This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Super Ad Romove In my browser

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi . Got this funny thing popping up on my browser and needs help solving it . Could someone please help ?

 

Many thanks . 

Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

 

 

 

Scan with FRST in normal mode

Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start –> Computer (right click) –> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.

FRST . txt 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:02-08-2015 01
Ran by [removed] (administrator) on PEANUT (06-08-2015 10:05:03)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterServer.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
() C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
() C:\Program Files\Lenovo Yoga PhoneCompanion\adb.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\msosync.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\ismagent.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-03-27] (Intel Corporation)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-01-22] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
HKLM\…\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2013-10-18] (Realtek semiconductor)
HKLM\…\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2014-07-22] (Lenovo)
HKLM\…\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-07-22] ()
HKLM\…\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2014-07-22] (Lenovo(beijing) Limited)
HKLM\…\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-07-22] (Lenovo(beijing) Limited)
HKLM-x32\…\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [119280 2014-01-07] (Lenovo)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [335232 2015-03-07] (Oracle Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-648119318-4113145362-2409287244-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.bing.com/search?q={searchTerms}&form;=MSSEDF&pc;=MSE1
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.bing.com/search?q={searchTerms}&form;=MSSEDF&pc;=MSE1
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-648119318-4113145362-2409287244-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.bing.com/search?q={searchTerms}&form;=MSSEDF&pc;=MSE1
SearchScopes: HKU\S-1-5-21-648119318-4113145362-2409287244-1001 -> {CAAA82DD-3477-40F8-BA0E-F1B8D2B0DB99} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-06-09] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-04-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{7DA0D1A2-70F9-47C3-BC28-7F89087C5CB0}: [DhcpNameServer] 169.254.54.64
Tcpip\..\Interfaces\{D0819CE9-A454-45FD-9F0F-B53A73CE30DF}: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-17] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-17] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-04-09] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-04-09] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-03-30] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-21] (Google Inc.)
 
Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Keng Ling\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (YouTube) - C:\Users\Keng Ling\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-18]
CHR Extension: (Google Search) - C:\Users\Keng Ling\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-18]
CHR Extension: (Google Wallet) - C:\Users\Keng Ling\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-18]
CHR Extension: (Gmail) - C:\Users\Keng Ling\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-18]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2753720 2015-07-01] (Microsoft Corporation)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-03-27] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282072 2014-03-11] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-28] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-28] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-17] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-17] (Intel Corporation)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-07-22] (Lenovo(beijing) Limited)
R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-07-22] (Lenovo)
S2 Mobile Partner. RunOuc; C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe [655744 2012-06-28] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-18] ()
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [167176 2014-02-25] (PointGrab LTD)
R2 PG_Service_Launcher; C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe [512776 2014-02-25] (PointGrab LTD)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe [285712 2014-07-22] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe [304144 2014-07-22] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-07-22] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 wifimansvc; C:\Program Files (x86)\Mobile Partner\eap\wifimansvc.exe [605696 2012-08-06] () [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-07-22] (Lenovo)
R2 YogaPicks.AppService; C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe [19440 2014-01-07] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-01-18] (Intel® Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S3 huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [238080 2012-06-06] (Huawei Technologies Co., Ltd.)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [142280 2013-10-18] (Intel Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-17] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3433952 2014-02-19] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
S3 NPF; C:\Windows\System32\drivers\NPF.sys [35344 2012-06-06] (CACE Technologies, Inc.)
S3 NPF; C:\Windows\SysWOW64\drivers\NPF.sys [35344 2012-06-06] (CACE Technologies, Inc.)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8876248 2013-10-18] (Realtek Semiconductor Corp.)
R3 SensorsHIDClassDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-12-19] (Synaptics Incorporated)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-06 10:05 - 2015-08-06 10:05 - 00017208 _____ C:\Users\Keng Ling\Downloads\FRST.txt
2015-08-06 10:04 - 2015-08-06 10:05 - 00000000 ____D C:\FRST
2015-08-06 10:04 - 2015-08-06 10:04 - 02169856 _____ (Farbar) C:\Users\Keng Ling\Downloads\FRST64.exe
2015-08-03 11:23 - 2015-08-03 11:47 - 72169331 _____ C:\Users\Keng Ling\Desktop\Planetshakers.m4a
2015-08-01 21:47 - 2015-07-25 21:34 - 01084928 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-08-01 19:31 - 2015-08-01 19:31 - 00000000 _____ C:\autoexec.bat
2015-08-01 19:30 - 2015-08-01 19:30 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\Keng Ling\Downloads\SpyHunter-Installer.exe
2015-07-26 20:28 - 2015-07-26 20:29 - 02248704 _____ C:\Users\Keng Ling\Downloads\adwcleaner_4.208.exe
2015-07-26 17:41 - 2015-07-26 17:41 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Keng Ling\Downloads\revosetup.exe
2015-07-26 17:41 - 2015-07-26 17:41 - 00001291 _____ C:\Users\Keng Ling\Desktop\Revo Uninstaller.lnk
2015-07-26 17:41 - 2015-07-26 17:41 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-07-21 16:14 - 2015-07-21 16:47 - 44792000 _____ C:\Users\Keng Ling\Downloads\Full_Movie_HDRip_HD720p_x624[YIFY].rar
2015-07-21 16:14 - 2015-07-21 16:14 - 00014417 _____ C:\Users\Keng Ling\Downloads\Full_Movie_BluRayRip_HD720p_x624[YIFY].rar.torrent
2015-07-21 15:48 - 2015-07-14 22:14 - 00358912 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-07-21 15:48 - 2015-07-14 22:14 - 00301056 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-07-21 15:48 - 2015-07-14 22:14 - 00035840 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-07-21 15:48 - 2015-07-14 22:13 - 00044032 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-07-19 01:26 - 2015-05-12 00:34 - 00332800 _____ (Microsoft Corporation) C:\windows\system32\fhcpl.dll
2015-07-18 02:04 - 2015-07-18 02:09 - 794375838 _____ C:\Users\Keng Ling\Downloads\SBS Camp Evolution.zip
2015-07-18 01:52 - 2015-07-18 01:57 - 00000000 ____D C:\Users\Keng Ling\Desktop\BIOLOGICAL SCIENCES
2015-07-18 01:50 - 2015-07-18 01:56 - 306936352 _____ C:\Users\Keng Ling\Downloads\Y2 S1.zip
2015-07-18 01:50 - 2015-07-18 01:53 - 256079802 _____ C:\Users\Keng Ling\Downloads\Y2 S2.zip
2015-07-18 01:50 - 2015-07-18 01:51 - 22020536 _____ C:\Users\Keng Ling\Downloads\BS1003_ORGANIC CHEMISTRY.zip
2015-07-18 01:50 - 2015-07-18 01:51 - 12271874 _____ C:\Users\Keng Ling\Downloads\BS1001_INTRO TO BIO.zip
2015-07-18 01:50 - 2015-07-18 01:50 - 05540020 _____ C:\Users\Keng Ling\Downloads\PE.zip
2015-07-18 01:50 - 2015-07-18 01:50 - 01678373 _____ C:\Users\Keng Ling\Downloads\UE.zip
2015-07-18 01:50 - 2015-07-18 01:50 - 00119650 _____ C:\Users\Keng Ling\Downloads\WORKPLACE SAFETY & HEALTH.zip
2015-07-18 01:49 - 2015-07-18 01:50 - 33685067 _____ C:\Users\Keng Ling\Downloads\Y1 S2.zip
2015-07-18 00:37 - 2015-05-03 08:39 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-07-18 00:37 - 2015-04-30 07:22 - 00130048 _____ (Microsoft Corporation) C:\windows\system32\WiFiDisplay.dll
2015-07-18 00:36 - 2015-06-30 06:43 - 00026288 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-07-18 00:36 - 2015-06-29 23:07 - 01145856 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-07-18 00:36 - 2015-06-29 23:07 - 00764928 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-07-18 00:36 - 2015-06-29 23:07 - 00433152 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-07-18 00:36 - 2015-06-29 23:07 - 00067584 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-07-18 00:36 - 2015-06-27 07:21 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-07-18 00:36 - 2015-06-27 07:21 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-07-18 00:36 - 2015-05-12 21:19 - 00294912 _____ (Microsoft Corporation) C:\windows\system32\SystemEventsBrokerServer.dll
2015-07-18 00:36 - 2015-05-12 02:17 - 01201664 ____C (Microsoft Corporation) C:\windows\system32\Drivers\bthport.sys
2015-07-18 00:36 - 2015-05-08 01:50 - 22292672 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-07-18 00:36 - 2015-05-08 01:00 - 03109376 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2015-07-18 00:36 - 2015-05-08 00:53 - 19734960 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-07-18 00:36 - 2015-05-08 00:12 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2015-07-18 00:36 - 2015-05-07 23:21 - 00522240 _____ (Microsoft Corporation) C:\windows\system32\GeofenceMonitorService.dll
2015-07-18 00:36 - 2015-05-07 23:05 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\GeofenceMonitorService.dll
2015-07-18 00:36 - 2015-05-03 23:09 - 00274944 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-18 00:36 - 2015-05-03 23:07 - 07784448 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2015-07-18 00:36 - 2015-05-03 22:58 - 00210944 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-18 00:36 - 2015-05-03 22:57 - 05264384 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2015-07-18 00:36 - 2015-05-03 22:55 - 00971776 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2015-07-18 00:36 - 2015-05-03 22:49 - 00811008 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2015-07-18 00:36 - 2015-05-02 07:33 - 00410739 _____ C:\windows\system32\ApnDatabase.xml
2015-07-18 00:36 - 2015-04-28 21:13 - 00513480 _____ C:\windows\SysWOW64\locale.nls
2015-07-18 00:36 - 2015-04-28 21:13 - 00513480 _____ C:\windows\system32\locale.nls
2015-07-18 00:36 - 2015-04-25 10:25 - 00020992 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-07-18 00:36 - 2015-04-23 23:47 - 03084288 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll
2015-07-18 00:36 - 2015-04-23 23:16 - 02471424 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll
2015-07-18 00:36 - 2014-11-05 03:25 - 00059712 ____C (Microsoft Corporation) C:\windows\system32\Drivers\kbdclass.sys
2015-07-18 00:36 - 2014-11-05 03:25 - 00051008 ____C (Microsoft Corporation) C:\windows\system32\Drivers\mouclass.sys
2015-07-18 00:36 - 2014-11-04 14:55 - 00026112 ____C (Microsoft Corporation) C:\windows\system32\Drivers\sermouse.sys
2015-07-18 00:36 - 2014-11-04 14:54 - 00108544 ____C (Microsoft Corporation) C:\windows\system32\Drivers\i8042prt.sys
2015-07-18 00:36 - 2014-11-04 14:54 - 00032256 ____C (Microsoft Corporation) C:\windows\system32\Drivers\kbdhid.sys
2015-07-18 00:36 - 2014-11-04 14:54 - 00030208 ____C (Microsoft Corporation) C:\windows\system32\Drivers\mouhid.sys
2015-07-16 12:11 - 2015-07-16 12:42 - 552401305 _____ C:\Users\Keng Ling\Downloads\prom.zip
2015-07-15 23:47 - 2015-07-10 03:51 - 00136904 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-07-15 23:47 - 2015-07-10 02:40 - 00359936 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-07-15 23:47 - 2015-07-10 00:03 - 03701760 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-07-15 23:47 - 2015-07-09 23:54 - 00035840 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-07-15 23:47 - 2015-07-09 23:53 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-07-15 23:47 - 2015-07-09 23:50 - 00409088 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2015-07-15 23:47 - 2015-07-09 23:50 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-07-15 23:47 - 2015-07-09 23:48 - 00891904 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-07-15 23:47 - 2015-07-09 23:46 - 02229248 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-07-15 23:47 - 2015-07-09 23:38 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-07-15 23:47 - 2015-07-09 23:37 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-07-15 23:47 - 2015-07-09 23:35 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-07-15 23:47 - 2015-07-09 23:34 - 00721920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-07-15 23:47 - 2015-07-02 06:08 - 05923840 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-07-15 23:47 - 2015-07-02 05:14 - 04520448 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-07-15 23:47 - 2015-06-28 13:07 - 00442712 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-07-15 23:47 - 2015-06-28 13:07 - 00178008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-07-15 23:47 - 2015-06-28 13:06 - 01311960 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-07-15 23:47 - 2015-06-28 13:06 - 00332120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-07-15 23:47 - 2015-06-28 00:42 - 00747520 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-07-15 23:47 - 2015-06-27 11:13 - 00202240 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-07-15 23:47 - 2015-06-27 11:12 - 00401408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-07-15 23:47 - 2015-06-27 11:12 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-07-15 23:47 - 2015-06-27 11:08 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-07-15 23:47 - 2015-06-27 11:08 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-07-15 23:47 - 2015-06-27 10:40 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2015-07-15 23:47 - 2015-06-27 10:14 - 00027136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-07-15 23:47 - 2015-06-27 10:05 - 01441792 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-07-15 23:47 - 2015-06-27 10:00 - 00989184 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-07-15 23:47 - 2015-06-27 09:53 - 00324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2015-07-15 23:47 - 2015-06-27 09:26 - 00802816 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-07-15 23:47 - 2015-06-25 10:31 - 04177920 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-07-15 23:47 - 2015-06-16 06:41 - 00065024 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2015-07-15 23:47 - 2015-06-16 06:24 - 03320320 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-07-15 23:47 - 2015-06-16 05:16 - 00059904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2015-07-15 23:47 - 2015-06-16 05:09 - 03607552 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2015-07-15 23:47 - 2015-06-16 04:50 - 02774528 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-07-15 23:47 - 2015-06-16 03:57 - 02460160 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-07-15 23:47 - 2015-05-31 05:18 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\werdiagcontroller.dll
2015-07-15 23:47 - 2015-05-31 03:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll
2015-07-15 23:47 - 2015-05-31 03:35 - 00911360 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-07-15 23:46 - 2015-07-03 05:21 - 19877376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-07-15 23:46 - 2015-07-03 04:50 - 02279424 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-07-15 23:46 - 2015-07-03 04:49 - 25193984 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-07-15 23:46 - 2015-07-03 04:23 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-07-15 23:46 - 2015-07-03 04:19 - 12855296 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-07-15 23:46 - 2015-07-03 03:55 - 01310720 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-07-15 23:46 - 2015-07-03 03:20 - 14453248 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-07-15 23:46 - 2015-07-03 02:59 - 01545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-07-15 23:45 - 2015-06-16 13:36 - 01661576 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2015-07-15 23:45 - 2015-06-16 13:36 - 01212248 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2015-07-15 23:45 - 2015-06-16 06:39 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-07-15 23:45 - 2015-06-16 06:38 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-07-15 23:45 - 2015-06-16 06:26 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-07-15 23:45 - 2015-06-16 06:24 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-07-15 23:45 - 2015-06-16 06:02 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2015-07-15 23:45 - 2015-06-16 05:58 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-07-15 23:45 - 2015-06-16 05:57 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-07-15 23:45 - 2015-06-16 05:56 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-07-15 23:45 - 2015-06-16 05:55 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-07-15 23:45 - 2015-06-16 05:49 - 01032704 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2015-07-15 23:45 - 2015-06-16 05:41 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-07-15 23:45 - 2015-06-16 05:38 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-07-15 23:45 - 2015-06-16 05:36 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-07-15 23:45 - 2015-06-16 05:17 - 02880000 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll
2015-07-15 23:45 - 2015-06-16 05:16 - 02427392 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-07-15 23:45 - 2015-06-16 05:15 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-07-15 23:45 - 2015-06-16 05:13 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-07-15 23:45 - 2015-06-16 05:04 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-07-15 23:45 - 2015-06-16 05:03 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-07-15 23:45 - 2015-06-16 04:52 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-07-15 23:45 - 2015-06-16 04:47 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2015-07-15 23:45 - 2015-06-16 04:44 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-07-15 23:45 - 2015-06-16 04:43 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-07-15 23:45 - 2015-06-16 04:42 - 00128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2015-07-15 23:45 - 2015-06-16 04:41 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-07-15 23:45 - 2015-06-16 04:37 - 00880128 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2015-07-15 23:45 - 2015-06-16 04:32 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-07-15 23:45 - 2015-06-16 04:31 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-07-15 23:45 - 2015-06-16 04:30 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-07-15 23:45 - 2015-06-16 04:30 - 00327168 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-07-15 23:45 - 2015-06-16 04:17 - 01048576 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll
2015-07-15 23:45 - 2015-06-16 04:07 - 01951232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-07-15 23:45 - 2015-06-16 04:02 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-07-15 23:45 - 2015-06-11 11:49 - 01380600 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-07-15 23:45 - 2015-06-11 00:13 - 01097216 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-07-15 23:45 - 2015-05-08 00:47 - 00564224 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2015-07-12 17:49 - 2015-08-01 19:23 - 00000024 _____ C:\Users\Keng Ling\AppData\Roaming\appdataFr25.bin
2015-07-12 17:30 - 2015-07-12 17:30 - 00000000 ____D C:\Users\Keng Ling\AppData\Local\GWX
2015-07-10 21:39 - 2015-08-02 15:57 - 00000000 ___HD C:\$Windows.~BT
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-06 10:02 - 2013-08-22 23:36 - 00000000 ____D C:\windows\system32\sru
2015-08-06 09:59 - 2014-07-22 18:03 - 01057876 _____ C:\windows\WindowsUpdate.log
2015-08-06 09:59 - 2013-08-22 23:36 - 00000000 ____D C:\windows\AppReadiness
2015-08-06 09:58 - 2015-06-16 20:31 - 00004982 _____ C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Peanut-Keng Ling Peanut
2015-08-06 09:58 - 2015-06-16 20:31 - 00000000 ____D C:\Users\Keng Ling\OneDrive
2015-08-06 09:57 - 2014-03-18 17:44 - 00215006 _____ C:\windows\PFRO.log
2015-08-06 09:57 - 2013-08-22 22:46 - 00052327 _____ C:\windows\setupact.log
2015-08-06 09:57 - 2013-08-22 22:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-08-06 09:56 - 2014-07-22 19:06 - 00002560 _____ C:\windows\system32\VfService.trf
2015-08-06 09:56 - 2013-08-22 21:25 - 00262144 ___SH C:\windows\system32\config\BBI
2015-08-06 09:55 - 2015-02-18 20:54 - 00003934 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{8313204A-2A2B-4621-AF26-3557D402B16A}
2015-08-06 09:54 - 2015-06-29 02:21 - 00450000 _____ C:\windows\system32\prfh0804.dat
2015-08-06 09:54 - 2015-06-29 02:21 - 00140290 _____ C:\windows\system32\prfc0804.dat
2015-08-06 09:54 - 2014-03-18 17:53 - 01438230 _____ C:\windows\system32\PerfStringBackup.INI
2015-08-04 04:15 - 2015-02-18 22:35 - 00113880 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-03 22:20 - 2014-09-18 03:21 - 00003598 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-648119318-4113145362-2409287244-1001
2015-08-02 16:03 - 2014-04-04 03:15 - 00000000 ____D C:\windows\Panther
2015-08-01 22:24 - 2013-08-22 23:20 - 00000000 ____D C:\windows\CbsTemp
2015-08-01 19:25 - 2015-03-30 23:05 - 00003100 _____ C:\windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-648119318-4113145362-2409287244-1001
2015-07-26 20:03 - 2015-02-18 20:57 - 00002214 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-25 19:36 - 2015-04-04 20:25 - 00000000 ___SD C:\windows\system32\GWX
2015-07-24 22:30 - 2014-09-18 03:15 - 00000000 ____D C:\Users\Keng Ling\AppData\Local\Packages
2015-07-21 19:22 - 2013-08-22 23:36 - 00000000 ____D C:\windows\rescache
2015-07-21 16:05 - 2015-03-30 23:01 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-07-21 15:52 - 2013-08-22 22:44 - 00492000 _____ C:\windows\system32\FNTCACHE.DAT
2015-07-18 16:45 - 2013-08-22 23:36 - 00000000 ___RD C:\windows\ToastData
2015-07-18 16:45 - 2013-08-22 23:36 - 00000000 ____D C:\windows\WinStore
2015-07-18 01:53 - 2015-02-19 11:49 - 00000000 ___SD C:\windows\system32\CompatTel
2015-07-18 01:53 - 2015-02-19 11:49 - 00000000 ____D C:\windows\system32\appraiser
2015-07-18 01:53 - 2015-02-19 02:20 - 00000000 ____D C:\windows\system32\MRT
2015-07-18 01:48 - 2015-04-04 20:25 - 00000000 ___SD C:\windows\SysWOW64\GWX
2015-07-14 05:10 - 2015-02-19 12:55 - 00792568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-07-14 05:10 - 2015-02-19 12:55 - 00178168 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
 
==================== Files in the root of some directories =======
 
2015-07-12 17:49 - 2015-08-01 19:23 - 0000024 _____ () C:\Users\Keng Ling\AppData\Roaming\appdataFr25.bin
2015-06-29 23:27 - 2015-06-29 23:27 - 0000000 _____ () C:\Users\Keng Ling\AppData\Local\Temp.dat
2014-07-22 18:31 - 2014-07-22 18:31 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
C:\Users\Keng Ling\AppData\Local\Temp\oct1439.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\oct19FB.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\oct27FA.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\oct98DE.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octB3E.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octC112.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octC383.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octC4B8.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octC99.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octCA.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octD02.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octDFB8.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octFE77.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octFE7B.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\Quarantine.exe
C:\Users\Keng Ling\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-08-01 22:22
 
==================== End of log ============================
 
 
Addition.txt
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:02-08-2015 01
Ran by [removed] (2015-08-06 10:06:11)
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-648119318-4113145362-2409287244-500 - Administrator - Disabled)
Guest (S-1-5-21-648119318-4113145362-2409287244-501 - Limited - Disabled)
Keng Ling (S-1-5-21-648119318-4113145362-2409287244-1001 - Administrator - Enabled) => C:\Users\Keng Ling
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
CyberLink MediaStory (HKLM-x32\…\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dolby Digital Plus Home Theater (HKLM\…\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Energy Manager (HKLM-x32\…\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.0.35 - Lenovo)
Energy Manager (x32 Version: 1.0.0.35 - Lenovo) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 43.0.2357.130 - Google Inc.)
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Intel Experience Center - Configuration (x32 Version: 1.7.0.179 - Intel) Hidden
Intel(R) Experience Center Desktop Software (HKLM-x32\…\{3608ec0a-56b4-4d9d-b038-9b3e51d72582}) (Version: 1.7.0.179 - Intel)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.0.2.1000 - Intel Corporation)
Intel(R) Update Manager (x32 Version: 1.6.2.69 - Intel Corporation) Hidden
Intel(R) Wireless Bluetooth(R) 4.0 (HKLM-x32\…\{96C730E4-F055-4118-BDF3-6E071763853C}) (Version: 3.0.1342.02 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{7e493493-a430-4b7b-b8a2-48d61599e220}) (Version: 17.0.0 - Intel Corporation)
Java 8 Update 40 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
Lenovo EasyCamera (HKLM-x32\…\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10249 - Realtek Semiconductor Corp.)
Lenovo Experience Improvement (HKLM\…\LenovoExperienceImprovement) (Version: 1.0.4.0 - Lenovo)
Lenovo FusionEngine  (HKLM-x32\…\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\…\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.8 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.8 - Lenovo) Hidden
Lenovo Motion Control (HKLM-x32\…\InstallShield_{E9325F15-6339-45E8-9DC4-C2D44B623039}) (Version: 2.5.1.0224 - PointGrab)
Lenovo Motion Control (x32 Version: 2.5.1.0224 - PointGrab) Hidden
Lenovo OneKey Recovery (HKLM-x32\…\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.0.0.2105 - CyberLink Corp.) Hidden
Lenovo Photo Master (HKLM-x32\…\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.52953.1504 - CyberLink Corp.)
Lenovo Photo Master (x32 Version: 1.0.52953.1504 - CyberLink Corp.) Hidden
Lenovo Smart Voice (HKLM\…\Lenovo SmartVoice) (Version: 1.0.2.2 - Lenovo)
Lenovo Transition (HKLM\…\Lenovo Transition) (Version: 2.0.13.10181 - Lenovo)
Lenovo VeriFace Pro (HKLM\…\Lenovo VeriFace) (Version: 5.0.14.1061 - Lenovo)
Lenovo Yoga 2 Demo (HKLM-x32\…\{03C682A4-05CD-4D22-B50A-B9C3C5F2B137}) (Version: 1.0.7 - Lenovo)
Lenovo Yoga PhoneCompanion (HKLM-x32\…\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.1.9.5 - Lenovo)
Lenovo Yoga PhoneCompanion (x32 Version: 1.1.9.5 - Lenovo) Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft Office 365 - en-us (HKLM\…\O365HomePremRetail - en-us) (Version: 15.0.4737.1003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-648119318-4113145362-2409287244-1001\…\OneDriveSetup.exe) (Version: 17.3.5907.0716 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mobile Partner (HKLM-x32\…\Mobile Partner) (Version: 23.009.05.00.203 - Huawei Technologies Co.,Ltd)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4737.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4737.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4737.1003 - Microsoft Corporation) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.39053 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7161 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.14.71 - Synaptics Incorporated)
Update for CHS Microsoft IME HAP Dictionary (Version: 16.0.1560.1 - Microsoft Corporation) Hidden
User Manuals (HKLM-x32\…\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
User Manuals (x32 Version: 3.0.0.3 - Lenovo) Hidden
Windows Driver Package - Lenovo (ACPIVPC) System  (02/17/2013 9.52.0.776) (HKLM\…\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid  (07/25/2013 10.30.0.288) (HKLM\…\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.21 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Yoga Picks (HKLM-x32\…\{267C8BA0-876B-4589-9F14-EFB84ABCEA7F}) (Version: 1.5.014.0106 - Lenovo)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-648119318-4113145362-2409287244-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-648119318-4113145362-2409287244-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Keng Ling\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncApi64.dll (Microsoft Corporation)
 
==================== Restore Points =========================
 
16-07-2015 13:36:27 Windows Update
21-07-2015 15:51:01 Windows Update
26-07-2015 17:42:26 Revo Uninstaller's restore point - TerminusKeeper
01-08-2015 22:22:04 Windows Update
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 21:25 - 2013-08-22 21:25 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1D333F56-8774-46E9-BEC5-34C163F5697A} - System32\Tasks\Lenovo\Experience Improvement Logon => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2013-06-03] (Lenovo)
Task: {22C3EAE4-AB23-4740-9411-760E9687AFA7} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Peanut-Keng Ling Peanut => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-06-02] (Microsoft Corporation)
Task: {32A44705-A3DD-4DF7-BB1A-3CE9633A74FF} - System32\Tasks\ISM-UpdateService-e57b59e7-5862-4250-9ce0-76fb411dc0d2-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\Bootstrap.exe [2013-07-04] (Intel Corporation)
Task: {636ED2CE-2B39-4117-BABA-4F721C550FDC} - \Bidaily Synchronize Task[pr] No Task File <==== ATTENTION
Task: {7263D23C-3791-4F80-9039-D3B3A2E500CA} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-07-01] (Microsoft Corporation)
Task: {8CE52C5E-4D81-47BF-91F2-E1624C59A156} - System32\Tasks\ISM-UpdateService-e57b59e7-5862-4250-9ce0-76fb411dc0d2 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\Bootstrap.exe [2013-07-04] (Intel Corporation)
Task: {9BC9B254-B7E7-4D6B-8C42-35AC14590681} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-12-19] (Synaptics Incorporated)
Task: {C07410D6-D5A2-4440-B02B-A746D49754E9} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-648119318-4113145362-2409287244-1001 => %localappdata%\Microsoft\OneDrive\OneDrive.exe
Task: {CA8C03CE-E4C5-40A6-B500-96F7C6408316} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe
Task: {D62355DB-C777-44A1-BE48-FFE46A919DED} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-07-22] (Lenovo)
Task: {DEF87012-576B-44EA-A909-BE17B61726B9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2015-07-03] (Microsoft Corporation)
Task: {E1CAE276-5894-4C4E-A52D-9D35DCC11153} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-07-01] (Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-03-30 23:01 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2011-03-14 23:27 - 2011-03-14 23:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe
2015-02-18 21:52 - 2012-06-28 10:46 - 00655744 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
2014-07-22 19:06 - 2012-04-24 18:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2014-07-22 19:06 - 2014-07-22 19:06 - 00067856 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
2014-07-22 19:06 - 2014-07-22 19:06 - 00672016 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfDataStorageInterface.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00061200 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll
2014-07-22 19:04 - 2014-01-07 06:14 - 00019440 _____ () C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
2015-04-01 15:43 - 2015-04-01 15:43 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
2014-07-22 19:04 - 2014-01-07 05:58 - 00044016 _____ () C:\Program Files (x86)\Lenovo\Yoga Picks\Util.dll
2015-03-07 23:03 - 2015-03-07 23:03 - 00207872 _____ () C:\windows\assembly\NativeImages_v4.0.30319_64\Windows.System\a4efa88b742703220e527956d8ab4e84\Windows.System.ni.dll
2015-03-07 23:03 - 2015-03-07 23:03 - 01259520 _____ () C:\windows\assembly\NativeImages_v4.0.30319_64\Windows.Networking\8f0dd293f95c402613c49fb2fac85bdd\Windows.Networking.ni.dll
2015-03-07 23:03 - 2015-03-07 23:03 - 00363520 _____ () C:\windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\6382e6f5ad8b7a9db4f5cd4817e70319\Windows.Foundation.ni.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00108304 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
2014-07-22 19:06 - 2014-07-22 19:06 - 00815104 _____ () C:\Program Files\Lenovo Yoga PhoneCompanion\adb.exe
2015-02-18 21:52 - 2009-01-10 18:32 - 00011362 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\mingwm10.dll
2015-02-18 21:52 - 2009-06-23 02:42 - 00043008 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\libgcc_s_dw2-1.dll
2015-02-18 21:52 - 2010-07-23 12:58 - 02415104 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QtCore4.dll
2015-02-18 21:52 - 2010-02-10 22:10 - 01148416 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QtNetwork4.dll
2015-02-18 21:52 - 2012-06-28 10:34 - 00843264 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QueryStrategy.dll
2015-02-18 21:52 - 2010-02-10 22:06 - 00398336 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QtXml4.dll
2014-02-25 07:39 - 2014-02-25 07:39 - 00013576 _____ () C:\Program Files (x86)\Lenovo\Motion Control\PointGrabDeviceAPI.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00102672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll
2015-04-01 15:43 - 2015-04-01 15:43 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
2015-04-01 15:42 - 2015-04-01 15:42 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\AppVIsvStream32.dll
2014-07-22 18:28 - 2013-09-17 03:17 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-02-25 07:39 - 2014-02-25 07:39 - 02690312 _____ () C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterFilter.ax
2015-06-24 00:10 - 2015-06-20 13:46 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libglesv2.dll
2015-06-24 00:10 - 2015-06-20 13:46 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Keng Ling\OneDrive:ms-properties
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-648119318-4113145362-2409287244-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{5536175F-D753-4FFC-8566-850AB49991B4}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{9E32A640-318B-4D4F-80E6-8C989B4154A5}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{BC3B45A1-0B93-4936-B69B-322F57DD121F}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{711B98C1-0609-409C-85FF-781FEA8B69EE}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{9BD8A0EB-31B0-4E8E-9C4E-1CAF25FA315A}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe
FirewallRules: [{70F9C12A-1BAA-4B2A-97CE-49A5D9A578E8}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe
FirewallRules: [{2C76A6A0-460C-41B4-910C-25B4B355C56E}] => (Allow) LPort=55100
FirewallRules: [{A28978D5-130D-4775-8831-02512A8D2144}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
FirewallRules: [{8D9556FF-5BFF-47D7-B5BA-BD3C2238D350}] => (Allow) C:\Users\Keng Ling\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{6CD11B93-F829-47C1-8C88-99ED74F3566E}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{6052E8A8-F2B2-4B06-8B76-5616A2AEB80B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/06/2015 09:57:39 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,StopICS success. failed with 0
 
Error: (08/06/2015 09:57:21 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrEnter ThreadNetworkMonitorAtRunTime. failed with 0
 
Error: (08/06/2015 09:55:36 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrSvc RESUMEAUTOMATIC control event received. failed with 0
 
Error: (08/06/2015 09:51:42 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
 
Error: (08/06/2015 09:51:42 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
 
Error: (08/06/2015 09:51:42 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
 
Error: (08/06/2015 09:51:42 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
 
Error: (08/06/2015 09:51:41 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
 
Error: (08/06/2015 09:51:41 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
 
Error: (08/06/2015 09:51:41 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
 
 
System errors:
=============
Error: (08/06/2015 09:59:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Google Update Service (gupdate) service failed to start due to the following error: 
%%2
 
Error: (08/06/2015 09:57:47 AM) (Source: DCOM) (EventID: 10016) (User: PEANUT)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}PeanutKeng LingS-1-5-21-648119318-4113145362-2409287244-1001LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (08/06/2015 09:57:47 AM) (Source: DCOM) (EventID: 10016) (User: PEANUT)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}PeanutKeng LingS-1-5-21-648119318-4113145362-2409287244-1001LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (08/06/2015 09:57:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Mobile Partner. OUC service failed to start due to the following error: 
%%1053
 
Error: (08/06/2015 09:57:23 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Mobile Partner. OUC service to connect.
 
Error: (08/06/2015 09:56:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Group Policy Client service failed to start due to the following error: 
%%1053
 
Error: (08/06/2015 09:56:38 AM) (Source: DCOM) (EventID: 10010) (User: PEANUT)
Description: {82C49192-BE68-467F-BF50-971FD01DABF3}
 
Error: (08/06/2015 09:56:38 AM) (Source: DCOM) (EventID: 10010) (User: PEANUT)
Description: {03E64E17-B220-4052-9B9B-155F9CB8E016}
 
Error: (08/06/2015 09:56:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Application Experience service failed to start due to the following error: 
%%1053
 
Error: (08/06/2015 09:56:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Group Policy Client service failed to start due to the following error: 
%%1053
 
 
Microsoft Office:
=========================
Error: (08/06/2015 09:57:39 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,StopICS success. failed with 0
 
Error: (08/06/2015 09:57:21 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrEnter ThreadNetworkMonitorAtRunTime. failed with 0
 
Error: (08/06/2015 09:55:36 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrSvc RESUMEAUTOMATIC control event received. failed with 0
 
Error: (08/06/2015 09:51:42 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
 
Error: (08/06/2015 09:51:42 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
 
Error: (08/06/2015 09:51:42 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
 
Error: (08/06/2015 09:51:42 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
 
Error: (08/06/2015 09:51:41 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
 
Error: (08/06/2015 09:51:41 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
 
Error: (08/06/2015 09:51:41 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i3-4030U CPU @ 1.90GHz
Percentage of memory in use: 47%
Total physical RAM: 4016.96 MB
Available physical RAM: 2125.46 MB
Total Virtual: 5296.96 MB
Available Virtual: 2953.79 MB
 
==================== Drives ================================
 
Drive c: (Windows8_OS) (Fixed) (Total:423.21 GB) (Free:343.86 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.56 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 87D8B3AE)
 
Partition: GPT Partition Type.
 
==================== End of log ============================

Fix with FRST (normal mode)

WARNING: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 

  • Download the attached fixlist.txt and save it to the location where FRST is saved to.
  • Run FRST.exe (on 64bit, run FRST64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.

Full System Scan with Malwarebytes Antimalware



  • If not existing, please download Malwarebytes Anti-Malware to your desktop.
  • Double-click the downloaded setup file and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish.

If the program is already installed:

  • Run Malwarebytes Antimalware
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.

Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.

 

Attachments:

Fixlog.txt

 

Fix result of Farbar Recovery Scan Tool (x64) Version:06-08-2015
Ran by [removed] (2015-08-07 22:05:20) Run:2
Running from C:\Users\[removed]\Downloads
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Task: {636ED2CE-2B39-4117-BABA-4F721C550FDC} - \Bidaily Synchronize Task[pr] No Task File <==== ATTENTION
2015-07-12 17:49 - 2015-08-01 19:23 - 0000024 _____ () C:\Users\Keng Ling\AppData\Roaming\appdataFr25.bin
2015-06-29 23:27 - 2015-06-29 23:27 - 0000000 _____ () C:\Users\Keng Ling\AppData\Local\Temp.dat
2014-07-22 18:31 - 2014-07-22 18:31 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Tcpip\..\Interfaces\{7DA0D1A2-70F9-47C3-BC28-7F89087C5CB0}: [DhcpNameServer] 169.254.54.64
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
CloseProcesses:
EmptyTemp:
Reboot:
*****************
 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{636ED2CE-2B39-4117-BABA-4F721C550FDC} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task[pr] => key not found. 
"C:\Users\Keng Ling\AppData\Roaming\appdataFr25.bin" => File/Folder not found.
"C:\Users\Keng Ling\AppData\Local\Temp.dat" => File/Folder not found.
C:\ProgramData\DP45977C.lfl => moved successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7DA0D1A2-70F9-47C3-BC28-7F89087C5CB0}\\DhcpNameServer => value not found.
HKLM\SOFTWARE\Policies\Google => key not found. 
Processes closed successfully.
EmptyTemp: => 29.7 MB temporary data Removed.
 
 
The system needed a reboot.. 
 
==== End of Fixlog 22:05:22 ====
 
Malwarebytes.txt
 
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 7/8/2015
Scan Time: 10:09 PM
Logfile: Malwarebytes.txt
Administrator: Yes
 
Version: 2.1.8.1057
Malware Database: v2015.08.07.03
Rootkit Database: v2015.08.06.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Keng Ling
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 337471
Time Elapsed: 9 min, 48 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
EssetScan.txt
 
C:\Program Files (x86)\Google\Chrome\Application\chrome.dll a variant of Win32/ExtenBro.BK trojan
C:\Users\Keng Ling\Downloads\[Zero Raws] FAIRY TAIL 11 RAW TX 1280x720 x264 mp4.exe a variant of Win32/Adware.MultiPlug.KX application
 

Please delete C:\Program Files (x86)\Google\Chrome\Application\chrome.dll.

 

Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe

  • Hit Scan and wait for the scan to finish.

  • Confirm the message but don´t uncheck anything.

  • Hit Clean

  • When the run is finished, it will open up a text file

  • Please post its contents within your next reply

  • You´ll find the log file at C:\AdwCleaner[S1].txt also




Delete junk with JRT

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.

  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".

  • The tool will open and start scanning your system.

  • Please be patient as this can take a while to complete depending on your system's specifications.

  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

  • Post the contents of JRT.txt into your next message.




SecurityCheck

Reboot your system before starting!

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.

  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.



Tell me: Are any problems left now or may I post the final reply? :)

Adware Cleaner Log

 

# AdwCleaner v4.208 - Logfile created 12/08/2015 at 22:25:57
# Updated 09/07/2015 by Xplode
# Database : 2015-08-12.1 [Server]
# Operating system : Windows 8.1  (x64)
# Username : Keng Ling - PEANUT
# Running from : C:\Users\Keng Ling\Downloads\adwcleaner_4.208 (1).exe
# Option : Cleaning
 
***** [ Services ] *****
 
Service Deleted : YSearchUtilSvc
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\windows\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil
Folder Deleted : C:\Users\Keng Ling\AppData\Local\YSearchUtil
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17840
 
 
-\\ Google Chrome v43.0.2357.130
 
 
*************************
 
AdwCleaner[R1].txt - [915 bytes] - [12/08/2015 22:24:07]
AdwCleaner[S1].txt - [847 bytes] - [12/08/2015 22:25:57]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [905  bytes] ##########
 
JRT Log
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.6 (08.10.2015:1)
OS: Windows 8.1 x64
Ran by [removed] on Wed 12/08/2015 at 22:33:42.22
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
~~~ Chrome
 
 
[C:\Users\Keng Ling\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\Keng Ling\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Users\Keng Ling\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\Keng Ling\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 12/08/2015 at 22:36:35.30
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

Security Check Log

 

 Results of screen317's Security Check version 1.006  
   x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
Windows Defender   
 WMI entry may not exist for antivirus; attempting automatic update. 
`````````Anti-malware/Other Utilities Check:````````` 
 Java 8 Update 51  
 Google Chrome (43.0.2357.124) 
 Google Chrome (43.0.2357.130) 
````````Process Check: objlist.exe by Laurent````````  
 Windows Defender MSMpEng.exe 
 Windows Defender MpCmdRun.exe   
 Mobile Partner OnlineUpdate ouc.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  % 
````````````````````End of Log`````````````````````` 
 
 
Everything should be fine now . Don't see any problems for the time being . THANKS ~

Uninstall our tools using delfix

Please follow these steps in order:

  1. In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  2. In the case we used Combofix. Deactivate your antivirus software once more, then rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  3. In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process

  4. If there is still something left please delete it manualy.




Delete System Restore Points

To ensure your System Restore Points are free of malware, we will delete all of them but the most recent or create a new one.

On Windows Vista: Please follow these instructions to delete all but the most common System Protection Restore Points.
On Windows 7/8: Please follow these instructions to delete all but the most common System Protection Restore Points.
On Windows XP: Please follow these instructions to delete all but the most common System Protection Restore Points.

 

 

 

Recommendations: How to protect yourself

  • System Updates
  • Please ensure to have automatic updates activated in your control panel.
    For further information and a tutorial, see this Microsoft Support article.
  • Protection
  • What you need is one (not more) virus scanner with background protection. Additionally I recommend a special malware scanner to run on demand weekly.
    Personally I am using avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer good protection for free.
    • To keep your browser free of advertising, you may install the Adblock Plus browser extension.
    • It will filter unwanted advertising out of the website´s content.
    • To protect yourself from accidentally visiting malicious web sites, install the Web of Trust (WOT) browser extension.
    • It will display a green (safe), yellow (unknown) or red (potentially dangerous) icon for a visited website within your browser.
      In addition, before accessing a dangerous classified web site, a warning screen is displayed.


  • Up to date Software
  • Keep your Windows and your third party software up to date. The easiest way to get infected is an outdated windows, followed by: browser(s) (including add-ons and plug-ins), Adobe Flash Player and Adobe Reader, Java Runtime Environment, your antivirus program and so on. These links may help you to check:
    • Secunia Personal Software Inspector - checks if your software has updates available.

    • SecurityCheck (by screen317) - scans your computer for most vulnerable outdated software.

    • Mozilla: Check your plugins - The webpage will tell you if you have outdated plugins running in your Firefox browser.


  • Backup
  • Hardware issues, malware, fire, lightning strike: There is a long list of different ways to loose all your data. Back up your files regularly. Use the windows internal backup function or a third party tool and save your data onto an external hard drive, cloud storage, optical media like CDs or DVDs or (if available) a professional network backup system.
  • Behaviour
  • The commonest error when using a computer is "error 80" - what means that the error is located about 80cm in front of the monitor. This is a common joke between IT support technicians but it shows that all the safety mechanisms won´t help if you aren´t careful enough.
    • While surfing the internet, don´t click on anything you don´t know. In the worst case, it infects your system with malware.

    • Watch your step in social networks! Many cyber criminals use them to spread malware, mine personal pata (to be sold to advertising companies, for example) or simply do damage to other users. Even if a received hyperlink within a message seems to be coming from one of your friends, have a closer look. In addition, don´t click everything.

    • When installing software, have a look to each of the setup windows and uncheck any additional toolbars or free programs that may be offered additionally. Most of today´s setup procedures contain potentially unwanted programs so keep them off your system.

    • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
    • They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI