000000 ____D C:\Windows\Minidump
2015-07-07 11:00 - 2007-05-10 11:06 - 00000000 ____D C:\Windows\Panther
2015-07-07 01:25 - 2012-06-06 18:33 - 00000000 ____D C:\Users\Sharon\AppData\Local\VirtualStore
2015-07-05 14:17 - 2013-03-09 15:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-07-05 14:16 - 2006-11-02 04:35 - 00000000 ____D C:\Windows\DigitalLocker
2015-07-05 12:50 - 2013-03-09 15:52 - 00000864 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-05 12:50 - 2013-03-09 15:52 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-05 10:30 - 2014-04-11 17:02 - 00000905 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-05 10:30 - 2014-04-11 17:02 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-07-03 08:49 - 2006-11-02 02:24 - 127070192 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
 
==================== Files in the root of some directories =======
 
2015-07-08 16:22 - 2015-07-12 11:21 - 0001356 _____ () C:\Users\Sharon\AppData\Local\d3d9caps.dat
2012-07-08 02:19 - 2015-05-06 19:35 - 0025088 _____ () C:\Users\Sharon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-25 02:07 - 2015-07-25 02:07 - 0252294 _____ () C:\ProgramData\1437816991.bdinstall.bin
2007-05-10 10:43 - 2013-03-21 07:29 - 0002738 _____ () C:\ProgramData\hpzinstall.log
 
Some files in TEMP:
====================
C:\Users\Sharon\AppData\Local\Temp\gb-installer-nsi.exe
C:\Users\Sharon\AppData\Local\Temp\Quarantine.exe
C:\Users\Sharon\AppData\Local\Temp\sqlite3.dll
 
 
Some zero byte size files/folders:
==========================
C:\Windows\System32\Drivers\avchv.sys
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-26 05:08
 
==================== End of log ============================

Let’s clear what we’ve done before with some logs and try again,

Uninstall AdwCleaner

  • double click on adwcleaner.exe to run the tool
  • click on Uninstall
  • confirm with Yes

===================================================

Download & run Delfix

  • download Delfix from here to remove many of the tools we've used during the cleaning process.
  • ensure “Remove disinfection tools” is checked.

Also place a checkmark next to:


o    Create registry backup
o    Purge system restore

  • click the Run button.

You can delete all other logs and programs we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

Please send me the new log,
 

Satchfan

 

Satchfan,

 

I could not run any of the programs you indicated.  It takes minutes to open programs or different windows if they do open.  It seems to have been worse since I downloaded BitDefender.  I am not saying that is the cause though.  I finally went to Safe Mode and uninstalled Adw.  I ran Delfix but did not delete the files on desktop.  I tried to do it manually bit would only delete 3 of 12.  I ran Adw and after it ran, I got a blue screen.  On restart, the other programs were deleted but it did not leave a log.  Again the computer was extremely slow and could not open programs except for Chrome.  I opened Safe mode with networking and I am in that now.  I noticed that I typed in yahoo.com and the computer said "waiting for googleads.g.doubleclick.com"

 

Thanks

GB

Strange that nothing has picked that up.

 

Let's try a different scan.

 

Download Combofix from either of the links below, and save it to your desktop.  

Link 1
Link 2

**Note:  It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.

  • when finished, it will produce a report for you
  • please post the C:\ComboFix.txt in your next post.

Satchfan

 

ComboFix 15-07-23.01 - Sharon 07/27/2015  11:15:31.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Basic   6.0.6000.0.1252.1.1033.18.1918.987 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1437816991.bdinstall.bin
c:\programdata\1438014410.bdinstall.bin
c:\programdata\1438014417.bdinstall.bin
c:\programdata\ntuser.pol
c:\users\Sharon\Documents\~WRL0003.tmp
c:\users\Sharon\Documents\~WRL3123.tmp
c:\users\Sharon\Documents\~WRL3525.tmp
c:\windows\system32\Cache
c:\windows\system32\Cache\07eaed9d8f634579.fb
c:\windows\system32\Cache\26c630d098e22dd5.fb
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\95f567698be8a182.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
c:\windows\system32\spsys.log
.
.
(((((((((((((((((((((((((   Files Created from 2015-06-27 to 2015-07-27  )))))))))))))))))))))))))))))))
.
.
2015-07-27 19:22 . 2015-07-27 19:22 ——– d—–w- c:\users\Default\AppData\Local\temp
2015-07-27 16:33 . 2015-07-27 16:34 ——– d—–w- C:\AdwCleaner
2015-07-27 16:16 . 2015-07-27 16:16 ——– d—–w- c:\windows\ERUNT
2015-07-26 19:02 . 2015-07-26 19:02 242504 —-a-w- c:\windows\system32\drivers\avchv.sys
2015-07-25 10:00 . 2009-07-14 01:19 38480 —-a-w- c:\windows\system32\drivers\WdfLdr.sys
2015-07-25 10:00 . 2009-07-14 01:19 445008 —-a-w- c:\windows\system32\drivers\Wdf01000.sys
2015-07-25 09:57 . 2009-07-15 07:27 1461992 —-a-w- c:\windows\system32\WdfCoInstaller01009.dll
2015-07-25 09:56 . 2013-04-17 22:59 633344 —-a-w- c:\windows\system32\drivers\avc3.sys
2015-07-25 09:56 . 2013-04-17 22:59 486536 —-a-w- c:\windows\system32\drivers\avckf.sys
2015-07-25 09:53 . 2015-07-25 10:05 ——– d—–w- c:\program files\Bitdefender
2015-07-25 09:38 . 2013-04-22 21:20 164952 —-a-w- c:\windows\system32\drivers\gzflt.sys
2015-07-25 09:38 . 2013-05-28 20:11 355744 —-a-w- c:\windows\system32\drivers\trufos.sys
2015-07-24 13:53 . 2015-07-25 09:53 ——– d—–w- c:\users\Sharon\AppData\Roaming\QuickScan
2015-07-18 21:15 . 2015-07-18 21:15 ——– d—–w- c:\program files\VS Revo Group
2015-07-18 10:43 . 2015-07-18 10:43 ——– d—–w- c:\program files\ESET
2015-07-17 05:26 . 2015-07-17 04:37 24064 —-a-w- c:\windows\zoek-delete.exe
2015-07-17 05:26 . 2015-07-27 19:22 ——– d—–w- c:\users\Sharon\AppData\Local\Temp
2015-07-07 18:56 . 2015-07-07 18:56 ——– d—–w- c:\program files\CCleaner
2015-07-07 09:38 . 2015-07-07 09:44 ——– d—–w- c:\programdata\Emsisoft
2015-07-07 09:10 . 2015-07-07 09:11 ——– d—–w- c:\program files\TrojanHunter
2015-07-07 01:14 . 2015-03-24 08:17 111368 —-a-w- c:\windows\system32\drivers\epp32.sys
2015-07-07 01:13 . 2015-07-27 16:40 ——– d—–w- c:\program files\Emsisoft Anti-Malware
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-17 11:28 . 2014-04-12 01:05 98520 —-a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-07-15 05:20 . 2012-07-08 08:19 778416 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2015-07-15 05:20 . 2012-07-08 08:19 142512 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-06-18 16:41 . 2014-04-12 01:02 51928 —-a-w- c:\windows\system32\drivers\mwac.sys
2015-06-18 16:41 . 2014-04-12 01:02 94936 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-06-18 16:41 . 2013-05-04 15:14 23256 —-a-w- c:\windows\system32\drivers\mbam.sys
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-02-11 90192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-11 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-11 81920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 4390912]
"SnapfishMediaDetector"="c:\program files\Snapfish Media Detector\SnapfishMediaDetector.exe" [2007-03-02 1441792]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-03-07 44168]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Snapfish Media Detector.lnk - c:\program files\Snapfish Media Detector\SnapfishMediaDetector.exe [2007-3-2 1441792]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Sharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk]
path=c:\users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.4.1.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
2015-06-01 18:27 6405912 —-a-w- c:\program files\CCleaner\CCleaner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\emsisoft anti-malware]
2015-07-08 22:45 4933096 —-a-w- c:\program files\Emsisoft Anti-Malware\a2guard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeScreenSharing]
2012-08-03 10:57 2265424 —-a-w- c:\users\Sharon\AppData\Local\FreeScreenSharing\FreeScreenSharing.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2015-05-11 00:53 107848 —-atw- c:\users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
2007-09-04 22:52 54576 —-a-w- c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2015-01-23 23:40 31087200 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard]
2015-06-18 16:13 1082832 —-a-w- c:\program files\TrojanHunter\THGuard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe"  -osboot
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 a2AntiMalware;Emsisoft Protection Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2015-07-08 5509384]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2014-08-29 142648]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - ECACHE
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ   PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ   Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ   hpqcxs08
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-07-25 20:30 995144 —-a-w- c:\program files\Google\Chrome\Application\44.0.2403.107\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2015-07-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-08 05:20]
.
2015-07-27 c:\windows\Tasks\G2MUpdateTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
- c:\users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupdate.exe [2015-07-10 03:15]
.
2015-07-27 c:\windows\Tasks\G2MUploadTask-S-1-5-21-1992874582-3349113656-4066416677-1001.job
- c:\users\Sharon\AppData\Local\Citrix\GoToMeeting\3019\g2mupload.exe [2015-07-10 03:15]
.
2015-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-04-27 11:00]
.
2015-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-04-27 11:00]
.
2015-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001Core.job
- c:\users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-11 00:53]
.
2015-07-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1992874582-3349113656-4066416677-1001UA.job
- c:\users\Sharon\AppData\Local\Google\Update\GoogleUpdate.exe [2015-05-11 00:53]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = about:blank
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\
.
.
——- File Associations ——-
.
inifile="%SystemRoot%\system32\NOTEPAD.EXE" %1
txtfile="%SystemRoot%\system32\NOTEPAD.EXE" %1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2015-07-27 11:22
Windows 6.0.6000  NTFS
.
scanning hidden processes …  
.
scanning hidden autostart entries … 
.
scanning hidden files …  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2015-07-27  11:24:24
ComboFix-quarantined-files.txt  2015-07-27 19:24
.
Pre-Run: 99,830,276,096 bytes free
Post-Run: 99,946,733,568 bytes free
.
- - End Of File - - DDB5617C1C76D041449BF2B71207FD56
8913823FF508CCF109DB74B636C301DA

That message in itself is not necessarily an indication that anything is wrong. Let’s try resetting your browsers.

Download zoek.exe again and save it to your Desktop:

Important: Disable your AntiVirus and AntiSpyware programs so they do not interfere with the running of the program.

  • on Windows Vista, 7/8, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    autoclean;
    emptyalltemp;
    emptyclsid;
    FFdefaults;
    iedefaults;
    chrdefaults;
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

Please include the zoek-results.log with the next post and let me know how things are now.

Satchfan

 

Satchfan,

 

I could not run Chrome or download zoek in normal startup so I did it in Safe Mode with Networking.  I did not see the log  on desktop but I found 2  files in C drive.  One was  a temp file with nothing in it and this is the other.  I hope it is the one you want.  I can use the computer in normal startup and it is better but still seems sluggish.

 

Thanks,

GB

 

restore;|C_Windows_Installer_3cec28.msi.vir|C:\Windows\Installer\3cec28.msi
restore;|C_Users_Sharon_AppData_Local_Google_Chrome_User Data_Default_Local Storage_http_www.bradsdeals.com_0.localstorage.vir|C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bradsdeals.com_0.localstorage
restore;|C_Users_Sharon_AppData_Local_Google_Chrome_User Data_Default_Local Storage_http_www.bradsdeals.com_0.localstorage-journal.vir|C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bradsdeals.com_0.localstorage-journal
 
Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Sharon on Tue 07/28/2015 at 21:12:03.50.
Microsoft® Windows Vista™ Home Basic  6.0.6000  x86
Running in: Safe Mode NETWORK Internet Access Detected
Launched: C:\Users\Sharon\Desktop\zoek.exe [Scan all users] [Script inserted] 
 
==== System Restore Info ======================
 
==== Empty Folders Check ======================
 
C:\Program Files\VS Revo Group deleted successfully
 
==== Deleting CLSID Registry Keys ======================
 
 
==== Deleting CLSID Registry Values ======================
 
 
==== Deleting Services ======================
 
 
==== FireFox Fix ======================
 
Deleted from C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\prefs.js:
 
Added to C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
 
==== Deleting Files \ Folders ======================
 
C:\Program Files\VS Revo Group not found
"C:\Windows\Installer\3cec28.msi" deleted
 
==== Firefox Start and Search pages ======================
 
ProfilePath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
 
==== Firefox Extensions Registry ======================
 
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [10/12/2013 08:51 PM]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04/04/2014 02:36 AM]
 
==== Firefox Extensions ======================
 
ProfilePath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
- adblockvideo - %ProfilePath%\extensions\[removed]
- Bitdefender QuickScan - %ProfilePath%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
- feedly - %ProfilePath%\extensions\[removed]
- Download YouTube Videos as MP4 - %ProfilePath%\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- User Agent Switcher - %ProfilePath%\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi
 
AppDir: C:\Program Files\Mozilla Firefox
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
==== Firefox Plugins ======================
 
Profilepath: C:\Users\Sharon\AppData\Roaming\Mozilla\Firefox\Profiles\jmphnpxt.default
0D18EE6AA78A9B3E8F95712812EF1DE8 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.1.3
69381B2D346878637D793407B29A7804 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.1.3
61967C540F5E29A5F1FDFDBE4F8967B0 - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.1.3
E2D0341646A7BAE01A477DAEB924B490 - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.1.3
D55959632B71CE1F9C992BCE7D7E41DA - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.1.3
2D7AB3805EFF23BB6D6C7AA44CE65EEE - C:\Program Files\QuickTime\Plugins\npqtplugin6.dll - QuickTime Plug-in 7.1.3
38D097E51BA924D79C2C735D1B33152A - C:\Program Files\QuickTime\Plugins\npqtplugin7.dll - QuickTime Plug-in 7.1.3
F055C91A961601B8D50EF2976145AEE6 - C:\Program Files\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat
1E5E8C84DE796A01D1D46E3A660690F1 - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
1F352B5944AF5C2204D9EFF7F845C5AF - C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll - Google Update
F8CB60A5ACA5D73807ECBD9942A8BCB7 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll - RealDownloader Plugin
4356F21FB6D547F22BFBC91164A597A6 - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll - RealNetworks Rhapsody Player Engine
96B3689320E9B16EDF38B7A5001C35F0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealNetworks™ RealDownloader HTML5VideoShim Plug-In (32-bit)
EAC427FEF96A13058C1ACD17C38966CF - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll - RealNetworks™ RealDownloader PepperFlashVideoShim Plug-In (32-bit)
BE126CB7049E89ED6F3038016668B502 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll - RealNetworks™ RealDownloader Chrome Background Extension Plug-In (32-bit)
0FCEAA7D12B7B0BA825E5C770B1DCA48 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll - RealPlayer Download Plugin
3A9E1940B4459CC97FDCBB24FCB69004 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll - RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit)
AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
5B4DA1113F240C3F06FFF9D52761528B - C:\Program Files\Google\Picasa3\npPicasa3.dll - Picasa
FD82108FD60B63010325D9AF6F00AF99 - C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll - Shockwave Flash
3BD80F4DAE84A0CBB153CB49A171B0FC - C:\Users\Sharon\AppData\Roaming\Zoom\bin\npzoomplugin.dll - Zoom launcher - 3.0.1
1F352B5944AF5C2204D9EFF7F845C5AF - C:\Users\Sharon\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll - Google Update
E3B4EA121F7BDEB0F6366E2BA9608CB5 - C:\Users\Sharon\AppData\Local\Citrix\Plugins\104\npappdetector.dll - Citrix Online Web Deployment Plugin 1.0.0.104
49D429EBF5305FC9ADD7545B7C914333 - C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin
6BEAD7859E8A087BE04556AB5A78855C - C:\Users\Sharon\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer
 
 
==== Chromium Look ======================
 
Google Chrome Version: 44.0.2403.107
 
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[08/14/2013 03:24 PM]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[10/09/2013 10:59 AM]
 
RealDownloader - Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
Chrome Hotword Shared Module - Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
Skype Click to Call - Sharon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
 
==== Chromium Startpages ======================
 
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Preferences
rt":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":101394},"supports_spdy":true},"www.googletagservices.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.gstatic.com:443":{"supports_spdy":true},"www.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.yahoo.com:443":{"supports_spdy":true},"www.youtube.com:443":{"supports_spdy":true},"www.youtube.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"yt3.ggpht.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":464622},"supports_spdy":true}},"supports_quic":{"address":"192.168.2.3","used_quic":true},"version":3}},"ntp":{"most_visited_blacklist":{"a6ef4bc3b579694e50cd2230dff605b5":null}},"partition":{"per_host_zoom_levels":{"2166136261":{}}},"password_bubble":{"nopes":0},"plugins":{"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"printing":{"print_preview_sticky_settings":{"appState":"{\"version\":2,\"isGcpPromoDismissed\":false,\"selectedDestinationId\":\"Save as PDF\",\"selectedDestinationOrigin\":\"local\",\"selectedDestinationAccount\":\"\",\"selectedDestinationCapabilities\":null,\"selectedDestinationName\":\"Save as PDF\",\"mediaSize\":{\"height_microns\":279400,\"is_default\":true,\"name\":\"NA_LETTER\",\"width_microns\":215900,\"custom_display_name\":\"Letter\"},\"selectedDestinationExtensionId\":\"\",\"customMargins\":null,\"vendorOptions\":{},\"selectedDestinationExtensionName\":\"\",\"isColorEnabled\":false,\"isDuplexEnabled\":false,\"marginsType\":0}","savePath":"C:\\Users\\Sharon\\Documents"}},"profile":{"avatar_bubble_tutorial_shown":1,"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{},"geolocation":{},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"https://www.craigslist.org:443,https://www.craigslist.org:443":{"geolocation":2}},"pref_version":1},"default_content_settings":{},"exit_type":"Normal","exited_cleanly":true,"icon_version":3,"managed_user_id":"","migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"Firstuser","password_manager_groups_for_domains":[2,null,null,null,0,null,4],"per_host_zoom_levels":{}},"protection":{"macs":{}},"savefile":{"default_directory":"C:\\Users\\Sharon\\Desktop","type":1},"selectfile":{"last_directory":"C:\\Users\\Sharon\\Pictures\\2015-05-28"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13041824175471000"},"sync":{"memory_warning_count":14067},"translate_accepted_count":{"de":0,"en":0,"hu":0,"is":0,"zh-CN":0},"translate_blocked_languages":["en"],"translate_denied_count":{"de":1,"en":1,"hu":1,"zh-CN":2},"translate_denied_count_for_language":{"is":1},"translate_last_denied_time":1437732281781.8,"translate_last_denied_time_for_language":{"is":1438117653691.308},"translate_too_often_denied":true,"translate_whitelists":{},"zerosuggest":{"cachedresults":""}}
 
 
==== Chromium Fix ======================
 
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bradsdeals.com_0.localstorage deleted successfully
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bradsdeals.com_0.localstorage-journal deleted successfully
 
==== Set IE to Default ======================
 
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
 
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
 
==== All HKCU SearchScopes ======================
 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
 
==== Reset Google Chrome ======================
 
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF1120f9f.TMP was reset successfully
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF12205c0.TMP will be reset at reboot
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
 
==== Deleting Registry Keys ======================
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4E30E037E0535E84D9E3349209D354D4 deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{730E03E4-350E-48E5-9D3E-4329903D454D} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4E30E037E0535E84D9E3349209D354D4 deleted successfully
 
==== Empty IE Cache ======================
 
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FJT50IAM will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JBG5KDNY will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NQYXMM63 will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XQ6N2PCQ will be deleted at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7XRMCVZ2 will be deleted at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EJJ2B266 will be deleted at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YL3FXUJG will be deleted at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZH2G5JDO will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FJT50IAM will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JBG5KDNY will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NQYXMM63 will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XQ6N2PCQ will be deleted at reboot
C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
 
==== Empty FireFox Cache ======================
 
C:\Users\Sharon\AppData\Local\Mozilla\Firefox\Profiles\jmphnpxt.default\cache2 emptied successfully
 
==== Empty Chrome Cache ======================
 
C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
 
==== Empty All Flash Cache ======================
 
Flash Cache Emptied Successfully
 
==== Empty All Java Cache ======================
 
No Java Cache Found
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=4 folders=0 101467 bytes)
 
==== Empty Temp Folders ======================
 
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Users\Sharon\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
 
==== After Reboot ======================
 
==== Empty Temp Folders ======================
 
C:\Windows\Temp successfully emptied
C:\Users\Sharon\AppData\Local\Temp successfully emptied
 
==== Empty Recycle Bin ======================
 
C:\$RECYCLE.BIN successfully emptied
 
==== Deleting Files / Folders ======================
 
"C:\Users\Sharon\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF12205c0.TMP" not found
"C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FJT50IAM" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JBG5KDNY" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NQYXMM63" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XQ6N2PCQ" not found
"C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7XRMCVZ2" not deleted
"C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EJJ2B266" not deleted
"C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YL3FXUJG" not deleted
"C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZH2G5JDO" not deleted
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FJT50IAM" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JBG5KDNY" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NQYXMM63" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XQ6N2PCQ" not found
 
==== EOF on Tue 07/28/2015 at 21:41:51.39 ======================

Glad things are better.

 

We need to clear up a few stragglers from your last FRST log.


Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

U5 avchv; C:\Windows\System32\Drivers\avchv.sys [0 2015-07-25] () <==== ATTENTION (zero byte File/Folder)
2015-07-25 05:44 - 2015-07-25 06:00 - 00000000 ____D C:\Users\Sharon\Desktop\FRST-OlderVersion
2015-07-25 02:30 - 2015-07-25 01:56 - 00000000 _____ C:\Windows\system32\Drivers\avchv.sys
C:\Users\Sharon\Desktop\FRST-OlderVersion
C:\Windows\system32\Drivers\avchv.sys
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

===================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.


NOTE: If you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED!, try rebooting the system and then run SecurityCheck again.

Satchfan

Satchfan,

 

 I ran FRST and then it rebooted by itself.  I got message that computer would not work right.  I forgot the exact words and it had me click "close" or to find out more information.  I clicked on the more info one and it took me to a Microsoft site that was selling Office and an OS.  I also clicked close and it closed me out of the program.  I went to Safe Mode with networking and got the log and the other scan.  Here are the logs.

Thanks 

GB

 

Results of screen317's Security Check version 1.006  
 Windows Vista  x86 (UAC is enabled)  
 Out of date service pack!! 
 Internet Explorer 7 Out of date! 
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Security Center service is not running! This report may not be accurate! 
 Windows Firewall Enabled!  
 WMI entry may not exist for antivirus; attempting automatic update. 
`````````Anti-malware/Other Utilities Check:````````` 
 SUPERAntiSpyware     
 CCleaner     
 Adobe Flash Player 9 Flash Player out of Date! 
 Adobe Flash Player 18.0.0.209  
 Adobe Reader 10.1.10 Adobe Reader out of Date!  
 Mozilla Firefox (39.0) 
 Google Chrome (44.0.2403.107) 
 Google Chrome (44.0.2403.125) 
````````Process Check: objlist.exe by Laurent````````  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 1 % 
````````````````````End of Log`````````````````````` 
 
Results of screen317's Security Check version 1.006  
 Windows Vista  x86 (UAC is enabled)  
 Out of date service pack!! 
 Internet Explorer 7 Out of date! 
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Security Center service is not running! This report may not be accurate! 
 Windows Firewall Enabled!  
 WMI entry may not exist for antivirus; attempting automatic update. 
`````````Anti-malware/Other Utilities Check:````````` 
 SUPERAntiSpyware     
 CCleaner     
 Adobe Flash Player 9 Flash Player out of Date! 
 Adobe Flash Player 18.0.0.209  
 Adobe Reader 10.1.10 Adobe Reader out of Date!  
 Mozilla Firefox (39.0) 
 Google Chrome (44.0.2403.107) 
 Google Chrome (44.0.2403.125) 
````````Process Check: objlist.exe by Laurent````````  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 1 % 
````````````````````End of Log`````````````````````` 
 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI