This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win 8.1 Notebook Suffering from Pop-Ups and Browser Redirects

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-08-03 00:08:57
—————————–
00:08:57.757    OS Version: Windows x64 6.2.9200 
00:08:57.757    Number of processors: 4 586 0x4501
00:08:57.758    ComputerName: AYSO  UserName: 
00:09:00.593    Initialize success
00:09:00.965    VM: initialized successfully
00:09:00.966    VM: Intel CPU BiosDisabled 
00:11:16.470    AVAST engine defs: 15080201
00:26:17.865    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002f
00:26:17.868    Disk 0 Vendor: ST500LM000-SSHD-8GB LVD4 Size: 476940MB BusType: 11
00:26:17.970    Disk 0 MBR read successfully
00:26:17.973    Disk 0 MBR scan
00:26:18.079    Disk 0 unknown MBR code
00:26:18.091    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
00:26:18.682    Disk 0 scanning C:\windows\system32\drivers
00:27:11.436    Service scanning
00:28:21.023    Modules scanning
00:28:21.030    Disk 0 trace - called modules:
00:28:21.037    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll iaStorA.sys 
00:28:21.070    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe001c83ba350]
00:28:21.079    3 CLASSPNP.SYS[fffff8000f774170] -> nt!IofCallDriver -> [0xffffe001c6408b70]
00:28:21.090    5 ACPI.sys[fffff8000f452c21] -> nt!IofCallDriver -> \Device\0000002f[0xffffe001c6408060]
00:28:25.399    AVAST engine scan C:\windows
00:28:33.367    AVAST engine scan C:\windows\system32
00:45:38.578    AVAST engine scan C:\windows\system32\drivers
00:46:35.427    AVAST engine scan C:\Users\Carson
00:57:04.432    AVAST engine scan C:\ProgramData
01:03:50.524    Disk 0 statistics 4629259/0/0 @ 2.24 MB/s
01:03:50.532    Scan finished successfully
01:19:40.568    Disk 0 MBR has been saved successfully to "C:\Users\Carson\Desktop\MBR.dat"
01:19:40.639    The log file has been saved successfully to "C:\Users\Carson\Desktop\aswMBR.txt"
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:02-08-2015 01
Ran by [removed] (administrator) on AYSO (03-08-2015 01:21:10)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(LENOVO INCORPORATED.) C:\Program Files\lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Maxthon) C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
(VentureOmni Technologies) C:\Users\Carson\AppData\Local\ArcadeTwist\cat\VOTPrx.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\mcafee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.5.450.0\McCSPServiceHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
() C:\Program Files\Stagelight\StagelightUpdate.exe
(Lenovo) C:\Program Files\lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(ArcadeTwist) C:\Users\Carson\AppData\Local\ArcadeTwist\AtwRun.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Pokki) C:\Users\Carson\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe
(Apple Inc.) C:\Program Files\iTunes\iTunes.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(LogMeIn, Inc.) C:\Users\Carson\AppData\Local\LogMeIn Rescue Applet\LMIR0002.tmp\lmi_rescue.exe
(LogMeIn, Inc.) C:\Users\Carson\AppData\Local\LogMeIn Rescue Applet\LMIR0002.tmp\LMI_Rescue_srv.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Rescue RC - e49fe85b-3cb3-4f16-bf24-6c0237fed2c7\LMIRescueRC.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe
(McAfee, Inc.) C:\Program Files\mcafee\VirusScan\mcods.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe
(AVAST Software) C:\Users\Carson\Downloads\aswMBR.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-10-17] (NVIDIA Corporation)
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-02-26] (Intel Corporation)
HKLM\…\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2013-10-17] (Realtek semiconductor)
HKLM\…\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-04] (Conexant Systems, Inc.)
HKLM\…\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-25] ()
HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-12] (Conexant Systems, Inc.)
HKLM\…\Run: [StageLightUpdate] => C:\Program Files\Stagelight\StagelightUpdate.exe [1397208 2014-08-29] ()
HKLM\…\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-09-14] (Lenovo)
HKLM\…\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2015-02-02] (Lenovo(beijing) Limited)
HKLM\…\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2015-02-02] (Lenovo(beijing) Limited)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM-x32\…\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe [110344 2014-09-09] (CyberLink)
HKLM-x32\…\Run: [CLVirtualDrive] => C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe [492808 2014-09-09] (CyberLink Corp.)
HKLM-x32\…\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [719272 2015-04-02] (McAfee, Inc.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
HKLM\…\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-10-29] (Qualcomm®Atheros®)
HKLM\…\Policies\Explorer: [NoFolderOptions] 0
HKLM\…\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2117907334-324167741-1091666529-1002\…\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.95\OptProLauncher.exe
HKU\S-1-5-21-2117907334-324167741-1091666529-1002\…\RunOnce: [Application Restart #3] => C:\Users\Carson\AppData\Local\Pokki\Engine\HostAppService.exe [7867904 2015-07-31] (Pokki)
AppInit_DLLs: C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL => C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL File not found
AppInit_DLLs-x32: C:\PROGRA~3\{56ACB~1\1172~1.1\dola.dll => "C:\PROGRA~3\{56ACB~1\1172~1.1\dola.dll" File not found
AppInit_DLLs-x32:  C:\PROGRA~2\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32Loader.dll => C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32Loader.dll [173896 2014-08-25] (ClientConnect LTD)
AppInit_DLLs-x32:  C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~3.DLL => C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonExtIE.dll [106304 2014-09-26] (Amazon Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2117907334-324167741-1091666529-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2117907334-324167741-1091666529-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-2117907334-324167741-1091666529-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://mystart.lenovo.com
URLSearchHook: [S-1-5-21-2117907334-324167741-1091666529-1001] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {9143e921-7c9a-4d27-ac43-eaccc78cc55a} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2117907334-324167741-1091666529-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2117907334-324167741-1091666529-1002 -> {9143e921-7c9a-4d27-ac43-eaccc78cc55a} URL = http://search.homepage-web.com/?src=omnibox&partner;=lenovo&q;={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-06-25] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-06-25] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\MSC\McSnIePl64.dll [2015-04-07] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2015-04-07] (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{47C05834-2A1F-4CDF-8AF8-DE51228E2FE7}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{80B328E7-A7C8-4844-B086-6AA517AEA392}: [DhcpNameServer] 192.168.1.7
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-04-07] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-04-07] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2013-12-12] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-23] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-23] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-02] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
 
Chrome: 
=======
CHR Profile: C:\Users\Carson\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Carson\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-06]
CHR Extension: (Google Docs) - C:\Users\Carson\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-06]
CHR Extension: (Google Drive) - C:\Users\Carson\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-04-06]
CHR Extension: (YouTube) - C:\Users\Carson\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-04-06]
CHR Extension: (Google Search) - C:\Users\Carson\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-06]
CHR Extension: (Google Sheets) - C:\Users\Carson\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-06]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Carson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Carson\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-06]
CHR Extension: (Gmail) - C:\Users\Carson\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-06]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 0037251438537121mcinstcleanup; C:\windows\TEMP\003725~1.EXE [883024 2015-04-06] (McAfee, Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [317568 2013-10-29] (Windows (R) Win 7 DDK provider) [File not signed]
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [592880 2014-07-09] ()
S4 CltMngSvc; C:\Program Files (x86)\LenovoBrowserGuard\Main\bin\CltMngSvc.exe [2538824 2014-08-25] (ClientConnect LTD)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-02-26] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344976 2015-03-31] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [561408 2014-09-22] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584632 2015-03-06] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2015-02-02] (Lenovo(beijing) Limited)
R2 LMIRescue_e49fe85b-3cb3-4f16-bf24-6c0237fed2c7; C:\Users\Carson\AppData\Local\LogMeIn Rescue Applet\LMIR0002.tmp\LMI_Rescue_srv.exe [3306336 2015-08-02] (LogMeIn, Inc.)
R2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [1872152 2015-05-14] (Maxthon)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [753768 2015-04-07] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.5.450.0\McCSPServiceHost.exe [207344 2015-04-08] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
R3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [612688 2015-04-09] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-02-17] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [372144 2015-04-06] (McAfee, Inc.)
R2 mfevtp; C:\windows\system32\mfevtps.exe [250672 2015-02-17] (McAfee, Inc.)
R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-12] (Nitro PDF Software)
R2 PSI_SVC_2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (arvato digital services llc)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2015-02-02] ()
R2 VOTPrx; C:\Users\Carson\AppData\Local\ArcadeTwist\cat\VOTPrx.exe [1733864 2015-03-23] (VentureOmni Technologies)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-10-29] (Atheros) [File not signed]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3880448 2013-11-13] (Qualcomm Atheros Communications, Inc.)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-10-29] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [68784 2015-02-17] (McAfee, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [401736 2015-02-17] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [337888 2015-02-17] (McAfee, Inc.)
R0 mfedisk; C:\Windows\System32\DRIVERS\mfedisk.sys [101872 2015-02-17] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [80160 2015-02-13] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [488000 2015-02-17] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [864072 2015-02-17] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [482600 2015-01-16] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [100720 2015-01-16] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [340448 2015-02-17] (McAfee, Inc.)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8876248 2013-10-17] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-12-23] (Synaptics Incorporated)
R2 VOTw8; C:\windows\system32\Drivers\VOTw864.sys [41408 2015-03-23] (VentureOmni Technologies)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
U3 aswMBR; \??\C:\Users\Carson\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Carson\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-03 01:21 - 2015-08-03 01:22 - 00024799 _____ C:\Users\Carson\Downloads\FRST.txt
2015-08-03 01:19 - 2015-08-03 01:19 - 00001926 _____ C:\Users\Carson\Desktop\aswMBR.txt
2015-08-03 01:19 - 2015-08-03 01:19 - 00000512 _____ C:\Users\Carson\Desktop\MBR.dat
2015-08-03 00:39 - 2015-08-03 01:21 - 00000000 ____D C:\FRST
2015-08-03 00:36 - 2015-08-03 00:36 - 02169856 _____ (Farbar) C:\Users\Carson\Downloads\FRST64.exe
2015-08-03 00:07 - 2015-08-03 00:08 - 05198336 _____ (AVAST Software) C:\Users\Carson\Downloads\aswMBR.exe
2015-08-02 22:08 - 2015-08-02 22:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-08-02 21:58 - 2015-08-02 21:58 - 00001868 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2015-08-02 21:58 - 2015-08-02 21:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-08-02 21:58 - 2015-08-02 21:58 - 00000000 ____D C:\Program Files (x86)\QuickTime
2015-08-02 21:51 - 2015-08-02 21:51 - 00000000 ____D C:\Program Files (x86)\LogMeIn Rescue RC - e49fe85b-3cb3-4f16-bf24-6c0237fed2c7
2015-08-02 21:49 - 2015-08-02 21:49 - 01611072 _____ (LogMeIn, Inc.) C:\Users\Carson\Downloads\Support-LogMeInRescue (2).exe
2015-08-02 21:49 - 2015-08-02 21:49 - 00002274 _____ C:\Users\Carson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Eric Woods (4).lnk
2015-08-02 21:48 - 2015-08-02 21:48 - 01611072 _____ (LogMeIn, Inc.) C:\Users\Carson\Downloads\Support-LogMeInRescue.exe
2015-08-02 21:48 - 2015-08-02 21:48 - 01611072 _____ (LogMeIn, Inc.) C:\Users\Carson\Downloads\Support-LogMeInRescue (1).exe
2015-08-02 11:18 - 2015-08-02 11:19 - 30568784 _____ C:\Users\Carson\Downloads\Hardwork feat. DTG.aif
2015-08-02 10:35 - 2015-08-02 10:38 - 00003224 _____ C:\windows\System32\Tasks\Pokki
2015-07-23 19:11 - 2015-07-09 12:51 - 00136904 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-07-23 19:11 - 2015-07-09 11:40 - 00359936 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-07-23 19:11 - 2015-07-09 09:03 - 03701760 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-07-23 19:11 - 2015-07-09 08:54 - 00035840 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-07-23 19:11 - 2015-07-09 08:53 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-07-23 19:11 - 2015-07-09 08:50 - 00409088 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2015-07-23 19:11 - 2015-07-09 08:50 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-07-23 19:11 - 2015-07-09 08:48 - 00891904 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-07-23 19:11 - 2015-07-09 08:46 - 02229248 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-07-23 19:11 - 2015-07-09 08:38 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-07-23 19:11 - 2015-07-09 08:37 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-07-23 19:11 - 2015-07-09 08:35 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-07-23 19:11 - 2015-07-09 08:34 - 00721920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-07-23 19:11 - 2015-06-26 20:08 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-07-23 19:11 - 2015-06-26 20:08 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-07-23 19:11 - 2015-06-26 19:14 - 00027136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-07-23 19:10 - 2015-06-29 15:43 - 00026288 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-07-23 19:10 - 2015-06-29 08:07 - 01145856 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-07-23 19:10 - 2015-06-29 08:07 - 01084928 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-07-23 19:10 - 2015-06-29 08:07 - 00764928 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-07-23 19:10 - 2015-06-29 08:07 - 00433152 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-07-23 19:10 - 2015-06-29 08:07 - 00067584 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-07-23 19:10 - 2015-06-26 16:21 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-07-23 19:10 - 2015-06-26 16:21 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-07-23 19:10 - 2015-05-11 11:17 - 01201664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthport.sys
2015-07-23 19:10 - 2015-05-11 09:34 - 00332800 _____ (Microsoft Corporation) C:\windows\system32\fhcpl.dll
2015-07-23 19:10 - 2015-05-07 10:50 - 22292672 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-07-23 19:10 - 2015-05-07 10:00 - 03109376 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2015-07-23 19:10 - 2015-05-07 09:53 - 19734960 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-07-23 19:10 - 2015-05-07 09:12 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2015-07-23 19:10 - 2015-05-07 08:21 - 00522240 _____ (Microsoft Corporation) C:\windows\system32\GeofenceMonitorService.dll
2015-07-23 19:10 - 2015-05-07 08:05 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\GeofenceMonitorService.dll
2015-07-23 19:10 - 2015-05-03 08:09 - 00274944 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-23 19:10 - 2015-05-03 08:07 - 07784448 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2015-07-23 19:10 - 2015-05-03 07:58 - 00210944 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-23 19:10 - 2015-05-03 07:57 - 05264384 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2015-07-23 19:10 - 2015-05-03 07:55 - 00971776 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2015-07-23 19:10 - 2015-05-03 07:49 - 00811008 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2015-07-23 19:10 - 2015-05-02 17:39 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-07-23 19:10 - 2015-05-01 16:33 - 00410739 _____ C:\windows\system32\ApnDatabase.xml
2015-07-23 19:10 - 2015-04-29 16:22 - 00130048 _____ (Microsoft Corporation) C:\windows\system32\WiFiDisplay.dll
2015-07-23 19:10 - 2015-04-28 06:13 - 00513480 _____ C:\windows\SysWOW64\locale.nls
2015-07-23 19:10 - 2015-04-28 06:13 - 00513480 _____ C:\windows\system32\locale.nls
2015-07-23 19:10 - 2015-04-24 19:25 - 00020992 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-07-23 19:10 - 2015-04-23 08:47 - 03084288 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll
2015-07-23 19:10 - 2015-04-23 08:16 - 02471424 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll
2015-07-23 18:55 - 2015-08-02 10:27 - 00000024 _____ C:\Users\Carson\AppData\Roaming\appdataFr25.bin
2015-07-23 18:47 - 2015-07-23 18:47 - 00000000 ____D C:\Users\Carson\Desktop\DWMTM ~ MEEK MILL
2015-07-23 18:40 - 2015-07-23 18:41 - 109448500 _____ C:\Users\Carson\Downloads\DWMTM_-_MEEK_MILL-2015-07-23.zip
2015-07-22 21:56 - 2015-06-27 22:07 - 00442712 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-07-22 21:56 - 2015-06-27 22:07 - 00178008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-07-22 21:56 - 2015-06-27 22:06 - 01311960 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-07-22 21:56 - 2015-06-27 22:06 - 00332120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-07-22 21:56 - 2015-06-27 09:42 - 00747520 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-07-22 21:56 - 2015-06-26 20:13 - 00202240 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-07-22 21:56 - 2015-06-26 20:12 - 00401408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-07-22 21:56 - 2015-06-26 20:12 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-07-22 21:56 - 2015-06-26 19:40 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2015-07-22 21:56 - 2015-06-26 19:05 - 01441792 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-07-22 21:56 - 2015-06-26 19:00 - 00989184 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-07-22 21:56 - 2015-06-26 18:53 - 00324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2015-07-22 21:56 - 2015-06-26 18:26 - 00802816 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-07-22 21:56 - 2015-06-24 19:31 - 04177920 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-07-22 21:56 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\windows\system32\Drivers\HipShieldK.sys
2015-07-22 21:54 - 2015-06-15 15:41 - 00065024 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2015-07-22 21:54 - 2015-06-15 15:24 - 03320320 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-07-22 21:54 - 2015-06-15 14:16 - 00059904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2015-07-22 21:54 - 2015-06-15 14:09 - 03607552 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2015-07-22 21:54 - 2015-06-15 13:50 - 02774528 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-07-22 21:54 - 2015-06-15 12:57 - 02460160 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-07-22 21:54 - 2015-05-30 14:18 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\werdiagcontroller.dll
2015-07-22 21:54 - 2015-05-30 12:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll
2015-07-22 21:54 - 2015-05-30 12:35 - 00911360 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-07-22 21:51 - 2015-08-02 21:55 - 00003348 _____ C:\windows\System32\Tasks\McAfee Remediation (Prepare)
2015-07-22 21:51 - 2015-07-22 21:51 - 00000000 ____D C:\Program Files\Common Files\AV
2015-07-22 21:48 - 2015-07-14 07:14 - 00358912 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-07-22 21:48 - 2015-07-14 07:14 - 00301056 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-07-22 21:48 - 2015-07-14 07:14 - 00035840 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-07-22 21:48 - 2015-07-14 07:13 - 00044032 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-07-22 21:48 - 2015-06-10 20:49 - 01380600 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-07-22 21:48 - 2015-06-10 09:13 - 01097216 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-07-22 21:41 - 2015-07-22 21:41 - 00000000 ____D C:\Users\Carson\AppData\Local\GWX
2015-07-14 15:36 - 2015-06-15 22:36 - 01661576 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2015-07-14 15:36 - 2015-06-15 22:36 - 01212248 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2015-07-14 15:36 - 2015-05-07 09:47 - 00564224 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-03 01:22 - 2015-06-05 20:30 - 00011272 _____ C:\windows\SysWOW64\VOTPrxOff.ini
2015-08-03 01:22 - 2015-06-05 20:30 - 00011272 _____ C:\windows\system32\VOTPrxOff.ini
2015-08-03 01:22 - 2015-06-05 20:30 - 00000266 _____ C:\windows\Tasks\ArcadeTwist Support.job
2015-08-03 01:18 - 2015-05-16 16:08 - 00000916 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA1d0902d32b8c3ba.job
2015-08-03 01:13 - 2015-04-06 21:03 - 00000916 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-03 01:02 - 2013-08-22 08:36 - 00000000 ____D C:\windows\system32\sru
2015-08-03 00:27 - 2015-06-05 20:30 - 00000274 _____ C:\windows\Tasks\ArcadeTwist Updater.job
2015-08-03 00:00 - 2015-06-05 20:33 - 00000000 ____D C:\Program Files (x86)\Optimizer Pro 3.95
2015-08-02 22:19 - 2015-02-02 04:54 - 01912267 _____ C:\windows\WindowsUpdate.log
2015-08-02 22:13 - 2015-04-02 16:20 - 00003596 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2117907334-324167741-1091666529-1002
2015-08-02 21:59 - 2013-08-22 08:36 - 00000000 ____D C:\windows\AppReadiness
2015-08-02 21:55 - 2015-02-02 06:27 - 00000000 ____D C:\ProgramData\McAfee
2015-08-02 21:55 - 2013-08-22 08:20 - 00000000 ____D C:\windows\CbsTemp
2015-08-02 21:49 - 2015-04-06 19:30 - 00000000 ____D C:\Users\Carson\AppData\Local\LogMeIn Rescue Applet
2015-08-02 21:28 - 2015-04-02 16:21 - 00003914 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{363FFB2C-A82E-4042-8ABA-F014F760CA07}
2015-08-02 21:25 - 2015-04-02 16:14 - 00000000 ____D C:\Users\Carson\AppData\Local\Pokki
2015-08-02 10:56 - 2015-05-03 20:21 - 00248832 ___SH C:\Users\Carson\Downloads\Thumbs.db
2015-08-02 10:45 - 2015-02-02 06:26 - 00000000 ____D C:\windows\System32\Tasks\Lenovo
2015-08-02 10:38 - 2015-04-06 20:55 - 00000000 ____D C:\Program Files (x86)\McAfee
2015-08-02 10:38 - 2015-04-06 20:17 - 00002320 _____ C:\Users\Carson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2015-08-02 10:38 - 2014-03-18 02:53 - 00865408 _____ C:\windows\system32\PerfStringBackup.INI
2015-08-02 10:35 - 2015-04-02 16:20 - 00000000 ____D C:\Users\Carson\OneDrive
2015-08-02 10:34 - 2015-05-16 16:08 - 00000912 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore1d0902d328ec5d2.job
2015-08-02 10:34 - 2015-04-06 21:03 - 00000912 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-02 10:33 - 2015-04-06 21:52 - 00000000 ___SD C:\windows\system32\GWX
2015-08-02 10:33 - 2013-08-22 06:25 - 00262144 ___SH C:\windows\system32\config\ELAM
2015-08-02 10:32 - 2013-08-22 07:46 - 00037171 _____ C:\windows\setupact.log
2015-08-02 10:32 - 2013-08-22 07:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-08-02 10:32 - 2013-08-22 07:44 - 00584256 _____ C:\windows\system32\FNTCACHE.DAT
2015-08-02 10:31 - 2014-03-18 02:44 - 00014948 _____ C:\windows\PFRO.log
2015-08-02 10:30 - 2015-02-02 06:33 - 00002560 _____ C:\windows\system32\VfService.trf
2015-08-02 10:30 - 2013-08-22 06:25 - 00262144 ___SH C:\windows\system32\config\BBI
2015-08-02 10:29 - 2015-04-06 21:52 - 00000000 ___SD C:\windows\SysWOW64\GWX
2015-08-02 10:29 - 2015-04-06 21:52 - 00000000 ____D C:\windows\system32\appraiser
2015-08-02 10:29 - 2015-02-02 05:33 - 00000000 ___SD C:\windows\system32\CompatTel
2015-08-02 10:29 - 2013-08-22 08:36 - 00000000 ___RD C:\windows\ToastData
2015-08-02 10:29 - 2013-08-22 08:36 - 00000000 ____D C:\windows\WinStore
2015-08-02 10:28 - 2015-02-02 05:57 - 01355946 _____ C:\Users\Public\CAFADEBUG.log
2015-07-23 19:13 - 2015-05-16 16:08 - 00003888 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA1d0902d32b8c3ba
2015-07-23 19:13 - 2015-05-16 16:08 - 00003652 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore1d0902d328ec5d2
2015-07-23 18:50 - 2015-04-06 21:01 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-07-23 18:47 - 2015-04-06 21:02 - 00003886 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2015-07-23 18:37 - 2015-06-05 20:34 - 00000000 ____D C:\Program Files (x86)\user extensions
2015-07-23 18:03 - 2015-04-06 20:09 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-07-23 18:02 - 2015-04-06 20:05 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-07-23 17:56 - 2015-04-06 21:20 - 00000000 ____D C:\windows\system32\MRT
2015-07-23 17:56 - 2013-08-22 06:25 - 00000167 _____ C:\windows\win.ini
2015-07-22 21:56 - 2015-04-06 20:53 - 00000000 ____D C:\Program Files\Common Files\McAfee
2015-07-22 21:56 - 2013-08-22 08:36 - 00000000 ___HD C:\windows\ELAMBKUP
2015-07-14 15:53 - 2015-04-02 16:15 - 00000000 ____D C:\Users\Carson\Documents\Bluetooth Folder
2015-07-14 13:50 - 2015-04-02 16:14 - 00000000 ____D C:\Users\Carson
2015-07-14 13:48 - 2015-02-02 06:27 - 00000000 ____D C:\Program Files\lenovo
2015-07-14 13:45 - 2013-08-22 06:36 - 00000000 ____D C:\windows\system32\Sysprep
2015-07-13 14:10 - 2015-04-06 21:56 - 00792568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-07-13 14:10 - 2015-04-06 21:56 - 00178168 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
 
==================== Files in the root of some directories =======
 
2015-07-23 18:55 - 2015-08-02 10:27 - 0000024 _____ () C:\Users\Carson\AppData\Roaming\appdataFr25.bin
2015-06-13 12:53 - 2015-06-13 12:53 - 0003584 _____ () C:\Users\Carson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-05 20:34 - 2015-06-05 20:34 - 0000064 _____ () C:\Users\Carson\AppData\Local\ecc7232fe4096386d167d395ff9231de
2015-02-02 05:57 - 2015-02-02 05:57 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-05-04 16:36 - 2015-05-04 16:36 - 0004936 _____ () C:\ProgramData\wmzddnmb.cix
 
Some files in TEMP:
====================
C:\Users\Carson\AppData\Local\Temp\gb-installer-nsi.exe
C:\Users\Carson\AppData\Local\Temp\gb-update.exe
C:\Users\Carson\AppData\Local\Temp\mccspuninstall.exe
C:\Users\Carson\AppData\Local\Temp\oct100A.tmp.exe
C:\Users\Carson\AppData\Local\Temp\oct4604.tmp.exe
C:\Users\Carson\AppData\Local\Temp\oct5D37.tmp.exe
C:\Users\Carson\AppData\Local\Temp\octB7A0.tmp.exe
C:\Users\Carson\AppData\Local\Temp\octD652.tmp.exe
C:\Users\Carson\AppData\Local\Temp\octECD3.tmp.exe
C:\Users\Carson\AppData\Local\Temp\optprosetup.exe
C:\Users\Carson\AppData\Local\Temp\ose00000.exe
C:\Users\Carson\AppData\Local\Temp\SPSetup.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-23 19:35
 
==================== End of log ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:02-08-2015 01
Ran by [removed] (2015-08-03 01:23:18)
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2117907334-324167741-1091666529-500 - Administrator - Disabled)
Carson (S-1-5-21-2117907334-324167741-1091666529-1002 - Administrator - Enabled) => C:\Users\Carson
Guest (S-1-5-21-2117907334-324167741-1091666529-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2117907334-324167741-1091666529-1004 - Limited - Enabled)
UpdatusUser (S-1-5-21-2117907334-324167741-1091666529-1001 - Limited - Enabled) => C:\Users\UpdatusUser
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Amazon 1Button App (HKLM-x32\…\{3E69CC95-C0F6-4C74-8F43-74F9046F20B2}) (Version: 1.0.10 - Amazon)
Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcadeTwist (HKU\S-1-5-21-2117907334-324167741-1091666529-1002\…\{2E73670A-F0AF-4A88-8BDF-ED0710B305B2}) (Version:  - ArcadeTwist)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CCSDK (HKLM-x32\…\{AE75190B-11B4-4F90-8254-DAB275CF2557}_is1) (Version: 1.0.3.4 - Lenovo)
Conexant HD Audio (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.65.28.50 - Conexant)
Contents (x32 Version: 18.0.1.26 - Corel Corporation) Hidden
Corel VideoStudio X8 (HKLM-x32\…\_{A22A80C4-F237-4B5A-825F-0731971ECBE6}) (Version: 18.0.1.26 - Corel Corporation)
CyberLink MediaStory (HKLM-x32\…\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\…\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.4505 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.36.00 - Lenovo Inc.) Hidden
Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dolby Digital Plus Home Theater (HKLM\…\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Energy Manager (HKLM-x32\…\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.0.35 - Lenovo)
Energy Manager (x32 Version: 1.0.0.35 - Lenovo) Hidden
GeniusBox 2.0 (HKLM-x32\…\GeniusBox) (Version: 2.0 - GeniusBox 2.0)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 44.0.2403.125 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Haali Media Splitter (HKLM-x32\…\HaaliMkx) (Version:  - )
Host App Service (HKU\S-1-5-21-2117907334-324167741-1091666529-1002\…\Pokki) (Version: 0.269.7.738 - Pokki)
ICA (x32 Version: 18.0.1.26 - Corel Corporation) Hidden
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4156 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.0.0.1098 - Intel Corporation)
IPM_VS_Pro (x32 Version: 18.0 - Corel Corporation) Hidden
iTunes (HKLM\…\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Lenovo Browser Guard (HKLM-x32\…\LenovoBrowserGuard) (Version: 2.16.50.5 - ClientConnect LTD) <==== ATTENTION
Lenovo Dependency Package (HKLM\…\Lenovo Dependency Package_is1) (Version: 1.6.36.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\…\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10249 - Realtek Semiconductor Corp.)
Lenovo FusionEngine  (HKLM-x32\…\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\…\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo OneKey Recovery (HKLM-x32\…\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.0.0.2105 - CyberLink Corp.) Hidden
Lenovo Photo Master (HKLM-x32\…\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.)
Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden
Lenovo PowerDVD10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo Reach (HKLM-x32\…\{3245D8C8-7FE0-4FD4-B04B-2720A333D592}) (Version: 1.1.3.7 - Stoneware, Inc.)
Lenovo VeriFace (HKLM\…\Lenovo VeriFace) (Version: 5.0.13.5261 - Lenovo)
Lenovo Web Start (HKU\S-1-5-21-2117907334-324167741-1091666529-1002\…\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1) (Version: 1.0.2.53457 - Pokki)
Maxthon Cloud Browser (HKLM-x32\…\Maxthon3) (Version: 4.4.2.2000 - Maxthon International Limited)
McAfee SecurityCenter (HKLM-x32\…\MSC) (Version: 14.0.1029 - McAfee, Inc.)
Metric Collection SDK 35 (x32 Version: 1.2.0006.00 - Lenovo Group Limited) Hidden
Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movavi Video Editor 10 (HKLM-x32\…\Movavi Video Editor 10) (Version: 10.1.2 - Movavi)
Nitro Pro 9 (HKLM\…\{70B831B7-A8EE-4C5F-8F34-F383D24B3A04}) (Version: 9.0.5.9 - Nitro)
NVIDIA GeForce Experience 1.7 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.7 - NVIDIA Corporation)
NVIDIA Graphics Driver 332.33 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.33 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.0927 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0927 - NVIDIA Corporation)
Onekey Theater (HKLM-x32\…\{91CC5BAE-A098-40D3-A43B-C0DC7CE263FE}) (Version: 3.0.1.2 - Lenovo)
Optimizer Pro v3.2 (HKLM-x32\…\Optimizer Pro_is1) (Version: 3.3.1.7 - PCUtilities Software Limited) <==== ATTENTION
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Pinnacle Studio 12 (HKLM-x32\…\{D041EB9E-890A-4098-8F94-51DA194AC72A}) (Version: 12.1.3.6605 - Pinnacle Systems)
Pinnacle Video Driver (HKLM\…\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.029 - Pinnacle Systems)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.308 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
QuickTime 7 (HKLM-x32\…\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39052 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
Setup (x32 Version: 18.0.1.26 - Corel Corporation) Hidden
Share (x32 Version: 18.0.1.26 - Corel Corporation) Hidden
SHAREit (HKLM-x32\…\SHAREit_is1) (Version: 2.1.8.0 - Lenovo Group Limited)
Stagelight (HKLM\…\Stagelight) (Version: 2.0.0.5015 - Open Labs, LLC.)
Start Menu (HKU\S-1-5-21-2117907334-324167741-1091666529-1002\…\Pokki_Start_Menu) (Version: 0.269.7.738 - Pokki)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.14.74 - Synaptics Incorporated)
UESDK (HKLM-x32\…\{EB3F6640-58AE-4886-B8BA-466B6939A933}_is1) (Version: 1.0.2.7 - Lenovo)
Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\…\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{40930C8E-A677-414C-A72F-DFDEB10738FB}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB3054946) 64-Bit Edition (HKLM\…\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{5280698D-EE40-4A94-9E69-ED2E2B1E12A2}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB3054946) 64-Bit Edition (HKLM\…\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{5280698D-EE40-4A94-9E69-ED2E2B1E12A2}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB3054946) 64-Bit Edition (HKLM\…\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{5280698D-EE40-4A94-9E69-ED2E2B1E12A2}) (Version:  - Microsoft)
User Manuals (HKLM-x32\…\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
User Manuals (x32 Version: 3.0.0.3 - Lenovo) Hidden
VideoPad Video Editor (HKLM-x32\…\VideoPad) (Version: 4.00 - NCH Software)
VSClassic (x32 Version: 18.0.1.26 - Corel Corporation) Hidden
VSPro (x32 Version: 18.0.1.26 - Corel Corporation) Hidden
Windows Driver Package - Lenovo (ACPIVPC) System  (02/17/2013 9.52.0.776) (HKLM\…\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\…\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2117907334-324167741-1091666529-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\windows\system32\igfxEM.exe (Intel Corporation)
 
==================== Restore Points =========================
 
13-06-2015 14:54:04 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
13-06-2015 14:54:24 Installed DirectX
14-07-2015 15:42:47 Windows Update
23-07-2015 17:42:35 Windows Update
02-08-2015 10:50:23 Windows Update
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 06:25 - 2013-08-22 06:25 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0E56B103-D57E-43EA-9DD9-2C6B75CFDB43} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {10DFE786-BC7E-4B2E-A4E0-CE7FBD94FA3B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-06] (Google Inc.)
Task: {114CC613-1045-4D60-8690-3BAD4B9FB09E} - System32\Tasks\GeniusBox => cmd.exe /C start "" "C:\Program Files (x86)\user extensions\client.exe" <==== ATTENTION
Task: {227BD830-49C0-4390-A3EF-C821F003C091} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Office2013\OFFICEICON.vbs [2013-06-02] ()
Task: {2A351760-2A55-45A4-BBF8-C64F6329C4FC} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {2C2E97A1-A0A2-4036-95BF-E95512248FC8} - System32\Tasks\GoogleUpdateTaskMachineCore1d0902d328ec5d2 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-06] (Google Inc.)
Task: {40C21339-87F5-4E90-BCB8-AC30A485A6FF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {448F4092-25B4-4CD3-9DF1-674DA2DBF36D} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-12-23] (Synaptics Incorporated)
Task: {565D9561-3512-4259-B83B-F61E77AAFBAB} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [2014-09-10] (Maxthon International ltd.)
Task: {63E5691B-03C6-4A0A-B998-DC8A9EA35D96} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2015-06-01] (McAfee, Inc.)
Task: {6A26BB6D-2471-47E7-9F8F-F6F242451FA5} - System32\Tasks\Pokki => %LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe
Task: {6AB5390B-F0F8-474C-A1B0-1DDAB349FEA5} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-03-06] ()
Task: {860BECB3-7AAF-46A4-B9E6-D1F7E76BF45E} - System32\Tasks\ArcadeTwist Updater => C:\Users\Carson\AppData\Local\ArcadeTwist\updater.exe [2015-06-05] (ArcadeTwist)
Task: {8CD42DB2-E151-4B4D-AE48-18C77BFE872B} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-08-18] (Lenovo)
Task: {9DCBDFB7-D84B-45A6-B68E-56AFA1AC47C1} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2015-07-03] (Microsoft Corporation)
Task: {A0451269-3C07-452F-B422-26FB64ED5638} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {A78C4306-E076-4585-AA0F-B1ACBC738F0E} - System32\Tasks\Bidaily Synchronize Task[3c32] => c:\programdata\{49b77fb8-be71-cff6-49b7-77fb8be7fee2}\hqghumeaylnlf.exe [2014-06-05] (PC Utilities Software Limited) <==== ATTENTION
Task: {ACBB5159-08D8-4F57-BF72-0C9B517F9C37} - System32\Tasks\Check Updates => C:\Program Files (x86)\user extensions\updater.exe [2015-07-23] () <==== ATTENTION
Task: {BB16BC20-F57C-4AF6-A8E2-924142326D38} - System32\Tasks\GoogleUpdateTaskMachineUA1d0902d32b8c3ba => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-06] (Google Inc.)
Task: {BFD36A99-268D-4D64-B724-75B8A2C9080F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {C9FAA1A7-D9F8-4EF7-B362-A4E1B38BB9C1} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-08] (CyberLink Corp.)
Task: {D47F885B-840C-4D06-A978-6D1564AED7C7} - System32\Tasks\ArcadeTwist Support => C:\Users\Carson\AppData\Local\ArcadeTwist\AtwRun.exe [2015-06-05] (ArcadeTwist)
Task: {DD132E6A-E69E-48BE-ABC2-B16A10F116BC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-06] (Google Inc.)
Task: {F675D023-4215-4939-AFD2-7424B40DDEBE} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-09-10] (Lenovo)
Task: {F90E5C85-CD93-42AF-AAC4-B06D7CF7AC60} - System32\Tasks\Validate Installation => C:\Program Files (x86)\user extensions\updater.exe [2015-07-23] () <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\ArcadeTwist Support.job => C:\Users\Carson\AppData\Local\ARCADE~1\AtwRun.exe
Task: C:\windows\Tasks\ArcadeTwist Updater.job => C:\Users\Carson\AppData\Local\ArcadeTwist\updater.exe
Task: C:\windows\Tasks\Bidaily Synchronize Task[3c32].job => c:\programdata\{49b77fb8-be71-cff6-49b7-77fb8be7fee2}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d0902d328ec5d2.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA1d0902d32b8c3ba.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-02-02 05:43 - 2014-01-06 01:13 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-02-02 06:31 - 2012-04-24 03:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2015-02-02 06:33 - 2015-02-02 06:33 - 00068368 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
2015-02-02 06:33 - 2015-02-02 06:33 - 00669288 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfDataStorageInterface.dll
2015-02-02 06:26 - 2014-07-09 18:19 - 00592880 _____ () C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-02-01 13:42 - 2015-03-31 19:02 - 00392592 _____ () C:\windows\system32\igfxTray.exe
2013-10-29 23:22 - 2013-10-29 23:22 - 00011264 _____ () C:\Program Files (x86)\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2013-10-29 23:19 - 2013-10-29 23:19 - 00086016 _____ () C:\Program Files (x86)\Bluetooth Suite\Modules\Map\MAP.dll
2013-10-29 23:26 - 2013-10-29 23:26 - 00012928 _____ () C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
2015-02-02 05:57 - 2010-10-25 21:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
2014-08-29 15:34 - 2014-08-29 15:34 - 01397208 _____ () C:\Program Files\Stagelight\StagelightUpdate.exe
2015-03-20 18:12 - 2015-03-20 18:12 - 00306984 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll
2015-02-02 05:48 - 2013-09-16 12:20 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2015-02-02 06:31 - 2014-07-03 21:35 - 00627672 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMediaLibrary.dll
2014-07-04 13:35 - 2014-07-04 13:35 - 00016856 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvcPS.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-03-20 18:12 - 2015-03-20 18:12 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2015-08-02 11:13 - 2015-07-25 01:46 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.125\libglesv2.dll
2015-08-02 11:13 - 2015-07-25 01:46 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.125\libegl.dll
2015-08-02 11:13 - 2015-07-25 01:46 - 16308040 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.125\PepperFlash\pepflashplayer.dll
2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Carson\OneDrive:ms-properties
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LMIRescue_e49fe85b-3cb3-4f16-bf24-6c0237fed2c7 => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VOTPrx => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VOTw8 => ""="Driver"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2117907334-324167741-1091666529-1002\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{E41B4E6D-C494-484E-BFB9-F09CEF2DDC31}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{31FBD173-49DA-46D3-A75D-417C2A35AB40}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{A0109A07-EA45-4535-B524-80BB8CF15637}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{7530FDFB-2070-49D9-BE6D-C97FE24E65D7}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{E36684C8-101D-412A-8CE8-1159C302BD0E}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{A57DD19B-6925-4B37-B336-F2F08D12E51C}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{3B479F39-0E7C-4DA2-8D9C-91091C125D19}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{1FBB4E7E-676F-476C-AEA9-A3FE88E11D1B}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{293782FB-579A-4A1F-B069-61C569D17C5B}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{4ABAD741-E44A-4F6F-A78B-8FBB0331519A}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{5B14377B-6DEF-454A-B9B3-80B5921FD8AA}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{4DE696A9-27B2-4CD2-966A-5E854176753B}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe
FirewallRules: [{01C4C2C4-B5DC-463C-98C9-9BC8C0588A24}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe
FirewallRules: [{31E1BAC1-2A46-48DD-9DE4-BAF7CBCA3DF2}] => (Allow) LPort=55100
FirewallRules: [{77B8119C-FE47-4BDC-974A-A01E75675FFD}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
FirewallRules: [{116AA121-FBB7-4C6B-9802-6956AD923EBE}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{64F58E0E-4FE4-4E70-B5F3-81E026A5DAAE}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{D5AF5690-6890-42F6-80EF-11898DA53914}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{E7536B5E-FFC0-4FA5-9A3B-2CDE696123B0}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{72B20095-5C99-4D2E-809F-7B102F6FD460}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{A2E0A73A-8559-4A0C-B078-41B67D9B84E3}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{29ABAC55-1691-43AF-99F8-08C256C55DE0}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{5C1D69C2-0981-49BC-A0C7-9C39E7CF3A00}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{29594C42-9566-41DE-8C69-7545217B833C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E6BE031D-0F4A-4326-A6DB-846BED7F9F4E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6ADB836C-AAB7-40A6-A9B1-17F19BBD1990}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{1588F7DA-C91B-4069-BFA9-76988908C239}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe
FirewallRules: [{FB1995EC-975B-4571-92FB-1FB019DB7E85}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe
FirewallRules: [{6B55AF68-A851-4B1E-A738-B267DA7E11C3}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe
FirewallRules: [{16A26EFF-0138-46FB-995C-3275A5837520}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe
FirewallRules: [{062C744F-4109-462F-9093-7B77227EF88B}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe
FirewallRules: [{2F7A6A5A-4298-4C38-854C-D1A71F308F45}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe
FirewallRules: [{A79F5785-2547-4395-998B-3AD3C96A920A}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{579ABFFC-E688-4D57-83BB-40A6820C8B39}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{56D88F96-36FA-4CB4-8BD1-92BE0BA532A3}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{6FB3FF13-CE6B-4B4C-B661-5E666A73C515}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{0DCEAB67-AE62-43DD-8BCD-BEB31583B8A3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/03/2015 12:47:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: McSvHost.exe, version: 5.0.281.0, time stamp: 0x551d930f
Faulting module name: ntdll.dll, version: 6.3.9600.17736, time stamp: 0x550f4336
Exception code: 0xc0000374
Fault offset: 0x00000000000f0f20
Faulting process id: 0xdbc
Faulting application start time: 0xMcSvHost.exe0
Faulting application path: McSvHost.exe1
Faulting module path: McSvHost.exe2
Report Id: McSvHost.exe3
Faulting package full name: McSvHost.exe4
Faulting package-relative application ID: McSvHost.exe5
 
Error: (08/02/2015 09:25:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 30924047
 
Error: (08/02/2015 09:25:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 30924047
 
Error: (08/02/2015 09:25:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (08/02/2015 11:01:02 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Client application bug: DNSServiceResolve(a8:96:8a:e3:4b:6d@fe80::aa96:8aff:fee3:4b6d._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network.
 
Error: (08/02/2015 10:24:44 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: The data is invalid.
.
 
Error: (08/02/2015 10:24:43 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>with error: The data is invalid.
.
 
Error: (07/23/2015 06:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1141
 
Error: (07/23/2015 06:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1141
 
Error: (07/23/2015 06:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
System errors:
=============
Error: (08/03/2015 12:48:56 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee Proxy Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (08/03/2015 12:48:56 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee Platform Services service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (08/03/2015 12:48:56 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee VirusScan Announcer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (08/03/2015 12:48:56 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee Personal Firewall Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (08/03/2015 12:48:56 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee Home Network service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (08/02/2015 10:37:24 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {209500FC-6B45-4693-8871-6296C4843751}
 
Error: (07/23/2015 07:16:22 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {44603E4D-56AE-4C42-ABE4-EC155FE8F1CD}
 
Error: (07/23/2015 07:15:51 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {44603E4D-56AE-4C42-ABE4-EC155FE8F1CD}
 
Error: (07/23/2015 07:15:20 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {44603E4D-56AE-4C42-ABE4-EC155FE8F1CD}
 
Error: (07/22/2015 09:56:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Proxy Service service failed to start due to the following error: 
%%1053
 
 
Microsoft Office:
=========================
Error: (08/03/2015 12:47:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: McSvHost.exe5.0.281.0551d930fntdll.dll6.3.9600.17736550f4336c000037400000000000f0f20dbc01d0cd493768b913C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exeC:\windows\SYSTEM32\ntdll.dlle4fe90ff-39b3-11e5-826f-d0534951200c
 
Error: (08/02/2015 09:25:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 30924047
 
Error: (08/02/2015 09:25:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 30924047
 
Error: (08/02/2015 09:25:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (08/02/2015 11:01:02 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Client application bug: DNSServiceResolve(a8:96:8a:e3:4b:6d@fe80::aa96:8aff:fee3:4b6d._apple-mobdev2._tcp.local.) active for over two minutes. This places considerable burden on the network.
 
Error: (08/02/2015 10:24:44 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
 
Error: (08/02/2015 10:24:43 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
 
Error: (07/23/2015 06:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1141
 
Error: (07/23/2015 06:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1141
 
Error: (07/23/2015 06:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz
Percentage of memory in use: 57%
Total physical RAM: 6036.27 MB
Available physical RAM: 2537.76 MB
Total Virtual: 6996.27 MB
Available Virtual: 2584.72 MB
 
==================== Drives ================================
 
Drive c: (Windows8_OS) (Fixed) (Total:423.84 GB) (Free:347.08 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.67 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 996B338A)
 
Partition: GPT Partition Type.
 
==================== End of log ============================

 

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.


Go to Control Panel > Programs and Features, and uninstall the following programs, you can follow this link for help
http://windows.microsoft.com/en-gb/windows-8/uninstall-change-program

Lenovo Browser Guard
Start Menu (This would be from Pokki)
Host App Service (HKU\S-1-5-21-2117907334-324167741-1091666529-1002\…\Pokki
Optimizer Pro v3.2

~~~~~~~~~~~~~~~
Running from C:\Users\[removed]\Downloads

It's best we move Farbar's to desktop.

Please go to your downloads folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]



start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-2117907334-324167741-1091666529-1002\…\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.95\OptProLauncher.exe
AppInit_DLLs: C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL => C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL File not found
AppInit_DLLs-x32: C:\PROGRA~3\{56ACB~1\1172~1.1\dola.dll => "C:\PROGRA~3\{56ACB~1\1172~1.1\dola.dll" File not found
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
URLSearchHook: [S-1-5-21-2117907334-324167741-1091666529-1001] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {9143e921-7c9a-4d27-ac43-eaccc78cc55a} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2117907334-324167741-1091666529-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2117907334-324167741-1091666529-1002 -> {9143e921-7c9a-4d27-ac43-eaccc78cc55a} URL = http://search.homepa…q={searchTerms}
2015-08-02 10:35 - 2015-08-02 10:38 - 00003224 _____ C:\windows\System32\Tasks\Pokki
2015-08-03 00:00 - 2015-06-05 20:33 - 00000000 ____D C:\Program Files (x86)\Optimizer Pro 3.95
C:\Users\Carson\AppData\Local\Temp\gb-installer-nsi.exe
C:\Users\Carson\AppData\Local\Temp\gb-update.exe
C:\Users\Carson\AppData\Local\Temp\mccspuninstall.exe
C:\Users\Carson\AppData\Local\Temp\oct100A.tmp.exe
C:\Users\Carson\AppData\Local\Temp\oct4604.tmp.exe
C:\Users\Carson\AppData\Local\Temp\oct5D37.tmp.exe
C:\Users\Carson\AppData\Local\Temp\octB7A0.tmp.exe
C:\Users\Carson\AppData\Local\Temp\octD652.tmp.exe
C:\Users\Carson\AppData\Local\Temp\octECD3.tmp.exe
C:\Users\Carson\AppData\Local\Temp\optprosetup.exe
C:\Users\Carson\AppData\Local\Temp\ose00000.exe
C:\Users\Carson\AppData\Local\Temp\SPSetup.exe
Task: {114CC613-1045-4D60-8690-3BAD4B9FB09E} - System32\Tasks\GeniusBox => cmd.exe /C start "" "C:\Program Files (x86)\user extensions\client.exe" <==== ATTENTION
Task: {6A26BB6D-2471-47E7-9F8F-F6F242451FA5} - System32\Tasks\Pokki => %LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe
Task: {A78C4306-E076-4585-AA0F-B1ACBC738F0E} - System32\Tasks\Bidaily Synchronize Task[3c32] => c:\programdata\{49b77fb8-be71-cff6-49b7-77fb8be7fee2}\hqghumeaylnlf.exe [2014-06-05] (PC Utilities Software Limited) <==== ATTENTION
Task: {ACBB5159-08D8-4F57-BF72-0C9B517F9C37} - System32\Tasks\Check Updates => C:\Program Files (x86)\user extensions\updater.exe [2015-07-23] () <==== ATTENTION
Task: {F90E5C85-CD93-42AF-AAC4-B06D7CF7AC60} - System32\Tasks\Validate Installation => C:\Program Files (x86)\user extensions\updater.exe [2015-07-23] () <==== ATTENTION
Task: C:\windows\Tasks\Bidaily Synchronize Task[3c32].job => c:\programdata\{49b77fb8-be71-cff6-49b7-77fb8be7fee2}\hqghumeaylnlf.exe <==== ATTENTION
EmptyTemp:
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~`

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click Scan.
  • Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
  • Follow the prompts and allow your computer to reboot.
  • After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
– File and registry key backups are made for anything removed using this tool. Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the entry. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


[external image: thisisujrt.gif]
Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
~~~
please post
Fixlog.txt
C:\AdwCleaner.txt
JRT.txt
Fix result of Farbar Recovery Scan Tool (x64) Version:06-08-2015
Ran by [removed] (2015-08-06 10:08:19) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-2117907334-324167741-1091666529-1002\…\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.95\OptProLauncher.exe
AppInit_DLLs: C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL => C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL File not found
AppInit_DLLs-x32: C:\PROGRA~3\{56ACB~1\1172~1.1\dola.dll => "C:\PROGRA~3\{56ACB~1\1172~1.1\dola.dll" File not found
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
URLSearchHook: [S-1-5-21-2117907334-324167741-1091666529-1001] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {9143e921-7c9a-4d27-ac43-eaccc78cc55a} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2117907334-324167741-1091666529-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2117907334-324167741-1091666529-1002 -> {9143e921-7c9a-4d27-ac43-eaccc78cc55a} URL = http://search.homepa…q={searchTerms}
2015-08-02 10:35 - 2015-08-02 10:38 - 00003224 _____ C:\windows\System32\Tasks\Pokki
2015-08-03 00:00 - 2015-06-05 20:33 - 00000000 ____D C:\Program Files (x86)\Optimizer Pro 3.95
C:\Users\Carson\AppData\Local\Temp\gb-installer-nsi.exe
C:\Users\Carson\AppData\Local\Temp\gb-update.exe
C:\Users\Carson\AppData\Local\Temp\mccspuninstall.exe
C:\Users\Carson\AppData\Local\Temp\oct100A.tmp.exe
C:\Users\Carson\AppData\Local\Temp\oct4604.tmp.exe
C:\Users\Carson\AppData\Local\Temp\oct5D37.tmp.exe
C:\Users\Carson\AppData\Local\Temp\octB7A0.tmp.exe
C:\Users\Carson\AppData\Local\Temp\octD652.tmp.exe
C:\Users\Carson\AppData\Local\Temp\octECD3.tmp.exe
C:\Users\Carson\AppData\Local\Temp\optprosetup.exe
C:\Users\Carson\AppData\Local\Temp\ose00000.exe
C:\Users\Carson\AppData\Local\Temp\SPSetup.exe
Task: {114CC613-1045-4D60-8690-3BAD4B9FB09E} - System32\Tasks\GeniusBox => cmd.exe /C start "" "C:\Program Files (x86)\user extensions\client.exe" <==== ATTENTION
Task: {6A26BB6D-2471-47E7-9F8F-F6F242451FA5} - System32\Tasks\Pokki => %LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe
Task: {A78C4306-E076-4585-AA0F-B1ACBC738F0E} - System32\Tasks\Bidaily Synchronize Task[3c32] => c:\programdata\{49b77fb8-be71-cff6-49b7-77fb8be7fee2}\hqghumeaylnlf.exe [2014-06-05] (PC Utilities Software Limited) <==== ATTENTION
Task: {ACBB5159-08D8-4F57-BF72-0C9B517F9C37} - System32\Tasks\Check Updates => C:\Program Files (x86)\user extensions\updater.exe [2015-07-23] () <==== ATTENTION
Task: {F90E5C85-CD93-42AF-AAC4-B06D7CF7AC60} - System32\Tasks\Validate Installation => C:\Program Files (x86)\user extensions\updater.exe [2015-07-23] () <==== ATTENTION
Task: C:\windows\Tasks\Bidaily Synchronize Task[3c32].job => c:\programdata\{49b77fb8-be71-cff6-49b7-77fb8be7fee2}\hqghumeaylnlf.exe <==== ATTENTION
EmptyTemp:
End
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
HKU\S-1-5-21-2117907334-324167741-1091666529-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro => value not found.
"C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL" => Value data removed successfully.
"C:\PROGRA~3\{56ACB~1\1172~1.1\dola.dll" => Value data removed successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
Could not restore Default URLSearchHook.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9143e921-7c9a-4d27-ac43-eaccc78cc55a}" => key removed successfully
HKCR\CLSID\{9143e921-7c9a-4d27-ac43-eaccc78cc55a} => key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
"HKU\S-1-5-21-2117907334-324167741-1091666529-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
"HKU\S-1-5-21-2117907334-324167741-1091666529-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9143e921-7c9a-4d27-ac43-eaccc78cc55a}" => key removed successfully
HKCR\CLSID\{9143e921-7c9a-4d27-ac43-eaccc78cc55a} => key not found. 
"C:\windows\System32\Tasks\Pokki" => File/Folder not found.
"C:\Program Files (x86)\Optimizer Pro 3.95" => File/Folder not found.
C:\Users\Carson\AppData\Local\Temp\gb-installer-nsi.exe => moved successfully.
C:\Users\Carson\AppData\Local\Temp\gb-update.exe => moved successfully.
C:\Users\Carson\AppData\Local\Temp\mccspuninstall.exe => moved successfully.
C:\Users\Carson\AppData\Local\Temp\oct100A.tmp.exe => moved successfully.
C:\Users\Carson\AppData\Local\Temp\oct4604.tmp.exe => moved successfully.
C:\Users\Carson\AppData\Local\Temp\oct5D37.tmp.exe => moved successfully.
C:\Users\Carson\AppData\Local\Temp\octB7A0.tmp.exe => moved successfully.
C:\Users\Carson\AppData\Local\Temp\octD652.tmp.exe => moved successfully.
C:\Users\Carson\AppData\Local\Temp\octECD3.tmp.exe => moved successfully.
C:\Users\Carson\AppData\Local\Temp\optprosetup.exe => moved successfully.
C:\Users\Carson\AppData\Local\Temp\ose00000.exe => moved successfully.
C:\Users\Carson\AppData\Local\Temp\SPSetup.exe => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{114CC613-1045-4D60-8690-3BAD4B9FB09E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{114CC613-1045-4D60-8690-3BAD4B9FB09E}" => key removed successfully
C:\Windows\System32\Tasks\GeniusBox => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GeniusBox" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A26BB6D-2471-47E7-9F8F-F6F242451FA5} => key not found. 
C:\Windows\System32\Tasks\Pokki not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Pokki => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A78C4306-E076-4585-AA0F-B1ACBC738F0E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A78C4306-E076-4585-AA0F-B1ACBC738F0E}" => key removed successfully
C:\Windows\System32\Tasks\Bidaily Synchronize Task[3c32] => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task[3c32]" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{ACBB5159-08D8-4F57-BF72-0C9B517F9C37}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ACBB5159-08D8-4F57-BF72-0C9B517F9C37}" => key removed successfully
C:\Windows\System32\Tasks\Check Updates => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Check Updates" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F90E5C85-CD93-42AF-AAC4-B06D7CF7AC60}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F90E5C85-CD93-42AF-AAC4-B06D7CF7AC60}" => key removed successfully
C:\Windows\System32\Tasks\Validate Installation => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Validate Installation" => key removed successfully
C:\windows\Tasks\Bidaily Synchronize Task[3c32].job => moved successfully.
EmptyTemp: => 2.7 GB temporary data Removed.
 
 
The system needed a reboot.. 
 
==== End of Fixlog 10:09:04 ====
 
# AdwCleaner v4.208 - Logfile created 06/08/2015 at 10:26:47
# Updated 09/07/2015 by Xplode
# Database : 2015-08-01.1 [Server]
# Operating system : Windows 8.1  (x64)
# Username : Carson - AYSO
# Running from : C:\Users\Carson\Desktop\AdwCleaner.exe
# Option : Cleaning
 
***** [ Services ] *****
 
Service Deleted : VOTPrx
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\{49b77fb8-be71-cff6-49b7-77fb8be7fee2}
Folder Deleted : C:\Program Files (x86)\user extensions
Folder Deleted : C:\Users\Carson\AppData\Local\ArcadeTwist
File Deleted : C:\windows\SysWOW64\VisualDiscovery.ini
File Deleted : C:\windows\SysWOW64\VisualDiscoveryOff.ini
File Deleted : C:\windows\SysWOW64\VOTPrxOff.ini
File Deleted : C:\windows\System32\VisualDiscoveryOff.ini
File Deleted : C:\windows\System32\VOTPrxOff.ini
 
***** [ Scheduled tasks ] *****
 
Task Deleted : ArcadeTwist Support
Task Deleted : ArcadeTwist Updater
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.LSPLogic.1
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.ReadOnlyManager
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.ReadOnlyManager.1
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.WFPController
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.WFPController.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\VOTPrx.EXE
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.DataContainer
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.DataContainer.1
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.DataController
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.DataController.1
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.DataTable
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.DataTable.1
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.DataTableFields
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.DataTableFields.1
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.DataTableHolder
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.DataTableHolder.1
Key Deleted : HKLM\SOFTWARE\Classes\VOTPrxLib.LSPLogic
Key Deleted : HKLM\SOFTWARE\bd16878d-88a9-934b-67bf-a9b7b862b746
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0B7CB21B-2D13-4315-9E35-69742BF77530}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{09CBD86E-22AC-4BFF-A97C-85744B2819AB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{542B7A6A-C8B6-4372-8829-FD8E35FA4CB8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{55AB8477-ED99-431F-ABB3-22022902A934}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{79701C41-C345-47EC-B57C-02C39A698A0D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86937CB9-BDDC-482F-A3B3-E05E3DFDFF08}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE479D24-AF59-4DEB-9D8B-D1E7DFA2C6A6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BED722AF-1533-4596-964F-B5E1F8A6456E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E94546E8-E2A0-48FE-BC53-568F314EAA7A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0394AE51-F76F-4FBF-848D-CF9407CE868F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{058281DD-014E-4E81-A5D3-9E14A1EBC8B7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AB1CA27-FA6E-434B-8433-612346BBDD3B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{34A729EE-F357-4A94-9243-D33E50A504A7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{420A2140-FB38-4984-B681-2A0217483077}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{46A200C2-2B44-4C47-8EA9-5DB33859BC7C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47F18772-002C-4A49-AA12-EE88297CCDD0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5C567C55-75EF-4000-B36F-FF562D4204C1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78AC0B67-463E-4702-A7B1-CFB4C33B3D56}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{95980124-E89B-48C2-BA92-DF835F62ABFB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AA33003C-AB62-428E-B24E-59933BE52393}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D22566FE-4D97-4D5D-968B-0E79353F22E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F0C53D54-F8AF-4156-8D66-420036A79A28}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{617E26CE-E6E1-4C75-A68A-A001F2B98491}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8128586C-DF69-4266-873F-CF4C6F705A7C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{007F707C-3F7A-4FBF-9BB1-4C9404211A9C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CB6BF8B6-E12B-42FA-A478-91BCCDE475DC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0394AE51-F76F-4FBF-848D-CF9407CE868F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{058281DD-014E-4E81-A5D3-9E14A1EBC8B7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1AB1CA27-FA6E-434B-8433-612346BBDD3B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{34A729EE-F357-4A94-9243-D33E50A504A7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{420A2140-FB38-4984-B681-2A0217483077}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{46A200C2-2B44-4C47-8EA9-5DB33859BC7C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{47F18772-002C-4A49-AA12-EE88297CCDD0}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{5C567C55-75EF-4000-B36F-FF562D4204C1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{78AC0B67-463E-4702-A7B1-CFB4C33B3D56}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{95980124-E89B-48C2-BA92-DF835F62ABFB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{AA33003C-AB62-428E-B24E-59933BE52393}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D22566FE-4D97-4D5D-968B-0E79353F22E4}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F0C53D54-F8AF-4156-8D66-420036A79A28}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2E5FA7B4-61A2-4662-BBCE-62BBB20FC649}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{5D7F05E3-075A-43AF-8BC7-21E2F7F38845}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{617E26CE-E6E1-4C75-A68A-A001F2B98491}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{79FBDBEA-A722-4ABD-BEC0-B7D463F6BA0E}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8128586C-DF69-4266-873F-CF4C6F705A7C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F9CFCE-A7DC-4072-8B31-1DEA57004C86}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EA4AD895-2A7F-430E-B973-DEE6C4E743A9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EBF4B60F-A863-426F-BE6F-5DFE83BC574F}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{F161AB30-EA2E-11E4-8265-D0534951200C}
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\Search Extensions
Key Deleted : HKCU\Software\geniusboxinstalled
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\VisualDiscovery
Key Deleted : HKLM\SOFTWARE\Superfish Inc. VisualDiscovery
Key Deleted : HKLM\SOFTWARE\GeniusBox
Key Deleted : HKLM\SOFTWARE\LENOVO\VisualDiscovery
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2E73670A-F0AF-4A88-8BDF-ED0710B305B2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GeniusBox
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\homepage-web.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\us.yhs4.search.yahoo.com
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17840
 
 
-\\ Google Chrome v44.0.2403.125
 
 
*************************
 
AdwCleaner[R0].txt - [10154 bytes] - [06/08/2015 10:23:17]
AdwCleaner[S0].txt - [9933 bytes] - [06/08/2015 10:26:47]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9992  bytes] ##########
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.5 (08.05.2015:1)
OS: Windows 8.1 x64
Ran by [removed] on Thu 08/06/2015 at 10:39:40.87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
Successfully deleted: [Service] 0044481438667789mcinstcleanup [Reboot required]
Successfully deleted: [Service] votw8 [Reboot required]
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
Successfully deleted: [File] C:\windows\system32\drivers\votw864.sys
Successfully deleted: [File] C:\Users\Carson\AppData\Roaming\appdataFr25.bin
Successfully deleted: [File] C:\Users\Carson\Appdata\Local\ecc7232fe4096386d167d395ff9231de
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] C:\windows\SysWOW64\config\systemprofile\appdata\local\votprx
 
 
 
~~~ Chrome
 
 
[C:\Users\Carson\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\Carson\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Users\Carson\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\Carson\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
  ogminpmldncgcmokldnmmapddoccmhfl
]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 08/06/2015 at 10:42:27.65
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

Please download Malwarebytes Anti-Malware and save it to your desktop.
  • Double-click on the setup file (mbam-setup.exe), then click on Run to install.
  • Malwarebytes will automatically open to it's Dashboard. If you have never run this version, you should see a red note at the top indicating "A scan has never been run on your system"
  • Click on Update Now to download the current database definitions, then click the Scan Now >> button.
  • If you have run this version before, you should see a green note at the top indicating "Your system is fully protected".
  • You will be prompted to update Malwarebytes…click on the Update Now button.
  • The THREAT SCAN will automatically begin.
  • When the scan has completed, the results will be displayed. Click on Quarantine All, then click on Apply Actions.
  • To complete any actions taken you will be prompted to restart your computer…click on Yes. Failure to reboot normally will prevent Malwarebytes from removing all the malware.
  • After rebooting the computer, copy and paste the mbam.log in your next reply.
To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 1)
  • Open Malwarebytes Anti-Malware.
  • Click the History Tab at the top and select Application Logs.
  • Select (check) the box next to Scan Log. Choose the most current scan.
  • Click the View button.
  • Click Copy to Clipboard at the bottom…come back to this thread, click Add Reply, then right-click and choose Paste.
  • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
  • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 2)



When the scan is finished and the log pops up…select Copy to Clipboard

Please paste the log back into this thread for review

Exit Malwarebytes
  • Open Malwarebytes Anti-Malware.
  • Click the Scan Tab at the top.
  • Click the View detailed log link on the right.
  • Click Copy to Clipboard at the bottom…come back to this thread, click Add Reply, then right-click and choose Paste.
  • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
  • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
Logs are named by the date of scan in the following format: mbam-log-yyyy-mm-dd and automatically saved to the following locations:
– XP: C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
– Vista, Windows 7/8: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd


~~~~~~~~~

How is your computer now?

Still getting ads (CouponFactory). MBAM didn't work quite as specified. Only have xml file (mbam-log-2015-08-06 (11-30-25).xml), no log. Here it is:

 

2015/08/06 11:30:27 -0700
mbam-log-2015-08-06 (11-30-25).xml
yes
2.1.8.1057
v2015.08.06.06
v2015.08.04.01
free[external image: arrow-10x10.png]
disabled[external image: arrow-10x10.png]
disabled
disabled
Windows 8[external image: arrow-10x10.png].1
x64
Carson
NTFS
threat
completed
398466
569
processes[external image: arrow-10x10.png]>0
0
2
1
0
0
2
0
enabled
enabled
enabled
enabled
disabled
disabled
enabled
enabled
enabled
PUP.Optional.MultiPlug.Asuccess1b8325e0cebdef47d988aaf75aaad12f
PUP.Optional.SuperOptimizer.Csuccess9806b5508b004cea508e4460768e40c0
AppPathPUP.Optional.Cassiopesa.AsuccessC:\Program Files (x86)\Tny_Cassiopesa\\a7f7669fc6c5e94d4453267d09fb6f91
PUP.Optional.Winsock.HijackBootsuccessc4da12f31972b581a1f0148756aea957
PUP.Optional.Winsock.HijackBootsuccess633bee17a5e64fe7a4ee2f6c4db7cc34
 
Did MalwareBytes quarantine what it found?

What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.


[external image: GzlsbnV.png]ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

[external image: GzlsbnV.png]ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.
  • Please download ESET Online Scan and save the file to your Desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Double-click esetsmartinstaller_enu.exe to run the programme.
  • Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
  • Agree to the Terms of Use once more and click Start. Allow components to download.
  • Place a checkmark next to Enable detection of potentially unwanted applications.
  • Click Advanced settings. Place a checkmark next to:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Ensure Remove found threats is unchecked.
  • Click Start.
  • Wait for the scan to finish. Please be patient as this can take some time.
  • Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points.
  • Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
  • Push the Back button.
  • Place a checkmark next to [external image: xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png] and click [external image: SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png].
  • Re-enable your anti-virus software.
  • Copy the contents of the log and paste in your next reply.
C:\AdwCleaner\Quarantine\C\ProgramData\{49b77fb8-be71-cff6-49b7-77fb8be7fee2}\hqghumeaylnlf.exe.vir a variant of Win32/Adware.SpeedingUpMyPC.AP application
C:\AdwCleaner\Quarantine\C\Users\Carson\AppData\Local\ArcadeTwist\uninstaller.exe.vir a variant of Win32/ArcadeParlor.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Carson\AppData\Local\ArcadeTwist\updater.exe.vir a variant of Win32/ArcadeParlor.D potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Carson\AppData\Local\ArcadeTwist\cat\VOTCerInst.dll.vir a variant of Win32/Packed.Komodia.A suspicious application
C:\AdwCleaner\Quarantine\C\Users\Carson\AppData\Local\ArcadeTwist\cat\VOTInstWXP.exe.vir a variant of Win32/Komodia.A potentially unsafe application
C:\AdwCleaner\Quarantine\C\Users\Carson\AppData\Local\ArcadeTwist\cat\VOTPrx.dll.vir a variant of Win32/Komodia.A potentially unsafe application
C:\AdwCleaner\Quarantine\C\Users\Carson\AppData\Local\ArcadeTwist\cat\VOTPrx.exe.vir a variant of Win32/Packed.Komodia.A suspicious application
C:\FRST\Quarantine\C\Users\Carson\AppData\Local\Temp\optprosetup.exe.xBAD multiple threats
C:\FRST\Quarantine\C\Users\Carson\AppData\Local\Temp\SPSetup.exe.xBAD a variant of Win32/ClientConnect.A potentially unwanted application
C:\Program Files (x86)\Google\Chrome\Application\chrome.dll a variant of Win32/ExtenBro.BK trojan
C:\Program Files (x86)\Google\Chrome\Application\GoogleUpdateHelper.dll a variant of Win32/ExtenBro.BK trojan
C:\Program Files (x86)\NCH Software\VideoPad\videopad.exe a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
C:\Program Files (x86)\NCH Software\VideoPad\videopadsetup_v4.00.exe a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
C:\Users\Carson\Downloads\vppsetup.exe a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
Operating memory a variant of Win32/ExtenBro.BK trojan
 
Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)
 

start
C:\Program Files (x86)\Google\Chrome\Application\chrome.dll
C:\Program Files (x86)\Google\Chrome\Application\GoogleUpdateHelper.dll
C:\Program Files (x86)\NCH Software\VideoPad\videopad.exe
C:\Program Files (x86)\NCH Software\VideoPad\videopadsetup_v4.00.exe
C:\Users\Carson\Downloads\vppsetup.exe
EmptyTemp:
End


Open FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


Tell me whats happening now.
Don't notice adware now. Does it appear to be fixed from the log? Thanks.
 
 
Fix result of Farbar Recovery Scan Tool (x64) Version:06-08-2015
Ran by [removed] (2015-08-07 16:32:32) Run:2
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
start
C:\Program Files (x86)\Google\Chrome\Application\chrome.dll
C:\Program Files (x86)\Google\Chrome\Application\GoogleUpdateHelper.dll
C:\Program Files (x86)\NCH Software\VideoPad\videopad.exe
C:\Program Files (x86)\NCH Software\VideoPad\videopadsetup_v4.00.exe
C:\Users\Carson\Downloads\vppsetup.exe
EmptyTemp:
End
 
*****************
 
C:\Program Files (x86)\Google\Chrome\Application\chrome.dll => moved successfully.
C:\Program Files (x86)\Google\Chrome\Application\GoogleUpdateHelper.dll => moved successfully.
C:\Program Files (x86)\NCH Software\VideoPad\videopad.exe => moved successfully.
C:\Program Files (x86)\NCH Software\VideoPad\videopadsetup_v4.00.exe => moved successfully.
C:\Users\Carson\Downloads\vppsetup.exe => moved successfully.
EmptyTemp: => 120.3 MB temporary data Removed.
 
 
The system needed a reboot.. 
 
==== End of Fixlog 16:32:38 ====
 

Don't notice adware now. Does it appear to be fixed from the log? Thanks.

I think so.
If,  you should have problems using Google Chrome,  please uninstall and reinstall the program. 
 
If you do need to reinstall
 
Instructions on how to backup your Favourites/Bookmarks and other data can be found below.
  • [external image: U5NwUGc.png]Backup Chrome Bookmarks
~~~~~~~~~~~~~~~~~~~`

Please download and install Revo Uninstaller Free
  • Double click Revo Uninstaller to run it.
  • From the list of programs double click on Google Chrome
  • When prompted if you want to uninstall click Yes.
  • Be sure the Moderate option is selected then click Next.
  • The program will run, If prompted again click Yes
  • when the built-in uninstaller is finished click on Next.
  • Once the program has searched for leftovers click Next.
  • Check/tick the bolded items only on the list then click Delete
  • when prompted click on Yes and then on next.
  • put a check on any folders that are found and select delete
  • when prompted select yes then on next
  • Once done click Finish.
  • ~~~~~~~~~~~~~~~~~~~~~
    Then, it can be reinstalled from
    http://www.google.com/chrome/

    If I'm correct,  an update came in from a place other then the original Google Chrome updater hence the adware.
*****

ready to remove tools and quarantine folders?
[external image: AFZxnZc.jpg] DelFix
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).

    ~~~~~~~~~~~~~~~`

  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP

    The following programmes come highly recommended in the security community.
  • [external image: xKsUqI5A.png.pagespeed.ic.vn1Hlvqi8h.jpg]AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
  • [external image: EG85Vjt.png]Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • [external image: x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpg]Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • [external image: xjv4nhMJ.png.pagespeed.ic.A5YbWn1eDO.png]NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • [external image: DgW1XL2.png.pagespeed.ce.v1OlJl_ZAS.png]Secuina PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • [external image: xj1OLIec.png.pagespeed.ic.k6hhwopU0q.jpg]SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • [external image: xJEP5iWI.png.pagespeed.ic.4tmM1lM7DQ.png]Web of Trust (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

    Want to help others? Join the ClassRoom and learn how.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI